feat(import): JSON / CSV vault import with heuristic column mapping
Round-trip companion to the existing doExport(). Supports two file
formats with auto-detection (extension + first-char sniff):
JSON
====
Native shape produced by doExport() AND a forgiving fallback for any
flat array of entry objects with site/url + password fields. Accepts:
- { version, exported_at, entries: [...] } (native)
- [{ ... }, { ... }] (flat array)
- mixed keys: site|url|name, username|user|login|email, etc.
CSV
===
RFC-4180-ish parser (~30 lines): quoted fields, escaped "", commas
inside quotes, CRLF line endings. No streaming since password-manager
imports are realistically MB-scale at most.
Heuristic column mapping (case + underscore tolerant) covers the
common exporters out of the box:
Site/URL : name, title, url, site, website, login_uri, login_url
Username : login_username, username, user, login, email
Password : login_password, password, pass, pwd
Folder : folder, group, category, path, collection
Tags : tags, labels (comma/semicolon-split)
Notes : notes, note, comment (short notes joined into tags)
TOTP : login_totp, totp, otpauth, authenticator, two_factor
If the TOTP column holds a full otpauth:// URI it's parsed and only
the secret param is stored — same path used by the slide-over TOTP
field. Invalid base32 TOTP secrets are dropped silently rather than
failing the whole import.
Backend
=======
New endpoint: POST /entries/bulk-import
Body: { entries: [{ site, username, encrypted_password, iv, folder,
tags, totp_secret, totp_iv }, ... ] }
Caps at 10,000 entries per request as a sanity bound. Inserts inside
a single SQLite transaction — partial failure rolls back cleanly, the
user retries from the same source file. Returns { imported: N }.
Rows missing site or ciphertext are skipped within the transaction
(not failed) so one bad row in a 500-entry import doesn't blow up
the whole batch.
Client flow
===========
doImport():
1. Hidden <input type="file" accept=".json,.csv"> picker
2. Read text, detect format, route to parseEntriesFromJSON or CSV
3. confirmDialog preview: count + first 3 sample sites + skipped rows
4. On confirm: encryptImportEntry() each plaintext entry with the
current vault key (reuses encryptPwd / base32Decode validation)
5. Single POST to /entries/bulk-import
6. Reload entries, refresh UI, trigger HIBP scan if enabled
UI
==
Two entry points (mirroring Export):
- Sidebar "Import vault" nav item, next to "Export vault"
- Settings panel "Import" section with descriptive blurb
Both call doImport(). New i-log-in icon added to the SVG sprite (mirror
of i-log-out used by Export).
Limitations
===========
- No de-duplication: importing the same file twice yields duplicate
entries. Trade-off to keep the v1 simple — the user can sort it
out with the existing trash/multi-select UI.
- No password-protected vault formats (Bitwarden encrypted JSON,
KeePass kdbx). Only plaintext exports — same trade-off as
doExport() which produces plaintext JSON.
This commit is contained in:
@@ -480,14 +480,124 @@ begin
|
||||
TJSONHelper.SendOK(AResponse, 'Trash emptied');
|
||||
end;
|
||||
|
||||
// ===== POST /entries/bulk-import =============================================
|
||||
// Accepts an array of already-encrypted entries (the client encrypts each
|
||||
// entry with the vault key before posting). Inserts them all in a single
|
||||
// transaction so a partial failure rolls back cleanly. Used by the JSON / CSV
|
||||
// import flow — much faster than N sequential POST /entries for large vaults.
|
||||
procedure HandleBulkImport(ARequest: TIdHTTPRequestInfo;
|
||||
AResponse: TIdHTTPResponseInfo; const AParams: TArray<string>);
|
||||
var
|
||||
LUserId, I, LImported: Integer;
|
||||
LBody, LObj, LEntry: TJSONObject;
|
||||
LArr: TJSONArray;
|
||||
LSite, LUser, LFolder, LEnc, LIV, LTags, LTotpSec, LTotpIv, LNow: string;
|
||||
LQ: TFDQuery;
|
||||
begin
|
||||
try
|
||||
LUserId := Authenticate(ARequest, AResponse);
|
||||
RequireCSRF(ARequest, AResponse, LUserId);
|
||||
except
|
||||
on ESessionRejected do Exit;
|
||||
end;
|
||||
|
||||
LBody := TJSONHelper.ReadBody(ARequest);
|
||||
try
|
||||
LArr := LBody.GetValue<TJSONArray>('entries');
|
||||
if (LArr = nil) or (LArr.Count = 0) then
|
||||
begin
|
||||
TJSONHelper.SendError(AResponse, 400, 'Missing or empty entries array');
|
||||
Exit;
|
||||
end;
|
||||
|
||||
// Sanity cap. A real vault rarely has > 10k entries; if someone uploads
|
||||
// a 100k-row CSV it's probably an attack or a mistake.
|
||||
if LArr.Count > 10000 then
|
||||
begin
|
||||
TJSONHelper.SendError(AResponse, 413, 'Too many entries (max 10000 per request)');
|
||||
Exit;
|
||||
end;
|
||||
|
||||
LNow := FormatDateTime('yyyy-mm-dd hh:nn:ss', Now);
|
||||
LImported := 0;
|
||||
|
||||
DB.Lock;
|
||||
try
|
||||
DB.Connection.StartTransaction;
|
||||
try
|
||||
LQ := TFDQuery.Create(nil);
|
||||
try
|
||||
LQ.Connection := DB.Connection;
|
||||
LQ.SQL.Text :=
|
||||
'INSERT INTO vault_entries ' +
|
||||
'(user_id, site, username, encrypted_password, iv, encryption_method, ' +
|
||||
' folder, tags, totp_secret, totp_iv, created_at, updated_at) ' +
|
||||
'VALUES (:uid, :s, :u, :e, :i, ''client'', :f, :t, :ts, :tiv, :c, :c2)';
|
||||
|
||||
for I := 0 to LArr.Count - 1 do
|
||||
begin
|
||||
LEntry := LArr.Items[I] as TJSONObject;
|
||||
LSite := Trim(LEntry.GetValue<string>('site', ''));
|
||||
LUser := Trim(LEntry.GetValue<string>('username', ''));
|
||||
LFolder := Trim(LEntry.GetValue<string>('folder', 'All'));
|
||||
LEnc := LEntry.GetValue<string>('encrypted_password', '');
|
||||
LIV := LEntry.GetValue<string>('iv', '');
|
||||
LTags := Trim(LEntry.GetValue<string>('tags', ''));
|
||||
LTotpSec := LEntry.GetValue<string>('totp_secret', '');
|
||||
LTotpIv := LEntry.GetValue<string>('totp_iv', '');
|
||||
|
||||
// Skip silently if a row is missing the minimum required fields
|
||||
// (site + ciphertext). Better than failing the whole batch on
|
||||
// one bad row when the user is importing 500+ entries.
|
||||
if (LSite = '') or (LEnc = '') or (LIV = '') then Continue;
|
||||
|
||||
LQ.ParamByName('uid').AsInteger := LUserId;
|
||||
LQ.ParamByName('s').AsString := LSite;
|
||||
LQ.ParamByName('u').AsString := LUser;
|
||||
LQ.ParamByName('e').AsString := LEnc;
|
||||
LQ.ParamByName('i').AsString := LIV;
|
||||
LQ.ParamByName('f').AsString := LFolder;
|
||||
LQ.ParamByName('t').AsString := LTags;
|
||||
if LTotpSec = '' then LQ.ParamByName('ts').Clear
|
||||
else LQ.ParamByName('ts').AsString := LTotpSec;
|
||||
if LTotpIv = '' then LQ.ParamByName('tiv').Clear
|
||||
else LQ.ParamByName('tiv').AsString := LTotpIv;
|
||||
LQ.ParamByName('c').AsString := LNow;
|
||||
LQ.ParamByName('c2').AsString := LNow;
|
||||
LQ.ExecSQL;
|
||||
Inc(LImported);
|
||||
end;
|
||||
finally
|
||||
LQ.Free;
|
||||
end;
|
||||
DB.Connection.Commit;
|
||||
except
|
||||
DB.Connection.Rollback;
|
||||
raise;
|
||||
end;
|
||||
finally
|
||||
DB.Unlock;
|
||||
end;
|
||||
finally
|
||||
LBody.Free;
|
||||
end;
|
||||
|
||||
LogAudit(LUserId, Format('bulk_import %d entries', [LImported]), GetClientIP(ARequest));
|
||||
LObj := TJSONObject.Create;
|
||||
LObj.AddPair('imported', TJSONNumber.Create(LImported));
|
||||
TJSONHelper.SendJSON(AResponse, LObj);
|
||||
end;
|
||||
|
||||
initialization
|
||||
// /entries/trash/empty must be registered BEFORE /entries/{id} to win the regex match
|
||||
Router.Register('DELETE', '/entries/trash/empty', HandleEmptyTrash);
|
||||
// /entries/trash/empty must be registered BEFORE /entries/{id} to win the regex match.
|
||||
// Same logic for /entries/bulk-import — register before the catch-all /entries/{id}.
|
||||
Router.Register('DELETE', '/entries/trash/empty', HandleEmptyTrash);
|
||||
Router.Register('POST', '/entries/bulk-import', HandleBulkImport);
|
||||
Router.Register('POST', '/entries/(\d+)/restore', HandleRestoreEntry);
|
||||
Router.Register('POST', '/entries/(\d+)/favorite', HandleToggleFavorite);
|
||||
Router.Register('GET', '/entries', HandleGetEntries);
|
||||
Router.Register('POST', '/entries', HandleCreateEntry);
|
||||
Router.Register('PUT', '/entries/(\d+)', HandleUpdateEntry);
|
||||
Router.Register('DELETE', '/entries/(\d+)', HandleDeleteEntry);
|
||||
Router.Register('GET', '/entries', HandleGetEntries);
|
||||
Router.Register('POST', '/entries', HandleCreateEntry);
|
||||
Router.Register('PUT', '/entries/(\d+)', HandleUpdateEntry);
|
||||
Router.Register('DELETE', '/entries/(\d+)', HandleDeleteEntry);
|
||||
|
||||
end.
|
||||
|
||||
Reference in New Issue
Block a user