Skip to content

feat(storage): add encrypted SQLCipher persistence - #12

Merged
kev1n77 merged 2 commits into
mainfrom
codex/sqlcipher-storage
Jul 15, 2026
Merged

kev1n77 merged 2 commits into
mainfrom
codex/sqlcipher-storage

Conversation

@kev1n77

@kev1n77 kev1n77 commented Jul 14, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • add a SQLCipher-backed storage crate with WAL, versioned migrations, indexed capture records, FTS5 search, cursor pagination, encrypted backup/restore, and integrity checks
  • store the random database key in Windows Credential Manager or macOS Keychain and verify real credential-store round trips in CI
  • restrict sanitized capture construction, connect trusted Core ingestion to persistence, and update security/progress documentation

Security evidence

  • rejects wrong database keys without damaging the database
  • scans database, WAL, and backup files for prompt and credential plaintext canaries
  • keeps key material redacted from Debug output and zeroizes key buffers
  • disables SQLCipher locked-memory mode on Windows because VirtualLock denial causes FTS5 initialization to overflow; encryption at rest remains enabled

Verification

  • cargo fmt --all -- --check
  • cargo test --workspace --all-targets
  • cargo clippy --workspace --all-targets -- -D warnings
  • cargo test -p codeischeap-storage --test os_key_store real_os_key_store_round_trip -- --ignored --exact --nocapture
  • npm run desktop:check
  • npm run desktop:build
  • python -m unittest discover -s sidecars/mitmproxy/tests -v

Cross-platform acceptance

The initial PR run passed all 9 jobs. SQLCipher plus the real credential-store experiment passed on both Windows and macOS, so DAT-001 is marked Done and ADR-003 is Accepted in the follow-up documentation commit.

@kev1n77
kev1n77 merged commit 839e9a3 into main Jul 15, 2026
9 checks passed
@kev1n77
kev1n77 deleted the codex/sqlcipher-storage branch July 15, 2026 01:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant