Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

[Bug][Security] Auth.Store.ts: Zustand persist middleware stores auth state in localStorage, making token and user data accessible to any JavaScript on the page

未关闭
#128 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
35/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
冷清
技术栈
tauri, typescript

调研方向

Start with src/features/Auth/v1/Store/Auth.Store.ts and inspect how Zustand persist writes the auth token and user data. Review the related Tauri CSP concern and determine whether the intended session flow is memory-only or requires an encrypted store. Done means auth credentials are no longer serialized to plaintext localStorage and the chosen secure re-establishment or persistence behavior is covered.

由索引模型根据 Issue 内容生成。

描述

Bug Summary

src/features/Auth/v1/Store/Auth.Store.ts uses Zustand's persist middleware with the default storage backend, which is localStorage:

const useAuthStore = create<AuthState>()(
  persist(
    (set) => ({
      token: null,
      user: null,
      setAuthData: (user: User) => set({ user }),
      clearAuthData: () => set({ user: null, token: null }),
    }),
    {
      name: "auth-storage",   // key written to localStorage
    },
  ),
);

localStorage is accessible to any JavaScript running in the same origin. In a Tauri application where CSP is disabled (see related issue), this is especially dangerous because injected scripts can read localStorage.getItem('auth-storage') and extract the full auth token and user object without any restriction.

Even with CSP enabled, localStorage is not suitable for storing authentication tokens because:

  1. It is synchronously readable by all JavaScript on the page, including third-party libraries.
  2. It persists indefinitely until explicitly cleared, even after the user closes the application.
  3. It is not HttpOnly -- the fundamental property that makes cookies resistant to XSS-based token theft.

For a Tauri desktop app, sensitive credentials should be stored using Tauri's secure storage plugin (tauri-plugin-stronghold or the OS keychain via tauri-plugin-store with encryption) rather than plaintext localStorage.

Expected Behavior

Auth tokens should not be persisted in localStorage. Session state should be kept in memory only (without the persist middleware) and re-established on app launch via a secure token refresh flow. If persistence is required, use an encrypted store.

Actual Behavior

Auth state (including token and user data) is serialised to plaintext localStorage on every state update.

Affected File

src/features/Auth/v1/Store/Auth.Store.ts


@NexGenStudioDev I would like to work on this issue. Could you please assign/ it to me? Contributing under NSoC '26.

主要语言
TypeScript
星标
7
派生
17
PR 合并指标
30 天内没有已合并 PR

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

NexGenStudioDev/CommDesk 的其他 Issue

查看 NexGenStudioDev/CommDesk 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。