JBrowser Source Docs
You are reading the documentation for JBrowser 1.5.3. The newest release is 1.5.4. Go to the latest documentation

jbrowser.services.vault

Generated from the source code of JBrowser 1.5.3.

jbrowser/services/vault.py · 385 lines

Encrypted local password vault.

  • Entries are serialised to JSON and sealed with AES-256-GCM using a random 256-bit key.
  • The vault key is protected either by Windows DPAPI (default — bound to the Windows user account, transparent unlock) or by a master password (Scrypt KDF, n=2^17).
  • Nothing sensitive is ever written to disk in plaintext.

Credential#

class Credentialsource

Attributes

Name Value
origin str
username str
password str
space_id str = ''
note str = ''
id str = field(default_factory=lambda: uuid.uuid4().hex[:16])
created float = field(default_factory=time.time)
updated float = field(default_factory=time.time)
last_used float = 0.0

Credential.host#

property hostsource

VaultError#

class VaultError(Exception)source

PasswordVault#

class PasswordVault(QObject)source
PasswordVault(path: Path, parent: QObject | None=None)

Signals

Signal Arguments
changed ()
lockChanged (bool)

Attributes

Name Value
AUTO_LOCK_MS 30 * 60 * 1000

PasswordVault.mode#

property modesource

PasswordVault.is_locked#

property is_lockedsource

PasswordVault.exists#

property existssource

PasswordVault.ensure_unlocked#

ensure_unlocked() -> boolsource

Unlock transparently when protected by DPAPI. Master-password vaults need unlock().

PasswordVault.unlock#

unlock(password: str | None=None) -> boolsource

PasswordVault.lock#

lock() -> Nonesource

PasswordVault.verify_password#

verify_password(password: str) -> boolsource

PasswordVault.set_master_password#

set_master_password(new_password: str) -> boolsource

Switch to (or change) master-password protection. Vault must be unlocked.

PasswordVault.remove_master_password#

remove_master_password() -> boolsource

Switch back to transparent DPAPI protection. Vault must be unlocked.

PasswordVault.entries#

entries() -> list[Credential]source

PasswordVault.get#

get(cid: str) -> Credential | Nonesource

PasswordVault.find_for_url#

find_for_url(url: QUrl | str, space_id: str='') -> list[Credential]source

PasswordVault.save_credential#

save_credential(url: QUrl | str, username: str, password: str, space_id: str='') -> Credentialsource

PasswordVault.has_exact#

has_exact(url: QUrl | str, username: str, password: str, space_id: str='') -> boolsource

PasswordVault.update#

update(cid: str, **fields) -> Nonesource

PasswordVault.remove#

remove(cid: str) -> Nonesource

PasswordVault.mark_used#

mark_used(cid: str) -> Nonesource

PasswordVault.never_list#

never_list() -> list[str]source

PasswordVault.is_never#

is_never(host: str) -> boolsource

PasswordVault.add_never#

add_never(host: str) -> Nonesource

PasswordVault.remove_never#

remove_never(host: str) -> Nonesource

PasswordVault.import_csv#

import_csv(path: str) -> intsource

Import a Chrome / Edge / Firefox password export (name,url,username,password[,note]).

Functions#

password_problems#

password_problems(entries: list[Credential]) -> dict[str, list[str]]source

Map credential id to a list of problems ("weak", "reused"); healthy logins are omitted.

Everything is computed locally from the decrypted vault; nothing leaves the machine.