trackslash
VAULT-101 P2 For an agent

A native Mac app

0
All issues

Description

Bradley (2026-09-29) wants a native Mac app alongside the iOS one, to keep items and fill codes on the Mac.

This is an epic. Write the design doc first, then split it into sub-issues.

Decisions (Bradley, 2026-09-29)

  • The Mac app requires an App Lock Password. There's no unencrypted vault on the Mac: setting a password is part of the first launch, and it can't be turned off.
  • No CLI, and no other way into the vault from outside the app. The vault's data stays isolated in the app.

Where the code stands

  • Already Mac-ready: Package.swift declares macOS 26, and a CI_macOS scheme exists. These modules are platform-neutral or nearly so:

    • VaultCore, VaultBackup, VaultKeygen, CryptoEngine, CArgon2, VaultSettings and FoundationExtensions;
    • VaultFeed (1 of 216 files mentions UIKit).

    CryptoEngineTests already run on macOS.

  • iOS-only:

    • VaultiOS (SwiftUI, 17 files mention UIKit);
    • VaultiOSAutofill, VaultiOSWidgets and VaultiOSShared;
    • VaultExport (PDF backups, 9 UIKit files) and ImageTools (UIKit).
  • Encryption: all of it is CryptoKit (VAULT-99), so export compliance is the same on the Mac (docs/export-compliance.md).

The Mac app

  • A native SwiftUI macOS app, not Mac Catalyst or the iPad app on Apple silicon.
    • It has its own UI module (such as VaultMac) on the shared VaultFeed and VaultCore.
    • It has a sidebar (Items, Tags, Backups, Settings, About), items and the editor, menu commands and keyboard shortcuts.
  • Always encrypted. The vault is only ever the encrypted vault file (G33), so it never depends on FileVault alone (G38). Duress passwords and erasing after 10 work as on iOS.
  • The same App Store record, with macOS added and the same bundle ID, for Universal Purchase. It needs its own screenshots and review.
  • Its own vault, with no sync (G69, the manifesto). Items move by backup and restore, or by the QR transfer, using the Mac's camera or Continuity Camera.
  • AutoFill of one-time codes on the Mac, with a credential provider extension (check what macOS 26 allows). Widgets can come later.
  • iOS assumptions to port. Each needs rows in docs/security-model.md:
    • App Lock: Touch ID, Apple Watch or the Mac's password, through LocalAuthentication, then the App Lock Password. Lock on screen lock and sleep, and on leaving the app per Require Unlock.
    • Hide While Recording: NSWindow.sharingType = .none keeps windows out of screen capture, which is stronger than iOS (G24).
    • Clipboard: concealed and transient pasteboard types, clearing after the timeout, and Universal Clipboard off by default (G50).
    • Keyboard: autocorrect, text completion and Writing Tools off in every field (G52).
    • Keychain: the data protection keychain (already used), with access groups for the app and its AutoFill extension only.
    • Backups: PDF rendering and printing need AppKit, split out of VaultExport and ImageTools; NSSavePanel; security-scoped bookmarks for the auto-backup folder.
    • Spotlight: the same rules as iOS (G49). With the password always on, Spotlight is always off (as on iOS while App Lock is on).
  • Validation: local-check gains a macOS build and test run, and Mac snapshot tests pinned to a set configuration.

Suggested order

  1. Design doc (docs/mac-app.md): the decisions above, and how each iOS protection maps to the Mac.
  2. Shared modules on macOS: split VaultExport's and ImageTools' UIKit code.
  3. The Mac app: first launch sets the password; then items, copying, adding and editing, locking and backups.
  4. AutoFill, and later widgets, on the Mac.
  5. The App Store: macOS on the same record, screenshots and review.

Done when

The Mac app ships, always encrypted, with every new promise in docs/security-model.md.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

0
No comments.