feat: entry templates + tag autocomplete + slideover push + robustness bundle
- Entry templates: new vault_entries.template column drives a typed
sub-kind ('credit-card', 'ssh-key', 'server', 'recovery-codes'). Card
+ table label off the template, badge reads "credit card" instead of
"note". Templates seed kind=note (no site/password required), use
custom_fields with optional dropdown options (brand, month/year,
protocol). Round-tripped across export/import/duplicate/master-pw
rotation, preserved by partial PUTs via a HasTemplate flag.
- Custom fields: support per-field `options[]` rendering as <select>
(card brand, expiry MM/YYYY, SSH/server protocol).
- Tags: existing-tag autocomplete dropdown under the chip input,
filtered against what's already selected.
- Search history: per-query X for individual delete + 1s debounced
commit (no Enter required).
- Slideover: clicking outside closes again (drag-selection respected
via mousedown origin tracker), Esc closes, X closes. App shell is
pushed left by 420px when the panel is open so the table / pagination
/ sort / search stay visible and interactive.
- Export/import: JSON now round-trips custom_fields, attachments
(decrypted to base64, re-encrypted under current key on restore),
icon_b64, and template. CSV warning lists what's not included.
- Auto-backup: same payload shape as user-driven export.
- Notes: import (JSON + CSV) accepts kind=note with empty site,
preserves title/template/custom_fields. CSV parser detects kind/
template columns.
- Bulk-import response returns `ids[]` parallel to input so the
client can map back to new entry IDs (drives attachment restore).
- Move-to-folder bugs fixed: moveEntryToFolder, batchMoveToFolder,
addTag, batchAddTag were all silently wiping TOTP / custom_fields
/ kind / template via partial PUT. Now re-ship full payload.
- Master-pw rotation: server mints a fresh session token + csrf so
the very next request after rotation no longer ESessionRejects.
Client adopts the new pair. Attachments are re-encrypted client-side
during rotation (GET old → decrypt with old key → encrypt with new
→ PUT). New endpoints: GET /attachments/all, PUT /attachments/:id.
- Duplicate: carries icon_b64 + template + attachments to the copy.
- HandleCreateEntry: accepts icon_b64.
- FireDAC param fix: all blob/icon/custom_fields params use ftMemo +
.Value assignment so SQLite TEXT no longer truncates to 4000 chars
(deepseek's 200+ KB favicon was being wiped on lock/unlock).
- HandleSetEntryIcon cap: 262144 → 524288 chars (base64 of a 256 KB
raw fetch overflows the old cap, fails silently in saveEntryIcon).
- Native save dialog: surfaces server errors instead of swallowing.
- Modals: reauth (export) + backup-password prompt support inline
error display, retry up to 5 attempts, then hard-stop.
- Keyboard cursor (j/k): bootstraps to current page, auto-paginates
when the cursor crosses a page boundary, Enter opens slideover.
- Slideover focuses Title on edit-open so j/k → Enter → type Just
Works.
- TOTP tool: Esc closes the modal.
- App version + launch mode (auto/manual): exposed via bridge,
surfaced in Settings → Account. Autostart launches suppress the
first-time tray balloon.
- Passkey button hidden (Delphi backend stubs WebAuthn at 501).
- TEST_PLAN.md captured for regression coverage.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
@@ -358,7 +358,9 @@ Résout le cas "j'ai ajouté un mot de passe avec tri A-Z, où se loge-t-il ?"
|
||||
Une `vault_entries` row porte **plusieurs blobs chiffrés indépendants** :
|
||||
`encrypted_password/iv`, `totp_secret/totp_iv`, `custom_fields/custom_fields_iv`,
|
||||
plus le champ-icône `icon_b64` et les méta non chiffrées (`site, title,
|
||||
username, folder, tags, kind`).
|
||||
username, folder, tags, kind, template`). `template` est le sous-type
|
||||
(ex: `credit-card`, `ssh-key`, `server`, `recovery-codes`) qui drive le
|
||||
label de card/table — vide pour login/note génériques.
|
||||
|
||||
Quand tu ajoutes un nouveau champ (chiffré ou non), il faut **toujours**
|
||||
mettre à jour ces 6 endroits sous peine de perdre la donnée silencieusement
|
||||
@@ -375,7 +377,13 @@ sur certaines actions :
|
||||
`for (const e of state.entries)` re-chiffre chaque blob et push dans
|
||||
`encrypted[]`. Manquer un champ chiffré = donnée perdue.
|
||||
6. **`duplicateEntry`** (js/app.js) — copier le blob chiffré tel quel
|
||||
(même vault key, pas besoin de re-chiffrer)
|
||||
(même vault key, pas besoin de re-chiffrer). Pour `icon_b64` :
|
||||
inclure dans le body POST. Pour attachments : boucle séparée après
|
||||
create qui GET source attachments + POST sur le nouveau id.
|
||||
7. **`moveEntryToFolder`** (js/app.js) — PUT partiel sans ces champs =
|
||||
wipe silencieux (TOTP perdu, custom_fields perdus, et notes rejetées
|
||||
en 400 "Site required" parce que `kind` default à 'login'). Re-ship
|
||||
le payload complet, seul `folder` change.
|
||||
|
||||
Bonus utile (pas critique) : `soDirtyCheck` doit comparer le nouveau
|
||||
champ, et `openSlideOver` doit le déchiffrer et l'exposer via `soState`.
|
||||
@@ -403,9 +411,11 @@ client-side with the vault key.
|
||||
mime, size are stored in cleartext (leaked metadata) so the listing
|
||||
doesn't have to decrypt all rows on slideover-open.
|
||||
- **Cap** : 5 MB raw client-side check, ~10 MB base64 server-side.
|
||||
- **Master pw rotation** : attachments are NOT re-encrypted on rotation
|
||||
→ they become inaccessible. Known limitation, document for users who
|
||||
rotate master pw (rotate before adding heavy attachments).
|
||||
- **Master pw rotation** : attachments ARE re-encrypted client-side after
|
||||
the entries flip. Loop fetches each blob via `GET /attachments/:id`,
|
||||
decrypts with old key, re-encrypts with new key, PUTs the new blob via
|
||||
`PUT /attachments/:id`. Best-effort: a failure on one attachment shows
|
||||
a warning but doesn't undo the rotation.
|
||||
- **UI** : `soAttachmentsField(entryId)` rendered in slideover (existing
|
||||
entries only, never on new). Upload via hidden file input + paperclip
|
||||
button. Download reuses `Bridge.saveFile` (native Save As dialog).
|
||||
|
||||
Reference in New Issue
Block a user