Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9b9f33b270 |
@@ -114,6 +114,7 @@ import { SequenceCardStyle } from '../styles.css';
|
|||||||
import { UpdateProgress, useTauriUpdater } from '../../../hooks/useTauriUpdater';
|
import { UpdateProgress, useTauriUpdater } from '../../../hooks/useTauriUpdater';
|
||||||
import { describeUpdateError, manualDownloadUrl } from '../../../utils/updateErrors';
|
import { describeUpdateError, manualDownloadUrl } from '../../../utils/updateErrors';
|
||||||
import { isTauri as isTauriEnv, invokeTauri, tauriInvoke } from '../../../hooks/useTauri';
|
import { isTauri as isTauriEnv, invokeTauri, tauriInvoke } from '../../../hooks/useTauri';
|
||||||
|
import { useKeychainMirrorStatus } from '../../../state/keychainMirror';
|
||||||
import { isSafeGlobalToggleKey } from '../../../hooks/useCallHotkeys';
|
import { isSafeGlobalToggleKey } from '../../../hooks/useCallHotkeys';
|
||||||
import { customWindowChromeAtom } from '../../../state/customWindowChrome';
|
import { customWindowChromeAtom } from '../../../state/customWindowChrome';
|
||||||
import { useDateFormatItems } from '../../../hooks/useDateFormat';
|
import { useDateFormatItems } from '../../../hooks/useDateFormat';
|
||||||
@@ -238,6 +239,27 @@ function AutostartSetting() {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// [Gitea #105] Desktop: whether the login is also kept in the OS keychain.
|
||||||
|
function KeychainMirrorSetting() {
|
||||||
|
const status = useKeychainMirrorStatus();
|
||||||
|
if (!isTauriEnv() || status.state === 'idle' || status.state === 'cleared') return null;
|
||||||
|
let description: string;
|
||||||
|
if (status.state === 'ok') {
|
||||||
|
description =
|
||||||
|
"A copy of your login is kept in the system keychain (Windows Credential Manager). A later update will keep it only there, out of the app's data folder.";
|
||||||
|
} else if (status.state === 'unsupported') {
|
||||||
|
description =
|
||||||
|
"Not available on this system yet. Your login is saved in the app's data folder, as before.";
|
||||||
|
} else {
|
||||||
|
description = `Couldn't save a copy to the system keychain (${status.error}). You stay logged in; your login is saved in the app's data folder, as before.`;
|
||||||
|
}
|
||||||
|
return (
|
||||||
|
<SequenceCard className={SequenceCardStyle} variant="SurfaceVariant" direction="Column">
|
||||||
|
<SettingTile title="Login in the system keychain" description={description} />
|
||||||
|
</SequenceCard>
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
type ThemeSelectorProps = {
|
type ThemeSelectorProps = {
|
||||||
themeNames: Record<string, string>;
|
themeNames: Record<string, string>;
|
||||||
themes: Theme[];
|
themes: Theme[];
|
||||||
@@ -570,6 +592,7 @@ function Appearance() {
|
|||||||
|
|
||||||
<DesktopChromeSetting />
|
<DesktopChromeSetting />
|
||||||
<AutostartSetting />
|
<AutostartSetting />
|
||||||
|
<KeychainMirrorSetting />
|
||||||
|
|
||||||
<SequenceCard className={SequenceCardStyle} variant="SurfaceVariant" direction="Column">
|
<SequenceCard className={SequenceCardStyle} variant="SurfaceVariant" direction="Column">
|
||||||
<SettingTile
|
<SettingTile
|
||||||
|
|||||||
@@ -0,0 +1,117 @@
|
|||||||
|
import { test } from 'node:test';
|
||||||
|
import assert from 'node:assert/strict';
|
||||||
|
import { KeychainInvoke, sameTokens, syncKeychain, tokensOf } from './keychainMirror';
|
||||||
|
import type { Session } from './sessions';
|
||||||
|
|
||||||
|
const session: Session = {
|
||||||
|
baseUrl: 'https://matrix.example.org',
|
||||||
|
userId: '@alice:example.org',
|
||||||
|
deviceId: 'DEV1',
|
||||||
|
accessToken: 'syt_token',
|
||||||
|
refreshToken: 'mar_refresh',
|
||||||
|
};
|
||||||
|
|
||||||
|
/** An in-memory keychain behind the same commands the desktop app exposes. */
|
||||||
|
const fakeKeychain = (opts: { supported?: boolean; failSet?: boolean; corrupt?: boolean } = {}) => {
|
||||||
|
let stored: unknown = null;
|
||||||
|
const calls: string[] = [];
|
||||||
|
const invoke: KeychainInvoke = async (cmd, args) => {
|
||||||
|
calls.push(cmd);
|
||||||
|
switch (cmd) {
|
||||||
|
case 'secure_session_supported':
|
||||||
|
return opts.supported ?? true;
|
||||||
|
case 'secure_session_get':
|
||||||
|
return stored;
|
||||||
|
case 'secure_session_set':
|
||||||
|
if (opts.failSet) throw new Error('Access is denied.');
|
||||||
|
stored = opts.corrupt ? { ...(args?.tokens as object), accessToken: 'x' } : args?.tokens;
|
||||||
|
return null;
|
||||||
|
case 'secure_session_clear':
|
||||||
|
stored = null;
|
||||||
|
return null;
|
||||||
|
default:
|
||||||
|
throw new Error(`unknown ${cmd}`);
|
||||||
|
}
|
||||||
|
};
|
||||||
|
return { invoke, calls, get: () => stored };
|
||||||
|
};
|
||||||
|
|
||||||
|
test('stores the tokens (not the whole session) and verifies them', async () => {
|
||||||
|
const kc = fakeKeychain();
|
||||||
|
assert.deepEqual(await syncKeychain(kc.invoke, session), { state: 'ok' });
|
||||||
|
assert.deepEqual(kc.get(), {
|
||||||
|
userId: '@alice:example.org',
|
||||||
|
deviceId: 'DEV1',
|
||||||
|
accessToken: 'syt_token',
|
||||||
|
refreshToken: 'mar_refresh',
|
||||||
|
});
|
||||||
|
assert.deepEqual(kc.calls, [
|
||||||
|
'secure_session_supported',
|
||||||
|
'secure_session_get',
|
||||||
|
'secure_session_set',
|
||||||
|
'secure_session_get',
|
||||||
|
]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('an up-to-date copy is not rewritten', async () => {
|
||||||
|
const kc = fakeKeychain();
|
||||||
|
await syncKeychain(kc.invoke, session);
|
||||||
|
kc.calls.length = 0;
|
||||||
|
assert.deepEqual(await syncKeychain(kc.invoke, session), { state: 'ok' });
|
||||||
|
assert.deepEqual(kc.calls, ['secure_session_supported', 'secure_session_get']);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('a token rotation rewrites; no session clears', async () => {
|
||||||
|
const kc = fakeKeychain();
|
||||||
|
await syncKeychain(kc.invoke, session);
|
||||||
|
await syncKeychain(kc.invoke, { ...session, accessToken: 'syt_new', refreshToken: undefined });
|
||||||
|
assert.equal((kc.get() as { accessToken: string }).accessToken, 'syt_new');
|
||||||
|
assert.equal('refreshToken' in (kc.get() as object), false);
|
||||||
|
assert.deepEqual(await syncKeychain(kc.invoke, null), { state: 'cleared' });
|
||||||
|
assert.equal(kc.get(), null);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('unsupported platform: nothing is touched', async () => {
|
||||||
|
const kc = fakeKeychain({ supported: false });
|
||||||
|
assert.deepEqual(await syncKeychain(kc.invoke, session), { state: 'unsupported' });
|
||||||
|
assert.deepEqual(kc.calls, ['secure_session_supported']);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('failures become a status, never an exception', async () => {
|
||||||
|
assert.deepEqual(await syncKeychain(fakeKeychain({ failSet: true }).invoke, session), {
|
||||||
|
state: 'error',
|
||||||
|
error: 'Access is denied.',
|
||||||
|
});
|
||||||
|
assert.deepEqual(await syncKeychain(fakeKeychain({ corrupt: true }).invoke, session), {
|
||||||
|
state: 'error',
|
||||||
|
error: 'read-back did not match',
|
||||||
|
});
|
||||||
|
// The credential store hangs (the support check itself is instant).
|
||||||
|
const hung: KeychainInvoke = async (cmd) =>
|
||||||
|
cmd === 'secure_session_supported'
|
||||||
|
? true
|
||||||
|
: new Promise(() => {
|
||||||
|
/* never settles */
|
||||||
|
});
|
||||||
|
assert.deepEqual(await syncKeychain(hung, session, 50), {
|
||||||
|
state: 'error',
|
||||||
|
error: 'keychain timed out',
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
test('a desktop build without the commands reads as unsupported, not an error', async () => {
|
||||||
|
const missingCommand: KeychainInvoke = async (cmd) => {
|
||||||
|
throw new Error(`Command ${cmd} not found`);
|
||||||
|
};
|
||||||
|
assert.deepEqual(await syncKeychain(missingCommand, session), { state: 'unsupported' });
|
||||||
|
});
|
||||||
|
|
||||||
|
test('sameTokens compares only the secrets, treating a missing refresh token as absent', () => {
|
||||||
|
const t = tokensOf({ ...session, refreshToken: undefined });
|
||||||
|
assert.equal(sameTokens({ ...t }, t), true);
|
||||||
|
assert.equal(sameTokens({ ...t, refreshToken: undefined }, t), true);
|
||||||
|
assert.equal(sameTokens({ ...t, accessToken: 'other' }, t), false);
|
||||||
|
assert.equal(sameTokens({ ...t, refreshToken: 'r' }, t), false);
|
||||||
|
assert.equal(sameTokens(null, t), false);
|
||||||
|
assert.equal(sameTokens('string', t), false);
|
||||||
|
});
|
||||||
@@ -0,0 +1,141 @@
|
|||||||
|
import { useEffect, useState } from 'react';
|
||||||
|
import { getFallbackSession, onSessionPersisted, Session } from './sessions';
|
||||||
|
|
||||||
|
/**
|
||||||
|
* [Gitea #105] Desktop, step 1: mirror the login tokens into the OS keychain.
|
||||||
|
*
|
||||||
|
* The session is still read from localStorage exactly as before; this only
|
||||||
|
* keeps a copy in the keychain (Windows Credential Manager) and checks it by
|
||||||
|
* reading it back, so real installs prove the keychain works before step 2
|
||||||
|
* switches reads over to it. Nothing here can log anyone out: every failure
|
||||||
|
* just records a status for Settings.
|
||||||
|
*
|
||||||
|
* Writes are serialized (a token rotation right after login must not race
|
||||||
|
* the login's write) and time out, so a hung credential store can't pile up.
|
||||||
|
* When there's no session the keychain entry is cleared, which also covers a
|
||||||
|
* logout whose page reload beat the clear.
|
||||||
|
*/
|
||||||
|
|
||||||
|
export type KeychainTokens = {
|
||||||
|
userId: string;
|
||||||
|
deviceId: string;
|
||||||
|
accessToken: string;
|
||||||
|
refreshToken?: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type KeychainMirrorStatus =
|
||||||
|
| { state: 'idle' }
|
||||||
|
| { state: 'unsupported' }
|
||||||
|
| { state: 'ok' }
|
||||||
|
| { state: 'cleared' }
|
||||||
|
| { state: 'error'; error: string };
|
||||||
|
|
||||||
|
export type KeychainInvoke = (cmd: string, args?: Record<string, unknown>) => Promise<unknown>;
|
||||||
|
|
||||||
|
export const KEYCHAIN_TIMEOUT_MS = 5000;
|
||||||
|
|
||||||
|
export const tokensOf = (session: Session): KeychainTokens => ({
|
||||||
|
userId: session.userId,
|
||||||
|
deviceId: session.deviceId,
|
||||||
|
accessToken: session.accessToken,
|
||||||
|
...(session.refreshToken ? { refreshToken: session.refreshToken } : {}),
|
||||||
|
});
|
||||||
|
|
||||||
|
export const sameTokens = (a: unknown, b: KeychainTokens): boolean => {
|
||||||
|
if (!a || typeof a !== 'object') return false;
|
||||||
|
const t = a as Partial<KeychainTokens>;
|
||||||
|
return (
|
||||||
|
t.userId === b.userId &&
|
||||||
|
t.deviceId === b.deviceId &&
|
||||||
|
t.accessToken === b.accessToken &&
|
||||||
|
(t.refreshToken ?? undefined) === (b.refreshToken ?? undefined)
|
||||||
|
);
|
||||||
|
};
|
||||||
|
|
||||||
|
const withTimeout = <T>(p: Promise<T>, ms: number): Promise<T> =>
|
||||||
|
new Promise<T>((resolve, reject) => {
|
||||||
|
const timer = setTimeout(() => reject(new Error('keychain timed out')), ms);
|
||||||
|
p.then(
|
||||||
|
(v) => {
|
||||||
|
clearTimeout(timer);
|
||||||
|
resolve(v);
|
||||||
|
},
|
||||||
|
(e) => {
|
||||||
|
clearTimeout(timer);
|
||||||
|
reject(e);
|
||||||
|
},
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
const errorText = (e: unknown): string =>
|
||||||
|
(e instanceof Error ? e.message : String(e)).slice(0, 200);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Bring the keychain in line with `session` (null = no session). Reads first
|
||||||
|
* and only writes when the stored copy differs, then verifies by reading back.
|
||||||
|
*/
|
||||||
|
export const syncKeychain = async (
|
||||||
|
invoke: KeychainInvoke,
|
||||||
|
session: Session | null,
|
||||||
|
timeoutMs = KEYCHAIN_TIMEOUT_MS,
|
||||||
|
): Promise<KeychainMirrorStatus> => {
|
||||||
|
// A desktop build without the commands (older than this feature) rejects
|
||||||
|
// the call: that is "not supported", not an error to show the user.
|
||||||
|
let supported: unknown;
|
||||||
|
try {
|
||||||
|
supported = await withTimeout(invoke('secure_session_supported'), timeoutMs);
|
||||||
|
} catch {
|
||||||
|
supported = false;
|
||||||
|
}
|
||||||
|
if (supported !== true) return { state: 'unsupported' };
|
||||||
|
try {
|
||||||
|
if (!session) {
|
||||||
|
await withTimeout(invoke('secure_session_clear'), timeoutMs);
|
||||||
|
return { state: 'cleared' };
|
||||||
|
}
|
||||||
|
const tokens = tokensOf(session);
|
||||||
|
const stored = await withTimeout(invoke('secure_session_get'), timeoutMs);
|
||||||
|
if (sameTokens(stored, tokens)) return { state: 'ok' };
|
||||||
|
await withTimeout(invoke('secure_session_set', { tokens }), timeoutMs);
|
||||||
|
const back = await withTimeout(invoke('secure_session_get'), timeoutMs);
|
||||||
|
if (!sameTokens(back, tokens)) return { state: 'error', error: 'read-back did not match' };
|
||||||
|
return { state: 'ok' };
|
||||||
|
} catch (e) {
|
||||||
|
return { state: 'error', error: errorText(e) };
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
let status: KeychainMirrorStatus = { state: 'idle' };
|
||||||
|
const statusListeners = new Set<(s: KeychainMirrorStatus) => void>();
|
||||||
|
const setStatus = (next: KeychainMirrorStatus): void => {
|
||||||
|
status = next;
|
||||||
|
statusListeners.forEach((cb) => cb(next));
|
||||||
|
};
|
||||||
|
|
||||||
|
export const getKeychainMirrorStatus = (): KeychainMirrorStatus => status;
|
||||||
|
|
||||||
|
let started = false;
|
||||||
|
|
||||||
|
/** Start mirroring (desktop only; call once at boot). */
|
||||||
|
export const startKeychainMirror = (invoke: KeychainInvoke | undefined): void => {
|
||||||
|
if (!invoke || started) return;
|
||||||
|
started = true;
|
||||||
|
let chain: Promise<unknown> = Promise.resolve();
|
||||||
|
const enqueue = (session: Session | null) => {
|
||||||
|
chain = chain.then(async () => setStatus(await syncKeychain(invoke, session)));
|
||||||
|
};
|
||||||
|
enqueue(getFallbackSession() ?? null);
|
||||||
|
onSessionPersisted((session) => enqueue(session));
|
||||||
|
};
|
||||||
|
|
||||||
|
export const useKeychainMirrorStatus = (): KeychainMirrorStatus => {
|
||||||
|
const [value, setValue] = useState(status);
|
||||||
|
useEffect(() => {
|
||||||
|
setValue(status);
|
||||||
|
statusListeners.add(setValue);
|
||||||
|
return () => {
|
||||||
|
statusListeners.delete(setValue);
|
||||||
|
};
|
||||||
|
}, []);
|
||||||
|
return value;
|
||||||
|
};
|
||||||
@@ -432,3 +432,20 @@ test('subscribeSessionChanges ignores unrelated storage keys', () => {
|
|||||||
listeners.forEach((cb) => cb({ key: 'some_unrelated_preference' }));
|
listeners.forEach((cb) => cb({ key: 'some_unrelated_preference' }));
|
||||||
assert.equal(fired, false);
|
assert.equal(fired, false);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
test('onSessionPersisted: told about writes and removals; a throwing listener is harmless', async () => {
|
||||||
|
installStorage();
|
||||||
|
const { onSessionPersisted } = await import('./sessions');
|
||||||
|
const seen: (string | null)[] = [];
|
||||||
|
const offBad = onSessionPersisted(() => {
|
||||||
|
throw new Error('boom');
|
||||||
|
});
|
||||||
|
const off = onSessionPersisted((s) => seen.push(s ? s.accessToken : null));
|
||||||
|
setFallbackSession('tok-a', 'DEV', '@a:hs', 'https://hs', { refreshToken: 'ref-a' });
|
||||||
|
removeFallbackSession();
|
||||||
|
off();
|
||||||
|
offBad();
|
||||||
|
setFallbackSession('tok-b', 'DEV', '@a:hs', 'https://hs');
|
||||||
|
assert.deepEqual(seen, ['tok-a', null]);
|
||||||
|
assert.equal(getFallbackSession()?.accessToken, 'tok-b', 'write still happened');
|
||||||
|
});
|
||||||
|
|||||||
@@ -233,6 +233,27 @@ export type SessionStoreName = {
|
|||||||
// crypto: 'crypto-store',
|
// crypto: 'crypto-store',
|
||||||
// } as const;
|
// } as const;
|
||||||
|
|
||||||
|
// [Gitea #105] Listeners told about every session write in THIS tab (login,
|
||||||
|
// token rotation) and removal (logout), e.g. the desktop keychain mirror.
|
||||||
|
// A throwing listener never breaks the write.
|
||||||
|
type PersistListener = (session: Session | null) => void;
|
||||||
|
const persistListeners = new Set<PersistListener>();
|
||||||
|
const notifyPersisted = (session: Session | null): void => {
|
||||||
|
persistListeners.forEach((cb) => {
|
||||||
|
try {
|
||||||
|
cb(session);
|
||||||
|
} catch {
|
||||||
|
/* listener errors must not affect login/logout */
|
||||||
|
}
|
||||||
|
});
|
||||||
|
};
|
||||||
|
export const onSessionPersisted = (cb: PersistListener): (() => void) => {
|
||||||
|
persistListeners.add(cb);
|
||||||
|
return () => {
|
||||||
|
persistListeners.delete(cb);
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
// Persist the session. Writes the atomic blob FIRST (so the consistent,
|
// Persist the session. Writes the atomic blob FIRST (so the consistent,
|
||||||
// never-torn copy is established before the multi-key legacy write), then
|
// never-torn copy is established before the multi-key legacy write), then
|
||||||
// dual-writes the legacy keys for rollback safety. Signature is unchanged —
|
// dual-writes the legacy keys for rollback safety. Signature is unchanged —
|
||||||
@@ -249,6 +270,7 @@ export function setFallbackSession(
|
|||||||
localStorage.setItem(SESSION_BLOB_KEY, JSON.stringify(persisted));
|
localStorage.setItem(SESSION_BLOB_KEY, JSON.stringify(persisted));
|
||||||
// Dual-write the legacy keys (removal of this half is a future release).
|
// Dual-write the legacy keys (removal of this half is a future release).
|
||||||
writeLegacyKeys(persisted);
|
writeLegacyKeys(persisted);
|
||||||
|
notifyPersisted(sessionFromPersisted(persisted));
|
||||||
}
|
}
|
||||||
|
|
||||||
// Clear BOTH the atomic blob and every legacy key so no reader (blob-preferring
|
// Clear BOTH the atomic blob and every legacy key so no reader (blob-preferring
|
||||||
@@ -257,6 +279,7 @@ export const removeFallbackSession = () => {
|
|||||||
localStorage.removeItem(SESSION_BLOB_KEY);
|
localStorage.removeItem(SESSION_BLOB_KEY);
|
||||||
Object.values(LEGACY_KEYS).forEach((key) => localStorage.removeItem(key));
|
Object.values(LEGACY_KEYS).forEach((key) => localStorage.removeItem(key));
|
||||||
Object.values(OIDC_KEYS).forEach((key) => localStorage.removeItem(key));
|
Object.values(OIDC_KEYS).forEach((key) => localStorage.removeItem(key));
|
||||||
|
notifyPersisted(null);
|
||||||
};
|
};
|
||||||
|
|
||||||
// Read the session, preferring the atomic blob. If the blob is absent or
|
// Read the session, preferring the atomic blob. If the blob is absent or
|
||||||
|
|||||||
@@ -17,10 +17,16 @@ import App from './app/pages/App';
|
|||||||
import './app/i18n';
|
import './app/i18n';
|
||||||
import { pushSessionToSW } from './sw-session';
|
import { pushSessionToSW } from './sw-session';
|
||||||
import { getFallbackSession } from './app/state/sessions';
|
import { getFallbackSession } from './app/state/sessions';
|
||||||
|
import { startKeychainMirror } from './app/state/keychainMirror';
|
||||||
|
import { tauriInvoke } from './app/hooks/useTauri';
|
||||||
import { cleanupSearchCacheIfSignedOut } from './client/initMatrix';
|
import { cleanupSearchCacheIfSignedOut } from './client/initMatrix';
|
||||||
|
|
||||||
document.body.classList.add(configClass, varsClass);
|
document.body.classList.add(configClass, varsClass);
|
||||||
|
|
||||||
|
// [Gitea #105] Desktop: keep a copy of the login tokens in the OS keychain
|
||||||
|
// (step 1: mirror only; the session is still read from localStorage).
|
||||||
|
startKeychainMirror(tauriInvoke());
|
||||||
|
|
||||||
// Register Service Worker
|
// Register Service Worker
|
||||||
// Service workers only register on http(s) pages. The desktop app loads from
|
// Service workers only register on http(s) pages. The desktop app loads from
|
||||||
// `tauri://localhost` in debug builds (and on any platform where the localhost
|
// `tauri://localhost` in debug builds (and on any platform where the localhost
|
||||||
|
|||||||
Reference in New Issue
Block a user