Find a file
Dan Stillman 056f61d8dd Encrypt API key and WebDAV password using OS keychain
Wraps the values stored in nsILoginManager with OSKeyStore, which derives
its master key from Keychain on macOS, DPAPI on Windows, and libsecret on
Linux. A copy of the profile alone is no longer enough to extract these
credentials.

Existing plaintext entries are mirrored once per session to a new
"(encrypted)" realm but preserved in the original realm so a user can
still downgrade to a release that doesn't know about encryption. Active
credential changes (sign in, sign out, password change) write to the
encrypted realm only and remove the legacy entry. A future version can
clear any remaining legacy entries on startup.

Patches MOZ_APP_BASENAME in the bundled runtime so the keychain master
key is labeled "Zotero Encrypted Storage" rather than "Firefox Encrypted
Storage", with a check_line guard so a future Mozilla change to the
OSKeyStore label format fails the build instead of silently rebranding
the entry. Also fixes check_line to take an explicit file argument.
2026-04-30 15:38:42 -04:00
.github/workflows Rename pdf-worker submodule to document-worker 2026-04-22 15:50:02 -04:00
app Encrypt API key and WebDAV password using OS keychain 2026-04-30 15:38:42 -04:00
chrome Encrypt API key and WebDAV password using OS keychain 2026-04-30 15:38:42 -04:00
defaults/preferences Add support for clearing challenge in browser during translation 2026-04-23 15:34:28 -04:00
document-worker@fd642b3828 Rename pdf-worker submodule to document-worker 2026-04-22 15:50:02 -04:00
js-build Rename pdf-worker submodule to document-worker 2026-04-22 15:50:02 -04:00
note-editor@107ab75c32 Update note-editor submodule 2026-03-19 15:57:30 +00:00
reader@9bdbadb3cd Update reader submodule 2026-04-27 16:05:48 -04:00
resource Item tree refactor megacommit 2026-04-27 14:44:39 -04:00
scripts Add script for pulling Fluent translations 2026-01-25 22:15:29 -05:00
scss Item tree refactor megacommit 2026-04-27 14:44:39 -04:00
styles@dff7452b24 Update translators, styles, CSL locales, and renamed-styles.json 2026-04-02 15:51:43 -04:00
test Add test for collection highlighting on Ctrl/Option 2026-04-29 15:21:29 -04:00
translators@cfc69de47e Update translators, styles, CSL locales, and renamed-styles.json 2026-04-02 15:51:43 -04:00
types/gecko fx140: Update type definitions 2025-07-30 22:30:37 -04:00
.babelrc Use production builds of react libraries (#4482) 2024-08-02 03:43:02 -04:00
.gitattributes Update Linux updater for Zotero 7 2023-05-20 10:51:47 +00:00
.gitignore Use user-provided codesign script for Windows signing 2024-04-08 10:12:58 +01:00
.gitmodules Rename pdf-worker submodule to document-worker 2026-04-22 15:50:02 -04:00
chrome.manifest Remove old citation dialogs (#5177) 2025-04-02 05:26:06 -04:00
CLAUDE.md Rename pdf-worker submodule to document-worker 2026-04-22 15:50:02 -04:00
CONTRIBUTING.md Add "support questions" to CONTRIBUTING.md 2022-12-01 05:10:42 -05:00
COPYING Update COPYING 2018-03-26 11:27:48 +02:00
eslint.config.mjs Replace CSL validator with reproducible WASM build (#5525) 2025-08-29 00:40:41 -04:00
package-lock.json Update package-lock.json 2026-01-29 13:22:13 -05:00
package.json Upgrade ftl-tx. Fix #5671. 2025-12-20 02:22:23 +01:00
README.md "Zotero wiki" → "Zotero documentation" in app build README 2023-04-26 04:40:22 -04:00
update.rdf Update Fx minVersion to 45 2016-12-13 09:12:55 -05:00
version Update version to 10.0 2026-04-10 13:41:18 -04:00

Zotero

CI

Zotero is a free, easy-to-use tool to help you collect, organize, cite, and share your research sources.

Please post feature requests or bug reports to the Zotero Forums. If you're having trouble with Zotero, see Getting Help.

For more information on how to use this source code, see the Zotero documentation.