trackslash
VAULT-72 P2

Spotlight search integration

0
All issues

Description

Moved from GitHub issue badbundle/vault-app#133 (opened 2024-05-24, labelled enhancement and priority-p2) when GitHub Issues was turned off for the repo. Trackslash is now the source of truth for Vault's issues.

The idea: searching Spotlight for a code or a note shows the item, and the result deep-links to that item's detail page in Vault.

To decide before building it:

  • Anything indexed in Spotlight can be searched outside Vault, without unlocking it. Check that against MANIFESTO.md's core principle (a coerced user who has to hand over an unlocked phone), and decide what, if anything, is indexed: titles only, and never hidden items, items in a locked vault, or anything behind the App Lock Password.
  • Whether removing an item, erasing the vault, or a killphrase deleting items also removes them from the index straight away, with no trace left in Spotlight (C2, C6).

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

3
Bradley

Built in https://github.com/badbundle/vault-app/pull/667 (merged as e97e7639), as the narrow version.

Show in Spotlight is a new toggle in Settings → Codes, off by default. It puts codes' site names in Spotlight, which Apple Intelligence also searches. Choosing a result opens the code in Vault, after unlocking if App Lock is on.

Limits:

  • Only while App Lock, and so the App Lock Password, is off. Turning App Lock on turns the setting off and empties the index.
  • Only codes: never notes, recovery phrases or encrypted items. Never a locked or hidden code, or one Vault's own search can't find by name.
  • Only the site's name, never the account name.
  • A code with a killphrase is shown like any other, so Spotlight can't be used to find which codes have one (C5).

How it's kept current:

  • The index is rebuilt from the whole vault, not the feed's filtered view, whenever the data, the setting or App Lock changes, and it's emptied at launch if it no longer applies.
  • It's Vault's own index, with complete file protection, so it can't be read while the device is locked.

Tested:

  • New tests cover what's shown, the unfiltered read, and the indexer's ordering and retries. 24 Settings snapshots are re-recorded.
  • In the Simulator: with it on, Spotlight shows "GitHub · Code" under Vault, and tapping it opens the code. With it off, the result is gone. Screenshots are in ~/Library/Caches/vault-backlog-qa/VAULT-72/.
  • Accepted limit: like any system index, Spotlight's files may keep a trace of a removed code.
Bradley

Decision (Bradley, 2026-09-27): build the narrow version; he thinks it'd be handy for Apple Intelligence. That means:

  • off by default;
  • only while App Lock, and so the App Lock Password, is off;
  • code titles only;
  • cleared when it can no longer apply.

Building it now.

Bradley

Needs your judgement: I've left this open and built nothing. The question isn't how to build it but whether it should exist, and the manifesto points against it.

What Spotlight would expose:

  • Anything indexed can be searched from the Home Screen with the device unlocked, without opening Vault. App Lock, the App Lock Password and the duress vault are all skipped.
  • Even titles alone say what the vault holds ("Coinbase", "ProtonMail"). The core principle rejects "convenience features that would help legitimate users but also lower the cost of coerced data exposure", and a coercer only needs to type into Spotlight.
  • App Lock Password: it encrypts the vault on the device, and today widgets, QuickType and AutoFill show nothing while it's on. A Spotlight index would be plaintext outside that encryption.
  • Duress vault: an index of the real vault's items would give it away while the duress vault is open (C5, C9).
  • Deleting: removing an entry from CoreSpotlight is asynchronous, and the system may keep traces. A killphrase deleting an item, or the erase, couldn't promise "no memory that it ever existed" (C2, C6).

My recommendation: close it as won't do. Search inside Vault already covers finding an item.

If you want it anyway, the narrowest version I'd defend:

  • Off by default, since this lowers a protection (C7).
  • Only while the App Lock Password is off.
  • Code titles only, never notes, recovery phrases, hidden or locked items.
  • Cleared whenever App Lock or the App Lock Password turns on, on an erase, and on Delete All Data.

Reply with "close", "build the narrow version", or something else, and I'll act on it.