Skip to main content
Back to Products
python

DotGhostBoard

Advanced cryptographic & privacy-first clipboard manager for Linux with hardware-level secure wiping

4 stars0 forks0 issuesVersion v2.1.0
DotGhostBoard โ€ข READMEโ€ข19 min read

๐Ÿ‘ป DotGhostBoard

Advanced clipboard manager for Kali Linux โ€” part of the DotSuite toolkit.

Version Codename Python PyQt6 Platform Tests License


What is DotGhostBoard?

DotGhostBoard is a lightweight, privacy-first clipboard manager built natively for Linux. It runs silently in the background, capturing everything you copy โ€” text, images, and video paths โ€” and stores them locally in a SQLite database. No cloud. No telemetry. No Electron.

Think Ditto (Windows) or CopyQ (Linux) โ€” but built for the DotSuite ecosystem with a Kali-native dark aesthetic.

DotGhostBoard UI DemoDotGhostBoard UI Demo DotGhostBoard Capture DemoDotGhostBoard Capture Demo

Features

  • Text capture โ€” Every text you copy is saved instantly
  • Image capture โ€” Screenshots and copied images saved as .png
  • Video path detection โ€” Detects copied file paths for .mp4, .mkv, .avi, and more
  • Pin system โ€” Pin important items; they are protected from deletion forever
  • Persistent storage โ€” SQLite database survives reboots
  • Real-time search โ€” Filter your clipboard history instantly
  • Clear history โ€” Wipe unpinned items in one click (pinned items always stay)
  • System tray โ€” Lives quietly in your tray, always available
  • Global Shortcuts โ€” Ctrl+Alt+V toggles the dashboard from anywhere; Ctrl+Alt+Space opens the floating Spotlight search overlay (GNOME & XFCE native)
  • Tiling Window Manager Support (EWMH) โ€” Seamless cross-workspace migration upon summon (Ctrl+Alt+V, dotghostboard --toggle) on Qtile, Openbox, and EWMH-compliant window managers; migrates to your active workspace and focuses without hiding
  • Spotlight Quick Search โ€” Floating, instant clipboard search overlay (Ctrl+Alt+Space); search, navigate with arrows, copy, and close instantly with zero window flicker; protected by Eclipse Master Password
  • In-Dashboard Search โ€” Ctrl+F instantly focuses and selects the search bar within the main dashboard
  • App icon โ€” Auto-generated neon ghost icon via scripts/generate_icon.py
  • Dark Neon UI โ€” Custom QSS theme built for dark desktops
  • Settings panel โ€” โš™ Max history limit, privacy clear-on-exit, theme toggle
  • Keyboard navigation โ€” โ†‘/โ†“ to move between cards, Enter to copy, Esc to clear focus
  • Double-click to paste โ€” Double-click any card to copy it instantly
  • Standalone autostart โ€” scripts/setup_autostart.py sets up boot entry without bash
  • Image thumbnail previews โ€” Lazy-loaded thumbnails capped at 300ร—180px; deferred rendering via QTimer.singleShot
  • Video thumbnails via ffmpeg โ€” First-frame extraction from video files; background thread processing; graceful fallback if ffmpeg unavailable
  • Auto-cleanup โ€” Configurable max_captures limit (default 100); oldest unpinned captures deleted from disk on startup
  • Image viewer popup โ€” Full-size image preview with smooth scaling; Ctrl+C to copy image; Escape to close
  • Copy image to clipboard โ€” Image items now copy actual image data (not file path) back to clipboard
  • Drag & drop reorder โ€” Pinned cards show drag handle; reorder persists via sort_order in database
  • Tag system โ€” Assign custom #tags to any item; colored chip display with rotating 6-palette colors; inline autocomplete from existing tags
Tag System DemoTag System Demo
  • Combined search โ€” Search by text and tag simultaneously (e.g. "python #code"); tag-only filter works on all item types
  • Collections & Drag-and-Drop โ€” Group items into named folders; sidebar panel with click-to-filter, right-click to rename/delete. Features intuitive drag-and-drop interface for organizing items.
Drag and Drop Collections DemoDrag and Drop Collections Demo
  • Multi-select โ€” Ctrl+Click to toggle, Shift+Click for range selection; neon green โœ“ overlay on selected cards
Multi-Select DemoMulti-Select Demo
  • Local Encryption (Eclipse Mode) โ€” Secure sensitive clipboard items using AES-256 encryption. Items are hidden and locked behind a Secret Overlay until explicitly revealed.
Local Encryption DemoLocal Encryption Demo
  • Session Lock & Master Password โ€” Protect your entire dashboard with a Master Password. Features automatic timeout locking and a stylish blurred lock screen.
Session Lock DemoSession Lock Demo
  • Advanced Settings & Pro UI โ€” Comprehensive control over Stealth Mode, App Filters, Auto-lock timeouts, and a beautiful DotSuite licensing/about page.
Settings and About DemoSettings and About Demo
  • Bulk actions toolbar โ€” Appears when 2+ selected: Pin All, Unpin All, Add Tag, Export, Delete All, Cancel

