|
UnENVerse 0.42.6
Local-first desktop secrets manager — TypeScript frontend
|
import type;Functions | |
| function export | copyAll (fmt:string) |
| function async | exportAs (fmt:string) |
| function export | parsePythonAssignments (text:string) |
Import simple Python NAME = literal config assignments; never evaluates code. | |
| function async | downloadText (content:string, filename:string, okMsg:string) |
Writes content to disk as filename and toasts what actually happened. | |
| function export | exportK8sSecret (name='unenverse') |
| Kubernetes Secret manifest (stringData — values kept readable, not base64). | |
| function export | exportTfvars () |
| Terraform .tfvars — variable = "value" pairs. | |
| function async | deriveBackupKey (password:string, salt:BufferSource, iterations=PBKDF2_ITERS,) |
| Base64 a buffer in chunks. | |
| function async | importEncryptedBackup (text:string, password:string) |
| Decrypt a .vaultbak envelope and replace the current vault. | |
| function | objectRecord (value:unknown) |
| function export | openEnvImportModal (vars:EnvVar[]) |
| function export | closeEnvImportModal () |
| function export | confirmEnvImport () |
| function export | handleFileSelect (input:HTMLInputElement) |
| function | loadFullVault (data:VaultData) |
Replace the whole vault from a parsed { api_keys, projects?, user_categories? } object. | |
Variables | |
| return | vars |
| const | BAK_MAGIC = 'ENVVBAK1' |
| const | PBKDF2_ITERS = 210_000 |
| export interface | EnvVar |
| value | __pad0__ |
| const | envVarsForList = new WeakMap<HTMLElement, EnvVar[]>() |
| function export copyAll | ( | fmt:string | ) |
| function async exportAs | ( | fmt:string | ) |
| function export parsePythonAssignments | ( | text:string | ) |
Import simple Python NAME = literal config assignments; never evaluates code.
| function async downloadText | ( | content:string, | |
| filename:string, | |||
| okMsg:string | |||
| ) |
Writes content to disk as filename and toasts what actually happened.
Exported for the timeline panel's .ics export and every other exporter that used to hand-roll the blob-and-anchor dance — one call site is one place for saveFile's Tauri/browser split to live, instead of nine.
A3 (2026-09-14): okMsg used to be shown unconditionally, whether or not anything was written — WebKitGTK's webview has no download handler, so every "Exported ✓" here was a lie in the desktop app. The toast now follows the write and names the real path when there is one.
| function export exportK8sSecret | ( | name = 'unenverse' | ) |
Kubernetes Secret manifest (stringData — values kept readable, not base64).
| function export exportTfvars | ( | ) |
Terraform .tfvars — variable = "value" pairs.
| function async deriveBackupKey | ( | password:string, | |
| salt:BufferSource, | |||
iterations = PBKDF2_ITERS |
|||
| ) |
Base64 a buffer in chunks.
String.fromCharCode(...bytes) spreads every byte as a separate argument, so it blew the call stack once the ciphertext passed roughly 100 KB — which any vault holding a few PEM certificates does. Nothing caught the RangeError, so "Export encrypted backup" simply did nothing, and it failed for exactly the vaults with the most to lose. Encrypt the full vault JSON with a separate backup password (not the master key).
| function async importEncryptedBackup | ( | text:string, | |
| password:string | |||
| ) |
Decrypt a .vaultbak envelope and replace the current vault.
| function objectRecord | ( | value:unknown | ) |
| function export openEnvImportModal | ( | vars:EnvVar[] | ) |
| function export closeEnvImportModal | ( | ) |
| function export confirmEnvImport | ( | ) |
| function export handleFileSelect | ( | input:HTMLInputElement | ) |
| function loadFullVault | ( | data:VaultData | ) |
Replace the whole vault from a parsed { api_keys, projects?, user_categories? } object.
| return vars |
| const BAK_MAGIC = 'ENVVBAK1' |
| const PBKDF2_ITERS = 210_000 |
| export interface EnvVar |
| value __pad0__ |
| const envVarsForList = new WeakMap<HTMLElement, EnvVar[]>() |