All sensitive data (identity, mappings, activity log) is now AES-256
encrypted in browser.storage.local when sync encryption is enabled.
TOTP secret is also encrypted at rest using the derived key.
Vault unlock flow:
- On browser restart, extension detects locked state (encrypted data,
no cached CryptoKey) and shows LOCK badge in red
- Popup shows a full-screen unlock prompt with password field,
optional TOTP, and biometric button
- After unlock, background decrypts and broadcasts data to all tabs
- Content scripts start with empty config when locked; receive
decrypted config via vault:unlocked message after unlock
- Injector skips encrypted blobs in storage change events
Storage module changes:
- _readSecure / _writeSecure transparently encrypt/decrypt
- encryptExistingData() migrates plaintext → encrypted on setup
- decryptAllData() restores plaintext when encryption is disabled
- isLocked() checks for encrypted data + missing key
https://claude.ai/code/session_01SWSwDfMVij53bCTNSCLMwn