fix: require startup data-use consent before app access - #4
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Interceptor now requires agreement to the current data-use notice before displaying Home or Settings. A root full-screen cover has only Agree and cannot be dismissed interactively. Consent persists across relaunch; the legacy decision flag cannot bypass missing or revoked authorization.
Remove the persistent Data Use section from Settings and put disclosure and confirmed withdrawal under Privacy. Withdrawal stops capture, disables automatic reconnection, clears capture notifications, and returns to the consent cover. Agreement leaves certificate/VPN setup and optional notification authorization as separate actions. The startup notice uses the approved SF Symbols/card layout with the localized About Data Use heading; the five disclosure bodies are unchanged. English/Japanese copy and draft review instructions describe the resulting behavior.
Validation: 11 unit tests and three selected iPhone Simulator UI tests passed; final iPad Air M2 Simulator lifecycle and maximum-text-size landscape tests passed. Japanese startup screenshots visually checked on both sizes. Independent Claude diff and follow-up reviews found no blocking code findings. LocalGPT review failed with draft_unsupported. Physical-device testing, VoiceOver, and Split View remain unverified.
TestFlight build 30 was uploaded earlier and retains the prior flow. These new changes have not been uploaded or submitted; public policy changes remain drafts pending reconciliation before replacement submission.
Card layout follow-up: lifecycle and maximum-text-size landscape UI tests passed on both iPhone and M2 iPad simulators; Japanese and iPhone dark-mode appearance visually checked. Independent Claude plan/diff review found no blocking findings.