Skip to main content

Module cxf

Module cxf 

Source
Expand description

FIDO Credential Exchange (CXF) import and export — Phase 24.5.

CXF (FIDO Alliance) is the JSON format password managers are converging on for moving credentials between products. This is the one place it is read or written: unv-cli calls it directly, and the desktop app reaches it over IPC, the same split TOTP import/export already uses and for the same reason — six formats parsed twice is six chances for the app and the CLI to disagree about what a file meant.

§What this is modelled from, and what that means

Built from the public CXF field tables (Item, Collection, the basic-auth / api-key / totp / note / wifi / ssh-key / custom-fields credential shapes) rather than against a corpus of real exports from other managers — the design’s own note said to check which managers emit a CXF file today before building this, and that check is still outstanding. Treat the shape here as a reasonable-effort reading of the spec, not a verified interop guarantee, until it has been run against a real export from at least one other product.

§The mapping

An Item with one credential becomes a plain entry. An Item with several becomes a Phase 24.1 bundle: one secretType: "bundle" parent plus one member per non-custom-fields credential. CXF custom fields become the bundle’s local variables, so they can participate in scoped templates rather than appearing as a fake member.

A totp credential never becomes its own entry: it is Phase 22’s stored seed, a field on whichever entry the rest of the item produced, matching how this project already refuses to give TOTP its own SecretType.

Every UnENVerse type without a native CXF shape — the majority of the 26 in secret_types — exports as custom-fields carrying an _unenverse_type field, so another manager sees labelled fields and UnENVerse-to-UnENVerse round-trips losslessly. Import of custom-fields reads _unenverse_type back when present and falls back to extra_vars otherwise, so a CXF file honestly written by some other tool still imports as something rather than being refused.

Structs§

CxfDocument
CxfField
CxfItem
CxfScope

Enums§

CxfCredential

Functions§

export
Builds a CXF document from a slice of entries (VaultData.api_keys).
import
Parses and converts a whole document. new_id/now are injected the way every other importer in this project injects them — determinism for tests, and one clock rather than each entry stamping its own.
parse
Parses a CXF JSON document from bytes.