- totp.js: add validateTotpSecret(input, { minBytes = 10 }). Secret is
optional (blank ok); when provided it must decode to a base32 key of at
least 80 bits, rejecting bad characters, typos, wrong format, and
too-short secrets.
- EntryForm: validate the TOTP secret on submit; if invalid, show an inline
error (⚠) and a red input border and block saving. Error clears as the
user types.
- Tests: blank ok, valid bare/grouped/otpauth URIs, invalid chars, too-short,
URI without a secret. 163 total pass.
- New src/lib/crypto/totp.js: native RFC 6238 TOTP using Web Crypto HMAC-SHA1
(no external crypto). base32Decode, extractSecret (bare base32 or otpauth://
URI), generateTotp, totpRemainingSeconds.
- Entries gain an optional encryptedTotpSecret, stored AES-GCM-encrypted like
passwords. schema.js createEntry/updateEntry/docs updated.
- Export/import re-key the TOTP secret alongside passwords when sealing with a
separate password, and decrypt/re-encrypt on import so TOTP survives moves.
- EntryForm: optional 'TOTP Secret (2FA)' field (base32 or otpauth:// URI).
- EntryDetail: live 6-digit TOTP display updating every second with a countdown
and urgency indicator, plus copy; guarded cleanup timer on unmount.
- Tests: RFC 6238 SHA-1 vectors (6 & 8 digit), base32/extractSecret, remaining
seconds, schema round-trip. 157 total pass.