Files
Amber/app
greenart7c3 41a37aacdc Re-encrypt Room application secrets during Keystore key rotation
Toggling "require unlocked device for key access" rotates the
AMBER_AES_KEY Keystore key, but rotateKey only re-encrypted the
DataStore secrets (account keys, PIN, WebDAV password). The
envelope-encrypted `secret`/`localKey` columns of the per-account
`application` Room tables were left under the old key, making every
NIP-46 connection row undecryptable after the toggle: getBySecret
lookups miss and localKey turns into undecryptable ciphertext.

rotateKey now stages those rows before deleting the old key and
rewrites them re-encrypted with the new key via the new
updateEncryptedColumnsRaw DAO query (ciphertext-in/ciphertext-out,
empty sentinel preserved, no schema change). Columns that fail
old-key decryption are written back verbatim so rotation never
destroys data it cannot recover, matching the decryptField failure
contract in ApplicationEntityCrypto.kt.
2026-08-14 13:23:13 -03:00
..
2024-03-01 06:56:32 -03:00
2023-07-26 16:44:33 -03:00
2026-08-14 08:15:03 -03:00