diff --git a/src/app/features/settings/general/General.tsx b/src/app/features/settings/general/General.tsx
index 4601e9e88..898c1a22d 100644
--- a/src/app/features/settings/general/General.tsx
+++ b/src/app/features/settings/general/General.tsx
@@ -114,6 +114,7 @@ import { SequenceCardStyle } from '../styles.css';
import { UpdateProgress, useTauriUpdater } from '../../../hooks/useTauriUpdater';
import { describeUpdateError, manualDownloadUrl } from '../../../utils/updateErrors';
import { isTauri as isTauriEnv, invokeTauri, tauriInvoke } from '../../../hooks/useTauri';
+import { useKeychainMirrorStatus } from '../../../state/keychainMirror';
import { isSafeGlobalToggleKey } from '../../../hooks/useCallHotkeys';
import { customWindowChromeAtom } from '../../../state/customWindowChrome';
import { useDateFormatItems } from '../../../hooks/useDateFormat';
@@ -238,6 +239,27 @@ function AutostartSetting() {
);
}
+// [Gitea #105] Desktop: whether the login is also kept in the OS keychain.
+function KeychainMirrorSetting() {
+ const status = useKeychainMirrorStatus();
+ if (!isTauriEnv() || status.state === 'idle' || status.state === 'cleared') return null;
+ let description: string;
+ if (status.state === 'ok') {
+ description =
+ "A copy of your login is kept in the system keychain (Windows Credential Manager). A later update will keep it only there, out of the app's data folder.";
+ } else if (status.state === 'unsupported') {
+ description =
+ "Not available on this system yet. Your login is saved in the app's data folder, as before.";
+ } else {
+ description = `Couldn't save a copy to the system keychain (${status.error}). You stay logged in; your login is saved in the app's data folder, as before.`;
+ }
+ return (
+
+
+
+ );
+}
+
type ThemeSelectorProps = {
themeNames: Record;
themes: Theme[];
@@ -570,6 +592,7 @@ function Appearance() {
+
{
+ let stored: unknown = null;
+ const calls: string[] = [];
+ const invoke: KeychainInvoke = async (cmd, args) => {
+ calls.push(cmd);
+ switch (cmd) {
+ case 'secure_session_supported':
+ return opts.supported ?? true;
+ case 'secure_session_get':
+ return stored;
+ case 'secure_session_set':
+ if (opts.failSet) throw new Error('Access is denied.');
+ stored = opts.corrupt ? { ...(args?.tokens as object), accessToken: 'x' } : args?.tokens;
+ return null;
+ case 'secure_session_clear':
+ stored = null;
+ return null;
+ default:
+ throw new Error(`unknown ${cmd}`);
+ }
+ };
+ return { invoke, calls, get: () => stored };
+};
+
+test('stores the tokens (not the whole session) and verifies them', async () => {
+ const kc = fakeKeychain();
+ assert.deepEqual(await syncKeychain(kc.invoke, session), { state: 'ok' });
+ assert.deepEqual(kc.get(), {
+ userId: '@alice:example.org',
+ deviceId: 'DEV1',
+ accessToken: 'syt_token',
+ refreshToken: 'mar_refresh',
+ });
+ assert.deepEqual(kc.calls, [
+ 'secure_session_supported',
+ 'secure_session_get',
+ 'secure_session_set',
+ 'secure_session_get',
+ ]);
+});
+
+test('an up-to-date copy is not rewritten', async () => {
+ const kc = fakeKeychain();
+ await syncKeychain(kc.invoke, session);
+ kc.calls.length = 0;
+ assert.deepEqual(await syncKeychain(kc.invoke, session), { state: 'ok' });
+ assert.deepEqual(kc.calls, ['secure_session_supported', 'secure_session_get']);
+});
+
+test('a token rotation rewrites; no session clears', async () => {
+ const kc = fakeKeychain();
+ await syncKeychain(kc.invoke, session);
+ await syncKeychain(kc.invoke, { ...session, accessToken: 'syt_new', refreshToken: undefined });
+ assert.equal((kc.get() as { accessToken: string }).accessToken, 'syt_new');
+ assert.equal('refreshToken' in (kc.get() as object), false);
+ assert.deepEqual(await syncKeychain(kc.invoke, null), { state: 'cleared' });
+ assert.equal(kc.get(), null);
+});
+
+test('unsupported platform: nothing is touched', async () => {
+ const kc = fakeKeychain({ supported: false });
+ assert.deepEqual(await syncKeychain(kc.invoke, session), { state: 'unsupported' });
+ assert.deepEqual(kc.calls, ['secure_session_supported']);
+});
+
+test('failures become a status, never an exception', async () => {
+ assert.deepEqual(await syncKeychain(fakeKeychain({ failSet: true }).invoke, session), {
+ state: 'error',
+ error: 'Access is denied.',
+ });
+ assert.deepEqual(await syncKeychain(fakeKeychain({ corrupt: true }).invoke, session), {
+ state: 'error',
+ error: 'read-back did not match',
+ });
+ // The credential store hangs (the support check itself is instant).
+ const hung: KeychainInvoke = async (cmd) =>
+ cmd === 'secure_session_supported'
+ ? true
+ : new Promise(() => {
+ /* never settles */
+ });
+ assert.deepEqual(await syncKeychain(hung, session, 50), {
+ state: 'error',
+ error: 'keychain timed out',
+ });
+});
+
+test('a desktop build without the commands reads as unsupported, not an error', async () => {
+ const missingCommand: KeychainInvoke = async (cmd) => {
+ throw new Error(`Command ${cmd} not found`);
+ };
+ assert.deepEqual(await syncKeychain(missingCommand, session), { state: 'unsupported' });
+});
+
+test('sameTokens compares only the secrets, treating a missing refresh token as absent', () => {
+ const t = tokensOf({ ...session, refreshToken: undefined });
+ assert.equal(sameTokens({ ...t }, t), true);
+ assert.equal(sameTokens({ ...t, refreshToken: undefined }, t), true);
+ assert.equal(sameTokens({ ...t, accessToken: 'other' }, t), false);
+ assert.equal(sameTokens({ ...t, refreshToken: 'r' }, t), false);
+ assert.equal(sameTokens(null, t), false);
+ assert.equal(sameTokens('string', t), false);
+});
diff --git a/src/app/state/keychainMirror.ts b/src/app/state/keychainMirror.ts
new file mode 100644
index 000000000..2ccdc38cf
--- /dev/null
+++ b/src/app/state/keychainMirror.ts
@@ -0,0 +1,141 @@
+import { useEffect, useState } from 'react';
+import { getFallbackSession, onSessionPersisted, Session } from './sessions';
+
+/**
+ * [Gitea #105] Desktop, step 1: mirror the login tokens into the OS keychain.
+ *
+ * The session is still read from localStorage exactly as before; this only
+ * keeps a copy in the keychain (Windows Credential Manager) and checks it by
+ * reading it back, so real installs prove the keychain works before step 2
+ * switches reads over to it. Nothing here can log anyone out: every failure
+ * just records a status for Settings.
+ *
+ * Writes are serialized (a token rotation right after login must not race
+ * the login's write) and time out, so a hung credential store can't pile up.
+ * When there's no session the keychain entry is cleared, which also covers a
+ * logout whose page reload beat the clear.
+ */
+
+export type KeychainTokens = {
+ userId: string;
+ deviceId: string;
+ accessToken: string;
+ refreshToken?: string;
+};
+
+export type KeychainMirrorStatus =
+ | { state: 'idle' }
+ | { state: 'unsupported' }
+ | { state: 'ok' }
+ | { state: 'cleared' }
+ | { state: 'error'; error: string };
+
+export type KeychainInvoke = (cmd: string, args?: Record) => Promise;
+
+export const KEYCHAIN_TIMEOUT_MS = 5000;
+
+export const tokensOf = (session: Session): KeychainTokens => ({
+ userId: session.userId,
+ deviceId: session.deviceId,
+ accessToken: session.accessToken,
+ ...(session.refreshToken ? { refreshToken: session.refreshToken } : {}),
+});
+
+export const sameTokens = (a: unknown, b: KeychainTokens): boolean => {
+ if (!a || typeof a !== 'object') return false;
+ const t = a as Partial;
+ return (
+ t.userId === b.userId &&
+ t.deviceId === b.deviceId &&
+ t.accessToken === b.accessToken &&
+ (t.refreshToken ?? undefined) === (b.refreshToken ?? undefined)
+ );
+};
+
+const withTimeout = (p: Promise, ms: number): Promise =>
+ new Promise((resolve, reject) => {
+ const timer = setTimeout(() => reject(new Error('keychain timed out')), ms);
+ p.then(
+ (v) => {
+ clearTimeout(timer);
+ resolve(v);
+ },
+ (e) => {
+ clearTimeout(timer);
+ reject(e);
+ },
+ );
+ });
+
+const errorText = (e: unknown): string =>
+ (e instanceof Error ? e.message : String(e)).slice(0, 200);
+
+/**
+ * Bring the keychain in line with `session` (null = no session). Reads first
+ * and only writes when the stored copy differs, then verifies by reading back.
+ */
+export const syncKeychain = async (
+ invoke: KeychainInvoke,
+ session: Session | null,
+ timeoutMs = KEYCHAIN_TIMEOUT_MS,
+): Promise => {
+ // A desktop build without the commands (older than this feature) rejects
+ // the call: that is "not supported", not an error to show the user.
+ let supported: unknown;
+ try {
+ supported = await withTimeout(invoke('secure_session_supported'), timeoutMs);
+ } catch {
+ supported = false;
+ }
+ if (supported !== true) return { state: 'unsupported' };
+ try {
+ if (!session) {
+ await withTimeout(invoke('secure_session_clear'), timeoutMs);
+ return { state: 'cleared' };
+ }
+ const tokens = tokensOf(session);
+ const stored = await withTimeout(invoke('secure_session_get'), timeoutMs);
+ if (sameTokens(stored, tokens)) return { state: 'ok' };
+ await withTimeout(invoke('secure_session_set', { tokens }), timeoutMs);
+ const back = await withTimeout(invoke('secure_session_get'), timeoutMs);
+ if (!sameTokens(back, tokens)) return { state: 'error', error: 'read-back did not match' };
+ return { state: 'ok' };
+ } catch (e) {
+ return { state: 'error', error: errorText(e) };
+ }
+};
+
+let status: KeychainMirrorStatus = { state: 'idle' };
+const statusListeners = new Set<(s: KeychainMirrorStatus) => void>();
+const setStatus = (next: KeychainMirrorStatus): void => {
+ status = next;
+ statusListeners.forEach((cb) => cb(next));
+};
+
+export const getKeychainMirrorStatus = (): KeychainMirrorStatus => status;
+
+let started = false;
+
+/** Start mirroring (desktop only; call once at boot). */
+export const startKeychainMirror = (invoke: KeychainInvoke | undefined): void => {
+ if (!invoke || started) return;
+ started = true;
+ let chain: Promise = Promise.resolve();
+ const enqueue = (session: Session | null) => {
+ chain = chain.then(async () => setStatus(await syncKeychain(invoke, session)));
+ };
+ enqueue(getFallbackSession() ?? null);
+ onSessionPersisted((session) => enqueue(session));
+};
+
+export const useKeychainMirrorStatus = (): KeychainMirrorStatus => {
+ const [value, setValue] = useState(status);
+ useEffect(() => {
+ setValue(status);
+ statusListeners.add(setValue);
+ return () => {
+ statusListeners.delete(setValue);
+ };
+ }, []);
+ return value;
+};
diff --git a/src/app/state/sessions.test.ts b/src/app/state/sessions.test.ts
index e54075237..0235a1736 100644
--- a/src/app/state/sessions.test.ts
+++ b/src/app/state/sessions.test.ts
@@ -432,3 +432,20 @@ test('subscribeSessionChanges ignores unrelated storage keys', () => {
listeners.forEach((cb) => cb({ key: 'some_unrelated_preference' }));
assert.equal(fired, false);
});
+
+test('onSessionPersisted: told about writes and removals; a throwing listener is harmless', async () => {
+ installStorage();
+ const { onSessionPersisted } = await import('./sessions');
+ const seen: (string | null)[] = [];
+ const offBad = onSessionPersisted(() => {
+ throw new Error('boom');
+ });
+ const off = onSessionPersisted((s) => seen.push(s ? s.accessToken : null));
+ setFallbackSession('tok-a', 'DEV', '@a:hs', 'https://hs', { refreshToken: 'ref-a' });
+ removeFallbackSession();
+ off();
+ offBad();
+ setFallbackSession('tok-b', 'DEV', '@a:hs', 'https://hs');
+ assert.deepEqual(seen, ['tok-a', null]);
+ assert.equal(getFallbackSession()?.accessToken, 'tok-b', 'write still happened');
+});
diff --git a/src/app/state/sessions.ts b/src/app/state/sessions.ts
index 85a03f203..2c00061c7 100644
--- a/src/app/state/sessions.ts
+++ b/src/app/state/sessions.ts
@@ -233,6 +233,27 @@ export type SessionStoreName = {
// crypto: 'crypto-store',
// } as const;
+// [Gitea #105] Listeners told about every session write in THIS tab (login,
+// token rotation) and removal (logout), e.g. the desktop keychain mirror.
+// A throwing listener never breaks the write.
+type PersistListener = (session: Session | null) => void;
+const persistListeners = new Set();
+const notifyPersisted = (session: Session | null): void => {
+ persistListeners.forEach((cb) => {
+ try {
+ cb(session);
+ } catch {
+ /* listener errors must not affect login/logout */
+ }
+ });
+};
+export const onSessionPersisted = (cb: PersistListener): (() => void) => {
+ persistListeners.add(cb);
+ return () => {
+ persistListeners.delete(cb);
+ };
+};
+
// Persist the session. Writes the atomic blob FIRST (so the consistent,
// never-torn copy is established before the multi-key legacy write), then
// dual-writes the legacy keys for rollback safety. Signature is unchanged —
@@ -249,6 +270,7 @@ export function setFallbackSession(
localStorage.setItem(SESSION_BLOB_KEY, JSON.stringify(persisted));
// Dual-write the legacy keys (removal of this half is a future release).
writeLegacyKeys(persisted);
+ notifyPersisted(sessionFromPersisted(persisted));
}
// Clear BOTH the atomic blob and every legacy key so no reader (blob-preferring
@@ -257,6 +279,7 @@ export const removeFallbackSession = () => {
localStorage.removeItem(SESSION_BLOB_KEY);
Object.values(LEGACY_KEYS).forEach((key) => localStorage.removeItem(key));
Object.values(OIDC_KEYS).forEach((key) => localStorage.removeItem(key));
+ notifyPersisted(null);
};
// Read the session, preferring the atomic blob. If the blob is absent or
diff --git a/src/index.tsx b/src/index.tsx
index 63631bc7d..528fd59c9 100644
--- a/src/index.tsx
+++ b/src/index.tsx
@@ -17,10 +17,16 @@ import App from './app/pages/App';
import './app/i18n';
import { pushSessionToSW } from './sw-session';
import { getFallbackSession } from './app/state/sessions';
+import { startKeychainMirror } from './app/state/keychainMirror';
+import { tauriInvoke } from './app/hooks/useTauri';
import { cleanupSearchCacheIfSignedOut } from './client/initMatrix';
document.body.classList.add(configClass, varsClass);
+// [Gitea #105] Desktop: keep a copy of the login tokens in the OS keychain
+// (step 1: mirror only; the session is still read from localStorage).
+startKeychainMirror(tauriInvoke());
+
// Register Service Worker
// Service workers only register on http(s) pages. The desktop app loads from
// `tauri://localhost` in debug builds (and on any platform where the localhost