Flowvault v1.4.0 — Markdown preview without the leaks Latest
v1.4.0 — Cmd+K search, bounded by your session
Flowvault now has a command-palette search (Ctrl/Cmd + K) across every
notebook you've unlocked in the current browser session. It's fast,
keyboard-first, and — by construction — incapable of seeing anything
you haven't already decrypted.
What's new
- Cmd+K search palette. A single keybind opens an overlay that
searches titles and content across every tab in the currently
unlocked slot. Case-insensitive substring, match highlighting, line
numbers, results grouped by notebook. - Keyboard-first navigation.
↑ ↓move,Enterjumps to the
match,Home/Endgo to the first/last hit,Esccloses.
Mouse-hover syncs with the keyboard cursor so the two drivers never
fight. - Jump-to-match. Selecting a hit switches to the right notebook
and selects the match range directly in the textarea, so the
browser scrolls it into view for you. If you're in pure Preview
mode, the editor flips to Edit so there's a surface to land on;
Split stays Split. - Discoverability button. A new
Search ⌘Kbutton sits in the
editor toolbar for anyone who doesn't already know the shortcut.
Why the constraints matter
A search feature is the kind of thing that can quietly undo a
zero-knowledge design: most apps index everything, store the index
somewhere the server can see, and call it "just metadata." Flowvault's
search does none of that.
- In-memory only. There is no persistent index, no IndexedDB
store, nolocalStoragecache. The corpus is the plaintext that's
already sitting in memory because you unlocked the slot. Locking
the vault drops the bundle and drops the search surface with it. - Zero server contact. The feature never issues a request. It is
a pure function from your unlocked notebooks + your query to a list
of hits, executed in the tab. - Deniability-preserving. Slots whose password you haven't
supplied in this session are not in memory, so the search is
physically incapable of traversing them. A match that exists under
a different password is invisible to the current session — exactly
like the rest of Flowvault. - No index to subpoena. There's nothing for us to hand over and
nothing for a compromised host to exfiltrate later. The same
invariant that makes backups portable makes search ephemeral.
Small notes
- Corpus ceiling per session is tiny by design (32 notebooks × a few
KiB per slot), so the scan runs on every keystroke without
debouncing. Sub-millisecond on real devices. - Per-notebook hit cap (20) and global cap (100) keep the palette
bounded when you search for common words. - The palette is suppressed while another modal owns the screen, so
it can't stack on top of rename, confirm-delete, add-password, or
handover dialogs.
Upgrade
Web: already live on useflowvault.com —
reload and press Ctrl/Cmd + K.
Self-hosted: pull v1.4.0 and rebuild (npm run build). No
migrations; the feature is purely client-side.