  • Export โ€” Export selected items to .txt (timestamped blocks) or .json (structured data with tags)

  • Global tag manager โ€” โš™ Settings โ†’ "Manage Tagsโ€ฆ"; rename or delete tags across all items in one click

  • Drag & drop visual feedback โ€” Ghost pixmap with neon border while dragging; source card dims to 35%; drop targets highlight with dashed green border

  • E2EE Local Network Sync (Nexus) โ€” End-to-end encrypted clipboard synchronization across your local network. AES-256-GCM protection with X25519 (ECDH) handshakes.

  • mDNS Auto-Discovery โ€” Zero-config discovery of peers on the same WiFi.

  • REST API โ€” Token-protected local-network API for history, item pushing, and pairing workflows.

  • CLI Companion โ€” dotghost push and dotghost pop from your terminal for seamless shell workflow.

  • Secure Device Pairing โ€” PIN-protected handshakes to ensure unauthorized devices can't intercept your sync data.

  • The Vault Subsystem (Ctrl+Shift+V) โ€” Dedicated encrypted drawer panel (vault.db) with envelope encryption (domain-separated KEK + per-database DEK), masked secrets, search filtering, category pills, constant-time deduplication, and auto-scrubbing. Features an expanded 380px drawer with a clean two-row header and an informative Empty State Tips Card.

  • Zero-Log Secret Detector โ€” Shannon entropy analysis & regex heuristics detecting API keys, tokens, and passwords on copy, offering one-click "Send to Vault" and auto-scrub actions without leaving plaintext in history.

  • Desktop Notifications โ€” Native FreeDesktop desktop notifications (notify-send) with interactive click-to-summon callbacks.

  • Copy Count Badge โ€” Each card shows a live pill badge (ร—2, ร—5, ร—10+) tracking how many times an item has been copied. Color escalates from teal โ†’ orange โ†’ ๐Ÿ”ฅ as the count grows.

  • Auto-Pin Suggestion โ€” At ร—5 copies a non-blocking toast appears suggesting you pin the item. At ร—10 the item is auto-pinned silently so frequently-used text is always protected from deletion.

  • Smart Auto-Tagging (Leviathan) โ€” Zero-overhead rules engine automatically categorizes incoming clips (#link, #code, #json, #secret, #email, #ip, #phone, #path, #hash) using local regex heuristics.

  • Contextual Smart Actions โ€” Inline card actions tailored to content type: ๐Ÿ”— Open Link in browser, { } Format JSON with indentation, โœ‰ Compose email, ๐Ÿ“ก Copy IP, or ๐Ÿ›ก โ†’ Vault to securely encrypt credentials.

  • Built-in Vault Password & Token Generator โ€” Cryptographically strong password/token generator in Add/Edit Secret dialog (โšก Generate) with customizable length, symbols, and live Shannon entropy strength bar.

  • Vault Password History โ€” Retains last 3 previous encrypted password versions (vault_item_history) with single-click reveal, copy, or revert via dedicated ๐Ÿ“œ history modal dialog.

  • Vault Encrypted Export & Import (.vault) โ€” Standalone AES-256-GCM encrypted backup packages protected by high-iteration PBKDF2-HMAC-SHA256 (100,000 rounds); exports all secrets, 3-version history, and expiry dates with zero disk plaintext leaks and intelligent duplicate resolution.

  • Secret Expiration Dates & Status Badges โ€” Optional expiration dates on vault items (30d, 90d, 180d, 1y, or custom date picker) with live visual card status badges (โ›” EXPIRED, โš ๏ธ Xd left, โณ YYYY-MM-DD).

  • Vault Plaintext History Sweep โ€” Deleting or scrubbing a secret from The Vault automatically purges any lingering unencrypted plaintext copies from clipboard history.

  • Dynamic Auto-Purge History โ€” Configurable history threshold dynamically enforced from Settings, auto-purging oldest unpinned items while respecting pin immunity.

  • Unified Password Input & Masking (PasswordInputWidget) โ€” Reusable password input with integrated ๐Ÿ‘๏ธ / ๐Ÿ™ˆ eye toggle, unified design system, and compact, balanced spacing across both App Session Lock and Vault Unlock screens.

  • Modern Typography & Aesthetic โ€” Clean sans-serif UI typography (Inter / Noto Sans), muted dark-slate theme, refined card padding, compact 26ร—26 action buttons, and customizable shortcuts button in Settings.

Native Desktop Integration: DotGhostBoard integrates seamlessly with desktop environment dock and app launcher.

Kali Dock IntegrationKali Dock Integration

Project Structure

CODE
DotGhostBoard/
โ”œโ”€โ”€ main.py                          # Entry point + IPC local server (--toggle, --spotlight)
โ”œโ”€โ”€ core/
โ”‚   โ”œโ”€โ”€ constants.py                 # App-wide constants (PAGE_SIZE, thresholds)
โ”‚   โ”œโ”€โ”€ config.py                    # Runtime configuration helpers
โ”‚   โ”œโ”€โ”€ paths.py                     # XDG path resolution
โ”‚   โ”œโ”€โ”€ crypto.py                    # AES-256-GCM + HKDF domain-separated key derivation
โ”‚   โ”œโ”€โ”€ notifications.py             # FreeDesktop notification dispatcher (action callbacks)
โ”‚   โ”œโ”€โ”€ window_manager.py            # Pure ctypes EWMH X11 window management
โ”‚   โ”œโ”€โ”€ watcher.py                   # Clipboard Orchestrator โ†’ Backend + Pipeline
โ”‚   โ”œโ”€โ”€ shortcuts.py                 # Global desktop shortcut manager (GNOME/XFCE)
โ”‚   โ”œโ”€โ”€ autostart.py                 # Modular XDG autostart desktop entry manager
โ”‚   โ”œโ”€โ”€ sync_engine.py               # E2EE background push worker (Nexus)
โ”‚   โ”œโ”€โ”€ network_discovery.py         # Zeroconf mDNS peer discovery (Nexus)
โ”‚   โ”œโ”€โ”€ api_server.py                # Local REST API & Handshake handler (Nexus)
โ”‚   โ”œโ”€โ”€ pairing.py                   # PIN-based ECDH handshake logic (Nexus)
โ”‚   โ”œโ”€โ”€ updater.py                   # GitHub auto-updater engine
โ”‚   โ”œโ”€โ”€ app_filter.py                # App whitelist/blacklist (Eclipse)
โ”‚   โ”œโ”€โ”€ media.py                     # Image/video handler
โ”‚   โ”œโ”€โ”€ clipboard/                   # Clipboard pipeline & backend abstraction
โ”‚   โ”‚   โ”œโ”€โ”€ events.py                # ClipboardEvent, CaptureDecision, Action enum
โ”‚   โ”‚   โ”œโ”€โ”€ pipeline.py              # Pure policy engine (no Qt dependency)
โ”‚   โ”‚   โ”œโ”€โ”€ backend.py               # ClipboardBackend Protocol
โ”‚   โ”‚   โ””โ”€โ”€ backends/qt_backend.py   # Qt polling backend
โ”‚   โ”œโ”€โ”€ security/                    # Security domain layer
โ”‚   โ”‚   โ”œโ”€โ”€ detector.py              # SecretDetector (regex & entropy heuristics)
โ”‚   โ”‚   โ”œโ”€โ”€ auto_tagger.py           # Rules-based auto-tagging engine (Leviathan)
โ”‚   โ”‚   โ””โ”€โ”€ vault/                   # Vault: isolated vault.db + DEK envelope encryption
โ”‚   โ”œโ”€โ”€ services/                    # Business logic layer (Qt-free)
โ”‚   โ”‚   โ”œโ”€โ”€ history_service.py       # Clipboard item queries, pins, tags, copy thresholds
โ”‚   โ”‚   โ”œโ”€โ”€ collection_service.py    # Collection management & categorization
โ”‚   โ”‚   โ”œโ”€โ”€ security_service.py      # Session lock, password lifecycle, Eclipse encryption
โ”‚   โ”‚   โ””โ”€โ”€ sync_service.py          # Peer trust & LAN sync orchestration
โ”‚   โ””โ”€โ”€ storage/                     # Persistence layer
โ”‚       โ”œโ”€โ”€ database.py              # Context-managed SQLite connection
โ”‚       โ”œโ”€โ”€ migrations.py            # Versioned schema migrations
โ”‚       โ”œโ”€โ”€ __init__.py              # Backward-compatible facade
โ”‚       โ””โ”€โ”€ repositories/
โ”‚           โ”œโ”€โ”€ clips.py             # Clipboard item CRUD, encryption, search
โ”‚           โ”œโ”€โ”€ tags.py              # Tag normalization & global rename/delete
โ”‚           โ”œโ”€โ”€ collections.py       # Collection categorization
โ”‚           โ”œโ”€โ”€ peers.py             # Trusted device credentials
โ”‚           โ””โ”€โ”€ stats.py             # Header metrics & copy counts
โ”œโ”€โ”€ ui/
โ”‚   โ”œโ”€โ”€ dashboard.py                 # Window shell + signal bus (Orchestrator โ‰ค 500 LOC)
โ”‚   โ”œโ”€โ”€ dashboard_compat.py          # DashboardCompatibilityMixin architectural shim
โ”‚   โ”œโ”€โ”€ window_utils.py              # EWMH cross-workspace migration & dialog modality
โ”‚   โ”œโ”€โ”€ components/                  # Isolated UI layout components
โ”‚   โ”‚   โ”œโ”€โ”€ __init__.py              # Component exports
โ”‚   โ”‚   โ”œโ”€โ”€ sidebar.py               # SidebarWidget (collections & devices layout)
โ”‚   โ”‚   โ”œโ”€โ”€ topbar.py                # TopBarWidget (header, logo, stats, action buttons)
โ”‚   โ”‚   โ”œโ”€โ”€ cards_view.py            # CardsView (QScrollArea container & DnD signals)
โ”‚   โ”‚   โ”œโ”€โ”€ bulk_toolbar.py          # BulkToolbar (HintStrip & BulkBar)
โ”‚   โ”‚   โ””โ”€โ”€ tray_manager.py          # DashboardTrayManager (tray icon, context menu, tooltips)
โ”‚   โ”œโ”€โ”€ controllers/                 # Behavioral QObject controllers
โ”‚   โ”‚   โ”œโ”€โ”€ history_controller.py    # Card lifecycle, pagination, search, pin/copy/delete
โ”‚   โ”‚   โ”œโ”€โ”€ collection_controller.py # Sidebar, drag-drop, collection CRUD
โ”‚   โ”‚   โ”œโ”€โ”€ security_controller.py   # Lock/unlock, secret copy, Eclipse encrypt/decrypt
โ”‚   โ”‚   โ”œโ”€โ”€ sync_controller.py       # Peer pairing, device list, broadcast
โ”‚   โ”‚   โ””โ”€โ”€ update_controller.py     # Update check worker and notification trigger
โ”‚   โ”œโ”€โ”€ vault/                       # The Vault UI subsystem
โ”‚   โ”‚   โ”œโ”€โ”€ vault_panel.py           # Slide-out Vault drawer widget (two-row header & tips card)
โ”‚   โ”‚   โ”œโ”€โ”€ vault_controller.py      # Vault lifecycle & duplicate detector
โ”‚   โ”‚   โ”œโ”€โ”€ secret_card.py           # Masked secret card with reveal/copy/scrub
โ”‚   โ”‚   โ”œโ”€โ”€ secret_dialog.py         # Add/Edit secret modal
โ”‚   โ”‚   โ”œโ”€โ”€ history_dialog.py        # Password history viewer & version revert modal
โ”‚   โ”‚   โ”œโ”€โ”€ backup_dialog.py         # Passphrase modal for encrypted export & import (.vault)
โ”‚   โ”‚   โ”œโ”€โ”€ unlock_dialog.py         # Vault master password unlock dialog
โ”‚   โ”‚   โ””โ”€โ”€ send_to_vault.py         # Bridge from clipboard cards to Vault
โ”‚   โ”œโ”€โ”€ widgets/                     # Modular widget package
โ”‚   โ”‚   โ”œโ”€โ”€ item_card.py             # Full clipboard card widget
โ”‚   โ”‚   โ”œโ”€โ”€ stats_header.py          # Header stats bar
โ”‚   โ”‚   โ”œโ”€โ”€ pin_toast.py             # Non-blocking pin suggestion toast
โ”‚   โ”‚   โ”œโ”€โ”€ tag_chip.py              # Tag chip widget
โ”‚   โ”‚   โ”œโ”€โ”€ tag_input.py             # Inline tag autocomplete input
โ”‚   โ”‚   โ””โ”€โ”€ password_input.py        # Composite PasswordInputWidget with eye visibility toggle
โ”‚   โ”œโ”€โ”€ spotlight.py                 # Floating Spotlight quick search overlay
โ”‚   โ”œโ”€โ”€ settings/                    # Settings package (decomposed)
โ”‚   โ”‚   โ”œโ”€โ”€ __init__.py              # Backward-compatible facade
โ”‚   โ”‚   โ”œโ”€โ”€ _io.py                   # Settings I/O and defaults
โ”‚   โ”‚   โ”œโ”€โ”€ dialog.py                # SettingsDialog orchestrator shell
โ”‚   โ”‚   โ””โ”€โ”€ pages/                   # Tab builders (General, Security, API, About)
โ”‚   โ”œโ”€โ”€ tag_manager.py               # Standalone TagManagerDialog
โ”‚   โ”œโ”€โ”€ lock_screen.py               # Session lock screen
โ”‚   โ”œโ”€โ”€ pairing_dialog.py            # Device pairing UI (Nexus)
โ”‚   โ”œโ”€โ”€ updater_dialog.py            # GUI for GitHub updates
โ”‚   โ”œโ”€โ”€ update_log_screen.py         # Update installation log & process relauncher
โ”‚   โ””โ”€โ”€ ghost.qss                    # Dark Neon theme stylesheet
โ”œโ”€โ”€ cli/
โ”‚   โ””โ”€โ”€ dotghost.py              # Command-line companion (push, pop, spotlight, toggle)
โ”œโ”€โ”€ data/
โ”‚   โ”œโ”€โ”€ icons/                   # Generated app icons + ghost.svg source
โ”‚   โ”œโ”€โ”€ captures/                # Sample captures (.png)
โ”‚   โ”œโ”€โ”€ assets/                  # GIFs, screenshots, demo media
โ”‚   โ””โ”€โ”€ settings.json            # Bundled default settings template
โ”œโ”€โ”€ scripts/
โ”‚   โ”œโ”€โ”€ generate_icon.py         # Draws ghost icon at 16/32/48/64/128/256px
โ”‚   โ”œโ”€โ”€ install.sh               # Autostart + shortcut + CLI symlinker
โ”‚   โ”œโ”€โ”€ setup_shortcuts.py       # Desktop shortcut configurator (GNOME/XFCE)
โ”‚   โ”œโ”€โ”€ build_appimage.sh        # AppImage builder
โ”‚   โ””โ”€โ”€ setup_autostart.py       # Standalone Python autostart installer
โ”œโ”€โ”€ tests/
โ”‚   โ”œโ”€โ”€ test_api.py              # REST API & Sync tests
โ”‚   โ”œโ”€โ”€ test_autostart.py        # Autostart manager tests
โ”‚   โ”œโ”€โ”€ test_eclipse.py          # Encryption & Security tests
โ”‚   โ”œโ”€โ”€ test_ipc_spotlight.py    # IPC, Spotlight & Shortcuts tests (220 total passed)
โ”‚   โ”œโ”€โ”€ test_media.py            # Media detection tests
โ”‚   โ”œโ”€โ”€ test_runtime_dir.py      # Runtime directory tests
โ”‚   โ””โ”€โ”€ test_storage.py          # Database CRUD tests
โ”œโ”€โ”€ roadmap(v1.x).md
โ”œโ”€โ”€ CHANGELOG.md
โ”œโ”€โ”€ requirements.txt
โ”œโ”€โ”€ pytest.ini
โ””โ”€โ”€ .gitignore

Requirements

DependencyVersion
Python3.11+
PyQt66.6.0+
Pillow10.0.0+
cryptography41.0.0+
pytest7.0.0+

๐Ÿ“ฅ Download

  • ๐Ÿง AppImage โ€” Portable Linux build
  • ๐Ÿ“ฆ DEB โ€” Debian / Ubuntu / Kali
  • ๐Ÿ“ฆ Arch package โ€” .pkg.tar.zst
  • ๐Ÿ—œ๏ธ Portable tarball โ€” Extract & run anywhere

Installation

Option A โ€” System Python (Kali Linux)

PyQt6 and Pillow are usually pre-installed on Kali:

BASH
git clone https://github.com/kareem2099/DotGhostBoard.git
cd DotGhostBoard
python3 main.py

Option B โ€” Virtual Environment (Recommended)

BASH
git clone https://github.com/kareem2099/DotGhostBoard.git
cd DotGhostBoard

# Create isolated environment
python3 -m venv venv --system-site-packages
source venv/bin/activate

# Install dependencies
pip install -r requirements.txt

# Generate app icon (run once)
python3 scripts/generate_icon.py

# Run
python3 main.py

Option C โ€” pip install (PyPI)

Note: PyPI package publication is planned; use DEB, AppImage, or Git clone for v1.5.7.

BASH
# Planned for PyPI release
pip install dotghostboard
dotghostboard

Option D โ€” AppImage (Portable)

Download the .AppImage from Releases, then:

BASH
chmod +x DotGhostBoard-*.AppImage
./DotGhostBoard-*.AppImage

No installation required. Runs on compatible 64-bit Linux distributions.

Option E โ€” Full install (autostart + shortcut + icon)

BASH
chmod +x scripts/install.sh
./scripts/install.sh

This configures autostart, the desktop launcher, CLI companion, and global shortcuts on supported GNOME/XFCE desktops:

  • Ctrl+Alt+V โ€” Toggle Dashboard
  • Ctrl+Alt+Space โ€” Spotlight Quick Search

Option F โ€” Build AppImage from source

BASH
pip install pyinstaller
chmod +x scripts/build_appimage.sh
./scripts/build_appimage.sh

Option G โ€” DEB Package (Debian/Ubuntu/Kali)

Quick install from Releases:

BASH
# Download the latest .deb from GitHub Releases
wget https://github.com/kareem2099/DotGhostBoard/releases/latest/download/dotghostboard_1.5.7_amd64.deb

# Install via apt
sudo apt install ./dotghostboard_1.5.7_amd64.deb

# Run
dotghostboard

Or build locally:

BASH
# Clone and build
git clone https://github.com/kareem2099/DotGhostBoard.git
cd DotGhostBoard

# Build the .deb package
chmod +x scripts/build_deb.sh
./scripts/build_deb.sh

# Install
sudo dpkg -i dotghostboard_*.deb

# Run
dotghostboard

Uninstall:

BASH
sudo apt remove dotghostboard

Installed locations:

  • Binary: /opt/dotghostboard/
  • Launcher: /usr/bin/dotghostboard
  • Desktop entry: /usr/share/applications/dotghostboard.desktop
  • Icon: /usr/share/icons/hicolor/256x256/apps/dotghostboard.png

Usage

ActionHow
Copy anythingJust use Ctrl+C anywhere โ€” DotGhostBoard captures it automatically
Toggle windowPress Ctrl+Alt+V from anywhere to show or hide the dashboard
Spotlight searchPress Ctrl+Alt+Space from anywhere for instant floating quick search
Focus searchPress Ctrl+F inside the dashboard to search history
Pin an itemClick ๐Ÿ“Œ on any card
Unpin an itemClick ๐Ÿ“ on a pinned card
Copy backClick โŽ˜ on any card โ€” or double-click the card
Delete an itemClick โœ• โ€” pinned items are protected
Keyboard navigationPress โ†‘ / โ†“ to move focus; Enter or Space to copy; Esc to clear
Clear historyClick "Clear History" โ€” pinned items are never deleted
SettingsClick โš™ in the top bar โ€” adjust history limit, global shortcuts, privacy
MinimizeClick X โ€” the app stays alive in the system tray
QuitRight-click the tray icon โ†’ Quit

๐Ÿ›ก๏ธ The Vault & Encrypted Backups (.vault)

The Vault (Ctrl+Shift+V) is a physically isolated, encrypted credential storage engine (vault.db).

  • Envelope Encryption: Secrets are encrypted with a per-database Data Encryption Key (DEK), wrapped with a domain-separated Key Encryption Key (KEK) derived from your Master Password via HKDF-SHA256.
  • Streamlined Two-Row Drawer: Slide-out drawer with dedicated title/badge status row and independent action toolbar (+ Add Secret, Lock/Unlock, Export, Import, Tips).
  • Empty State Onboarding: Informative tips card explaining quick shortcuts (Ctrl+Shift+V), 30-second clipboard scrubbing, 3-version history, and expiration monitoring.
  • Encrypted Export (.vault): Clicking ๐Ÿ“ค Export packages all secrets, 3-version password histories, categories, timestamps, and expiration dates into a standalone binary file.
    • Cipher: AES-256-GCM (authenticated encryption with 96-bit random nonce and 128-bit authentication tag).
    • Key Derivation: PBKDF2-HMAC-SHA256 with 100,000 rounds and an independent, per-backup 16-byte random salt.
    • Zero Plaintext: Absolutely zero unencrypted text is written to disk. The resulting .vault package is safe to store in the cloud, on USB drives, or transfer across systems.
    • Passphrase Security: Protected by an independent passphrase chosen at export. Passphrases are never stored; backups cannot be decrypted if the passphrase is forgotten.
  • Authenticated Import: Clicking ๐Ÿ“ฅ Import prompts for the backup passphrase, verifies the package's cryptographic integrity tag, and imports secrets into your Vault while automatically skipping exact duplicates.

Window Manager & Multi-Workspace Compatibility

DotGhostBoard automatically adheres to the Extended Window Manager Hints (EWMH) specification under X11. When invoked via global shortcut (Ctrl+Alt+V) or Spotlight (Ctrl+Alt+Space) on another virtual desktop or workspace, the window and modal dialogs seamlessly migrate to your active workspace (verified against Qtile and Openbox; should work on any EWMH-compliant tiling WM such as i3 or bspwm, but not yet independently tested on those).

Environment Variables

VariableDefaultDescription
DOTGHOST_HOME~/.config/dotghostboardOverride the custom configuration and database directory.
DOTGHOST_NO_EWMH0Set to 1 to disable EWMH workspace migration and leave window placement strictly to your window manager's default placement rules.

Running Tests

BASH
python3 -m pytest

Expected output:

CODE
tests/test_api.py .....                                                  [  1%]
tests/test_autostart.py .................                                [  3%]
tests/test_auto_tagger.py ...........                                    [  5%]
tests/test_eclipse.py .................................                  [ 11%]
tests/test_ipc_spotlight.py ..........                                   [ 13%]
tests/test_media.py ...........................                          [ 19%]
tests/test_password_generator.py ......                                  [ 20%]
tests/test_storage.py ................................                   [ 26%]
tests/test_vault.py ........                                             [ 27%]
tests/test_vault_history.py .....                                        [ 28%]
tests/test_vault_ui.py ................................................. [ 38%]
tests/test_watcher_backend_integration.py .......                        [ 40%]
tests/test_window_manager.py ...................                          [ 44%]
....                                                                     [ 96%]
tests/test_updater_core.py .................................             [100%]

