[package] name = "secure-storage-spike" version = "0.1.0" edition = "2021" publish = false description = "Chanora PoC: SecureStore trait + Linux Secret Service adapter; prove SS-AUD-001..006 for the audit report." # Not product code. See docs/architecture/proof-of-concept-plan.md ยง4 and # docs/security/secure-storage-audit-report.md. [dependencies] thiserror = "2" tracing = "0.1" tracing-subscriber = { version = "0.3", features = ["env-filter"] } zeroize = { version = "1", features = ["derive"] } # Linux secure storage: keyring crate. # * sync-secret-service: libsecret-compatible Secret Service via D-Bus. # * linux-native: Kernel session keyring (keyutils). No D-Bus required. # Both are acceptable Linux backends per SysRS-053 / SysRS-162 # ("Secret Service, libsecret, or equivalent"). The adapter picks at # construction; the test suite exercises the keyutils backend because # headless CI commonly lacks an unlocked Secret Service collection. [target.'cfg(target_os = "linux")'.dependencies] keyring = { version = "3", default-features = false, features = ["sync-secret-service", "crypto-rust", "linux-native"] } # rusqlite is a stand-in for the production `LocalDatabaseRepository`. Bundled # build avoids depending on a system libsqlite3. rusqlite = { version = "0.32", features = ["bundled"] } [dev-dependencies] anyhow = "1" serial_test = "3" tempfile = "3" [[bin]] name = "secure-storage-cli" path = "src/main.rs" [lib] name = "secure_storage_spike" path = "src/lib.rs"