Copy a password without leaving a trace of it

The launcher's Copy Password command, built alone and last as the plan
required, because every line of it is the security design: the secret
travels rbw to wl-copy through a pipe -- never argv, never a file --
and the copy carries wl-clipboard's --sensitive hint, which vicinae's
clipboard history documents it ignores. That claim was not taken on
faith: a plain probe landed in the live history database and a
sensitive one did not, before any of this was written. A transient
timer clears the clipboard after thirty seconds. An unconfigured rbw
gets a setup message; a vault that locks between list and get gets an
honest failure instead of an empty copy claiming success. rbw joins
desktop-packages, and the contract pins the whole journey with a stub
vault, including that the secret never appears on a command line.
This commit is contained in:
Gabriel Brown
2026-08-21 19:38:38 -04:00
parent 4e978bf3b7
commit c02329ac3c
5 changed files with 125 additions and 13 deletions
+3
View File
@@ -72,6 +72,9 @@ openssl-devel
opus-devel
papers
python3-dnf-plugin-versionlock
# The launcher's Copy Password command; talks to the same Bitwarden account
# the desktop app signs into. See panama-pick.
rbw
rocm-opencl
# The Snapshots page is snapper end to end; see scripts/panama-snapshots.
snapper