fix: cross-browser sync import corrupting local encryption + v2.0.9
Root cause: when importing an encrypted sync code from another device, _decryptFromSync was replacing the local encryption config (salt) with the source device's salt. This caused: 1. Local key cache derived from wrong salt 2. Local data (encrypted with local salt) became unreadable 3. _applyData tried to write with the wrong key Fixed with a complete refactor of cross-device decryption: - authenticateForSync() derives a TEMPORARY key using the source salt - Temporary key stored separately as 'tempSyncKey' in IndexedDB - Local encryption config and cached key are NEVER modified - After decryption, _applyData writes via _writeSecure using the LOCAL key (which uses the local salt) - _handleDecryptedMeta extracted for code reuse Also: - Options.js auth handler detects pending sync import and routes to authenticateForSync instead of regular authenticate - After auth success, automatically retries the import - README updated: imported passwords are protected (dots in UI, vault password to reveal, AES-256 encrypted at rest) - Bumped to v2.0.9 https://claude.ai/code/session_01SWSwDfMVij53bCTNSCLMwn
This commit is contained in:
@@ -89,7 +89,7 @@ Import your existing data from password managers and browser autofill to pre-pop
|
||||
| Plain CSV (2 columns) | Real → substitute pairs |
|
||||
| Plain text (1 per line) | Auto-categorized values needing substitutes |
|
||||
|
||||
Passwords are imported as exact-match mappings (e.g. `MyS3cret!` → `[REDACTED-PASSWORD-1]`) so they get caught in any context — not just `password=value` patterns.
|
||||
Passwords are imported as exact-match mappings (e.g. `MyS3cret!` → `[REDACTED-PASSWORD-1]`) so they get caught in any context — not just `password=value` patterns. Imported passwords are protected: they're shown as dots in the UI and require your vault encryption password to reveal. When at-rest encryption is enabled, imported passwords are AES-256 encrypted in storage like all other sensitive data.
|
||||
|
||||
Go to **Options** → **Transfer Data** → **Import CSV / Password Export**.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user