FXCM-2280: Implement Migration for Encrypted Autofill Storage - #7576
Draft
theidkamp wants to merge 3 commits into
Draft
FXCM-2280: Implement Migration for Encrypted Autofill Storage#7576theidkamp wants to merge 3 commits into
theidkamp wants to merge 3 commits into
Conversation
Move autofill's credit-card encryption onto the shared db-crypto crate and let AutofillDb own the encryptor, as logins' LoginDb does. The consumer supplies it when building the store, so no key is passed into individual calls or down through the sync layers.
Move encrypting and decrypting a card number behind one type, so the knowledge of what the stored value looks like lives in a single place instead of being spread across the db and sync code. A struct rather than a bare string is deliberate: a CVV is expected as a second encrypted field, which needs a structured encoding and a rewrite of existing rows (FXCM-2280). No stored data changes here.
Store the encrypted number as {"v":1,"n":"<number>"} rather than the bare
number, so a CVV can be added as a second encrypted field later without
rewriting every row again. db::migrate_cc_secure_fields rewrites existing rows
in place, on the raw table so sync_change_counter and time_last_modified do not
move, and matching on the old ciphertext so a concurrent write is not clobbered.
It runs from run_maintenance before the vacuum there, guarded by a moz_meta flag
that is only set when no row was skipped.
Bump the schema to 6. No tables change; the bump makes a downgrade fail in
open_database rather than read a blob as a card number and upload it.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Blocked on #7542 — does not build until the shared db-crypto crate lands,
so CI here is expected to be red. Verified locally against #7542's head
(
cc7212f7d): fmt clean, clippy clean, 109 tests passing.Stacked on #<2281> and #<2279>. Do not merge before both* — this branch
contains their commits, so merging here would land all three. Please review
only the last commit,
eb4fa2f3b.Description
Stores the encrypted card number as
{"v":1,"n":"<number>"}instead of the barenumber, so a CVV can be added as a second encrypted field later without
rewriting every row a second time.
db::migrate_cc_secure_fieldsrewritesexisting rows in place.
Pull Request checklist
[ci full]to the PR title.