fix(privacy): wipe plaintext/PII localStorage caches on logout (SEC-1/2)
Several localStorage caches held decrypted message content or user PII and survived a normal logout, leaving residue on a shared device (the search index was already wiped; these were not): - cinny_scheduled_messages_v1 - decrypted IContent.body of pending sends - cinny_recent_searches_v1 - search query text - cinny_recent_forward_targets_v1 - recent forward contact/room graph - cinny_recent_gifs_v1 / cinny_recent_stickers_v1 - media the user sent - navToActivePath<userId> - per-space last-visited room paths - (plus the translation cache added earlier) Add a clear function per module and a single auditable clearPlaintextCaches() aggregator, called from both logout paths (logoutClient + the server-forced SessionLoggedOut handler) alongside the existing session/search-index wipes. Unit-tested. Deliberately NOT cleared (documented in the aggregator): unsent composer drafts and the presence status message (preserved by product decision N98); SDK sync/crypto store + io.lotus.* account data (reminders/bookmarks/notes), already wiped by mx.clearStores(); low-sensitivity UI/metadata residue. The forward-targets/gifs/stickers/nav-path additions and the accurate "not covered" documentation address findings from two review passes. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,43 @@
|
||||
import { clearTranslationCache } from './translation';
|
||||
import { clearScheduledMessages } from './scheduledMessages';
|
||||
import { clearRecentSearches } from './recentSearches';
|
||||
import { clearRecentForwardTargets } from './recentForwardTargets';
|
||||
import { clearRecentGifs } from './recentGifs';
|
||||
import { clearRecentStickers } from './recentStickers';
|
||||
import { clearNavToActivePathStore } from './navToActivePath';
|
||||
|
||||
/**
|
||||
* Single auditable place that wipes the `localStorage` caches holding decrypted
|
||||
* message content, sent media, or a user's messaging/nav activity. Called on
|
||||
* logout so this residue can't survive on a shared device.
|
||||
*
|
||||
* Swept here:
|
||||
* - `cinny_translation_cache_v1` — decrypted translated message text
|
||||
* - `cinny_scheduled_messages_v1` — decrypted `IContent.body` of pending sends
|
||||
* - `cinny_recent_searches_v1` — search query text (PII)
|
||||
* - `cinny_recent_forward_targets_v1` — recent forward contact/room graph (PII)
|
||||
* - `cinny_recent_gifs_v1` / `cinny_recent_stickers_v1` — media the user sent
|
||||
* - `navToActivePath<userId>` — per-space last-visited room paths (needs userId)
|
||||
*
|
||||
* NOT swept here (by design):
|
||||
* - session credential keys → `removeFallbackSession()`
|
||||
* - the SDK sync/crypto store + all `io.lotus.*` account data (reminders,
|
||||
* bookmarks, user notes, status presets — themselves plaintext) → wiped by
|
||||
* `mx.clearStores()` on both logout paths
|
||||
* - the opt-in encrypted-search index (IndexedDB) → `deleteSearchCacheDatabase()`
|
||||
* - unsent composer drafts (`draft-msg-*`) and the presence status message
|
||||
* (`lotus-status-msg-*`) are deliberately preserved across a normal logout
|
||||
* (N98); clearing them is a separate product decision
|
||||
* - low-sensitivity UI/metadata residue (`io.lotus.mute_timers`, collapsed
|
||||
* nav/space categories, `cinny_oidc_dynamic_clients`) is treated as
|
||||
* preferences, not swept here
|
||||
*/
|
||||
export const clearPlaintextCaches = (userId?: string): void => {
|
||||
clearTranslationCache();
|
||||
clearScheduledMessages();
|
||||
clearRecentSearches();
|
||||
clearRecentForwardTargets();
|
||||
clearRecentGifs();
|
||||
clearRecentStickers();
|
||||
if (userId) clearNavToActivePathStore(userId);
|
||||
};
|
||||
Reference in New Issue
Block a user