Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
67 commits
Select commit Hold shift + click to select a range
2fdd4ca
feat(mobile): scaffold Expo app
mergemaven11 Aug 27, 2026
0295312
feat(mobile): add iOS and Android app config
mergemaven11 Aug 27, 2026
17795df
feat(mobile): add BragStack theme tokens
mergemaven11 Aug 27, 2026
0c8c2cb
feat(mobile): add secure session storage
mergemaven11 Aug 27, 2026
05c3875
feat(mobile): add authenticated API client
mergemaven11 Aug 27, 2026
77edaa1
feat(mobile): add branded tab navigation and starter screens
mergemaven11 Aug 27, 2026
034de28
docs(mobile): add local development guide
mergemaven11 Aug 27, 2026
bd99059
docs: add mobile roadmap
mergemaven11 Aug 27, 2026
099d9ed
chore(mobile): align scaffold with current Expo SDK 57
mergemaven11 Aug 27, 2026
e350fb8
docs: add changelog with mobile foundation entry
mergemaven11 Aug 27, 2026
73d6ee6
feat(mobile): polish product preview and quick capture
mergemaven11 Aug 27, 2026
3fbff92
build(mobile): add store build profiles
mergemaven11 Aug 27, 2026
1ecca29
docs(mobile): add API environment example
mergemaven11 Aug 27, 2026
de7880a
docs: record mobile preview polish
mergemaven11 Aug 27, 2026
dd50458
merge main into mobile foundation
mergemaven11 Aug 27, 2026
aa73d40
fix: align mobile theme with official BragStack brand guide
mergemaven11 Aug 27, 2026
97133da
feat: add official BragStack vector brandmark to mobile
mergemaven11 Aug 27, 2026
03d2176
feat: wire mobile auth to BragStack backend
mergemaven11 Aug 27, 2026
eab9451
chore: add vector logo support for mobile
mergemaven11 Aug 27, 2026
00523f6
feat: add official branding and real mobile authentication
mergemaven11 Aug 27, 2026
9210cc7
docs: record official mobile branding and auth
mergemaven11 Aug 27, 2026
371f59c
docs: document mobile auth and canonical branding
mergemaven11 Aug 27, 2026
6bca126
chore: include canonical BragStack brandmark asset in mobile
mergemaven11 Aug 27, 2026
3b59b4a
chore: sync canonical changelog policy from main
mergemaven11 Aug 27, 2026
ca08c6f
merge: sync latest main into mobile foundation
mergemaven11 Aug 27, 2026
287fdba
docs: add mobile architecture and release guide
mergemaven11 Aug 27, 2026
1349caf
docs: add customer-facing mobile guide source
mergemaven11 Aug 27, 2026
97f3426
docs: refresh mobile roadmap and documentation gates
mergemaven11 Aug 27, 2026
e00650f
docs: expand mobile readme with customer and release docs
mergemaven11 Aug 27, 2026
4287d18
test(mobile): add Jest coverage and Mobile CI
mergemaven11 Aug 27, 2026
613131d
test(mobile): cover authenticated API client
mergemaven11 Aug 27, 2026
d64be5c
docs(mobile): add Codespaces and device testing checklist
mergemaven11 Aug 27, 2026
8254ec9
Merge main into feature/mobile-foundation
mergemaven11 Aug 27, 2026
423a2c2
fix: align React Native test dependencies for Expo 57
mergemaven11 Aug 27, 2026
69d21ad
fix(mobile): align Jest with Expo SDK 57
mergemaven11 Aug 27, 2026
07a7534
test: fix Jest axios mock hoisting
mergemaven11 Aug 27, 2026
281f3a4
test(mobile): fix API interceptor mock isolation
mergemaven11 Aug 27, 2026
453af3b
fix: add expo doctor dev dependency
mergemaven11 Aug 27, 2026
b935ea0
fix: align mobile dependencies with Expo SDK 57
mergemaven11 Aug 27, 2026
8b9de80
fix: wrap mobile app in SafeAreaProvider
mergemaven11 Aug 27, 2026
c82ac88
fix: align mobile colors with BragStack brand palette
mergemaven11 Aug 27, 2026
16a9881
fix: restore BragStack mobile auth branding and social sign-in
mergemaven11 Aug 27, 2026
6adceda
fix: resolve mobile API URL in Codespaces
mergemaven11 Aug 27, 2026
368bfbb
feat: modernize mobile sign-in experience
mergemaven11 Aug 27, 2026
aaabf7f
fix: make mobile sign-in responsive and scroll-safe
mergemaven11 Aug 27, 2026
1d7c506
fix: make mobile layouts responsive across phones and tablets
mergemaven11 Aug 27, 2026
1564bcf
fix: make mobile root fill all device viewports
mergemaven11 Aug 27, 2026
74e95d7
fix: make mobile layout truly responsive across device sizes
mergemaven11 Aug 27, 2026
2000e77
test: align mobile theme expectations with current brand palette
mergemaven11 Aug 27, 2026
00f0d7c
fix: initialize mobile web viewport before React Native
mergemaven11 Aug 27, 2026
0965af3
fix: use custom mobile entrypoint for responsive web viewport
mergemaven11 Aug 27, 2026
b32d8d4
feat(mobile): complete password auth flows
mergemaven11 Aug 27, 2026
ff61da6
feat(mobile): wire live proof and profile APIs
mergemaven11 Aug 27, 2026
ecc2a29
feat(mobile): rebuild responsive auth and live product screens
mergemaven11 Aug 27, 2026
0bb11a7
test(mobile): cover complete auth lifecycle
mergemaven11 Aug 27, 2026
74d67d5
test(mobile): cover live product data flows
mergemaven11 Aug 27, 2026
281cd7e
chore(mobile): configure production API for release builds
mergemaven11 Aug 27, 2026
8722326
docs(mobile): document live app and store blockers
mergemaven11 Aug 27, 2026
81ffe00
feat(mobile): enable phone and tablet rotation
mergemaven11 Aug 28, 2026
fb81bb6
docs(mobile): add Codespaces phone and tablet QA matrix
mergemaven11 Aug 28, 2026
dbaa97b
feat(mobile): add responsive landscape and tablet layouts
mergemaven11 Aug 28, 2026
a8c7872
chore(mobile): add Codespaces preview command
mergemaven11 Aug 28, 2026
5091239
chore(mobile): ignore Expo local state
mergemaven11 Aug 28, 2026
0ffb618
fix(mobile): use api.usebragstack.com in Codespaces
mergemaven11 Aug 28, 2026
e95cbf8
fix(mobile): point EAS builds at api.usebragstack.com
mergemaven11 Aug 28, 2026
19055fe
docs(mobile): use canonical BragStack API hostname
mergemaven11 Aug 28, 2026
fde99f9
docs(mobile): correct Codespaces production API hostname
mergemaven11 Aug 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
36 changes: 36 additions & 0 deletions .github/workflows/mobile-ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
name: Mobile CI

