Skip to content

feat(gui): Lock while away — lock-on-disconnect + auto-unlock toggles - #188

Merged
clintcan merged 1 commit into
mainfrom
feat/gui-lock-on-disconnect
Sep 27, 2026
Merged

clintcan merged 1 commit into
mainfrom
feat/gui-lock-on-disconnect

Conversation

@clintcan

Copy link
Copy Markdown
Owner

Adds a Lock while away (experimental) section to the menu-bar controller's Display tab, exposing the two settings from #181: LOCK_ON_DISCONNECT and AUTO_UNLOCK.

Behaviour

  • Disabled under "Keep local screen on", with a note that they need a Detach/Blank mode. Both run only inside the headless session watcher, so the server ignores them without one.
  • normalize() clears both when no headless mode is active, following the existing parent-resets-child rule (virtual display, UDP tunnel), so a stale ON can't silently re-arm when a mode is picked later. primaryMode already honours a legacy CAPTURE_PRIMARY=1.
  • Exposed as a pair. Lock on without auto-unlock shows an orange warning: a remote-only Mac can't be reached once it locks — reproduced on a real remote Mac mini during feat(session): --lock-on-disconnect + always-on auto-unlock on reconnect #181's live test.
  • The caption states what the toggles can't show: the lock is only real when Require password after screen saver begins is Immediately, and auto-unlock leaves the physical Mac usable by anyone at it.

docs/features.md updated to mention the section.

Verification

  • swift build -c release --product macrdptray clean.
  • Config key names match the server's bridge (src/main.rs on("LOCK_ON_DISCONNECT") / on("AUTO_UNLOCK")) and packaging/config.env.example.
  • Installed locally and checked visually: greyed out under "Keep local screen on", enabled under a Blank mode, warning shown for lock-without-unlock, both cleared on switching back.

Adds a "Lock while away (experimental)" section to the controller's Display
tab for the two #181 settings, LOCK_ON_DISCONNECT and AUTO_UNLOCK.

Both only run inside the headless session watcher, so the toggles are
disabled under "Keep local screen on", and normalize() clears them when no
headless mode is active — the same parent-resets-child rule the virtual
display and UDP tunnel already follow — so a stale ON can't silently re-arm
when a mode is picked later.

The two are exposed as a pair rather than lock alone: turning the lock on
without auto-unlock shows an orange warning, because a remote-only Mac can't
be reached once it locks (reproduced on a real remote mini during #181's
live test). The caption states the two things a user can't see from the
toggle: the lock is only real when "Require password after screen saver
begins" is Immediately, and auto-unlock leaves the physical Mac usable by
anyone at it.
@clintcan
clintcan merged commit 3fe7566 into main Sep 27, 2026
3 checks passed
clintcan added a commit that referenced this pull request Sep 27, 2026
A feature release for headless, remote-only Macs plus a --shield-primary
fix. Everything new is opt-in; the default runtime path is unchanged.

- #181 (@antonmos): --lock-on-disconnect locks the Mac ~25 s after the last
  client leaves; --auto-unlock types the PAM-validated password into the lock
  screen on reconnect, with a shared per-lock budget of 2 real submissions.
  Both experimental; live-verified on a Mac mini.
- #188: GUI controller toggles for both (Display tab, "Lock while away").
- #187 (@antonmos): --shield-primary engages on a lid-closed MacBook instead
  of erroring, which had silently disabled the shield, restore-windows and
  the connect-time window gather.
- Repo hardening: CODEOWNERS + code-owner review, fork-PR CI approval for all
  outside collaborators, enforced SHA pinning.

Known issue: a reconnect ~12-22 s after leaving can be locked mid-handshake;
self-corrects with --auto-unlock, strands a remote user without it.

Pre-tag gates: fmt clean (stable + nightly), clippy -D warnings clean,
212 tests passing. Docs: release-history, README status, CLAUDE.md status.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant