fix(security): redact secrets from plaintext persistence

- Strip password, cookies, and headers from download_queue before writing
  to store.bin; secrets remain in-memory for the active session only.
- Move extension pairing token from PersistedSettings to the OS keychain,
  rotating it on upgrade from versions that persisted it as plaintext.
- Add ignores_legacy_extension_pairing_token_field test to confirm serde
  silently drops the old field so existing installs migrate cleanly.
- Document intentional retention of URLs (signed params are the download
  source and cannot be redacted without breaking resume/retry).
This commit is contained in:
NimBold
2026-06-18 08:20:22 +03:30
parent e2dd387a8c
commit 3a76c6f5d7
7 changed files with 105 additions and 13 deletions
+7
View File
@@ -67,6 +67,13 @@ function App() {
useEffect(() => {
useDownloadStore.getState().initDB();
// Hydrate the browser-extension pairing token from the OS keychain before
// the reactive push to the backend. If no token exists (fresh install or
// upgrade from a plaintext-persisting version) a new one is minted and
// stored, effectively rotating it away from any leaked plaintext.
useSettingsStore.getState().hydratePairingToken().catch(error => {
console.error('Failed to hydrate extension pairing token:', error);
});
}, []);
useEffect(() => {