on:
pull_request:
paths:
- 'mobile/**'
- '.github/workflows/mobile-ci.yml'
push:
branches: [main]
paths:
- 'mobile/**'
- '.github/workflows/mobile-ci.yml'

permissions:
contents: read

jobs:
mobile:
runs-on: ubuntu-latest
timeout-minutes: 15
defaults:
run:
working-directory: mobile
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '22.13'
- name: Install dependencies
run: npm install --no-audit --no-fund
- name: Expo dependency and config health
run: npm run doctor
- name: Unit tests
run: npm run test:ci
- name: Export bundle smoke test
run: npx expo export --platform web --output-dir dist-ci
4 changes: 4 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,10 @@ node_modules/
dist/
npm-debug.log*

# Expo local state
.expo/
mobile/.expo/

# Logs
logs
*.log
Expand Down
100 changes: 100 additions & 0 deletions docs/MOBILE_APP.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,100 @@
# BragStack Mobile App

BragStack Mobile is the native iOS and Android client for the BragStack career-evidence platform. It is under active pre-release development and is tracked by issue #200.

## Product goal

Mobile should make it easier to capture meaningful work while the details are still fresh without creating a separate account system, separate career history, or weaker privacy model.

The mobile client reuses the existing FastAPI backend, authentication model, Impact Receipt semantics, profile model, and private-by-default trust principles.

## Current foundation

- React Native / Expo cross-platform application under `mobile/`
- iOS bundle identifier and Android package: `com.bragstack.app`
- canonical BragStack vector brandmark from `frontend/public/brandmark.svg`
- authenticated-app palette from the BragStack Brand Guide
- Home, Proof, Add, Profile, and Settings navigation
- real password sign-in against `POST /auth/login`
- verified-email enforcement inherited from the backend
- encrypted access-token storage with Expo SecureStore
- session restore through `GET /auth/me`
- sign out that clears the local mobile token
- shared authenticated Axios client
- interactive private-by-default Impact Receipt preview
- EAS preview and production build profiles
- no unnecessary native permissions in the foundation

## Authentication model

Mobile does not maintain a separate identity system.

