Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Bug][Security] Auth.Store.ts: Zustand persist middleware stores auth state in localStorage, making token and user data accessible to any JavaScript on the page

Open
#128 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Quiet
Tech stack
tauri, typescript

Research direction

Start with src/features/Auth/v1/Store/Auth.Store.ts and inspect how Zustand persist writes the auth token and user data. Review the related Tauri CSP concern and determine whether the intended session flow is memory-only or requires an encrypted store. Done means auth credentials are no longer serialized to plaintext localStorage and the chosen secure re-establishment or persistence behavior is covered.

Written by the indexing model from the issue text.

Description

Bug Summary

src/features/Auth/v1/Store/Auth.Store.ts uses Zustand's persist middleware with the default storage backend, which is localStorage:

const useAuthStore = create<AuthState>()(
  persist(
    (set) => ({
      token: null,
      user: null,
      setAuthData: (user: User) => set({ user }),
      clearAuthData: () => set({ user: null, token: null }),
    }),
    {
      name: "auth-storage",   // key written to localStorage
    },
  ),
);

localStorage is accessible to any JavaScript running in the same origin. In a Tauri application where CSP is disabled (see related issue), this is especially dangerous because injected scripts can read localStorage.getItem('auth-storage') and extract the full auth token and user object without any restriction.

Even with CSP enabled, localStorage is not suitable for storing authentication tokens because:

  1. It is synchronously readable by all JavaScript on the page, including third-party libraries.
  2. It persists indefinitely until explicitly cleared, even after the user closes the application.
  3. It is not HttpOnly -- the fundamental property that makes cookies resistant to XSS-based token theft.

For a Tauri desktop app, sensitive credentials should be stored using Tauri's secure storage plugin (tauri-plugin-stronghold or the OS keychain via tauri-plugin-store with encryption) rather than plaintext localStorage.

Expected Behavior

Auth tokens should not be persisted in localStorage. Session state should be kept in memory only (without the persist middleware) and re-established on app launch via a secure token refresh flow. If persistence is required, use an encrypted store.

Actual Behavior

Auth state (including token and user data) is serialised to plaintext localStorage on every state update.

Affected File

src/features/Auth/v1/Store/Auth.Store.ts


@NexGenStudioDev I would like to work on this issue. Could you please assign/ it to me? Contributing under NSoC '26.

Dominant language
TypeScript
Stars
7
Forks
17
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from NexGenStudioDev/CommDesk

All issues in NexGenStudioDev/CommDesk

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.