Skip to content

Prove passphrase-hidden items fail closed without a matcher - #569

Merged
bradleymackey merged 1 commit into
mainfrom
test/hidden-item-fail-closed
Sep 15, 2026
Merged

bradleymackey merged 1 commit into
mainfrom
test/hidden-item-fail-closed

Conversation

@bradleymackey

Copy link
Copy Markdown
Member

Problem

No test anywhere asserted the fail-closed behavior of passphrase-hidden items: when retrieve(query:searchPassphraseMatcher:) is called with a nil matcher — the real state after a keychain key-load failure leaves searchPassphraseDigester nil in VaultDataModel — .onlyPassphrase items must stay hidden. Only the positive match path was covered.

Changes (test-only)

Two tests in PersistedLocalVaultStoreTests, using hidden items whose titles also match the text query — so the text predicate alone would leak them if searchableLevel were mishandled:

  • retrieveMatchingQuery_keepsOnlyPassphraseItemsHiddenWhenMatcherNil — both the explicit matcher: nil call and the retrieve(query:) convenience return only the control item.
  • retrieveMatchingQuery_keepsOnlyPassphraseItemsHiddenForWrongPhrase — a present matcher with a non-matching query text also returns only the control item.

Local verification: PersistedLocalVaultStoreTests suite green on iPhone 18 Pro Max / iOS 27.0.

⚠️ Automatic CI is still disabled (#548), so this is local verification only.

🤖 Generated with Claude Code

Nothing asserted that onlyPassphrase items stay hidden when the
search-passphrase matcher is nil, which is the real state after a
keychain key-load failure. Cover the nil-matcher and wrong-phrase
paths with hidden items whose titles would otherwise match the text
query.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@bradleymackey
bradleymackey merged commit 5d6b30e into main Sep 15, 2026
@bradleymackey
bradleymackey deleted the test/hidden-item-fail-closed branch September 15, 2026 06:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant