Skip to content

Flowvault v1.4.0 — Markdown preview without the leaks Latest

Choose a tag to compare

@flowdeskadmin flowdeskadmin released this 24 Apr 04:52
· 17 commits to master since this release

v1.4.0 — Cmd+K search, bounded by your session

Flowvault now has a command-palette search (Ctrl/Cmd + K) across every
notebook you've unlocked in the current browser session. It's fast,
keyboard-first, and — by construction — incapable of seeing anything
you haven't already decrypted.

What's new

  • Cmd+K search palette. A single keybind opens an overlay that
    searches titles and content across every tab in the currently
    unlocked slot. Case-insensitive substring, match highlighting, line
    numbers, results grouped by notebook.
  • Keyboard-first navigation. ↑ ↓ move, Enter jumps to the
    match, Home/End go to the first/last hit, Esc closes.
    Mouse-hover syncs with the keyboard cursor so the two drivers never
    fight.
  • Jump-to-match. Selecting a hit switches to the right notebook
    and selects the match range directly in the textarea, so the
    browser scrolls it into view for you. If you're in pure Preview
    mode, the editor flips to Edit so there's a surface to land on;
    Split stays Split.
  • Discoverability button. A new Search ⌘K button sits in the
    editor toolbar for anyone who doesn't already know the shortcut.

Why the constraints matter

A search feature is the kind of thing that can quietly undo a
zero-knowledge design: most apps index everything, store the index
somewhere the server can see, and call it "just metadata." Flowvault's
search does none of that.

  • In-memory only. There is no persistent index, no IndexedDB
    store, no localStorage cache. The corpus is the plaintext that's
    already sitting in memory because you unlocked the slot. Locking
    the vault drops the bundle and drops the search surface with it.
  • Zero server contact. The feature never issues a request. It is
    a pure function from your unlocked notebooks + your query to a list
    of hits, executed in the tab.
  • Deniability-preserving. Slots whose password you haven't
    supplied in this session are not in memory, so the search is
    physically incapable of traversing them. A match that exists under
    a different password is invisible to the current session — exactly
    like the rest of Flowvault.
  • No index to subpoena. There's nothing for us to hand over and
    nothing for a compromised host to exfiltrate later. The same
    invariant that makes backups portable makes search ephemeral.

Small notes

  • Corpus ceiling per session is tiny by design (32 notebooks × a few
    KiB per slot), so the scan runs on every keystroke without
    debouncing. Sub-millisecond on real devices.
  • Per-notebook hit cap (20) and global cap (100) keep the palette
    bounded when you search for common words.
  • The palette is suppressed while another modal owns the screen, so
    it can't stack on top of rename, confirm-delete, add-password, or
    handover dialogs.

Upgrade

Web: already live on useflowvault.com —
reload and press Ctrl/Cmd + K.
Self-hosted: pull v1.4.0 and rebuild (npm run build). No
migrations; the feature is purely client-side.