feat(identity): two exits for an identity that holds no key

Phase 6 of docs/npub-sign-in.md. Leaving: one sequence, two doors.

ForgetIdentity is NostrSecretViewModel.forgetKey's sequence lifted out --
the credential out of the file, the metadata hidden, the account rows
gone, in that order so a failure partway leaves the credential on disk
rather than an identity the selector lists but nothing can open. Since the
credentials file the first step is the same call for both credential
kinds, so it is one function; a mnemonic identity is refused at the first
step, because removing a seed is a wallet question this does not answer.
The nsec view model calls it now and keeps only its own state.

Sign out on the profile tab does, for a read-only identity only, what its
colour has been promising: a confirmation naming the npub -- this device
holds no key for it, so there is nothing to lose; the profile stays on the
relays -- then the identity leaves the device and the nav host's tail
re-lists and clears the active identity, which shows the selector or, if
this was the last one, Landing. It is the first real sign out in the app.
For the other two kinds the button keeps its pending route. SignOutViewModel
owns the confirmation and the in-flight state; SignOutDependencies bundles
what the screen needs so that a caller with none of it -- previews, tests
-- passes nothing.

The not-found screen had, for a read-only identity, no exit: Phase 5 hid
the set-up form (a kind 0 has to be signed), the profile tab is not
reachable before ProfileLoaded, and a user whose npub was found on no relay
could try again for ever. So a third action, shown only where the second is
not: use a different key, which is the same sequence behind the same
dialog, reached from the other end of the identity's life.

Tests: the sequence and where it stops, the view model's states around it,
and the two screens composed as each kind -- the profile's sign out asking
first and naming the npub, the not-found screen offering the form to one
kind and the other key to the other.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Pulled-From: curated/curated@a586b7c116
This commit is contained in:
Kgothatso Ngako
2026-09-12 20:45:34 +02:00
parent f5a6f74731
commit 786ac15959
11 changed files with 678 additions and 19 deletions

View File

@@ -267,6 +267,10 @@
<string name="read_only">Read only</string>
<string name="messages_need_the_secret_key_this_profile">Messages need the secret key. This profile is read only: you can see it and the people it follows, but nothing here can be opened or sent.</string>
<string name="sign_in_with_the_nsec">Sign in with the nsec</string>
<string name="sign_out_of_this_profile_question">Sign out of this profile?</string>
<string name="use_a_different_key_question">Use a different key?</string>
<string name="this_device_holds_no_key_for_s_so_there">This device holds no key for %1$s, so there is nothing to lose. The profile stays on the relays, and you can sign in again any time.</string>
<string name="could_not_sign_out_please_try_again">Could not sign out. Please try again.</string>
<string name="this_will_give_you_write_access_to_the">This will give you write access to the profile.</string>
<string name="torch_will_be_broadcast_what_you_publish_to">Mantra broadcasts what you publish to a distributed set of relays, so it stays decentralised.</string>
<string name="translate_chunk">Translate chunk</string>