[Bug][Security] Auth.Store.ts: Zustand persist middleware stores auth state in localStorage, making token and user data accessible to any JavaScript on the page
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 35/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 冷清
- 技术栈
- tauri, typescript
调研方向
Start with src/features/Auth/v1/Store/Auth.Store.ts and inspect how Zustand persist writes the auth token and user data. Review the related Tauri CSP concern and determine whether the intended session flow is memory-only or requires an encrypted store. Done means auth credentials are no longer serialized to plaintext localStorage and the chosen secure re-establishment or persistence behavior is covered.
由索引模型根据 Issue 内容生成。
描述
Bug Summary
src/features/Auth/v1/Store/Auth.Store.ts uses Zustand's persist middleware with the default storage backend, which is localStorage:
const useAuthStore = create<AuthState>()(
persist(
(set) => ({
token: null,
user: null,
setAuthData: (user: User) => set({ user }),
clearAuthData: () => set({ user: null, token: null }),
}),
{
name: "auth-storage", // key written to localStorage
},
),
);
localStorage is accessible to any JavaScript running in the same origin. In a Tauri application where CSP is disabled (see related issue), this is especially dangerous because injected scripts can read localStorage.getItem('auth-storage') and extract the full auth token and user object without any restriction.
Even with CSP enabled, localStorage is not suitable for storing authentication tokens because:
- It is synchronously readable by all JavaScript on the page, including third-party libraries.
- It persists indefinitely until explicitly cleared, even after the user closes the application.
- It is not HttpOnly -- the fundamental property that makes cookies resistant to XSS-based token theft.
For a Tauri desktop app, sensitive credentials should be stored using Tauri's secure storage plugin (tauri-plugin-stronghold or the OS keychain via tauri-plugin-store with encryption) rather than plaintext localStorage.
Expected Behavior
Auth tokens should not be persisted in localStorage. Session state should be kept in memory only (without the persist middleware) and re-established on app launch via a secure token refresh flow. If persistence is required, use an encrypted store.
Actual Behavior
Auth state (including token and user data) is serialised to plaintext localStorage on every state update.
Affected File
src/features/Auth/v1/Store/Auth.Store.ts
@NexGenStudioDev I would like to work on this issue. Could you please assign/ it to me? Contributing under NSoC '26.
- 主要语言
- TypeScript
- 星标
- 7
- 派生
- 17
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
NexGenStudioDev/CommDesk 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 68/100
NexGenStudioDev/CommDesk#140 ·
-
难度 2/5 1-3 小时 新手友好度 68/100
NexGenStudioDev/CommDesk#138 ·
-
难度 2/5 1-3 小时 新手友好度 76/100
NexGenStudioDev/CommDesk#130 · 2 条评论 ·
-
难度 2/5 1-3 小时 新手友好度 72/100
NexGenStudioDev/CommDesk#123 · 2 条评论 ·
-
[UX] Hardcoded window dimensions not DPI-aware — UI broken on high-DPI displays可能重新可做 @anshul23102 于 83 天前认领,目前没有进行中的 PR。 未关闭
NexGenStudioDev/CommDesk#141 · 已指派 1 人 ·
查看 NexGenStudioDev/CommDesk 的全部 Issue
相似的 Issue
-
needs:triage
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复
-
ai-discovered
难度 2/5 1-3 小时 新手友好度 83/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 88/100
jessepollak/home#1627 ·
维护者通常 1 天内回复
-
agent-canvas bug llm priority:low ready-for-dev
难度 2/5 1-3 小时 新手友好度 82/100
OpenHands/OpenHands#17806 · 3 条评论 ·
维护者通常 1 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 76/100
radius-project/ai-extensions#923 ·
维护者通常 1 天内回复