Make the README's storage and file format text match the code (closes #102)
check / check (push) Failing after 3s
check / check (push) Failing after 3s
The directory tree shows `current` and `currentvault` as plain files holding a name, a version's metadata as the encrypted `metadata.age`, the real state directory under the user's configuration directory, and the `lock` file. `version promote` rewrites `current`. File Formats tells unencrypted vault and unlocker metadata from encrypted version metadata; `pub.age` is plain text and vault metadata holds no vault name. Unlocker bullets lose Touch ID claims the code does not set up, and the Secure Enclave only decrypts. Per-version keys no longer claim forward secrecy. Testing lists only `make test`. Model: opus-5-5
This commit is contained in:
@@ -18,6 +18,17 @@ https://git.eeqj.de/sneak/secret/milestone/12
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: README's Storage Architecture, `secret version promote`,
|
||||
Technical Details and Testing text matches the code
|
||||
(https://git.eeqj.de/sneak/secret/issues/102). `current` and
|
||||
`currentvault` are plain files holding a name, not symbolic links; a
|
||||
version's metadata is the encrypted `metadata.age`; the state directory is
|
||||
`berlin.sneak.pkg.secret` in the user's configuration directory, not
|
||||
`~/.local/share/secret`, and holds the `lock` file. Also corrected: the
|
||||
code sets up no Touch ID for the keychain or Secure Enclave unlocker, and
|
||||
the Secure Enclave only decrypts; per-version keys give no forward
|
||||
secrecy; `pub.age` is not age-encrypted; vault metadata holds no vault
|
||||
name. Testing lists only `make test`.
|
||||
- 2026-10-04: A failed `secret unlocker add keychain` or
|
||||
`secret unlocker add secure-enclave` no longer leaves its keychain item or
|
||||
Secure Enclave key behind (https://git.eeqj.de/sneak/secret/issues/89).
|
||||
|
||||
Reference in New Issue
Block a user