1. The user signs in using the existing BragStack account.
2. `/auth/login` returns the normal BragStack bearer token and serialized user.
3. The token is stored through Expo SecureStore rather than plaintext application storage.
4. On app launch, the client attempts `/auth/me` to restore the session.
5. Invalid or expired sessions are cleared and the user returns to sign-in.
6. Sign out removes the stored token.

Registration, email verification, password reset, recovery deep links, and account-deletion UX must be completed and tested before store release.

## Brand system

The mobile product follows the authenticated BragStack app context rather than using the marketing palette as its primary UI.

- app background: `#090909`
- primary text: `#F7F4EE`
- secondary text: `#AAA39A`
- primary action / accent: `#FFB184`
- canonical logo/brandmark retains the approved blue-purple-cyan gradient identity

The mobile app must not substitute a generic lettermark or create a separate mobile-only visual identity.

## Data and privacy model

Mobile should remain another client for the same BragStack record.

- private workplace evidence stays private by default
- sharing is intentional and separate from capture
- missing results, metrics, evidence, or confirmation are not invented
- evidence permissions are requested only when a user initiates a feature that needs them
- auth tokens and sensitive proof must not be written to logs, URLs, analytics payloads, or crash breadcrumbs
- public profile behavior must preserve the same publication boundaries as web

## Store-readiness gate

Before the PR or later release work can be called store-ready, BragStack must complete:

- live accomplishment and Impact Receipt reads/writes
- registration, verification, reset, recovery, and deletion flows
- loading, empty, retry, offline, and expired-session states
- accessibility and dynamic-text validation
- device/OS compatibility testing
- production API configuration
- app icon, splash, screenshots, and store metadata
- Apple privacy disclosures and required-reason review
- Google Play Data safety disclosure
- Terms, Privacy, support, and account-deletion links
- signing and release credentials
- TestFlight and Play internal testing
- mobile CI, dependency/security validation, and production build verification
- security review of token lifecycle, deep links, logs, evidence handling, and third-party SDKs

## Release truth

The mobile app is **pre-release** until production listings are actually live. Documentation, marketing, support, and investor materials should distinguish between:

- implemented mobile foundation
- functionality still under development
- internal/beta availability
- public App Store / Google Play availability

Do not describe the app as publicly downloadable before the applicable production listing is live.

## Related documentation

- `mobile/README.md` — local development and current implementation status
- `docs/ROADMAP.md` — phased mobile delivery plan
- `docs/MOBILE_CUSTOMER_GUIDE.md` — customer-facing mobile copy source
- issue #200 — mobile program epic
- PR #201 — initial mobile foundation
63 changes: 63 additions & 0 deletions docs/MOBILE_CUSTOMER_GUIDE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
# BragStack Mobile — Customer Guide

> **Status: pre-release.** BragStack Mobile is in active development for iOS and Android and is not yet publicly available in the Apple App Store or Google Play.

## What BragStack Mobile is for

BragStack Mobile is designed to help you capture meaningful work while the details are still fresh, then use the same professional proof across BragStack on web and mobile.

The first public release is intended to support:

- signing in with an existing BragStack account
- restoring a secure signed-in session on your device
- viewing a mobile dashboard and proof library
- quickly capturing a new accomplishment
- working with Impact Receipts using the same trust model as the web product
- accessing profile and account settings
- keeping private workplace evidence private unless you intentionally share it

## What is already built into the mobile foundation

The current mobile foundation includes the native iOS/Android app structure, official BragStack branding, the authenticated BragStack theme, real account sign-in, encrypted on-device session storage, session restore, sign out, mobile navigation, and internal preview/release build configuration.

Some screens still use preview data while live mobile data flows are completed.

## What is still being completed before launch

Before public release, BragStack is completing and validating:

- live accomplishment and Impact Receipt persistence across mobile screens
- registration, email verification, password reset, and recovery flows
- loading, retry, offline, expired-session, and API error states
- accessibility and dynamic-text behavior
- device and operating-system compatibility
- account-deletion behavior and privacy/support links
- Apple privacy disclosures and Google Play Data safety disclosures
- production signing, TestFlight, Google Play internal testing, store assets, and final security/release review

## Privacy and permissions

BragStack Mobile follows the same private-first approach as the web product. Sensitive workplace evidence should not become public automatically.

The app should ask for a device permission only when a feature genuinely needs it and, where possible, only after you start that action. A missing result, metric, or piece of evidence stays missing; BragStack should not invent professional outcomes to make a record look more complete.

## Your account and data

BragStack Mobile is being built to use the same BragStack account and backend as the web product rather than creating a separate mobile-only account system.

