Files
Amber/gradle/libs.versions.toml
T
greenart7c3 98dfca7095 Envelope-encrypt NIP-46 connection secrets at rest (GHSA-5fjp-ghh8-wch8)
The per-account Room database (amber_db_<npub>) stored two NIP-46 secret
values as cleartext TEXT columns: the bunker connection `secret` and the
`localKey` — the latter being a full Nostr private key. Anyone with access
to the app's internal storage (rooted device, privilege-escalating malware,
or a future bug exporting the DB) could recover these values and bypass the
Keystore protection the main account nsec enjoys (CWE-312).

Fix: envelope-encrypt both columns with the existing Keystore-backed AES-256-GCM
key (SecureCryptoHelper) before Room persistence, and decrypt on read, so every
existing consumer continues to see the plaintext values it already expects.

- SecureCryptoHelper: add non-suspend encryptBlocking/decryptBlocking so
  Migration.migrate() and getByKeySync() can call them without a runBlocking
  bridge; suspend variants now delegate to the blocking implementations.
- ApplicationEntityCrypto.kt (new): encryptForStorage/decryptFromStorage
  mappers + DecryptingPagingSource. Sentinel rule: empty values stay "" at
  rest (matches the WebDAV password idiom in LocalPreferences.kt:661-681),
  preserving `WHERE localKey != ''` enumeration in NotificationSubscription
  and the `localPubKey` derivation on empty localKey.
- ApplicationDao: split methods touching `secret`/`localKey` into Room-
  generated `*Raw` (encrypted columns) and default-method wrappers that
  apply the mappers. `getBySecret` rewritten to decrypt and filter in Kotlin
  (random GCM IV breaks `WHERE secret = :secret`).
- CachingApplicationDao: add delegating `*Raw` overrides so the decorator
  still instantiates; cache logic unchanged.
- AppDatabase: add MIGRATION_18_19 (in-place envelope-encrypt of existing
  plaintext rows via compiled statement + transaction; empty values stay
  empty). Bump @Database version to 19.
- Backup/restore: no changes — ApplicationBackup.buildPayload reads via the
  wrapped DAO (plaintext) and the JSON is already NIP-44 encrypted by the
  account key; restore goes through the wrapped insert (auto-encrypts).
- Tests: new androidTest ApplicationEntityCryptoTest covers round-trip,
  raw-column-ciphertext assertion, empty sentinel, localPubKey derivation,
  getAllWithLocalKey filter, getBySecret (hit/miss/empty),
  insertApplicationWithPermissions, getAll, and the MIGRATION_18_19 row
  re-encryption. Requires a device/emulator (AndroidKeyStore unavailable
  under JVM test).
- New room-testing androidTestImplementation dependency.

Verified: ktlintCheck, lint (no issues), testFreeDebugUnitTest (0 failures),
compileFreeDebugAndroidTestKotlin, assembleFreeDebug, assembleOfflineDebug,
and the offline merged manifest check (no INTERNET/ACCESS_NETWORK_STATE/
CHANGE_NETWORK_STATE permissions leaked).
2026-08-10 14:55:51 -03:00

97 lines
5.9 KiB
TOML

[versions]
activityCompose = "1.13.0"
appcompat = "1.7.1"
biometricKtx = "1.2.0-alpha05"
core = "3.5.4"
coreKtx = "1.19.0"
datastorePreferences = "1.2.1"
espressoCore = "3.7.0"
junit = "4.13.2"
junitVersion = "1.3.0"
lifecycle_version = "2.11.0"
material3 = "1.4.0"
nav_version = "2.9.8"
quartz = "1.12.6"
compose_ui = "1.11.3"
roomKtx = "2.8.4"
securityCryptoKtx = "1.1.0"
zxingAndroidEmbedded = "4.3.0"
okhttp = "5.4.0"
kotlin = "2.4.0"
workRuntimeKtx = "2.11.2"
agp = "9.3.0"
ktlint = "14.1.0"
ksp = "2.3.5"
coil = "3.5.0"
storage = "2.2.0"
jna = "5.19.1"
materialIconsExtended = "1.7.8"
collections = "0.5.0"
pagingCommon = "3.5.0"
mockk = "1.14.11"
coroutinesTest = "1.11.0"
kmpTor = "2.6.0"
kmpTorResource = "409.5.0"
secp256k1Jni = "0.23.0"
leakcanary = "1.0.0"
[libraries]
datastore-preferences = { module = "androidx.datastore:datastore-preferences", version.ref = "datastorePreferences" }
jna = { module = "net.java.dev.jna:jna", version.ref = "jna" }
activity-compose = { module = "androidx.activity:activity-compose", version.ref = "activityCompose" }
appcompat = { module = "androidx.appcompat:appcompat", version.ref = "appcompat" }
biometric-ktx = { module = "androidx.biometric:biometric-ktx", version.ref = "biometricKtx" }
core = { module = "com.google.zxing:core", version.ref = "core" }
core-ktx = { module = "androidx.core:core-ktx", version.ref = "coreKtx" }
espresso-core = { module = "androidx.test.espresso:espresso-core", version.ref = "espressoCore" }
ext-junit = { module = "androidx.test.ext:junit", version.ref = "junitVersion" }
junit = { module = "junit:junit", version.ref = "junit" }
lifecycle-runtime-compose = { module = "androidx.lifecycle:lifecycle-runtime-compose", version.ref = "lifecycle_version" }
lifecycle-runtime-ktx = { module = "androidx.lifecycle:lifecycle-runtime-ktx", version.ref = "lifecycle_version" }
lifecycle-viewmodel-compose = { module = "androidx.lifecycle:lifecycle-viewmodel-compose", version.ref = "lifecycle_version" }
lifecycle-process = { module = "androidx.lifecycle:lifecycle-process", version.ref = "lifecycle_version" }
material-icons-extended = { module = "androidx.compose.material:material-icons-extended", version.ref = "materialIconsExtended" }
material3 = { module = "androidx.compose.material3:material3", version.ref = "material3" }
navigation-compose = { module = "androidx.navigation:navigation-compose", version.ref = "nav_version" }
quartz = { module = "com.vitorpamplona.quartz:quartz-android", version.ref = "quartz" }
kotlinx-collections-immutable = { module = "org.jetbrains.kotlinx:kotlinx-collections-immutable", version.ref = "collections" }
room-compiler = { module = "androidx.room:room-compiler", version.ref = "roomKtx" }
room-ktx = { module = "androidx.room:room-ktx", version.ref = "roomKtx" }
room-runtime = { module = "androidx.room:room-runtime", version.ref = "roomKtx" }
room-paging = { module = "androidx.room:room-paging", version.ref = "roomKtx" }
room-testing = { module = "androidx.room:room-testing", version.ref = "roomKtx" }
security-crypto = { module = "androidx.security:security-crypto", version.ref = "securityCryptoKtx" }
security-crypto-ktx = { module = "androidx.security:security-crypto-ktx", version.ref = "securityCryptoKtx" }
ui = { module = "androidx.compose.ui:ui", version.ref = "compose_ui" }
ui-test-junit4 = { module = "androidx.compose.ui:ui-test-junit4", version.ref = "compose_ui" }
ui-test-manifest = { module = "androidx.compose.ui:ui-test-manifest", version.ref = "compose_ui" }
ui-tooling = { module = "androidx.compose.ui:ui-tooling", version.ref = "compose_ui" }
ui-tooling-preview = { module = "androidx.compose.ui:ui-tooling-preview", version.ref = "compose_ui" }
zxing-android-embedded = { module = "com.journeyapps:zxing-android-embedded", version.ref = "zxingAndroidEmbedded" }
okhttp = { group = "com.squareup.okhttp3", name = "okhttp", version.ref = "okhttp" }
okhttpCoroutines = { group = "com.squareup.okhttp3", name = "okhttp-coroutines", version.ref = "okhttp" }
work-runtime-ktx = { group = "androidx.work", name = "work-runtime-ktx", version.ref = "workRuntimeKtx" }
coil-compose = { group = "io.coil-kt.coil3", name = "coil-compose", version.ref = "coil" }
coil-gif = { group = "io.coil-kt.coil3", name = "coil-gif", version.ref = "coil" }
coil-svg = { group = "io.coil-kt.coil3", name = "coil-svg", version.ref = "coil" }
coil-okhttp = { group = "io.coil-kt.coil3", name = "coil-network-okhttp", version.ref = "coil" }
storage = { module = "com.anggrayudi:storage", version.ref = "storage" }
material3-window = { group = "androidx.compose.material3", name = "material3-window-size-class", version.ref = "material3" }
paging-common = { group = "androidx.paging", name = "paging-common", version.ref = "pagingCommon" }
paging-compose = { group = "androidx.paging", name = "paging-compose", version.ref = "pagingCommon" }
paging-runtime = { group = "androidx.paging", name = "paging-runtime", version.ref = "pagingCommon" }
mockk = { module = "io.mockk:mockk", version.ref = "mockk" }
kotlinx-coroutines-test = { module = "org.jetbrains.kotlinx:kotlinx-coroutines-test", version.ref = "coroutinesTest" }
kmptor-runtime = { module = "io.matthewnelson.kmp-tor:runtime", version.ref = "kmpTor" }
kmptor-resource-exec = { module = "io.matthewnelson.kmp-tor:resource-exec-tor", version.ref = "kmpTorResource" }
secp256k1-jni-jvm = { module = "fr.acinq.secp256k1:secp256k1-kmp-jni-jvm", version.ref = "secp256k1Jni" }
leakcanary = { group = "com.android.tools.studio.leakcanary", name = "leakcanary", version.ref = "leakcanary" }
[plugins]
androidLibrary = { id = "com.android.library", version.ref = "agp" }
androidApplication = { id = "com.android.application", version.ref = "agp" }
gradle_ktlint = { id = "org.jlleitschuh.gradle.ktlint", version = "ktlint" }
serialization = { id = "org.jetbrains.kotlin.plugin.serialization", version.ref = "kotlin" }
kotlin_ksp = { id = "com.google.devtools.ksp", version = "ksp" }
jetbrainsComposeCompiler = { id = "org.jetbrains.kotlin.plugin.compose", version.ref = "kotlin" }