JBrowser Source Docs

jbrowser.services.vault

Generated from the source code of JBrowser 1.5.4.

jbrowser/services/vault.py · 403 lines

Encrypted local password vault.

  • Entries are serialised to JSON and sealed with AES-256-GCM using a random 256-bit key.
  • The vault key is protected either by Windows DPAPI (default — bound to the Windows user account, transparent unlock) or by a master password (Scrypt KDF, n=2^17).
  • Nothing sensitive is ever written to disk in plaintext.

Credential#

class Credentialsource

Attributes

Name Value
origin str
username str
password str
space_id str = ''
note str = ''
id str = field(default_factory=lambda: uuid.uuid4().hex[:16])
created float = field(default_factory=time.time)
updated float = field(default_factory=time.time)
last_used float = 0.0

Credential.host#

property hostsource

VaultError#

class VaultError(Exception)source

PasswordVault#

class PasswordVault(QObject)source
PasswordVault(path: Path, parent: QObject | None=None)

Signals

Signal Arguments
changed ()
lockChanged (bool)

Attributes

Name Value
AUTO_LOCK_MS 30 * 60 * 1000

PasswordVault.mode#

property modesource

PasswordVault.is_locked#

property is_lockedsource

PasswordVault.exists#

property existssource

PasswordVault.ensure_unlocked#

ensure_unlocked() -> boolsource

Unlock transparently when protected by DPAPI. Master-password vaults need unlock().

PasswordVault.unlock#

unlock(password: str | None=None) -> boolsource

PasswordVault.lock#

lock() -> Nonesource

PasswordVault.verify_password#

verify_password(password: str) -> boolsource

PasswordVault.set_master_password#

set_master_password(new_password: str) -> boolsource

Switch to (or change) master-password protection. Vault must be unlocked.

PasswordVault.remove_master_password#

remove_master_password() -> boolsource

Switch back to transparent DPAPI protection. Vault must be unlocked.

PasswordVault.entries#

entries() -> list[Credential]source

PasswordVault.get#

get(cid: str) -> Credential | Nonesource

PasswordVault.find_for_url#

find_for_url(url: QUrl | str, space_id: str='') -> list[Credential]source

PasswordVault.save_credential#

save_credential(url: QUrl | str, username: str, password: str, space_id: str='') -> Credentialsource

PasswordVault.has_exact#

has_exact(url: QUrl | str, username: str, password: str, space_id: str='') -> boolsource

PasswordVault.update#

update(cid: str, **fields) -> Nonesource

PasswordVault.remove#

remove(cid: str) -> Nonesource

PasswordVault.mark_used#

mark_used(cid: str) -> Nonesource

PasswordVault.never_list#

never_list() -> list[str]source

PasswordVault.is_never#

is_never(host: str) -> boolsource

PasswordVault.add_never#

add_never(host: str) -> Nonesource

PasswordVault.remove_never#

remove_never(host: str) -> Nonesource

PasswordVault.export_csv#

export_csv() -> tuple[bytes, int]source

Every saved login as CSV in the column layout Chrome, Edge and Firefox export and import (name,url,username,password,note). Returns (UTF-8 bytes, number of logins). Only ever written to disk inside an encrypted ZIP (see PasswordsDialog._export).

PasswordVault.import_csv#

import_csv(path: str, data: bytes | None=None) -> intsource

Import a Chrome / Edge / Firefox password export (name,url,username,password[,note]), from path or, when given, from data (a CSV read out of an encrypted ZIP).

Functions#

password_problems#

password_problems(entries: list[Credential]) -> dict[str, list[str]]source

Map credential id to a list of problems ("weak", "reused"); healthy logins are omitted.

Everything is computed locally from the decrypted vault; nothing leaves the machine.