feat(desktop): add password-protected backups in settings - #3701
Draft
tellaho wants to merge 4 commits into
Draft
Conversation
Co-authored-by: Taylor Ho <taylorkmho@gmail.com> Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
Co-authored-by: Taylor Ho <taylorkmho@gmail.com> Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
- Preload NIP-49 encryption silently while preserving the editable password until submission. - Replace queued-download status text with randomized progress and automatically open the native save dialog when encryption completes. - Move the temporary backup workflow into a compact confirmation dialog with aligned guidance and actions. - Preserve encrypted backups after canceled saves so the download dialog can be reopened without repeating encryption. - Expand reducer and browser coverage for preload, retry, progress, modal lifecycle, and repeated downloads. Co-authored-by: Taylor Ho <taylorkmho@gmail.com> Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
- Add an app-level encrypted backup provider to preserve encryption and native save work after the modal or settings screen closes. - Replace the standalone backup settings rows with private-key menu actions and a focused backup confirmation dialog. - Preload NIP-49 encryption silently, show simulated progress after submission, and open the native save dialog automatically. - Keep completed backups available for five minutes with a descending Download backup button and actionable Sonner status updates. - Extend the masked private-key display with reusable overflow-menu actions for creating and testing backups. - Update Playwright coverage for modal lifecycle, background completion, temporary downloads, expiry, and backup verification. Co-authored-by: Taylor Ho <taylorkmho@gmail.com> Signed-off-by: Taylor Ho <taylorkmho@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Category: new-feature
User Impact: Users can create, download, and verify a password-protected backup of their private identity from desktop Settings.
Problem: Buzz does not currently give signed-in users a Settings-based path to protect or validate their private identity independently of onboarding. Solution: Add a focused backup menu to the private-key row, keep encryption and verification local in Rust, and preserve completed encrypted backups briefly so native saves can be retried without repeating encryption.
File changes
desktop/src/features/settings/
Adds the background backup lifecycle, create and test dialogs, private-key menu integration, password handling, and focused unit coverage.
desktop/src/features/onboarding/ui/NsecMaskedDisplay.tsx
Extends the masked private-key display with reusable overflow-menu actions used by Settings.
desktop/src/app/App.tsx
Mounts the backup provider at app scope so encryption and save work survive closing Settings or the modal.
desktop/src/shared/api/tauriIdentity.ts
Adds typed desktop bindings for local backup creation, save, selection, and verification.
desktop/src-tauri/src/key_backup.rs and desktop/src-tauri/src/commands/identity.rs
Implements local NIP-49 encryption, password generation, file handling, and public-identity-only verification results.
desktop/src-tauri/src/egress_guard.rs and guarded call sites
Blocks encrypted secret material from relay, websocket, snapshot, sharing, and huddle egress paths.
desktop/src-tauri tests and fixtures
Covers encryption, verification, file behavior, and fail-closed no-egress protections.
desktop/src/testing/e2eBridge.ts, desktop/tests/, and desktop/playwright.config.ts
Expands the mock native bridge and browser coverage across create, retry, expiry, and current/different-identity verification states.
desktop/src-tauri/Cargo.toml, Cargo.lock, and assets
Adds the local cryptography/password-generation dependencies and embedded short-word list.
Reproduction steps
.ncryptsecfile; cancel and retry to confirm the temporary download remains available.npub.Screenshots
Visual review and additional states: Buzz thread