Changelog
Every release, in the open
This page is generated from the repository's changelog on every build, so it cannot drift from what shipped. Entries under "Unreleased" are on the main branch and not yet in a numbered release.
Unreleased
-
Production audit, critical and high findings fixed (docs/audit/PRODUCTION-AUDIT-2026-09.md §13 has the log): a vault rename or template save can no longer empty the vault when one record is unreadable (A01); sync manifests carry their lineage so a mirror fork, a cloud lost write or a folder switch merges from an empty base instead of deleting local items (A02–A04, manifest format 2); the Secret Key is written to the app’s private keychain group by name (A05); the desktop bridge serves credentials only to the browser host binary, and the host runs only under a browser (A06); trusted browsers on Android are bound to their signing certificates (A07); the Android WebView no longer offers the master password and Secret Key to other autofill services (A08); the license date parser refuses non-ASCII input instead of panicking (A09); vault-core builds on Windows again and CI checks it there (A10); one unreadable record no longer blanks every list, and sync refuses to install records the key cannot open (A11); every vault, archive and sidecar write is fsync’d and atomic (A12).
-
Licensing (docs/features/LICENSING.md): activate with nothing but an email — the app emails a one-tap approval link, and the license (or a free trial for an email that never held one) installs itself on the device that asked. A daily check against the license server keeps the cached, RSA-4096-signed license fresh; offline never freezes anything. Without an active license or trial the app becomes read-only after a 14-day courtesy window: reveal, copy, autofill, search, export, sync, backup and restore always work. Settings › License, a banner when there is something to say, and the activation step after the Recovery Kit. The license server’s address ships as an encrypted constant. Phones show status and activation only, never a price or a buy link.
-
Website (
website/): tigerpassword.com built per docs/WEBSITE.md — Lit templates rendered to static HTML at build, a Go 1.26.8 binary that embeds and serves it with strict headers and precompressed responses, Resend-backed contact and launch-list endpoints, real app screenshots, and a Dockerfile + compose file for Dokploy. -
Website: TigerCodes license gate. The form and admin endpoints answer only while a valid offline license file is mounted on the host (verified against the pinned public key, re-checked every 5 minutes); the static site is never gated.
-
New app icon and brand mark: the TigerCodes tiger as the bow of a key on the violet-to-blue gradient. Desktop, Android and iOS icon sets regenerated from the 1024 px master (
website/public/brand/). -
Website: data-breach chart on the home and security pages — US data compromises 2020–2024 (Identity Theft Resource Center), inline SVG with an accessible data table and the source linked.
-
Seed phrases are entered as numbered cells with BIP-39 word suggestions after two letters (from vault-core’s own list; only the typed prefix crosses IPC), a 12/24 toggle, whole-phrase paste into any cell, and Enter moving to the next word. Validation and “Save it anyway” are unchanged (MOBILE-GUI-AUDIT P3 / F24).
-
Long-press a vault row (right-click on desktop) for quick actions: copy the account, copy the password, open — with a haptic tick where the platform has one.
-
Pull down on the vault list to sync on touch screens; it says so plainly when sync is not set up.
-
iOS: swipe from the left edge to go back.
-
Per-vault accent: Settings → Appearance → “Use this accent for this vault on every device” stores the preset id encrypted in the vault (CRYPTO-SPEC §5
_vault_meta); unlocking adopts it, locking restores the device’s own. -
Android remembers the Secret Key. After the first unlock (or kit confirmation) the key is kept sealed under an Android Keystore key in app-private storage that is excluded from every backup and transfer; the lock screen then folds the field behind “This device remembers the Secret Key (never synced)” with “Use a different Secret Key”, exactly as on iPhone, and Settings gains “Forget Secret Key on this device”. Biometric unlock on Android is still to come.
-
Scan the Secret Key QR when setting up a phone: the lock screen gains “Scan the Secret Key QR from another device” where a camera and decoder exist — iOS through a native scanner, Android through the webview. The link sits beside the remembered-key lines on both platforms. Anything but a tigerpassword code is refused; the key goes into the field and nowhere else.
-
Scheduled backups on phones: choose a folder once (Files / a Storage Access Framework folder); every due encrypted archive is copied there while the vault is unlocked. Retention applies to the app’s own copies.
-
Fixed: dark mode never applied on iOS and Android. tao reports
Theme::Lightunconditionally on mobile and the app trusted that over the webview’s ownprefers-color-scheme; the native signal is now ignored on phones and tablets (nativeThemeSignalTrusted, pinned by theme.test.ts). Found by docs/features/MOBILE-GUI-AUDIT.md (F42). -
Compact-layout polish from the same audit (P0): hover lift no longer sticks after a tap on touch screens; the centered card screens (unlock, create, Recovery Kit, re-auth) respect the safe-area insets; an item’s kind reads as its template name on every surface (chips, rows, the detail badge) instead of “Crypto Wallet” / “Crypto wallet” / “crypto_wallet” depending on where you looked.
-
Phones navigate with a bottom tab bar. The compact layout’s chip strip scrolled sideways and hid three of its six destinations, Lock among them. Compact layouts now have a tab bar (Vault · Generator · Health · More) with a More sheet for Sync & Backup, Recovery Kit, Settings and Lock; Lock also sits in the top bar; New item is a floating button above the bar; the sidebar rail is unchanged on wide layouts. Escape closes the sheet without locking the vault — the one exception to Escape-locks. The layout probe asserts every visible navigation control is inside the viewport at every size.
-
Phones get a native bridge — no plugins, no new crates. A concealed, self-clearing clipboard (flagged sensitive on Android, local-only with an expiry on iOS); the OS document picker for saving an encrypted backup wherever the phone can and for choosing an archive to restore; and the Recovery Kit rendered to a PDF in memory and handed to the share sheet behind a keep-it-safe notice. Sync & Backup on phones no longer shows a single file path; sync is an honest card until the platform cloud transport lands.
-
Lock when leaving the app, and a privacy screen. Switching away conceals every revealed secret at once; the vault locks after a configurable time in the background (immediately / 1 minute / 5 minutes / never, default 1 minute) on a wall-clock deadline, and the biometric prompt greets you on return. Release builds on Android block screenshots and the Recents thumbnail of the vault; on iOS the app switcher snapshot shows a plain cover instead of the vault.
-
Settings regrouped, with Appearance. Vault, Security, Autofill, Appearance, This device and About cards. Appearance adds a theme override (follow the system, light, dark, two high-contrast options) and the seven contrast-checked accent presets; the semantic warning and error colours never change with the accent.
-
Editor on phones. Save sits in the header (disabled until the item has a title) as well as at the end of the form; fields carry mobile keyboard hints — no auto-capitalisation or autocorrect on usernames, URLs, emails, secrets and seed words, and the URL / email / phone keyboards where they apply.
-
Type on touch screens. Body text and inputs are 16 px under a coarse pointer (which also stops WebKit zooming into focused inputs); headings are damped at accessibility text sizes so a display heading grows about half as fast as body instead of three lines for three words; header titles follow the type scale instead of a fixed 20 px.
-
Item detail on phones. Each field is a small card with the label above and the value and its actions on one row; the one-time code shows as two digit groups with the seconds left and a draining ring; a revealed recovery phrase shows as numbered cells. Wide layouts keep the label column.
-
List rows show the account. The second line of a row is now the username or email the item is for (never a concealed value), with the kind as a quiet tag while no filter is active; the filter chips are lighter pills in a strip that fades at its edge.
-
Biometric-first unlock on phones. When Face ID / Touch ID can open the vault, the phone lock screen leads with it and raises the prompt as soon as the app opens (a Settings toggle turns the prompt off); the master password stays one tap away and a cancelled prompt lands on it with the reason. A remembered Secret Key folds its field away on every platform; phones show the vault-location control only when no vault exists yet; “Create a new vault” is demoted to a text link there.
-
Back works on Android. Every screen now leaves a history entry, so the back button and gesture return to the previous screen instead of exiting the app. Back cannot leave the fresh Recovery Kit, never lands past the lock screen, and never re-enters a password gate; history state carries a route name and item id only, never the kit.
-
The shell tells the frontend its platform.
BootstrapDto.platform(macos / ios / android / windows / linux) feeds a small capability table so screens stop offering keychain, biometric or QuickType controls where the platform has none (the Android “Face ID / Touch ID” promise was the first casualty). -
Item detail: Delete leaves the header. On a phone the header wrapped and put the red Delete button directly under Back. The header is now Back · title · Edit on one row, the kind badge sits under the title, and Delete lives in a destructive footer at the end of the screen with its existing two-step confirmation.
-
Copy that is true on a phone. “Find vaults on this computer” is now “on this device”; the vault name is “shown at the top of the app” rather than “in the window title”; the developer-facing “Requires a signed build” is gone from Settings; and the empty vault’s first step no longer points a phone at a command-line tool. A source scan (copy.test.ts) keeps those phrases out.
-
Tooling: the layout probe now measures real phone sizes. Headless Chrome clamps windows to 500 px wide, so the old “compact 414” pass had silently measured a 500 px layout; screens now render inside an iframe of the device size (390×844, 320×568, 874×402 landscape, plus desktop and 200 % text) and a horizontal-overflow assertion joins the overlap, spacing and tight-target checks.
v0.1.0 — 2026-08-15 (release candidate, unaudited)
First release candidate. Not production-ready: the third-party security audit (docs/AUDIT-SCOPE.md) and the human verification gates listed in RELEASE.md are still open, and artifacts are ad-hoc/debug-signed only.
Core (vault-core)
- Zero-knowledge vault: Argon2id (RFC 9106, Secret-Key secret input) → XChaCha20-Poly1305 sealed records with AAD binding; Ed25519-signed sync manifests; BLAKE3/HKDF key hierarchy. Format v3, SQLite persistence with legacy-JSON auto-detection and migration.
- Secret Key (§2.5) with Recovery Kit, provisioning QR, and the never-in-a-synced-file invariant, test-pinned.
- Templates engine: 13 built-ins (stable ids bound into AADs) + encrypted custom templates; §6.4 render path keeps old items lossless.
- BIP-39 validation with official vectors, repair candidates, and scheme detection (Electrum v2 via HMAC tag, Monero, SLIP-39) — never weakened, never blocking a save.
- Password generator (password/passphrase/PIN) with chi-square-tested distribution; TOTP (RFC 6238, SHA-1/256/512).
- Autofill matching engine with PSL, phishing corpus, exact-host DAL grants (cert-bound, 7-day TTL), and a structurally secret-free QuickType identity index.
- Sync: folder providers (iCloud Drive/Dropbox/Syncthing/…), three-way merge that loses nothing (conflict copies, edit-beats-delete, tombstones to earliest), hostile-provider refusals, chaos suite.
- Backup: always-encrypted
.tpbkarchives (CRYPTO-SPEC §10), vault-key- optional passphrase envelopes, retention, chunk-level damage isolation; WebDAV / S3 (SigV4, KAT-pinned) / SFTP (russh, mandatory TOFU-pinned host keys) / local-folder destinations with credentials as hidden encrypted records.
- Import: LastPass, Bitwarden, Chrome/Edge/Brave, Apple Passwords, Firefox, generic CSV mapper, SafeInCloud, 1Password 1pux, KeePass KDBX, Electrum, Sparrow, MetaMask (decrypted keyrings) — every parser fuzzed, resource-capped, zero silent field loss.
- Export (§10.7): lossless JSON (round-trip identity, test-gated) and RFC-4180 CSV behind a typed plaintext confirmation; docs/EXPORT-FORMAT.md.
- Vault health: reuse (BLAKE3 groups), weak (honest upper-bound entropy), old, unverified seeds; HIBP k-anonymous breach check (5-hex-char prefixes only).
- Hardening: KDF parameter caps on all file reads, overflow-checks in release, pinned toolchain, reproducible vault-cli builds (bit-identical, CI-verified), 14 fuzz targets.
Apps
- Desktop (macOS, Tauri 2): unlock/create with kit gate, list/search, editor, generator, reveal-with-countdown, TOTP chips, health screen, sync & backup UI incl. remote destinations with in-UI SFTP key pinning, settings (biometric unlock scaffolding, auto-lock, clipboard hygiene), per-field IPC reveal only, axe-clean screens, 4 themes + custom accents, WCAG 2.2 AA runbook (docs/audit/ACCESSIBILITY-AUDIT.md).
- Browser extension (MV3): matching-free picker over a native- messaging host; matched origin always visible; gated fills demand a second explicit action; design parity with the desktop shell.
- Android: Tauri shell + TigerAutofillService (dropdown + inline keyboard chips), save-from-fill with review activity, DAL-verified app↔site association, bridge-socket credential release re-matched server-side.
- iOS: app shell + ASCredentialProviderExtension (stateless C ABI, no KDF in-process, QuickType identities) — signed-device verification pending (docs/PHASE7/8-VERIFICATION.md).
- CLI (vault-cli): full feature surface incl. import/export, backup/ restore (local + remote destinations), sync, health, TOTP, checkseed.
Known gaps at v0.1.0
- Third-party audit not yet performed; hardware checklists (Touch ID, real devices, signed builds), real cloud-endpoint verification, and the manual accessibility passes are open — see RELEASE.md.
- macOS artifact is ad-hoc signed (Gatekeeper will refuse on other Macs until Developer-ID-signed + notarized); Android APK is debug-key-signed; iOS ships from source only.