Commands for the web client to keep a copy of the login tokens in the OS
keychain: secure_session_supported / _set / _get / _clear.
- Windows: Credential Manager via the keyring crate (3.6, windows-native),
entry "session" in service "Lotus Chat". Only the secrets are stored
(userId, deviceId, accessToken, refreshToken); the serialized value is
capped at 1200 chars (Windows' limit is 2560 bytes).
- Other platforms: supported = false and the other commands answer "not
supported on this platform" (Linux Secret Service can prompt to unlock a
wallet at startup; that needs its own testing). No new Linux dependency:
without a platform feature the crate only has its mock store.
- Keychain calls run on the blocking pool, off the main thread.
Step 1 is a mirror only (the web client still reads its session from
localStorage); see the cinny PR.
Tests: round trip + clear, clearing an empty keychain, incomplete and
oversized sessions rejected with nothing written, the JSON shape the web
client sends, a realistic OIDC session fits (keyring's mock store). Linux
release build: commands answer as designed and login is unaffected.
Windows: type-checked only.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA