trackslash
VAULT-49 P2

Encryption 10: lock down widgets, AutoFill and QuickType while the password is on

0
Sub-issue of VAULT-22 P2 Add an optional password to the app lock

Description

Sub-issue 10 of the on-device encryption design (VAULT-26, docs/on-device-encryption.md, "Widgets, AutoFill and QuickType").

While the password is on:

  • QuickType: empty the identity store and keep it gated.
  • Widgets: add a locked state and an empty entity query, and reload the timelines.
  • AutoFill: add a password unlock inside the AutoFill sheet. Check the extension's memory headroom for the key derivation, and use a cross-process flock.

Tests: unit tests, plus snapshots of the locked states.

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

1
Bradley

Done in https://github.com/badbundle/vault-app/pull/646.

While the vault is encrypted (any non-plain mode):

  • Widgets:
    • They show the locked placeholder.
    • The configuration list is empty, and HOTP can't be advanced.
    • The app ignores widget HOTP links.
    • Timelines reload when the password is set.
    • The setup screen says to remove existing widgets, and that AutoFill will ask for the password.
  • QuickType:
    • Every write goes through a mode check, and a full sync empties the store.
    • Requests return userInteractionRequired without reading the vault.
    • Clearing is journaled and retried. Every non-plain launch empties the store again.
  • AutoFill:
    • Mode: it's read fresh on every request. The vault is locked and purged before any UI shows. Anything but a settled password mode (encrypting, erasing, turning off or on, device-key mode until VAULT-50) shows "Open Vault".
    • Unlocking: the sheet asks for device authentication, then the App Lock Password, through the same unlock service and shared attempt counter. It's never Face ID alone.
    • Memory: it's checked before each attempt is counted and before each save. If it's short, the user is sent to Vault.
    • Locking: the vault locks before the sheet completes or cancels, and when it disappears. The extension's lock delay is always immediate.
    • The state file: the extension only reads the deadline, and never writes it.

Also: the attempt counter now holds an App Group flock around its read-modify-write, so the app and AutoFill can't lose counts.

Tests:

  • Unit tests for the QuickType gate, the adapter, widget loading, provider, query and HOTP, and the AutoFill view model, including a mode change mid-process.
  • Light and dark snapshots of the AutoFill checking, password and "Open Vault" states, and of the widget's locked state.

Review: a security review found one blocker (AutoFill deciding the mode once per process, which could show cached codes behind Face ID alone) and five should-fixes. All were fixed and re-reviewed. The review's note about AutoFill not erasing at the threshold is handled in VAULT-34.