Compare commits

..

3 Commits

Author SHA1 Message Date
byGalax 05c962d46f fix(auth): scope signOut to local session only
Release desktop app / build (, windows-latest) (push) Has been cancelled
Release desktop app / build (--target universal-apple-darwin --bundles app,updater, macos-14) (push) Has been cancelled
2026-04-19 20:11:08 +02:00
byGalax cf3fef6936 fix(secretStore): fall back to localStorage when stronghold init fails
Release desktop app / build (, windows-latest) (push) Has been cancelled
Release desktop app / build (--target universal-apple-darwin --bundles app,updater, macos-14) (push) Has been cancelled
2026-04-19 20:05:37 +02:00
byGalax 8c878b3718 fix(capabilities): allow stronghold operations
Release desktop app / build (, windows-latest) (push) Has been cancelled
Release desktop app / build (--target universal-apple-darwin --bundles app,updater, macos-14) (push) Has been cancelled
2026-04-19 20:02:44 +02:00
5 changed files with 29 additions and 7 deletions
@@ -15,6 +15,14 @@
"updater:allow-check",
"updater:allow-download",
"updater:allow-install",
"updater:allow-download-and-install"
"updater:allow-download-and-install",
"stronghold:default",
"stronghold:allow-initialize",
"stronghold:allow-load-client",
"stronghold:allow-create-client",
"stronghold:allow-save",
"stronghold:allow-get-store-record",
"stronghold:allow-save-store-record",
"stronghold:allow-remove-store-record"
]
}
+1 -1
View File
@@ -1,7 +1,7 @@
{
"$schema": "https://schema.tauri.app/config/2",
"productName": "ChatApp",
"version": "0.3.1",
"version": "0.3.4",
"identifier": "com.meinname.chatapp",
"build": {
"beforeDevCommand": "pnpm vite:dev",
+1 -1
View File
@@ -61,7 +61,7 @@ export function AuthProvider({ children }: { children: ReactNode }) {
const status = (error as { status?: number }).status;
if (status === 401 || status === 403) {
// Token genuinely invalid — wipe.
await supabase.auth.signOut().catch(() => {
await supabase.auth.signOut({ scope: 'local' }).catch(() => {
/* ignore */
});
setSession(null);
+13 -3
View File
@@ -39,11 +39,21 @@ export async function setSecretStoreUser(userId: string | null): Promise<void> {
if (userId && isTauriRuntime()) {
const stronghold = makeStrongholdStore(userId);
activeBackend = stronghold;
try {
await migrateLocalStorageToStronghold(userId, PREFIX);
// Force a tiny round-trip to verify Stronghold can actually open the
// vault on this machine. If not (broken vault file, bundled rust crate
// mismatch, etc.) we fall back to localStorage so the rest of the app
// remains usable instead of bricking device registration.
await stronghold.getSecret('__probe');
activeBackend = stronghold;
try {
await migrateLocalStorageToStronghold(userId, PREFIX);
} catch (err: unknown) {
console.warn('stronghold migration failed', err);
}
} catch (err: unknown) {
console.warn('stronghold migration failed', err);
console.warn('stronghold init failed — falling back to localStorage', err);
activeBackend = localStore;
}
} else {
activeBackend = localStore;
+5 -1
View File
@@ -86,7 +86,11 @@ export async function completeSessionFromUrl(
}
export async function signOut(client: AppSupabaseClient): Promise<void> {
const { error } = await client.auth.signOut();
// `scope: 'local'` only ends the session in THIS client. Without it Supabase
// defaults to 'global', which invalidates the user's refresh tokens
// everywhere — meaning a logout in the browser would also kick the desktop
// app (and vice versa) the next time it tries to refresh its token.
const { error } = await client.auth.signOut({ scope: 'local' });
if (error) throw error;
}