[Bug][Security] Auth.Store.ts: Zustand persist middleware stores auth state in localStorage, making token and user data accessible to any JavaScript on the page
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Quiet
- Tech stack
- tauri, typescript
- Domain
- authentication, desktop, security
Research direction
Start with src/features/Auth/v1/Store/Auth.Store.ts and inspect how Zustand persist writes the auth token and user data. Review the related Tauri CSP concern and determine whether the intended session flow is memory-only or requires an encrypted store. Done means auth credentials are no longer serialized to plaintext localStorage and the chosen secure re-establishment or persistence behavior is covered.
Written by the indexing model from the issue text.
Description
Bug Summary
src/features/Auth/v1/Store/Auth.Store.ts uses Zustand's persist middleware with the default storage backend, which is localStorage:
const useAuthStore = create<AuthState>()(
persist(
(set) => ({
token: null,
user: null,
setAuthData: (user: User) => set({ user }),
clearAuthData: () => set({ user: null, token: null }),
}),
{
name: "auth-storage", // key written to localStorage
},
),
);
localStorage is accessible to any JavaScript running in the same origin. In a Tauri application where CSP is disabled (see related issue), this is especially dangerous because injected scripts can read localStorage.getItem('auth-storage') and extract the full auth token and user object without any restriction.
Even with CSP enabled, localStorage is not suitable for storing authentication tokens because:
- It is synchronously readable by all JavaScript on the page, including third-party libraries.
- It persists indefinitely until explicitly cleared, even after the user closes the application.
- It is not HttpOnly -- the fundamental property that makes cookies resistant to XSS-based token theft.
For a Tauri desktop app, sensitive credentials should be stored using Tauri's secure storage plugin (tauri-plugin-stronghold or the OS keychain via tauri-plugin-store with encryption) rather than plaintext localStorage.
Expected Behavior
Auth tokens should not be persisted in localStorage. Session state should be kept in memory only (without the persist middleware) and re-established on app launch via a secure token refresh flow. If persistence is required, use an encrypted store.
Actual Behavior
Auth state (including token and user data) is serialised to plaintext localStorage on every state update.
Affected File
src/features/Auth/v1/Store/Auth.Store.ts
@NexGenStudioDev I would like to work on this issue. Could you please assign/ it to me? Contributing under NSoC '26.
- Dominant language
- TypeScript
- Stars
- 7
- Forks
- 17
- PR merge metrics
- No merged PRs in 30d
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from NexGenStudioDev/CommDesk
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
NexGenStudioDev/CommDesk#140 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
NexGenStudioDev/CommDesk#138 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
NexGenStudioDev/CommDesk#130 · 2 comments ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
NexGenStudioDev/CommDesk#123 · 2 comments ·
-
[UX] Hardcoded window dimensions not DPI-aware — UI broken on high-DPI displaysPossibly taken @anshul23102 claimed this 89 days ago. Open
NexGenStudioDev/CommDesk#141 · 1 assignee ·
All issues in NexGenStudioDev/CommDesk
Similar issues
-
area:docs bug triage:confirmed
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
Cotal-AI/Cotal#2875 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
anomalyco/models.dev#8862 · 1 comment ·
Maintainers usually reply within 1 day
-
fix(data-lake): wizard source step still previews the local slug, not the server-disambiguated onePossibly taken A pull request linked to this issue is open or already merged. Opendata-lake
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
ready-for-triage
Difficulty 1/5 Under an hour Newbie friendliness 88/100
konflux-ci/konflux-ui#1596 · 1 comment ·
Maintainers usually reply within 1 day
-
enhancement good first issue priority: low size: XS
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Maintainers usually reply within 1 day