The opt-in encrypted cache (encryptCache) uses a SQLCipher passphrase sealed by a Keystore
key that currently auto-unwraps with no user authentication (DatabaseKeyStore / KeystoreCrypto). No biometric/app-lock exists yet. This ticket lets the user unlock and
decrypt with their device screen lock.
Scope
App-lock setting: require the device screen lock (biometric or device credential) to
open the app; gate the UI behind a lock screen on launch/resume/timeout.
Bind decryption to auth: make the Keystore key that seals the DB passphrase require user
authentication (setUserAuthenticationRequired(true)), unlocked via BiometricPrompt
(with device-credential fallback), so the cache is only decryptable after the user
authenticates.
Handle enrollment changes / lock removal (key invalidation) gracefully; define behavior
when the user removes their screen lock.
Tie into the existing encryptCache toggle: "unlock & decrypt with screen lock" is
offered when encryption/lock is enabled.
Acceptance criteria
With the option on, the app requires screen-lock auth to open and the encrypted cache is
only readable after authentication.
Removing the device lock / new biometric enrollment is handled without data corruption
(clear + re-sync if needed).
Relevant files
data/security/{KeystoreCrypto,DatabaseKeyStore}.kt, a lock UI, MainActivity, settings
Dependencies
Builds on the encryptCache path; relates to #21 (do not back up keys).
## Context
The opt-in encrypted cache (`encryptCache`) uses a SQLCipher passphrase sealed by a Keystore
key that **currently auto-unwraps with no user authentication** (`DatabaseKeyStore` /
`KeystoreCrypto`). No biometric/app-lock exists yet. This ticket lets the user unlock and
decrypt with their device screen lock.
## Scope
- [ ] App-lock setting: require the device screen lock (biometric or device credential) to
open the app; gate the UI behind a lock screen on launch/resume/timeout.
- [ ] Bind decryption to auth: make the Keystore key that seals the DB passphrase require user
authentication (`setUserAuthenticationRequired(true)`), unlocked via `BiometricPrompt`
(with device-credential fallback), so the cache is only decryptable after the user
authenticates.
- [ ] Handle enrollment changes / lock removal (key invalidation) gracefully; define behavior
when the user removes their screen lock.
- [ ] Tie into the existing `encryptCache` toggle: "unlock & decrypt with screen lock" is
offered when encryption/lock is enabled.
## Acceptance criteria
- With the option on, the app requires screen-lock auth to open and the encrypted cache is
only readable after authentication.
- Removing the device lock / new biometric enrollment is handled without data corruption
(clear + re-sync if needed).
## Relevant files
- `data/security/{KeystoreCrypto,DatabaseKeyStore}.kt`, a lock UI, `MainActivity`, settings
## Dependencies
Builds on the `encryptCache` path; relates to #21 (do not back up keys).
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Context
The opt-in encrypted cache (
encryptCache) uses a SQLCipher passphrase sealed by a Keystorekey that currently auto-unwraps with no user authentication (
DatabaseKeyStore/KeystoreCrypto). No biometric/app-lock exists yet. This ticket lets the user unlock anddecrypt with their device screen lock.
Scope
open the app; gate the UI behind a lock screen on launch/resume/timeout.
authentication (
setUserAuthenticationRequired(true)), unlocked viaBiometricPrompt(with device-credential fallback), so the cache is only decryptable after the user
authenticates.
when the user removes their screen lock.
encryptCachetoggle: "unlock & decrypt with screen lock" isoffered when encryption/lock is enabled.
Acceptance criteria
only readable after authentication.
(clear + re-sync if needed).
Relevant files
data/security/{KeystoreCrypto,DatabaseKeyStore}.kt, a lock UI,MainActivity, settingsDependencies
Builds on the
encryptCachepath; relates to #21 (do not back up keys).