Skip to content

feat: add Keyfold, a key manager editor - #79

Open
nickstruglia wants to merge 1 commit into
standardnotes:mainfrom
nickstruglia:add-keyfold
Open

nickstruglia wants to merge 1 commit into
standardnotes:mainfrom
nickstruglia:add-keyfold

Conversation

@nickstruglia

Copy link
Copy Markdown

Adds Keyfold (io.github.nickstruglia.keyfold), an editor for crypto seed phrases and wallet keys, SSH and PGP keys, API tokens and recovery codes:

  • Entries fold into one-line cards.
  • Secrets stay masked until revealed.
  • Seed phrases and keys get checksum checks (BIP39, Electrum, Base58Check, Bech32, PGP armor).
  • An optional vault password encrypts the note again (AES-256-GCM with a PBKDF2-SHA256 key, 600,000 iterations).
  • Encrypted backup files open in a single-file offline viewer.

Security

  • The editor's Content Security Policy sets connect-src 'none'.
  • It only allows scripts from its own folder and the desktop app's local server, and images and fonts only as data:.
  • It runs in the standard plugin sandbox and uses only the component messages.
  • The only runtime dependency is Preact.

Why the files are prebuilt. Keyfold builds with Vite 8, which needs Node 20.19 or newer, and this repository's pull request workflow uses Node 16.

  • The package carries Keyfold's own build for this package's address (https://standardnotes.github.io/plugins/cdn/dist/static/io.github.nickstruglia.keyfold/dist/).
  • yarn build runs a dependency-free build.mjs. It checks every file against SHA256SUMS, fails on any changed, missing or extra file, and then copies them to dist/.
  • The build is reproducible: the package README gives the commands to rebuild it from the commit it names and compare byte for byte.

If you'd rather build from source here, I'm happy to rework it.

Tested

  • yarn install (adds the workspace to the lockfile).
  • yarn build on Node 22. The package's build step also ran on Node 16.20.
  • yarn workspace @standardnotes/community-cdn run package.
  • The packaged output, served in place of the published directory to app.standardnotes.com (v3.202.9), with the gallery's subscription check bypassed for the test. Keyfold appears in Preferences → Plugins, installs, asks once to activate, opens a note, saves entries and picks up the active theme.
  • Keyfold's own checks on every deploy: typecheck, unit tests, and Playwright tests in a mock of the plugin sandbox at desktop, Android, iPhone and 320 px sizes.

The entry sits next to Excalidraw in cdn/plugins.json rather than at the end, so it doesn't conflict with my separate Cypherpunk pull request.

Source, tests and documentation: https://github.com/nickstruglia/standard-notes-keyfold (MIT)

I'd appreciate your consideration and any feedback either way. If it doesn't fit the directory or needs changes, I'm glad to adjust.

Keyfold keeps crypto seed phrases and wallet keys, SSH and PGP keys, API
tokens and recovery codes in one note, as collapsible cards with hidden
fields, checksum checks and an optional vault password.

The package carries Keyfold's own build for this address, with SHA-256
checksums that `yarn build` verifies before copying the files to dist/:
Keyfold builds with Vite 8, which needs Node 20.19+, and this repository
builds on Node 16. The package README says how to rebuild the files and
compare them.

Source: https://github.com/nickstruglia/standard-notes-keyfold

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant