05/18 Enhanced codes and functionalities 4
This commit is contained in:
@@ -0,0 +1,45 @@
|
||||
"""encrypt shared item name — add enc_name/iv_name to shared_items
|
||||
|
||||
Revision ID: g7h8i9j0k1l2
|
||||
Revises: f6a7b8c9d0e1
|
||||
Create Date: 2026-05-18 00:00:00.000000
|
||||
|
||||
Prior to this migration, shared_items.item_name stored the plaintext display
|
||||
name of the shared vault item (e.g. "Chase Bank"), leaking it to anyone with
|
||||
DB read access and contradicting the zero-knowledge architecture.
|
||||
|
||||
After this migration:
|
||||
- enc_name : AES-256-GCM ciphertext of the item name, encrypted with the
|
||||
ECDH shared secret (same key used for enc_data). Base64.
|
||||
- iv_name : 12-byte GCM nonce for enc_name. Base64.
|
||||
- item_name : Repurposed as a non-sensitive fallback label (item_type string,
|
||||
e.g. "password"). Existing rows keep their current value;
|
||||
new rows set item_name = item_type.
|
||||
|
||||
Both new columns are nullable so existing rows are not affected before the
|
||||
application writes enc_name/iv_name on the next share operation.
|
||||
"""
|
||||
from alembic import op
|
||||
import sqlalchemy as sa
|
||||
|
||||
|
||||
revision = 'g7h8i9j0k1l2'
|
||||
down_revision = 'f6a7b8c9d0e1'
|
||||
branch_labels = None
|
||||
depends_on = None
|
||||
|
||||
|
||||
def upgrade():
|
||||
op.add_column(
|
||||
'shared_items',
|
||||
sa.Column('enc_name', sa.String(512), nullable=True),
|
||||
)
|
||||
op.add_column(
|
||||
'shared_items',
|
||||
sa.Column('iv_name', sa.String(64), nullable=True),
|
||||
)
|
||||
|
||||
|
||||
def downgrade():
|
||||
op.drop_column('shared_items', 'iv_name')
|
||||
op.drop_column('shared_items', 'enc_name')
|
||||
Reference in New Issue
Block a user