Skip to content

Releases: caRl0oo/oxidvault

v3.0.0 - Vault format consolidated to v4

Choose a tag to compare

@caRl0oo caRl0oo released this 10 Jul 06:47

OxidVault 3.0.0

Breaking: Vault format consolidated to v4

OxidVault now reads and writes only vault format v4 (multi-user, header-authenticated
via AES-GCM AAD). Support for legacy formats v1–v3 has been removed entirely.

If you created a vault with OxidVault < 2.0: open it once with
OxidVault 2.5.1,
migrate to the multi-user format, then upgrade. Vaults created with 2.0.0 or
later are unaffected.

Why

  • Smaller attack surface — the vault file parser shrank by ~50%. Every legacy
    code path was untested input-handling surface for untrusted files.
  • Single authenticated format — every vault now benefits from header AAD
    binding and the format-downgrade guard. No unauthenticated legacy headers remain.

Hardened key derivation

  • New vaults, new users, and password changes now derive keys with
    Argon2id at 128 MiB memory (previously 64 MiB), t=3, p=4.
  • Existing vaults keep their stored parameters — no silent re-derivation.
  • New admin policy field kdfMemoryMib (64–1024) lets IT set the memory cost
    centrally via policy.json.

Removed

  • create_vault, migrate_vault_to_v3 IPC commands and the migration UI
  • v1/v2/v3 header parsing and single-user unlock paths

v2.5.1 — Security Hardening & Architecture Improvements

Choose a tag to compare

@caRl0oo caRl0oo released this 09 Jul 12:44

Security Hardening & Architecture Improvements

This patch introduces critical security hardening updates for memory safety, cryptographic isolation, and sandbox constraints. No breaking changes to existing .oxid vaults.

Security Updates

  • Enforced IPC Sandbox & Least Privilege: Completely removed filesystem and dialog wildcards ("path": "**") from frontend capabilities. The JavaScript frontend is now entirely decoupled from direct OS file access. All I/O operations are strictly isolated within the Rust core.
  • KDF Downgrade Attack Protection: Implemented hardcoded baseline thresholds for Argon2id parameters during file parsing and key derivation. Vaults with manipulated or weak iterations below corporate security baselines will now be actively rejected (mitigating ETH Zurich BW07 vector).
  • RAM Zeroization Hardening: Fixed a potential memory fragment leak where old credentials lingered in unallocated heap space during entry updates. Explicit zeroize_secrets() is now enforced prior to memory re-assignment.

Maintenance & Refactoring

  • Tauri v2 capabilities updated to the latest security guidelines.
  • Verified cryptographic identity bindings (v4 headers bound via AES-256-GCM AEAD).

v2.5.0 — Auditor-Ready Compliance Reports

Choose a tag to compare

@caRl0oo caRl0oo released this 08 Jul 16:45

Compliance Report v2 (PDF)

  • Date-range export — new export dialog: last 50 events (default) or
    custom date range; client-side filtering in local time
  • Cover page — vault metadata (name, path, exported at/by, app version),
    report scope ("x of y events"), covered period, integrity status
    (hash chain + HMAC checkpoint verification)
  • Auditor notes — cover page explains tamper detection (hash chain),
    HMAC checkpoint authentication, and data minimisation; includes ISMS
    responsibility disclaimer; HMAC section omitted for legacy v1 vaults
  • Timezone fix — event table now renders local time with seconds,
    consistent with the cover page (previously raw UTC)
  • Checkpoint events included — HMAC integrity checkpoints no longer
    missing from the PDF
  • Brand refresh — teal accents and black wordmark instead of indigo;
    footer version read from tauri.conf.json at runtime

Custom Titlebar

  • Native titlebar replaced — single themed top bar with logo, vault
    status, version, Git sync indicator, lock, settings, and window controls
  • Windows conventions — drag anywhere on the bar, double-click to
    maximize, close (X) keeps minimizing to tray; forceLockOnMinimize GPO
    unchanged
  • Theme-aware — works in all 4 themes including Oxid Light

SSH Quick Connect

  • Right-click paste (PuTTY-style) — right-click pastes clipboard into
    the session; right-click with a selection copies it; Ctrl+Shift+V
    supported; clipboard read via Rust backend (no WebView permission prompt)
  • RSA/DSA keys rejected with clear message — validated at entry save
    time (inline field error) and at connect; localized error explains the
    security rationale (Marvin attack) and recommends Ed25519/ECDSA.
    Existing vaults containing RSA entries remain fully readable.

Fixes

  • Sidebar entry rows no longer nest buttons (invalid DOM); quick actions
    no longer change the selected entry
Platform File
Windows OxidVault_2.5.0_x64_en-US.msi

v2.4.2 Visual Redesign & Brand Update

Choose a tag to compare

@caRl0oo caRl0oo released this 08 Jul 07:14

🚀 OxidVault 2.4.2

🎨 UI / Design

  • ✨ Complete Visual Redesign: The desktop application has been completely overhauled with a fresh new look.
  • 💎 New Branding: The new OxidVault logo is now consistently integrated across all surfaces (app header, auth screen, system tray, and installer).
  • 🧩 Browser Extension: CSS has been updated to fully align with the new design language.
  • ⚖️ Design Consistency: Unified design tokens (vault-accent, vault-border, …) have been applied throughout all themes.

📦 Assets

  • 🖼️ Logo Refresh: Updated all assets in public/logo.png and src-tauri/icons/ with the new branding.
  • 📖 Documentation: The README.md has been updated with the new logo implementation.

📥 Download

Platform File
💻 Windows OxidVault_2.4.2_x64_en-US.msi

v2.4.1 — Native Messaging Installer

Choose a tag to compare

@caRl0oo caRl0oo released this 03 Jul 12:16
4033d34

OxidVault 2.4.1

Patch release fixing the MSI native messaging registration. If you
installed v2.4.0 and the browser extension shows "offline" or cannot
connect, this release fixes it
— please install this MSI (no vault
migration required, your data is untouched).

Fixed

The MSI-installed native messaging host registration was broken
end-to-end: on a fresh installation, the Chrome Web Store extension
could not connect to the desktop app. Four distinct bugs in the
registration chain were identified and fixed:

  • Stale extension ID: the bundled host manifest contained a
    hardcoded outdated extension ID in allowed_origins. It is now
    rendered from a single source of truth
    (browser-extension/chrome-store-extension.id).
  • Fragile inline registration: the WiX custom action embedded
    ~900 characters of inline PowerShell whose registry writes failed
    silently. Registration now runs via a bundled
    install-native-messaging-host.ps1 that writes the manifest and
    HKCU keys for Chrome and Edge — and removes both on uninstall.
  • Orphaned WiX fragment: Tauri only links WiX fragments referenced
    via componentRefs; the registration fragment contained no
    component, so the custom actions were silently dropped from the MSI.
    A marker component fixes the linkage; actions are now scheduled
    after InstallFinalize instead of mid-InstallFiles.
  • Broken argument parsing (MSI error 1722): the trailing backslash
    in the expanded [INSTALLDIR] argument broke PowerShell's
    command-line parsing. The script now derives its path from
    $PSScriptRoot and takes no arguments.

Developer

  • CI: new windows-latest job — Windows-specific code paths
    (os_protect DACLs, clipboard history exclusion, NM bridge) are now
    compiled, linted and tested in CI alongside the Linux job.
  • Rendered WiX outputs are build artifacts now: gitignored and
    generated from .in templates; CI renders them before building.
  • register_native_host.ps1 writes both store and dev extension IDs —
    no re-registration when switching between store and unpacked
    extension.
  • CHANGELOG.md translated to English.

Notes

  • The browser extension itself is unchanged (v0.5.0 remains current on
    the Chrome Web Store).
  • Vault file format is unchanged (v4, introduced in 2.4.0). Files
    written by 2.4.x cannot be read by versions before 2.4.0.

Full Changelog: v2.4.0...v2.4.1

OxidVault v2.4.0 Fortress

Choose a tag to compare

@caRl0oo caRl0oo released this 02 Jul 16:17
c5d94b6

🚀 Highlights

This release introduces the new File Format v4, which significantly increases security for multi-user vaults by binding the plaintext header to the payload using AES-GCM AAD (Additional Authenticated Data). Furthermore, the browser extension has been fundamentally hardened for more secure autofill operations.

🛡️ Security & Architecture

  • File Format v4:
    • Introduced encrypt_with_aad / decrypt_with_aad to ensure the integrity of the plaintext header.
    • Automatic upgrade from v3 to v4 upon saving.
    • Downgrade protection via explicit format_version in the payload.
    • Header mutations (e.g., user management or MFA changes) now trigger a re-encryption of the payload.
  • Audit Log Integrity:
    • Introduced Audit-HMAC checkpoints, derived via HKDF from the DEK.
    • Added support for verify_audit_chain_keyed for tamper-proof history verification.
  • Hardening:
    • NM Bridge: Session file ACLs via OS-Protect; token rotation upon unlock; explicit allowlist for actions allowed while locked.
    • Clipboard: Windows-specific exclusion of history/cloud sync when copying secrets.
    • Password Policy: Enforcement of a Zxcvbn score $\ge 2$ for master passwords (including I18n support for failure reasons).

🌐 Extension (v0.5.0)

  • Autofill Security: Transitioned to Gesture-Gated Autofill (autofill only triggered by explicit user gesture).
  • Anti-Phishing: Strict hostname validation via eTLD+1 using psl (no more substring matching); authority is strictly derived from sender.tab.url.

📚 Documentation & Deployment

  • Updated CHANGELOG.md.
  • Added docs/ADMIN_DEPLOYMENT.md for enterprise environments.
  • Added architecture version sync scripts.
  • Added compliance notes for legacy format migrations.

Migration Notice: Vaults will be automatically migrated to the v4 format upon the first save after this update. The migrate_to_v3 tool now writes the v4 format by default.

OxidVault v2.3.1

Choose a tag to compare

@caRl0oo caRl0oo released this 01 Jul 18:42

v2.3.1 — Patch Release

Fix

  • About dialog and Settings now automatically read the app version from tauri.conf.json
  • No more manually hardcoded version strings in the UI
  • Version will always be correct on future releases without extra steps

Download

  • Windows: OxidVault_2.3.1_x64_en-US.msi

OxidVault v2.3.0 — Password Import

Choose a tag to compare

@caRl0oo caRl0oo released this 01 Jul 11:37

What's New in v2.3.0

🔑 Password Import

Migrate from your existing password manager with one click. OxidVault now supports importing from:

  • Bitwarden (JSON export)
  • 1Password (CSV export)
  • KeePass (CSV export)
  • Chrome (CSV export)
  • RoboForm (CSV export) — including Secure Notes

How it works

  • New vault: After creating a new vault, OxidVault will offer to import your existing passwords
  • Existing vault: Settings → Import Passwords

Duplicate detection ensures existing entries are never overwritten. Secure Notes from RoboForm are imported as OxidVault Secure Notes.

🚀 Stable Release

OxidVault is no longer in beta. The core feature set is stable and ready for production use in small and medium businesses.

Full Changelog

  • Password import for Bitwarden, 1Password, KeePass, Chrome, RoboForm
  • RoboForm Secure Notes support
  • First-run import modal after new vault creation
  • Import entry point in Settings
  • Import progress persisted in settings.json

Download

  • Windows: OxidVault_2.3.0_x64_en-US.msi

OxidVault v2.2.0

Choose a tag to compare

@caRl0oo caRl0oo released this 28 Jun 10:20

OxidVault v2.2.0

Neu

  • Auto-Lock Timer — einstellbar in Einstellungen →
    Sicherheit (1 / 5 / 10 / 15 / 30 Min / Nie);
    Default 10 Minuten; Admin-GPO überschreibt
  • PDF Compliance Report — professioneller DSGVO-Audit-Export
    direkt aus dem Aktivitäts-Log; A4, OxidVault-Branding,
    Logo, farbige Aktionen, automatischer Seitenumbruch,
    Speicherort wählbar

Technisch

  • jsPDF + jspdf-autotable statt printpdf
    (keine externen Dependencies, vollständig offline)
  • cargo audit grün ohne Allowlist

Download

  • Windows: OxidVault_2.2.0_x64_en-US.msi

Lizenz

Community Edition: AGPLv3, kostenlos, bis 5 User
Enterprise Edition: support@oxidvault.com

OxidVault v2.1.1

Choose a tag to compare

@caRl0oo caRl0oo released this 27 Jun 22:18

OxidVault v2.1.1

Fixes

  • Extension Focus-Loop behoben — App springt nicht
    mehr hoch wenn im Tray minimiert
  • Deadlock-Schutz in perform_lock (5s Timeout)
  • Tray-Hide korrekt erkannt (is_visible Check)

Download

  • Windows: OxidVault_2.1.1_x64_en-US.msi