Skip to content

v1.0.62 - Clerk Auth with Email OTP & OAuth, Watermark Removal & Capture Overlay Fix

Latest

Choose a tag to compare

@parthasdey2304 parthasdey2304 released this 27 Sep 13:32
39d9575

Vastavik Learning v1.0.62 - Release Notes

Welcome to Vastavik Learning v1.0.62! This release adds full Clerk authentication (email + OTP, Google & GitHub OAuth), removes the app-wide privacy watermark, kills the false-positive "SCREEN CAPTURE BLOCKED" overlay, fixes the blank Practice tabs after deleting everything, and hardens the login/sign-up error UX — plus a required Android toolchain bump (AGP 8.9.1, Kotlin 2.4.20, compileSdk 36).


What's New and Improved

1. Clerk Authentication — Email/Password + Email OTP + Google & GitHub OAuth

  • Opt-in by key: set CLERK_PUBLISHABLE_KEY=pk_... in local.properties and the app switches all sign-in/sign-up to Clerk; leave it blank and the existing backend/Firebase auth keeps working untouched (VastavikApplication.kt initializes com.clerk.api.Clerk only when the key is present).
  • Sign-up with email OTP: SignupScreen now has a verification step — AuthViewModel.signUpWithClerk creates the Clerk sign-up, sends the code (sendCode), and the form swaps to a 6-digit code field with Verify Email, Resend, and Use a different email controls; verifyClerkOtp completes it (verifyCode(code, VerificationType.EMAIL)). Password policy follows Clerk (min 8 chars) when enabled.
  • Sign-in: signInWithClerk uses signInWithPassword; a NEEDS_SECOND_FACTOR/NEEDS_CLIENT_TRUST status routes into the same OTP step (sendMfaEmailCode + verifyMfaCode(..., EMAIL_CODE)). The Sign in with Google and Sign in with GitHub buttons go through Clerk.auth.signInWithOAuth(OAuthProvider.GOOGLE/GITHUB) when Clerk is enabled — the SDK's SSOReceiverActivity handles the clerk://<appId>.callback redirect (auto-merged from the Clerk AAR, no manifest change needed).
  • Backend session bridge: after any Clerk flow, ClerkSessionBridge exchanges the Clerk session token (Clerk.auth.getToken()) for this backend's own JWTs via the new POST /api/v1/auth/clerk (backend verifies the token against Clerk's JWKS + issuer, resolves the email from claims or GET /v1/users/{sub}, then provisions/links the user by email so existing accounts merge). Every existing API call keeps working unchanged.
  • Session restore: SplashScreen now accepts a backend JWT or a live Clerk session (AuthViewModel.hasPersistedSession()), re-bridging to backend tokens on cold start; signOut() also revokes the Clerk session.
  • Errors stay inline: every Clerk failure (errorMessage) flows into the existing formError line under the buttons — never a toast.

2. "SCREEN CAPTURE BLOCKED" False Positives Fixed

  • SecurityProtectionManager now reveals the blocked message only when the app is still resumed 250 ms after a focus-loss trigger, and cancels stale blackout jobs the moment focus returns — brief window switches no longer flash the overlay (isBlockedMessageVisible + setActivityResumed + blackoutJob cancellation).
  • FocusLossBlackoutCurtain shows the message only when showMessage is set, with clearer copy: "Another app is covering this screen or a screenshot was attempted…". Screenshot detection (Activity.ScreenCaptureCallback, API 34+) and the app-switcher peek trigger still get the message; key-based triggers are unchanged.

3. Practice Tabs — Real Empty States That Survive Deletion

  • All four tabs (MCQ, Predict the Output, Coding, PYQ) render an EmptyState (icon, message, "tap + icon", CTA that opens the AI generate dialog) instead of a blank screen.
  • Seeding now keys off VastavikAiDiskCache.hasSaved* (prefs.contains) instead of the in-memory list, so deletions persist across restarts — the tabs no longer resurrect wiped content or show empty white space.
  • PYQ rows gained a delete button (trash icon → savePYQs + toast), mirroring MCQ/Coding/Predict.

4. Watermark & Auth UX Cleanup

  • Removed the app-wide PrivacyWatermarkOverlay, its component file, the "Anti-Leak Forensic Watermark" settings row, and updated the emulator banner/curtain copy that still mentioned it.
  • Login & Sign Up validate inline (email pattern, required fields, password ≥ 6/8, confirm match) and show all server errors as red text under the primary button — no more floating toasts.
  • GitHub sign-in (non-Clerk mode): real browser OAuth flow via GitHubOAuth.kt (SecureRandom state, vastavik://oauth/github deep link, MainActivity.handleOAuthRedirect), with friendly messaging for the backend's 501 when GITHUB_CLIENT_ID/GITHUB_CLIENT_SECRET aren't set on Render.

5. Toolchain Bump Required by Clerk (AGP 8.9.1 / Kotlin 2.4.20 / compileSdk 36)

  • Gradle: AGP 8.7.3 → 8.9.1, Kotlin 2.0.20 → 2.4.20, Hilt 2.52 → 2.58, compileSdk 35 → 36 (targetSdk stays 35, minSdk 24) — Clerk 1.1.9's AARs require API 36.
  • Migrations: jvmTarget moved to the kotlin { compilerOptions { ... } } DSL in both modules; kotlin-metadata-jvm:2.4.20 pinned on the kapt classpath (Dagger/Hilt must read Kotlin 2.4 metadata); OkHttp resolves to 5.4.0 (Clerk's line) with a packaging exclude for the duplicate META-INF/versions/9/OSGI-INF/MANIFEST.MF.
  • Verified: .\gradlew.bat :app:assembleDebug and :app:assembleRelease :companion-codeoss:assembleRelease both BUILD SUCCESSFUL (R8 kotlin-metadata warnings are non-fatal); backend py_compile + module import pass.

6. Version Bump

  • App versionCode 62 / versionName 1.0.62 (app/build.gradle.kts:21) and Companion versionCode 29 / versionName 1.0.62 (companion-codeoss/build.gradle.kts:15).

Release Assets

Asset Description Size
vastavikLearning-v1.0.62.apk Main Vastavik Learning Android app (versionCode 62, versionName 1.0.62, minSdk 24, targetSdk 35) ~61.6 MB
vastavik-codeoss-extension.apk CodeOSS Companion Extension Pack with Monaco/VS Code Web and Ubuntu Terminal (versionCode 29, versionName 1.0.62) ~13.4 MB

Upgrade Notes

  • Install vastavikLearning-v1.0.62.apk over your existing build — user data, login session, and user_profile prefs are preserved. The companion APK installs side-by-side.
  • To enable Clerk: add CLERK_PUBLISHABLE_KEY=pk_... to the app's local.properties (placeholder already added; blank = built-in auth stays active), enable Google/GitHub connections in the Clerk Dashboard, then on Render set CLERK_PUBLISHABLE_KEY and CLERK_SECRET_KEY and redeploy vastavikLearning-backend-app so POST /api/v1/auth/clerk can issue backend JWTs.
  • GitHub sign-in without Clerk: set GITHUB_CLIENT_ID/GITHUB_CLIENT_SECRET on Render (the endpoint currently returns a friendly 501 until then).
  • New backend dependencies already in requirements.txt (pyjwt>=2.8.0) — no Python package changes required.

Built with love by the Vastavik Learning Team