Skip to content

FXCM-2279: Introduce EncryptedFields Abstraction for Autofill Storage - #7575

Draft
theidkamp wants to merge 2 commits into
mozilla:mainfrom
theidkamp:fxcm-2279-secure-credit-card-fields
Draft

FXCM-2279: Introduce EncryptedFields Abstraction for Autofill Storage#7575
theidkamp wants to merge 2 commits into
mozilla:mainfrom
theidkamp:fxcm-2279-secure-credit-card-fields

Conversation

@theidkamp

Copy link
Copy Markdown

Moves card-number encryption and decryption behind a single type, keeping the stored-value format in one place instead of spreading that knowledge across DB and sync code.

SecureCreditCardFields is intentionally a struct because CVV will become a second encrypted field. That requires a structured encoding and a migration of existing rows (FXCM-2280).

Blocked on #7542 — this branch does not build until the shared db-crypto
crate lands, so CI here is expected to be red. Verified locally against
#7542's head (cc7212f7d): fmt clean, clippy clean, 95 tests passing.
Stacked on #<PR-Nummer von 2281>. The diff against main contains that
PR's commit too — please review only the second commit, 82ed8ea24.

Pull Request checklist

  • Breaking changes: This PR follows our breaking change policy
    • This PR follows the breaking change policy:
      • This PR has no breaking API changes, or
      • There are corresponding PRs for our consumer applications that resolve the breaking changes and have been approved
  • Quality: This PR builds and tests run cleanly
    • Note:
      • For changes that need extra cross-platform testing, consider adding [ci full] to the PR title.
      • If this pull request includes a breaking change, consider cutting a new release after merging.
  • Tests: This PR includes thorough tests or an explanation of why it does not
  • Changelog: This PR includes a changelog entry in CHANGELOG.md or an explanation of why it does not need one
    • Any breaking changes to Swift or Kotlin binding APIs are noted explicitly
  • Dependencies: This PR follows our dependency management guidelines
    • Any new dependencies are accompanied by a summary of the due diligence applied in selecting them.

Move autofill's credit-card encryption onto the shared db-crypto crate and let
AutofillDb own the encryptor, as logins' LoginDb does. The consumer supplies it
when building the store, so no key is passed into individual calls or down
through the sync layers.
Move encrypting and decrypting a card number behind one type, so the knowledge
of what the stored value looks like lives in a single place instead of being
spread across the db and sync code. A struct rather than a bare string is
deliberate: a CVV is expected as a second encrypted field, which needs a
structured encoding and a rewrite of existing rows (FXCM-2280). No stored data
changes here.
@theidkamp theidkamp changed the title Fxcm 2279: Introduce EncryptedFields Abstraction for Autofill Storage FXCM-2279: Introduce EncryptedFields Abstraction for Autofill Storage Sep 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant