Files
Amber/gradle
Claudeandgreenart7c3 e4256d0ebf Add an opt-in passphrase lock for the desktop signer
Provides protection that does not rely on the OS credential store: when a
passphrase is set, the AES master key is stored only wrapped (AES-256-GCM)
under an Argon2id-derived key in master.key.enc, and the plain keystore and
its credential-store/file password are deleted. The passphrase is never
persisted.

- PassphraseLock: enable/unlock/lock/disable/changePassphrase, with a
  DISABLED/LOCKED/UNLOCKED state flow the UI observes
- Startup unlock screen; Settings → Security controls to set, change and
  remove the passphrase, choose an auto-lock timeout, and lock on demand
- Locking evicts every decrypted key from memory, clears pending requests
  and disconnects the relays; the bunker engine refuses to consume or
  subscribe while locked, so nothing can be signed until unlock
- Auto-lock after an idle timeout (off by default); activity resets it
- Full-lifecycle unit test with reduced Argon2 cost parameters

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YQTVwy8RBj7spdEK3aEc3i
2026-09-28 10:12:10 -03:00
..
2024-10-19 15:36:03 -03:00