sync: detect orphaned blobs (pepper rotation) + fix AESGCM arg order
Adds an 8-byte HKDF fingerprint of the current pepper to portfolio_sync rows. On fetch, a mismatch surfaces as 410 Gone (distinct from genuine GCM corruption → 500), and the UI silently cleans up the dead row and shows a soft "please re-import" notice instead of a confusing PIN re-prompt. Legacy rows (pepper_fp NULL) are probed optimistically and backfilled on success. Also fixes a latent bug in unwrap(): AESGCM.decrypt args were swapped (ct, nonce instead of nonce, ct), so restore-from-cloud always failed even when the pepper was correct. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
parent
f1903e1e61
commit
5c7cc4c6aa
8 changed files with 224 additions and 18 deletions
|
|
@ -204,6 +204,10 @@ class PortfolioSync(Base):
|
|||
updated_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), default=utcnow)
|
||||
fetch_window_start: Mapped[datetime | None] = mapped_column(DateTime(timezone=True))
|
||||
fetch_count: Mapped[int] = mapped_column(Integer, nullable=False, default=0)
|
||||
# 8-byte HKDF fingerprint of the pepper that wrapped this row. A
|
||||
# mismatch against the current pepper means the row is orphaned
|
||||
# (pepper was rotated) — distinct from genuine GCM corruption.
|
||||
pepper_fp: Mapped[bytes | None] = mapped_column(LargeBinary(length=8))
|
||||
|
||||
|
||||
class Referral(Base):
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue