feat(fdosecrets): Add persistent client authorization via path and SHA-256 allowlist - #13703
mynameisdeleted wants to merge 3 commits into
Conversation
Added functionality to manage authorized clients for FdoSecrets by implementing: - addAuthorizedClient() method that calculates SHA256 checksum of executables and stores them with paths - removeAuthorizedClient() method to remove entries from authorized clients list - Updated AccessControlDialog to show permanent decision warning and store executable path - Enhanced settings interface with new client authorization methods This allows for more secure access control by tracking application checksums and enabling permanent authorization decisions.
That doesn't sound secure at all. Anyway, this is already in progress in #13610. |
|
While investigating storing
Moving these policies to per-database |
|
I noticed @Aetf's comprehensive work in #13610, which strongly validates storing client authorizations and executable hashes in database Given the substantial scope and surface area of #13610 (~6,000 lines across 50 files), I would propose a phased approach:
I’m happy to leave both open and let the maintainers decide whether they prefer the monolithic overhaul in #13610 or this phased, incremental path. |
…eduplicate hash logic - Consolidate SHA-256 binary hash computation into FdoSecretsSettings::hashProcess() - On Linux, read /proc/<pid>/exe directly to verify the exact executing binary inode - Fall back gracefully to executable file path if PID is unavailable or on non-Linux systems - Pass client PID from PeerInfo through DBusClient and AccessControlDialog - Add unit test verifying /proc/<pid>/exe hashing and client authorization lifecycle
Update:
|
Overview
Currently, KeePassXC only remembers Secret Service (
FdoSecrets) access authorizations in memory for the active session. Every time a background daemon restarts or the system reboots, its PID changes and KeePassXC prompts the user for access again (e.g.goa-daemon, IDE language servers, credential helpers).This PR adds persistent client authorization by storing the executable's canonical path and SHA-256 checksum in
keepassxc.iniunder[FdoSecrets]/AuthorizedClients.How It Works
path:sha256in settings.Changes
FdoSecrets/AuthorizedClientsstring list setting.path:sha256client entries using canonical paths and SHA-256 hashing.Testing
goa-daemonand language servers: access is granted silently after process restarts and reboots.