trackslash
VAULT-41 P2

Encryption 2: introduce VaultRecord and share the item and tag codecs

0
Sub-issue of VAULT-22 P2 Add an optional password to the app lock

Description

Sub-issue 2 of the on-device encryption design (VAULT-26, docs/on-device-encryption.md).

The change:

  • Add a VaultRecord that mirrors the persisted schema field for field.
  • Make PersistedVaultItemEncoder / PersistedVaultItemDecoder, and the tag pair, produce and consume records.
  • The SwiftData store copies records to and from its @Model objects.
  • Add a schema parity test that fails if a persisted field is missing from the record.

Behaviour: none changes.

Tests: round trips, the parity test, and the existing store suite.

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

1
Bradley

Fixed in https://github.com/badbundle/vault-app/pull/616 (merged as 013dccfe).

The new records: VaultItemRecord, with nested OTP, note and encrypted-item details, and VaultTagRecord. They're field-for-field copies of the stored schema in raw form, so even items that wouldn't decode survive a move between stores.

Encoders and decoders: they no longer depend on SwiftData, and now live in VaultStore/Records/. The SwiftData store copies between records and its models, and its behaviour is unchanged.

Tests:

  • A schema parity test fails, naming the fields, if the schema and the records drift apart.
  • Round-trip tests cover every field and edge case.
  • Store tests cover tags, digests and imports.