feat: entry templates + tag autocomplete + slideover push + robustness bundle

- Entry templates: new vault_entries.template column drives a typed
  sub-kind ('credit-card', 'ssh-key', 'server', 'recovery-codes'). Card
  + table label off the template, badge reads "credit card" instead of
  "note". Templates seed kind=note (no site/password required), use
  custom_fields with optional dropdown options (brand, month/year,
  protocol). Round-tripped across export/import/duplicate/master-pw
  rotation, preserved by partial PUTs via a HasTemplate flag.
- Custom fields: support per-field `options[]` rendering as <select>
  (card brand, expiry MM/YYYY, SSH/server protocol).
- Tags: existing-tag autocomplete dropdown under the chip input,
  filtered against what's already selected.
- Search history: per-query X for individual delete + 1s debounced
  commit (no Enter required).
- Slideover: clicking outside closes again (drag-selection respected
  via mousedown origin tracker), Esc closes, X closes. App shell is
  pushed left by 420px when the panel is open so the table / pagination
  / sort / search stay visible and interactive.
- Export/import: JSON now round-trips custom_fields, attachments
  (decrypted to base64, re-encrypted under current key on restore),
  icon_b64, and template. CSV warning lists what's not included.
- Auto-backup: same payload shape as user-driven export.
- Notes: import (JSON + CSV) accepts kind=note with empty site,
  preserves title/template/custom_fields. CSV parser detects kind/
  template columns.
- Bulk-import response returns `ids[]` parallel to input so the
  client can map back to new entry IDs (drives attachment restore).
- Move-to-folder bugs fixed: moveEntryToFolder, batchMoveToFolder,
  addTag, batchAddTag were all silently wiping TOTP / custom_fields
  / kind / template via partial PUT. Now re-ship full payload.
- Master-pw rotation: server mints a fresh session token + csrf so
  the very next request after rotation no longer ESessionRejects.
  Client adopts the new pair. Attachments are re-encrypted client-side
  during rotation (GET old → decrypt with old key → encrypt with new
  → PUT). New endpoints: GET /attachments/all, PUT /attachments/:id.
- Duplicate: carries icon_b64 + template + attachments to the copy.
- HandleCreateEntry: accepts icon_b64.
- FireDAC param fix: all blob/icon/custom_fields params use ftMemo +
  .Value assignment so SQLite TEXT no longer truncates to 4000 chars
  (deepseek's 200+ KB favicon was being wiped on lock/unlock).
- HandleSetEntryIcon cap: 262144 → 524288 chars (base64 of a 256 KB
  raw fetch overflows the old cap, fails silently in saveEntryIcon).
- Native save dialog: surfaces server errors instead of swallowing.
- Modals: reauth (export) + backup-password prompt support inline
  error display, retry up to 5 attempts, then hard-stop.
- Keyboard cursor (j/k): bootstraps to current page, auto-paginates
  when the cursor crosses a page boundary, Enter opens slideover.
- Slideover focuses Title on edit-open so j/k → Enter → type Just
  Works.
- TOTP tool: Esc closes the modal.
- App version + launch mode (auto/manual): exposed via bridge,
  surfaced in Settings → Account. Autostart launches suppress the
  first-time tray balloon.
- Passkey button hidden (Delphi backend stubs WebAuthn at 501).
- TEST_PLAN.md captured for regression coverage.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
r-zakarya
2026-06-26 21:20:07 +01:00
parent fa7ea191be
commit e23a78dda7
14 changed files with 1752 additions and 203 deletions
+16 -8
View File
@@ -772,6 +772,7 @@ var
LValid: Boolean;
LEntryId: Integer;
LEncPwd, LIv, LTotpSec, LTotpIv: string;
LNewToken, LNewCsrf: string;
begin
try
LUserId := Authenticate(ARequest, AResponse);
@@ -941,18 +942,18 @@ begin
LQ.ParamByName('iv').AsString := LIv;
// TOTP / custom_fields are optional per entry — clear when
// empty so existing-NULL rows don't get stomped with empty strings.
LQ.ParamByName('ts').DataType := ftString;
LQ.ParamByName('tiv').DataType := ftString;
LQ.ParamByName('cf').DataType := ftString;
LQ.ParamByName('cfiv').DataType := ftString;
LQ.ParamByName('ts').DataType := ftMemo;
LQ.ParamByName('tiv').DataType := ftMemo;
LQ.ParamByName('cf').DataType := ftMemo;
LQ.ParamByName('cfiv').DataType := ftMemo;
if LTotpSec.IsEmpty then LQ.ParamByName('ts').Clear
else LQ.ParamByName('ts').AsString := LTotpSec;
else LQ.ParamByName('ts').Value := LTotpSec;
if LTotpIv = '' then LQ.ParamByName('tiv').Clear
else LQ.ParamByName('tiv').AsString := LTotpIv;
else LQ.ParamByName('tiv').Value := LTotpIv;
if LCf = '' then LQ.ParamByName('cf').Clear
else LQ.ParamByName('cf').AsString := LCf;
else LQ.ParamByName('cf').Value := LCf;
if LCfIv = '' then LQ.ParamByName('cfiv').Clear
else LQ.ParamByName('cfiv').AsString := LCfIv;
else LQ.ParamByName('cfiv').Value := LCfIv;
LQ.ExecSQL;
end;
// Password history is encrypted with the OLD vault key — we
@@ -993,6 +994,11 @@ begin
end;
DeleteAllUserSessions(LUserId);
// Immediately mint a fresh session for the calling client so the
// very next request doesn't bounce with ESessionRejected. The user
// hasn't logged out — they rotated their key, the UI session is
// still legitimate.
CreateSession(LUserId, LNewToken, LNewCsrf);
finally
LBody.Free;
end;
@@ -1004,6 +1010,8 @@ begin
LObj.AddPair('message', 'Master password changed');
LObj.AddPair('salt', LNewSalt);
LObj.AddPair('kdfIterations', TJSONNumber.Create(PBKDF2_ITERATIONS_TARGET));
LObj.AddPair('token', LNewToken);
LObj.AddPair('csrf', LNewCsrf);
TJSONHelper.SendJSON(AResponse, LObj);
end;