trackslash
VAULT-40 P2

Encryption 1: make the vault store switchable at runtime

0
Sub-issue of VAULT-22 P2 Add an optional password to the app lock

Description

Sub-issue 1 of the on-device encryption design, from VAULT-26 (docs/on-device-encryption.md, "Store session").

The change:

  • Replace VaultRoot's fixed static let vaultStore with a VaultStoreSession.
  • The session implements the store protocols and forwards to one of three things:
    • the plain SQLite store
    • an unlocked encrypted store
    • locked, where reads return nothing and writes throw
  • VaultDataModel purges items, tags and caches when it locks.

Behaviour: none changes. The plain store opens at launch as it does today.

Depends on: the lock state from VAULT-21, which this should build on.

Tests: forwarding, locked behaviour, and the purge.

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

1
Bradley

Fixed in https://github.com/badbundle/vault-app/pull/626 (merged as 15c099ed).

  • VaultStoreSession: an actor that implements every store protocol and forwards to .plain(store) or .locked.
    • When locked, reads return nothing and writes throw.
    • Export also throws, so an empty export can never replace a real backup.
    • Killphrase deletion returns false (C2).
    • switchTo(_:) and lock() wait for calls already in flight.
  • VaultRoot.vaultStore: now a session opened on the plain store (plainVaultStore). The rehash services still write to the plain store directly.
  • VaultDataModel.purgeVaultContents(): forgets items, tags, the search and tag filter, and the item caches. A generation counter stops a reload that was in flight from putting anything back.
  • App lock: it now purges the vault contents when it locks, instead of only clearing the search.
  • Everything else: unchanged. Nothing switches the session to another store yet; that comes with VAULT-46 and VAULT-47.
  • Follow-up for VAULT-47 and VAULT-22: the lock hook is synchronous but session.lock() is async, so an async lock step will be needed.