# Parental Lock Issue #285. A PIN-protected lock for individual categories: Xtream categories, Stalker genres and M3U `group-title`s. While the lock is active, everything in a locked category is withheld from the app; entering the PIN shows it again until the app locks itself. This document is the contract. Phase 1 (this document's scope) covers the portals' own surfaces; the aggregate surfaces listed under "Not yet covered" follow in a second PR. ## Product rules - Off by default. Enabling asks for a new PIN (4–8 digits); disabling and changing the PIN always verify the current PIN against the stored hash, even while the session is unlocked (`verifyCurrentPin()`, never the `requestUnlock()` short-cut) — a parent leaving the app unlocked must not leave the lock removable. Disabling keeps the locks for a later re-enable. - The unit of locking is the category. Nothing is blurred or greyed: a withheld category and its rows are absent. The only trace is one "N locked · Enter PIN to show" row at the bottom of a portal's category rail, which opens the PIN prompt. In fail-closed mode (lock store unreadable) the row shows without a count, since which categories are locked is unknown while every one of them is withheld. - The unlock lives in memory only. The app locks again on every restart, on "Lock now" (header button, command palette, settings), and after `Settings.parentalLockRelockMinutes` minutes without user interaction (default 15; `0` = only on restart). The idle timer follows the UNLOCKED transition: armed the moment a session is unlocked — including the session that just enabled the feature — and disarmed on lock. Active playback of a built-in web player counts as interaction, so a film never locks half way — video through the keep-awake tracker, and audio (the radio player) read from the playing `