Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package QtPass for openSUSE:Factory checked in at 2026-09-28 10:40:26 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/QtPass (Old) and /work/SRC/openSUSE:Factory/.QtPass.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "QtPass" Mon Sep 28 10:40:26 2026 rev:10 rq:1380313 version:1.8.2 Changes: -------- --- /work/SRC/openSUSE:Factory/QtPass/QtPass.changes 2026-09-17 15:20:20.354294874 +0200 +++ /work/SRC/openSUSE:Factory/.QtPass.new.383539/QtPass.changes 2026-09-28 10:41:00.655274405 +0200 @@ -1,0 +2,11 @@ +Thu Sep 24 21:26:51 UTC 2026 - ecsos <[email protected]> + +- Update to version 1.8.2: + * Release v1.8.2 (#1934) + * 1.8: install the AppStream metainfo under its component id (ported from #1804) (#1927) + * 1.8: auto push/pull were never saved since 1.8.0 (ported from #1792) (#1795) + * 1.8: lint fixes the main branch already has + * Let the settings decide which key: value lines become fields (#1766) + * flatpak: build v1.8.1, drop the source overlays (#1750) + +------------------------------------------------------------------- Old: ---- QtPass-1.8.1.tar.xz New: ---- QtPass-1.8.2.tar.xz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ QtPass.spec ++++++ --- /var/tmp/diff_new_pack.N6Nw39/_old 2026-09-28 10:41:04.102418953 +0200 +++ /var/tmp/diff_new_pack.N6Nw39/_new 2026-09-28 10:41:04.104419037 +0200 @@ -18,7 +18,7 @@ %define _name qtpass Name: QtPass -Version: 1.8.1 +Version: 1.8.2 Release: 0 Summary: A multi-platform gui for pass License: GPL-3.0-only @@ -54,7 +54,6 @@ %install %qmake6_install install -Dpm0644 %{_name}.desktop %{buildroot}%{_datadir}/applications/%{_name}.desktop -install -Dpm0644 %{_name}.appdata.xml %{buildroot}%{_datadir}/metainfo/%{_name}.appdata.xml install -Dpm0644 artwork/icon.svg %{buildroot}%{_datadir}/icons/hicolor/scalable/apps/%{_name}-icon.svg install -Dpm0644 %{_name}.1 %{buildroot}%{_mandir}/man1/%{_name}.1 @@ -65,6 +64,6 @@ %{_datadir}/applications/%{_name}.desktop %{_datadir}/icons/hicolor/scalable/apps/%{_name}-icon.svg %{_datadir}/icons/hicolor/512x512/apps/%{_name}-icon.png -%{_datadir}/metainfo/%{_name}.appdata.xml +%{_datadir}/metainfo/org.qtpass.QtPass.metainfo.xml %{_mandir}/man?/%{_name}.?%{ext_man} ++++++ QtPass-1.8.1.tar.xz -> QtPass-1.8.2.tar.xz ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/.codecov.yml new/QtPass-1.8.2/.codecov.yml --- old/QtPass-1.8.1/.codecov.yml 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/.codecov.yml 2026-09-24 23:00:10.000000000 +0200 @@ -3,16 +3,17 @@ ignore: - tests/* - src/qrc_*.cpp - project: - default: - # Coverage on this codebase fluctuates run-to-run because - # integration tests hit different paths depending on runner - # state (GPG keyring, test fixture race conditions, async - # signal timing). Observed delta on PRs that don't touch src/ - # at all has been ~0.05% (2-3 lines of ~5k instrumented). - # 0.2% gives a 4x buffer for variance peaks while still - # catching real regressions of ~10+ lines. - threshold: 0.2% - patch: - default: - target: 0% + status: + project: + default: + # Coverage on this codebase fluctuates run-to-run because + # integration tests hit different paths depending on runner + # state (GPG keyring, test fixture race conditions, async + # signal timing). Observed delta on PRs that don't touch src/ + # at all has been ~0.05% (2-3 lines of ~5k instrumented). + # 0.2% gives a 4x buffer for variance peaks while still + # catching real regressions of ~10+ lines. + threshold: 0.2% + patch: + default: + target: 0% diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/.opencode/skills/qtpass-releasing/SKILL.md new/QtPass-1.8.2/.opencode/skills/qtpass-releasing/SKILL.md --- old/QtPass-1.8.1/.opencode/skills/qtpass-releasing/SKILL.md 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/.opencode/skills/qtpass-releasing/SKILL.md 2026-09-24 23:00:10.000000000 +0200 @@ -26,7 +26,7 @@ - `changelog.1.4.html` (gh-pages) - `old.html` (gh-pages) -**NOTE:** `qtpass.appdata.xml` and `appdmg.json` don't have version fields to update. +**NOTE:** `org.qtpass.QtPass.metainfo.xml` and `appdmg.json` don't have version fields to update. ```bash # Find version strings (replace X.Y with actual version) @@ -148,7 +148,7 @@ - Where: PR to the Flathub app repository. - How: bump the `qtpass` module tag/commit in `flatpak/org.qtpass.QtPass.yml`, - add a `<release>` to `qtpass.appdata.xml`, run `flatpak-builder-lint`. + add a `<release>` to `org.qtpass.QtPass.metainfo.xml`, run `flatpak-builder-lint`. - Flathub's [generative-AI policy](https://docs.flathub.org/docs/for-app-authors/requirements#generative-ai-policy): AI-generated code, packaging or metadata must be disclosed (which parts, how much) and is accepted at reviewer discretion; AI tools must not open diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/CHANGELOG.md new/QtPass-1.8.2/CHANGELOG.md --- old/QtPass-1.8.1/CHANGELOG.md 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/CHANGELOG.md 2026-09-24 23:00:10.000000000 +0200 @@ -1,5 +1,30 @@ # Changelog +## [1.8.2](https://github.com/IJHack/QtPass/tree/v1.8.2) (2026-09-24) + +### Changed + +- The AppStream metainfo installs as `org.qtpass.QtPass.metainfo.xml`, the + filename the spec derives from the component ID, instead of + `qtpass.appdata.xml` (ported from [#1804](https://github.com/IJHack/QtPass/pull/1804)). Packagers who install the + file themselves need the new name; the Flatpak manifest drops + `rename-appdata-file` with this tag + +### Bugfixes + +- "Automatically push" and "Automatically pull" in the settings did nothing + since 1.8.0: [#1140](https://github.com/IJHack/QtPass/pull/1140) started + storing them per profile and stopped writing the global keys that the + backends and the pull-on-start actually read. Both are saved again, and + switching profiles now applies that profile's Git flags along with its path + and signing key (ported from [#1792](https://github.com/IJHack/QtPass/pull/1792)) +- The Edit dialog turned every `key: value` line into a label-locked field + since 1.8.0, also with templates off, so those keys could no longer be + edited as text ([#1138](https://github.com/IJHack/QtPass/pull/1138) forced "all fields" on for [#132](https://github.com/IJHack/QtPass/issues/132)). Which lines become + fields follows the settings again: the template's fields when templates are + on, every `key: value` line only with "Template all fields", closes + [#1766](https://github.com/IJHack/QtPass/issues/1766) (ported from [#1767](https://github.com/IJHack/QtPass/pull/1767)) + ## [1.8.1](https://github.com/IJHack/QtPass/tree/v1.8.1) (2026-09-15) The security and data-loss fixes from the 2.0 branch, backported to the 1.8 @@ -34,7 +59,7 @@ "All characters" when loaded instead of indexing the character-set table out of bounds when the Settings dialog opens [#1724](https://github.com/IJHack/QtPass/pull/1724) (ported from [#1715](https://github.com/IJHack/QtPass/pull/1715)) -### Bugfixes +### Bugfixes <!-- markdownlint-disable-line MD024 --> - "New folder" wrote a zero-byte `.gpg-id`, shadowing the parent recipients and breaking every insert in that folder; it is now seeded from the parent diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/Doxyfile new/QtPass-1.8.2/Doxyfile --- old/QtPass-1.8.1/Doxyfile 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/Doxyfile 2026-09-24 23:00:10.000000000 +0200 @@ -48,7 +48,7 @@ # could be handy for archiving the generated documentation or if some version # control system is used. -PROJECT_NUMBER = 1.8.1 +PROJECT_NUMBER = 1.8.2 # Using the PROJECT_BRIEF tag one can provide an optional one line description # for a project that appears at the top of each page and should give viewers a diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/REUSE.toml new/QtPass-1.8.2/REUSE.toml --- old/QtPass-1.8.1/REUSE.toml 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/REUSE.toml 2026-09-24 23:00:10.000000000 +0200 @@ -25,7 +25,7 @@ SPDX-License-Identifier = "CC0-1.0" [[annotations]] -path = "qtpass.appdata.xml" +path = "org.qtpass.QtPass.metainfo.xml" precedence = "aggregate" SPDX-FileCopyrightText = "IJHack" SPDX-License-Identifier = "GFDL-1.3-or-later" diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/flatpak/README.md new/QtPass-1.8.2/flatpak/README.md --- old/QtPass-1.8.1/flatpak/README.md 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/flatpak/README.md 2026-09-24 23:00:10.000000000 +0200 @@ -23,7 +23,7 @@ ```sh flatpak run --command=flatpak-builder-lint org.flatpak.Builder manifest flatpak/org.qtpass.QtPass.yml -flatpak run --command=flatpak-builder-lint org.flatpak.Builder appstream qtpass.appdata.xml +flatpak run --command=flatpak-builder-lint org.flatpak.Builder appstream org.qtpass.QtPass.metainfo.xml ``` ## How GnuPG works inside the sandbox @@ -64,6 +64,10 @@ (metainfo, square icon, `main.cpp`, `qtpasssettings.cpp`, and for the 1.8.1 first-run fix `mainwindow.h`, `mainwindow.cpp`, `qtpass.cpp`) exist only because v1.8.0 predates those changes — drop them when building from