Expand description
Reading and writing the export files other authenticator apps produce.
Phase 22 gave the vault somewhere to keep a third-party TOTP seed. This
module is how a seed gets in and out without being retyped from a phone
screen — Ente Auth, Aegis, 2FAS, andOTP, Bitwarden and Google Authenticator
on the way in; a portable otpauth:// list, Aegis or 2FAS on the way out.
§It lives here, and only here
Six formats parsed twice is six chances to disagree, and a disagreement here
is a seed that imports into the app and not the CLI — or worse, imports with
the wrong period and produces six digits the issuer rejects. So this is
Rust only: the CLI calls it directly, the desktop app calls it over IPC
(totp_import_parse / totp_export_build), and there is no TypeScript twin
to pin. That is the shape pools.ts already uses and the one CLAUDE.md’s
twin-pair table says to prefer over a golden fixture.
§Encrypted exports are refused, never decrypted
Every app here can export encrypted, and each uses its own KDF and envelope.
Implementing six of those would mean this crate holding six password-guessing
paths whose failures are indistinguishable from a corrupt file. detect
recognises each encrypted shape and returns a message naming the app and
saying to export again without encryption. Refusing with a reason beats
failing to parse with none.
§What is deliberately not read
otpauth://hotp/ and every counter-based entry in every format. HOTP has no
clock, so “the current code” does not exist for it: importing one produces an
entry whose code never changes and never works. They are counted and named in
the report rather than silently dropped.
Structs§
- Imported
- One seed read out of somebody else’s export.
- Parse
Report - What a parse produced, including what it refused.
- Skipped
- One entry the parser declined, and why.
Enums§
- Format
- An export format this module can read, write, or both.
- Plan
- What an import would do to one incoming seed.
Functions§
- build
- Write the seeds out in a format another app reads.
- detect
- Work out which app wrote this file.
- new_
entry - Build a fresh entry for a seed that matched nothing in the vault.
- parse
- Read an export, detecting the format.
- parse_
as - Read an export in a format the caller has already decided.
- plan
- Decide, for each incoming seed, what should happen to it.
- write_
fields - Write a seed and its parameters onto an entry.