Vastavik Learning v1.0.62 - Release Notes
Welcome to Vastavik Learning v1.0.62! This release adds full Clerk authentication (email + OTP, Google & GitHub OAuth), removes the app-wide privacy watermark, kills the false-positive "SCREEN CAPTURE BLOCKED" overlay, fixes the blank Practice tabs after deleting everything, and hardens the login/sign-up error UX — plus a required Android toolchain bump (AGP 8.9.1, Kotlin 2.4.20, compileSdk 36).
What's New and Improved
1. Clerk Authentication — Email/Password + Email OTP + Google & GitHub OAuth
- Opt-in by key: set
CLERK_PUBLISHABLE_KEY=pk_...inlocal.propertiesand the app switches all sign-in/sign-up to Clerk; leave it blank and the existing backend/Firebase auth keeps working untouched (VastavikApplication.ktinitializescom.clerk.api.Clerkonly when the key is present). - Sign-up with email OTP:
SignupScreennow has a verification step —AuthViewModel.signUpWithClerkcreates the Clerk sign-up, sends the code (sendCode), and the form swaps to a 6-digit code field with Verify Email, Resend, and Use a different email controls;verifyClerkOtpcompletes it (verifyCode(code, VerificationType.EMAIL)). Password policy follows Clerk (min 8 chars) when enabled. - Sign-in:
signInWithClerkusessignInWithPassword; aNEEDS_SECOND_FACTOR/NEEDS_CLIENT_TRUSTstatus routes into the same OTP step (sendMfaEmailCode+verifyMfaCode(..., EMAIL_CODE)). The Sign in with Google and Sign in with GitHub buttons go throughClerk.auth.signInWithOAuth(OAuthProvider.GOOGLE/GITHUB)when Clerk is enabled — the SDK'sSSOReceiverActivityhandles theclerk://<appId>.callbackredirect (auto-merged from the Clerk AAR, no manifest change needed). - Backend session bridge: after any Clerk flow,
ClerkSessionBridgeexchanges the Clerk session token (Clerk.auth.getToken()) for this backend's own JWTs via the newPOST /api/v1/auth/clerk(backend verifies the token against Clerk's JWKS + issuer, resolves the email from claims orGET /v1/users/{sub}, then provisions/links the user by email so existing accounts merge). Every existing API call keeps working unchanged. - Session restore:
SplashScreennow accepts a backend JWT or a live Clerk session (AuthViewModel.hasPersistedSession()), re-bridging to backend tokens on cold start;signOut()also revokes the Clerk session. - Errors stay inline: every Clerk failure (
errorMessage) flows into the existingformErrorline under the buttons — never a toast.
2. "SCREEN CAPTURE BLOCKED" False Positives Fixed
SecurityProtectionManagernow reveals the blocked message only when the app is still resumed 250 ms after a focus-loss trigger, and cancels stale blackout jobs the moment focus returns — brief window switches no longer flash the overlay (isBlockedMessageVisible+setActivityResumed+blackoutJobcancellation).FocusLossBlackoutCurtainshows the message only whenshowMessageis set, with clearer copy: "Another app is covering this screen or a screenshot was attempted…". Screenshot detection (Activity.ScreenCaptureCallback, API 34+) and the app-switcher peek trigger still get the message; key-based triggers are unchanged.
3. Practice Tabs — Real Empty States That Survive Deletion
- All four tabs (MCQ, Predict the Output, Coding, PYQ) render an
EmptyState(icon, message, "tap + icon", CTA that opens the AI generate dialog) instead of a blank screen. - Seeding now keys off
VastavikAiDiskCache.hasSaved*(prefs.contains) instead of the in-memory list, so deletions persist across restarts — the tabs no longer resurrect wiped content or show empty white space. - PYQ rows gained a delete button (trash icon →
savePYQs+ toast), mirroring MCQ/Coding/Predict.
4. Watermark & Auth UX Cleanup
- Removed the app-wide
PrivacyWatermarkOverlay, its component file, the "Anti-Leak Forensic Watermark" settings row, and updated the emulator banner/curtain copy that still mentioned it. - Login & Sign Up validate inline (email pattern, required fields, password ≥ 6/8, confirm match) and show all server errors as red text under the primary button — no more floating toasts.
- GitHub sign-in (non-Clerk mode): real browser OAuth flow via
GitHubOAuth.kt(SecureRandom state,vastavik://oauth/githubdeep link,MainActivity.handleOAuthRedirect), with friendly messaging for the backend's 501 whenGITHUB_CLIENT_ID/GITHUB_CLIENT_SECRETaren't set on Render.
5. Toolchain Bump Required by Clerk (AGP 8.9.1 / Kotlin 2.4.20 / compileSdk 36)
- Gradle: AGP
8.7.3 → 8.9.1, Kotlin2.0.20 → 2.4.20, Hilt2.52 → 2.58,compileSdk 35 → 36(targetSdk stays 35, minSdk 24) — Clerk 1.1.9's AARs require API 36. - Migrations:
jvmTargetmoved to thekotlin { compilerOptions { ... } }DSL in both modules;kotlin-metadata-jvm:2.4.20pinned on the kapt classpath (Dagger/Hilt must read Kotlin 2.4 metadata); OkHttp resolves to 5.4.0 (Clerk's line) with a packaging exclude for the duplicateMETA-INF/versions/9/OSGI-INF/MANIFEST.MF. - Verified:
.\gradlew.bat :app:assembleDebugand:app:assembleRelease :companion-codeoss:assembleReleaseboth BUILD SUCCESSFUL (R8 kotlin-metadata warnings are non-fatal); backendpy_compile+ module import pass.
6. Version Bump
- App
versionCode 62/versionName 1.0.62(app/build.gradle.kts:21) and CompanionversionCode 29/versionName 1.0.62(companion-codeoss/build.gradle.kts:15).
Release Assets
| Asset | Description | Size |
|---|---|---|
| vastavikLearning-v1.0.62.apk | Main Vastavik Learning Android app (versionCode 62, versionName 1.0.62, minSdk 24, targetSdk 35) | ~61.6 MB |
| vastavik-codeoss-extension.apk | CodeOSS Companion Extension Pack with Monaco/VS Code Web and Ubuntu Terminal (versionCode 29, versionName 1.0.62) | ~13.4 MB |
Upgrade Notes
- Install
vastavikLearning-v1.0.62.apkover your existing build — user data, login session, anduser_profileprefs are preserved. The companion APK installs side-by-side. - To enable Clerk: add
CLERK_PUBLISHABLE_KEY=pk_...to the app'slocal.properties(placeholder already added; blank = built-in auth stays active), enable Google/GitHub connections in the Clerk Dashboard, then on Render setCLERK_PUBLISHABLE_KEYandCLERK_SECRET_KEYand redeployvastavikLearning-backend-appsoPOST /api/v1/auth/clerkcan issue backend JWTs. - GitHub sign-in without Clerk: set
GITHUB_CLIENT_ID/GITHUB_CLIENT_SECRETon Render (the endpoint currently returns a friendly 501 until then). - New backend dependencies already in
requirements.txt(pyjwt>=2.8.0) — no Python package changes required.
Built with love by the Vastavik Learning Team