Sync .obsidian configuration #65

Closed
opened 2026-09-21 18:06:06 +01:00 by cruelacid · 1 comment
Owner

Part of #37.

What Relay does

Not shipped. Their issue #37 is open and labelled "tracking" with no ETA.

What we do today

Refused by design. blob-policy.ts:30 ignores any path with a dot-segment, and
the comment says why: listFiles walks the vault index which already excludes
them, and the rule is stated explicitly "so that nobody later reaches for
adapter.list(), which does see them, and starts syncing the plugin's own
configuration"
.

Why this is riskier for us than for them

Syncing .obsidian means syncing our own data.json, which holds folder
mappings and, where there is no OS credential store, secrets. A loop where the
plugin syncs its own configuration between devices is a footgun with sharp edges,
and docs/security-model.md already notes any plugin can read what we store.

If it is ever built it must be an explicit allowlist of config files — themes,
snippets, hotkeys — never the whole directory, and never our own.

Risk

risk:none mechanically; a real security-model question.

Part of #37. ## What Relay does **Not shipped.** Their issue #37 is open and labelled "tracking" with no ETA. ## What we do today Refused by design. `blob-policy.ts:30` ignores any path with a dot-segment, and the comment says why: `listFiles` walks the vault index which already excludes them, and the rule is stated explicitly *"so that nobody later reaches for `adapter.list()`, which does see them, and starts syncing the plugin's own configuration"*. ## Why this is riskier for us than for them Syncing `.obsidian` means syncing **our own `data.json`**, which holds folder mappings and, where there is no OS credential store, secrets. A loop where the plugin syncs its own configuration between devices is a footgun with sharp edges, and `docs/security-model.md` already notes any plugin can read what we store. If it is ever built it must be an explicit allowlist of config files — themes, snippets, hotkeys — never the whole directory, and never our own. ## Risk `risk:none` mechanically; a real security-model question.
Author
Owner

Moved to the Vikunja board as NEC-42: https://projectron.nerchure.com/tasks/42

Moved to the Vikunja board as **NEC-42**: https://projectron.nerchure.com/tasks/42
Sign in to join this conversation.
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Nectenda/nectenda#65
No description provided.