Puranjay Savar Mattas 20baab78c0 feat(outlinekit): encrypt the offline cache at rest
Both CachedPayload and PendingOperation only ever stored their
payload as plain JSON on disk (SwiftData/SQLite, no encryption of its
own) - readable by anyone with access to the logged-in session, per
the earlier discussion on where this cache lives. Adds AES-GCM
encryption at the one place raw bytes cross into/out of
OfflineCacheStore (CachingOutlineAPIClient, which already owns
encode/decode) - OfflineCacheStore itself stays a dumb opaque-blob
store, since its key/id/kind columns can't be encrypted without
breaking the #Predicate queries built against them.

Key management (KeychainCacheEncryptionKeyStore, mirrors
KeychainTokenStore exactly): a random 256-bit key, generated once and
Keychain-stored, not derived from anything guessable. It doesn't need
deriving to survive an uninstall/reinstall either - Keychain items
are scoped to the app's code signature, not its on-disk presence, so
a reinstall of the same app regains access to the same key
automatically (same reason a saved API token already survives a
reinstall today). If the on-disk cache also happens to survive
(dragging the .app to the Trash doesn't clean ~/Library/Containers),
a reinstall can still read it.

A row written before this shipped (still plaintext) or encrypted
under a since-cleared key just fails to decrypt and is treated as a
cache miss - same as any other decode failure, so it silently
refetches and re-caches encrypted rather than crashing. No explicit
migration needed.

Also: OfflineCacheStore.clearEverything() wipes both the cache AND
the pending write queue (clearAll(), used by Settings' "Clear All
Cache", still only touches the cache - it shouldn't silently discard
someone's unsynced edits). Exposed as
CachingOutlineAPIClient.clearEverythingForSignOut(), for sign-out to
use alongside clearing the key.

CacheEncryptionKeyStoring is a protocol (like TokenStoring) so tests
never touch the real Keychain - existing CachingOutlineAPIClientTests
now inject an in-memory StaticCacheEncryptionKeyStore. 8 new tests
(retry/failure-log tests from the previous commit plus 3 new ones
here: ciphertext isn't plaintext JSON, a cleared key makes old rows
unreadable, clearEverythingForSignOut wipes both tables). 95/95
passing.
2026-08-21 01:15:15 +01:00
2026-08-12 18:48:19 +01:00
2026-08-12 18:48:19 +01:00
2026-08-12 19:08:30 +01:00

Outpost logo

Outpost

Download on TestFlight

A native Apple ecosystem client for Outline — built for iOS, iPadOS, and macOS from a single SwiftUI codebase, aiming for full editing parity with Outline's web app, including realtime collaborative editing.

Early alpha — macOS only for now. Expect missing features and rough edges. iOS/iPadOS support is planned but not in the current build. See the releases page for changelogs, and open an issue if you hit anything.

Why

Outline's web app is great, but there's no native Apple client with full editing parity. This project connects to a self-hosted Outline instance over its REST API and realtime collaboration socket to provide a proper native experience across the Apple ecosystem.

Requirements

  • Xcode 27+ (currently developed against an Xcode 27 beta — this is a hard minimum, not a suggestion)
  • macOS 27+. iOS/iPadOS support is planned but not in the current build (see the alpha note above) — same 27+ minimum will apply once it lands
  • A self-hosted (or hosted) Outline instance with API access

Setup

  1. Clone the repo and open the .xcodeproj in Xcode.
  2. Generate a scoped API key on your Outline instance (Settings → API Keys).
  3. On first launch, enter your instance URL and API key — these are stored in Keychain, never in app config or source.

Architecture

See CLAUDE.md and docs/ARCHITECTURE.md for the full technical breakdown: REST layer, Yjs/Hocuspocus realtime sync via YSwift, and the ProseMirror-schema-to-native-editor mapping.

Disclaimer

This project is being built to solve a personal problem — I wanted a genuinely good native knowledge-base client for my own self-hosted Outline instance and none of the existing options fit. It's a personal-use tool first, not a polished product with support guarantees.

Parts of this codebase are AI-assisted (built with the help of AI coding tools). Treat that however you like — review, use, fork, or ignore the code accordingly. No warranty of quality, security, or fitness for any particular use is implied beyond what's stated in the license below.

License

Outpost itself is licensed under the Business Source License 1.1 — the same license family Outline's own server uses, for the same reason. In short: free to read, self-host, and modify for personal or non-commercial use; not free to repackage as a competing hosted product or to distribute under a name/branding that claims official or affiliated status. It converts automatically to Apache License 2.0 on the change date stated in LICENSE. "Outpost" and its logo are trademarks of the project — see the license's trademark notice.

This project is a client only — it does not include, vendor, or redistribute any of Outline's own (also BSL 1.1 licensed) server source.

Credits

The native markdown editor is built on swift-markdown-engine by Luca Chen, licensed under Apache License 2.0. It's vendored directly in Vendor/swift-markdown-engine (see its LICENSE); local fixes made in that copy haven't been upstreamed yet.

Privacy

Outpost collects nothing about you — no analytics, no telemetry, no crash reporting of its own, no age or demographic data, nothing. The only thing stored locally is your Outline server URL and API token (in the device Keychain) and, optionally, a local offline cache of what you've viewed. Everything else goes straight from your device to whatever Outline server you configure — there's no backend in between, and the developer has no access to your data or your server.

Full policy, terms of service, and data-processing statement are on the wiki:

Not affiliated with Outline

This is an independent, unofficial client. Not affiliated with or endorsed by General Outline, Inc.

S
Description
Native Apple ecosystem client for a self-hosted Outline instance
Readme
8.2 MiB
Languages
Swift 99.2%
Shell 0.8%