Expand description
FIDO Credential Exchange (CXF) import and export — Phase 24.5.
CXF (FIDO Alliance) is the JSON format password managers are converging on
for moving credentials between products. This is the one place it is read
or written: unv-cli calls it directly, and the desktop app reaches it
over IPC, the same split TOTP import/export already uses and for the same
reason — six formats parsed twice is six chances for the app and the CLI
to disagree about what a file meant.
§What this is modelled from, and what that means
Built from the public CXF field tables (Item, Collection, the
basic-auth / api-key / totp / note / wifi / ssh-key /
custom-fields credential shapes) rather than against a corpus of real
exports from other managers — the design’s own note said to check which
managers emit a CXF file today before building this, and that check is
still outstanding. Treat the shape here as a reasonable-effort reading of
the spec, not a verified interop guarantee, until it has been run against
a real export from at least one other product.
§The mapping
An Item with one credential becomes a plain entry. An Item with
several becomes a Phase 24.1 bundle: one secretType: "bundle" parent
plus one member per non-custom-fields credential. CXF custom fields become
the bundle’s local variables, so they can participate in scoped templates
rather than appearing as a fake member.
A totp credential never becomes its own entry: it is Phase 22’s stored
seed, a field on whichever entry the rest of the item produced, matching
how this project already refuses to give TOTP its own SecretType.
Every UnENVerse type without a native CXF shape — the majority of the 26 in
secret_types — exports as custom-fields carrying an
_unenverse_type field, so another manager sees labelled fields and
UnENVerse-to-UnENVerse round-trips losslessly. Import of custom-fields
reads _unenverse_type back when present and falls back to extra_vars
otherwise, so a CXF file honestly written by some other tool still imports
as something rather than being refused.
Structs§
Enums§
Functions§
- export
- Builds a CXF document from a slice of entries (
VaultData.api_keys). - import
- Parses and converts a whole document.
new_id/noware injected the way every other importer in this project injects them — determinism for tests, and one clock rather than each entry stamping its own. - parse
- Parses a CXF JSON document from bytes.