Searching End-to-End Encrypted Journal Content in the Browser
How Inpages.me searches protected journal titles and diary notes: account-scoped catalog, browser-side decryption, local matching, and clear limits today.
Engineering notes
Architecture, security boundaries, and hard implementation choices from Inpages.me—written with the limits included.
Encryption, recovery, integrity, and the boundary between private and public.
How Inpages.me searches protected journal titles and diary notes: account-scoped catalog, browser-side decryption, local matching, and clear limits today.
See how Inpages.me combines Argon2id, AES-GCM, a browser-held master key, and Rails storage to protect journal text and files before they are uploaded.
Read the practical Inpages.me threat model: which server and database risks encryption reduces, which metadata remains, and where browsers limit it today.
Inside the browser and Rails workflow that replaces journal text, links, photos, and files together—or leaves the original Memory untouched after failure.
Follow how Inpages.me encrypts photo and file bytes in the browser, stores opaque Active Storage blobs, and reconstructs media only after local decryption.
See how Inpages.me exports an account-bound Recovery Key in the browser, verifies it without uploading the key, and restores access without server escrow.
Learn why protected and public Memories require different data paths, how publication changes the trust boundary, and why visibility is not encryption.
Learn how Inpages.me keeps Content Security Policy nonces stable across Turbo visits, constrains trusted sources, and treats CSP as defense in depth today.
See why Inpages.me sanitizes rich text before encrypting it in the browser, preserving safe rendering without asking Rails to inspect plaintext on each page.
Learn how Inpages.me tests browser-based encryption across Rails requests, locked states, and client transitions without relying on server decryption.
Follow how Inpages.me builds account-scoped data exports in Rails, collecting only owned records and attachments while keeping recovery material separate.
See how Inpages.me verifies ZIP data exports with root checks, manifests, and SHA-256 before a private archive becomes available to download to an owner.
Learn how Inpages.me uses Rails and Solid Queue to limit export availability, expire delivery files, and clean incomplete export work safely on local disk.
See how Inpages.me cleans up abandoned encrypted-upload blobs without purging attachments that became part of a protected Memory or active attachments.
Learn how Inpages.me reuses Active Storage blobs in photo books while preserving reference safety and avoiding premature physical deletion from shared storage.
See how Inpages.me filters sensitive Rails parameters before they enter application logs, while treating operational logs as private material too by default.
Learn how Inpages.me keeps Rails sitemap lastmod dates accurate by updating them only for significant public-content, link, or schema changes in production.
Zoom's case shows why an encryption label is not proof. Use six technical questions to test who holds keys, what is protected, and which risks remain.
The LastPass incident shows why encrypted fields do not erase every breach risk. Map ciphertext, metadata, passwords, and recovery before trusting a journal.
BetterHelp and Flo show how sensitive data can reach advertisers. See why protected journal plaintext must stay outside analytics and server analysis.
The Strava heatmap made sensitive patterns visible without revealing messages. Learn what encrypted journal metadata can still disclose and how to reduce it.
An accidental public route can defeat a private default. Trace how Inpages separates protected content, publication, and search discovery in every access path.
A private AI feature needs an explicit data boundary. See why Inpages excludes protected memories from server-side embeddings, insights, and assistant inputs.
A readable login password is a serious failure, but it should not unlock every private page. See why Inpages separates account access from its vault key.
Backups can preserve encrypted records without recovering a lost secret. Learn the separate roles of restore drills, vault keys, and Recovery Keys for journals.
A private photo upload can leak through previews, analysis, or metadata. See how Inpages keeps protected file bytes opaque and names remaining side channels.
Encryption is a state transition, not a checkbox. See why Inpages preserves the prior Memory when protected uploads or the final commit cannot complete safely.