Files
cinny-desktop/src-tauri/Cargo.toml
T
Lotus CIandClaude Opus 5.5 032b6e04e7 feat: secure_session commands, login tokens in the OS keychain (cinny #105, step 1)
Commands for the web client to keep a copy of the login tokens in the OS
keychain: secure_session_supported / _set / _get / _clear.

- Windows: Credential Manager via the keyring crate (3.6, windows-native),
  entry "session" in service "Lotus Chat". Only the secrets are stored
  (userId, deviceId, accessToken, refreshToken); the serialized value is
  capped at 1200 chars (Windows' limit is 2560 bytes).
- Other platforms: supported = false and the other commands answer "not
  supported on this platform" (Linux Secret Service can prompt to unlock a
  wallet at startup; that needs its own testing). No new Linux dependency:
  without a platform feature the crate only has its mock store.
- Keychain calls run on the blocking pool, off the main thread.

Step 1 is a mirror only (the web client still reads its session from
localStorage); see the cinny PR.

Tests: round trip + clear, clearing an empty keychain, incomplete and
oversized sessions rejected with nothing written, the JSON shape the web
client sends, a realistic OIDC session fits (keyring's mock store). Linux
release build: commands answer as designed and login is unaffected.
Windows: type-checked only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
2026-09-29 00:25:01 -04:00

86 lines
3.4 KiB
TOML

# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
[package]
name = "cinny"
version = "4.12.2" # CI patches src-tauri/tauri.conf.json at build time; that file is the source of truth for the shipped version.
description = "Yet another matrix client"
authors = ["Ajay Bura"]
license = "AGPL-3.0-only"
repository = "https://github.com/cinnyapp/cinny-desktop"
default-run = "cinny"
edition = "2021"
rust-version = "1.77.2"
[build-dependencies]
tauri-build = { version = "2", features = [] }
[dependencies]
serde_json = "1.0.109"
serde = { version = "1.0.193", features = ["derive"] }
tauri = { version = "2", features = ["devtools", "wry", "tray-icon", "image-png"] }
tauri-plugin-localhost = "2"
tauri-plugin-window-state = "2"
tauri-plugin-notification = "2"
tauri-plugin-opener = "2"
tauri-plugin-deep-link = "2"
[features]
# by default Tauri runs in production mode
# when `tauri dev` runs it is executed with `cargo run --no-default-features` if `devPath` is an URL
default = [ "custom-protocol" ]
# this feature is used used for production builds where `devPath` points to the filesystem
# DO NOT remove this
custom-protocol = [ "tauri/custom-protocol" ]
[target.'cfg(not(any(target_os = "android", target_os = "ios")))'.dependencies]
tauri-plugin-updater = "2"
tauri-plugin-single-instance = "2"
tauri-plugin-autostart = "2" # P6-1 launch-on-login
# Update retry backoff (already in the tree via tauri; adds only the timer).
tokio = { version = "1", features = ["time"] }
# cinny #105: login tokens in the OS keychain. Without a platform feature
# the crate only has its in-memory mock store (used by the tests); Windows
# turns on Credential Manager below.
keyring = "3.6"
[target.'cfg(target_os = "linux")'.dependencies]
# P6-1 desktop parity: screensaver inhibit (no-sleep in calls) + Unity launcher
# badge, both via the session D-Bus. zbus 5.x ships the blocking API under the
# default `blocking-api` feature and the default `async-io` runtime, so plain
# default features suffice (no tokio integration needed here).
zbus = "5"
# Same version wry/tauri already pull in transitively (see Cargo.lock) — pinning
# it directly lets us reach WebKitSettings/permission APIs wry doesn't expose.
webkit2gtk = "2.0"
[target.'cfg(target_os = "windows")'.dependencies]
keyring = { version = "3.6", features = ["windows-native"] }
webview2-com = "0.38"
window-vibrancy = "0.6"
windows = { version = "0.61", features = [
# WinRT namespaces
"Data_Xml_Dom", # P5-41 toast XML
"Foundation",
"Foundation_Collections", # P5-41 toast UserInput IMap
"Media",
"UI_Notifications", # P5-41 WinRT toast notifications
# Win32 namespaces
"Win32_Foundation",
"Win32_Storage_EnhancedStorage", # P5-36 jump list (PKEY_Title)
"Win32_Graphics_Gdi",
"Win32_Networking_NetworkListManager", # P5-49 network awareness
"Win32_System_Com",
"Win32_System_Com_StructuredStorage", # P5-36 jump list (PROPVARIANT)
"Win32_System_Power", # P5-46 no-sleep
"Win32_System_WinRT", # P5-43 SMTC interop
"Win32_UI_Input_KeyboardAndMouse", # cinny-desktop #2 global PTT/deafen poll
"Win32_UI_Shell",
"Win32_UI_Shell_Common", # P5-36 jump list (IObjectArray/IObjectCollection)
"Win32_UI_Shell_PropertiesSystem", # P5-36 jump list (IPropertyStore/PKEY_Title)
"Win32_UI_WindowsAndMessaging",
] }
[lib]
name = "app_lib"
crate-type = ["staticlib", "cdylib", "rlib"]