Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 9 additions & 1 deletion app/src/main/java/app/passwordstore/ui/settings/PGPSettings.kt
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,15 @@ import kotlinx.coroutines.launch

class PGPSettings(private val activity: FragmentActivity) : SettingsProvider {

private val backend = OpenPgpApiBackend(activity.applicationContext)
// Keep the optional OpenPGP API implementation out of the SettingsActivity startup path. A
// broken or unavailable provider integration must not make the entire settings screen unusable.
private val backend by
lazy(LazyThreadSafetyMode.NONE) {
OpenPgpApiBackend(activity.applicationContext)
}

// Activity Result launchers must be registered before the activity reaches STARTED, so this
// bridge remains eager even though the OpenPGP backend itself is initialized on demand.
private val interactionHandler = OpenPgpActivityInteractionHandler(activity)

override fun provideSettings(builder: PreferenceScreen.Builder) {
Expand Down
6 changes: 4 additions & 2 deletions app/src/main/java/app/passwordstore/util/git/sshj/SshKey.kt
Original file line number Diff line number Diff line change
Expand Up @@ -382,9 +382,11 @@ object SshKey {
val publicKey = androidKeystore.sshPublicKey ?: throw NullPointerException()
val privateKey = androidKeystore.sshPrivateKey ?: throw NullPointerException()

// let Keystore do cryptographic operations
SecurityUtils.setRegisterBouncyCastle(false)
// SSHJ 0.41.1 resets the BouncyCastle registration mode when its configured provider is
// cleared. Clear the provider first, then explicitly disable BC so Android Keystore-backed
// private keys are signed by the platform provider without requiring an exportable encoding.
SecurityUtils.setSecurityProvider(null)
SecurityUtils.setRegisterBouncyCastle(false)

client.loadKeys(KeyPair(publicKey, privateKey))
}
Expand Down
Loading