Files
Password-Manager/delphi-backend/Source/PM.JSON.pas
T
Zaki 40b3154a34 feat: MFA tools, single-instance, tray polish, prefs persistence
Session highlights:

- feat(prefs): DPAPI-backed key/value store (PM.UserPrefs) — fixes
  rememberedUsername being lost across reboots due to the random
  ephemeral HTTP port changing the localStorage origin every launch.
  Bridge cmd://prefs/{get,set} round-trips through Delphi.

- feat(tray): icon visible from startup (NIM_ADD at constructor, not
  at first minimize). Tray context menu themed via uxtheme!135
  SetPreferredAppMode so it follows the app's dark/light setting.

- feat(single-instance): named mutex + RegisterWindowMessage broadcast.
  Second launch posts WM_PMSHOW to HWND_BROADCAST and exits; the
  running bridge restores the window from tray. Mutex lives in Local\
  namespace so distinct Windows users can still each run one.

- feat(mfa): Authenticator sidebar view (live TOTP codes for every
  entry with a secret) + standalone TOTP generator modal (paste
  base32 / otpauth:// URI, or generate a random 20-byte secret).

- feat(sidebar): Folders / Tags / Tools sections collapsible with
  chevron toggle. Badge counts stay visible when collapsed. State
  persisted in settings_json (synced across devices).

- feat(autofill): hotkey when vault is locked now restores the app
  and focuses the master password input instead of no-op'ing
  silently. Cleaner UX for the common "I hit Ctrl+Shift+L but the
  vault was locked" path.

- feat(quick-unlock): when enabled, skip lockVault on Windows lock /
  sleep. Rationale: the DPAPI blob already gates access via the
  Windows account, so re-locking on top of the OS lock is redundant.
  Idle auto-lock still fires (separate opt-in).

- fix(quick-unlock): re-sync state.quickUnlockEnabled from DPAPI
  source-of-truth at boot, instead of trusting (now-volatile)
  localStorage.

- docs: CLAUDE.md updated with all new modules, bridge commands,
  and the port-ephemeral pitfall.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-06-08 21:31:39 +01:00

78 lines
2.0 KiB
ObjectPascal

unit PM.JSON;
interface
uses
System.SysUtils, System.Classes, System.JSON, IdCustomHTTPServer;
type
TJSONHelper = class
public
class function ReadBody(ARequest: TIdHTTPRequestInfo): TJSONObject;
class procedure SendJSON(AResponse: TIdHTTPResponseInfo; AObj: TJSONValue;
ACode: Integer = 200; AOwnsObj: Boolean = True);
class procedure SendError(AResponse: TIdHTTPResponseInfo; ACode: Integer;
const AMsg: string);
class procedure SendOK(AResponse: TIdHTTPResponseInfo; const AMessage: string = 'OK');
end;
implementation
class function TJSONHelper.ReadBody(ARequest: TIdHTTPRequestInfo): TJSONObject;
var
S: string;
LSS: TStringStream;
LValue: TJSONValue;
begin
if ARequest.PostStream = nil then Exit(TJSONObject.Create);
LSS := TStringStream.Create('', TEncoding.UTF8);
try
ARequest.PostStream.Position := 0;
LSS.CopyFrom(ARequest.PostStream);
S := LSS.DataString;
finally
LSS.Free;
end;
if Trim(S) = '' then Exit(TJSONObject.Create);
LValue := TJSONObject.ParseJSONValue(S);
if LValue is TJSONObject then
Result := TJSONObject(LValue)
else
begin
LValue.Free;
Result := TJSONObject.Create;
end;
end;
class procedure TJSONHelper.SendJSON(AResponse: TIdHTTPResponseInfo;
AObj: TJSONValue; ACode: Integer; AOwnsObj: Boolean);
begin
AResponse.ResponseNo := ACode;
AResponse.ContentType := 'application/json; charset=utf-8';
AResponse.CharSet := 'utf-8';
AResponse.ContentText := AObj.ToJSON;
if AOwnsObj then AObj.Free;
end;
class procedure TJSONHelper.SendError(AResponse: TIdHTTPResponseInfo;
ACode: Integer; const AMsg: string);
var
LObj: TJSONObject;
begin
LObj := TJSONObject.Create;
LObj.AddPair('error', AMsg);
SendJSON(AResponse, LObj, ACode);
end;
class procedure TJSONHelper.SendOK(AResponse: TIdHTTPResponseInfo;
const AMessage: string);
var
LObj: TJSONObject;
begin
LObj := TJSONObject.Create;
LObj.AddPair('message', AMessage);
SendJSON(AResponse, LObj);
end;
end.