Repository navigation
Conversation
rbw edit re-encrypted password/notes with the user/org key while the server kept the entry's individual item key, corrupting the entry for all clients (doy#364).
Encrypt custom-field (and password/notes) values with the entry's individual item key when present, and send that key on the cipher PUT. Without this, keyed items become mixed-key and fail with invalid mac (doy#364; same plumbing as doy#368). Refuse SSH key entries (Client::edit is unreachable for them) and linked fields. Require boolean fields to be true/false. Interactive edits strip only the appended help suffix so user lines starting with # are kept.
|
Heads up: I opened #371, which overlaps this PR. It fixes the same item-key corruption (#364) with the same approach, but bundles four more cipher-write fixes on top: preserving Because those additions replace I did not want to duplicate your work silently, so either order works for me: if this PR merges first I will rebase #371 onto it and drop the duplicated part; if @doy prefers the combined one, this can be closed. |
|
I have no preference. I am happy if i can settle my patches. |
Fixes #364.
rbw editencrypted fields with the user/org key and dropped thekeyfield from the cipher PUT, corrupting entries that have an individual item key (vault becomes undecryptable withinvalid mac).Now the agent encrypts with the item key when present and the PUT preserves
key. Tested against vaultwarden.