mirror of
https://github.com/profullstack/logicsrc.git
synced 2026-10-04 13:45:40 +00:00
`logicsrc vault` (OpenCreds) lived only in ~/.config/logicsrc/opencreds. Lose the machine and the vault went with it, and a second machine had no way to get it. It now syncs to the logged-in account. Server (apps/pwa, /api/opencreds, session or lsk_ bearer): - opencreds_vaults: one per user. meta (key material already wrapped under the master password) + an encrypted folder list, each with a revision. - opencreds_items: one row per item, as the spec asks; envelope NULL is a tombstone so purges propagate; seq for incremental pulls. - Every write names its base revision; a stale one gets 409 with the current row. Writes are conditional and read back (each envelope's random IV identifies our write), so this needs nothing dialect-specific from SQLite or Postgres. - Stores ciphertext only. The server learns item count and type codes, as OpenCreds security.md already accepts. Client (@logicsrc/opencreds sync.ts, key-free except where noted): - Pull before every vault command, push after. Offline, the command still works and the change goes up next time. - Conflicts never lose data: the account's edit keeps the id and this machine's becomes "<name> (conflict copy)" (needs the unlocked key, so it waits otherwise). An edit beats a purge. Byte-identical envelopes are adopted, not split, so a lost sync.json is harmless. - Two different vaults (meta.createdAt differs) are never merged: refused, with `vault sync --use-remote` (backs this machine's up to .bak-NNN) or `--use-local`. - Remote item ids must be plain ids; anything else is ignored and never becomes a path. - Folder names are AES-GCM encrypted under the user key before upload. CLI (0.6.0): `logicsrc vault sync [--status|--use-remote|--use-local]`. Only the default vault syncs, and only when logged in; a --home or OPENCREDS_HOME vault stays local unless LOGICSRC_VAULT_SYNC=on; LOGICSRC_VAULT_SYNC=off disables it. The standalone `opencreds` binary gets no remote and never syncs. `init` on a machine that just downloaded the account's vault says to unlock it instead of suggesting --force. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
43 lines
1.6 KiB
JSON
43 lines
1.6 KiB
JSON
{
|
|
"name": "@logicsrc/cli",
|
|
"version": "0.6.0",
|
|
"description": "LogicSRC CLI: every LogicSRC standard and tool as one command.",
|
|
"type": "module",
|
|
"main": "./dist/index.js",
|
|
"types": "./dist/index.d.ts",
|
|
"bin": {
|
|
"logicsrc": "./dist/index.js"
|
|
},
|
|
"scripts": {
|
|
"build": "tsc -p tsconfig.json",
|
|
"dev": "tsx src/index.ts",
|
|
"test": "vitest run src"
|
|
},
|
|
"dependencies": {
|
|
"@fission-ai/openspec": "^1.13.0",
|
|
"@logicsrc/account-core": "file:../account-core",
|
|
"@logicsrc/opencontext": "file:../opencontext",
|
|
"@logicsrc/opencreds": "file:../opencreds",
|
|
"@logicsrc/openfleet": "file:../openfleet",
|
|
"@logicsrc/openmcp": "^0.3.1",
|
|
"@logicsrc/openontology": "file:../openontology",
|
|
"@logicsrc/openprd": "file:../openprd",
|
|
"@logicsrc/plugin-agentbbs": "file:../../plugins/agentbbs",
|
|
"@logicsrc/plugin-coinpay": "file:../../plugins/coinpay",
|
|
"@logicsrc/plugin-core": "file:../plugin-core",
|
|
"@logicsrc/plugin-credential-sharing": "file:../../plugins/credential-sharing",
|
|
"@logicsrc/plugin-email-accounts": "file:../../plugins/email-accounts",
|
|
"@logicsrc/plugin-feed-discovery": "file:../../plugins/feed-discovery",
|
|
"@logicsrc/plugin-social-accounts": "file:../../plugins/social-accounts",
|
|
"@logicsrc/plugin-ugig": "file:../../plugins/ugig",
|
|
"@logicsrc/tui": "file:../tui",
|
|
"@logicsrc/validators": "file:../validators",
|
|
"@profullstack/hqtui": "^0.5.0",
|
|
"@profullstack/logicsrc-mcp": "file:../logicsrc-mcp",
|
|
"commander": "^14.0.2"
|
|
},
|
|
"devDependencies": {
|
|
"tsx": "^4.21.0",
|
|
"vitest": "^4.0.8"
|
|
}
|
|
}
|