# Relicario Roadmap > Living document — update alongside `STATUS.md` when milestones shift. > "Up next" items have specs; "Medium-term" items may have specs; "Long-term" items are direction, not committed scope. ## Shipped | Version | Highlights | |---|---| | v0.5.0 (2026-05-02) | Security audit fixes, device auth, backup/restore, LastPass import, fullscreen UX phases 1+2A | See `CHANGELOG.md` for full details. ## Up next (v0.5.x) These are specced and either in progress or immediately queued: - **Vault lock screen + container polish** — logo on lock screen, max-width viewport constraint *(in progress)* - **Phase 2B: form layout** — spacing, section headers, attachment previews in detail pane Spec: `docs/superpowers/specs/2026-05-02-phase-2b-form-layout-design.md` - **1C-γ: attachments + Document type** — attachment UI in popup + vault tab; Document item add/view/edit/extract Specs: `docs/superpowers/specs/2026-04-24-relicario-extension-1c-gamma1-design.md`, `docs/superpowers/specs/2026-04-26-relicario-extension-1c-gamma2-design.md` - **v0.5.x UX polish** — recovery QR display in extension, password coloring refinements Spec: `docs/superpowers/specs/2026-05-03-v0.5.x-ux-polish-and-recovery-qr-design.md` ## Medium-term - **Phase 3: vault-tab shell** — fullscreen sidebar with nav sections, pane routing Spec: `docs/superpowers/specs/2026-04-27-relicario-vault-tab-design.md` - **Phase 4: command palette** — ⌘K global search + action dispatch across the vault tab - **Trash & history UI** — trash view, item history viewer, field-history viewer - **Device manager UI** — device registration + revocation in vault tab - **CLI restructure** — subcommand reorganisation, interactive TUI mode Spec: `docs/superpowers/specs/2026-05-04-cli-restructure-design.md` - **Extension restructure** — bundle / message-routing cleanup Spec: `docs/superpowers/specs/2026-05-04-extension-restructure-design.md` - **Security polish** — `docs/superpowers/specs/2026-05-04-security-polish-design.md` ## Long-term / backlog - **Relay server** — encrypted WebSocket relay for multi-device sync without a shared git server Spec: `docs/superpowers/specs/2026-05-02-relay-server-design.md` - **Recovery QR** — QR code encoding of the reference-image secret for printed cold backup Spec: `docs/superpowers/specs/2026-05-01-recovery-qr-design.md` - **Mobile** — Rust core compiles to ARM; JNI wrapper for Android, Swift wrapper for iOS - **Credential capture** — extension content-script form detection + autofill Spec: `docs/superpowers/specs/2026-04-12-relicario-credential-capture-design.md` ## Non-goals (explicitly deferred or cancelled) - **Reference-image rotation** — changing the image factor without re-embedding. Back-burner, not cancelled. - **Per-entry subkeys** — no real-world benefit at family-vault scale; see design rationale in `docs/ARCHITECTURE.md`. - **libgit2 / gitoxide** — shell-out to `git` is intentional; see `crates/relicario-cli/ARCHITECTURE.md`.