Skip to content

feat(links): don't ask again for a trusted website - #1735

Merged
bmc08gt merged 1 commit into
code/cashfrom
feat/trusted-websites
Oct 9, 2026
Merged

bmc08gt merged 1 commit into
code/cashfrom
feat/trusted-websites

Conversation

@bmc08gt

@bmc08gt bmc08gt commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

The "You're Leaving Flipcash" warning had no way to remember a site, so every tap on a link to the same host asked again. This adds a "Don't ask again for " box above Open Website (design node 11230:13376), and a Settings › Privacy › Trusted Websites screen to undo it (node 11230:67653). iOS is building the same thing in code-payments/code-ios-app#1028.

Saving. The box starts unchecked every time. The host is saved only when Open Website is tapped with it checked; Cancel, dismissing, or unticking first saves nothing. Links with no host (mailto:) still warn but aren't offered the box, since the label would read "Don't ask again for mailto".

Matching. The saved host is the normalized ASCII one the warning already shows, so a look-alike domain is stored as its xn-- form. Matching is exact string equality: x.com does not cover mail.x.com. First-party hosts are checked before the trusted list and keep their own handling. classifyLink takes the trusted set as a parameter, so ExternalLinksTest stays pure.

Storage. One list per device in its own Preferences file (trusted-websites) next to app-settings, one key per host holding the date it was added. It's local only and not registered with AuthManager.resetStateForUser, so it survives Log Out and Switch Accounts. AuthManagerTest guards that. The contract (TrustedWebsites, LocalTrustedWebsites) lives in core because shared/appsettings already depends on core; MainActivity provides the implementation.

Settings. A Trusted Websites row sits under Blocked and always shows, with no count, to match iOS. The screen lists hosts newest first with "Added Oct 7"-style subtitles and an immediate Remove. An empty list gets the same title-and-hint layout as Blocked.

Bottom bar. BottomBarMessage gains an optional checkbox (label plus a checked-state callback), drawn between the subtitle and the actions. showInfo takes it as an optional parameter; every existing message is unchanged.

The empty-state hint copy ("Skip the “You're Leaving Flipcash” warning for a website by checking “Don't ask again” when you open its link") isn't in the design and may still change.

The "You're Leaving Flipcash" warning now has a "Don't ask again for
<host>" box above Open Website. It starts unchecked, and the host is saved
only when Open Website is tapped with it checked; Cancel or dismissing
saves nothing. A saved host opens straight away next time.

The host is the normalized ASCII one the warning shows, so a look-alike
domain is saved as its xn-- form. Matching is exact: x.com does not cover
mail.x.com. First-party hosts keep their own handling, and a link with no
host (mailto:) isn't offered the box.

The list lives in its own Preferences file next to app-settings: one list
for the device, never synced, and not registered with resetStateForUser,
so it outlives Log Out and Switch Accounts. Settings > Privacy always
shows a Trusted Websites row under Blocked. The screen lists hosts newest
first with Remove, and an empty list gets the same title-and-hint
treatment as Blocked.

BottomBarMessage gains an optional checkbox, drawn between the subtitle
and the actions; existing messages are unchanged.
@bmc08gt bmc08gt self-assigned this Oct 9, 2026
@github-actions github-actions Bot added type: feature New functionality area: auth Login, session, access keys, identity area: ui Compose UI, theme, components, resources area: notifications Push notifications, in-app messaging labels Oct 9, 2026
@bmc08gt
bmc08gt merged commit d893985 into code/cash Oct 9, 2026
3 checks passed
@bmc08gt
bmc08gt deleted the feat/trusted-websites branch October 9, 2026 16:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: auth Login, session, access keys, identity area: notifications Push notifications, in-app messaging area: ui Compose UI, theme, components, resources type: feature New functionality

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant