Skip to content

Latest commit

 

History

History
80 lines (63 loc) · 2.86 KB

File metadata and controls

80 lines (63 loc) · 2.86 KB

Roadmap

This roadmap tracks product direction at a high level. README.md remains the best source for the currently implemented surface.

Phase 0 - Foundation

  • Rust workspace and repository setup
  • Git repository initialization
  • baseline project structure

Phase 1 - Core MFA vault

  • core, storage, cli, gui
  • encrypted local vault
  • TOTP add, list, token, remove, and metadata export
  • Windows MSI packaging

Phase 2 - Hardening and shared flows

  • atomic writes and backup/restore strategy
  • password rotation with vault re-encryption
  • otpauth:// import via shared domain logic
  • QR parsing for otpauth://
  • richer validation and migration support
  • richer search, internal metadata, and project directories
  • optional OS keychain or keyfile strategy

Phase 3 - Desktop GUI

  • Rust-native desktop shell
  • vault initialize and unlock workflow
  • account add, edit, remove, token, and export flows
  • persistent light and dark theme
  • live countdown and explicit copy action
  • visual project directories and inline account actions
  • account history and restore UX
  • deletion of empty workspace and subdirectory nodes
  • multi-selection and bulk account deletion
  • wider release validation of Windows secondary verification

Phase 4 - Local automation

  • native unlock window for local automation access
  • process-scoped session over JSON stdio
  • persistent agent/MCP lifecycle hardening with EOF shutdown, Win32 message pumping, bounded native waits, session identity, and broker recovery
  • machine-readable account and token operations
  • explicit short-lived grants for sensitive operations
  • password rotation inside the local automation boundary
  • loopback-only HTTP API
  • broader client-scoped authorization model

Phase 5 - Interop and integrations

  • CSV import
  • selective import from external authenticators and managers
  • controlled export formats beyond metadata-only JSON
  • browser integration
  • SSH agent integration
  • Secret Service equivalent
  • challenge-response hardware support

Phase 6 - Advanced MFA

  • HOTP
  • WebAuthn and passkeys
  • hardware-backed options

Phase 7 - Release hardening

  • dedicated mfa-forge-mcp binary
  • dedicated mfa-forge-agent binary
  • dedicated mfa-forge-launcher binary
  • minimal MCP server over JSON-RPC stdio
  • local audit trail for sensitive automation actions
  • validated local RC17 -> RC18 upgrade path
  • validated startup-updater proof on RC25 -> RC26
  • stable public release publication
  • hotfix 1.0.2 issue closure for lifecycle, audit/storage boundaries, module split, test KDF isolation, and mixed-DPI window behavior
  • broader client-scoped deny-by-default policy model
  • deeper audit and reporting workflows