Security
Your configuration can hold things you'd rather others didn't read: text that actions type, paths, script code. A password encrypts the files that hold them, so someone who copies or opens the files sees nothing useful without the password.
Protection is a deterrent against casual reading, not a vault: while Input.Observer runs, it has your configuration open, and anything an action does is visible on screen as usual.
There is no way to recover a forgotten password. Nobody, including you and the makers of Input.Observer, can decrypt a protected file without it. Read If you forget the password before you set one.
Changes on the Security page take effect at once. They don't wait for Apply, and Discard doesn't undo them.
What the password protects
One password protects three files, all kept together in your configuration folder (The configuration file):
| File | Holds |
|---|---|
| Configuration (config.toml) | Everything you set up: groups, actions, gestures, settings |
| License (license.dat) | Your license email and key |
| Console (console.toml) | The console's script editor text and window position |
All three are protected or none is; there is no password per file. A file that doesn't exist yet (for example, the license file before you activate a license) is protected as soon as it is created.
These are not protected:
- which gesture profile is active;
- values scripts store between runs (the
Storagebuiltins); - macro recordings, in the
Recordingsfolder; - plugin settings, such as the Styles plugin's settings file, and style purchase files;
- exported files: an export is always plain text, and the export dialog warns you when your configuration is protected (Import and export).
When you turn protection on, the plain-text backups of your configuration in its Backup folder are deleted, so
an older copy can't give away what you just protected. Backups made from then on are encrypted
(Backups).
The Security page
Protection status shows each file as Password protected, Not protected, or Not created yet.
Setting a password
- On the Security page, choose Set password… ①.
- Type the password in New password and again in Confirm password, and choose OK.
The three files are encrypted at once. The tray menu's Set Password... does the same.
Changing or removing the password
Once a password is set, the button reads Change or remove password… (the tray menu's item reads Change Password...).
- To change it, type the current password, then the new one twice.
- To remove protection, type the current password and leave New password ① and Confirm password blank. All three files are decrypted.
If the current password is wrong, nothing is changed and the page says so.
When you are asked for the password
- Every time Input.Observer starts. It can't read your configuration without it. Cancelling closes Input.Observer.
- When you open the configuration window, unless the password is still remembered (below).
- When you open the console, unless it is still remembered.
- When something saves a protected file and the password isn't remembered, for example the tray menu's Global Actions switch.
Remember password for
Remember password for ② sets how long a correctly typed password is remembered, so you aren't asked several times in a row — at startup, for example, the configuration, the license and the console settings may all need it within seconds.
| Setting | Default | Range |
|---|---|---|
| Remember password for | 60 s | 0–300 s; 0 asks every time |
While the configuration window or the console is open, the remembered password doesn't run out; the time starts again when you close the window. A remembered password is held encrypted in memory and is always checked against the file again before it is used.
Changing this setting while your configuration is protected saves the configuration, which needs the password. If none is at hand, the page says so: open Change or remove password… once to confirm the password, then try again.
When the files don't match
If some of the three files are protected and others aren't (for example, a file was restored from an old copy), the Security page shows "Your protected files are not all in the same state", with Protect all three… and Remove protection from all three…. Input.Observer also asks at every start until it is fixed, with three choices: Encrypt all three files (recommended), Remove protection from all three files, or Leave the files as they are.
If you forget the password
There is no reset and no recovery code. What you can do depends on the file:
- Configuration. After three wrong passwords at startup (or when opening the console), Input.Observer offers
Browse for a configuration file, Start fresh with a new default configuration or Close
Input.Observer (Recovery). Browsing or starting fresh renames the protected file
aside, still encrypted, rather than deleting it, so it can still be opened if you remember the password later.
An exported file you kept is plain text and can be imported into the fresh configuration
(Import and export). Backups in the
Backupfolder are encrypted with the password that was in use when each was made. - License. If you cancel the license password prompt at startup, Input.Observer says it can't read your license file and then asks you to activate, as if no license were there. Enter your license email and key again (About and license).
- Console. The console won't open without the password. Its file only holds the console's script editor text
and window position; deleting
console.tomlfrom your configuration folder lets the console open again, empty. If Input.Observer then reports that the protected files aren't all in the same state, choose to protect all three.