pub fn check_salt_pairing(
db_path: &Path,
salt_path: &Path,
) -> Result<(), String>Expand description
Refuse to derive a key when a database exists but its salt does not.
read_or_create_salt generates a salt when the file is absent, which is
right for a first run and catastrophic for an existing vault: the new salt
derives a different key, every unlock reports “Wrong master password”,
and the user spends the afternoon convinced they have forgotten it. The
evidence that anything else happened is gone by then, because the missing
file has been silently replaced.
Called before key derivation by every path that opens an existing vault.