diff --git a/apps/mobile/lib/legacyDeviceVault.ts b/apps/mobile/lib/legacyDeviceVault.ts new file mode 100644 index 0000000..81d50dc --- /dev/null +++ b/apps/mobile/lib/legacyDeviceVault.ts @@ -0,0 +1,9 @@ +import { secretStore } from './secretStore'; + +// During the migration window the orchestrator probes SecureStore for legacy +// per-device private keys. We keep this read-only — never write — so a future +// reset can safely wipe the new chatapp.userpriv.* slot without affecting +// pre-existing legacy entries. +export function legacyDeviceKey(userId: string, deviceId: string): Promise { + return secretStore.getSecret('chatapp.priv.' + userId + '.' + deviceId); +}