a later tag. +Since 1.8.2 the metainfo is installed under its component ID +(`org.qtpass.QtPass.metainfo.xml`): drop `rename-appdata-file` when the +module moves to the 1.8.2 tag (`ci-manifest.sh` strips it for the tree build +meanwhile). ## CI diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/flatpak/ci-manifest.sh new/QtPass-1.8.2/flatpak/ci-manifest.sh --- old/QtPass-1.8.1/flatpak/ci-manifest.sh 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/flatpak/ci-manifest.sh 2026-09-24 23:00:10.000000000 +0200 @@ -8,7 +8,10 @@ cd "$(dirname "$0")" out=org.qtpass.QtPass.ci.yml -sed '/^ - name: qtpass$/,$ { /^ sources:$/,$d }' org.qtpass.QtPass.yml >"$out" +# The tree installs the metainfo as org.qtpass.QtPass.metainfo.xml already; +# rename-appdata-file is only there for the tagged v1.8.1 source. +sed -e '/^ - name: qtpass$/,$ { /^ sources:$/,$d }' \ + -e '/^rename-appdata-file:/d' org.qtpass.QtPass.yml >"$out" printf '%s\n' \ ' sources:' \ ' - type: dir' \ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/flatpak/org.qtpass.QtPass.yml new/QtPass-1.8.2/flatpak/org.qtpass.QtPass.yml --- old/QtPass-1.8.1/flatpak/org.qtpass.QtPass.yml 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/flatpak/org.qtpass.QtPass.yml 2026-09-24 23:00:10.000000000 +0200 @@ -22,6 +22,8 @@ command: qtpass rename-desktop-file: qtpass.desktop rename-icon: qtpass-icon +# v1.8.1 installs the metainfo as qtpass.appdata.xml; from 1.8.2 on it is +# installed under the component id. Drop this line with the 1.8.2 tag. rename-appdata-file: qtpass.appdata.xml finish-args: - --share=ipc @@ -134,14 +136,10 @@ # the KDE SDK ships Qt 6 qmake as plain "qmake" - qmake PREFIX=/app CONFIG+=release qtpass.pro - make -j$FLATPAK_BUILDER_N_JOBS sub-src sub-main + # installs bin/qtpass, the desktop file, the metainfo and the hicolor + # icons under the upstream names; rename-desktop-file / rename-icon + # (and rename-appdata-file, for v1.8.1) rewrite them to the app id - make -C main install - # installed under the upstream names; rename-desktop-file / rename-icon - # rewrite them (and the metainfo launchable) to the app id - - install -Dm644 qtpass.desktop /app/share/applications/qtpass.desktop - - install -Dm644 artwork/qtpass-icon.svg /app/share/icons/hicolor/scalable/apps/qtpass-icon.svg - - install -Dm644 artwork/icon.png /app/share/icons/hicolor/512x512/apps/qtpass-icon.png - # same path qmake uses since 1.8.1; rename-appdata-file gives it the app id - - install -Dm644 qtpass.appdata.xml /app/share/metainfo/qtpass.appdata.xml # QtPassSettings::initExecutables() (and pass) look for "gpg2"; the runtime # ships "gpg". The wrapper also scrubs sandbox-only env before the host # gpg-agent sees it — see the comments in flatpak/gpg2. @@ -149,42 +147,8 @@ sources: - type: git url: https://github.com/IJHack/QtPass.git - tag: v1.8.0 - commit: 9816bf18d27179b4af2e3471c8e26e9af22d1885 + tag: v1.8.1 + commit: 1a389718013586bf21e3b6d603d437f57a055c88 x-checker-data: type: git tag-pattern: ^v([\d.]+)$ - # v1.8.0 predates the Flatpak-ready metainfo, square icon and desktop-file - # name handling; overlay them from the repository until the next tag. - - type: file - path: ../qtpass.appdata.xml - dest-filename: qtpass.appdata.xml - - type: file - path: ../artwork/qtpass-icon.svg - dest: artwork - dest-filename: qtpass-icon.svg - - type: file - path: gpg2 - dest: flatpak - - type: file - path: ../main/main.cpp - dest: main - dest-filename: main.cpp - - type: file - path: ../src/qtpasssettings.cpp - dest: src - dest-filename: qtpasssettings.cpp - # 1.8.1 backport of #1689/#1696 (first-run wizard cancel/re-ask): main.cpp - # above needs MainWindow::initSucceeded(), which v1.8.0 does not have. - - type: file - path: ../src/mainwindow.h - dest: src - dest-filename: mainwindow.h - - type: file - path: ../src/mainwindow.cpp - dest: src - dest-filename: mainwindow.cpp - - type: file - path: ../src/qtpass.cpp - dest: src - dest-filename: qtpass.cpp diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/main/main.pro new/QtPass-1.8.2/main/main.pro --- old/QtPass-1.8.1/main/main.pro 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/main/main.pro 2026-09-24 23:00:10.000000000 +0200 @@ -29,7 +29,7 @@ desktop.path = $$PREFIX/share/applications desktop.files = ../qtpass.desktop metainfo.path = $$PREFIX/share/metainfo -metainfo.files = ../qtpass.appdata.xml +metainfo.files = ../org.qtpass.QtPass.metainfo.xml icon_scalable.path = $$PREFIX/share/icons/hicolor/scalable/apps icon_scalable.files = ../artwork/qtpass-icon.svg icon_512.path = $$PREFIX/share/icons/hicolor/512x512/apps diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/org.qtpass.QtPass.metainfo.xml new/QtPass-1.8.2/org.qtpass.QtPass.metainfo.xml --- old/QtPass-1.8.1/org.qtpass.QtPass.metainfo.xml 1970-01-01 01:00:00.000000000 +0100 +++ new/QtPass-1.8.2/org.qtpass.QtPass.metainfo.xml 2026-09-24 23:00:10.000000000 +0200 @@ -0,0 +1,99 @@ +<?xml version="1.0" encoding="UTF-8"?