vault: autosync the personal vault to the logicsrc account (#226)
Some checks are pending
CI / build (push) Waiting to run
Deploy to dev2 / deploy (push) Waiting to run
test / test (push) Waiting to run

`logicsrc vault` (OpenCreds) lived only in ~/.config/logicsrc/opencreds.
Lose the machine and the vault went with it, and a second machine had
no way to get it. It now syncs to the logged-in account.

Server (apps/pwa, /api/opencreds, session or lsk_ bearer):
- opencreds_vaults: one per user. meta (key material already wrapped
  under the master password) + an encrypted folder list, each with a
  revision.
- opencreds_items: one row per item, as the spec asks; envelope NULL is
  a tombstone so purges propagate; seq for incremental pulls.
- Every write names its base revision; a stale one gets 409 with the
  current row. Writes are conditional and read back (each envelope's
  random IV identifies our write), so this needs nothing dialect-specific
  from SQLite or Postgres.
- Stores ciphertext only. The server learns item count and type codes,
  as OpenCreds security.md already accepts.

Client (@logicsrc/opencreds sync.ts, key-free except where noted):
- Pull before every vault command, push after. Offline, the command
  still works and the change goes up next time.
- Conflicts never lose data: the account's edit keeps the id and this
  machine's becomes "<name> (conflict copy)" (needs the unlocked key, so
  it waits otherwise). An edit beats a purge. Byte-identical envelopes
  are adopted, not split, so a lost sync.json is harmless.
- Two different vaults (meta.createdAt differs) are never merged:
  refused, with `vault sync --use-remote` (backs this machine's up to
  .bak-NNN) or `--use-local`.
- Remote item ids must be plain ids; anything else is ignored and never
  becomes a path.
- Folder names are AES-GCM encrypted under the user key before upload.

CLI (0.6.0): `logicsrc vault sync [--status|--use-remote|--use-local]`.
Only the default vault syncs, and only when logged in; a --home or
OPENCREDS_HOME vault stays local unless LOGICSRC_VAULT_SYNC=on;
LOGICSRC_VAULT_SYNC=off disables it. The standalone `opencreds` binary
gets no remote and never syncs. `init` on a machine that just downloaded
the account's vault says to unlock it instead of suggesting --force.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Anthony Ettinger 2026-10-04 03:45:25 -07:00 • committed by GitHub
parent 5bebc50beb
commit d38db62e8b
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
14 changed files with 1293 additions and 7 deletions

View file

@ -1,5 +1,6 @@
import type { Command } from "commander";
import { registerCredsCommands } from "@logicsrc/opencreds/commands";
import { accountRemoteFor } from "./vault-sync.js";
/**
* `logicsrc vault …`
@ -45,6 +46,12 @@ Personal vault:
logicsrc vault export --format csv --category db --out db.csv --yes
logicsrc vault import bitwarden.csv
Your personal vault syncs to your account (after logicsrc login), end to end
encrypted: every vault command pulls first and pushes after. A new machine
gets it with: logicsrc login, then logicsrc vault sync.
logicsrc vault sync --status what is synced, what is waiting
LOGICSRC_VAULT_SYNC=off turn it off (a --home vault never syncs)
Help for any command: logicsrc vault <command> --help (or: logicsrc vault help <command>)
`;
@ -59,5 +66,6 @@ export function registerOpenCredsCommands(program: Command): void {
// under `teams`. Say so first, with commands they can paste.
.addHelpText("after", VAULT_GUIDE);
registerCredsCommands(vault);
// Logged in: the vault syncs to the account around every command.
registerCredsCommands(vault, { remote: accountRemoteFor });
}