this.me / Tests / Security
Two identities can use the same paths, the same _ secret strings, even the same ciphertext bytes. Data encrypted under one identity root doesn't open under another. A copy of the snapshot, the envelope or the public rootId doesn't help without that identity's password. The owner restoring their own backup with their own password is recovery, and it works.
Code the cases below call that isn't part of the kernel.
Every attempt made by the cases below, with what the kernel returned. Cases are numbered in file order.
Protection against an attacker who controls the unlocked process itself. If code runs inside a kernel that is already unlocked with the right branch secrets supplied, it can read whatever that session can read — that is not a bug, it's what "unlocked" means. root-lifecycle.test.ts's rotate-auth regression is the one place this line gets close: it closes a gap where a caller did not need to unlock at all, which is different from "the process is already unlocked."README §1, attack model and its limits · tests/Security/README.md