Skip to content

Show which components change in a modify approval #174

Description

@sudoHG

Goal

Give write approvals a per-component digest so a modify card can tell exactly which components' values change, instead of tagging same-size, same-delivery components "May be replaced".

Context

BrokerCredentialWriteSummary carries one digest over all components (beforeDigest / afterDigest). In #173 a component whose byte count and delivery do not change, while another component does, cannot be shown as Unchanged or Replaced, so the card says 可能已替换 / May be replaced. Found during the v0.3.0 card review (#169).

Scope

May change: BrokerCredentialComponentSummary (add a value digest, or an equal/changed flag computed App-side), Vault+AgentWriteFreeze.swift summary construction, the write card presentation, tests. Must keep values out of every Broker response; the digest stays App-side.

Acceptance

swift build; filtered tests; hygiene and module checks. A bundle where only one same-length component is rotated shows that component as Replaced and the others as Unchanged; CI green. risk:security.

Blocked by

#173.

Activity

  1. added
    enhancementNew feature or request
    risk:securityTouches broker, approval, delivery, crypto or keychain; requires line-by-line review
    and removed
    risk:securityTouches broker, approval, delivery, crypto or keychain; requires line-by-line review
    on Oct 9, 2026
  2. luoji-bot commented on Oct 9, 2026

    @luoji-bot

    Folded into PR #175 (#173) so the v0.3.0 modify cards tag each component exactly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestrisk:securityTouches broker, approval, delivery, crypto or keychain; requires line-by-line review

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions