jbrowser.services.vault
Generated from the source code of JBrowser 1.5.3.
Encrypted local password vault.
- Entries are serialised to JSON and sealed with AES-256-GCM using a random 256-bit key.
- The vault key is protected either by Windows DPAPI (default — bound to the Windows user account, transparent unlock) or by a master password (Scrypt KDF, n=2^17).
- Nothing sensitive is ever written to disk in plaintext.
Credential#
class Credentialsource
Attributes
| Name | Value |
|---|---|
origin |
str |
username |
str |
password |
str |
space_id |
str = '' |
note |
str = '' |
id |
str = field(default_factory=lambda: uuid.uuid4().hex[:16]) |
created |
float = field(default_factory=time.time) |
updated |
float = field(default_factory=time.time) |
last_used |
float = 0.0 |
Credential.host#
property hostsource
VaultError#
class VaultError(Exception)source
PasswordVault#
class PasswordVault(QObject)source
PasswordVault(path: Path, parent: QObject | None=None)
Signals
| Signal | Arguments |
|---|---|
changed |
() |
lockChanged |
(bool) |
Attributes
| Name | Value |
|---|---|
AUTO_LOCK_MS |
30 * 60 * 1000 |
PasswordVault.mode#
property modesource
PasswordVault.is_locked#
property is_lockedsource
PasswordVault.exists#
property existssource
PasswordVault.ensure_unlocked#
ensure_unlocked() -> boolsource
Unlock transparently when protected by DPAPI. Master-password vaults need unlock().
PasswordVault.unlock#
unlock(password: str | None=None) -> boolsource
PasswordVault.lock#
lock() -> Nonesource
PasswordVault.verify_password#
verify_password(password: str) -> boolsource
PasswordVault.set_master_password#
set_master_password(new_password: str) -> boolsource
Switch to (or change) master-password protection. Vault must be unlocked.
PasswordVault.remove_master_password#
remove_master_password() -> boolsource
Switch back to transparent DPAPI protection. Vault must be unlocked.
PasswordVault.entries#
entries() -> list[Credential]source
PasswordVault.get#
get(cid: str) -> Credential | Nonesource
PasswordVault.find_for_url#
find_for_url(url: QUrl | str, space_id: str='') -> list[Credential]source
PasswordVault.save_credential#
save_credential(url: QUrl | str, username: str, password: str, space_id: str='') -> Credentialsource
PasswordVault.has_exact#
has_exact(url: QUrl | str, username: str, password: str, space_id: str='') -> boolsource
PasswordVault.update#
update(cid: str, **fields) -> Nonesource
PasswordVault.remove#
remove(cid: str) -> Nonesource
PasswordVault.mark_used#
mark_used(cid: str) -> Nonesource
PasswordVault.never_list#
never_list() -> list[str]source
PasswordVault.is_never#
is_never(host: str) -> boolsource
PasswordVault.add_never#
add_never(host: str) -> Nonesource
PasswordVault.remove_never#
remove_never(host: str) -> Nonesource
PasswordVault.import_csv#
import_csv(path: str) -> intsource
Import a Chrome / Edge / Firefox password export (name,url,username,password[,note]).
Functions#
password_problems#
password_problems(entries: list[Credential]) -> dict[str, list[str]]source
Map credential id to a list of problems ("weak", "reused"); healthy logins are omitted.
Everything is computed locally from the decrypted vault; nothing leaves the machine.