Skip to content

security: validate and normalize imported automations before mutation #17

Description

@emi-ran

Scope

Harden both normal and encrypted imports at the repository trust boundary.

Required behavior

  • Central semantic validation before any DataStore mutation
  • Reject malformed enum-dependent fields, unsafe references, invalid ranges, and excessive field/list sizes
  • Assign fresh unique IDs for every imported rule, including REPLACE_ALL, or reject blank/duplicate IDs
  • Apply bounded document, ciphertext, plaintext, rule, action, condition, and string limits
  • Preserve existing repository unchanged on every validation failure
  • Keep encrypted-backup enabled-state behavior as an explicit product decision; do not change it accidentally

Evidence

  • BackupManager.kt:244-340
  • SettingsScreen.kt:97-105,288-314
  • AutomationRepository.kt:480-565

Tests

Use sentinel repository state; malformed, oversized, and duplicate-ID imports must fail before mutation. Verify one-rule enable/edit/delete semantics after import.

Audit: 0a39f7e.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions