Scope
Harden both normal and encrypted imports at the repository trust boundary.
Required behavior
- Central semantic validation before any DataStore mutation
- Reject malformed enum-dependent fields, unsafe references, invalid ranges, and excessive field/list sizes
- Assign fresh unique IDs for every imported rule, including
REPLACE_ALL, or reject blank/duplicate IDs
- Apply bounded document, ciphertext, plaintext, rule, action, condition, and string limits
- Preserve existing repository unchanged on every validation failure
- Keep encrypted-backup enabled-state behavior as an explicit product decision; do not change it accidentally
Evidence
BackupManager.kt:244-340
SettingsScreen.kt:97-105,288-314
AutomationRepository.kt:480-565
Tests
Use sentinel repository state; malformed, oversized, and duplicate-ID imports must fail before mutation. Verify one-rule enable/edit/delete semantics after import.
Audit: 0a39f7e.
Scope
Harden both normal and encrypted imports at the repository trust boundary.
Required behavior
REPLACE_ALL, or reject blank/duplicate IDsEvidence
BackupManager.kt:244-340SettingsScreen.kt:97-105,288-314AutomationRepository.kt:480-565Tests
Use sentinel repository state; malformed, oversized, and duplicate-ID imports must fail before mutation. Verify one-rule enable/edit/delete semantics after import.
Audit:
0a39f7e.