mirror of
https://github.com/greenart7c3/Amber.git
synced 2026-10-05 19:08:23 +00:00
The per-account Room database (amber_db_<npub>) stored two NIP-46 secret values as cleartext TEXT columns: the bunker connection `secret` and the `localKey` — the latter being a full Nostr private key. Anyone with access to the app's internal storage (rooted device, privilege-escalating malware, or a future bug exporting the DB) could recover these values and bypass the Keystore protection the main account nsec enjoys (CWE-312). Fix: envelope-encrypt both columns with the existing Keystore-backed AES-256-GCM key (SecureCryptoHelper) before Room persistence, and decrypt on read, so every existing consumer continues to see the plaintext values it already expects. - SecureCryptoHelper: add non-suspend encryptBlocking/decryptBlocking so Migration.migrate() and getByKeySync() can call them without a runBlocking bridge; suspend variants now delegate to the blocking implementations. - ApplicationEntityCrypto.kt (new): encryptForStorage/decryptFromStorage mappers + DecryptingPagingSource. Sentinel rule: empty values stay "" at rest (matches the WebDAV password idiom in LocalPreferences.kt:661-681), preserving `WHERE localKey != ''` enumeration in NotificationSubscription and the `localPubKey` derivation on empty localKey. - ApplicationDao: split methods touching `secret`/`localKey` into Room- generated `*Raw` (encrypted columns) and default-method wrappers that apply the mappers. `getBySecret` rewritten to decrypt and filter in Kotlin (random GCM IV breaks `WHERE secret = :secret`). - CachingApplicationDao: add delegating `*Raw` overrides so the decorator still instantiates; cache logic unchanged. - AppDatabase: add MIGRATION_18_19 (in-place envelope-encrypt of existing plaintext rows via compiled statement + transaction; empty values stay empty). Bump @Database version to 19. - Backup/restore: no changes — ApplicationBackup.buildPayload reads via the wrapped DAO (plaintext) and the JSON is already NIP-44 encrypted by the account key; restore goes through the wrapped insert (auto-encrypts). - Tests: new androidTest ApplicationEntityCryptoTest covers round-trip, raw-column-ciphertext assertion, empty sentinel, localPubKey derivation, getAllWithLocalKey filter, getBySecret (hit/miss/empty), insertApplicationWithPermissions, getAll, and the MIGRATION_18_19 row re-encryption. Requires a device/emulator (AndroidKeyStore unavailable under JVM test). - New room-testing androidTestImplementation dependency. Verified: ktlintCheck, lint (no issues), testFreeDebugUnitTest (0 failures), compileFreeDebugAndroidTestKotlin, assembleFreeDebug, assembleOfflineDebug, and the offline merged manifest check (no INTERNET/ACCESS_NETWORK_STATE/ CHANGE_NETWORK_STATE permissions leaked).
97 lines
5.9 KiB
TOML
97 lines
5.9 KiB
TOML
[versions]
|
|
activityCompose = "1.13.0"
|
|
appcompat = "1.7.1"
|
|
biometricKtx = "1.2.0-alpha05"
|
|
core = "3.5.4"
|
|
coreKtx = "1.19.0"
|
|
datastorePreferences = "1.2.1"
|
|
espressoCore = "3.7.0"
|
|
junit = "4.13.2"
|
|
junitVersion = "1.3.0"
|
|
lifecycle_version = "2.11.0"
|
|
material3 = "1.4.0"
|
|
nav_version = "2.9.8"
|
|
quartz = "1.12.6"
|
|
compose_ui = "1.11.3"
|
|
roomKtx = "2.8.4"
|
|
securityCryptoKtx = "1.1.0"
|
|
zxingAndroidEmbedded = "4.3.0"
|
|
okhttp = "5.4.0"
|
|
kotlin = "2.4.0"
|
|
workRuntimeKtx = "2.11.2"
|
|
agp = "9.3.0"
|
|
ktlint = "14.1.0"
|
|
ksp = "2.3.5"
|
|
coil = "3.5.0"
|
|
storage = "2.2.0"
|
|
jna = "5.19.1"
|
|
materialIconsExtended = "1.7.8"
|
|
collections = "0.5.0"
|
|
pagingCommon = "3.5.0"
|
|
mockk = "1.14.11"
|
|
coroutinesTest = "1.11.0"
|
|
kmpTor = "2.6.0"
|
|
kmpTorResource = "409.5.0"
|
|
secp256k1Jni = "0.23.0"
|
|
leakcanary = "1.0.0"
|
|
|
|
[libraries]
|
|
datastore-preferences = { module = "androidx.datastore:datastore-preferences", version.ref = "datastorePreferences" }
|
|
jna = { module = "net.java.dev.jna:jna", version.ref = "jna" }
|
|
activity-compose = { module = "androidx.activity:activity-compose", version.ref = "activityCompose" }
|
|
appcompat = { module = "androidx.appcompat:appcompat", version.ref = "appcompat" }
|
|
biometric-ktx = { module = "androidx.biometric:biometric-ktx", version.ref = "biometricKtx" }
|
|
core = { module = "com.google.zxing:core", version.ref = "core" }
|
|
core-ktx = { module = "androidx.core:core-ktx", version.ref = "coreKtx" }
|
|
espresso-core = { module = "androidx.test.espresso:espresso-core", version.ref = "espressoCore" }
|
|
ext-junit = { module = "androidx.test.ext:junit", version.ref = "junitVersion" }
|
|
junit = { module = "junit:junit", version.ref = "junit" }
|
|
lifecycle-runtime-compose = { module = "androidx.lifecycle:lifecycle-runtime-compose", version.ref = "lifecycle_version" }
|
|
lifecycle-runtime-ktx = { module = "androidx.lifecycle:lifecycle-runtime-ktx", version.ref = "lifecycle_version" }
|
|
lifecycle-viewmodel-compose = { module = "androidx.lifecycle:lifecycle-viewmodel-compose", version.ref = "lifecycle_version" }
|
|
lifecycle-process = { module = "androidx.lifecycle:lifecycle-process", version.ref = "lifecycle_version" }
|
|
material-icons-extended = { module = "androidx.compose.material:material-icons-extended", version.ref = "materialIconsExtended" }
|
|
material3 = { module = "androidx.compose.material3:material3", version.ref = "material3" }
|
|
navigation-compose = { module = "androidx.navigation:navigation-compose", version.ref = "nav_version" }
|
|
quartz = { module = "com.vitorpamplona.quartz:quartz-android", version.ref = "quartz" }
|
|
kotlinx-collections-immutable = { module = "org.jetbrains.kotlinx:kotlinx-collections-immutable", version.ref = "collections" }
|
|
room-compiler = { module = "androidx.room:room-compiler", version.ref = "roomKtx" }
|
|
room-ktx = { module = "androidx.room:room-ktx", version.ref = "roomKtx" }
|
|
room-runtime = { module = "androidx.room:room-runtime", version.ref = "roomKtx" }
|
|
room-paging = { module = "androidx.room:room-paging", version.ref = "roomKtx" }
|
|
room-testing = { module = "androidx.room:room-testing", version.ref = "roomKtx" }
|
|
security-crypto = { module = "androidx.security:security-crypto", version.ref = "securityCryptoKtx" }
|
|
security-crypto-ktx = { module = "androidx.security:security-crypto-ktx", version.ref = "securityCryptoKtx" }
|
|
ui = { module = "androidx.compose.ui:ui", version.ref = "compose_ui" }
|
|
ui-test-junit4 = { module = "androidx.compose.ui:ui-test-junit4", version.ref = "compose_ui" }
|
|
ui-test-manifest = { module = "androidx.compose.ui:ui-test-manifest", version.ref = "compose_ui" }
|
|
ui-tooling = { module = "androidx.compose.ui:ui-tooling", version.ref = "compose_ui" }
|
|
ui-tooling-preview = { module = "androidx.compose.ui:ui-tooling-preview", version.ref = "compose_ui" }
|
|
zxing-android-embedded = { module = "com.journeyapps:zxing-android-embedded", version.ref = "zxingAndroidEmbedded" }
|
|
okhttp = { group = "com.squareup.okhttp3", name = "okhttp", version.ref = "okhttp" }
|
|
okhttpCoroutines = { group = "com.squareup.okhttp3", name = "okhttp-coroutines", version.ref = "okhttp" }
|
|
work-runtime-ktx = { group = "androidx.work", name = "work-runtime-ktx", version.ref = "workRuntimeKtx" }
|
|
coil-compose = { group = "io.coil-kt.coil3", name = "coil-compose", version.ref = "coil" }
|
|
coil-gif = { group = "io.coil-kt.coil3", name = "coil-gif", version.ref = "coil" }
|
|
coil-svg = { group = "io.coil-kt.coil3", name = "coil-svg", version.ref = "coil" }
|
|
coil-okhttp = { group = "io.coil-kt.coil3", name = "coil-network-okhttp", version.ref = "coil" }
|
|
storage = { module = "com.anggrayudi:storage", version.ref = "storage" }
|
|
material3-window = { group = "androidx.compose.material3", name = "material3-window-size-class", version.ref = "material3" }
|
|
paging-common = { group = "androidx.paging", name = "paging-common", version.ref = "pagingCommon" }
|
|
paging-compose = { group = "androidx.paging", name = "paging-compose", version.ref = "pagingCommon" }
|
|
paging-runtime = { group = "androidx.paging", name = "paging-runtime", version.ref = "pagingCommon" }
|
|
mockk = { module = "io.mockk:mockk", version.ref = "mockk" }
|
|
kotlinx-coroutines-test = { module = "org.jetbrains.kotlinx:kotlinx-coroutines-test", version.ref = "coroutinesTest" }
|
|
kmptor-runtime = { module = "io.matthewnelson.kmp-tor:runtime", version.ref = "kmpTor" }
|
|
kmptor-resource-exec = { module = "io.matthewnelson.kmp-tor:resource-exec-tor", version.ref = "kmpTorResource" }
|
|
secp256k1-jni-jvm = { module = "fr.acinq.secp256k1:secp256k1-kmp-jni-jvm", version.ref = "secp256k1Jni" }
|
|
leakcanary = { group = "com.android.tools.studio.leakcanary", name = "leakcanary", version.ref = "leakcanary" }
|
|
|
|
[plugins]
|
|
androidLibrary = { id = "com.android.library", version.ref = "agp" }
|
|
androidApplication = { id = "com.android.application", version.ref = "agp" }
|
|
gradle_ktlint = { id = "org.jlleitschuh.gradle.ktlint", version = "ktlint" }
|
|
serialization = { id = "org.jetbrains.kotlin.plugin.serialization", version.ref = "kotlin" }
|
|
kotlin_ksp = { id = "com.google.devtools.ksp", version = "ksp" }
|
|
jetbrainsComposeCompiler = { id = "org.jetbrains.kotlin.plugin.compose", version.ref = "kotlin" }
|