Keep native credential-store completion pending until the frontend accepts it, prevent stale grant races, and isolate blocking keyring work from the UI. Derive sidebar reveal spacing from each custom control style and restore neutral GNOME/minimal hover feedback.
Implement marker-based portable storage, portable WebView and log paths, secure queue and migration sanitization, and Windows portable ZIP validation while preserving the NSIS installer path.
Refs #15
- Revert hydrate_extension_pairing_token to consult the DB's
keychainAccessGranted flag instead of unconditionally skipping the
keychain. When the flag is true the backend tries the keychain; if
macOS trusts the current binary (no code-signature change) the read
succeeds silently and the modal is suppressed. When the flag is
false the keychain is skipped and the modal is shown exactly once.
- Fix the Grant Access button in the KeychainPermissionModal by
writing the result (token, persistent flag) directly into the store
instead of calling hydratePairingToken() again. The re-hydration
raced with Zustand's async persist middleware, which could read
keychainAccessGranted=false from the DB and flip persistent back
to false, re‑showing the modal in an endless loop.
- The scheduler defaults (enabled: false) were already correct in
both the Rust default_settings() and the frontend Zustand store;
no code change needed.