Repository navigation
Releases: YntraAB/yntra-vault
Releases · YntraAB/yntra-vault
Release list
Yntra Vault v0.2.6
Added
- Add Smart Login sequential email/username/phone method chooser support, traversing visible semantic buttons and links to select the matching identifier mode.
- Add Phone custom field type with end-to-end encryption in the entry editor, supported as a saved-identifier fallback, with full translation coverage across all 24 supported locales.
- Add deep composed-DOM focus verification and Windows foreground browser window binding via UI Automation, tolerating Chromium toolbar differences and
www.display elision while enforcing exact origin boundaries. - Add provider attempt-limit and error detection to post-submit verification to stop immediately without retrying credentials.
- Add open shadow root and same-origin frame traversal in Smart Login field analyzer, combined identifier placeholder parsing, and bounded chooser transitions.
- Add focused Smart Login chooser, identifier matching, native browser focus and attempt-limit regressions.
- Add a detailed 0.2.6 Smart Login compatibility and performance review, including browser-standard research, supported-site matrix, verification evidence and remaining boundaries.
Fixed
- Prevent phone-first login forms with descriptive metadata from receiving usernames when
autocompletesuggests username. - Re-arm the autotype gate after unlocked entry reads to prevent prior lock state from poisoning subsequent attempts.
- Avoid a full composed-DOM walk on every page-readiness poll when ordinary top-document controls already prove that the page is interactive.
- Preserve the exact HTTPS origin and non-standard port when generating generic login probes, while requiring the existing authentication-domain policy before using a known provider URL.
- Read Chromium's dynamic CDP port from
DevToolsActivePortwhen reconnecting to an existing browser, rather than attempting to reconnect to port0. - Reject malformed or non-local CDP browser endpoints, including zero ports, redirects, userinfo, query strings and invalid browser endpoint paths.
Changed
- Keep conventional login URLs in place when unfamiliar method choosers are encountered instead of probing guessed URLs.
- Update Smart Login developer guide and CDP session verification documentation.
- Keep existing Smart Login timing and credential/focus guards unchanged while adding bounded CDP connection checks and a cheaper readiness hot path; no universal-site bypass or unsafe JavaScript field setter was introduced.
Security
- Keep automated navigation restricted to parsed exact HTTPS origins or explicitly approved SSO pairs. Generic probe discovery now preserves the saved origin, including its effective port, and known-provider shortcuts are accepted only when the same policy approves them.
- Validate the local CDP handshake before connecting. The browser endpoint must be a
wsendpoint on127.0.0.1/localhost, use the requested port, contain no credentials/query/fragment, and have a valid browser endpoint path. - Document browser-enforced limits instead of weakening them: cross-origin iframes, closed shadow roots, passkeys/WebAuthn, CAPTCHA and MFA remain outside silent generic automation.
- Record Chrome 136's restriction on remote debugging with the default user-data directory as an open lifecycle compatibility item; the current review does not claim that ordinary default-profile launches are solved.
Verification
cargo check -p yntra-vault-coreandcargo check --workspacepassed.- Smart Login tests passed: 42 passed, 0 failed, 6 ignored.
- Full core library suite passed with serialized execution: 202 passed, 0 failed, 12 ignored.
- The ignored/live browser diagnostics still require explicit real-account opt-in and were not used as universal-site evidence.
Yntra Vault v0.2.5
Security and bug fixes take priority over new features.
Security
- Rotate local storage keys and recovery secrets when changing a protected vault's password or USB factor. Completing the recovery wizard requires two saved-share confirmations; closing early warns that the change is already applied and the new shares will no longer be shown. Old shares remain valid only for old backups.
- Authenticate linked devices individually and use fresh encrypted sessions. Removed peers cannot impersonate a remaining device using the old shared sync key; legacy peers must update and re-pair. Trust lists remain local.
- Restrict Git credential selection and Smart Login to validated origins and accounts; refuse ambiguous Git matches, cross-tenant domains and insecure remote redirects. Remove the browser's unsandboxed fallback.
- Require an independent Ed25519 publisher signature over update metadata and verify downloaded package hashes before opening desktop installers. Reject missing, expired or changed signatures with no unsigned fallback.
- Enforce Closed System mode in the native engine, cancel ongoing network work when it is enabled, and block automatic update startup until privacy settings are applied.
- Prevent late entry/tag responses and failed-operation rollbacks from restoring plaintext after locking. Keep sensitive entry details out of list previews; remove persistent website-icon caches.
- Respect native memory page sizes, fail safely when protected-memory setup fails, clear temporary secrets on drop, and restrict test-only authentication mocks to test builds.
- Reduce release-workflow permissions, pin third-party actions and separate package building from protected signing jobs. Refresh dependencies with security fixes.
- Update rustls, ratatui/lru and frontend dependencies; include a documented upstream glib security backport. Track remaining unmaintained dependencies and platform verification limits in the security notes.
Fixed
- Prevent plaintext exports from overwriting the open vault, including filesystem aliases; serialize competing saves and reject stale writers.
- Apply reader-compatible size limits when writing vaults and enforce the attachment limit for staged imports.
- Clear pending pairing/adoption data on every native lock path; preserve unrelated clipboard contents when the app no longer owns them.
- Lock an unlocked protected session when its bound USB device or vault file disappears; cancel active network/autotype work, revalidate the exact session after removable-storage checks and keep the application on the lock screen for safe reconnect.
- Automatically re-check recently used vault paths while the vault picker is open, so reconnecting a USB drive re-enables its vault without requiring an app or page refresh.
- Display OS screen-lock integration only where supported; report unavailable biometric consent instead of silently succeeding.
- Bound and pad breach-check requests, ignore padding records, and refresh previously checked passwords after the configured age.
- Add regression coverage for recovery rotation, wrong-origin credentials, revoked peers, asynchronous locking, privacy toggles and update signatures. Live clipboard, device and network tests require explicit opt-in.
- Allow setup and recovery-share dialogs to be cancelled through the close button, Escape or Cancel with a warning when newly generated shares have not been saved. Standardize security, hardware-key and language popups with the startup card visual style. Harmonize Settings access and recovery rows with the standard settings layout, streamline the USB Protection flow into a clean two-step verification and selection dialog with smooth vertical slide transitions, and automatically pre-select the primary connected USB drive.
Changed
- Protected-vault CLI password changes require
--recovery-output-dirwhen recovery is enabled. Store the replacement shares separately. - Device removal revokes future authenticated P2P sessions on that replica; it cannot erase old files, secrets already shared, or access retained through an independent WebDAV account.
- See security notes, USB/recovery and updates for migration and verification limits.
Yntra Vault v0.2.4
Reliability follow-up rebuilt at user request — 2026-09-27
This rebuild retains version 0.2.4. Install it manually over an existing 0.2.4 installation; automatic update checks do not offer unchanged versions. The application identity, data locations and permanent Android signing identity are preserved.
Import fixes
- Refresh entries and tags together so imported tags appear immediately; register tags on overwrite as well as insertion.
- Match duplicates by title, exact username, URL and entry type. Empty usernames no longer match unrelated accounts, and later records in one export are not silently skipped as duplicates of earlier imported records.
- Stage bulk inserts/overwrites and save once; restore entries, tags and search state if persistence fails.
- Preserve CSV credential whitespace, use exact column aliases, retain the first headerless row, and handle UTF-8 BOM and common line endings. Report malformed files and entry-limit violations instead of empty success or silent truncation.
- Retain KeePass custom fields and custom-field-only entries, Bitwarden folder tags and card/identity/SSH fields, and Proton keyed vaults with nested metadata/content. Preserve extended Proton data in sensitive custom fields and complete OTP/Steam URIs with their parameters. Unsupported archives, attachments and operational passkey migration are not newly implemented.
USB and recovery interface
- Replace verbose settings with compact USB protection and Recovery keys rows and focused dialogs matching the rest of the app. Move technical USB details into an expandable explanation while keeping biometric removal/re-pairing consequences visible.
- Align recovery setup with the shared compact three-step dialog. Preserve one visible share at a time, individual exports, two distinct saved-share confirmations and keyboard focus containment; unfinished recovery setup cannot be dismissed.
- Clear stale/disconnected USB selections after refresh or discovery failure, ignore obsolete responses and late keyfile selections, disable actions after status-load failure and offer retry. Disable incompatible hardware-key/local-protection setup.
- Guard duplicate creation, password changes and share exports; block dismissal during active writes and never report a cancelled export as saved. Damaged or unavailable optional recent-vault history cannot hide a newly created recovery kit. Fit path/keyfile controls on narrow screens.
Password and synchronization security
- Validate creation fields before file selection or keyfile generation; buttons, Enter and direct form submissions enforce the same confirmation and optional-factor requirements.
- Require non-blank new master passwords of at least 12 Unicode characters in the interface and native creation/rekey/recovery paths. Count characters rather than UTF-8 bytes or UTF-16 units, preserve credential whitespace exactly, and retain unlock support for existing nonempty shorter passwords.
- Reject empty ordinary unlocks, blank pending QR adoption and missing/duplicate recovery shares. Clear password state with temporary buffers after password-change attempts.
- Start locked, prevent rendering vault contents without a selected unlocked vault, and prevent native login from falling through to simulated success without a selected vault.
- Create new vault files atomically without overwriting an existing file; normal saves retain atomic replacement.
- Enforce QR expiry throughout handshake, transfer and receipt I/O, including peers that keep sending bytes. Exclude local hardware-password restoration records from PIN/QR payloads and receiving adoption.
Verification
- Add native and component regressions for import completeness/tag visibility/rollback, QR expiry and local-factor isolation, stale USB selections, cancelled/duplicate actions, invalid passwords/confirmations, initial lock state, non-overwriting creation and legacy password compatibility. Synthetic fixtures do not establish every exporter or physical USB/phone configuration's compatibility.
Android startup correction (rebuilt at user request)
Fixed
- Fix Android startup stopping at “Saved app settings could not be loaded,” including after a clean installation. Rust 1.95's standard file-lock API is unsupported on Android; use the native POSIX lock on Unix/Android while retaining Windows locking, atomic metadata writes and protection against silently resetting damaged metadata.
- Preserve existing vault files and application metadata during the fix. Users can install the signed update over 0.2.4 without uninstalling or clearing app data.
Verification
- Add regression coverage for clean metadata initialization, persisted preferences after restart, exclusive file locking and release of locks on close.
- Gate Android package publication on an emulator test using the signed APK: reproduce the 0.2.4 startup failure, upgrade in place, open the vault-creation screen, restart, and verify a clean app-data start. This supplements compilation and certificate checks; it does not certify every phone or complete vault migration.
Update reliability and data preservation
- Validate Android Build Tools 37 certificate output without weakening the pinned signing identity; reject unknown or extra signer certificates.
- Run opt-in update checks once at application startup instead of only when opening Settings. Keep updater state across navigation, prevent overlapping checks/installations, retain installer errors for retry, and disable native installation when a valid checksum is unavailable.
- Preserve recent vault IDs/names/paths, preferences, theme and setup state in a versioned native metadata file with migration from existing WebView storage, ordered atomic writes and explicit failure handling. Restore metadata before rendering and flush pending saves before update actions; exclude passwords, recovery shares and keyfile paths.
- Keep the application ID and existing WebView origin/data location stable. Enforce the permanent Android release certificate, application ID and version mapping in release validation.
- Reject inconsistent release versions and non-official asset locations. Stage Android APKs atomically under their content hash, recheck the staged digest, package identity, signing certificates and newer versionCode before opening the system installer.
- Fix Android customization-script parsing and include its required helper scripts in the public export allowlist. Document platform behavior, preservation guarantees and limitations in Updates and application data. Desktop detached updater signatures and device installation verification remain outstanding.
- Align recovery/format documentation with random-secret recovery v2, hardware-bound v5 and the separate local envelope. Clarify migration and verification limits; keep private AI/review notes out of the public changelog projection and include the user-facing USB/update guides in its documentation index.
Added
- Add an Android native clipboard bridge, sensitive-content marking, ownership-aware expiry, screen-capture protection and document-provider support for vault import, backup/export, recovery shares, key files and attachment saving.
- Optional Windows USB hardware-serial binding in vault creation and Security settings. The vault can be renamed or moved while requiring the enrolled device at unlock; no USB sidecar key file is created.
- Recovery v2: a random independent recovery secret split into two-of-three shares, individual native share exports, generation identity/checksums, and password-reset recovery for a lost password or USB. Add CLI recovery generation, revocation and restore commands.
- Document setup, recovery, synchronization, migration, hardware limitations and test scope in USB binding and recovery.
Changed
- Present recovery setup as a compact three-step dialog with one share at a time, individual export, hidden-by-default codes and a final saved-share review.
- Keep imported user tags/groups without adding synthetic source tags such as KeePass, Bitwarden or Imported.
- Persist the application's device identity independently of display-name changes; assign separate random identities to mobile installations and retain devices with matching display names.
- Separate each replica's local password, USB binding and recovery envelope from synchronized vault content. Phone updates preserve desktop protection; paired phone copies have no inherited USB requirement.
- Require fresh authentication to replace/revoke recovery. Replacement rotates the local storage key; password changes and USB changes preserve the current kit. Recovery consumes the current kit and requires explicit USB re-enrollment.
- The first v2 migration requires re-pairing existing devices and clears biometric enrollment. Biometric and legacy hardware-key enrollment are unavailable for protected v2 files. Legacy hardware 2FA must be disabled before migration; older applications cannot open the new envelope.
Fixed
- Detect the native operating system independently of window size. Hide desktop automation, installed-app selection, tray/startup controls, desktop keyboard settings, USB enrollment and unavailable native authentication on phones; retain supported vault functions.
- Stop showing successful copies after clipboard errors and remove the silent unprotected native-to-browser fallback. Use native clipboard access for pairing codes and addresses.
- Keep phones with identical names as distinct trusted devices throughout pairing and sync.
- Make password changes transactional on failure and prevent key-file generation from overwriting an existing factor. Fail plaintext exports if an entry cannot be decrypted instead of silently omitting it.
- Restore bounded, resizable desktop sidebar/item-list widths and persist them on drag release. Preserve full-width mobile layout.
- Parse KeePass XML structurally: empt...
Yntra Vault v0.2.3
Added
- Extend opt-in browser regressions for native identifier/password entry, hidden and read-only fields, focus loss, account identity and live result verification. A separate hidden-terminal password opt-in keeps authorized test credentials out of source, command-line arguments and application logs; normal test runs do not perform live account login.
- Universal Multi-Platform Auto-Update Engine:
- Implemented core update engine in
crates/core/src/services/updater.rssupporting Desktop (Windows Installer/MSI/Portable, Linux AppImage/deb, macOS), Mobile (Android APK), and CLI (yntra-cli). - Added robust semantic version comparison (
is_newer_version,parse_version) supporting major, minor, patch, pre-release tags, and normalization for bothvandVprefixes. - Added pre-release isolation in
is_newer_version: ensures users on stable releases are never prompted to update to unstable pre-release builds (-rc,-beta). - Implemented universal
UpdateManifest(latest.json) ingestion with dedicated platforms mapping for Tauri updater andextraplatform payloads for Android APK, CLI, and portable Windows executables. - Added constant-time SHA-256 cryptographic verification (
verify_sha256) usingsubtle::ConstantTimeEqagainst hex strings, preventing timing side-channel attacks during download validation. - Added HTTPS manifest retrieval with a GitHub Releases fallback for the default endpoint. Custom endpoint failures do not silently contact another provider.
- Enforced strict HTTPS scheme validation and a 250 MB package size limit (
MAX_UPDATE_PACKAGE_SIZE) to safeguard against transport tampering and memory exhaustion attacks.
- Implemented core update engine in
- Tauri Native Updater IPC Bridge:
- Implemented commands in
src-tauri/src/commands/updater.rs:check_app_update,download_and_install_apk,install_portable_update, andget_app_version. - Added automatic operating system and distribution detection (
android,windows-portable,windows-x86_64,linux-x86_64,darwin). - Native in-place replacement for portable Windows executables using a staged file, backup rename and rollback attempt, with automatic startup cleanup of lingering
.exe.oldbinaries insrc-tauri/src/lib.rs. - Added sandboxed Android APK download via native Rust HTTPS with mandatory SHA-256 pre-verification before launching system package installer.
- Implemented commands in
- CLI In-Place Self-Updater (
yntra update):- Added CLI subcommand
yntra updateincrates/cli/src/main.rswith--check(query only),-y/--yes(unattended batch upgrade), and--json(machine-readable scripting format). - Implemented Windows-safe running executable replacement (
replace_current_exe): stages and flushes the verified binary before renaming the running executable to.old, with rollback on replacement failure and startup cleanup. - Added non-intrusive terminal tip notification: caches update checks in local user cache (
update_cache.json) for 24 hours, displaying a gentle one-line recommendation tostderrwithout disrupting standard output streams or piped JSON execution. - Dynamic package version reporting via
env!("CARGO_PKG_VERSION").
- Added CLI subcommand
- Frontend Reactive Updater Slice & Settings UI:
- Created state management hook
useUpdaterinsrc/features/updater/useUpdater.tsmanaging update lifecycle (idle,checking,available,downloading,ready,up-to-date,error). - Created glassmorphic
UpdateModalinsrc/features/updater/UpdateModal.tsxfeaturing version diff badges (v0.2.2 → v0.2.3), published dates, release notes preview, and real-time download feedback. - Added "App Updates & Version" section to
src/features/settings/components/GeneralTab.tsxwith current version display, manual "Check for Updates" trigger, and automatic background check toggle (autoCheckUpdates). - Completed missing UI keys in all 24 language catalogs, with 1,087 matching keys and automated parameter checks.
- Created state management hook
- Android APK Direct Package Installation Bridge:
- Added
<uses-permission android:name="android.permission.REQUEST_INSTALL_PACKAGES" />insrc-tauri/android-overrides/AndroidManifest.xml. - Updated build hook
scripts/apply-android-customizations.jsto automatically verify and inject installation permissions into Android platform files on build.
- Added
- CI/CD Universal Release Manifest Generation & Publishing Verification:
- Updated
.github/workflows/release.ymlto automatically generaterelease-assets/latest.jsoncontaining SHA-256 checksums and asset download URLs for all 7 platform release targets, downloading the universal APK to populate exact checksums. - Enhanced
publish-public.ps1(-VerifyAssets) to verify thatlatest.jsonis published and active alongside all 7 multi-platform binaries.
- Updated
Changed
- Share evidence-based Smart Login result assessment between native and CDP observers. Check existing sessions before login, distinguish the selected account from another account, wait for post-password results and report explicit errors/challenges instead of treating missing password fields as success. Unrecognized states remain unconfirmed.
- Subscribe to Smart Login results before starting, reject overlapping attempts, cancel on vault lock and provide localized result messages across all 24 language catalogs.
- General Settings Tab:
- Integrated application update checking card and configurable auto-check preference into
GeneralTab.tsx. - Added
autoCheckUpdatessetting toSettingsContext.tsxdefaulting tofalsewhile preserving saved preferences.
- Integrated application update checking card and configurable auto-check preference into
- Tauri Application Setup:
- Registered updater IPC commands in
src-tauri/src/lib.rsinvoke handler.
- Registered updater IPC commands in
- Segregated HTTP Client Timeouts:
- Differentiated network timeouts: 15-second timeout for lightweight manifest queries and 300-second (5 min) extended timeout for large binary package downloads to prevent premature disconnects on standard connections.
Fixed
- Android launcher icon: Use a bright white mark on a charcoal background, reduce the adaptive foreground by approximately 22%, and provide matching round/legacy launcher resources so the mark has more room inside phone icon masks.
- Preserve existing vault files and remembered vault paths during portable executable replacement; add a regression against the production replacement function. Restore desktop installer links in the GitHub update-check fallback. Android now opens verified packages through a cache-only FileProvider and rejects mismatched application/signing identities without uninstalling or deleting data.
- Publish update metadata only after all seven required packages are present, with verified SHA-256 checksums. Build the exact requested tag, keep incomplete releases as drafts and prevent overwriting published releases.
- Use a permanent Android signing identity for future updates. Older APKs signed with temporary build keys may reject in-place installation: export and verify a vault backup before any manual migration, and do not uninstall an existing app merely to retry an update.
- Stop GitHub Smart Login from probing profile/repository paths when a session already exists. Recognize closed account menus and GitHub viewer metadata, match saved usernames, stop discovery on existing sessions, and restrict GitHub fallback navigation to its authentication routes. Re-evaluate results across delayed redirects after password/TOTP submission instead of ending on the first unconfirmed frame; preserve explicit account mismatches and challenges.
- Speed up Google account selection: select a unique visible match immediately, advance from a stable non-matching list after 250 ms, and keep a bounded loading fallback for unrecognized lists. Reset observations on navigation and poll active login steps more frequently. An authorized live Brave test completed identifier/password entry and confirmed the selected account; the separate session-reuse test selected its account 766 ms after start.
- Continue Smart Login from an exact account-chooser selection to the password step. Remove email-prefill URL hints, recognize redirected chooser paths, and correctly read Brave's elided address-bar scheme when Google redirect parameters contain nested URLs or email addresses. Bind the newly opened window before acting; unresolved direct password steps fall back to blank sign-in instead of silently stalling.
- Keep Google Smart Login account-specific: reuse the selected account's session, allow adding another account while existing sessions stay signed in, and remove stale numeric account selectors. Require matching account identity before filling a directly opened password step; bound fallback navigation and never retry submitted credentials.
- Bind native keyboard input to the selected CDP document's address as well as the focused field. Reject hidden/read-only fields, ambiguous account evidence and unexpected pages; use explicit MFA evidence before TOTP autofill.
- Restore website icons by default while respecting a saved disabled preference. Wait for the native setting before fetching, retry temporary failures, share requests for identical domains, and discard late results after disabling icons.
- Remove unused Tauri imports in pairing commands. Resolve the local missing-MSVC-linker build blocker through Windows C++ build-tool setup; subsequent native development builds pass without the reported warnings.
- Refresh existing entry details after synchronization, including unchanged timestamps, and discard stale frontend refreshes after locking or switching vaults.
- Merge completed P2P transfers into the current vault instead of replacing its in-memory data. App P2P transfers use temporary encrypted snapshots, captured after peer connection on the listener, to isolate network writes from active vault saves.
- Fetch and authenticate the current WebDAV revision before uploading. Conditional writes use the ETag from the same download response, with bound...
Yntra Vault v0.2.2
Yntra Vault v0.2.2
Added
- P2P Local Network & VPN Warning Modal:
- Implemented
P2pVpnWarningModalmatching the Smart Login modal design system, alerting users before Wi-Fi pairing that active VPN connections block local network (LAN) discovery. - Added "Don't show this warning again" preference persisted to
localStorage(yntra-vault-p2p-vpn-warning-dismissed). - Added flow isolation: closing or canceling the initial VPN notice exits pairing without advancing into "Pair Device via Wi-Fi".
- Added discrete header shield button (
ShieldAlert) and neutral reminder banner inDevicePairingWizardallowing users to review VPN guidance on demand. - Formatted with concise copy and complete translation key parity across Swedish and English.
- Implemented
- Delete Unused Tags Confirmation Modal:
- Created
DeleteUnusedTagsModalmatchingDeleteTagModal1:1 in design, typography, and keyboard safety, preventing accidental bulk deletion when selecting "Delete Unused Tags" from the sidebar context menu. - Supports both single and plural tag previews with color-coded badges, safe default focus on Cancel, Tab cycling, and Escape dismissal.
- Added differentiated toast feedback distinguishing single vs multiple tag deletions.
- Created
- Android Native Camera & WebChromeClient File Chooser Bridge:
- Implemented custom
MainActivity.ktinsrc-tauri/android-overridesoverridingonPermissionRequestto request OS-level runtime camera permissions instead of silently denying WebView access. - Implemented
onShowFileChooserinMainActivity.ktallowing users to pick QR images or photos directly from device galleries or system photo pickers. - Added automated build hook (
scripts/apply-android-customizations.js) integrated intorelease.ymlandpackage.json.
- Implemented custom
- High-Performance Multi-Scale QR Decoder:
- Created
src/utils/qrDecoder.tsfeaturing hardware-acceleratedBarcodeDetectorwith dynamic downscaling (1024px, 640px, 1600px) to decode high-resolution mobile camera captures (12MP–48MP) without memory exhaustion. - Added bidirectional contrast inversion (
inversionAttempts: 'attemptBoth') and adaptive binarization for photos of screens or low-light conditions.
- Created
- Direct Camera Scanner in TOTP / 2FA Setup:
- Integrated
QrScannerModaldirectly intoEntryModal, allowing users to scan 2FA QR codes live from screen or paper without manually typing base32 secrets.
- Integrated
Changed
- Mobile Entry Detail Tag Navigation:
- Updated tag click handler in
PasswordDetailon mobile devices (< 768px) to clearselectedEntrywhen filtering by tag, immediately closing the full-screen detail view and transitioning the user to the filtered entry list.
- Updated tag click handler in
- Android App Sandbox Key Wrapping Preparation:
- Added Android app-sandbox private data paths (
/data/user/0/com.yntravault.app/files,/data/data/com.yntravault.app/files) incrates/crypto/src/tpm.rsfor isolated key wrapping while strictly enforcing Invariant 25 (rejecting insecure/tmppaths). - Explicitly guarded Android biometric unlock against unprompted access in
crates/crypto/src/biometric.rspending active native BiometricPrompt bridge integration, preventing unauthenticated auto-unlock.
- Added Android app-sandbox private data paths (
Fixed
- Ghost Windows Hello / Biometric Prompt on Application Close:
- Resolved issue where closing the window (or minimizing to tray) triggered an unwanted Windows Hello modal over the desktop.
- Added window visibility guards in
Login.tsx(document.hidden,visibilityState !== 'visible') and added listeners to only prompt when the application window is actively restored and focused. - Added
window.is_visible()validation inunlock_vault_biometric(src-tauri/src/commands/auth.rs) to prevent invoking system biometrics when the window is hidden. - Resolved tray restore race condition by resetting
autoBioTriggered.currentref when hidden so focusing/restoring immediately prompts for biometrics.
- Android WebChromeClient Least Privilege:
- Enforced strict
RESOURCE_VIDEO_CAPTUREresource granting inMainActivity.kt, rejecting audio capture and preventing WebView crashes from unrequested OS permissions.
- Enforced strict
- Smart TOTP QR URI Parameter Parsing:
- Added automatic extraction and intelligent prefilling of
title(issuer) andusername(account) when scanning standardotpauth://QR codes inEntryModal, alongside automated base32 space/dash cleaning.
- Added automatic extraction and intelligent prefilling of
- Android WebView Media Stream CSP:
- Added
media-src 'self' blob: data: mediastream:;intauri.conf.jsonto allow live camera feeds in Android WebViews.
- Added
Security
- Android App Sandbox Key Wrapping & Invariant 25 Enforcement:
- Restricted hardware key wrapping paths on Android strictly to internal app-isolated storage directories (
/data/user/0/com.yntravault.app/files,/data/data/com.yntravault.app/files), rejecting world-writable or shared storage locations.
- Restricted hardware key wrapping paths on Android strictly to internal app-isolated storage directories (
- Biometric Prompt Window Visibility & Background Suppression:
- Enforced active window visibility verification (
window.is_visible()) prior to launching native biometric authentication, preventing background or tray-minimized Windows Hello prompt execution.
- Enforced active window visibility verification (
Downloads
- Standard Windows Setup: Yntra.Vault_0.2.2_x64-setup.exe (Recommended desktop installer)
- MSI Installer: Yntra.Vault_0.2.2_x64_en-US.msi (Windows Installer package)
- Portable Executable: Yntra.Vault_0.2.2_portable.exe (Standalone desktop app, runs directly without installation)
- Command-Line Interface (CLI): Yntra.Vault_0.2.2_cli.exe (Terminal tool for PowerShell / CMD scripts)
- Linux AppImage: Yntra.Vault_0.2.2_amd64.AppImage (Universal standalone Linux package)
- Linux Debian Package: Yntra.Vault_0.2.2_amd64.deb (Ubuntu / Debian installer)
- Android APK: Yntra.Vault_0.2.2_universal.apk (Signed universal package for direct Android installation)
Yntra Vault v0.2.1
Yntra Vault v0.2.1
Added
- Multi-Tier Favicon Resolution Pipeline:
- Implemented 4-tier fallback resolution in
crates/core/src/services/favicon.rs: (1) DuckDuckGo Favicon CDN (https://icons.duckduckgo.com/ip3/{domain}.ico) for fast, crisp ICOs, (2) Google s2 API (https://www.google.com/s2/favicons?domain={domain}&sz=64) for broad global coverage, (3) Direct host fallback (https://{domain}/favicon.ico), and (4) Parent/base domain fallback for subdomains without dedicated root icons (e.g.login.live.com->live.com,app.slack.com->slack.com).
- Implemented 4-tier fallback resolution in
- Two-Tier Persistent Favicon Caching:
- Frontend persistent storage in
localStorage(yntra-favicons-cache) caching up to 250 data URIs for instant 0ms startup rendering without IPC or network overhead. - Backend persistent disk caching in OS local cache directories (
LOCALAPPDATA/Yntra Vault/cache/faviconson Windows,~/.cache/yntra-vault/faviconson Unix/macOS) storing fetched data URIs across application restarts.
- Frontend persistent storage in
- Intelligent Title Fallback for Domains:
- Added domain parser fallback extracting domains from entry
titlewhen theurlfield is empty or missing (e.g. entries titledgithub.comorreddit.com).
- Added domain parser fallback extracting domains from entry
- Network Recovery Auto-Retry:
- Registered window
onlineevent listener to automatically clear failure cooldowns and re-fetch missing favicons as soon as poor network connectivity recovers.
- Registered window
Changed
- Concurrency Throttling & Socket Starvation Prevention:
- Enforced bounded concurrency on both frontend (
MAX_CONCURRENT_FETCHES = 4) and backend (tokio::sync::Semaphore::new(6)), preventing network socket exhaustion, DNS timeouts, and UI freezes when rendering vaults with large numbers of items.
- Enforced bounded concurrency on both frontend (
- Streamlined Client P2P Adoption on Login Screen:
- Clicking "Link via P2P" from the vault selection / login screen starts directly at the connection step with the optical QR scanner mode active by default, removing redundant navigation steps.
- In manual PIN mode on the login screen, integrated the master password field directly on the same screen alongside the 6-digit PIN input for seamless adoption.
- Password Input Hygiene & Discrete Tooltips:
- Replaced overflowing sentence placeholder text with standard masked dots (
••••••••••••). - Added accessible
ActionTooltips to password visibility toggle buttons and helper icons inDevicePairingWizard.
- Replaced overflowing sentence placeholder text with standard masked dots (
Fixed
- Favicon Startup Race Condition & Permanent Failure Poisoning:
- Resolved race condition where initial entry rendering queried favicons before
set_external_favicons_enabledcompleted IPC synchronization with Rust, which previously causednullto be permanently cached for all initial entries. - Eliminated permanent
nullcaching: replaced permanent in-memory failure markers with a 30-second transient cooldown (failedCooldowns). - Synced cache invalidation with settings: toggling
externalFaviconsEnabledoff immediately purges both in-memory and disk/localStorage caches, while toggling on dispatches reset events to re-fetch.
- Resolved race condition where initial entry rendering queried favicons before
- Device Pairing Wizard Progress Stepper Misalignment:
- Corrected wizard stepper progress bar to dynamically map over
stepTitles, eliminating the 4th orphaned blank bar and fixing off-center horizontal alignment.
- Corrected wizard stepper progress bar to dynamically map over
- Sidebar Tag Drag-and-Drop Gesture State:
- Eliminated stuck shadow and scale artifacts caused by unbacked inline
whileDragstyles on Framer Motion<Reorder.Item>. - Guarded tag drop commit with initial-vs-final order diffing and deferred backend persistence to prevent mid-gesture layout interruption.
- Replaced global body drag attributes with scoped CSS grab cursor states.
- Eliminated stuck shadow and scale artifacts caused by unbacked inline
Security
- Favicon Concurrency, MIME Validation & SSRF Shield (Invariant 31):
- External favicon downloads strictly respect the
EXTERNAL_FAVICONS_ENABLEDgate (disabled by default in Rust core). - Rate-limited socket usage (
tokio::sync::Semaphore::new(6)in Rust,MAX_CONCURRENT_FETCHES = 4in React) prevents remote denial of service / TCP starvation under high vault entry counts. - Image MIME & magic signature validation: enforces image MIME types and magic headers (PNG, ICO, SVG, WebP, GIF, JPEG) capped at 512 KB, rejecting non-image payloads (such as SPA HTML 200 OK pages) and preventing cache poisoning.
- SSRF & Local Network Shield: drops and rejects loopback, private LAN (
10/8,172.16/12,192.168/16), cloud metadata (169.254.169.254), and internal/anonymity TLDs (.local,.lan,.internal,.home,.corp,.onion,.i2p) from external resolution. - BLAKE3 Cache Key Isolation: hashes domain keys via BLAKE3 for on-disk persistence, eliminating Windows DOS device name collisions (
CON,PRN,AUX,NUL) and avoiding filesystem path traversal.
- External favicon downloads strictly respect the
Downloads
- Standard Windows Setup: Yntra.Vault_0.2.1_x64-setup.exe (Recommended desktop installer)
- MSI Installer: Yntra.Vault_0.2.1_x64_en-US.msi (Windows Installer package)
- Portable Executable: Yntra.Vault_0.2.1_portable.exe (Standalone desktop app, runs directly without installation)
- Command-Line Interface (CLI): Yntra.Vault_0.2.1_cli.exe (Terminal tool for PowerShell / CMD scripts)
- Linux AppImage: Yntra.Vault_0.2.1_amd64.AppImage (Universal standalone Linux package)
- Linux Debian Package: Yntra.Vault_0.2.1_amd64.deb (Ubuntu / Debian installer)
- Android APK: Yntra.Vault_0.2.1_universal.apk (Signed universal package for direct Android installation)
Yntra Vault v0.2.0
Yntra Vault v0.2.0
Added
- Zero-Knowledge Optical QR-Code Device Pairing Protocol (
YQR2):- Implemented an air-gapped, zero-knowledge pairing exchange allowing clients (smartphones, tablets, secondary workstations) to securely pair and adopt vaults without manually typing IP addresses, 6-digit PINs, or master passwords.
- Optical payload uses custom URI scheme (
yntrapair://v2?id=<session_id>&s=<secret_hex>&ip=<ip>&p=<port>&sas=<sas>&name=<name>), encoding a 256-bit CSPRNG ephemeral optical secret, session UUID, host network endpoints, and Short Authentication String (SAS). - Short Authentication String (SAS) visual badge (4-digit decimal confirmation code derived via keyed BLAKE3) displayed concurrently on both host screen and scanner interface for out-of-band visual verification against Active Man-in-the-Middle (MitM) attacks.
- Single-use 90-second ephemeral session TTL with real-time countdown progress indicator and 1-click regeneration.
- Automatic memory zeroization (
zeroize::Zeroizing) of ephemeral optical pre-shared keys, transit encryption keys, and adopted credentials immediately following session completion.
- Embedded Camera QR Scanner with Dual-Engine Optical Fallback:
- Built high-performance in-app camera viewfinder modal (
QrScannerModal) utilizing browser-nativeBarcodeDetectorwhere hardware-accelerated, with seamless fallback tojsQRcanvas raster scanning. - Real-time animated scanning beam, camera switcher (front/rear lens selection), flash/torch detection, and local image file drag-and-drop / picker fallback for environments lacking direct webcam access.
- Discrete visual feedback upon successful optical capture.
- Built high-performance in-app camera viewfinder modal (
- Seamless 1-Click Biometric Enrollment on Adopted Devices:
- Optional transit master password transfer encrypted end-to-end under the ephemeral optical key (
XChaCha20-Poly1305+ dynamic sessionAAD), enabling mobile and desktop clients to enroll directly into hardware biometrics (Touch ID, Face ID, Android Keystore, Windows Hello) immediately upon adopting a vault without manual master password entry. - Master password in volatile memory is cleared and zeroized immediately after biometric key envelope creation.
- Optional transit master password transfer encrypted end-to-end under the ephemeral optical key (
- Unified Tabbed Device Pairing Interface:
- Re-architected
DevicePairingWizardwith a sleek segmented mode switcher:QR-kod (Snabbast)as the modern optical default, alongside6-siffrig PINas the manual fallback. - Discrete monochrome SVG QR code renderer (
QrCodeView) adhering strictly to the design system geometry (rounded-[3px], semantic theme tokens). - Synchronous 4-digit SAS verification badge displayed during connection and success states on both host and client screens.
- Re-architected
- Manual Password Adoption Fallback & IPC Command:
- Added safe adoption flow for vaults adopted without an optical password (
include_password: false): client saves into a dedicated.vdbfile and prompts user to verify the existing master password. - Added
complete_adopted_vaultTauri IPC command to finalize and verify adoption without leaking secrets across the webview bridge.
- Added safe adoption flow for vaults adopted without an optical password (
- Date-Section Grouping for Password Entries (
groupByDate):- Added structured chronological section headers ("Idag", "Igår", "Tidigare" / "Today", "Yesterday", "Earlier") when sorting entries by updated or created date.
- Added a dedicated setting toggle in
GeneralTab(settings.group_by_date) and a quick-toggle option directly in the list area context menu (menu.group_by_date). - Enhanced sort order fallback logic to cleanly handle entries with missing timestamps.
- Refined Smart Login & Autotype Tooltips & Disabled States:
- Replaced abrupt button hiding with a discrete disabled button and helpful localized tooltips (
smart_login.disabled_tooltip,context_menu.autotype_no_url_tooltip) when an entry lacks a website URL or application target. - Added localized helper descriptions for hardware key enrollment and challenge verification (
hw.enroll_desc,hw.test_desc).
- Replaced abrupt button hiding with a discrete disabled button and helpful localized tooltips (
Security
- Zero-IPC Master Password Leakage Invariant:
- Master passwords provisioned during adoption are held exclusively inside
zeroize::Zeroizingbuffers within Rust TauriAppState.pending_adopted_vault. Plaintext credentials are NEVER serialized or transmitted across the Tauri IPC boundary to webview JavaScript or V8 heap (receivedMasterPasswordcompletely eliminated from React state). - Hardware biometrics wrap credentials directly in native memory (TPM 2.0 / DPAPI / Secure Enclave), and RAM is purged immediately upon completion.
- Master passwords provisioned during adoption are held exclusively inside
- Dynamic Session AAD Binding:
- Transit AEAD payload encryption (
XChaCha20-Poly1305) binds dynamic Additional Authenticated Data (format!("yntra-qr-transit-v2:{}", session_id)), cryptographically binding every encrypted packet to the unique session UUID and eliminating cross-session replay or payload injection attacks.
- Transit AEAD payload encryption (
- Protocol
YQR2Mutual Pre-Authentication Handshake:- Employs mutual HMAC challenge-response verification (68-byte client request, 48-byte host response) using dedicated
client_to_hostandhost_to_clientsubkeys derived viaHKDF-SHA512over the 256-bit optical CSPRNG secret. - Unauthenticated peers or network scanners are rejected immediately before any vault metadata or payload is exposed, closing unauthenticated password and sync oracles.
- Employs mutual HMAC challenge-response verification (68-byte client request, 48-byte host response) using dedicated
- Non-Destructive Adoption & Collision Avoidance (
AdoptIntoDir):- Client QR adoption uses
ClientPairingMode::AdoptIntoDir, adopting into a collision-free file (<HostVaultName>.vdb,<HostVaultName> (1).vdb) in the user's vaults directory, guaranteeing that existing vaults on disk are never overwritten, unpersisted, or corrupted.
- Client QR adoption uses
- 256-Bit CSPRNG Optical Pre-Shared Secrets & Out-of-Band Transit Isolation:
- The QR code contains zero plaintext passwords, database payloads, or long-term private keys. All Wi-Fi traffic is encrypted using
XChaCha20-Poly1305AEAD with subkeys derived viaHKDF-SHA512bound to the optical pre-shared secret. - Eavesdroppers on the local Wi-Fi network who observe network packets cannot decrypt the transit payload without optical line-of-sight to the host screen.
- The QR code contains zero plaintext passwords, database payloads, or long-term private keys. All Wi-Fi traffic is encrypted using
Changed
- P2P Discovery & Sync Engine Extensibility:
- Modularized pairing protocol functions (
run_p2p_qr_pairing_host,run_p2p_qr_pairing_client,derive_qr_pairing_subkeys,compute_qr_sas_code,complete_adopted_vault_save) incrates/core/src/services/sync/pairing.rs. - Updated desktop Tauri IPC commands and state management to support concurrent cancelable QR pairing background threads and pending adopted vault storage.
- Modularized pairing protocol functions (
- IPC Contract Hardening:
- Updated
QrClientPairingResultinsrc/types/ipc.ts,crates/core, andsrc-tauri: replaced sensitivemaster_passwordfield withhas_master_password: bool,needs_password: bool, andsas_code: String.
- Updated
- Localization Parity & Comprehensive Fallbacks:
- Added
'pairing.manual_adopt_title','common.retry','hw.enroll_desc', and'hw.test_desc'toen.tsandsv.ts. - Propagated complete translation coverage and fallbacks across all 24 supported language dictionaries.
- Added
Downloads
- Standard Windows Setup: Yntra.Vault_0.2.0_x64-setup.exe (Recommended desktop installer)
- MSI Installer: Yntra.Vault_0.2.0_x64_en-US.msi (Windows Installer package)
- Portable Executable: Yntra.Vault_0.2.0_portable.exe (Standalone desktop app, runs directly without installation)
- Command-Line Interface (CLI): Yntra.Vault_0.2.0_cli.exe (Terminal tool for PowerShell / CMD scripts)
- Linux AppImage: Yntra.Vault_0.2.0_amd64.AppImage (Universal standalone Linux package)
- Linux Debian Package: Yntra.Vault_0.2.0_amd64.deb (Ubuntu / Debian installer)
- Android APK: Yntra.Vault_0.2.0_universal.apk (Signed universal package for direct Android installation)
Yntra Vault v0.1.9
Yntra Vault v0.1.9
Added
- Symmetrical Key File Generation in Master Password Rekeying:
- Added option to generate a brand-new cryptographically secure
.keyfile or select an existing one directly inChangeMasterPasswordModal. - Integrated
saveFileDialogandbackend.generateKeyFileto safely write random 32-byte key files with strict permissions prior to cryptographic subkey derivation and re-encryption.
- Added option to generate a brand-new cryptographically secure
- CLI Key File Generation & Initialization:
- Added
--gen-keyfile <PATH>option toyntra init, allowing new vaults to be initialized and bound to a fresh 32-byte keyfile in a single step. - Added
--keyfile <PATH>toyntra generateto create standalone cryptographically secure 32-byte keyfiles directly from the terminal.
- Added
- Global Appearance Configuration in SettingsProvider:
- Implemented root-level propagation of user-selected
fontSizeanddata-densityattributes directly insideSettingsProvider, ensuring consistent UI typography and density across Login, Onboarding, and Vault Selection screens.
- Implemented root-level propagation of user-selected
- Comprehensive Window & Modal Aesthetic Harmonization:
- Standardized all application modals and dialogs (
DeleteEntryModal,DeleteTagModal,CreateTagModal,EditTagModal,EntryModal,BulkEditModal,AppPickerModal,AttachmentPreviewModal,SmartLoginModal,Hardware2FaModal,BackupTabmanual IP modal,DeleteTrashModal,ImportModal,CreateVaultModal, andChangeMasterPasswordModal) to strictly match the clean, discrete monochrome geometry ofDevicePairingWizard(P2P window) andOnboarding(first-run setup window). - Enforced
rounded-[3px]geometry,border border-[var(--border)],bg-[var(--bg-elevated)]body, andbg-[var(--bg-surface)]header styling uniformly across all modals. - Standardized modal headers with discrete
h-7 w-7icon badge containers (rounded-[3px] border border-[var(--border)] bg-[var(--bg-base)] text-[var(--text-secondary)]) and clean monochrome close/cancel/confirm action buttons. - Eliminated all colorful badges, saturated buttons, and harsh borders (emerald, green, amber, red, purple, blue) across
AttachmentPreviewModal,SmartLoginModal,TOTPDisplay,ImportModal,Loginemergency recovery,VaultSelectwarning and badges, andSecurityDashboardStatCard summary cards. - Replaced hardcoded color tokens with semantic dark/light theme variables (
var(--border),var(--bg-base),var(--bg-elevated),var(--text-secondary),var(--text-primary),var(--destructive)).
- Standardized all application modals and dialogs (
- Structured Rekey Wizard in Change Master Password:
- Implemented a 2-step verification and configuration flow in
ChangeMasterPasswordModal(Step 0: current credentials verification; Step 1: new credentials, strength score, and keyfile options). - Integrated a discrete 5-segment monochrome password strength meter using semantic theme tokens (
var(--text-primary),var(--border-subtle)), eliminating saturated multi-colored bars.
- Implemented a 2-step verification and configuration flow in
Security
- Empty (0-Byte) Key File Rejection:
- Enforced strict non-zero validation in
read_key_file_safely(crates/core/src/vault/manager.rs), preventing empty files from being accepted as keyfiles which would otherwise silently degrade to password-only derivation.
- Enforced strict non-zero validation in
- Git Credential Helper Phishing Hardening & Strict Domain Boundary Isolation:
- Implemented strict host and subdomain boundary matching (
host == domain || host.ends_with(&format!(".{domain}"))), preventing cross-domain substring phishing attacks (e.g.evilgithub.comorgithub.com.attacker.commatchinggithub.com). - Hardened
normalize_hostandextract_domain_stemagainst URLs containing user credentials (user@,user:token@), custom ports, paths, and query fragments, ensuring correct host extraction. - Restricted title-based heuristic matching to entries without explicit URLs, preventing domain mismatch bypasses.
- Implemented strict host and subdomain boundary matching (
- Unix Socket Path Hardening & IPC Inactivity Auto-Lock Parity:
- Enforced strict
0700permissions (0o700) on fallback Unix socket directories under/tmpwhen$XDG_RUNTIME_DIRand$HOMEare unset. - Aligned background inactivity timeout (15-minute idle) with explicit lock:
mgr.lock()purges sensitive vault settings, search tokens, and keys from RAM,clear_clipboard()purges system clipboard, the Unix socket file is unlinked, and session tokens are invalidated.
- Enforced strict
- Secure File Permissions for Plaintext Exports (CSV / JSON):
- Added
write_sensitive_file_safelycreating export files with atomic0o600permissions on Unix and reapplyingset_permissions(0o600)to ensure sensitive decrypted exports cannot be read by other local OS users. - Maintained formula injection sanitization (CWE-1236) across CSV cell values.
- Added
- Atomic Linux Wrap-Key Acquisition & Complete TOCTOU Elimination:
- Eliminated the
exists()TOCTOU race condition inlinux_get_or_create_wrap_key. Key files are read directly, or created atomically usingOpenOptions::create_new(true).mode(0o600), safely handling concurrent initializations without file replacement windows.
- Eliminated the
- Blinded Audit Key Zeroization & Zero-Allocation Strength Analysis:
- Directly initialized ephemeral 32-byte BLAKE3 blinding keys into
zeroize::Zeroizing::new([0u8; 32])withfill_bytes(&mut *ephemeral_key), leaving zero unzeroized plaintext key copies on the stack. - Replaced intermediate
Vec<u8>plaintext password heap allocations with zero-allocation borrowed string slices (std::str::from_utf8(&pwd_bytes)) for real-time strength analysis.
- Directly initialized ephemeral 32-byte BLAKE3 blinding keys into
- Smart Login TOTP CDP Injection Escaping:
- Serialized one-time password characters via
serde_json::to_stringbefore dispatching to Chromium CDP JavaScript evaluation, preventing string breakout and script injection.
- Serialized one-time password characters via
Changed
- Change Master Password Modal Geometry & Vertical Compaction:
- Eliminated artificial
min-h-[300px]andjustify-betweenon the modal body container inChangeMasterPasswordModal, reducing vertical footprint by ~45% and eliminating empty void spacing. - Standardized modal width to
max-w-[420px]to matchCreateVaultModalandOnboarding. - Added structured sub-header divider (
border-b border-[var(--border-subtle)] bg-[var(--bg-base)]/40) under the stepper progress bar for clean separation from form fields.
- Eliminated artificial
- Discrete Monochrome Theme Harmony:
- Replaced colorful badges, saturated buttons, and harsh red/rose/amber styling across
BackupTab,TrashTab,SecurityTab,KeybindsTab,DeleteTrashModal, andImportModalwith consistent dark-mode tailored tokens (var(--border),var(--bg-elevated),var(--text-secondary)).
- Replaced colorful badges, saturated buttons, and harsh red/rose/amber styling across
- Git Credential Helper Exact Domain Precedence:
- Prioritized exact domain matches (
160points) over subdomain matches (140points) inscore_entry_match, ensuring specific credentials (e.g.gist.github.com) win deterministically over generic parent domain credentials.
- Prioritized exact domain matches (
- Bloom Filter Test Isolation:
- Converted
test_generate_and_populate_bloom_filterto in-memory bit validation, preventing test runs from modifying or dirtyingcrates/core/data/bloom.binon disk.
- Converted
- Idiomatic Rust & Clippy Zero-Warning Hygiene:
- Cleaned up manual implementations of
div_ceil, unnecessary mutable bindings, redundant reference dereferences, and collapsible conditionals across all 4 workspace crates (yntra-crypto,yntra-vault-core,yntra-cli,src-tauri), compiling cleanly under-D warnings.
- Cleaned up manual implementations of
- Smooth SPA Navigation for Setup Wizard Rerun:
- Replaced hard
window.location.hrefassignment with React Routernavigate('/setup')inGeneralTab, avoiding uncoordinated hash reloads.
- Replaced hard
- Storage Footprint Metric Localization:
- Removed hardcoded unit suffix (
" st") inTrashTabstorage footprint display in favor of clean universal count notation.
- Removed hardcoded unit suffix (
Fixed
- Mobile Touch Scrolling & Momentum Gestures:
- Resolved missing, clipped, and unresponsive touch scrolling across mobile and Android release builds, specifically fixing the entry list in
PasswordList. - Fixed parent flex container height collapse in
AppLayout.tsxon mobile wherePasswordList'sh-fullwas treated as indefinite and clipped byoverflow: hidden. - Removed synthetic
onTouchStart,onTouchMove, andonTouchEndevent hijacking onListItem, allowing the Android WebView touch compositor thread to immediately recognise vertical kinetic scroll gestures without dead zones. - Added
shrink-0to list sections and items, preventing flexbox compression from collapsing the scrollable boundary. - Replaced global
* { touch-action: manipulation; }with targeted interactive element selectors, and added.overflow-y-auto * { touch-action: pan-y; }to guarantee buttons inside lists never block kinetic scrolling. - Removed
user-select: none(select-none) from scrollable root containers and modal backdrops, preventing Chromium WebView from misinterpreting touch drags as text selection intents. - Added
-webkit-overflow-scrolling: touch,overscroll-behavior: contain, andtouch-action: pan-y / pan-xacross all scrollable views (PasswordList,PasswordDetail,SettingsPanel,Login,VaultSelect,Onboarding). - Added flex-column
min-h-0constraints and eliminated double-nested scroll collisions on mobile detail views. - Standardized all 13 application modals with responsive overlay scrolling, viewport height clamping (
max-h-[calc(100dvh-1.5rem)]), and safe-area insets to prevent clipping on mobile screens and when virtual keyboards open. - Decoupled
MobileBottomSheetdrag gestures usinguseDragControlsactivated exclusively from the drag handle, allowing sheet inner content to scroll freely without accidental sheet dismissals.
- Resolved missing, clipped, and unresponsive touch scrolling across mobile and Android release builds, specifically fixing the entry list in
- Mobile & Desktop Launcher Icon Ergonomics & Android Adaptive Sizing:
- Fixed an issue where the application icon appeared massively oversized and clipped on Android home screens and desktop shortcu...
Yntra Vault v0.1.8
Yntra Vault v0.1.8
Added
- Dedicated Pairing Port (Port 5324) & Port Collision Separation:
- Separated zero-knowledge device pairing onto dedicated port
5324(DEFAULT_PAIRING_PORT), eliminating port collisions with continuous background Wi-Fi synchronization on port5322. - Added resilient fallback port traversal (
5324->5325->5322) during device pairing connections. - Added automatic pause and resumption of the background Wi-Fi sync listener during device pairing sessions to prevent socket contention.
- Separated zero-knowledge device pairing onto dedicated port
- Collision-Safe Adopt Flow on Unauthenticated Clients:
- Implemented safe vault adoption (
ClientPairingMode::AdoptIntoDir) when pairing from an unauthenticated client instance (VaultSelect), saving remote salt and entries into isolated non-colliding files without touching existing local vaults.
- Implemented safe vault adoption (
- Active UDP Query-Response P2P Discovery Protocol (
YQRY/YPAR):- Implemented active bidirectional query-response discovery for instant LAN peering (<50ms). Clients actively pulse
YQRYqueries; hosts respond with direct unicastYPARbeacons to the client's address, bypassing router broadcast suppressions and AP isolation.
- Implemented active bidirectional query-response discovery for instant LAN peering (<50ms). Clients actively pulse
- Multi-Interface Local Network Enumeration & Subnet Directed Broadcast:
- Added
get_local_lan_ipsprobing all active network adapters (Ethernet, Wi-Fi, virtual adapters) via host name resolution and gateway route tests. Discovery packets are broadcast simultaneously across255.255.255.255, RFC 2365 administratively scoped multicast (239.255.53.23), and directed subnet broadcasts (x.y.z.255:5323) for every active interface.
- Added
- Timing-Safe Constant-Time Network Beacon Verification:
- Hardened discovery beacon and query verification with
subtle::ConstantTimeEqacross all UDP listener endpoints.
- Hardened discovery beacon and query verification with
- Fast-Timeout Candidate Port Probing with Pre-UDP Ping:
- Optimized TCP connection establishment in pairing and P2P sync clients with parallel fallback ports
[5324, 5322, 5325]and a 350ms connect timeout, preceded by direct UDP reachability verification.
- Optimized TCP connection establishment in pairing and P2P sync clients with parallel fallback ports
- Strict Trusted Device Deduplication:
- Enforced dual-tier deduplication by UUID and case-insensitive
(name, os)pairs during device registration, pairing, and CRDT synchronization.
- Enforced dual-tier deduplication by UUID and case-insensitive
- Pairing UI & Host IP Multi-Interface Ergonomics:
- Added one-click IP copy buttons, alternate interface IP selector badges, one-click autofill for the last paired peer IP, and a seamless in-wizard re-synchronization action.
- Immediate Host Pairing Cancellation (
cancel_pairing_host):- Added atomic cancellation support (
pairing_cancel: Arc<AtomicBool>) and exposed Tauri commandcancel_pairing_host, immediately unbinding TCP port 5324 and UDP discovery sockets within 40ms when the user cancels or closes the pairing wizard.
- Added atomic cancellation support (
- Real-Time IPv4 Auto-Dot & Local Hostname Formatter:
- Implemented automatic octet dot insertion, boundary clamping, local hostname support (
localhost,*.local), and port sanitization (formatIpv4Input) with unit test coverage.
- Implemented automatic octet dot insertion, boundary clamping, local hostname support (
- Host Network Adapter Enumeration Caching:
- Implemented adapter IP caching in
broadcast_pairing_beacon_with_ips, throttling adapter enumeration to every 10 seconds and eliminating UDP socket churn during pairing.
- Implemented adapter IP caching in
- Repeat Adoption Collision Guard:
- Preserved newly adopted vault paths in
adoptedVaultPathRefduring active pairing wizard sessions, preventing duplicate<Vault> (1).vdbcreation on subsequent in-wizard syncs ("Sync Again").
- Preserved newly adopted vault paths in
- Comprehensive Wi-Fi & Auto-Sync Notifications:
- Added in-app toasts and native desktop notifications (
sendDesktopNotificationvia@tauri-apps/plugin-notification) for both client discovery auto-sync and incoming peer connections as host, informing users when sync completes, passwords update, or vaults are already in sync.
- Added in-app toasts and native desktop notifications (
- Minimalist Monochrome Pairing Wizard & Stepper Redesign:
- Redesigned the Device Pairing Wizard (
DevicePairingWizard.tsx) to match the exact aesthetic of the first-time setup window (Onboarding.tsx), utilizing segmented horizontal progress bars (h-1 rounded-full), cleanrounded-[3px]elevated borders, and a minimal 420px width. - Replaced colored accents and green status elements with consistent monochrome palette variables (
var(--text-primary),var(--border),var(--bg-elevated)). - Standardized English defaults across in-code strings and added complete localization keys in
en.tsandsv.tsfor pairing steps, role descriptions, hints, and sync notices.
- Redesigned the Device Pairing Wizard (
Changed
- Progressive Multi-Step Pairing Wizard:
- Redesigned
DevicePairingWizard.tsxinto a calm, focused multi-step workflow with visual stepper progress breadcrumbs (1. Password➔2. Pairing PIN➔3. Synchronize), separating master password verification from 6-digit PIN entry and eliminating visual clutter. - Added auto-focus and Enter key progression on the password step, and auto-focus with clipboard paste distribution on the 6-digit PIN inputs.
- Displayed resolved host pairing IP and dedicated port (
<ip>:5324) on the host screen.
- Redesigned
Security
- Unauthenticated Client Adopt Mode Isolation:
- Enforced strict session authentication checks in
start_pairing_client: clients pairing from theVaultSelectscreen or locked states operate exclusively inClientPairingMode::AdoptIntoDir. - Prohibited unauthenticated background decryption or transmission of local
.vdbfiles on disk when pairing from logged-out states. - Adopted vaults are written to dedicated, collision-resistant filenames derived from the host vault's metadata name (
<HostVaultName>.vdb,<HostVaultName> (1).vdb), completely eliminating silent overwriting of unrelated local vaults.
- Enforced strict session authentication checks in
- P2P Discovery In-Loop Self-Echo Filtering:
- Relocated local LAN IP and loopback filtering directly inside the packet receive loop of
listen_discovery_beacon, ensuring discovery listeners do not short-circuit on their own UDP broadcast reflections and allowing remote LAN peers to be discovered reliably.
- Relocated local LAN IP and loopback filtering directly inside the packet receive loop of
- IPv4 LAN Prioritization & IPv6 Link-Local Isolation:
- Excluded un-routable IPv6 link-local (
fe80::/10) and multicast addresses fromis_valid_lan_ip, ensuringget_local_lan_ips()andget_local_lan_ip()prioritize valid, reachable IPv4 addresses on multi-homed interfaces.
- Excluded un-routable IPv6 link-local (
- Windows DOS Reserved Filename Sanitization:
- Hardened
sanitize_vault_filenameagainst reserved Windows device names (CON,PRN,AUX,NUL,COM1-9,LPT1-9) during client adopt mode database initialization.
- Hardened
Fixed
- P2P LAN Discovery Blind Spot (Self-Echo):
- Fixed a critical issue where
listen_discovery_beaconreceived its own beacon and terminated the discovery process before remote devices could reply.
- Fixed a critical issue where
- Host Pairing TCP/UDP Port Hang:
- Fixed an issue where closing or cancelling the pairing wizard left TCP port 5324 and UDP port 5323 bound for up to 180 seconds, blocking subsequent pairing attempts.
- IPv6 Link-Local Address Presentation:
- Fixed an issue on Windows where link-local
fe80::addresses were displayed as the host's primary pairing IP, causing connection failures when entered into clients.
- Fixed an issue on Windows where link-local
- Duplicate Vault Accumulation on Re-Sync:
- Fixed an issue where clicking "Sync Again" after adopting a vault created duplicate incremental database files on disk (
<Name> (1).vdb).
- Fixed an issue where clicking "Sync Again" after adopting a vault created duplicate incremental database files on disk (
Downloads
- Standard Windows Setup:
Yntra.Vault_0.1.8_x64-setup.exe(Recommended desktop installer) - MSI Installer:
Yntra.Vault_0.1.8_x64_en-US.msi(Windows Installer package) - Portable Executable:
Yntra.Vault_0.1.8_portable.exe(Standalone desktop app, runs directly without installation) - Command-Line Interface (CLI):
Yntra.Vault_0.1.8_cli.exe(Terminal tool for PowerShell / CMD scripts) - Linux AppImage:
Yntra.Vault_0.1.8_amd64.AppImage(Universal standalone Linux package) - Linux Debian Package:
Yntra.Vault_0.1.8_amd64.deb(Ubuntu / Debian installer) - Android APK:
Yntra.Vault_0.1.8_universal.apk(Signed universal package for direct Android installation)
Yntra Vault v0.1.7
Yntra Vault v0.1.7
Added
- Independent Multi-Platform Release Distribution:
- Automated CI release packaging for Linux (
.AppImage,.deb), Android (signed universal.apk), and Windows (.exesetup,.msi, portable.exe, standalone CLI). - Implemented automated Android release signing via
jarsignerwith release keystore generation.
- Automated CI release packaging for Linux (
- Standalone Windows Portable & CLI Executables:
- Published self-contained single-executable portable desktop bundle (
Yntra.Vault_0.1.7_portable.exe) running without installation or administrator rights. - Published standalone command-line interface executable (
Yntra.Vault_0.1.7_cli.exe) for terminal workflows and automated scripting.
- Published self-contained single-executable portable desktop bundle (
- Unified Trusted Devices Architecture:
- Implemented persistent device pairing registry in
VaultSettings.trusted_deviceswith device UUID, human-readable name, OS badge, hardware type, and sync timestamps. - Added mutual device metadata exchange during 6-digit PIN handshake (
DeviceInfo,resolve_local_device_info). - Added host-side device session revocation (
revoke_trusted_device), actively expelling unapproved devices from the encrypted.vdbsettings payload. - Added cryptographic revocation rejection signal (
P2P_REVOKED_SIG), immediately closing connections from revoked devices and prompting the client to re-pair. - Added continuous, code-free background auto-synchronization for paired devices on local Wi-Fi.
- Implemented persistent device pairing registry in
- Zero-Knowledge UDP Discovery Beacon (Port 5323):
- Added zero-knowledge discovery beacon exchange via BLAKE3 keyed hash tokens (
compute_pairing_beacon_id,compute_p2p_discovery_id) for automatic LAN discovery without manual IP entry.
- Added zero-knowledge discovery beacon exchange via BLAKE3 keyed hash tokens (
- Zero-Vault Adopt Flow on New Clients:
- Added automatic standard vault file initialization (
Documents/YntraVault/yntra-vault.vdb) when pairing from an uninitialized client instance, adopting remote salt and entries seamlessly.
- Added automatic standard vault file initialization (
- Trusted Devices Management UI:
- Added trusted devices section in Settings > Backup (
BackupTab.tsx) with device type icons, OS labels, pairing dates, last sync timestamps, and per-device disconnect ("Koppla från") action. - Added single unified toggle for background Wi-Fi synchronization.
- Added trusted devices section in Settings > Backup (
Changed
- 6-Digit PIN Pairing Wizard UX:
- Upgraded PIN input in
DevicePairingWizard.tsxto 3+3 triplet layout with clipboard paste (Ctrl+V) distribution and Enter key submission. - Replaced native browser checkboxes with standardized
<Toggle />components across pairing and backup settings. - Refined action button margins and text container padding to eliminate viewport clipping.
- Upgraded PIN input in
Security
- P2P Transit AEAD Encryption (Defense-in-Depth):
- Encrypted all database network payloads over TCP with XChaCha20-Poly1305 AEAD (
P2P_TRANSIT_AAD) usingsubkeys.vault_key, maintaining transparent backward compatibility for unencrypted legacy payloads.
- Encrypted all database network payloads over TCP with XChaCha20-Poly1305 AEAD (
- Zero-Knowledge Salt Commitment (P2P Handshake):
- Replaced plaintext Argon2id root salt transmission over TCP with a 32-byte keyed BLAKE3 commitment (
compute_salt_commitment), verifying vault compatibility early without disclosing the root salt.
- Replaced plaintext Argon2id root salt transmission over TCP with a 32-byte keyed BLAKE3 commitment (
- Argon2id-Hardened Pairing Discovery Beacon:
- Replaced fast un-salted BLAKE3 PIN hashing with Argon2id-derived pairing subkeys (
compute_pairing_beacon_id_from_subkeys,compute_pairing_beacon_id), preventing LAN eavesdroppers from conducting offline dictionary attacks against 6-digit PINs.
- Replaced fast un-salted BLAKE3 PIN hashing with Argon2id-derived pairing subkeys (
- Encrypted Host Root Salt in Pairing:
- Encrypted the host pairing response payload (
PairingHostPayload) using XChaCha20-Poly1305 AEAD (PAIRING_AAD_HOST) keyed with pairing subkeys, eliminating plaintext Argon2id salt transmission during initial device pairing.
- Encrypted the host pairing response payload (
- Device Revocation & Nil-UUID Rejection:
- Enforced strict revocation checks rejecting
Uuid::nil()or unlisted client devices withP2P_REVOKED_SIGwhen trusted devices are configured. Boundclient_device_uuiddirectly into the client's mutual HMAC signature.
- Enforced strict revocation checks rejecting
- Volatile Memory Zeroization in P2P & Pairing:
- Wrapped all decrypted and merged database buffers in
zeroize::Zeroizing<Vec<u8>>acrosscrates/core/src/services/sync/mod.rsandcrates/core/src/services/sync/pairing.rs.
- Wrapped all decrypted and merged database buffers in
- Frontend Ephemeral Password Zeroing:
- Added unconditional state zeroization (
setPassword(''),setInputDigits(...)) on modal close, completion, and unmount inDevicePairingWizard.tsx.
- Added unconditional state zeroization (
- LAN Discovery Self-Echo Suppression:
- Added loopback and local LAN IP filtering in
scan_p2p_discovery(src-tauri/src/commands/sync.rs), preventing desktop instances from discovering and attempting to sync with their own listeners.
- Added loopback and local LAN IP filtering in
- P2P Handshake Timing and Asymmetry Hardening:
- Replaced dynamic length rejection responses with uniform 64-byte
P2P_AUTH_FAILED_SIGand constant-time verification (subtle::ConstantTimeEq), preventing client panics and timing side-channels.
- Replaced dynamic length rejection responses with uniform 64-byte
- Root Salt Mismatch Enforcement:
- Enforced mutual root salt checks (
P2P_SALT_MISMATCH_MARKER) early in the handshake phase before decrypting or processing remote payloads.
- Enforced mutual root salt checks (
- Constant-Time Hardware 2FA Comparison:
- Replaced non-constant-time byte comparison in
enable_hardware2fa_with_password()withsubtle::ConstantTimeEq(ct_eq), closing a timing side-channel during Hardware 2FA enrollment.
- Replaced non-constant-time byte comparison in
- Session Token Path & Storage Hardening:
- Unified Windows session token location between CLI (
yntra-cli) and core (yntra-crypto) to%LOCALAPPDATA%/Yntra Vault/session.token. - Removed plaintext fallback to ensure session tokens are strictly encrypted via App-Bound DPAPI / BLAKE3.
- Unified Windows session token location between CLI (
- In-Memory Transit Secret Scrubbing:
- Wired
clearSessionSecrets()to thevault-connection-lostevent inAuthContext, ensuring transit import and sync credentials in volatile memory are immediately wiped on disconnect.
- Wired
- Key File POSIX Permission Hardening:
- Enforced POSIX file mode
0o600(read/writeowner-only) and filesystem sync (sync_all()) on newly generated key files inrekey.rs.
- Enforced POSIX file mode
- KDF Lower Bound Alignment:
- Normalized Argon2id lower resource bounds to 64 MB (
65_536 KB) and 2 iterations across core validation logic, architecture specifications, and agent guidelines.
- Normalized Argon2id lower resource bounds to 64 MB (
Fixed
- Linux Key Wrapping Enum Variant:
- Corrected wrap key failure mapping in
linux_get_or_create_wrap_key(crates/crypto/src/tpm.rs), returningVaultError::TpmErrorinstead of invalid enum variants.
- Corrected wrap key failure mapping in
- 32-Bit Linux & Android Memory Limit Arithmetic:
- Fixed integer overflow and type mismatch in
crates/crypto/src/mem.rsby casting allocations tolibc::rlim_twith saturating addition, ensuring compatibility with 32-bit Android architectures (armv7-linux-androideabi,i686-linux-android).
- Fixed integer overflow and type mismatch in
- Cross-Platform Window Handle Gating:
- Gated Win32-specific window handle retrieval (
window.hwnd()) behind#[cfg(target_os = "windows")]insrc-tauri/src/lib.rs,src-tauri/src/commands/tools.rs, andsrc-tauri/src/commands/auth.rs, with safe non-Windows fallbacks.
- Gated Win32-specific window handle retrieval (
- Desktop-Only Window Configuration Gating:
- Gated
window.set_always_on_top()behind#[cfg(desktop)]insrc-tauri/src/commands/auth.rsto ensure clean compilation on Android and mobile targets.
- Gated
- Host Device Authorization Fail-Closed Enforcement:
- Replaced silent error absorption (
if let Ok(...)) during local vault read/decryption in P2P handshake with strict error propagation (SyncError), ensuring connections fail-closed if the trusted devices registry cannot be verified.
- Replaced silent error absorption (
- Authoritative Trusted Devices Re-Sync:
- Adopted host's authoritative
trusted_deviceslist on the client during return synchronization, automatically propagating newly paired or revoked devices across all client vaults.
- Adopted host's authoritative
- P2P Socket Interface Binding:
- Switched default sync listener binding from loopback (
127.0.0.1) to all interfaces (0.0.0.0:5322), enabling cross-device mobile connections on local LANs.
- Switched default sync listener binding from loopback (
- Listener and Client Connection Hangs:
- Implemented non-blocking socket handling with bounded timeouts in
run_p2p_sync_listenerto prevent indefinite background thread lockups. - Replaced unbounded
TcpStream::connectwithconnect_timeout(2s) inrun_p2p_sync_client.
- Implemented non-blocking socket handling with bounded timeouts in
- Sync Tag and State Desynchronization:
- Synchronized
refreshTags()alongsiderefreshEntries()upon all P2P and WebDAV merge operations.
- Synchronized
- macOS Native Clipboard Argument Passing:
- Replaced broken
cat /dev/stdinAppleScript pipe withon run argvscript arguments incrates/crypto/src/clipboard.rs, resolving empty string returns during clipboard operations on macOS.
- Replaced broken
- Mobile Safe Area & Notch Layout:
- Added
viewport-fit=cover,maximum-scale=1.0, anduser-scalable=noto the viewport meta tag inindex.htmlfor proper edge-to-edge rendering and zoom prevention. - Separated top safe-area padding (
env(safe-area-inset-top)) from header height in the mobile detail view (AppLayout.tsx), preventing squashed headers on devices with Dynamic Island or notch.
- Added
- Mobile Bottom Navigation & Scroll Margins:
- Dynamically sized the bottom navigation bar to
calc(4rem + env(safe-area-inset-bottom))inMobileBottomNav.tsxto prevent icons and labels from compressing against the home bar. - Added bottom padding offsets to entry list and detail view scroll containers to prevent content from being occluded beneath the fixed navigation bar.
- Dynamically sized the bottom navigation bar to
- Mobile Drawer & Bottom Sheet Exit Animations:
- Moved conditional rendering inside
<AnimatePresence>inMobileDrawer.tsxandMobileBottomSheet.tsx, enabling smooth Framer Motion exit transitions on close.
- Moved conditional rendering inside
- Mobile Onboarding Overflow:
- Replaced fixed
w-[420px]container withw-full max-w-[420px]andmin-h-dvh overflow-y-autoinOnboarding.tsx, eliminating horizontal clipping on narrow mobile viewports.
- Replaced fixed
- Mobile Localization Parity:
- Extracted hardcoded English ...