- Add BackupTestFlow.tsx: after downloading the Keycase, the step becomes an
explicit "Test your backup" view — a large dropzone for the downloaded
file, then a password prompt that succeeds the instant the password is
typed completely, ending in a spring-in check badge with an emoji burst
celebration (skipped under reduced motion)
- Verification is instant and KDF-free: the dropped file's bytes are
compared to the committed ncryptsec blob and the typed password to the
in-memory passphrase, so no key material beyond what the creator already
held enters the component
- Wrong files get inline errors (Keycase-but-different vs not-a-Keycase);
full-length wrong passwords get a mismatch hint; a "Re-download backup"
button re-opens the native save dialog and "Use a different file" returns
to the dropzone
- EncryptedBackupCreator.tsx: swap the masked-ncryptsec result view
(NsecMaskedDisplay + "Save a copy…") for BackupTestFlow
- DownloadKeyStep.tsx: header/subtitle now conditional — "Backup your key
with a password" while creating, "Test your backup" once created; remove
the bracketed shell-box visual, the keep-this-file-private hints, and the
"back up anytime in Settings" footer note
- BackupStep.tsx / MachineOnboardingFlow.tsx: chooser footer "Next" now
always leads into the download step (skip lives there as "Skip for now")
- Update onboarding-backup.spec.ts happy path to drive the new flow
(wrong file, right file, wrong password, success, Next) with screenshots;
align docked-CTA spec and passThroughBackupStep helper with the new
navigation; allowlist BackupTestFlow.tsx in the ncryptsec source scan
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
Co-authored-by: Taylor Ho <taylorkmho@gmail.com>
Signed-off-by: Taylor Ho <taylorkmho@gmail.com>