From a3e9f9ab0eb4df7210acf675093419a0fa0616ab Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Zo=C3=AB?= Date: Wed, 26 Aug 2026 14:47:23 +0200 Subject: [PATCH] fix(crypto): correct cipher type indices to match Bitwarden API --- bitwarden_client.py | 2 +- crypto.py | 12 ++++++------ main.py | 14 ++++++++++++++ 3 files changed, 21 insertions(+), 7 deletions(-) diff --git a/bitwarden_client.py b/bitwarden_client.py index d26321a..de138a2 100644 --- a/bitwarden_client.py +++ b/bitwarden_client.py @@ -383,7 +383,7 @@ class BitwardenClient: # Decrypt ciphers decrypted_ciphers = [] for cipher in ciphers: - if cipher.get("type") in [1, 2, 3, 4]: # Login, Note, Card, Identity + if cipher.get("type") in [0, 1, 2, 3]: # Login, Note, Card, Identity decrypted = self.crypto.decrypt_cipher( cipher, enc_key, mac_key ) diff --git a/crypto.py b/crypto.py index eff4ba3..2c28994 100644 --- a/crypto.py +++ b/crypto.py @@ -233,7 +233,7 @@ class BitwardenCrypto: cipher_type = cipher_data.get("type") - if cipher_type == 1: # Login + if cipher_type == 0: # Login login = cipher_data.get("login", {}) result["login"] = { "username": self._decrypt_field( @@ -255,11 +255,11 @@ class BitwardenCrypto: for u in login.get("uris", []) ], } - elif cipher_type == 2: # Secure Note + elif cipher_type == 1: # Secure Note result["notes"] = self._decrypt_field( cipher_data.get("notes"), enc_key, mac_key ) - elif cipher_type == 3: # Card + elif cipher_type == 2: # Card card = cipher_data.get("card", {}) result["card"] = { "cardholderName": self._decrypt_field( @@ -278,7 +278,7 @@ class BitwardenCrypto: card.get("expYear"), enc_key, mac_key ), } - elif cipher_type == 4: # Identity + elif cipher_type == 3: # Identity identity = cipher_data.get("identity", {}) result["identity"] = { "firstName": self._decrypt_field( @@ -310,8 +310,8 @@ class BitwardenCrypto: }) result["fields"] = fields - # Decrypt notes - if cipher_data.get("notes") and cipher_type != 2: + # Decrypt notes (only for non-Note types, Notes already handled above) + if cipher_data.get("notes") and cipher_type != 1: result["notes"] = self._decrypt_field( cipher_data.get("notes"), enc_key, mac_key ) diff --git a/main.py b/main.py index d64ec77..bbe663d 100644 --- a/main.py +++ b/main.py @@ -108,6 +108,20 @@ class Plugin: "email": email, "kdf_info": self.client.get_kdf_info(), }) + + # Sync and decrypt vault immediately if we have keys + if self._enc_key and self._mac_key: + try: + sync_data = await self.client.sync_vault() + self._vault_data = sync_data + self._decrypted_vault = self.client.decrypt_vault( + sync_data, self._enc_key, self._mac_key + ) + return {"success": True, "needs_unlock": False} + except Exception as e: + decky_plugin.logger.error(f"Vault sync/decrypt failed: {e}") + return {"success": True, "needs_unlock": False} + return {"success": True, "needs_unlock": result.get("enc_key") is None} return {"success": False, "error": "Login failed"}