refactor(security): derive backup exclusion set from DatabaseFiles #135

Merged
JMR-dev merged 4 commits from refactor-db-file-backup-sot into main 2026-07-02 15:58:06 +00:00
4 Commits
Author SHA1 Message Date
Jason Ross 2848937309 Merge branch 'main' into refactor-db-file-backup-sot 2026-07-02 10:45:19 -05:00
Jason Ross ec418797f9 Merge branch 'main' into refactor-db-file-backup-sot 2026-07-02 10:33:56 -05:00
Jason Ross 6758c833b0 Merge branch 'main' into refactor-db-file-backup-sot 2026-07-02 10:14:38 -05:00
JMR-devandClaude Fable 5 a7a7c323b5 refactor(security): derive backup exclusion set from DatabaseFiles
Make BackupPolicy.EXCLUDED_DATABASE_PATHS the true single source of truth
by deriving it from DatabaseFiles.NAME and DatabaseFiles.ACCOUNTS_NAME plus
their SQLite sidecars via a new DatabaseFiles.fileNames() helper, instead of
a hand-maintained list. This adds libremail-accounts.db (accounts + encrypted
credentials, split into their own DB by #118/#111) to the never-back-up set,
matching the field's stated intent, so a newly added database can never
silently fall out of the exclusions again.

Also fix DatabaseFiles.clear to wipe the cache DB via
context.deleteDatabase(NAME), which additionally removes the -mj*
master-journal temp files the hand-rolled suffix list missed. It still wipes
ONLY the cache DB (NAME) and never the accounts DB (ACCOUNTS_NAME), preserving
the sign-in-survives-cache-wipe separation from #111.

Update the backup XML comments (data_extraction_rules.xml, backup_rules.xml)
to note libremail-accounts.db is also kept off-device by the strict include-
allowlist, and extend the tests to assert the accounts DB is covered by the
exclusion SoT and that the derivation stays in lockstep with the XML resources.

There is no active backup leak today: the XML is a strict include-allowlist,
so the accounts DB was already excluded by omission. This closes the SoT drift
#118 introduced and the -mj* gap, so the security posture no longer depends on
the allowlist staying strict by luck.

Closes #103

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 09:45:54 -05:00