feat(gui): Lock while away — lock-on-disconnect + auto-unlock toggles - #188
Merged
Merged
Conversation
Adds a "Lock while away (experimental)" section to the controller's Display tab for the two #181 settings, LOCK_ON_DISCONNECT and AUTO_UNLOCK. Both only run inside the headless session watcher, so the toggles are disabled under "Keep local screen on", and normalize() clears them when no headless mode is active — the same parent-resets-child rule the virtual display and UDP tunnel already follow — so a stale ON can't silently re-arm when a mode is picked later. The two are exposed as a pair rather than lock alone: turning the lock on without auto-unlock shows an orange warning, because a remote-only Mac can't be reached once it locks (reproduced on a real remote mini during #181's live test). The caption states the two things a user can't see from the toggle: the lock is only real when "Require password after screen saver begins" is Immediately, and auto-unlock leaves the physical Mac usable by anyone at it.
clintcan
added a commit
that referenced
this pull request
Sep 27, 2026
A feature release for headless, remote-only Macs plus a --shield-primary fix. Everything new is opt-in; the default runtime path is unchanged. - #181 (@antonmos): --lock-on-disconnect locks the Mac ~25 s after the last client leaves; --auto-unlock types the PAM-validated password into the lock screen on reconnect, with a shared per-lock budget of 2 real submissions. Both experimental; live-verified on a Mac mini. - #188: GUI controller toggles for both (Display tab, "Lock while away"). - #187 (@antonmos): --shield-primary engages on a lid-closed MacBook instead of erroring, which had silently disabled the shield, restore-windows and the connect-time window gather. - Repo hardening: CODEOWNERS + code-owner review, fork-PR CI approval for all outside collaborators, enforced SHA pinning. Known issue: a reconnect ~12-22 s after leaving can be locked mid-handshake; self-corrects with --auto-unlock, strands a remote user without it. Pre-tag gates: fmt clean (stable + nightly), clippy -D warnings clean, 212 tests passing. Docs: release-history, README status, CLAUDE.md status.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a Lock while away (experimental) section to the menu-bar controller's Display tab, exposing the two settings from #181:
LOCK_ON_DISCONNECTandAUTO_UNLOCK.Behaviour
normalize()clears both when no headless mode is active, following the existing parent-resets-child rule (virtual display, UDP tunnel), so a stale ON can't silently re-arm when a mode is picked later.primaryModealready honours a legacyCAPTURE_PRIMARY=1.docs/features.mdupdated to mention the section.Verification
swift build -c release --product macrdptrayclean.src/main.rson("LOCK_ON_DISCONNECT")/on("AUTO_UNLOCK")) andpackaging/config.env.example.