(feat): add cache package
(feat): improve local storage security (feat): move settings to dedicated settings package
This commit is contained in:
parent
fb095db7a6
commit
790a1db788
54 changed files with 1984 additions and 947 deletions
|
|
@ -17,6 +17,13 @@ import {
|
|||
type DesktopScreenShareCapabilities,
|
||||
} from "../shared/ipc.js";
|
||||
import { initTray, setTrayCallStatus } from "./tray.js";
|
||||
import {
|
||||
clearSecureStorage,
|
||||
deleteSecureStorage,
|
||||
getSecureStorageStatus,
|
||||
loadSecureStorage,
|
||||
saveSecureStorage,
|
||||
} from "./secureStorage.js";
|
||||
|
||||
const __dirname = dirname(fileURLToPath(import.meta.url));
|
||||
const verbose = process.argv.includes("--verbose");
|
||||
|
|
@ -190,6 +197,18 @@ function registerIpc() {
|
|||
);
|
||||
ipcMain.handle(ipcChannels.getVersion, () => app.getVersion());
|
||||
ipcMain.handle(ipcChannels.checkForUpdates, checkForUpdates);
|
||||
ipcMain.handle(ipcChannels.getSecureStorageStatus, getSecureStorageStatus);
|
||||
ipcMain.handle(ipcChannels.loadSecureStorage, (_event, key: unknown) =>
|
||||
loadSecureStorage(key),
|
||||
);
|
||||
ipcMain.handle(
|
||||
ipcChannels.saveSecureStorage,
|
||||
(_event, key: unknown, value: unknown) => saveSecureStorage(key, value),
|
||||
);
|
||||
ipcMain.handle(ipcChannels.deleteSecureStorage, (_event, key: unknown) =>
|
||||
deleteSecureStorage(key),
|
||||
);
|
||||
ipcMain.handle(ipcChannels.clearSecureStorage, clearSecureStorage);
|
||||
ipcMain.handle(ipcChannels.setCallStatus, (_event, status: unknown) => {
|
||||
if (
|
||||
typeof status !== "object" ||
|
||||
|
|
|
|||
130
apps/electron/src/main/secureStorage.ts
Normal file
130
apps/electron/src/main/secureStorage.ts
Normal file
|
|
@ -0,0 +1,130 @@
|
|||
import { app, safeStorage } from "electron";
|
||||
import { mkdir, readFile, rename, writeFile } from "node:fs/promises";
|
||||
import { dirname, join } from "node:path";
|
||||
import {
|
||||
secureStorageLimits,
|
||||
type DesktopSecureStorageStatus,
|
||||
} from "../shared/ipc.js";
|
||||
|
||||
type StoredValues = Record<string, string>;
|
||||
|
||||
let pendingWrite = Promise.resolve();
|
||||
|
||||
function storagePath() {
|
||||
return join(app.getPath("userData"), "secure-storage.json");
|
||||
}
|
||||
|
||||
function validateKey(key: unknown): asserts key is string {
|
||||
if (
|
||||
typeof key !== "string" ||
|
||||
key.length === 0 ||
|
||||
Buffer.byteLength(key, "utf8") > secureStorageLimits.maxKeyBytes
|
||||
) {
|
||||
throw new Error("Invalid secure storage key.");
|
||||
}
|
||||
}
|
||||
|
||||
function validateValue(value: unknown): asserts value is string {
|
||||
if (
|
||||
typeof value !== "string" ||
|
||||
Buffer.byteLength(value, "utf8") > secureStorageLimits.maxValueBytes
|
||||
) {
|
||||
throw new Error("Invalid secure storage value.");
|
||||
}
|
||||
}
|
||||
|
||||
export function getSecureStorageStatus(): DesktopSecureStorageStatus {
|
||||
if (!safeStorage.isEncryptionAvailable()) {
|
||||
return { available: false, backend: null };
|
||||
}
|
||||
|
||||
const backend =
|
||||
process.platform === "linux"
|
||||
? safeStorage.getSelectedStorageBackend()
|
||||
: process.platform === "darwin"
|
||||
? "keychain"
|
||||
: process.platform === "win32"
|
||||
? "dpapi"
|
||||
: null;
|
||||
|
||||
return {
|
||||
available: process.platform !== "linux" || backend !== "basic_text",
|
||||
backend,
|
||||
};
|
||||
}
|
||||
|
||||
function requireAvailable() {
|
||||
if (!getSecureStorageStatus().available) {
|
||||
throw new Error("Secure storage is unavailable.");
|
||||
}
|
||||
}
|
||||
|
||||
async function readValues(): Promise<StoredValues> {
|
||||
try {
|
||||
const parsed: unknown = JSON.parse(await readFile(storagePath(), "utf8"));
|
||||
if (!parsed || typeof parsed !== "object" || Array.isArray(parsed)) {
|
||||
throw new Error("Invalid secure storage data.");
|
||||
}
|
||||
|
||||
const values = parsed as Record<string, unknown>;
|
||||
if (Object.values(values).some((value) => typeof value !== "string")) {
|
||||
throw new Error("Invalid secure storage data.");
|
||||
}
|
||||
return values as StoredValues;
|
||||
} catch (error) {
|
||||
if ((error as NodeJS.ErrnoException).code === "ENOENT") return {};
|
||||
throw error;
|
||||
}
|
||||
}
|
||||
|
||||
async function writeValues(values: StoredValues) {
|
||||
const path = storagePath();
|
||||
const temporaryPath = `${path}.tmp`;
|
||||
await mkdir(dirname(path), { recursive: true, mode: 0o700 });
|
||||
await writeFile(temporaryPath, JSON.stringify(values), { mode: 0o600 });
|
||||
await rename(temporaryPath, path);
|
||||
}
|
||||
|
||||
function mutateValues(mutation: (values: StoredValues) => void) {
|
||||
const operation = pendingWrite.then(async () => {
|
||||
const values = await readValues();
|
||||
mutation(values);
|
||||
await writeValues(values);
|
||||
});
|
||||
pendingWrite = operation.catch(() => undefined);
|
||||
return operation;
|
||||
}
|
||||
|
||||
export async function loadSecureStorage(key: unknown): Promise<string | null> {
|
||||
requireAvailable();
|
||||
validateKey(key);
|
||||
await pendingWrite;
|
||||
const encrypted = (await readValues())[key];
|
||||
if (encrypted === undefined) return null;
|
||||
return safeStorage.decryptString(Buffer.from(encrypted, "base64"));
|
||||
}
|
||||
|
||||
export function saveSecureStorage(key: unknown, value: unknown) {
|
||||
requireAvailable();
|
||||
validateKey(key);
|
||||
validateValue(value);
|
||||
const encrypted = safeStorage.encryptString(value).toString("base64");
|
||||
return mutateValues((values) => {
|
||||
values[key] = encrypted;
|
||||
});
|
||||
}
|
||||
|
||||
export function deleteSecureStorage(key: unknown) {
|
||||
requireAvailable();
|
||||
validateKey(key);
|
||||
return mutateValues((values) => {
|
||||
delete values[key];
|
||||
});
|
||||
}
|
||||
|
||||
export function clearSecureStorage() {
|
||||
requireAvailable();
|
||||
return mutateValues((values) => {
|
||||
for (const key of Object.keys(values)) delete values[key];
|
||||
});
|
||||
}
|
||||
|
|
@ -3,12 +3,21 @@ import {
|
|||
ipcChannels,
|
||||
type DesktopCallStatus,
|
||||
type DesktopScreenShareSource,
|
||||
secureStorageLimits,
|
||||
} from "../shared/ipc.js";
|
||||
|
||||
function windowAction(channel: string) {
|
||||
return () => ipcRenderer.invoke(channel);
|
||||
}
|
||||
|
||||
function validKey(key: string) {
|
||||
return (
|
||||
typeof key === "string" &&
|
||||
key.length > 0 &&
|
||||
Buffer.byteLength(key, "utf8") <= secureStorageLimits.maxKeyBytes
|
||||
);
|
||||
}
|
||||
|
||||
const desktopApi = {
|
||||
media: {
|
||||
listScreenShareSources: () =>
|
||||
|
|
@ -46,6 +55,24 @@ const desktopApi = {
|
|||
return ipcRenderer.invoke(ipcChannels.setCallStatus, status);
|
||||
},
|
||||
},
|
||||
secureStorage: {
|
||||
getStatus: () => ipcRenderer.invoke(ipcChannels.getSecureStorageStatus),
|
||||
load: (key: string) =>
|
||||
validKey(key)
|
||||
? ipcRenderer.invoke(ipcChannels.loadSecureStorage, key)
|
||||
: Promise.reject(new Error("Invalid secure storage key.")),
|
||||
save: (key: string, value: string) =>
|
||||
validKey(key) &&
|
||||
typeof value === "string" &&
|
||||
Buffer.byteLength(value, "utf8") <= secureStorageLimits.maxValueBytes
|
||||
? ipcRenderer.invoke(ipcChannels.saveSecureStorage, key, value)
|
||||
: Promise.reject(new Error("Invalid secure storage key or value.")),
|
||||
delete: (key: string) =>
|
||||
validKey(key)
|
||||
? ipcRenderer.invoke(ipcChannels.deleteSecureStorage, key)
|
||||
: Promise.reject(new Error("Invalid secure storage key.")),
|
||||
clear: () => ipcRenderer.invoke(ipcChannels.clearSecureStorage),
|
||||
},
|
||||
window: {
|
||||
minimize: () => windowAction(ipcChannels.minimizeWindow),
|
||||
maximize: () => windowAction(ipcChannels.maximizeWindow),
|
||||
|
|
|
|||
|
|
@ -26,6 +26,16 @@ export type DesktopCallStatus = {
|
|||
iconDataUrl?: string;
|
||||
};
|
||||
|
||||
export type DesktopSecureStorageStatus = {
|
||||
available: boolean;
|
||||
backend: string | null;
|
||||
};
|
||||
|
||||
export const secureStorageLimits = {
|
||||
maxKeyBytes: 256,
|
||||
maxValueBytes: 1024 * 1024,
|
||||
} as const;
|
||||
|
||||
export type ReleaseArtifact = {
|
||||
name: string;
|
||||
platform: string;
|
||||
|
|
@ -62,4 +72,9 @@ export const ipcChannels = {
|
|||
getVersion: "app:getVersion",
|
||||
checkForUpdates: "updates:checkForUpdates",
|
||||
setCallStatus: "call:setStatus",
|
||||
getSecureStorageStatus: "secureStorage:getStatus",
|
||||
loadSecureStorage: "secureStorage:load",
|
||||
saveSecureStorage: "secureStorage:save",
|
||||
deleteSecureStorage: "secureStorage:delete",
|
||||
clearSecureStorage: "secureStorage:clear",
|
||||
} as const;
|
||||
|
|
|
|||
Loading…
Reference in a new issue