WriteIn v4.2.0
WriteIn v4.2.0 — End-to-End Encrypted Device Transfer & Security Hardening
WriteIn v4.2.0 introduces a zero-knowledge, end-to-end encrypted device-to-device transfer system. You can now seamlessly and securely migrate your entire WriteIn studio library—projects, chapters, worldbuilding, timelines, character networks, and attachments—from one desktop machine to another without ever trusting your data to third-party cloud databases or compromising your offline privacy.
🌟 What's New
🔒 Zero-Knowledge Device-to-Device Library Transfer
Transfer your entire writing environment between laptops or desktops with zero configuration:
- Temporary 10-Minute Pairing Sessions: Generate a short, human-readable pairing code (
XXXX-XXXX) on your source computer and connect from your destination computer. - Client-Side End-to-End Encryption:
- Ephemeral ECDH (P-256) key agreement with HKDF-SHA256 key derivation.
- Authenticated payload encryption and decryption via AES-256-GCM (96-bit random IV).
- SHA-256 package checksum validation to detect tampering in transit.
- Zero-knowledge: Decryption keys never leave your devices, and the temporary relay worker only handles blind, short-lived ciphertext chunks.
- Pre-Import Package Inspection: Review exact project counts, word counts, document totals, and attachment statistics before confirming the import.
- Conflict-Safe & Atomic Import: Imported projects are remapped and isolated within SQLite transactions, appending
(Transferred)to conflicting titles to prevent accidental overwrites of existing local manuscripts. - Transfer Audit History: View past incoming and outgoing transfers directly in the new
Settings > Devicespanel.
🛡️ Security & Reliability Improvements
- CSPRNG Hardening (CWE-338): Replaced pseudo-random math calls with cryptographically secure random number generators (
crypto.getRandomValues) for all session tokens, mock IDs, and fallback device identifiers. - Safe Session Cancellation: Canceling an ongoing transfer immediately invalidates session tokens and purges ephemeral buffers on both ends.
- Attachment Relational Integrity: Enhanced attachment import to remap internal IDs and relational references atomically, ensuring image and media attachments stay bound to their respective entities.
- Updater Key Rotation: Rotated minisign signing keys for the Tauri v2 auto-updater to maintain high delivery security.
- Dev-Mode Relay Switcher: Added support for local development relay testing (
127.0.0.1:8787) alongside the production Cloudflare Worker relay.
🧪 Testing & Tooling
- Added automated test suites covering Web Crypto primitives, end-to-end simulated device transfers, and the
DeviceTransferViewuser interface. - Enhanced version management scripts (
set-version.ps1) with lossless UTF-8 reading/writing, SemVer format validation, and automated website component synchronization.
📦 Commits & Full Diff
Full Changelog: v4.1.0...v4.2.0