Skip to content

Add an encrypted-values collection flow alongside the default example - #1

Merged
rgarcia merged 3 commits into
mainfrom
hypeship/encrypt-credential-submissions
Oct 10, 2026
Merged

rgarcia merged 3 commits into
mainfrom
hypeship/encrypt-credential-submissions

Conversation

@rgarcia

@rgarcia rgarcia commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

summary

Adds a second collection flow that encrypts credential values in the browser to the vault's Kernel-managed public key, so this app's backend only relays ciphertext and Kernel decrypts it. The existing plaintext flow is unchanged.

default flow encrypted flow (new)
page /credentials/collect /credentials/collect-encrypted
API route /api/credential-requests/current /api/credential-requests/current-encrypted
link bun run create-request bun run create-request -- --encrypted
sent to Kernel value encrypted_value (compact JWE, ECDH-ES + A256GCM)

Uses GET /vaults/{id_or_name}/encryption_key and encrypted_value, available in @onkernel/sdk 0.122.0.

Earlier revisions of this PR replaced the default flow and used app-held per-request keys. Both are gone: the default flow's page, API route and page test are identical to main, and there is no decryption in this repo.

how the encrypted flow works

  1. GET returns { item, encryption_key }; the backend fetches the key with kernel.vaults.retrieveEncryptionKey(vaultId).
  2. On submit, the page encrypts each entered value with jose (lib/encrypted-submission.ts). Clearing an optional field stays { "value": null }.
  3. The route accepts only a well-formed compact JWE (≤ 24 KiB) or a clear per field, and rejects plaintext value strings.
  4. kernel.vaults.items.update forwards each encrypted_value unchanged.

Shared code changes are additive: createCollectionHandler takes encrypted?: boolean, CredentialVaultClient gains encryptionKey(), and the mock vault generates a key pair and decrypts the way Kernel does.

validation

  • bun run typecheck, bun run test (22 tests across both flows), bun run build.
  • End to end against the production Kernel API, driven from a Kernel browser:
    • created a test vault with one pending credential item per flow; ran the app with MOCK_VAULT=false, reached from a Kernel browser through a private tunnel
    • default flow: PATCH 200 with value fields, item ready
    • encrypted flow: PATCH 200 with only encrypted_value fields and no plaintext in the request body, item ready
    • both: fragment cleared after submit, and reopening the link shows "already completed"
    • confirmed Kernel decrypted correctly: vault fill into a real login page in a vault-attached Kernel browser wrote the exact password entered in each flow
    • test vault and browsers deleted afterwards

@rgarcia

rgarcia commented Sep 20, 2026

Copy link
Copy Markdown
Contributor Author

@cursor review

@cursor

cursor Bot commented Sep 20, 2026

Copy link
Copy Markdown

Skipping Bugbot: Bugbot is disabled for this repository. Visit the Bugbot dashboard to update your settings.

@rgarcia rgarcia changed the title Encrypt credential submissions with per-request JWE keys Encrypt credential submissions to the vault's Kernel encryption key Oct 9, 2026
@rgarcia rgarcia changed the title Encrypt credential submissions to the vault's Kernel encryption key Add an encrypted-values collection flow alongside the default example Oct 9, 2026
@rgarcia
rgarcia merged commit f2447a8 into main Oct 10, 2026
1 check passed
@rgarcia
rgarcia deleted the hypeship/encrypt-credential-submissions branch October 10, 2026 18:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant