Compare commits
9
Commits
offline-outbox
...
lotus
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
d6548c56fd | ||
|
|
23f059d9a4 | ||
|
|
9b9f33b270 | ||
|
|
7d7a379ce0 | ||
|
|
91f82d60e3 | ||
|
|
f0865115a4 | ||
|
|
899e160aed | ||
|
|
3e5fdd0dab | ||
|
|
bb569d69a2 |
@@ -257,12 +257,21 @@ test.describe('local homeserver regression', () => {
|
||||
await page.clock.install({ time: Date.now() + 14 * 60 * 1000 });
|
||||
await loginUI(page, alice);
|
||||
await openRoom(page, room);
|
||||
for (let i = 0; i < 4; i += 1) {
|
||||
// eslint-disable-next-line no-await-in-loop
|
||||
await sendText(bob, room, `tick ${i}`);
|
||||
// eslint-disable-next-line no-await-in-loop
|
||||
await page.waitForTimeout(500);
|
||||
}
|
||||
const ticks = async (from: number, n: number) => {
|
||||
for (let i = from; i < from + n; i += 1) {
|
||||
// eslint-disable-next-line no-await-in-loop
|
||||
await sendText(bob, room, `tick ${i}`);
|
||||
// eslint-disable-next-line no-await-in-loop
|
||||
await page.waitForTimeout(500);
|
||||
}
|
||||
};
|
||||
await ticks(0, 4);
|
||||
// "Ahead" could be a late delivery (a stalled server), so it is only
|
||||
// reported once it has held for a minute of fresh samples.
|
||||
await page.waitForTimeout(2000);
|
||||
await expect(page.getByText(/clock is .*ahead of the server/)).toHaveCount(0);
|
||||
await page.clock.fastForward('01:05');
|
||||
await ticks(4, 2);
|
||||
await expect(page.getByText(/clock is .*14 minutes ahead of the server/)).toBeVisible();
|
||||
await page.getByRole('button', { name: 'Dismiss for 24 h' }).click();
|
||||
await expect(page.getByText(/clock is .*ahead of the server/)).toHaveCount(0);
|
||||
|
||||
@@ -72,9 +72,9 @@ export function CallStatus({ callEmbed }: CallStatusProps) {
|
||||
size="T200"
|
||||
truncate
|
||||
style={{ color: color.Warning.Main }}
|
||||
title="Fix your computer's clock — calls and encryption depend on it"
|
||||
title="This device's clock is off. Calls and encryption depend on it: turn on automatic time in your system settings."
|
||||
>
|
||||
Clock {describeSkewVsServer(clockSkew.skewMs)} — calls will fail
|
||||
Device clock {describeSkewVsServer(clockSkew.skewMs)}: calls may fail
|
||||
</Text>
|
||||
</>
|
||||
)}
|
||||
|
||||
@@ -114,6 +114,7 @@ import { SequenceCardStyle } from '../styles.css';
|
||||
import { UpdateProgress, useTauriUpdater } from '../../../hooks/useTauriUpdater';
|
||||
import { describeUpdateError, manualDownloadUrl } from '../../../utils/updateErrors';
|
||||
import { isTauri as isTauriEnv, invokeTauri, tauriInvoke } from '../../../hooks/useTauri';
|
||||
import { useKeychainMirrorStatus } from '../../../state/keychainMirror';
|
||||
import { isSafeGlobalToggleKey } from '../../../hooks/useCallHotkeys';
|
||||
import { customWindowChromeAtom } from '../../../state/customWindowChrome';
|
||||
import { useDateFormatItems } from '../../../hooks/useDateFormat';
|
||||
@@ -238,6 +239,27 @@ function AutostartSetting() {
|
||||
);
|
||||
}
|
||||
|
||||
// [Gitea #105] Desktop: whether the login is also kept in the OS keychain.
|
||||
function KeychainMirrorSetting() {
|
||||
const status = useKeychainMirrorStatus();
|
||||
if (!isTauriEnv() || status.state === 'idle' || status.state === 'cleared') return null;
|
||||
let description: string;
|
||||
if (status.state === 'ok') {
|
||||
description =
|
||||
"A copy of your login is kept in the system keychain (Windows Credential Manager). A later update will keep it only there, out of the app's data folder.";
|
||||
} else if (status.state === 'unsupported') {
|
||||
description =
|
||||
"Not available on this system yet. Your login is saved in the app's data folder, as before.";
|
||||
} else {
|
||||
description = `Couldn't save a copy to the system keychain (${status.error}). You stay logged in; your login is saved in the app's data folder, as before.`;
|
||||
}
|
||||
return (
|
||||
<SequenceCard className={SequenceCardStyle} variant="SurfaceVariant" direction="Column">
|
||||
<SettingTile title="Login in the system keychain" description={description} />
|
||||
</SequenceCard>
|
||||
);
|
||||
}
|
||||
|
||||
type ThemeSelectorProps = {
|
||||
themeNames: Record<string, string>;
|
||||
themes: Theme[];
|
||||
@@ -570,6 +592,7 @@ function Appearance() {
|
||||
|
||||
<DesktopChromeSetting />
|
||||
<AutostartSetting />
|
||||
<KeychainMirrorSetting />
|
||||
|
||||
<SequenceCard className={SequenceCardStyle} variant="SurfaceVariant" direction="Column">
|
||||
<SettingTile
|
||||
|
||||
@@ -26,6 +26,15 @@ export type ClientConfig = {
|
||||
*/
|
||||
elementCallUrl?: string;
|
||||
|
||||
/**
|
||||
* [Gitea #43] Desktop only: the loopback origin the desktop app's local
|
||||
* server also answers on (e.g. "http://127.0.0.1:44548"), to load the
|
||||
* bundled call page from a different origin than the app
|
||||
* ("http://localhost:44548"). Set by cinny-desktop together with the server
|
||||
* and CSP changes it needs; unset keeps the same-origin call page.
|
||||
*/
|
||||
desktopCallOrigin?: string;
|
||||
|
||||
/**
|
||||
* Absolute https URL of the public web app (e.g. https://chat.lotusguild.org).
|
||||
* The desktop app sets it so it can hand calls it can't make to the browser.
|
||||
|
||||
+14
-2
@@ -36,7 +36,11 @@ import { applyCustomAccent, removeCustomAccent } from '../utils/accentColor';
|
||||
import { zIndices } from '../styles/zIndex';
|
||||
import { OIDC_CALLBACK_PATH } from './paths';
|
||||
import { OidcCallback } from './auth/oidc/OidcCallback';
|
||||
import { resolveCallPageUrl, setCallPageUrl } from '../plugins/call/callPageUrl';
|
||||
import {
|
||||
resolveCallPageUrl,
|
||||
resolveDesktopCallPageUrl,
|
||||
setCallPageUrl,
|
||||
} from '../plugins/call/callPageUrl';
|
||||
|
||||
// The emoji families (Twemoji when "Twitter emoji" is on, Twemoji flags on
|
||||
// Windows — see SystemEmojiFeature) must sit before the generic family, or the
|
||||
@@ -223,7 +227,15 @@ function App() {
|
||||
>
|
||||
{(clientConfig) => {
|
||||
// [Gitea #43] Idempotent: where the call page is loaded from.
|
||||
setCallPageUrl(resolveCallPageUrl(clientConfig.elementCallUrl, isTauri()));
|
||||
setCallPageUrl(
|
||||
isTauri()
|
||||
? resolveDesktopCallPageUrl(
|
||||
clientConfig.desktopCallOrigin,
|
||||
window.location.origin,
|
||||
import.meta.env.BASE_URL,
|
||||
)
|
||||
: resolveCallPageUrl(clientConfig.elementCallUrl, false),
|
||||
);
|
||||
return (
|
||||
<ClientConfigProvider value={clientConfig}>
|
||||
<QueryClientProvider client={queryClient}>
|
||||
|
||||
@@ -1072,6 +1072,10 @@ function ClockSkewFeature() {
|
||||
data,
|
||||
) => {
|
||||
if (!data.liveEvent) return;
|
||||
// Only events our homeserver stamped: a federated event's
|
||||
// origin_server_ts is the other server's clock.
|
||||
const senderServer = mEvent.getSender()?.split(':').slice(1).join(':');
|
||||
if (senderServer !== mx.getDomain()) return;
|
||||
monitor.sample(mEvent.getTs(), mEvent.getAge(), mEvent.localTimestamp);
|
||||
};
|
||||
mx.on(RoomEvent.Timeline, onTimeline);
|
||||
|
||||
@@ -19,7 +19,7 @@ const readDismissedUntil = (): number => {
|
||||
};
|
||||
|
||||
/**
|
||||
* [Gitea #158] "Your computer's clock is 14 minutes ahead of the server."
|
||||
* [Gitea #158] "This device's clock is 14 minutes ahead of the server."
|
||||
* Same slot and style as the sync banners. Shown while the skew monitor is
|
||||
* over its threshold; the direction matters, so it is said. Dismissable for
|
||||
* 24 h; never auto-corrects anything.
|
||||
@@ -53,8 +53,8 @@ export function ClockSkewBanner() {
|
||||
>
|
||||
<Box alignItems="Center" gap="300" wrap="Wrap" justifyContent="Center">
|
||||
<Text size="L400" align="Center">
|
||||
Your computer's clock is <b>{describeSkewVsServer(skewMs)}</b>. Encrypted messages
|
||||
and voice calls will fail until it is fixed.
|
||||
This device's clock is <b>{describeSkewVsServer(skewMs)}</b>. Voice calls and
|
||||
encrypted messages can fail until it's corrected.
|
||||
</Text>
|
||||
<Button
|
||||
size="300"
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
import { test } from 'node:test';
|
||||
import assert from 'node:assert/strict';
|
||||
import { resolveCallPageUrl } from './callPageUrl';
|
||||
import { resolveCallPageUrl, resolveDesktopCallPageUrl } from './callPageUrl';
|
||||
|
||||
const URL_OK = 'https://call.chat.example.org/public/element-call/index.html';
|
||||
|
||||
@@ -38,3 +38,44 @@ test('anything else falls back to the bundled page', () => {
|
||||
'data:text/html,x',
|
||||
].forEach((v) => assert.equal(resolveCallPageUrl(v, false), undefined, String(v)));
|
||||
});
|
||||
|
||||
const APP = 'http://localhost:44548';
|
||||
const PAGE = '/public/element-call/index.html';
|
||||
|
||||
test('desktop: the bundled page from the loopback origin on the same port', () => {
|
||||
assert.equal(
|
||||
resolveDesktopCallPageUrl('http://127.0.0.1:44548', APP, '/'),
|
||||
`http://127.0.0.1:44548${PAGE}`,
|
||||
);
|
||||
assert.equal(
|
||||
resolveDesktopCallPageUrl('http://127.0.0.1:44548/', APP, '/app/'),
|
||||
`http://127.0.0.1:44548/app${PAGE}`,
|
||||
);
|
||||
});
|
||||
|
||||
test('desktop: unset or anything but same-port loopback http keeps the same-origin page', () => {
|
||||
[
|
||||
undefined,
|
||||
'',
|
||||
'http://127.0.0.1:44549',
|
||||
'http://127.0.0.1',
|
||||
'https://127.0.0.1:44548',
|
||||
'http://localhost:44548',
|
||||
'http://[::1]:44548',
|
||||
'http://10.0.0.5:44548',
|
||||
'https://call.chat.lotusguild.org',
|
||||
'http://127.0.0.1:44548/evil/',
|
||||
'http://127.0.0.1:44548/?x=1',
|
||||
'http://user:pw@127.0.0.1:44548',
|
||||
'not a url',
|
||||
42,
|
||||
].forEach((v) => assert.equal(resolveDesktopCallPageUrl(v, APP, '/'), undefined, String(v)));
|
||||
});
|
||||
|
||||
test('desktop: only when the app itself runs on http://localhost (release builds)', () => {
|
||||
const v = 'http://127.0.0.1:44548';
|
||||
assert.equal(resolveDesktopCallPageUrl(v, 'tauri://localhost', '/'), undefined);
|
||||
assert.equal(resolveDesktopCallPageUrl(v, 'http://tauri.localhost', '/'), undefined);
|
||||
assert.equal(resolveDesktopCallPageUrl(v, 'https://chat.lotusguild.org', '/'), undefined);
|
||||
assert.equal(resolveDesktopCallPageUrl(v, 'http://localhost', '/'), undefined);
|
||||
});
|
||||
|
||||
@@ -7,9 +7,9 @@
|
||||
* app loads it from that origin instead, so the call frame can no longer
|
||||
* reach this origin's storage (login token, crypto store) or service worker.
|
||||
*
|
||||
* Web only: the desktop app keeps its bundled copy (its CSP doesn't allow
|
||||
* another frame origin, and a network copy could drift from the bundle).
|
||||
* Anything that isn't an absolute https URL (http only on localhost, for
|
||||
* Web only: the desktop app keeps its bundled copy (a network copy could
|
||||
* drift from the bundle); see resolveDesktopCallPageUrl for how it isolates
|
||||
* it. Anything that isn't an absolute https URL (http only on localhost, for
|
||||
* development) is ignored, so a bad value falls
|
||||
* back to the bundled page instead of breaking calls.
|
||||
*/
|
||||
@@ -28,6 +28,40 @@ export const resolveCallPageUrl = (value: unknown, desktop: boolean): string | u
|
||||
}
|
||||
};
|
||||
|
||||
/**
|
||||
* [Gitea #43] Desktop: the bundled call page from a second origin.
|
||||
*
|
||||
* The desktop app is served by its local server at http://localhost:<port>.
|
||||
* The same server answers on http://127.0.0.1:<port>, which is a different
|
||||
* origin (and still a secure context), so loading the bundled call page from
|
||||
* there cuts the call frame off from the app's storage (login token, crypto
|
||||
* store) without a network copy that could drift from the bundle.
|
||||
*
|
||||
* Only used when cinny-desktop sets `desktopCallOrigin` (it ships the server
|
||||
* and CSP changes this needs in the same release), only for a loopback http
|
||||
* origin on the SAME port as the app, and only when the app itself runs on
|
||||
* http://localhost (release builds). Anything else keeps the same-origin page.
|
||||
*/
|
||||
export const resolveDesktopCallPageUrl = (
|
||||
value: unknown,
|
||||
appOrigin: string,
|
||||
basePath: string,
|
||||
): string | undefined => {
|
||||
if (typeof value !== 'string' || value.trim() === '') return undefined;
|
||||
try {
|
||||
const app = new URL(appOrigin);
|
||||
const call = new URL(value);
|
||||
if (app.protocol !== 'http:' || app.hostname !== 'localhost' || !app.port) return undefined;
|
||||
if (call.protocol !== 'http:' || call.hostname !== '127.0.0.1') return undefined;
|
||||
if (call.port !== app.port || call.username || call.password) return undefined;
|
||||
if (call.pathname !== '/' || call.search || call.hash) return undefined;
|
||||
const base = basePath.replace(/\/+$/, '');
|
||||
return `${call.origin}${base}/public/element-call/index.html`;
|
||||
} catch {
|
||||
return undefined;
|
||||
}
|
||||
};
|
||||
|
||||
let callPageUrl: string | undefined;
|
||||
|
||||
export const setCallPageUrl = (url: string | undefined): void => {
|
||||
|
||||
@@ -0,0 +1,117 @@
|
||||
import { test } from 'node:test';
|
||||
import assert from 'node:assert/strict';
|
||||
import { KeychainInvoke, sameTokens, syncKeychain, tokensOf } from './keychainMirror';
|
||||
import type { Session } from './sessions';
|
||||
|
||||
const session: Session = {
|
||||
baseUrl: 'https://matrix.example.org',
|
||||
userId: '@alice:example.org',
|
||||
deviceId: 'DEV1',
|
||||
accessToken: 'syt_token',
|
||||
refreshToken: 'mar_refresh',
|
||||
};
|
||||
|
||||
/** An in-memory keychain behind the same commands the desktop app exposes. */
|
||||
const fakeKeychain = (opts: { supported?: boolean; failSet?: boolean; corrupt?: boolean } = {}) => {
|
||||
let stored: unknown = null;
|
||||
const calls: string[] = [];
|
||||
const invoke: KeychainInvoke = async (cmd, args) => {
|
||||
calls.push(cmd);
|
||||
switch (cmd) {
|
||||
case 'secure_session_supported':
|
||||
return opts.supported ?? true;
|
||||
case 'secure_session_get':
|
||||
return stored;
|
||||
case 'secure_session_set':
|
||||
if (opts.failSet) throw new Error('Access is denied.');
|
||||
stored = opts.corrupt ? { ...(args?.tokens as object), accessToken: 'x' } : args?.tokens;
|
||||
return null;
|
||||
case 'secure_session_clear':
|
||||
stored = null;
|
||||
return null;
|
||||
default:
|
||||
throw new Error(`unknown ${cmd}`);
|
||||
}
|
||||
};
|
||||
return { invoke, calls, get: () => stored };
|
||||
};
|
||||
|
||||
test('stores the tokens (not the whole session) and verifies them', async () => {
|
||||
const kc = fakeKeychain();
|
||||
assert.deepEqual(await syncKeychain(kc.invoke, session), { state: 'ok' });
|
||||
assert.deepEqual(kc.get(), {
|
||||
userId: '@alice:example.org',
|
||||
deviceId: 'DEV1',
|
||||
accessToken: 'syt_token',
|
||||
refreshToken: 'mar_refresh',
|
||||
});
|
||||
assert.deepEqual(kc.calls, [
|
||||
'secure_session_supported',
|
||||
'secure_session_get',
|
||||
'secure_session_set',
|
||||
'secure_session_get',
|
||||
]);
|
||||
});
|
||||
|
||||
test('an up-to-date copy is not rewritten', async () => {
|
||||
const kc = fakeKeychain();
|
||||
await syncKeychain(kc.invoke, session);
|
||||
kc.calls.length = 0;
|
||||
assert.deepEqual(await syncKeychain(kc.invoke, session), { state: 'ok' });
|
||||
assert.deepEqual(kc.calls, ['secure_session_supported', 'secure_session_get']);
|
||||
});
|
||||
|
||||
test('a token rotation rewrites; no session clears', async () => {
|
||||
const kc = fakeKeychain();
|
||||
await syncKeychain(kc.invoke, session);
|
||||
await syncKeychain(kc.invoke, { ...session, accessToken: 'syt_new', refreshToken: undefined });
|
||||
assert.equal((kc.get() as { accessToken: string }).accessToken, 'syt_new');
|
||||
assert.equal('refreshToken' in (kc.get() as object), false);
|
||||
assert.deepEqual(await syncKeychain(kc.invoke, null), { state: 'cleared' });
|
||||
assert.equal(kc.get(), null);
|
||||
});
|
||||
|
||||
test('unsupported platform: nothing is touched', async () => {
|
||||
const kc = fakeKeychain({ supported: false });
|
||||
assert.deepEqual(await syncKeychain(kc.invoke, session), { state: 'unsupported' });
|
||||
assert.deepEqual(kc.calls, ['secure_session_supported']);
|
||||
});
|
||||
|
||||
test('failures become a status, never an exception', async () => {
|
||||
assert.deepEqual(await syncKeychain(fakeKeychain({ failSet: true }).invoke, session), {
|
||||
state: 'error',
|
||||
error: 'Access is denied.',
|
||||
});
|
||||
assert.deepEqual(await syncKeychain(fakeKeychain({ corrupt: true }).invoke, session), {
|
||||
state: 'error',
|
||||
error: 'read-back did not match',
|
||||
});
|
||||
// The credential store hangs (the support check itself is instant).
|
||||
const hung: KeychainInvoke = async (cmd) =>
|
||||
cmd === 'secure_session_supported'
|
||||
? true
|
||||
: new Promise(() => {
|
||||
/* never settles */
|
||||
});
|
||||
assert.deepEqual(await syncKeychain(hung, session, 50), {
|
||||
state: 'error',
|
||||
error: 'keychain timed out',
|
||||
});
|
||||
});
|
||||
|
||||
test('a desktop build without the commands reads as unsupported, not an error', async () => {
|
||||
const missingCommand: KeychainInvoke = async (cmd) => {
|
||||
throw new Error(`Command ${cmd} not found`);
|
||||
};
|
||||
assert.deepEqual(await syncKeychain(missingCommand, session), { state: 'unsupported' });
|
||||
});
|
||||
|
||||
test('sameTokens compares only the secrets, treating a missing refresh token as absent', () => {
|
||||
const t = tokensOf({ ...session, refreshToken: undefined });
|
||||
assert.equal(sameTokens({ ...t }, t), true);
|
||||
assert.equal(sameTokens({ ...t, refreshToken: undefined }, t), true);
|
||||
assert.equal(sameTokens({ ...t, accessToken: 'other' }, t), false);
|
||||
assert.equal(sameTokens({ ...t, refreshToken: 'r' }, t), false);
|
||||
assert.equal(sameTokens(null, t), false);
|
||||
assert.equal(sameTokens('string', t), false);
|
||||
});
|
||||
@@ -0,0 +1,141 @@
|
||||
import { useEffect, useState } from 'react';
|
||||
import { getFallbackSession, onSessionPersisted, Session } from './sessions';
|
||||
|
||||
/**
|
||||
* [Gitea #105] Desktop, step 1: mirror the login tokens into the OS keychain.
|
||||
*
|
||||
* The session is still read from localStorage exactly as before; this only
|
||||
* keeps a copy in the keychain (Windows Credential Manager) and checks it by
|
||||
* reading it back, so real installs prove the keychain works before step 2
|
||||
* switches reads over to it. Nothing here can log anyone out: every failure
|
||||
* just records a status for Settings.
|
||||
*
|
||||
* Writes are serialized (a token rotation right after login must not race
|
||||
* the login's write) and time out, so a hung credential store can't pile up.
|
||||
* When there's no session the keychain entry is cleared, which also covers a
|
||||
* logout whose page reload beat the clear.
|
||||
*/
|
||||
|
||||
export type KeychainTokens = {
|
||||
userId: string;
|
||||
deviceId: string;
|
||||
accessToken: string;
|
||||
refreshToken?: string;
|
||||
};
|
||||
|
||||
export type KeychainMirrorStatus =
|
||||
| { state: 'idle' }
|
||||
| { state: 'unsupported' }
|
||||
| { state: 'ok' }
|
||||
| { state: 'cleared' }
|
||||
| { state: 'error'; error: string };
|
||||
|
||||
export type KeychainInvoke = (cmd: string, args?: Record<string, unknown>) => Promise<unknown>;
|
||||
|
||||
export const KEYCHAIN_TIMEOUT_MS = 5000;
|
||||
|
||||
export const tokensOf = (session: Session): KeychainTokens => ({
|
||||
userId: session.userId,
|
||||
deviceId: session.deviceId,
|
||||
accessToken: session.accessToken,
|
||||
...(session.refreshToken ? { refreshToken: session.refreshToken } : {}),
|
||||
});
|
||||
|
||||
export const sameTokens = (a: unknown, b: KeychainTokens): boolean => {
|
||||
if (!a || typeof a !== 'object') return false;
|
||||
const t = a as Partial<KeychainTokens>;
|
||||
return (
|
||||
t.userId === b.userId &&
|
||||
t.deviceId === b.deviceId &&
|
||||
t.accessToken === b.accessToken &&
|
||||
(t.refreshToken ?? undefined) === (b.refreshToken ?? undefined)
|
||||
);
|
||||
};
|
||||
|
||||
const withTimeout = <T>(p: Promise<T>, ms: number): Promise<T> =>
|
||||
new Promise<T>((resolve, reject) => {
|
||||
const timer = setTimeout(() => reject(new Error('keychain timed out')), ms);
|
||||
p.then(
|
||||
(v) => {
|
||||
clearTimeout(timer);
|
||||
resolve(v);
|
||||
},
|
||||
(e) => {
|
||||
clearTimeout(timer);
|
||||
reject(e);
|
||||
},
|
||||
);
|
||||
});
|
||||
|
||||
const errorText = (e: unknown): string =>
|
||||
(e instanceof Error ? e.message : String(e)).slice(0, 200);
|
||||
|
||||
/**
|
||||
* Bring the keychain in line with `session` (null = no session). Reads first
|
||||
* and only writes when the stored copy differs, then verifies by reading back.
|
||||
*/
|
||||
export const syncKeychain = async (
|
||||
invoke: KeychainInvoke,
|
||||
session: Session | null,
|
||||
timeoutMs = KEYCHAIN_TIMEOUT_MS,
|
||||
): Promise<KeychainMirrorStatus> => {
|
||||
// A desktop build without the commands (older than this feature) rejects
|
||||
// the call: that is "not supported", not an error to show the user.
|
||||
let supported: unknown;
|
||||
try {
|
||||
supported = await withTimeout(invoke('secure_session_supported'), timeoutMs);
|
||||
} catch {
|
||||
supported = false;
|
||||
}
|
||||
if (supported !== true) return { state: 'unsupported' };
|
||||
try {
|
||||
if (!session) {
|
||||
await withTimeout(invoke('secure_session_clear'), timeoutMs);
|
||||
return { state: 'cleared' };
|
||||
}
|
||||
const tokens = tokensOf(session);
|
||||
const stored = await withTimeout(invoke('secure_session_get'), timeoutMs);
|
||||
if (sameTokens(stored, tokens)) return { state: 'ok' };
|
||||
await withTimeout(invoke('secure_session_set', { tokens }), timeoutMs);
|
||||
const back = await withTimeout(invoke('secure_session_get'), timeoutMs);
|
||||
if (!sameTokens(back, tokens)) return { state: 'error', error: 'read-back did not match' };
|
||||
return { state: 'ok' };
|
||||
} catch (e) {
|
||||
return { state: 'error', error: errorText(e) };
|
||||
}
|
||||
};
|
||||
|
||||
let status: KeychainMirrorStatus = { state: 'idle' };
|
||||
const statusListeners = new Set<(s: KeychainMirrorStatus) => void>();
|
||||
const setStatus = (next: KeychainMirrorStatus): void => {
|
||||
status = next;
|
||||
statusListeners.forEach((cb) => cb(next));
|
||||
};
|
||||
|
||||
export const getKeychainMirrorStatus = (): KeychainMirrorStatus => status;
|
||||
|
||||
let started = false;
|
||||
|
||||
/** Start mirroring (desktop only; call once at boot). */
|
||||
export const startKeychainMirror = (invoke: KeychainInvoke | undefined): void => {
|
||||
if (!invoke || started) return;
|
||||
started = true;
|
||||
let chain: Promise<unknown> = Promise.resolve();
|
||||
const enqueue = (session: Session | null) => {
|
||||
chain = chain.then(async () => setStatus(await syncKeychain(invoke, session)));
|
||||
};
|
||||
enqueue(getFallbackSession() ?? null);
|
||||
onSessionPersisted((session) => enqueue(session));
|
||||
};
|
||||
|
||||
export const useKeychainMirrorStatus = (): KeychainMirrorStatus => {
|
||||
const [value, setValue] = useState(status);
|
||||
useEffect(() => {
|
||||
setValue(status);
|
||||
statusListeners.add(setValue);
|
||||
return () => {
|
||||
statusListeners.delete(setValue);
|
||||
};
|
||||
}, []);
|
||||
return value;
|
||||
};
|
||||
@@ -432,3 +432,20 @@ test('subscribeSessionChanges ignores unrelated storage keys', () => {
|
||||
listeners.forEach((cb) => cb({ key: 'some_unrelated_preference' }));
|
||||
assert.equal(fired, false);
|
||||
});
|
||||
|
||||
test('onSessionPersisted: told about writes and removals; a throwing listener is harmless', async () => {
|
||||
installStorage();
|
||||
const { onSessionPersisted } = await import('./sessions');
|
||||
const seen: (string | null)[] = [];
|
||||
const offBad = onSessionPersisted(() => {
|
||||
throw new Error('boom');
|
||||
});
|
||||
const off = onSessionPersisted((s) => seen.push(s ? s.accessToken : null));
|
||||
setFallbackSession('tok-a', 'DEV', '@a:hs', 'https://hs', { refreshToken: 'ref-a' });
|
||||
removeFallbackSession();
|
||||
off();
|
||||
offBad();
|
||||
setFallbackSession('tok-b', 'DEV', '@a:hs', 'https://hs');
|
||||
assert.deepEqual(seen, ['tok-a', null]);
|
||||
assert.equal(getFallbackSession()?.accessToken, 'tok-b', 'write still happened');
|
||||
});
|
||||
|
||||
@@ -233,6 +233,27 @@ export type SessionStoreName = {
|
||||
// crypto: 'crypto-store',
|
||||
// } as const;
|
||||
|
||||
// [Gitea #105] Listeners told about every session write in THIS tab (login,
|
||||
// token rotation) and removal (logout), e.g. the desktop keychain mirror.
|
||||
// A throwing listener never breaks the write.
|
||||
type PersistListener = (session: Session | null) => void;
|
||||
const persistListeners = new Set<PersistListener>();
|
||||
const notifyPersisted = (session: Session | null): void => {
|
||||
persistListeners.forEach((cb) => {
|
||||
try {
|
||||
cb(session);
|
||||
} catch {
|
||||
/* listener errors must not affect login/logout */
|
||||
}
|
||||
});
|
||||
};
|
||||
export const onSessionPersisted = (cb: PersistListener): (() => void) => {
|
||||
persistListeners.add(cb);
|
||||
return () => {
|
||||
persistListeners.delete(cb);
|
||||
};
|
||||
};
|
||||
|
||||
// Persist the session. Writes the atomic blob FIRST (so the consistent,
|
||||
// never-torn copy is established before the multi-key legacy write), then
|
||||
// dual-writes the legacy keys for rollback safety. Signature is unchanged —
|
||||
@@ -249,6 +270,7 @@ export function setFallbackSession(
|
||||
localStorage.setItem(SESSION_BLOB_KEY, JSON.stringify(persisted));
|
||||
// Dual-write the legacy keys (removal of this half is a future release).
|
||||
writeLegacyKeys(persisted);
|
||||
notifyPersisted(sessionFromPersisted(persisted));
|
||||
}
|
||||
|
||||
// Clear BOTH the atomic blob and every legacy key so no reader (blob-preferring
|
||||
@@ -257,6 +279,7 @@ export const removeFallbackSession = () => {
|
||||
localStorage.removeItem(SESSION_BLOB_KEY);
|
||||
Object.values(LEGACY_KEYS).forEach((key) => localStorage.removeItem(key));
|
||||
Object.values(OIDC_KEYS).forEach((key) => localStorage.removeItem(key));
|
||||
notifyPersisted(null);
|
||||
};
|
||||
|
||||
// Read the session, preferring the atomic blob. If the blob is absent or
|
||||
|
||||
@@ -8,44 +8,96 @@ import {
|
||||
formatSkew,
|
||||
} from './clockSkew';
|
||||
|
||||
// A live event received when the local clock is `skew` ms ahead of the server:
|
||||
// origin_server_ts = T (server clock), age = a, localTimestamp = (T + a + skew) - a.
|
||||
const feed = (m: ClockSkewMonitor, skew: number, age = 500, t = 1_700_000_000_000) =>
|
||||
m.sample(t, age, t + skew);
|
||||
const T = 1_700_000_000_000;
|
||||
|
||||
test('needs three samples, then reports the median with direction', () => {
|
||||
/**
|
||||
* A live event received `atSec` seconds into the test, when the local clock is
|
||||
* `skew` ms off the server and the response took `delay` ms to arrive:
|
||||
* localTimestamp − origin_server_ts = skew + delay.
|
||||
*/
|
||||
const feed = (m: ClockSkewMonitor, skew: number, atSec = 0, delay = 0, wallJump = 0) =>
|
||||
m.sample(T, 500, T + skew + delay, { wall: T + atSec * 1000 + wallJump, mono: atSec * 1000 });
|
||||
|
||||
test('behind: reported as soon as there are three samples', () => {
|
||||
const m = new ClockSkewMonitor();
|
||||
assert.equal(feed(m, 60_000).skewMs, null);
|
||||
assert.equal(feed(m, 61_000).skewMs, null);
|
||||
const s = feed(m, 59_000);
|
||||
assert.equal(s.skewMs, 60_000);
|
||||
assert.equal(feed(m, -60_000, 0).skewMs, null);
|
||||
assert.equal(feed(m, -61_000, 1).skewMs, null);
|
||||
const s = feed(m, -59_000, 2);
|
||||
assert.equal(s.skewMs, -61_000);
|
||||
assert.equal(s.warning, true);
|
||||
assert.equal(formatSkew(s.skewMs!), '60 seconds ahead');
|
||||
assert.equal(formatSkew(s.skewMs!), '61 seconds behind');
|
||||
});
|
||||
|
||||
test('one bad sample cannot trip the warning (median) and hysteresis clears only under 15 s', () => {
|
||||
test('ahead: only once it has held for a minute', () => {
|
||||
const m = new ClockSkewMonitor();
|
||||
feed(m, 1000);
|
||||
feed(m, 1500);
|
||||
assert.equal(feed(m, 90_000).warning, false); // outlier
|
||||
assert.equal(m.getState().skewMs, 1500);
|
||||
feed(m, 60_000, 0);
|
||||
feed(m, 60_000, 10);
|
||||
assert.equal(feed(m, 60_000, 20).warning, false);
|
||||
assert.equal(m.getState().skewMs, 60_000);
|
||||
assert.equal(feed(m, 60_000, 59).warning, false);
|
||||
assert.equal(feed(m, 60_000, 61).warning, true);
|
||||
});
|
||||
|
||||
test('server stall (2026-09-29): a burst of late events does not read as a wrong clock', () => {
|
||||
const m = new ClockSkewMonitor();
|
||||
// Normal traffic, then the homeserver stalls and one /sync arrives 30 s late
|
||||
// with a pile of events, then normal traffic again.
|
||||
feed(m, 200, 0);
|
||||
feed(m, 150, 5);
|
||||
feed(m, 300, 10);
|
||||
[1, 2, 3, 4, 5, 6].forEach(() => feed(m, 0, 130, 31_000));
|
||||
assert.equal(m.getState().warning, false);
|
||||
assert.ok(m.getState().skewMs! < 1000);
|
||||
|
||||
// Fresh client whose first samples are all from the late burst.
|
||||
const fresh = new ClockSkewMonitor();
|
||||
[1, 2, 3, 4, 5, 6].forEach(() => feed(fresh, 0, 0, 31_000));
|
||||
assert.equal(fresh.getState().warning, false);
|
||||
// …and the next timely event brings the estimate back down.
|
||||
feed(fresh, 0, 70, 100);
|
||||
assert.equal(fresh.getState().warning, false);
|
||||
assert.equal(fresh.getState().skewMs, 100);
|
||||
});
|
||||
|
||||
test('slow deliveries mixed with fast ones: the fastest one wins', () => {
|
||||
const m = new ClockSkewMonitor();
|
||||
[0, 20, 40, 60, 80].forEach((at, i) => feed(m, 45_000, at, i === 2 ? 0 : 20_000));
|
||||
assert.equal(m.getState().skewMs, 45_000);
|
||||
assert.equal(m.getState().warning, true);
|
||||
});
|
||||
|
||||
test('hysteresis: once on, clears only under 15 s', () => {
|
||||
const w = new ClockSkewMonitor();
|
||||
[40_000, 41_000, 39_000, 40_000, 40_000].forEach((s) => feed(w, s));
|
||||
[0, 1, 2].forEach((at) => feed(w, -40_000, at));
|
||||
assert.equal(w.getState().warning, true);
|
||||
// drifting down to 20 s: still >= 15 s → stays on
|
||||
[20_000, 20_000, 20_000, 20_000, 20_000].forEach((s) => feed(w, s));
|
||||
// Samples expire after 5 minutes; drifting to -20 s keeps it on (>= 15 s).
|
||||
[400, 401, 402].forEach((at) => feed(w, -20_000, at));
|
||||
assert.equal(w.getState().skewMs, -20_000);
|
||||
assert.equal(w.getState().warning, true);
|
||||
[10_000, 10_000, 10_000, 10_000, 10_000].forEach((s) => feed(w, s));
|
||||
[800, 801, 802].forEach((at) => feed(w, -10_000, at));
|
||||
assert.equal(w.getState().warning, false);
|
||||
});
|
||||
|
||||
test('fixing the local clock starts the measurement afresh', () => {
|
||||
const m = new ClockSkewMonitor();
|
||||
[0, 1, 2].forEach((at) => feed(m, -14 * 60_000, at));
|
||||
assert.equal(m.getState().warning, true);
|
||||
// The user sets the clock forward 14 minutes: wall jumps vs the monotonic clock.
|
||||
const jump = 14 * 60_000;
|
||||
feed(m, 0, 10, 0, jump);
|
||||
assert.equal(m.getState().warning, false);
|
||||
assert.equal(m.getState().skewMs, null);
|
||||
feed(m, 0, 11, 0, jump);
|
||||
feed(m, 0, 12, 0, jump);
|
||||
assert.equal(m.getState().skewMs, 0);
|
||||
assert.equal(m.getState().warning, false);
|
||||
});
|
||||
|
||||
test('stale or missing age is ignored (cache replay must not read as skew)', () => {
|
||||
const m = new ClockSkewMonitor();
|
||||
const t = 1_700_000_000_000;
|
||||
m.sample(t, undefined, t + 3_600_000);
|
||||
m.sample(t, 40 * 24 * 60 * 60 * 1000, t + 3_600_000);
|
||||
m.sample(t, -5, t);
|
||||
m.sample(T, undefined, T + 3_600_000);
|
||||
m.sample(T, 40 * 24 * 60 * 60 * 1000, T + 3_600_000);
|
||||
m.sample(T, -5, T);
|
||||
assert.equal(m.getState().skewMs, null);
|
||||
});
|
||||
|
||||
@@ -53,10 +105,7 @@ test('subscribe fires on change only; reset clears', () => {
|
||||
const m = new ClockSkewMonitor();
|
||||
const seen: (number | null)[] = [];
|
||||
m.subscribe((s) => seen.push(s.skewMs));
|
||||
feed(m, -120_000);
|
||||
feed(m, -120_000);
|
||||
feed(m, -120_000);
|
||||
feed(m, -120_000);
|
||||
[0, 1, 2, 3].forEach((at) => feed(m, -120_000, at));
|
||||
assert.deepEqual(seen, [-120_000]);
|
||||
assert.equal(formatSkew(-120_000), '2 minutes behind');
|
||||
m.reset();
|
||||
|
||||
+56
-11
@@ -22,8 +22,23 @@
|
||||
|
||||
export const SKEW_WARN_MS = 30_000;
|
||||
export const SKEW_CLEAR_MS = 15_000;
|
||||
export const SKEW_SAMPLES = 5;
|
||||
export const SKEW_MIN_SAMPLES = 3;
|
||||
/** Samples older than this are forgotten. */
|
||||
export const SKEW_WINDOW_MS = 5 * 60 * 1000;
|
||||
export const SKEW_MAX_SAMPLES = 30;
|
||||
/**
|
||||
* "Ahead" must hold across samples received at least this far apart.
|
||||
*
|
||||
* Incident 2026-09-29: the homeserver's host ran out of memory and stalled for
|
||||
* ~2 minutes; the /sync that finally went out carried events whose `age` was
|
||||
* computed ~30 s before it arrived, so every client read "your clock is 30 s
|
||||
* ahead" — while the real problem was the server. A late delivery can only make
|
||||
* the local clock look AHEAD (never behind), so the estimate is the LOWEST
|
||||
* recent sample (the one delivered fastest), and "ahead" has to persist across
|
||||
* a minute of fresh samples before it is reported. "Behind" can't come from a
|
||||
* delay and is reported as soon as there are enough samples.
|
||||
*/
|
||||
export const SKEW_AHEAD_SPAN_MS = 60_000;
|
||||
/**
|
||||
* Sanity cap on `age`. Old events are still valid samples (the server computes
|
||||
* `age` at response time, so `ts + age` is its clock regardless of the event's
|
||||
@@ -38,14 +53,21 @@ export type ClockSkewState = {
|
||||
warning: boolean;
|
||||
};
|
||||
|
||||
const median = (xs: number[]): number => {
|
||||
const s = [...xs].sort((a, b) => a - b);
|
||||
const mid = Math.floor(s.length / 2);
|
||||
return s.length % 2 ? s[mid] : (s[mid - 1] + s[mid]) / 2;
|
||||
/** A wall-clock change larger than this (vs the monotonic clock) resets the samples. */
|
||||
export const CLOCK_JUMP_MS = 5_000;
|
||||
|
||||
type Sample = { skew: number; at: number };
|
||||
|
||||
const currentClock = (): { wall: number; mono: number } => {
|
||||
const wall = Date.now();
|
||||
const mono = typeof performance !== 'undefined' ? performance.now() : wall;
|
||||
return { wall, mono };
|
||||
};
|
||||
|
||||
export class ClockSkewMonitor {
|
||||
private samples: number[] = [];
|
||||
private samples: Sample[] = [];
|
||||
|
||||
private clockOffset: number | undefined;
|
||||
|
||||
private state: ClockSkewState = { skewMs: null, warning: false };
|
||||
|
||||
@@ -64,25 +86,47 @@ export class ClockSkewMonitor {
|
||||
|
||||
/**
|
||||
* Feed one live event. `originServerTs` + `age` come from the event;
|
||||
* `localTimestamp` is the SDK's `Date.now() − age` at construction.
|
||||
* `localTimestamp` is the SDK's `Date.now() − age` at construction; `clock`
|
||||
* is when the sample was taken: wall clock and a monotonic clock
|
||||
* (performance.now()), so samples are aged by real elapsed time and a change
|
||||
* of the local clock (someone fixing it) starts the measurement afresh.
|
||||
* Only feed events stamped by OUR homeserver: another server's
|
||||
* `origin_server_ts` carries that server's clock.
|
||||
* Returns the new state (unchanged object when nothing moved).
|
||||
*/
|
||||
public sample(
|
||||
originServerTs: number,
|
||||
age: number | undefined,
|
||||
localTimestamp: number,
|
||||
clock: { wall: number; mono: number } = currentClock(),
|
||||
): ClockSkewState {
|
||||
if (age === undefined || !Number.isFinite(age) || age < 0 || age > SKEW_MAX_AGE_MS) {
|
||||
return this.state;
|
||||
}
|
||||
if (!Number.isFinite(originServerTs) || !Number.isFinite(localTimestamp)) return this.state;
|
||||
this.samples.push(localTimestamp - originServerTs);
|
||||
if (this.samples.length > SKEW_SAMPLES) this.samples.shift();
|
||||
const now = clock.mono;
|
||||
const offset = clock.wall - clock.mono;
|
||||
if (this.clockOffset !== undefined && Math.abs(offset - this.clockOffset) > CLOCK_JUMP_MS) {
|
||||
// The local clock was changed: earlier samples measured the old clock.
|
||||
this.reset();
|
||||
}
|
||||
this.clockOffset = offset;
|
||||
this.samples.push({ skew: localTimestamp - originServerTs, at: now });
|
||||
this.samples = this.samples.filter((s) => now - s.at <= SKEW_WINDOW_MS);
|
||||
if (this.samples.length > SKEW_MAX_SAMPLES) this.samples.shift();
|
||||
if (this.samples.length < SKEW_MIN_SAMPLES) return this.state;
|
||||
|
||||
const skewMs = median(this.samples);
|
||||
// Delivery delay only ever adds to a sample: the smallest is the truest.
|
||||
const skewMs = Math.min(...this.samples.map((s) => s.skew));
|
||||
const abs = Math.abs(skewMs);
|
||||
const warning = this.state.warning ? abs >= SKEW_CLEAR_MS : abs > SKEW_WARN_MS;
|
||||
let warning: boolean;
|
||||
if (this.state.warning) warning = abs >= SKEW_CLEAR_MS;
|
||||
else if (skewMs < -SKEW_WARN_MS) warning = true;
|
||||
else if (skewMs > SKEW_WARN_MS) {
|
||||
// Ahead: only if the fastest-delivered samples stayed high for a minute.
|
||||
const span = now - Math.min(...this.samples.map((s) => s.at));
|
||||
warning = span >= SKEW_AHEAD_SPAN_MS;
|
||||
} else warning = false;
|
||||
if (skewMs === this.state.skewMs && warning === this.state.warning) return this.state;
|
||||
this.state = { skewMs, warning };
|
||||
this.listeners.forEach((cb) => cb(this.state));
|
||||
@@ -91,6 +135,7 @@ export class ClockSkewMonitor {
|
||||
|
||||
public reset(): void {
|
||||
this.samples = [];
|
||||
this.clockOffset = undefined;
|
||||
if (this.state.skewMs !== null || this.state.warning) {
|
||||
this.state = { skewMs: null, warning: false };
|
||||
this.listeners.forEach((cb) => cb(this.state));
|
||||
|
||||
@@ -17,10 +17,16 @@ import App from './app/pages/App';
|
||||
import './app/i18n';
|
||||
import { pushSessionToSW } from './sw-session';
|
||||
import { getFallbackSession } from './app/state/sessions';
|
||||
import { startKeychainMirror } from './app/state/keychainMirror';
|
||||
import { tauriInvoke } from './app/hooks/useTauri';
|
||||
import { cleanupSearchCacheIfSignedOut } from './client/initMatrix';
|
||||
|
||||
document.body.classList.add(configClass, varsClass);
|
||||
|
||||
// [Gitea #105] Desktop: keep a copy of the login tokens in the OS keychain
|
||||
// (step 1: mirror only; the session is still read from localStorage).
|
||||
startKeychainMirror(tauriInvoke());
|
||||
|
||||
// Register Service Worker
|
||||
// Service workers only register on http(s) pages. The desktop app loads from
|
||||
// `tauri://localhost` in debug builds (and on any platform where the localhost
|
||||
|
||||
Reference in New Issue
Block a user