Skip to content

Releases: HiImRook/valid-vault-password-manager

v0.7.4 - Transfer Authentication and Autofill Fixes

Choose a tag to compare

@HiImRook HiImRook released this 05 Oct 06:58

Transfer Authentication and Autofill Fixes

Export and import now require fingerprint authentication. Export Key, Import Key, Export Vault, Import Vault, Share Master Key, Share Vault, and receiving a key or vault by QR all ask for fingerprint, device PIN, or password first, even while the vault is unlocked. A brand-new browser with no vault yet skips the check, so first setup still works.

Added

  • Password style choice. The inverted V now offers With special characters (Aa1!) or Letters and numbers only (Aa1) for sites that reject symbols. Generate a different one keeps the style you picked.

Changed

  • Symbols in generated passwords now come from !@#$%^&*, the set most sites accept.

  • Security questions. Three were replaced in the same positions:

    • City where you were born → Name of your favorite childhood toy
    • Name of your first street → Your favorite childhood book
    • Your mothers maiden name → Your mothers middle name

    Key files saved earlier with one of these show the new wording and still need the original answer.

Fixed

  • Password fields inside web components now get a V and fill correctly, and a lone confirm field no longer gets a login V.
  • Leftover V tags on multi-step forms now clear when a step slides out of view.

Known Gaps

  • The phone app does not yet require fingerprint authentication for export and import. Planned for the v0.8.x phone de-drift.

Install: Valid Vault on the Chrome Web Store

See CHANGELOG.md for full details.

v0.7.3 - Uni-Vault and User Guide

Pre-release

Choose a tag to compare

@HiImRook HiImRook released this 30 Sep 23:13

Every browser on one computer can now share one vault. Uni-Vault links each browser to a single encrypted vault file and keeps them in sync automatically. After the first link, you never need to export or import again. This release also adds a searchable User Guide inside the extension and makes fingerprint or device PIN the first choice when you import a key. Extension only.

Added

  • Uni-Vault.
    • Export Vault offers to link the browser to the file you save.
    • Import Vault offers to link another browser to that same file.
    • Linked browsers stay in sync on their own, and the newest edit wins.
    • Each browser keeps its own working copy, so autofill stays instant.
    • A damaged file, or one made with a different key, is refused and never overwritten.
    • Sync has a panel with Reconnect and Unlink.
  • Brave support. Brave ships with the setting Uni-Vault needs switched off. The User Guide shows the one switch to flip, and in the meantime Export Vault and Import Vault keep working as before.
  • User Guide.
    • Open it from the popup menu. It covers setup, locking, timers, autofill, the generator, keys and backups, Uni-Vault, moving between devices, ten recommended setups, and troubleshooting.
    • Search it with Ctrl+F or /.

Changed

  • Key import leads with fingerprint or device PIN. A master password remains as the fallback, and an existing fingerprint relinks with a single Windows Hello prompt.
  • About links now include Discord and open in a new tab.

Fixed

  • Unlock methods and Clear Vault re-authenticate. Editing or deleting an unlock method, and clearing the vault, now ask for your fingerprint, PIN, or password first.
  • Masked password prompts. The prompt for setting a master password and the one for editing a login's password are now masked.

Notes

  • Uni-Vault syncs browsers on the same computer using the import feature. To move the vault between devices, use QR, or Export and Import, and use your own method of transport to the new device.
  • If a browser asks for file permission again after a restart, Reconnect restores it in one click.
  • Additional extensions for other popular browsers coming soon. Currently works with all browsers using the Chrome Store extension platform (see user guide for note on use with the Brave browser).

v0.7.2 - Password Generator

Pre-release

Choose a tag to compare

@HiImRook HiImRook released this 28 Sep 19:32

Password Generator

Valid Vault now creates strong passwords for you. New password and change password fields get an inverted V (black circle, green V). Click it and a random password fills both the new and confirm boxes, masked, ready to submit.

What's new

  • Password generator. Every password is drawn from the browser's cryptographic random source, with every character equally likely, and always includes an uppercase letter, a lowercase letter, a digit, and a symbol. Any length, pattern, or password rules the site declares are followed, and a limit the site sets always wins. Don't like it? Generate a different one from the same note, which closes on its own after 5 seconds or on Escape.
  • Choose your length. A new Password Generator section in Settings sets the minimum (16 or 20) and maximum (24, 32, 48, or 64). Each maximum has its own range: minimum to 24, 25 to 32, 33 to 48, or 49 to 64. Defaults are 16 and 24.
  • Change password forms. The current password field keeps the normal V and fills your saved login, the new and confirm fields get the generator, and the save prompt updates the right account.
  • Previous password safety net. When you change a saved password, the old one stays in the vault, encrypted, as a labeled previous password in the login picker. If the site never accepted the change, one click restores it. It is removed only after the new password has been used 3 times and 14 days have passed.
  • Readable timeouts. Settings shows auto-lock as hours, minutes, and seconds and QR stream timeout as minutes and seconds, updated as you type.

Changed

  • The auto-lock limit is now 2 hours on the extension, up from 1 hour. Crypto Wallets follows the same timer.
  • The popup has a green border on the sides and bottom with rounded bottom corners.

Fixed

  • Revealed passwords in Manage no longer run under the edit and delete buttons. Passwords up to 64 characters read in full, and long usernames and emails wrap instead of being cut off.

Known gaps

  • The phone app has no password generator, as it is primarily a transport and editing convenience tool, and keeps its 1 hour auto-lock limit until the v0.8.x phone de-drift.
  • QR scanner reliability and the bookmarks QR share move to v0.8.x, after the phone de-drift.

Install

Extension only. Load the extension folder as an unpacked extension, or reload it if you already have it installed. Your vault carries over as is.

See CHANGELOG.md for full details.

v0.7.1 - Protected Master Key Transfer

Pre-release

Choose a tag to compare

@HiImRook HiImRook released this 28 Sep 06:17

Protected Master Key Transfer

The master key no longer leaves a device as a raw key. Share Master Key and Export Key now carry it wrapped under a passphrase and three security questions you choose, and the receiving device has to enter all of them before it can use the key. A photographed QR code or a stolen key file is useless without them.

How it works

  • The first time you share or export your key, you set a passphrase and pick three security questions from a list of ten
  • After that, Share Master Key and Export Key are one click and reuse the same protection
  • The receiving device, from a scanned QR or a key file, asks for the passphrase and all three answers. Wrong answers are rejected and nothing changes
  • A device that accepts a key keeps the same protection, so it can pass the key on with the same passphrase
  • Change Key Passphrase in Sync replaces the protection whenever you want

Security

  • The key is wrapped with PBKDF2-SHA256 at 1,000,000 rounds and AES-GCM. The passphrase and answers are never stored
  • Common passwords and their obvious variations are refused. Four or more random words plus a number and a symbol is the recommendation
  • Unprotected key QR codes from older versions are refused
  • Every password prompt in Manage is now a masked Valid Vault dialog with a show/hide toggle. The old browser prompts showed typed text
  • Personal Info edits try fingerprint or device PIN first, with your master password as the fallback

Fixes

  • Crypto Wallets locks itself when you switch Manage tabs or browser tabs, and after the auto-lock time
  • Auto-lock now resets on real activity anywhere in the browser, and an open Manage tab no longer locks the vault while you work elsewhere. Pages can't fake activity to keep the vault open
  • About shows the correct version

Good to know

  • Key files you already exported still import
  • Moving a key between the phone and the extension over QR resumes when the phone gets this update in v0.8.x. The key file path works between them now, and vault QR sync is unaffected
  • Next up is v0.7.2: QR scanner reliability on real devices and a bookmarks QR share

Updating

Reload the extension in chrome://extensions after updating. The first time you share or export your key, you'll be asked to set your passphrase and questions. Pick questions you will always remember the answers to, since a lost passphrase or answer can't be recovered.

See CHANGELOG.md for full details.

v0.7.0 - Crypto Wallets and Encrypted Bookmarks

Choose a tag to compare

@HiImRook HiImRook released this 27 Sep 20:18

Crypto Wallets and Encrypted Bookmarks

Valid Vault now stores crypto wallet seed phrases and bookmarks inside the same encrypted vault as your logins. Everything stays local, encrypted under your master key, and moves between browsers only as ciphertext.

Crypto Wallets

  • New Crypto Wallets tab in Manage, with its own unlock
  • Wallets hold named accounts, each with 24 numbered word boxes (fill 12, 18, 24, whatever your wallet uses) plus one optional note, such as a wallet password
  • Every word is checked on your device against the standard 2048-word BIP-39 list, with suggestions as you type and a full-phrase checksum check on save
  • Seed words only appear while you click Show, and hide again when you leave the window, switch tabs, lock, or the auto-lock timer runs out
  • Rename, edit (with a warning first), delete, and drag to reorder wallets and accounts, plus Sort A-Z for wallets

Bookmarks

  • Bookmark icon next to the lock in the popup: hollow when the page isn't saved, filled when it is
  • Bookmarks in the menu opens a side panel with search, rename, remove, and drag reorder

Security

  • Wallets and bookmarks are each sealed as one AES-256-GCM blob with a fresh IV per write, so wallet names, seed words, notes, addresses, and titles are not readable at rest
  • Seed words are never autofilled, never sent to a web page, and kept out of the live QR share
  • The word list is bundled and SHA-256 verified against the official list; checking works fully offline with no new dependencies
  • Merges are deterministic across any number of devices: permanent IDs, newest edit wins, deletes carry over, no duplicates

Full breakdown in the README under Crypto Wallet and Bookmark Security.

Also in this release

  • On-page unlocks open a small Valid Vault window with Windows Hello or password, handled in the extension's own origin
  • Popup lock button fixed, and the popup picks up an unlock done anywhere else
  • New globe-in-a-V icons and a centered Manage layout

Moving your vault

Bookmarks and Crypto Wallets travel with Export Vault and Import Vault. The phone app and QR transport are in active development (v0.8.x and v0.7.x); your data stays encrypted throughout.

Updating

Reload the extension in chrome://extensions after updating. Chrome may ask to approve the new side panel permission.

See CHANGELOG.md for full details.

v0.6.4 - Extension Hotfix for v0.6.3

Pre-release

Choose a tag to compare

@HiImRook HiImRook released this 26 Sep 19:02

Status: Released - Active Testing

What Changed

This is an extension-only hotfix for v0.6.3. It fixes key import, sync, migration, and autofill problems found in real use after the single-blob release, and moves all autofill to click-to-fill V tags. The phone app receives the matching key and transport fixes in the next release.

Fixed

  • Setting up a second browser could not receive a vault. Every browser creates its own key at setup and writes an empty vault under it on first unlock. Importing the real master key afterwards left that vault unreadable, so every read failed and Import Vault or QR sync threw a raw OperationError. Importing a key now checks whether this browser's vault opens with it. If not, a warning explains that the current vault will become unusable and that this is how you prepare to receive the vault from another device; on confirmation the old vault data is cleared and the key is saved.
  • Imported keys reverted on the next unlock. QR key import only set the key for the current session. File and QR key import now both rewrap the key under the browser's password (confirmed by entering it) and relink or turn off fingerprint, so the key survives lock and unlock.
  • Key file import always reported a wrong passphrase. The unwrapped key was passed back into a raw-bytes import and threw, which was caught and shown as a bad passphrase even with correct answers.
  • Deleted logins came back. mergeVaults() and mergeWebCredsVaults() dropped tombstones from their output, so any older device or backup resurrected a deleted item on the next sync. Tombstones are now kept.
  • The migration journal stored the vault in plaintext. The verification fingerprint added in v0.6.3 was the full plaintext tree written to IndexedDB. It is now a SHA-256 digest; a journal left by v0.6.3 is still verified.
  • Manage showed every site with 0 accounts. The list read credentials from the raw vault row, which a single-blob row no longer has. It now reads through the decrypted tree.
  • The background auto-lock ignored the seconds setting. It used old minute-based defaults, so the autofill session stayed open about 5 minutes idle. It now follows the auto-lock setting, and a fresh unlock or activity on the Manage page counts as activity instead of tripping an immediate lock.
  • Mismatched keys and scan results were silent or cryptic. Vault import and QR sync now fail with a clear message when the vault was made with a different key, and scan outcomes are always shown.
  • Locked save prompts lost the login. Saving while locked only said to unlock elsewhere, and clicking outside the prompt dismissed it and discarded the capture. The prompt now shows a masked master password box with a show/hide toggle and unlocks and saves in one step; only "Not now" dismisses it.
  • V tags attached to checkboxes whose label mentioned a keyword like "email". Non-text inputs are skipped.

Changed

  • Personal Info no longer fills on page load. Each matched field gets a visible V tag; clicking it opens a picker with the saved value, and nothing fills until you pick.
  • Login fields use the V tag instead of a focus popup. The login email/username and password fields each get a V tag listing saved logins for the site, plus saved emails on an email field. Picking a login fills both fields; picking an email fills just that field. The tag moves clear of a site's own icons at the field edge.
  • Manage shows "Locked" instead of "Not enrolled" / "Not set" while locked, and lists Personal Info above Misc Credentials.

Known Gaps

  • The phone app still has the v0.6.3 key import, key file import, and silent scan result problems. Phone de-drift and end-to-end QR sync are the next release.
  • Old plaintext journal data from a v0.6.3 migration may linger in the browser's own database files until the browser compacts them. New migrations no longer write it.
  • Unlock behavior still has rough edges across surfaces; community testing reports will drive the next round.

Notes

  • Every fix in this release was verified with Playwright-in-Chromium tests against the actual running extension, and with direct tests of the merge and migration logic, before shipping.

Full Changelog: See [CHANGELOG.md](https://github.com/HiImRook/valid-vault-password-manager/blob/v0.6.4/CHANGELOG.md)
Previous Release: v0.6.3

v0.6.3 - Single-Blob Vault Encryption and Migration Hardening

Choose a tag to compare

@HiImRook HiImRook released this 22 Sep 05:42

v0.6.3 - Single-Blob Vault Encryption and Migration Hardening

Status: Released — Active Testing

What Changed

This release replaces per-credential encryption for Website Credentials with single-blob vault encryption, closing the last major gap in what's readable from the raw database at rest. It also closes out three real migration-safety gaps found across independent code review before shipping, and completes the loginType classification work scoped since v0.6.0.

Added

  • loginType field on Website Credentials. Each saved login now classifies as username, email, or phone, so autofill and the credential picker can target the right field type reliably instead of guessing from a generic login string.
  • Single-blob vault encryption for Website Credentials. The vault row is now {schemaVersion: 2, blob: {iv, ciphertext}}, encrypting the whole {meta, credentials} tree as one AES-GCM ciphertext. Domain names, credential IDs, timestamps, login types, usernames, passwords, and per-site extra fields are no longer readable as plaintext from the Website Credentials IndexedDB row.
  • Automatic migration on first unlock. A legacy row is decrypted, backed up encrypted (not plaintext) in a short-lived vaultMigration journal, converted to the new tree, and verified before the journal clears. An interrupted migration is detected and rolled back from that encrypted backup on the next unlock instead of being silently treated as done.

Fixed

  • Unsupported or malformed vault rows could be misread as an empty legacy vault. decryptAnyRowToTree() and migrateLegacyVault() now throw on any schemaVersion other than 2 or undefined, and a schemaVersion: 2 row missing its blob now throws instead of passing undefined into decrypt. Previously either case could fall through to the legacy path and, on a later write, silently overwrite real data with an empty tree.
  • Decrypted vault-tree validation only checked the top-level shape. isValidVaultTree() now validates every domain's credential list: each entry needs a string id, deleted (if present) must actually be a boolean rather than any truthy value, and live (non-tombstoned) credentials need string username/password.
  • Legacy migration discarded unknown credential fields. decryptLegacyTree() now spreads the original record before overwriting only the fields it actually decrypts, so a future or unrecognized field on an old credential survives conversion instead of being silently dropped.
  • Migration verification only proved the blob could decrypt, not that conversion preserved the data. finalizeMigration() now compares a full-tree fingerprint of the plaintext tree against the fingerprint of the tree decrypted back from the written blob, rolling back on any mismatch. The expected fingerprint is stored in the migration journal, so this check also covers a migration resumed after an interrupted run.

Changed

  • Pairing and sync no longer reconcile two different master keys. Importing the same master key on both devices before syncing was already the intended behavior; the old reconciliation path was leftover early-stage logic and is removed. A mismatched key now fails clearly instead of one device's key silently winning.
  • mergeVaults() operates on already-decrypted plaintext trees and no longer needs a master key itself.
  • getAllDomains() now returns {success: false, locked: true} when called with no key, instead of assuming it can list domains unencrypted.

Known Gaps

  • Custom div-based comboboxes and contenteditable fields remain unsupported by autofill.
  • Every credential read now decrypts the full Website Credentials tree - the accepted tradeoff of single-blob storage. A decrypted-tree cache has not been added, since it hasn't been needed in real use yet.

Notes

  • Every hardening fix in this release was verified across multiple rounds of independent code review before shipping, following the same practice established in v0.6.2.

v0.6.2 - Website Credentials Save Fix and Autofill Hardening

Choose a tag to compare

@HiImRook HiImRook released this 21 Sep 03:24

v0.6.2 - Website Credentials Save Fix and Autofill Hardening

Status: Released — Active Testing

What Changed

This release resolves the top-priority gap left open by v0.6.1: Website Credentials now reliably saves new logins from real signup flows. It also closes out a long list of correctness and robustness issues in the autofill/injection layer found across several rounds of independent code review, each one verified against the actual code and against real browser behavior (Playwright + Chromium) before shipping.

Fixed

  • Website Credentials save regression, resolved. Root cause was detectLoginForm()/matchSignupFieldType() sharing mutable global state across forms, letting a second wired form silently repoint a first form's listeners at the wrong fields. Both now use per-form closures instead of shared globals.
  • Submit-triggered navigation losing the save prompt. Captured credentials now stage in background.js synchronously and are recovered on whatever page loads next in the same tab, surviving cross-domain SSO/MFA redirects and multi-hop flows. A race between staging and resolving that record is closed via per-tab serialization.
  • False-positive personal-info classification. Bare keywords like "state" no longer match inside unrelated free text - only against structured signals (name/id/autocomplete).
  • Autofill silently failing on React/Vue-style controlled inputs, fixed by using the native value-property setter before dispatching input.
  • Duplicate save prompts from one submission, collapsed via an in-flight capture guard.
  • Fields that gain their identifying attributes after insertion (framework hydration, multi-step forms) are now reclassified instead of staying unrecognized.
  • Detached SPA forms and personal-info fields no longer leak listeners - torn down within one debounce cycle of leaving the DOM.
  • Two separate formless login widgets on one page no longer both react to one click - button ownership is now scoped to the smallest containing element that already holds a button.
  • Personal Info autofill and per-site extra-field capture now support <select> and <textarea>, filled by matching actual option value/text rather than a blind assignment.
  • Activity tracking completed - ordinary typing, passive autofill, dropdown opens, and pending-save recovery all now reset the inactivity timer.

Known Gaps

  • Pending-save recovery is scoped to the browser tab, not the destination page, and expires after 45 seconds - a deliberate tradeoff to survive cross-domain SSO/MFA redirects, not an oversight.
  • The formless-widget heuristic can still misattribute on unusually flattened markup - a narrow edge case, not the general multi-widget bug from v0.6.1, which is fixed.
  • Custom div-based comboboxes and contenteditable fields remain unsupported.
  • loginType (username vs. email vs. phone) on Website Credentials remains scoped but not built.

Notes

  • Every fix in this release was verified with Playwright-in-Chromium tests and/or direct unit tests of the storage logic against the actual running code.

v0.6.1 - Autofill Injection Foundation

Pre-release

Choose a tag to compare

@HiImRook HiImRook released this 18 Sep 21:43

v0.6.1 - Autofill Injection Foundation

Status: Released

What Changed

This release adds real autofill injection to the extension, reading Personal Info and Website Credentials to populate page forms, and fixes two real bugs that were silently breaking background vault access and the session key.

Personal Info autofill

  • Empty, matched fields (name, phone, address) auto-populate on page load using a three-tier heuristic: autocomplete attribute match first, keyword match against field id/name/placeholder second, nearby label text as a fallback
  • This replaces exact-selector matching, which failed on real signup forms (a field with id="firstName-field" never matched id="firstName")
  • Email fields are click-to-pick, never auto-filled. A profile can hold several ranked emails, so email is never silently populated. Clicking the field's tag opens a small picker listing every saved email by rank, and only the one selected gets injected

Website Credentials autofill

  • Clicking a tagged login field shows a picker of saved usernames for the current site
  • Injection only, no password reveal. That's the site's own UI if it has one

Visible field tag

  • A small circular badge marks any field Valid Vault has matched
  • Repositions correctly on scroll and resize

Inline unlock, directly on the page

  • Clicking a tagged field while the vault is locked prompts for the master password right there, no popup required
  • Password-only by design. See Security Model below

Fixed

  • background.js had indexedDB.open('ValidVault', 1) hardcoded in three places. With the database now at version 3 after v0.6.0's new stores, this threw a VersionError and silently broke background vault access. Opens with no explicit version now
  • Popup/background session key race. popup.js wrote the session key to chrome.storage.session itself, and Manifest V3 destroys a popup instantly on losing focus, which could interrupt that write mid-flight on a fast tab switch. The write is now delegated to background.js via message-passing, which has a longer lifecycle

Security Model

Autofill never exposes the master key. background.js is the only place the session key lives; content.js, running in the page's own context, only ever receives specific plaintext values it explicitly requested for injection. Inline unlock is password-only for a real reason, not a missing feature: a WebAuthn platform credential is bound to the origin that created it (chrome-extension://...), and a content script running in a visited page's own origin can never trigger that same credential. No competitor-targeting logic exists or is planned. Autofill wins on being fully local and already-unlocked in memory, not on hiding another extension's UI.

Known Gaps in This Release

  • Website Credentials does not reliably save new logins captured from a real signup flow. detectLoginForm()'s field-selection can collide with Personal Info's autofill targeting the same field on a form. A fix was built, caused a separate regression, and was rolled back. Root cause understood, still open, and the clear next priority
  • Autofill matching quality varies site to site. This release is a working foundation, not a finished feature
  • loginType (username vs. email vs. phone) on Website Credentials remains scoped but not built
  • Sync, backup, and the scanner still need on-device field testing across Android versions
  • Per-method auth edit and delete are still deferred on the phone
  • Personal Info is still a placeholder on the phone
  • The WebAuthn RP name stays "Local Vault" in code to preserve existing enrollments

Full Changelog: See CHANGELOG.md
Previous Release: v0.6.0

v0.6.0 - Web Credentials, Personal Info, and Uni-Vault Key Fix

Choose a tag to compare

@HiImRook HiImRook released this 15 Sep 00:38

v0.6.0 - Web Credentials, Personal Info, and Uni-Vault Key Fix

Status: Released — Active Testing

What Changed

This release adds two new pieces of storage to the extension, Web Credentials and Personal Info, and fixes a real correctness bug that would have broken syncing the same vault across multiple browsers.

Added

  • Personal Info, a new tab under Manage for first name, last name, phone, address, and multiple ranked emails (reorder with up/down, the top one is marked Primary). Viewing requires a normal unlock, but adding or editing any field requires the master password specifically, never fingerprint, a deliberately stricter gate for this category of data.
  • Web Credentials gained a working Edit. It previously supported add and delete only.
  • Website Credentials and Web Credentials now require their own explicit re-unlock inside Manage, separate from simply having the extension open, and re-lock when the extension itself locks.
  • Personal Info, Web Credentials, and login credentials are all now included in Share Vault, Export Vault, Import Vault, and QR sync, so they travel together as one vault.

Fixed

  • Importing a master key only ever changed the session in memory. It never re-wrapped the browser's own password or fingerprint around the imported key, so after a lock and unlock, the browser silently reverted to its original key, and anything saved since the import became unreadable. Importing a key now re-wraps it under the browser's existing unlock methods, so it genuinely becomes the browser's key going forward. This was the key gap standing between "export and import a file" and the same vault file staying usable across Chrome, Firefox, and other browsers with one shared master key.
  • The save-on-submit prompt fired on every login, even to a site already saved with an unchanged password. It now checks first: silent if nothing changed, a save prompt for a genuinely new username, and an update prompt only when the password for an existing username has changed.
  • A fingerprint enrollment issue was tracked down during this cycle: Windows began showing its cross-device/security-key chooser with no local Windows Hello option. Traced through the actual commit history rather than guessed at; the extension's code was confirmed unchanged since v0.3.1. The cause was Windows account passkey state, not the extension, resolved by removing the existing passkey in Windows Settings and re-enrolling.

Known Gaps in This Release

  • Autofill injection is scoped but not yet built. Personal Info and login-type detection (username vs. email vs. phone) exist as storage only for now.
  • Extra fields on login credentials (recovery email, notes, and similar) were deliberately left out. A future native autofill feature will handle that separately rather than storing it on the credential record.
  • This build remains under active testing — expect rough edges
  • Per-method auth edit and delete are still deferred on the phone
  • SSN and credit/debit card storage remain deliberately deferred, pending additional security work
  • The extension's Export/Import Key modals still use plain browser prompts rather than styled modals
  • The WebAuthn RP name stays "Local Vault" in code to preserve existing enrollments

Full Changelog: See CHANGELOG.md
Previous Release: v0.5.5