Files
cinny/src/app/state/plaintextCaches.ts
T
jaredandClaude Opus 4.8 726cefb5ab fix(privacy): wipe plaintext/PII localStorage caches on logout (SEC-1/2)
Several localStorage caches held decrypted message content or user PII and
survived a normal logout, leaving residue on a shared device (the search
index was already wiped; these were not):

- cinny_scheduled_messages_v1 - decrypted IContent.body of pending sends
- cinny_recent_searches_v1     - search query text
- cinny_recent_forward_targets_v1 - recent forward contact/room graph
- cinny_recent_gifs_v1 / cinny_recent_stickers_v1 - media the user sent
- navToActivePath<userId>       - per-space last-visited room paths
- (plus the translation cache added earlier)

Add a clear function per module and a single auditable clearPlaintextCaches()
aggregator, called from both logout paths (logoutClient + the server-forced
SessionLoggedOut handler) alongside the existing session/search-index wipes.
Unit-tested.

Deliberately NOT cleared (documented in the aggregator): unsent composer
drafts and the presence status message (preserved by product decision N98);
SDK sync/crypto store + io.lotus.* account data (reminders/bookmarks/notes),
already wiped by mx.clearStores(); low-sensitivity UI/metadata residue.

The forward-targets/gifs/stickers/nav-path additions and the accurate
"not covered" documentation address findings from two review passes.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-18 16:56:08 -04:00

44 lines
2.1 KiB
TypeScript

import { clearTranslationCache } from './translation';
import { clearScheduledMessages } from './scheduledMessages';
import { clearRecentSearches } from './recentSearches';
import { clearRecentForwardTargets } from './recentForwardTargets';
import { clearRecentGifs } from './recentGifs';
import { clearRecentStickers } from './recentStickers';
import { clearNavToActivePathStore } from './navToActivePath';
/**
* Single auditable place that wipes the `localStorage` caches holding decrypted
* message content, sent media, or a user's messaging/nav activity. Called on
* logout so this residue can't survive on a shared device.
*
* Swept here:
* - `cinny_translation_cache_v1` — decrypted translated message text
* - `cinny_scheduled_messages_v1` — decrypted `IContent.body` of pending sends
* - `cinny_recent_searches_v1` — search query text (PII)
* - `cinny_recent_forward_targets_v1` — recent forward contact/room graph (PII)
* - `cinny_recent_gifs_v1` / `cinny_recent_stickers_v1` — media the user sent
* - `navToActivePath<userId>` — per-space last-visited room paths (needs userId)
*
* NOT swept here (by design):
* - session credential keys → `removeFallbackSession()`
* - the SDK sync/crypto store + all `io.lotus.*` account data (reminders,
* bookmarks, user notes, status presets — themselves plaintext) → wiped by
* `mx.clearStores()` on both logout paths
* - the opt-in encrypted-search index (IndexedDB) → `deleteSearchCacheDatabase()`
* - unsent composer drafts (`draft-msg-*`) and the presence status message
* (`lotus-status-msg-*`) are deliberately preserved across a normal logout
* (N98); clearing them is a separate product decision
* - low-sensitivity UI/metadata residue (`io.lotus.mute_timers`, collapsed
* nav/space categories, `cinny_oidc_dynamic_clients`) is treated as
* preferences, not swept here
*/
export const clearPlaintextCaches = (userId?: string): void => {
clearTranslationCache();
clearScheduledMessages();
clearRecentSearches();
clearRecentForwardTargets();
clearRecentGifs();
clearRecentStickers();
if (userId) clearNavToActivePathStore(userId);
};