|
UnENVerse 0.42.6
Local-first desktop secrets manager — TypeScript frontend
|
import type;Functions | |
| function async | invoke< T=unknown > (cmd:string, args:Record< string, unknown >={},) |
| User/class management dispatcher. | |
| function | strictToggleHtml (kind:'user'| 'class', on:boolean) |
Strict write scoping (unv user strict-write, Phase 33.4): under it a write must satisfy every scope the subject has, not any one. | |
| function | wireStrictToggle (kind:'user'| 'class', id:string, reload:()=> Promise< void >|void,) |
| function | totpSectionHtml (totp:TotpState) |
| The section body for a user's second factor. | |
| function async | changePassword (userId:string) |
| function async | deleteUser (userId:string) |
| function async | newToken (userId:string) |
| function | showTokenCreatedOverlay (token:string) |
| function async | revokeToken (tokenId:string, userId:string) |
| function export | openCreateUserForm () |
| function async | renderClassesPanel () |
| function async | renderClassDetail (classId:string) |
| function async | saveClassDetails (classId:string) |
| function async | deleteClass (classId:string) |
| function | openCreateClassForm () |
| function export | resetUsersPanelState () |
| Forgets which user/class was open. | |
Variables | |
| const | localInvoke |
| enabled | __pad0__ |
| let | _activeClassId |
| let | _activeSubPanel |
| let | _usersPanelInited = false |
| function async invoke< T=unknown > | ( | cmd:string, | |
args:Record< string, unknown > = {} |
|||
| ) |
User/class management dispatcher.
On a remote vault the local SQLCipher DB is locked, so route each command to the server's owner-only REST endpoints; on a local vault, fall through to the Tauri command. Keeps every call site unchanged.
| function strictToggleHtml | ( | kind:'user'| 'class', | |
| on:boolean | |||
| ) |
Strict write scoping (unv user strict-write, Phase 33.4): under it a write must satisfy every scope the subject has, not any one.
Shown as a checkbox in the user and class detail. Owner-only on the server, as turning it off widens what a sub-user can write.
| function wireStrictToggle | ( | kind:'user'| 'class', | |
| id:string, | |||
| reload:(), | |||
| Promise< void >| void | |||
| ) |
| function totpSectionHtml | ( | totp:TotpState | ) |
The section body for a user's second factor.
Three states, and the middle one is the reason enrollment is two-phase: a secret exists but was never confirmed, so the account is not protected and must not look as though it is. Binds the section's buttons.
Assignment, not addEventListener: renderUserDetail rewrites this markup on every visit and after every action, and the enrollment panel is shown, hidden and shown again within one render — invariant 9. Phase one: mint a secret and show it for manual entry.
There is no QR code. Drawing one needs a library, and the CSP allows no external script — relaxing it so that a secret can be rendered would be an odd trade. Every authenticator accepts manual entry, so the secret is shown in groups of four, which is the difference between typing 32 characters right and typing them wrong. Base32 in groups of four, matching vault_core::totp::grouped.
| function async changePassword | ( | userId:string | ) |
| function async deleteUser | ( | userId:string | ) |
| function async newToken | ( | userId:string | ) |
| function showTokenCreatedOverlay | ( | token:string | ) |
| function async revokeToken | ( | tokenId:string, | |
| userId:string | |||
| ) |
| function export openCreateUserForm | ( | ) |
| function async renderClassesPanel | ( | ) |
| function async renderClassDetail | ( | classId:string | ) |
| function async saveClassDetails | ( | classId:string | ) |
| function async deleteClass | ( | classId:string | ) |
| function openCreateClassForm | ( | ) |
| function export resetUsersPanelState | ( | ) |
Forgets which user/class was open.
User and class ids are scoped to one vault, so carrying a selection from one server to the next made the panel highlight — and try to load — an id that belongs to a different vault entirely. Call whenever the backing vault changes.
| const localInvoke |
| enabled __pad0__ |
| let _activeClassId |
| let _activeSubPanel |
| let _usersPanelInited = false |