Opened 5 years ago

Closed 5 years ago

Last modified 5 years ago

#15334 closed task (fixed)

HaikuBook: document Key/KeyStore API

Reported by: nielx Owned by: nielx
Priority: normal Milestone: R1/beta2
Component: Documentation Version: R1/Development
Keywords: HaikuBook Cc:
Blocked By: Blocking:
Platform: All

Description

Change History (9)

comment:1 by waddlesplash, 5 years ago

Milestone: R1/beta2Unscheduled

comment:2 by waddlesplash, 5 years ago

The Keystore doesn't encrypt its contents, so I'm not sure we should be advertising it so widely without fixing that...

comment:3 by nielx, 5 years ago

We could make the decision to actively document this decision, like: "Warning: the KeyStore system does not currently encrypt passwords and other data. If you application needs a higher level of security, you will need to use other methods to securely store password and other data."

We could also choose to explicitly warn people against using the API.

The third option is to leave it undocumented.

I am leaning for the first one here.

comment:4 by pulkomandy, 5 years ago

Rather than telling people to use other methods, I would rather tell them to wait until this is implemented, or help fixing it (we don't want app to come up with their own things here, there's a good reason we want to provide an API for this). But yes, not documenting this is the worst thing to do.

It can't be that hard to add a password request and encryption system to the keystore, right?

comment:5 by nielx, 5 years ago

Milestone: UnscheduledR1/beta2

Putting it back as a goal for R1 beta 2.

It should indeed be made clear that the password is not encrypted, and the convenience is in the API and not in security.

comment:6 by waddlesplash, 5 years ago

Milestone: R1/beta2Unscheduled

comment:7 by nielx, 5 years ago

Status: newin-progress

comment:8 by nielx, 5 years ago

Resolution: fixed
Status: in-progressclosed

Included as hrev53971

comment:9 by nielx, 5 years ago

Milestone: UnscheduledR1/beta2

Assign tickets with status=closed and resolution=fixed within the R1/beta2 development window to the R1/beta2 Milestone

Note: See TracTickets for help on using tickets.