feat(desktop): unlock with Touch ID, and copy secrets from the main process - #24
Merged
Conversation
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Two things: Copy is fixed — it never worked in a packaged build — and the vault can now be unlocked by fingerprint instead of the master password.
Copy.
copyWithTimeoutused the renderer'snavigator.clipboard, which needs a secure context (a packaged build serves the UI fromfile://, where the API is simply absent) and a read permission Electron never grants, so the clear-after-30s half always threw. It now runs in the main process:Still clears only if it is still ours, so a shopping list copied since survives; a second copy supersedes the first timer; locking the vault cancels it.
Touch ID. What is stored is the master password, sealed by the OS credential store via
safeStorage— Keychain, DPAPI, libsecret — and released only aftersystemPreferences.promptTouchID(). The vault file is untouched and still opens with the password anywhere else, so this changes who is asked, not what protects the vault.enrolrefuses whensafeStorage.isEncryptionAvailable()is false (no keyring on Linux) rather than falling back to anything weaker, and the IPC handler unlocks the vault with the password before promising it works, so a typo cannot enrol a password that fails at the doors.macOS is the only platform Electron gives a biometric prompt for, so elsewhere
biometricStatus().biometricis false and the same stored password is released without one — labelled "Unlock with Credential Manager" / "the system keyring" rather than Touch ID.Three places keep the remembered password honest, since one that no longer opens the vault is a dead end:
~/.dcrypt, which is whereconfig/unlock.binlives.On the unlock screen the fingerprint prompt fires as soon as the doors appear when one is enrolled, with the password field still there behind it; a cancelled prompt is treated as a choice, not an error.
Link to Devin session: https://app.devin.ai/sessions/04636534e07048089ffb6b78142e12cd
Requested by: @pyramation