At launch, supported mobile data should sync through the same BragStack record so you can move between devices without maintaining two separate career histories.

## Support

During pre-release testing, include the following when reporting a mobile problem when available:

- device type
- operating-system version
- BragStack app/build version
- the exact non-sensitive error message or behavior

Never send BragStack passwords, access tokens, confidential employer evidence, or full payment information to support.

## Store availability

Installation links and supported OS versions will be added only after BragStack has completed internal testing and the production listings are live.
88 changes: 88 additions & 0 deletions docs/ROADMAP.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,88 @@
# BragStack Roadmap

## Mobile initiative — iOS + Android

BragStack Mobile is an active pre-release initiative tracked by issue #200. It is intended to extend the same BragStack account, proof record, trust model, and privacy defaults to a native cross-platform client rather than create a separate mobile product.

### Phase 1: Foundation — substantially complete
- Expo / React Native application scaffold
- canonical BragStack brandmark
- authenticated-app theme tokens from the BragStack Brand Guide
- navigation shell for Home, Proof, Add, Profile, and Settings
- real sign-in against the existing `/auth/login` endpoint
- verified-email behavior inherited from the backend
- secure on-device token storage with Expo SecureStore
- session restore through `/auth/me`
- sign out that clears the local mobile session
- authenticated API client configuration
- EAS preview / production build profiles
- store-safe default permission posture
- mobile engineering and customer documentation foundation

### Phase 2: Core product parity — next
- Dashboard backed by live API data
- Accomplishments / Impact Receipts list and detail views backed by live data
- Quick-add accomplishment persistence
- Edit and delete flows with confirmation
- Registration and email verification UX
- Password reset / recovery deep-link flow
- Profile editing and public-profile controls
- Loading, empty, expired-session, offline, retry, and API error states
- Automated tests for auth/session/data flows

### Phase 3: Mobile-native value
- Camera/file evidence capture with explicit privacy controls
- Native share sheet for public profile and selected proof
- Deep links into public profiles and selected mobile screens
- Optional biometric re-entry protection where appropriate
- Carefully scoped, opt-in notifications only when they provide clear user value
- Mobile analytics focused on activation/friction without sending sensitive proof content

### Phase 4: Store readiness
- Accessibility and dynamic-text review
- App icon, splash screen, screenshots, and store copy
- Apple privacy disclosures / required-reason review
- Google Play Data safety disclosure
- Account deletion flow validation
- Terms, Privacy Policy, and support links
- Production API configuration
- iOS signing / TestFlight
- Android signing / Play internal testing
- Crash reporting decision, implementation, and disclosure if adopted
- Device / OS compatibility matrix
- Third-party SDK and mobile dependency review
- Mobile CI and production-build verification

### Phase 5: Release and hardening
- Beta feedback pass
- Performance and crash-free-session targets
- Security review of token lifecycle, deep links, logs, analytics, and evidence handling
- App Store and Google Play production submission
- Store-review issue handling
- Support playbooks and customer-facing known limitations
- Post-launch crash/auth/API/error monitoring

## Mobile success criteria
1. Reduce time from a real-world win to a useful BragStack record.
2. Preserve reliable session behavior without weakening account security.
3. Keep private workplace evidence private by default.
4. Make web ↔ mobile movement feel like one BragStack account and record.
5. Drive useful repeat capture/review behavior rather than notification spam.
6. Ship only when store disclosures and customer documentation match actual production behavior.

## Mobile product principles
1. Keep private workplace evidence private by default.
2. Reuse BragStack's existing backend and trust model instead of duplicating business logic in the client.
3. Ask for device permissions only at the moment a feature genuinely needs them.
4. Keep core accomplishment capture fast enough to use immediately after a win.
5. Preserve user control over what becomes public, exported, or shared.
6. Never invent missing professional results, evidence, verification, or metrics.
7. Distinguish pre-release capability from publicly shipped store availability.

## Documentation
- `docs/MOBILE_APP.md` — architecture, auth, brand, privacy, and release gates
- `docs/MOBILE_CUSTOMER_GUIDE.md` — source for customer-facing mobile guidance
- `mobile/README.md` — local setup and implementation status

Tracking epic: #200
Foundation PR: #201
4 changes: 4 additions & 0 deletions mobile/.env.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
# BragStack API reachable by the simulator/emulator/device.
# Android emulator commonly uses http://10.0.2.2:8000 for a host-local API.
# Physical devices need your computer's LAN address or a deployed HTTPS API.
EXPO_PUBLIC_API_URL=http://localhost:8000
Loading
Loading