Repository navigation
Conversation
|
I will check the linter issues. ✌️ |
these are pre-existing lints that newer clippy versions have started flagging (they fail the lint CI job on main as well), and are unrelated to the organization and collection support in this branch: - collapse two match expressions into ? in actions::unlock - use a match guard instead of a nested if in classify_login_error - drop a redundant reference in a format! argument in dirs cargo clippy --all-targets --all-features -- -Dwarnings is clean with this applied.
|
heads up on the red CI, since it looks worse than it is: the that clippy failure is also why there's a |
Fixes #102
Summary
This implements organization/collection support as requested in #102:
rbw syncnow stores the account's organizations and collections in the local database, and each entry's collection memberships.rbw list --fields name,org,collection(andsearch --fields ...) show which organization and collections an entry belongs to;rbw get --rawincludes them in the JSON output.--org <name>and--collection <name>filter/disambiguate lookups onget,code,edit,remove,history, andsearch— useful when the same entry name exists both personally and in an organization.rbw addandrbw generateaccept--org <name> --collection <name>to create entries directly in an organization (POST /ciphers/create), encrypted with the organization key.--collectionis repeatable; the two flags require each other since Bitwarden requires org items to be in at least one collection.rbw edit --set-collection <name>replaces the set of collections an existing org entry belongs to (PUT /ciphers/{id}/collections), allowing moves between collections of the same organization. This doesn't touch the entry's contents and doesn't open an editor — no re-encryption is needed since all collections of an organization share the org key.Design notes
rename/aliasfor server casing variance,--fieldsvalues, filter flags), with two deliberate differences: collections are many-to-many, so they're stored as lookup tables (Db.organizations,Db.collections) plusEntry.collection_idsinstead of denormalized per entry — each collection name is decrypted at most once per command; and collection names are encrypted with the organization key, unlike folder names (org names arrive in plaintext in the sync profile).Decrypt/Encryptactions already carryorg_id.#[serde(default)], so existing db files load fine, and older rbw versions simply ignore the new fields.collectionsarray, per-ciphercollectionIds, and orgnameare all optional, so servers that omit them keep working; a collection name that fails to decrypt degrades to showing its id with a warning instead of failing the command.--org/--collectionact as a hard pre-filter before the existing exact/substring disambiguation infind_entry_raw, which stays untouched. Filter names match exactly (case-insensitively with-i); a miss lists the known names in the error.Out of scope (possible follow-ups)
PUT /ciphers/{id}/share; requires re-encrypting every field with the org key).--collectionintentionally has no create-if-missing behavior, unlike--folder.Testing
Opt::command().debug_assert()).add/generatewith--org/--collectionand verifying them in the web vault;editon org entries preserving collection membership;--set-collectionmoving entries between collections; error paths (unknown names, org item without collection,--set-collectionon a personal entry).rbw list --fields name,org,collectionthat groups entries by organization and collection.