first commit

This commit is contained in:
2026-01-30 14:02:52 +01:00
commit 0c86217bde
52 changed files with 10219 additions and 0 deletions

116
clients/desktop/src/App.css Normal file
View File

@@ -0,0 +1,116 @@
.logo.vite:hover {
filter: drop-shadow(0 0 2em #747bff);
}
.logo.react:hover {
filter: drop-shadow(0 0 2em #61dafb);
}
:root {
font-family: Inter, Avenir, Helvetica, Arial, sans-serif;
font-size: 16px;
line-height: 24px;
font-weight: 400;
color: #0f0f0f;
background-color: #f6f6f6;
font-synthesis: none;
text-rendering: optimizeLegibility;
-webkit-font-smoothing: antialiased;
-moz-osx-font-smoothing: grayscale;
-webkit-text-size-adjust: 100%;
}
.container {
margin: 0;
padding-top: 10vh;
display: flex;
flex-direction: column;
justify-content: center;
text-align: center;
}
.logo {
height: 6em;
padding: 1.5em;
will-change: filter;
transition: 0.75s;
}
.logo.tauri:hover {
filter: drop-shadow(0 0 2em #24c8db);
}
.row {
display: flex;
justify-content: center;
}
a {
font-weight: 500;
color: #646cff;
text-decoration: inherit;
}
a:hover {
color: #535bf2;
}
h1 {
text-align: center;
}
input,
button {
border-radius: 8px;
border: 1px solid transparent;
padding: 0.6em 1.2em;
font-size: 1em;
font-weight: 500;
font-family: inherit;
color: #0f0f0f;
background-color: #ffffff;
transition: border-color 0.25s;
box-shadow: 0 2px 2px rgba(0, 0, 0, 0.2);
}
button {
cursor: pointer;
}
button:hover {
border-color: #396cd8;
}
button:active {
border-color: #396cd8;
background-color: #e8e8e8;
}
input,
button {
outline: none;
}
#greet-input {
margin-right: 5px;
}
@media (prefers-color-scheme: dark) {
:root {
color: #f6f6f6;
background-color: #2f2f2f;
}
a:hover {
color: #24c8db;
}
input,
button {
color: #ffffff;
background-color: #0f0f0f98;
}
button:active {
background-color: #0f0f0f69;
}
}

View File

@@ -0,0 +1,51 @@
import { useState } from "react";
import reactLogo from "./assets/react.svg";
import { invoke } from "@tauri-apps/api/core";
import "./App.css";
function App() {
const [greetMsg, setGreetMsg] = useState("");
const [name, setName] = useState("");
async function greet() {
// Learn more about Tauri commands at https://tauri.app/develop/calling-rust/
setGreetMsg(await invoke("greet", { name }));
}
return (
<main className="container">
<h1>Welcome to Tauri + React</h1>
<div className="row">
<a href="https://vite.dev" target="_blank">
<img src="/vite.svg" className="logo vite" alt="Vite logo" />
</a>
<a href="https://tauri.app" target="_blank">
<img src="/tauri.svg" className="logo tauri" alt="Tauri logo" />
</a>
<a href="https://react.dev" target="_blank">
<img src={reactLogo} className="logo react" alt="React logo" />
</a>
</div>
<p>Click on the Tauri, Vite, and React logos to learn more.</p>
<form
className="row"
onSubmit={(e) => {
e.preventDefault();
greet();
}}
>
<input
id="greet-input"
onChange={(e) => setName(e.currentTarget.value)}
placeholder="Enter a name..."
/>
<button type="submit">Greet</button>
</form>
<p>{greetMsg}</p>
</main>
);
}
export default App;

View File

@@ -0,0 +1,29 @@
import { BrowserRouter, Routes, Route, Navigate } from 'react-router-dom';
import Login from './pages/Login';
import Dashboard from './pages/Dashboard';
import { auth } from './lib/auth';
function PrivateRoute({ children }: { children: React.ReactNode }) {
return auth.isAuthenticated() ? children : <Navigate to="/login" />;
}
function App() {
return (
<BrowserRouter>
<Routes>
<Route path="/login" element={<Login />} />
<Route
path="/dashboard"
element={
<PrivateRoute>
<Dashboard />
</PrivateRoute>
}
/>
<Route path="/" element={<Navigate to="/dashboard" />} />
</Routes>
</BrowserRouter>
);
}
export default App;

View File

@@ -0,0 +1 @@
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" aria-hidden="true" role="img" class="iconify iconify--logos" width="35.93" height="32" preserveAspectRatio="xMidYMid meet" viewBox="0 0 256 228"><path fill="#00D8FF" d="M210.483 73.824a171.49 171.49 0 0 0-8.24-2.597c.465-1.9.893-3.777 1.273-5.621c6.238-30.281 2.16-54.676-11.769-62.708c-13.355-7.7-35.196.329-57.254 19.526a171.23 171.23 0 0 0-6.375 5.848a155.866 155.866 0 0 0-4.241-3.917C100.759 3.829 77.587-4.822 63.673 3.233C50.33 10.957 46.379 33.89 51.995 62.588a170.974 170.974 0 0 0 1.892 8.48c-3.28.932-6.445 1.924-9.474 2.98C17.309 83.498 0 98.307 0 113.668c0 15.865 18.582 31.778 46.812 41.427a145.52 145.52 0 0 0 6.921 2.165a167.467 167.467 0 0 0-2.01 9.138c-5.354 28.2-1.173 50.591 12.134 58.266c13.744 7.926 36.812-.22 59.273-19.855a145.567 145.567 0 0 0 5.342-4.923a168.064 168.064 0 0 0 6.92 6.314c21.758 18.722 43.246 26.282 56.54 18.586c13.731-7.949 18.194-32.003 12.4-61.268a145.016 145.016 0 0 0-1.535-6.842c1.62-.48 3.21-.974 4.76-1.488c29.348-9.723 48.443-25.443 48.443-41.52c0-15.417-17.868-30.326-45.517-39.844Zm-6.365 70.984c-1.4.463-2.836.91-4.3 1.345c-3.24-10.257-7.612-21.163-12.963-32.432c5.106-11 9.31-21.767 12.459-31.957c2.619.758 5.16 1.557 7.61 2.4c23.69 8.156 38.14 20.213 38.14 29.504c0 9.896-15.606 22.743-40.946 31.14Zm-10.514 20.834c2.562 12.94 2.927 24.64 1.23 33.787c-1.524 8.219-4.59 13.698-8.382 15.893c-8.067 4.67-25.32-1.4-43.927-17.412a156.726 156.726 0 0 1-6.437-5.87c7.214-7.889 14.423-17.06 21.459-27.246c12.376-1.098 24.068-2.894 34.671-5.345a134.17 134.17 0 0 1 1.386 6.193ZM87.276 214.515c-7.882 2.783-14.16 2.863-17.955.675c-8.075-4.657-11.432-22.636-6.853-46.752a156.923 156.923 0 0 1 1.869-8.499c10.486 2.32 22.093 3.988 34.498 4.994c7.084 9.967 14.501 19.128 21.976 27.15a134.668 134.668 0 0 1-4.877 4.492c-9.933 8.682-19.886 14.842-28.658 17.94ZM50.35 144.747c-12.483-4.267-22.792-9.812-29.858-15.863c-6.35-5.437-9.555-10.836-9.555-15.216c0-9.322 13.897-21.212 37.076-29.293c2.813-.98 5.757-1.905 8.812-2.773c3.204 10.42 7.406 21.315 12.477 32.332c-5.137 11.18-9.399 22.249-12.634 32.792a134.718 134.718 0 0 1-6.318-1.979Zm12.378-84.26c-4.811-24.587-1.616-43.134 6.425-47.789c8.564-4.958 27.502 2.111 47.463 19.835a144.318 144.318 0 0 1 3.841 3.545c-7.438 7.987-14.787 17.08-21.808 26.988c-12.04 1.116-23.565 2.908-34.161 5.309a160.342 160.342 0 0 1-1.76-7.887Zm110.427 27.268a347.8 347.8 0 0 0-7.785-12.803c8.168 1.033 15.994 2.404 23.343 4.08c-2.206 7.072-4.956 14.465-8.193 22.045a381.151 381.151 0 0 0-7.365-13.322Zm-45.032-43.861c5.044 5.465 10.096 11.566 15.065 18.186a322.04 322.04 0 0 0-30.257-.006c4.974-6.559 10.069-12.652 15.192-18.18ZM82.802 87.83a323.167 323.167 0 0 0-7.227 13.238c-3.184-7.553-5.909-14.98-8.134-22.152c7.304-1.634 15.093-2.97 23.209-3.984a321.524 321.524 0 0 0-7.848 12.897Zm8.081 65.352c-8.385-.936-16.291-2.203-23.593-3.793c2.26-7.3 5.045-14.885 8.298-22.6a321.187 321.187 0 0 0 7.257 13.246c2.594 4.48 5.28 8.868 8.038 13.147Zm37.542 31.03c-5.184-5.592-10.354-11.779-15.403-18.433c4.902.192 9.899.29 14.978.29c5.218 0 10.376-.117 15.453-.343c-4.985 6.774-10.018 12.97-15.028 18.486Zm52.198-57.817c3.422 7.8 6.306 15.345 8.596 22.52c-7.422 1.694-15.436 3.058-23.88 4.071a382.417 382.417 0 0 0 7.859-13.026a347.403 347.403 0 0 0 7.425-13.565Zm-16.898 8.101a358.557 358.557 0 0 1-12.281 19.815a329.4 329.4 0 0 1-23.444.823c-7.967 0-15.716-.248-23.178-.732a310.202 310.202 0 0 1-12.513-19.846h.001a307.41 307.41 0 0 1-10.923-20.627a310.278 310.278 0 0 1 10.89-20.637l-.001.001a307.318 307.318 0 0 1 12.413-19.761c7.613-.576 15.42-.876 23.31-.876H128c7.926 0 15.743.303 23.354.883a329.357 329.357 0 0 1 12.335 19.695a358.489 358.489 0 0 1 11.036 20.54a329.472 329.472 0 0 1-11 20.722Zm22.56-122.124c8.572 4.944 11.906 24.881 6.52 51.026c-.344 1.668-.73 3.367-1.15 5.09c-10.622-2.452-22.155-4.275-34.23-5.408c-7.034-10.017-14.323-19.124-21.64-27.008a160.789 160.789 0 0 1 5.888-5.4c18.9-16.447 36.564-22.941 44.612-18.3ZM128 90.808c12.625 0 22.86 10.235 22.86 22.86s-10.235 22.86-22.86 22.86s-22.86-10.235-22.86-22.86s10.235-22.86 22.86-22.86Z"></path></svg>

After

Width:  |  Height:  |  Size: 4.0 KiB

View File

@@ -0,0 +1,17 @@
@tailwind base;
@tailwind components;
@tailwind utilities;
:root {
font-family: Inter, system-ui, Avenir, Helvetica, Arial, sans-serif;
line-height: 1.5;
font-weight: 400;
}
body {
margin: 0;
display: flex;
place-items: center;
min-width: 320px;
min-height: 100vh;
}

View File

@@ -0,0 +1,15 @@
import axios from 'axios';
const api = axios.create({
baseURL: 'http://localhost', // Nginx Gateway
});
api.interceptors.request.use((config) => {
const token = localStorage.getItem('token');
if (token) {
config.headers.Authorization = `Bearer ${token}`;
}
return config;
});
export default api;

View File

@@ -0,0 +1,69 @@
import srp from 'secure-remote-password/client';
import api from './api';
import { crypto } from './crypto';
export const auth = {
register: async (email, password) => {
const salt = srp.generateSalt();
const privateKey = srp.derivePrivateKey(salt, email, password);
const verifier = srp.deriveVerifier(privateKey);
await api.post('/api/auth/register', {
email,
salt,
verifier
});
},
login: async (email, password) => {
// Step 1
const secret = srp.generateEphemeral(); // 'a'
const clientPublic = secret.public; // 'A'
const step1Response = await api.post('/api/auth/login/step1', {
email,
clientPublic
});
const { salt, serverPublic } = step1Response.data;
// Calculate Client Proof (M1)
const privateKey = srp.derivePrivateKey(salt, email, password);
const clientSession = srp.deriveSession(
secret.secret,
serverPublic,
salt,
email,
privateKey
);
// Step 2
const step2Response = await api.post('/api/auth/login/step2', {
email,
clientProof: clientSession.proof
});
const { serverProof, token } = step2Response.data;
// Verify Server Proof (M2)
srp.verifySession(serverPublic, clientSession, serverProof);
// If we're here, SRP is successful
localStorage.setItem('token', token);
// Now derive the vault key in Rust
await crypto.deriveKey(password, salt);
return true;
},
logout: () => {
localStorage.removeItem('token');
// Ideally clear Rust state too, but hard to do without restart or command
// window.location.reload() might be enough
},
isAuthenticated: () => {
return !!localStorage.getItem('token');
}
};

View File

@@ -0,0 +1,15 @@
import { invoke } from '@tauri-apps/api/core';
export const crypto = {
deriveKey: async (password: string, salt: string): Promise<string> => {
return invoke('derive_key', { password, salt });
},
encrypt: async (cleartext: string): Promise<string> => {
return invoke('encrypt_val', { cleartext });
},
decrypt: async (encrypted: string): Promise<string> => {
return invoke('decrypt_val', { encrypted });
}
};

View File

@@ -0,0 +1,9 @@
import React from "react";
import ReactDOM from "react-dom/client";
import App from "./App";
ReactDOM.createRoot(document.getElementById("root")).render(
<React.StrictMode>
<App />
</React.StrictMode>,
);

View File

@@ -0,0 +1,224 @@
import { useEffect, useState } from 'react';
import api from '../lib/api';
import { crypto } from '../lib/crypto';
import { auth } from '../lib/auth';
import { useNavigate } from 'react-router-dom';
import { Plus, LogOut, Trash2, Eye, EyeOff, Copy } from 'lucide-react';
interface Secret {
id: string;
encrypted_data: string; // bytea from pg comes as hex string usually in postgrest? or we encoded it?
// We didn't define encoding in schema, but usually PostgREST returns hex for bytea.
// However, our encrypt command returns base64.
// We should ensure consistency.
// If we send base64 to bytea column, PG might need decode.
// Or we store as TEXT in DB for simplicity in this prototype.
// Schema said BYTEA. PostgREST handles bytea as hex.
// We will assume we need to handle hex/base64 conversion if needed.
// actually, let's treat it as TEXT in the client for now to see what we get.
iv: string;
auth_tag: string;
type: string;
created_at: string;
// Decrypted
name?: string; // We don't have a name column?
// Wait, PROJECT.md schema didn't have name.
// It had "data" blob.
// Just "encrypted_data".
// We should probably store a JSON blob inside encrypted_data: { name: "...", value: "..." }
// Or add a name column (encrypted or plaintext?).
// "Zero-Knowledge" implies name should be encrypted too if sensitive,
// but usually metadata like name is useful to be plain or separately encrypted.
// Let's assume the blob is `name: value` or JSON.
decryptedValue?: string;
}
export default function Dashboard() {
const [secrets, setSecrets] = useState<Secret[]>([]);
const [loading, setLoading] = useState(true);
const [newSecret, setNewSecret] = useState('');
const [adding, setAdding] = useState(false);
const navigate = useNavigate();
const fetchSecrets = async () => {
try {
const res = await api.get('/rest/secrets?select=*');
const data = res.data as Secret[];
// Decrypt all
const decrypted = await Promise.all(data.map(async (s) => {
try {
// PostgREST returns bytea as hex starting with \x
// But we likely sent base64 string if we used TEXT column?
// Schema defined BYTEA.
// Let's assume we receive hex string.
// But our crypto.decrypt expects Base64 (from our lib.rs).
// We need to handle this data format mismatch.
// For prototype, let's assume we store it as TEXT in schema for now to avoid hex conversion issues
// OR we convert.
// Let's assume the server returns what we sent if we use TEXT, or we need to parse.
// Let's try to decrypt whatever it is.
// In lib.rs, decrypt_val takes String (Base64).
// If it's Postgres Bytea Hex (\x...), we need to convert to Base64.
let ciphertext = s.encrypted_data;
if (ciphertext.startsWith('\\x')) {
// It is hex. Convert to base64.
// Skip \x
const hex = ciphertext.substring(2);
const bytes = new Uint8Array(hex.match(/.{1,2}/g)!.map(byte => parseInt(byte, 16)));
// Convert bytes to base64
ciphertext = btoa(String.fromCharCode(...bytes));
}
const plain = await crypto.decrypt(ciphertext);
return { ...s, decryptedValue: plain };
} catch (e) {
console.error("Failed to decrypt secret", s.id, e);
return { ...s, decryptedValue: 'Error decrypting' };
}
}));
setSecrets(decrypted);
} catch (err) {
console.error(err);
} finally {
setLoading(false);
}
};
useEffect(() => {
fetchSecrets();
}, []);
const handleLogout = () => {
auth.logout();
navigate('/login');
};
const handleAdd = async (e: React.FormEvent) => {
e.preventDefault();
if (!newSecret) return;
setAdding(true);
try {
const encrypted = await crypto.encrypt(newSecret);
// encrypted is base64 string (nonce+ciphertext).
// We need to split if schema enforces separation?
// Schema has: encrypted_data, iv, auth_tag.
// Our Rust `encrypt_val` returns combined blob (nonce+ciphertext).
// We should probably update Rust to return JSON or separate parts,
// OR update Schema to just have `blob`.
// Current Schema: encrypted_data, iv, auth_tag.
// Current Rust: combined string.
// Workaround: We will store EVERYTHING in `encrypted_data` column for now,
// and dummy values for iv/auth_tag if required, OR update schema.
// Schema has NOT NULL for iv/auth_tag.
// Hack: Store combined in encrypted_data, and "00" in iv/auth_tag.
// Ideally we refactor.
// Note: Postgres Bytea expects hex format (start with \x) or valid escape.
// If we send a string to bytea, PostgREST might complain unless we format it.
// Better: Change schema columns to TEXT for prototype simplicity?
// OR use a proper format.
// Let's try sending keys.
await api.post('/rest/secrets', {
encrypted_data: encrypted, // We might need to hex encode this for BYTEA?
iv: "00", // dummy
auth_tag: "00", // dummy
owner_id: (JSON.parse(atob(localStorage.getItem('token')!.split('.')[1]))).sub // extract sub from jwt
});
setNewSecret('');
fetchSecrets();
} catch (err) {
console.error(err);
alert('Failed to add secret');
} finally {
setAdding(false);
}
};
const [visible, setVisible] = useState<Record<string, boolean>>({});
return (
<div className="min-h-screen bg-gray-950 text-white font-sans">
<nav className="border-b border-gray-800 bg-gray-900 p-4">
<div className="mx-auto flex max-w-5xl items-center justify-between">
<h1 className="text-xl font-bold flex items-center gap-2">
<span className="text-blue-500">keys</span>
Secrets Manager
</h1>
<button
onClick={handleLogout}
className="flex items-center gap-2 rounded-md bg-gray-800 px-3 py-1.5 text-sm hover:bg-gray-700"
>
<LogOut size={16} /> Logout
</button>
</div>
</nav>
<main className="mx-auto max-w-5xl p-6">
<div className="mb-8 rounded-xl bg-gray-900 p-6 border border-gray-800">
<h2 className="mb-4 text-lg font-semibold">Store New Secret</h2>
<form onSubmit={handleAdd} className="flex gap-4">
<input
type="text"
value={newSecret}
onChange={(e) => setNewSecret(e.target.value)}
placeholder="Enter secret text (e.g. API_KEY=123)"
className="flex-1 rounded-md border border-gray-700 bg-gray-950 px-4 py-2 focus:border-blue-500 focus:outline-none"
/>
<button
type="submit"
disabled={adding}
className="flex items-center gap-2 rounded-md bg-blue-600 px-6 py-2 font-medium hover:bg-blue-700 disabled:opacity-50"
>
<Plus size={18} /> Add
</button>
</form>
</div>
<div className="grid gap-4">
{loading ? (
<p className="text-gray-400">Loading vault...</p>
) : (
secrets.map((secret) => (
<div key={secret.id} className="flex items-center justify-between rounded-lg border border-gray-800 bg-gray-900 p-4 transition hover:bg-gray-800/80">
<div className="flex-1 font-mono text-sm">
{visible[secret.id] ? (
<span className="text-green-400">{secret.decryptedValue || 'Decrypting...'}</span>
) : (
<span className="text-gray-500"></span>
)}
</div>
<div className="flex items-center gap-2">
<button
onClick={() => setVisible(p => ({ ...p, [secret.id]: !p[secret.id] }))}
className="rounded p-2 text-gray-400 hover:bg-gray-700 hover:text-white"
>
{visible[secret.id] ? <EyeOff size={18} /> : <Eye size={18} />}
</button>
<button className="rounded p-2 text-gray-400 hover:bg-gray-700 hover:text-white">
<Copy size={18} />
</button>
<button className="rounded p-2 text-red-400 hover:bg-red-900/20 hover:text-red-300">
<Trash2 size={18} />
</button>
</div>
</div>
))
)}
</div>
</main>
</div>
);
}

View File

@@ -0,0 +1,106 @@
import { useState } from 'react';
import { auth } from '../lib/auth';
import { useNavigate } from 'react-router-dom';
import { Lock, User, KeyRound } from 'lucide-react';
export default function Login() {
const [isLogin, setIsLogin] = useState(true);
const [email, setEmail] = useState('');
const [password, setPassword] = useState('');
const [loading, setLoading] = useState(false);
const [error, setError] = useState('');
const navigate = useNavigate();
const handleSubmit = async (e: React.FormEvent) => {
e.preventDefault();
setLoading(true);
setError('');
try {
if (isLogin) {
await auth.login(email, password);
navigate('/dashboard');
} else {
await auth.register(email, password);
// After register, switch to login or auto-login
alert('Registration successful! Please login.');
setIsLogin(true);
}
} catch (err) {
console.error(err);
setError('Action failed. Please check credentials or try again.');
} finally {
setLoading(false);
}
};
return (
<div className="flex min-h-screen items-center justify-center bg-gray-950 p-4 text-white">
<div className="w-full max-w-md space-y-8 rounded-xl bg-gray-900 p-8 shadow-2xl border border-gray-800">
<div className="text-center">
<div className="mx-auto flex h-12 w-12 items-center justify-center rounded-full bg-blue-600">
<Lock className="h-6 w-6 text-white" />
</div>
<h2 className="mt-6 text-3xl font-extrabold tracking-tight">
{isLogin ? 'Unlock Vault' : 'Create Vault'}
</h2>
<p className="mt-2 text-sm text-gray-400">
Zero-Knowledge Encryption
</p>
</div>
<form className="mt-8 space-y-6" onSubmit={handleSubmit}>
<div className="space-y-4 rounded-md shadow-sm">
<div className="relative">
<User className="absolute left-3 top-3 h-5 w-5 text-gray-400" />
<input
required
type="email"
placeholder="Email address"
value={email}
onChange={(e) => setEmail(e.target.value)}
className="block w-full rounded-md border border-gray-700 bg-gray-800 pl-10 py-2 text-white placeholder-gray-400 focus:border-blue-500 focus:ring-blue-500 sm:text-sm"
/>
</div>
<div className="relative">
<KeyRound className="absolute left-3 top-3 h-5 w-5 text-gray-400" />
<input
required
type="password"
placeholder="Master Password"
value={password}
onChange={(e) => setPassword(e.target.value)}
className="block w-full rounded-md border border-gray-700 bg-gray-800 pl-10 py-2 text-white placeholder-gray-400 focus:border-blue-500 focus:ring-blue-500 sm:text-sm"
/>
</div>
</div>
{error && (
<div className="text-sm text-red-500 text-center">
{error}
</div>
)}
<div>
<button
type="submit"
disabled={loading}
className="group relative flex w-full justify-center rounded-md border border-transparent bg-blue-600 py-2 px-4 text-sm font-medium text-white hover:bg-blue-700 focus:outline-none focus:ring-2 focus:ring-blue-500 focus:ring-offset-2 disabled:opacity-50"
>
{loading ? 'Processing...' : (isLogin ? 'Unlock' : 'Create Account')}
</button>
</div>
</form>
<div className="text-center">
<button
onClick={() => setIsLogin(!isLogin)}
className="text-sm font-medium text-blue-500 hover:text-blue-400"
>
{isLogin ? 'Need an account? Register' : 'Already have an account? Login'}
</button>
</div>
</div>
</div>
);
}