Files
DigiRadio/Software/.cursor/rules/40-security.mdc
T
micheleandCursor 8439ec4055 Sync all project docs for firmware 0.8.3 completion.
Update READMEs, manual chapters, agent guides, CONTRIBUTING, and TODO to reflect T1–T8 done, encrypted NVS, CI gates, and pending HIL checklist.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-07 07:49:07 +02:00

20 lines
784 B
Plaintext

---
description: Secure storage and secret handling
globs: **/*Secret*, **/*Store*, **/secure/**, **/*Credential*, **/*Config*
alwaysApply: false
---
# Secure storage
Full spec: @AGENTS.md §7.5.
- Stores Wi-Fi SSID/password, station list, audio profiles, last-preset index.
**Encrypted at rest** — `CONFIG_NVS_ENCRYPTION` + flash encryption in
`sdkconfig.defaults` (development mode); `secure_store::initEncryptedStorage()`
before any NVS access. See `docs/security-flash-nvs.md`.
- A `Secret` wrapper: no operator<<, no implicit conversion to a loggable
string, buffer zeroised on destruction.
- Secrets are never logged, never placed in URLs, never serialised to
plaintext. Access goes through `ISecureStore` so core and tests never
touch real flash or real keys.