Skip to content

Commit 10e1c5a

Browse files
committed
feat: add clean receipts and clipboard quarantine
1 parent a231876 commit 10e1c5a

13 files changed

Lines changed: 1598 additions & 102 deletions

‎README.md‎

Lines changed: 19 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -157,7 +157,12 @@ they contain no real account, organization, or third-party message data.
157157
- **Session Copy History:** keeps up to 50 recent text copies in local memory
158158
while Active Guard is running. Each entry shows its exact capture time,
159159
probable source application, a bounded visible preview, character count, and
160-
detected risks. The source is inferred from the active application; macOS
160+
detected risks. Automatic text-cleaning entries also show a Clean Receipt and,
161+
only when the original was eligible for history and not truncated, guarded
162+
**Copy Clean Result** and **Restore Original** actions. Those actions first
163+
confirm that the pasteboard still holds the matching clean result; concealed,
164+
transient, auto-generated, and privacy-sensitive items are never retained for
165+
restoration. The source is inferred from the active application; macOS
161166
does not provide a trustworthy browser tab or page URL. Concealed,
162167
transient, and auto-generated pasteboard entries are not retained, long
163168
entries are truncated, and all history disappears when Signal Sieve exits.
@@ -192,7 +197,19 @@ they contain no real account, organization, or third-party message data.
192197
limits input to 4,000 characters, and refuses to overwrite detected changes
193198
to URLs, numbers, or quotations. Automatic processing skips source code,
194199
files, images, and privacy-sensitive clipboard types. Deterministic cleaning
195-
reanalyzes the result before reporting whether alerts were removed or remain.
200+
prepares and reanalyzes the candidate before replacing the clipboard. If a
201+
high-risk finding remains after reanalysis, Signal Sieve leaves the clipboard
202+
unchanged and marks the copy as quarantined. A red finding that was
203+
successfully removed may be replaced, but the red source warning still
204+
appears. The Clean Receipt reports the selected protocol, original and
205+
remaining alert counts and highest severity, deterministic removed/replaced
206+
counts, skipped status, and a short content-free reason with progressively
207+
disclosed technical evidence.
208+
A green receipt means only that Signal Sieve found no remaining risk covered
209+
by this cleaning analysis; it is not a malware verdict, authorship proof, or
210+
guarantee that the source is trustworthy. Visual Transfer uses the same
211+
receipt and quarantine decision, while its OCR transformation is identified
212+
separately from deterministic removed/replaced counts.
196213
Alert visibility is a separate setting: users may hide
197214
green and yellow alerts, or hide green through orange alerts. The two
198215
visibility choices are mutually exclusive, and red alerts cannot be disabled.

‎SECURITY.md‎

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,9 @@ public issue. Provide the smallest synthetic reproduction possible.
2121
entries and 20,000 characters per entry; concealed, transient, and
2222
auto-generated pasteboard items are not stored. Source application names are
2323
best-effort observations of the foreground app, not authenticated provenance.
24+
Clean-result and original-restore actions are available only for history-
25+
eligible, untruncated automatic-cleaning entries, and they fail closed if the
26+
pasteboard change count or expected text no longer matches.
2427
- Opening a finding in the browser is an explicit network boundary. Unicode
2528
queries contain element metadata only; Surface Regularity queries contain only
2629
the generic signal topic. Neither may contain the analyzed text.
@@ -31,6 +34,16 @@ public issue. Provide the smallest synthetic reproduction possible.
3134
- Code Guard never executes, compiles, or automatically rewrites copied code.
3235
Sanitized output requires explicit review, and visually confusable
3336
identifiers remain unchanged because their intended spelling is unknowable.
37+
- Automatic clipboard cleaning prepares and reanalyzes its candidate before
38+
writing. If a high-risk finding remains, the pasteboard is left unchanged and
39+
the item is treated as quarantined. If an original red finding is removed, the
40+
clean text may replace the clipboard, but the red source warning remains
41+
mandatory. Clean Receipts store only counts, severities, the selected
42+
protocol, skipped status, and bounded content-free reasons.
43+
A green receipt is limited to the supported cleaning analysis and is not a
44+
general safety or source-trust verdict. Automatic Visual Transfer follows the
45+
same reanalysis and quarantine decision, but its OCR output remains lossy and
46+
is not represented as a deterministic scalar-replacement count.
3447
- Binary Guard never decodes or executes a detected payload. Encoded data is
3548
not inherently unsafe; the label describes its representation, not intent.
3649
- Contextual Unicode classification is fail-safe rather than blanket removal.

‎Sources/SignalSieve/App/ContentView.swift‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -63,6 +63,8 @@ struct ContentView: View {
6363
entries: model.clipboardHistory,
6464
language: model.language,
6565
onOpen: model.openClipboardHistoryEntry,
66+
onCopyCleanResult: model.copyCleanResultFromHistory,
67+
onRestoreOriginal: model.restoreOriginalFromHistory,
6668
onDelete: model.removeClipboardHistoryEntry,
6769
onClear: model.clearClipboardHistory
6870
)

0 commit comments

Comments
 (0)