Merge PR #37: lock screen PIN (3urobeat), adapted

The contributor's feature -- a PIN asked before the screen unlocks, on
boot, and when the magnet cover opens, stored as a salted SHA-256 -- on
top of this branch, with:

- ui-core/ScreenLock.h: set / check / isSet and the tries limit, shared by
  L1 and L2. isSet looks at every byte (the PR tested only the first, so one
  PIN in 256 silently disabled the lock). 5 misses pause entry for 30 s.
- NodePrefs: the fields at the tail after quiet hours, sentinel 0xC0DE0031,
  sizeof 2880; an older file's bytes there are cleared. A sentinel bump no
  longer resets display_brightness_pct from a file that already has it.
- DataStore: no AGPL header (the project is MIT), no whitespace churn.
- Keyboard: the number pad is a widget flag (pin_mode) with a prompt in the
  preview ("New PIN", "Again", "PIN"), not keyboard_type = 2 written into the
  prefs and restored after.
- L1 Settings: "Lock PIN" right after the schema's "Lock screen" row, typed
  twice, at least 4 characters, saved at once (a power-off right after
  setting it kept no PIN). Home is told about a boot-time lock once it
  exists (also fixes booting with the cover closed).
- L2: the screen PIN moves from plain text in NVS to the same hash in
  NodePrefs; the old one is migrated on first boot and removed. The pad
  unlocks as soon as the hash matches from 4 digits on.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Jakub
2026-09-29 00:06:01 +02:00
co-authored by Claude Opus 5.5
13 changed files with 540 additions and 71 deletions
@@ -63,3 +63,23 @@ Fully autonomous, independent of Auto-lock and of any key combo:
- **Magnet near (cover closed)** — locks and blanks the display immediately, no wake grace.
- **Magnet away (cover opened)** — unlocks and wakes the display right away.
---
### Lock PIN
**Settings › Display › Lock PIN** asks for a PIN before the screen unlocks,
also right after power-up, and when the magnet cover opens.
- Enter on the row opens a number pad: type the PIN (at least 4 characters),
confirm with ✓, then type it again. The pad's keyboard key switches to the
normal keyboard for a PIN with letters.
- Unlocking (Back + Enter three times, or opening the cover) shows the pad
with the input masked. A wrong PIN says how many tries are left; after 5 in
a row, entry pauses for 30 seconds.
- Enter on the row again removes the PIN.
The PIN is kept as a salted SHA-256 hash, never as the PIN itself. It locks
the screen only: messages still arrive and the phone app still connects.
On the Wio Tracker L2 it's **Settings › Display & power › Screen PIN**
(digits only).