What's wrong
JsonFilePersistenceProvider.LoadStateAsync (JsonFilePersistenceProvider.cs#L65-L85) catches JsonException, IOException and ArgumentException. For each of them it returns null, which callers treat as "no saved state".
File.ReadAllTextAsync throws UnauthorizedAccessException when the file exists but can't be read. That exception derives from SystemException, not IOException, so it isn't caught. It escapes through Navigation<T>.LoadStateAsync into the caller.
Why it matters
docs/Design-Decisions.md promises "Graceful Degradation: Navigation continues if persistence fails".
- The behaviour is also inconsistent. A file locked by another process (
IOException) degrades to "no state". A file the user can't read crashes application startup instead. That happens when the file is owned by another account, when its ACLs were tightened, or when a roaming profile copied it with the wrong permissions.
Suggested fix
Add catch (UnauthorizedAccessException) { return null; } alongside the existing handlers.
Acceptance criteria
- A test makes the state file unreadable (
chmod 000 on Unix, or a deny ACL on Windows) and asserts that LoadStateAsync returns null.
- Loading through
Navigation<T> in that state reports "no state loaded" rather than throwing.
What's wrong
JsonFilePersistenceProvider.LoadStateAsync(JsonFilePersistenceProvider.cs#L65-L85) catchesJsonException,IOExceptionandArgumentException. For each of them it returnsnull, which callers treat as "no saved state".File.ReadAllTextAsyncthrowsUnauthorizedAccessExceptionwhen the file exists but can't be read. That exception derives fromSystemException, notIOException, so it isn't caught. It escapes throughNavigation<T>.LoadStateAsyncinto the caller.Why it matters
docs/Design-Decisions.mdpromises "Graceful Degradation: Navigation continues if persistence fails".IOException) degrades to "no state". A file the user can't read crashes application startup instead. That happens when the file is owned by another account, when its ACLs were tightened, or when a roaming profile copied it with the wrong permissions.Suggested fix
Add
catch (UnauthorizedAccessException) { return null; }alongside the existing handlers.Acceptance criteria
chmod 000on Unix, or a deny ACL on Windows) and asserts thatLoadStateAsyncreturnsnull.Navigation<T>in that state reports "no state loaded" rather than throwing.