-
Notifications
You must be signed in to change notification settings - Fork 2
Optional session file encryption #370
Copy link
Copy link
Open
Labels
effort-largeLarge effort: >4 hoursLarge effort: >4 hoursenhancementNew feature or requestNew feature or requestimpact-mediumMedium impact on users or systemMedium impact on users or systempost-mvpPost-MVP feature, not needed for initial releasePost-MVP feature, not needed for initial releasesecuritySecurity vulnerabilities or concernsSecurity vulnerabilities or concerns
Metadata
Metadata
Assignees
Labels
effort-largeLarge effort: >4 hoursLarge effort: >4 hoursenhancementNew feature or requestNew feature or requestimpact-mediumMedium impact on users or systemMedium impact on users or systempost-mvpPost-MVP feature, not needed for initial releasePost-MVP feature, not needed for initial releasesecuritySecurity vulnerabilities or concernsSecurity vulnerabilities or concerns
Summary
Session files may contain sensitive information (file paths, API config, audit ratings). Add optional AES-256 encryption with user-provided key to protect data at rest.
Sensitive Data in Session Files
Proposed Enhancement
Add optional encryption with AES-256.
Usage
Implementation
Files:
cli/src/utils/session-state-manager.tsanalyzer/src/utils/session_state_manager.pyEncryption:
TypeScript:
Trade-offs
Effort
~6 hours
Related