Expand description
vault-core — shared encryption, storage, and tooling for UnENVerse.
Used by the Tauri desktop app, the HTTP server (unv-server), and the CLI
(unv-cli). Has no dependency on Tauri; accepts &Path for all I/O.
Re-exports§
pub use generators::generate_certificate;pub use generators::generate_ssh_keypair;pub use permex::eval as eval_perm_expr;pub use permex::parse as parse_perm_expr;pub use permex::EntryView;pub use permex::Expr as PermExpr;pub use permex::Field as PermField;pub use users::assign_user_class;pub use users::create_user;pub use users::create_user_class;pub use users::create_user_token;pub use users::delete_user;pub use users::delete_user_class;pub use users::effective_permission_expr;pub use users::ensure_owner_user;pub use users::filter_vault_for_user;pub use users::get_class_permissions;pub use users::get_permission_expr;pub use users::get_user_capabilities;pub use users::get_user_permissions;pub use users::glob_matches;pub use users::init_users_schema;pub use users::list_user_classes;pub use users::list_user_tokens;pub use users::list_users;pub use users::merge_user_vault_write;pub use users::rename_user;pub use users::revoke_user_token;pub use users::seed_default_admin;pub use users::set_class_permissions;pub use users::set_permission_expr;pub use users::set_user_password;pub use users::set_user_permissions;pub use users::token_user_id;pub use users::update_user_class;pub use users::verify_user_password;pub use users::verify_user_token;pub use users::AdminSeed;pub use users::ClassPermission;pub use users::PermissionRecord;pub use users::TokenRecord;pub use users::UserClass;pub use users::UserRecord;
Modules§
- blast
- Phase 36 — blast radius (ADR-0142).
- bundle_
import - Import a Python config module as bundle-local variables (Phase 24.1).
- bundle_
scope - Bundle-local template resolution (Phase 24.1, step 4).
- calendar
- iCalendar (RFC 5545) feed for the vault’s dates — the Rust twin of
src/ts/calendar.ts. - catalogue
- The provider catalogue: a signed, public table of issuer key prefixes that
unv enrichconsults before the table compiled into the binary. - composite
- Composite secrets (Phase 24.1) — one value with secrets inside it.
- config_
check - Cross-chunk, cross-format checks for a project (Phase 29, “the config compiler”; ADR-0137).
- config_
history - Phase 35 — the config time machine (ADR-0141).
- cxf
- FIDO Credential Exchange (CXF) import and export — Phase 24.5.
- entropy
- Entropy sources for secret generation.
- generators
- Cryptographic key and certificate generators.
- ics_
feeds - Calendar feed tokens — Phase 24.3.
- jwks
- The public half of a
signing_keyas a JSON Web Key Set (Phase 24.5). - nodes
- Phase 34 — Nodes: the protocol, the hub’s registry and the node’s config.
- nodes_
apply - Phase 34 — the filesystem half of a node: hash a target, apply bytes to it transactionally, and keep the last few versions.
- oauth
- OAuth refresh-token grants, shared by
unv oauth refreshand the desktop app’s “Refresh access token” (Phase 24.5). Pure over JSON: the HTTP call is the caller’s (the CLI’s blocking client, the app’s pinnedremote_request), so there is exactly one reading of what an issuer’s answer means and one rule for what gets stored. - permex
- Permission expressions — a small boolean language over vault entries.
- pgp
- What an OpenPGP key says about itself: fingerprint, key id, user ids and, the
reason this exists, when it expires (Phase 24.5,
gpg_key). - php_
config - A reader for PHP array literals, enough for application config files such as
Nextcloud’s
config/config.php(Phase 38.1, ADR-0148). - pool
- The key-pool state file:
pools.json. - secret_
types - The secret-type registry — Phase 24.5.
- session_
import - Web-session capture parsers (Phase 24.5, step 3).
- stack
- Phase 38 — stack integrations as data (ADR-0144).
- storage
- Row-per-entry storage, schema v2 (Phase 30, review-01 section 2.1; ADR-0138).
- telemetry
- Structured logging, shared by all three binaries.
- templates
- Secret templates: predefined field presets for common services (a GitHub PAT,
an AWS key, a Postgres DSN). One JSON file at the repo root,
secret-templates.json, compiled in here and imported by the app’s Templates pane, sounv entry add --template IDand the pane offer the same presets (Phase 33.6). - textdiff
- A small line diff for rendered config files (Phase 35).
- tls
- Shared TLS client policy — the one place that decides whether a server is trusted.
- toml_
import - Import TOML config values as environment-style name/value pairs.
- totp
- RFC 6238 time-based one-time passwords.
- totp_
import - Reading and writing the export files other authenticator apps produce.
- type_
emit - Per-type emitters and validators for the Phase 24.5 credential types.
- uid_
registry - The unique-ID registry — Phase 24.4.
- users
- User management, token management, and RBAC for UnENVerse.
Structs§
- Audit
Row - A single audit log row, including the hash-chain fields.
- SaveCtx
- Who is writing, and what they believe the vault currently is.
- SqlConnection
- A connection to a SQLite database.
Constants§
- CONFLICT_
ERR - Marker prefix on the error returned when a compare-and-swap write is refused. Callers match on this to tell “someone else wrote first” from a real failure.
- KEY_LEN
- MERGED_
SUFFIX - Appended to the version returned by a save that folded in other writers’
changes (Phase 30). The part before it is the current version token; a writer
that sends the whole thing back as
expect_versionis understood. - SALT_
LEN - SCHEMA_
ERR - Marker prefix on the error returned when the stored vault was written by a newer build than this one. Callers match on it to tell “upgrade me” from a real failure.
- VAULT_
SCHEMA_ VERSION - The vault-document schema this build writes.
Traits§
- Zeroize
- Trait for securely erasing values from memory.
Functions§
- apply_
row_ patch - Phase 30.1: apply a delta to a stored vault document. Shared by
PATCH /api/vaultand the desktop’ssave_vault_rowsso they cannot differ. - check_
salt_ pairing - Refuse to derive a key when a database exists but its salt does not.
- check_
schema_ version - Refuses to touch a vault written by a newer build.
- derive_
key - Derives a 32-byte AES-256 key from
passwordandsaltusing Argon2id (m=65536 KiB, t=3, p=1 — OWASP 2023 recommendation). - ensure_
current_ schema - Refuse a newer schema and convert a v1 vault, so that a version read after this is a version of the converted vault. A caller that reads the version before the data (the safe order, see the server’s PUT handler) must call this first, or it pairs a v1 hash with a v2 document and its first save conflicts.
- entry_
ck - Canonical identity key for a vault entry.
- env_
quote - A value as it must appear after the
=in a.env(Phase 23, E1). - get_
expiring_ entries - Returns vault entries whose
expires_atdate falls withinwithin_daysdays from today (inclusive of today, exclusive of entries already expired). - get_
expiring_ entries_ for_ user - Like
get_expiring_entriesbut first filters the vault to the entries the user is permitted to read. Prevents non-owner sessions from learning about the expiry (and full contents) of secrets outside their RBAC scope. - init_
schema - Creates the
vaultandvault_audittables if absent; adds hash-chain columns tovault_auditvia idempotent ALTER TABLE (errors silently ignored on existing columns). - iso_now
- load_
audit - Returns all audit rows ordered newest-first.
- load_
vault - Loads the raw vault JSON from an open connection.
- load_
vault_ lite - The vault document without any entry’s
version_history: what a selective read needs, without the 50-revision secret trail per entry that a full read carries (Phase 30). - migrate_
legacy_ json - Inserts raw JSON from a legacy
vault.jsoninto thevaulttable. Called once on first unlock after a Phase 1 → Phase 2 upgrade. - new_
uuid - Returns the current UTC time as an ISO-8601 string (
YYYY-MM-DDTHH:MM:SSZ). A random UUID v4, with the version and variant bits set. - open_db
- Opens (or creates) the SQLCipher database at
db_pathusing the 32-bytekey. - read_
or_ create_ salt - Reads salt from
salt_path; generates and writes a fresh 16-byte salt if absent. - record_
event - Records a hash-chained audit event with the current timestamp.
- restrict_
to_ owner - Restrict a file to its owner where the platform can express that.
- save_
vault - Serialises
datato the vault, updatingversion_historyon key changes and appending to thevault_audithash chain. Returns the new version. - vault_
schema_ version - The schema version stamped on the stored vault, or
Nonefor a vault written before versioning existed (or an empty database). - vault_
version - Current version of the stored vault, or
Nonewhen the vault is empty. - verify_
vault_ integrity - Verifies the stored vault data against its SHA-256 integrity hash.
Returns
Ok(true)if hash matches,Ok(false)if tampered or hash absent,Erron I/O.
Type Aliases§
- Vault
Key - In-memory AES-256 vault key.
Derive Macros§
- Zeroize
- Derive the
Zeroizetrait.