FXCM-2279: Introduce EncryptedFields Abstraction for Autofill Storage - #7575
Draft
theidkamp wants to merge 2 commits into
Draft
FXCM-2279: Introduce EncryptedFields Abstraction for Autofill Storage#7575theidkamp wants to merge 2 commits into
theidkamp wants to merge 2 commits into
Conversation
Move autofill's credit-card encryption onto the shared db-crypto crate and let AutofillDb own the encryptor, as logins' LoginDb does. The consumer supplies it when building the store, so no key is passed into individual calls or down through the sync layers.
Move encrypting and decrypting a card number behind one type, so the knowledge of what the stored value looks like lives in a single place instead of being spread across the db and sync code. A struct rather than a bare string is deliberate: a CVV is expected as a second encrypted field, which needs a structured encoding and a rewrite of existing rows (FXCM-2280). No stored data changes here.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Moves card-number encryption and decryption behind a single type, keeping the stored-value format in one place instead of spreading that knowledge across DB and sync code.
SecureCreditCardFields is intentionally a struct because CVV will become a second encrypted field. That requires a structured encoding and a migration of existing rows (FXCM-2280).
Blocked on #7542 — this branch does not build until the shared db-crypto
crate lands, so CI here is expected to be red. Verified locally against
#7542's head (
cc7212f7d): fmt clean, clippy clean, 95 tests passing.Stacked on #<PR-Nummer von 2281>. The diff against
maincontains thatPR's commit too — please review only the second commit,
82ed8ea24.Pull Request checklist
[ci full]to the PR title.