Description
Bradley (2026-09-29) wants a native Mac app alongside the iOS one, to keep items and fill codes on the Mac.
This is an epic. Write the design doc first, then split it into sub-issues.
Decisions (Bradley, 2026-09-29)
- The Mac app requires an App Lock Password. There's no unencrypted vault on the Mac: setting a password is part of the first launch, and it can't be turned off.
- No CLI, and no other way into the vault from outside the app. The vault's data stays isolated in the app.
Where the code stands
-
Already Mac-ready:
Package.swiftdeclares macOS 26, and aCI_macOSscheme exists. These modules are platform-neutral or nearly so:- VaultCore, VaultBackup, VaultKeygen, CryptoEngine, CArgon2, VaultSettings and FoundationExtensions;
- VaultFeed (1 of 216 files mentions UIKit).
CryptoEngineTests already run on macOS.
-
iOS-only:
- VaultiOS (SwiftUI, 17 files mention UIKit);
- VaultiOSAutofill, VaultiOSWidgets and VaultiOSShared;
- VaultExport (PDF backups, 9 UIKit files) and ImageTools (UIKit).
-
Encryption: all of it is CryptoKit (VAULT-99), so export compliance is the same on the Mac (
docs/export-compliance.md).
The Mac app
- A native SwiftUI macOS app, not Mac Catalyst or the iPad app on Apple silicon.
- It has its own UI module (such as
VaultMac) on the shared VaultFeed and VaultCore. - It has a sidebar (Items, Tags, Backups, Settings, About), items and the editor, menu commands and keyboard shortcuts.
- It has its own UI module (such as
- Always encrypted. The vault is only ever the encrypted vault file (G33), so it never depends on FileVault alone (G38). Duress passwords and erasing after 10 work as on iOS.
- The same App Store record, with macOS added and the same bundle ID, for Universal Purchase. It needs its own screenshots and review.
- Its own vault, with no sync (G69, the manifesto). Items move by backup and restore, or by the QR transfer, using the Mac's camera or Continuity Camera.
- AutoFill of one-time codes on the Mac, with a credential provider extension (check what macOS 26 allows). Widgets can come later.
- iOS assumptions to port. Each needs rows in
docs/security-model.md:- App Lock: Touch ID, Apple Watch or the Mac's password, through LocalAuthentication, then the App Lock Password. Lock on screen lock and sleep, and on leaving the app per Require Unlock.
- Hide While Recording:
NSWindow.sharingType = .nonekeeps windows out of screen capture, which is stronger than iOS (G24). - Clipboard: concealed and transient pasteboard types, clearing after the timeout, and Universal Clipboard off by default (G50).
- Keyboard: autocorrect, text completion and Writing Tools off in every field (G52).
- Keychain: the data protection keychain (already used), with access groups for the app and its AutoFill extension only.
- Backups: PDF rendering and printing need AppKit, split out of VaultExport and ImageTools; NSSavePanel; security-scoped bookmarks for the auto-backup folder.
- Spotlight: the same rules as iOS (G49). With the password always on, Spotlight is always off (as on iOS while App Lock is on).
- Validation: local-check gains a macOS build and test run, and Mac snapshot tests pinned to a set configuration.
Suggested order
- Design doc (
docs/mac-app.md): the decisions above, and how each iOS protection maps to the Mac. - Shared modules on macOS: split VaultExport's and ImageTools' UIKit code.
- The Mac app: first launch sets the password; then items, copying, adding and editing, locking and backups.
- AutoFill, and later widgets, on the Mac.
- The App Store: macOS on the same record, screenshots and review.
Done when
The Mac app ships, always encrypted, with every new promise in docs/security-model.md.
Sub-issues
0Linked issues
0GitHub
0No branches or pull requests linked.
Comments
0No comments.