You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Encly is the successor of My Notes. My Notes will get a page that introduces Encly and hands all its data over in one tap. This issue is the Encly side: receive that hand-off and import it into the vault.
One way only. My Notes → Encly. Encly never exports to or accepts requests from My Notes; it exposes no provider and nothing readable.
Counterpart: pasichDev/MyNotes#167. This one ships first: My Notes can only offer the button once an Encly release can receive.
Hand-off contract (shared with My Notes)
My Notes starts com.pasich.encly.action.IMPORT_FROM_MY_NOTES with an explicit package, startActivityForResult, and a content:// URI from its own FileProvider with FLAG_GRANT_READ_URI_PERMISSION.
The URI is a ZIP with handoff.json (format mynotes-handoff, schema: 1); attachment files are not sent. It carries raw My Notes data and Encly does the mapping, so the Encly block format stays private to Encly.
handoff.json: notes (incl. trashed), tags, tasks and task categories. Each record has a stable id (My Notes sync_metadata.stableId, or mynotes:<type>:<id> when missing), so a second hand-off adds nothing twice.
Result: RESULT_OK with counts (notes, tasks, tags, skipped) or RESULT_CANCELED with a reason code.
Encly side
Exported ImportFromMyNotesActivity for that action only.
Trust check before reading anything: getCallingPackage() == "com.pasich.mynotes"andPackageManager.hasSigningCertificate(…, CERT_INPUT_SHA256) against the pinned My Notes Play signing certificate. <queries><package android:name="com.pasich.mynotes" /></queries>. Anything else is refused without reading the URI.
Vault must be unlocked (normal PIN / biometric flow); then a preview: N notes, M tasks, K tags, what will not come over. Import only after the user confirms.
Encly is the successor of My Notes. My Notes will get a page that introduces Encly and hands all its data over in one tap. This issue is the Encly side: receive that hand-off and import it into the vault.
One way only. My Notes → Encly. Encly never exports to or accepts requests from My Notes; it exposes no provider and nothing readable.
Counterpart: pasichDev/MyNotes#167. This one ships first: My Notes can only offer the button once an Encly release can receive.
Hand-off contract (shared with My Notes)
com.pasich.encly.action.IMPORT_FROM_MY_NOTESwith an explicit package,startActivityForResult, and acontent://URI from its own FileProvider withFLAG_GRANT_READ_URI_PERMISSION.handoff.json(formatmynotes-handoff,schema: 1); attachment files are not sent. It carries raw My Notes data and Encly does the mapping, so the Encly block format stays private to Encly.handoff.json: notes (incl. trashed), tags, tasks and task categories. Each record has a stable id (My Notessync_metadata.stableId, ormynotes:<type>:<id>when missing), so a second hand-off adds nothing twice.RESULT_OKwith counts (notes,tasks,tags,skipped) orRESULT_CANCELEDwith a reason code.Encly side
Exported
ImportFromMyNotesActivityfor that action only.Trust check before reading anything:
getCallingPackage() == "com.pasich.mynotes"andPackageManager.hasSigningCertificate(…, CERT_INPUT_SHA256)against the pinned My Notes Play signing certificate.<queries><package android:name="com.pasich.mynotes" /></queries>. Anything else is refused without reading the URI.Vault must be unlocked (normal PIN / biometric flow); then a preview: N notes, M tasks, K tags, what will not come over. Import only after the user confirms.
Strict parsing with size limits (total bytes, records, note length); unknown
schema→ "update Encly".Mapping into the existing
BackupImporterMERGE path (one transaction, uid-based skip):valueJsonempty) → one TEXT block per paragraphparagraph→ TEXT,Headers/headerlevel 1–4 → H1–H4,listunordered/ordered → LIST_BULLET/LIST_NUMBER (nested items flattened),checklist→ LIST_CHECK,delimiter→ SEPARATOR,spacerdropped<b>,<mark>,<code>,<br>, entities) → plain text; no raw HTML reaches the vaultimage/attaches: not imported; the preview says how many attachments stay in My NotesResult screen +
setResultcounts; the temporary copy is wiped.Tests: mapper per block type, malformed/oversized input, wrong caller, wrong certificate, repeat hand-off imports nothing.
Strings in all 9 locales; CHANGELOG; PRIVACY.md (data arrives on## Decided
Attachments and images are not imported (Encly has no attachment blocks); the preview and the result show how many were skipped.
Later