511 passed
Tests OutputTests Output

Roadmap

VersionCodenameStatusGoal
v1.0.0Ghostโœ… ReleasedStable base โ€” clipboard, pin system, dark UI, SQLite
v1.1.0Phantomโœ… ReleasedSettings panel, keyboard nav, double-click paste, SVG icon
v1.2.0Specterโœ… ReleasedImage thumbnails, video preview via ffmpeg, auto-cleanup, image viewer
v1.3.0Wraithโœ… ReleasedTags, collections, multi-select, bulk actions, export
v1.4.0Eclipseโœ… ReleasedAES-256 encryption, master lock, stealth mode, pro UI
v1.4.1Mem & Perfโœ… ReleasedMemory optimizations, GitHub auto-updater, IPC/Wayland bug fixes
v1.5.0Nexusโœ… ReleasedE2EE Network Sync, mDNS Discovery, REST API, CLI Companion
v1.5.1Nexus Hotfix Iโœ… ReleasedUpdate pipeline security, self-cleanup install script
v1.5.2Nexus Hotfix IIโœ… ReleasedAura Check easter egg, Pigeon Doctor purge screen, migration fix
v1.5.3Nexus Hotfix IIIโœ… ReleasedFix blank/white window in deb & AppImage (PyInstaller resource path)
v1.5.4Nexus Hotfix IVโœ… ReleasedClipboard capture reliability fix (3-layer bug); Copy Count Badge; Auto-Pin Suggestion
v1.5.5Nexus Polish & Spotlightโœ… ReleasedSpotlight quick search overlay, relative time, copy count reset, image deduplication, search debounce
v1.5.6Nexus Global Hotkeys & UI Polishโœ… ReleasedPer-user Global Desktop Shortcuts (GNOME/XFCE), decoupled Spotlight, Eclipse lock protection, UI theme polish, 220 tests
v1.5.7Nexus Hotfix Vโœ… ReleasedCI headless stability, packaging Python dependencies, CLI enhancements, 220 tests
v1.6.0Phantomโœ… Releasedv2.x Architecture Foundation: Controllers, Services, Repositories, Pipeline (306 tests)
v2.0.0Cerberusโœ… ReleasedThe Vault UI, Zero-Log Secret Detector, FreeDesktop Notifications, 2.0.0 Icon Architecture (470 tests)
v2.0.1Cerberusโœ… ReleasedTiling Window Manager EWMH Migration (Qtile/Openbox), Workspace Toggle Fix, Vault & Notification Hardening (489 tests)
v2.1.0Leviathanโœ… ReleasedSmart Auto-Tagging, Contextual Card Actions, Vault Generator, Password History, Vault Export/Import, Secret Expiry, Vault Sweep, Auto-Purge (522 tests)

Full details in roadmap(v2.x).md


Acknowledgments

Special thanks to @knodalyte for reporting GitHub Issue #1 ("[BUG] does not behave well under tiling window manager") and providing valuable diagnostic feedback that enabled native EWMH cross-workspace migration.


Contributing

Contributions are welcome. Please read CONTRIBUTING.md before submitting a pull request.


License

Apache 2.0 โ€” see LICENSE for details.


Part of DotSuite

DotGhostBoard is one tool in the DotSuite collection โ€” a set of lightweight, privacy-focused productivity tools built for Linux power users.

DotEnv ยท DotCommand ยท DotSense ยท DotFetch ยท DotShare ยท DotScramble ยท DotGhostBoard


Built with ๐Ÿ’€ on Kali Linux

Related Products

โ€Œ
โ€Œ
โ€Œ
โ€Œ
โ€Œ
โ€Œ
โ€Œ
โ€Œ
โ€Œ
โ€Œ
โ€Œ
โ€Œ
โ€Œ
โ€Œ
โ€Œ
โ€Œ
โ€Œ
โ€Œ
โ€Œ
โ€Œ
โ€Œ
DotGhostBoard โ€” Python Tool | dotsuite