- Gate every layer behind AppLockView when the lock is enabled and
lock on launch and on backgrounding; the passcode lives only in the
Keychain (AppLockVault) and the enable state defaults to off.
- Add the lock section to Settings: enable/setup, change passcode and
disable all require the current passcode via a shared passcode
sheet; Face ID / Touch ID unlock prompts automatically and can be
toggled with passcode confirmation.
- Add NSFaceIDUsageDescription to both app targets, cover the passcode
policy with tests, guard the feature in verify.sh and document it in
SECURITY.md.
- Drive chat list, timeline and forward picker from SwiftData @Query
instead of AppModel's in-memory arrays; inject the per-account
ModelContext from RootView with an in-memory fallback.
- Physically delete locally deleted messages (context.delete) and
purge rows marked deleted by older builds on store open, so @Query
views never resurrect them.
- Delete the legacy JSON snapshot only after a successful import save
and restore the completeUntilFirstUserAuthentication data protection
attribute on the store file.
- Mirror the old ChatArchive tolerant decoding in LegacyArchiveImporter
so snapshots from older schema versions (missing reactions,
isGroupMessage, roster fields) still import.
- Cover the new behaviour in ArchiveStoreTests and guard it with new
verify.sh invariants; update AGENTS.md, ARCHITECTURE.md and
SECURITY.md.