breadclip: document pin verb, config file, and ignore rules
All checks were successful
check / check (push) Successful in 2m9s
All checks were successful
check / check (push) Successful in 2m9s
- EVENTS.md: `bread.command.clip.pin` and `bread.clip.pinned` /
`.pin.failed` are now implemented; `select` stays explicitly not
implemented with the reason. AGENTS.md follows.
- README: Configuration section, Ctrl+P bind, updated privacy notes
(CLIPBOARD_STATE + ignore rules), JPEG image entries, primary badge.
- check.yml also runs on pushes to `main` — a push to main triggers a
dev-track release build, so it should be linted/tested first.
- release.yml uses `${GITHUB_REPOSITORY}` instead of a hard-coded
`Breadway/breadclip` for the GitHub mirror release upload.
This commit is contained in:
parent
d308593efd
commit
6db4a96026
6 changed files with 88 additions and 25 deletions
32
README.md
32
README.md
|
|
@ -77,6 +77,7 @@ Running `breadclip` a second time while it is open closes it (toggle behaviour).
|
|||
| `Up` / `Down` | Move selection |
|
||||
| `Enter` | Copy selected entry to clipboard and close |
|
||||
| `Delete` | Remove selected entry from history |
|
||||
| `Ctrl+P` | Pin/unpin selected entry (pinned entries survive trimming and sort to the top) |
|
||||
| `Escape` | Close without copying |
|
||||
|
||||
Clicking an entry copies it and closes the popup. Clicking outside the panel closes it.
|
||||
|
|
@ -85,6 +86,25 @@ Clicking an entry copies it and closes the popup. Clicking outside the panel clo
|
|||
|
||||
The popup has three filter chips — **All**, **Text**, **Images** — and a search box. The search box filters text entries by content; image entries only appear under the **Images** filter.
|
||||
|
||||
## Configuration
|
||||
|
||||
Optional TOML config at `$XDG_CONFIG_HOME/breadclip/config.toml` (typically
|
||||
`~/.config/breadclip/config.toml`). Every key has a sensible default, so the
|
||||
file can be omitted entirely — a copy of the full example lives in
|
||||
`contrib/config.toml.example`:
|
||||
|
||||
```toml
|
||||
[retention]
|
||||
text = 200 # max non-pinned text entries (0 = keep none)
|
||||
images = 50 # max non-pinned image entries (0 = keep none)
|
||||
|
||||
[panel]
|
||||
width = 520 # popup panel width, px
|
||||
|
||||
[capture]
|
||||
primary = false # also watch the middle-click primary selection
|
||||
```
|
||||
|
||||
## Data storage
|
||||
|
||||
History is stored under `$XDG_DATA_HOME/breadclip/` (typically `~/.local/share/breadclip/`):
|
||||
|
|
@ -92,14 +112,20 @@ History is stored under `$XDG_DATA_HOME/breadclip/` (typically `~/.local/share/b
|
|||
| Path | Contents |
|
||||
|------|----------|
|
||||
| `history.db` | SQLite database of all entries |
|
||||
| `images/` | PNG files for image entries |
|
||||
| `images/` | PNG/JPEG files for image entries |
|
||||
|
||||
The daemon keeps at most 200 text entries and 50 image entries, trimming oldest entries automatically.
|
||||
The daemon trims the oldest non-pinned entries automatically, keeping at
|
||||
most `retention.text` text entries and `retention.images` image entries
|
||||
(defaults 200 and 50; configurable). **Pinned entries are exempt from
|
||||
trimming** and sort to the top of the popup. Entries captured from the
|
||||
primary (middle-click) selection — when `capture.primary = true` — are
|
||||
stored alongside regular clipboard entries with a `primary` badge.
|
||||
|
||||
### Privacy
|
||||
|
||||
- `history.db` and every file under `images/` are created with `0600` permissions (owner read/write only), regardless of your umask.
|
||||
- breadclipd **never persists clipboard content flagged as sensitive by a password manager**. If a clipboard offer advertises the `x-kde-passwordManagerHint` MIME type — the convention used by KeePassXC, Bitwarden, and other password managers to mark content they own — that copy is skipped entirely and never reaches the database.
|
||||
- breadclipd **never persists clipboard content flagged as sensitive**. `wl-paste --watch` reports copies made with `wl-copy --sensitive` — which also covers offers advertising the `x-kde-passwordManagerHint` MIME type, the convention used by KeePassXC, Bitwarden, and other password managers to mark content they own — via `CLIPBOARD_STATE=sensitive`, and those copies are skipped entirely and never reach the database.
|
||||
- On top of that, breadclipd runs **best-effort ignore rules** that skip copies that *look* like secrets even when the app didn't flag them: one-time codes, Luhn-valid credit card numbers, private key blocks, `password:`-style credential lines, and well-known API token prefixes (see `breadclipd/src/ignore_rules.rs`). These are deliberately conservative and are a convenience, not a security boundary — the 0600/0700 permissions are the real protection.
|
||||
- That said, this is still a plaintext SQLite database of everything else you copy. Anything copied by an app that doesn't set the hint (e.g. copying a password from a terminal or a non-integrated app) will be stored like any other text entry. Treat `history.db` as sensitive, and don't rely on it as your only safeguard.
|
||||
|
||||
## Theming
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue