fix: reject any passphrase when vault is initialized but empty (#837)#856
fix: reject any passphrase when vault is initialized but empty (#837)#856saurabhhhcodes wants to merge 1 commit into
Conversation
…i123#837) - Store an encrypted verification token during first-time vault setup - Always verify the passphrase by decrypting the verification token, even when no credentials are stored yet - Prevents silent irreversible lock-out when wrong passphrase is used on an empty vault
|
Warning Review limit reached
Next review available in: 57 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
🚀 Thank You for Contributing to Late-MeetPlease ensure that:
Thank you for contributing 💙 |
|
👋 Thank you @saurabhhhcodes for your contribution to Late-Meet!
Please review any automated suggestions or code review comments that may appear below! We will review your PR as soon as possible! Please consider starring the repository ⭐ to show your support! |
|
|
This PR has been marked as stale due to inactivity. |



Problem
unlockCredentials()insrc/utils/credentials.tshas a critical security flaw: when the vault is initialized (salt is stored) but no credentials have been saved yet, the passphrase verification block is skipped entirely, and any passphrase is accepted.This creates a silent irreversible lock-out: if the wrong passphrase is accepted, subsequent saves encrypt with a derived key that the real passphrase cannot decrypt, permanently locking the user out of their credentials.
Root cause
The verification only ran when
encryptedCredswas non-empty (i.e., at least one API key had been stored). With an empty vault, the code fell through toreturn truewithout checking the passphrase.Fix
VAULT_VERIFICATION_KEYstorage key