Screen unlock and decrypt #22

Closed
opened 2026-07-01 03:23:19 +00:00 by JMR-dev · 0 comments
JMR-dev commented 2026-07-01 03:23:19 +00:00 (Migrated from github.com)

Context

The opt-in encrypted cache (encryptCache) uses a SQLCipher passphrase sealed by a Keystore
key that currently auto-unwraps with no user authentication (DatabaseKeyStore /
KeystoreCrypto). No biometric/app-lock exists yet. This ticket lets the user unlock and
decrypt with their device screen lock.

Scope

  • App-lock setting: require the device screen lock (biometric or device credential) to
    open the app; gate the UI behind a lock screen on launch/resume/timeout.
  • Bind decryption to auth: make the Keystore key that seals the DB passphrase require user
    authentication (setUserAuthenticationRequired(true)), unlocked via BiometricPrompt
    (with device-credential fallback), so the cache is only decryptable after the user
    authenticates.
  • Handle enrollment changes / lock removal (key invalidation) gracefully; define behavior
    when the user removes their screen lock.
  • Tie into the existing encryptCache toggle: "unlock & decrypt with screen lock" is
    offered when encryption/lock is enabled.

Acceptance criteria

  • With the option on, the app requires screen-lock auth to open and the encrypted cache is
    only readable after authentication.
  • Removing the device lock / new biometric enrollment is handled without data corruption
    (clear + re-sync if needed).

Relevant files

  • data/security/{KeystoreCrypto,DatabaseKeyStore}.kt, a lock UI, MainActivity, settings

Dependencies

Builds on the encryptCache path; relates to #21 (do not back up keys).

## Context The opt-in encrypted cache (`encryptCache`) uses a SQLCipher passphrase sealed by a Keystore key that **currently auto-unwraps with no user authentication** (`DatabaseKeyStore` / `KeystoreCrypto`). No biometric/app-lock exists yet. This ticket lets the user unlock and decrypt with their device screen lock. ## Scope - [ ] App-lock setting: require the device screen lock (biometric or device credential) to open the app; gate the UI behind a lock screen on launch/resume/timeout. - [ ] Bind decryption to auth: make the Keystore key that seals the DB passphrase require user authentication (`setUserAuthenticationRequired(true)`), unlocked via `BiometricPrompt` (with device-credential fallback), so the cache is only decryptable after the user authenticates. - [ ] Handle enrollment changes / lock removal (key invalidation) gracefully; define behavior when the user removes their screen lock. - [ ] Tie into the existing `encryptCache` toggle: "unlock & decrypt with screen lock" is offered when encryption/lock is enabled. ## Acceptance criteria - With the option on, the app requires screen-lock auth to open and the encrypted cache is only readable after authentication. - Removing the device lock / new biometric enrollment is handled without data corruption (clear + re-sync if needed). ## Relevant files - `data/security/{KeystoreCrypto,DatabaseKeyStore}.kt`, a lock UI, `MainActivity`, settings ## Dependencies Builds on the `encryptCache` path; relates to #21 (do not back up keys).
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: JMR-dev/LibreMail#22