mirror of
https://github.com/greenart7c3/Amber.git
synced 2026-10-06 03:18:23 +00:00
Toggling "require unlocked device for key access" rotates the AMBER_AES_KEY Keystore key, but rotateKey only re-encrypted the DataStore secrets (account keys, PIN, WebDAV password). The envelope-encrypted `secret`/`localKey` columns of the per-account `application` Room tables were left under the old key, making every NIP-46 connection row undecryptable after the toggle: getBySecret lookups miss and localKey turns into undecryptable ciphertext. rotateKey now stages those rows before deleting the old key and rewrites them re-encrypted with the new key via the new updateEncryptedColumnsRaw DAO query (ciphertext-in/ciphertext-out, empty sentinel preserved, no schema change). Columns that fail old-key decryption are written back verbatim so rotation never destroys data it cannot recover, matching the decryptField failure contract in ApplicationEntityCrypto.kt.