Managing a stored credential meant installing Seahorse. The keyring
rows on Privacy could say whether it was locked and nothing about what
was in it.
Four rules, each pinned by a contract, because each is a way this could
leak the thing it exists to protect:
Listing never reads values. Enumerating reports labels and attributes;
it does not ask the keyring to hand over what it is protecting.
A secret never reaches a command line. /proc makes argv readable by
every process on this machine, so a password passed as an argument is
published to all of them. The helper reads the value in process and
writes it to wl-copy on stdin.
A secret never reaches an error message, a log, or a QML property. An
exception raised while holding a password does not get to choose what
text is printed, so the clipboard tool's stderr is discarded rather
than echoed.
Forgetting one is irreversible, so the first press asks and the second
does it, and the confirming button is the only one wearing danger.
The list is collapsed until asked for: opening Privacy should not
enumerate someone's passwords as a side effect. A copied value clears
itself about a minute later, but only if the clipboard still holds it --
the guard compares a SHA-256, so the waiting process never has the
password.
Claude-Session: https://claude.ai/code/session_01BRvzt4H8XXLPVH5MyYdk9L