> +<component type="desktop-application"> + <id>org.qtpass.QtPass</id> + <launchable type="desktop-id">qtpass.desktop</launchable> + <provides> + <id>qtpass.desktop</id> + </provides> + <name>QtPass</name> + <summary>GUI for the standard UNIX password store</summary> + <summary xml:lang="nl-NL">GUI voor de standaard UNIX wachtwoord opslag</summary> + <developer id="org.ijhack"> + <name>IJHack</name> + </developer> + <description> + <p> + QtPass is a multi-platform GUI for pass, the standard UNIX password manager. + Your passwords stay in GPG-encrypted files that you control, optionally + synchronised with git, and QtPass works with the pass command line tool + or drives gpg and git directly. + </p> + <p>Features:</p> + <ul> + <li>Using pass or git and gpg2 directly</li> + <li>Cross platform: Linux, BSD, macOS and Windows</li> + <li>Using native widgets and iconography where possible</li> + <li>Reading pass password stores</li> + <li>Decrypting and displaying the password and related info</li> + <li>Editing and adding of passwords and information</li> + <li>Updating to and from a git repository</li> + <li>Per-folder user selection for multi recipient encryption</li> + <li>Configuration options for backends and executable/folder locations</li> + <li>Copying password to clipboard</li> + <li>Password generation with configurable complexity</li> + <li>OTP (one-time password) support</li> + <li>Smartcard and USB token support (OpenPGP, YubiKey)</li> + <li>Importing GPG keys from file or clipboard</li> + <li>Re-encrypting a folder, exporting your public key and adding recipients</li> + <li>Opt-in content search across decrypted entries</li> + <li>Configurable shoulder surfing protection options</li> + <li>Experimental WebDAV support</li> + </ul> + </description> + <metadata_license>GFDL-1.3</metadata_license> + <project_license>GPL-3.0-or-later</project_license> + <url type="homepage">https://qtpass.org/</url> + <url type="bugtracker">https://github.com/IJHack/QtPass/issues</url> + <url type="faq">https://github.com/IJHack/QtPass/blob/main/FAQ.md</url> + <url type="help">https://qtpass.org/getting-started</url> + <url type="vcs-browser">https://github.com/IJHack/QtPass</url> + <url type="translate">https://hosted.weblate.org/projects/qtpass/qtpass/</url> + <url type="contribute">https://github.com/IJHack/QtPass/blob/main/CONTRIBUTING.md</url> + <content_rating type="oars-1.1" /> + <supports> + <control>pointing</control> + <control>keyboard</control> + </supports> + <branding> + <color type="primary" scheme_preference="light">#6ba2e2</color> + <color type="primary" scheme_preference="dark">#1d4f7c</color> + </branding> + <screenshots> + <screenshot type="default"> + <caption>QtPass main window</caption> + <caption xml:lang="nl_NL">QtPass hoofdscherm</caption> + <image width="768" height="596">https://qtpass.org/images/qtpass.png</image> + </screenshot> + <screenshot> + <caption>QtPass Configuration window</caption> + <caption xml:lang="nl_NL">QtPass Configuratie scherm</caption> + <image width="900" height="637">https://qtpass.org/images/config.png</image> + </screenshot> + </screenshots> + <releases> + <release version="1.8.2" date="2026-09-24"> + <url>https://github.com/IJHack/QtPass/releases/tag/v1.8.2</url> + <description> + <p>Bug-fix release: the automatic Git push and pull settings are saved again, the edit dialog only turns key: value lines into fields when the settings ask for it, and the AppStream metainfo installs under the component ID.</p> + </description> + </release> + <release version="1.8.1" date="2026-09-15"> + <url>https://github.com/IJHack/QtPass/releases/tag/v1.8.1</url> + <description> + <p>Security and bug-fix release: WSL commands run without a shell, gpg encrypt calls ignore encrypt-to, only http(s) URLs are clickable, hardened single-instance IPC, new folders inherit recipients, a missing GPG home is ignored, and copying an entry onto a folder works again.</p> + </description> + </release> + <release version="1.8.0" date="2026-09-13"> + <url>https://github.com/IJHack/QtPass/releases/tag/v1.8.0</url> + <description> + <p>Built-in TOTP one-time passwords (RFC 6238, Steam Guard), share submenu, GPG key import, process output panel, SSH_AUTH_SOCK auto-detection, 14 new languages and many security and bug fixes.</p> + </description> + </release> + <release version="1.7.0" date="2026-04-20"> + <url>https://github.com/IJHack/QtPass/releases/tag/v1.7.0</url> + </release> + <release version="1.6.0" date="2026-04-13"> + <url>https://github.com/IJHack/QtPass/releases/tag/v1.6.0</url> + </release> + </releases> +</component> diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/qtpass.appdata.xml new/QtPass-1.8.2/qtpass.appdata.xml --- old/QtPass-1.8.1/qtpass.appdata.xml 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/qtpass.appdata.xml 1970-01-01 01:00:00.000000000 +0100 @@ -1,93 +0,0 @@ -<?xml version="1.0" encoding="UTF-8"?> -<component type="desktop-application"> - <id>org.qtpass.QtPass</id> - <launchable type="desktop-id">qtpass.desktop</launchable> - <provides> - <id>qtpass.desktop</id> - </provides> - <name>QtPass</name> - <summary>GUI for the standard UNIX password store</summary> - <summary xml:lang="nl-NL">GUI voor de standaard UNIX wachtwoord opslag</summary> - <developer id="org.ijhack"> - <name>IJHack</name> - </developer> - <description> - <p> - QtPass is a multi-platform GUI for pass, the standard UNIX password manager. - Your passwords stay in GPG-encrypted files that you control, optionally - synchronised with git, and QtPass works with the pass command line tool - or drives gpg and git directly. - </p> - <p>Features:</p> - <ul> - <li>Using pass or git and gpg2 directly</li> - <li>Cross platform: Linux, BSD, macOS and Windows</li> - <li>Using native widgets and iconography where possible</li> - <li>Reading pass password stores</li> - <li>Decrypting and displaying the password and related info</li> - <li>Editing and adding of passwords and information</li> - <li>Updating to and from a git repository</li> - <li>Per-folder user selection for multi recipient encryption</li> - <li>Configuration options for backends and executable/folder locations</li> - <li>Copying password to clipboard</li> - <li>Password generation with configurable complexity</li> - <li>OTP (one-time password) support</li> - <li>Smartcard and USB token support (OpenPGP, YubiKey)</li> - <li>Importing GPG keys from file or clipboard</li> - <li>Re-encrypting a folder, exporting your public key and adding recipients</li> - <li>Opt-in content search across decrypted entries</li> - <li>Configurable shoulder surfing protection options</li> - <li>Experimental WebDAV support</li> - </ul> - </description> - <metadata_license>GFDL-1.3</metadata_license> - <project_license>GPL-3.0-or-later</project_license> - <url type="homepage">https://qtpass.org/</url> - <url type="bugtracker">https://github.com/IJHack/QtPass/issues</url> - <url type="faq">https://github.com/IJHack/QtPass/blob/main/FAQ.md</url> - <url type="help">https://qtpass.org/getting-started</url> - <url type="vcs-browser">https://github.com/IJHack/QtPass</url> - <url type="translate">https://hosted.weblate.org/projects/qtpass/qtpass/</url> - <url type="contribute">https://github.com/IJHack/QtPass/blob/main/CONTRIBUTING.md</url> - <content_rating type="oars-1.1" /> - <supports> - <control>pointing</control> - <control>keyboard</control> - </supports> - <branding> - <color type="primary" scheme_preference="light">#6ba2e2</color> - <color type="primary" scheme_preference="dark">#1d4f7c</color> - </branding> - <screenshots> - <screenshot type="default"> - <caption>QtPass main window</caption> - <caption xml:lang="nl_NL">QtPass hoofdscherm</caption> - <image width="768" height="596">https://qtpass.org/images/qtpass.png</image> - </screenshot> - <screenshot> - <caption>QtPass Configuration window</caption> - <caption xml:lang="nl_NL">QtPass Configuratie scherm</caption> - <image width="900" height="637">https://qtpass.org/images/config.png</image> - </screenshot> - </screenshots> - <releases> - <release version="1.8.1" date="2026-09-15"> - <url>https://github.com/IJHack/QtPass/releases/tag/v1.8.1</url> - <description> - <p>Security and bug-fix release: WSL commands run without a shell, gpg encrypt calls ignore encrypt-to, only http(s) URLs are clickable, hardened single-instance IPC, new folders inherit recipients, a missing GPG home is ignored, and copying an entry onto a folder works again.</p> - </description> - </release> - <release version="1.8.0" date="2026-09-13"> - <url>https://github.com/IJHack/QtPass/releases/tag/v1.8.0</url> - <description> - <p>Built-in TOTP one-time passwords (RFC 6238, Steam Guard), share submenu, GPG key import, process output panel, SSH_AUTH_SOCK auto-detection, 14 new languages and many security and bug fixes.</p> - </description> - </release> - <release version="1.7.0" date="2026-04-20"> - <url>https://github.com/IJHack/QtPass/releases/tag/v1.7.0</url> - </release> - <release version="1.6.0" date="2026-04-13"> - <url>https://github.com/IJHack/QtPass/releases/tag/v1.6.0</url> - </release> - </releases> -</component> diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/qtpass.iss new/QtPass-1.8.2/qtpass.iss --- old/QtPass-1.8.1/qtpass.iss 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/qtpass.iss 2026-09-24 23:00:10.000000000 +0200 @@ -1,6 +1,6 @@ #define MyAppName "QtPass" #ifndef MyAppVersion - #define MyAppVersion "1.8.1" + #define MyAppVersion "1.8.2" #endif #define MyAppPublisher "IJHack" #define MyAppURL "https://qtpass.org/" diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/qtpass.pri new/QtPass-1.8.2/qtpass.pri --- old/QtPass-1.8.1/qtpass.pri 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/qtpass.pri 2026-09-24 23:00:10.000000000 +0200 @@ -1,7 +1,7 @@ # QtPass - GUI for pass # SPDX-FileCopyrightText: 2014 Anne Jan Brouwer -VERSION = 1.8.1 +VERSION = 1.8.2 CONFIG(coverage) { QMAKE_LFLAGS += --coverage diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/qtpass.spec new/QtPass-1.8.2/qtpass.spec --- old/QtPass-1.8.1/qtpass.spec 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/qtpass.spec 2026-09-24 23:00:10.000000000 +0200 @@ -7,7 +7,7 @@ # This should probably be part of a release process. Name: qtpass -Version: 1.8.1 +Version: 1.8.2 Release: 1%{?dist} Summary: QtPass is a multi-platform GUI for pass, the standard unix password manager. License: GPLv3 @@ -61,6 +61,9 @@ /usr/bin/gtk-update-icon-cache %{_datadir}/icons/hicolor &>/dev/null || : %changelog +* Thu Sep 24 2026 Anne Jan Brouwer <[email protected]> 1.8.2 +- Updated QtPass + * Tue Sep 15 2026 Anne Jan Brouwer <[email protected]> 1.8.1 - Updated QtPass diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/src/configdialog.cpp new/QtPass-1.8.2/src/configdialog.cpp --- old/QtPass-1.8.1/src/configdialog.cpp 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/src/configdialog.cpp 2026-09-24 23:00:10.000000000 +0200 @@ -194,6 +194,11 @@ settings.startMinimized = ui->checkBoxStartMinimized->isChecked(); } settings.useGit = ui->checkBoxUseGit->isChecked(); + // The backends and the auto-pull-on-start read the global keys; #1140 + // started storing these per profile as well and stopped writing the + // globals, which left both checkboxes without effect. + settings.autoPush = ui->checkBoxAutoPush->isChecked(); + settings.autoPull = ui->checkBoxAutoPull->isChecked(); settings.useOtp = ui->checkBoxUseOtp->isChecked(); settings.useGrepSearch = ui->checkBoxUseGrepSearch->isChecked(); settings.useQrencode = ui->checkBoxUseQrencode->isChecked(); diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/src/mainwindow.cpp new/QtPass-1.8.2/src/mainwindow.cpp --- old/QtPass-1.8.1/src/mainwindow.cpp 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/src/mainwindow.cpp 2026-09-24 23:00:10.000000000 +0200 @@ -1445,6 +1445,15 @@ s.activeProfile = name; s.passStore = prof.value("path"); s.passSigningKey = prof.value("signingKey"); + // Per-profile git flags (#1140) were stored but never applied; a profile + // without them keeps the global values. + const auto flag = [&prof](const char *key, bool current) { + const QString value = prof.value(QLatin1String(key)); + return value.isEmpty() ? current : value == QLatin1String("true"); + }; + s.useGit = flag("useGit", s.useGit); + s.autoPush = flag("autoPush", s.autoPush); + s.autoPull = flag("autoPull", s.autoPull); QtPassSettings::save(s); ui->statusBar->showMessage(tr("Profile changed to %1").arg(name), 2000); diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/src/passworddialog.cpp new/QtPass-1.8.2/src/passworddialog.cpp --- old/QtPass-1.8.1/src/passworddialog.cpp 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/src/passworddialog.cpp 2026-09-24 23:00:10.000000000 +0200 @@ -64,6 +64,7 @@ m_passConfig = s.passwordConfiguration; usePwgen(s.usePwgen); setTemplate(s.passTemplate, s.useTemplate); + templateAll(s.templateAllFields); setLength(m_passConfig.length); setPasswordCharTemplate(m_passConfig.selected); @@ -159,10 +160,15 @@ * @param password */ void PasswordDialog::setPassword(const QString &password) { - // Always parse all fields as editable so users can edit any field in the - // password file. This fixes issue #132 where users couldn't edit - // fields without toggling the "Show all fields templated" setting. - FileContent fileContent = FileContent::parse(password, m_fields, true); + // Which lines become fields is the user's choice, not ours: the template's + // fields when templating is on, every `key: value` line only with "Template + // all fields". Forcing allFields (#1138, for #132) turned every such line + // in every store into a label-locked widget, also with templates off, and + // took away plain-text editing of those lines (#1766). The same rule is + // applied in MainWindow when rendering the entry. + FileContent fileContent = + FileContent::parse(password, m_templating ? m_fields : QStringList(), + m_templating && m_allFields); ui->lineEditPassword->setText(fileContent.getPassword()); QWidget *previous = ui->checkBoxShow; @@ -388,6 +394,15 @@ } /** + * @brief PasswordDialog::templateAll split every `key: value` line into a + * field, not only the template's. + * @param templateAll + */ +void PasswordDialog::templateAll(bool templateAll) { + m_allFields = templateAll; +} + +/** * @brief PasswordDialog::setLength * PasswordDialog::setLength password length. * @param length diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/src/passworddialog.h new/QtPass-1.8.2/src/passworddialog.h --- old/QtPass-1.8.1/src/passworddialog.h 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/src/passworddialog.h 2026-09-24 23:00:10.000000000 +0200 @@ -69,6 +69,16 @@ void setTemplate(const QString &rawFields, bool useTemplate); /** + * @brief Whether every `key: value` line becomes a field of its own. + * + * Mirrors the "Template all fields" setting. Off, only the template's + * fields get widgets and every other line stays in the free-text body, + * where the user can edit key and value alike. + * @param templateAll true to split every tokenisable line into a field. + */ + void templateAll(bool templateAll); + + /** * @brief Set the desired password length shown in the dialog. * @param length Desired password length. */ @@ -163,6 +173,7 @@ QStringList m_fields; QString m_file; bool m_templating{}; + bool m_allFields{}; bool m_isNew{}; /// True once the existing entry's decrypted content has been loaded, so /// on_accepted() can refuse to overwrite it with empty fields before the diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/tests/auto/configdialog/tst_configdialog.cpp new/QtPass-1.8.2/tests/auto/configdialog/tst_configdialog.cpp --- old/QtPass-1.8.1/tests/auto/configdialog/tst_configdialog.cpp 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/tests/auto/configdialog/tst_configdialog.cpp 2026-09-24 23:00:10.000000000 +0200 @@ -53,6 +53,7 @@ void customCharsetRoundTrip(); void customCharsetPreservedWhenBuiltinSelected(); void addProfileSelectsNewRowAfterSort(); + void acceptSavesTheGlobalAutoPushAndAutoPull(); }; /** @@ -365,5 +366,33 @@ } } +/** + * @brief Since #1140 the dialog stored auto push/pull per profile and no + * longer wrote the global keys the backends read, so both checkboxes + * had no effect. + */ +void tst_configdialog::acceptSavesTheGlobalAutoPushAndAutoPull() { + { + AppSettings seed = QtPassSettings::load(); + seed.useGit = false; + seed.autoPush = false; + seed.autoPull = false; + QtPassSettings::save(seed); + } + ConfigDialog dialog(nullptr); + for (const char *name : + {"checkBoxUseGit", "checkBoxAutoPush", "checkBoxAutoPull"}) { + auto *box = dialog.findChild<QCheckBox *>(QLatin1String(name)); + QVERIFY2(box != nullptr, name); + box->setChecked(true); + } + dialog.accept(); + const AppSettings s = QtPassSettings::load(); + QVERIFY(s.useGit); + QVERIFY2(s.autoPush, "auto push must reach the global setting"); + QVERIFY2(s.autoPull, "auto pull must reach the global setting"); + QVERIFY(QtPassSettings::isAutoPush()); +} + QTEST_MAIN(tst_configdialog) #include "tst_configdialog.moc" diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/QtPass-1.8.1/tests/auto/ui/tst_ui.cpp new/QtPass-1.8.2/tests/auto/ui/tst_ui.cpp --- old/QtPass-1.8.1/tests/auto/ui/tst_ui.cpp 2026-09-15 12:27:43.000000000 +0200 +++ new/QtPass-1.8.2/tests/auto/ui/tst_ui.cpp 2026-09-24 23:00:10.000000000 +0200 @@ -7,6 +7,7 @@ #include <QHash> #include <QLabel> #include <QLineEdit> +#include <QPlainTextEdit> #include <QPointer> #include <QSignalSpy> #include <QSpinBox> @@ -27,6 +28,7 @@ private Q_SLOTS: void initTestCase(); void contentRemainsSame(); + void keyValueLinesFollowTemplateSettings(); void emptyPassword(); void multilineRemainingData(); void cleanupTestCase(); @@ -119,6 +121,87 @@ d->setTemplate("name", true); d->setPass(input); QCOMPARE(d->getPassword(), input); + + d.reset(new PasswordDialog(PasswordConfiguration{}, nullptr)); + d->setTemplate("", false); + d->templateAll(true); + d->setPass(input); + QCOMPARE(d->getPassword(), input); + + d.reset(new PasswordDialog(PasswordConfiguration{}, nullptr)); + d->setTemplate("", true); + d->templateAll(true); + d->setPass(input); + QCOMPARE(d->getPassword(), input); + + d.reset(new PasswordDialog(PasswordConfiguration{}, nullptr)); + d->setTemplate("name", true); + d->templateAll(true); + d->setPass(input); + QCOMPARE(d->getPassword(), input); +} + +/** + * @brief Which `key: value` lines become fields follows the settings, not a + * hard-coded "all". Regression for #1766: with templates off, every such + * line was turned into a label-locked field, so the key could no longer be + * edited as text. + */ +void tst_ui::keyValueLinesFollowTemplateSettings() { + const QString input = "pw\nDB: db-value\nlogin: user\nfree text\n"; + const auto lineEditNamed = [](PasswordDialog *d, const char *name) { + return d->findChild<QLineEdit *>(QLatin1String(name)); + }; + const auto body = [](PasswordDialog *d) { + return d->findChild<QPlainTextEdit *>(QStringLiteral("plainTextEdit")) + ->toPlainText(); + }; + // Templated modes write the template's fields first, so the line order can + // legitimately change; the content must not. + const auto sameLines = [](const QString &a, const QString &b) { + QStringList la = a.split('\n'), lb = b.split('\n'); + la.sort(); + lb.sort(); + return la == lb; + }; + + // Templates off: nothing is split out, the whole rest is editable text. + QScopedPointer<PasswordDialog> d( + new PasswordDialog(PasswordConfiguration{}, nullptr)); + d->setTemplate("login", false); + d->templateAll(false); + d->setPass(input); + QVERIFY2(lineEditNamed(d.data(), "DB") == nullptr, + "templates off: DB must not become a field"); + QVERIFY2(lineEditNamed(d.data(), "login") == nullptr, + "templates off: the template's own field must not appear either"); + QVERIFY(body(d.data()).contains(QStringLiteral("DB: db-value"))); + QVERIFY(body(d.data()).contains(QStringLiteral("login: user"))); + QCOMPARE(d->getPassword(), input); + + // Templates on, all-fields off: only the template's field is a widget. + d.reset(new PasswordDialog(PasswordConfiguration{}, nullptr)); + d->setTemplate("login", true); + d->templateAll(false); + d->setPass(input); + QVERIFY(lineEditNamed(d.data(), "login") != nullptr); + QCOMPARE(lineEditNamed(d.data(), "login")->text(), QStringLiteral("user")); + QVERIFY2(lineEditNamed(d.data(), "DB") == nullptr, + "all-fields off: a line outside the template stays text"); + QVERIFY(body(d.data()).contains(QStringLiteral("DB: db-value"))); + QVERIFY(sameLines(d->getPassword(), input)); + + // Templates on, all-fields on: every key: value line is a widget. + d.reset(new PasswordDialog(PasswordConfiguration{}, nullptr)); + d->setTemplate("login", true); + d->templateAll(true); + d->setPass(input); + QVERIFY(lineEditNamed(d.data(), "login") != nullptr); + QVERIFY(lineEditNamed(d.data(), "DB") != nullptr); + QCOMPARE(lineEditNamed(d.data(), "DB")->text(), QStringLiteral("db-value")); + QVERIFY(!body(d.data()).contains(QStringLiteral("DB:"))); + QVERIFY(body(d.data()).contains(QStringLiteral("free text"))); + QVERIFY(sameLines(d->getPassword(), input)); } void tst_ui::initTestCase() {} ++++++ _service ++++++ --- /var/tmp/diff_new_pack.N6Nw39/_old 2026-09-28 10:41:04.394431198 +0200 +++ /var/tmp/diff_new_pack.N6Nw39/_new 2026-09-28 10:41:04.399431408 +0200 @@ -6,7 +6,7 @@ <param name="exclude">.git</param> <param name="versionformat">@PARENT_TAG@</param> <param name="versionrewrite-pattern">v(.*)</param> - <param name="revision">v1.8.1</param> + <param name="revision">v1.8.2</param> <param name="changesgenerate">enable</param> </service> <service name="recompress" mode="manual"> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.N6Nw39/_old 2026-09-28 10:41:04.422432372 +0200 +++ /var/tmp/diff_new_pack.N6Nw39/_new 2026-09-28 10:41:04.425432498 +0200 @@ -1,6 +1,6 @@ <servicedata> <service name="tar_scm"> <param name="url">https://github.com/IJHack/QtPass.git</param> - <param name="changesrevision">1a389718013586bf21e3b6d603d437f57a055c88</param></service></servicedata> + <param name="changesrevision">71122182ddaef33d83c60868a7baff4a85442f1a</param></service></servicedata> (No newline at EOF)
