Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
54 changes: 54 additions & 0 deletions apps/desktop/src/app/ClerkTokenStorage.test.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,54 @@
import * as NodeServices from "@effect/platform-node/NodeServices";
import { assert, describe, it } from "@effect/vitest";
import * as HostProcess from "@t3tools/shared/HostProcess";
import * as Effect from "effect/Effect";
import * as FileSystem from "effect/FileSystem";
import { vi } from "vite-plus/test";

vi.mock("electron", () => ({
safeStorage: {
isEncryptionAvailable: () => true,
encryptString: (value: string) => Buffer.from(value),
decryptString: (value: Buffer) => value.toString(),
},
}));

import { storage } from "@clerk/electron/storage";

const fileMode = (path: string) =>
Effect.gen(function* () {
const fileSystem = yield* FileSystem.FileSystem;
const info = yield* fileSystem.stat(path);
return info.mode & 0o777;
});

describe("Clerk token storage", () => {
it.effect("writes the token file readable and writable only by its owner", () =>
Effect.gen(function* () {
if ((yield* HostProcess.Platform) === "win32") return;
const fileSystem = yield* FileSystem.FileSystem;
const stateDir = yield* fileSystem.makeTempDirectoryScoped({ prefix: "t3-clerk-tokens-" });

yield* Effect.promise(async () => {
await storage({ path: stateDir }).setItem("__clerk_client_jwt", "t");
});

assert.equal(yield* fileMode(`${stateDir}/clerk-tokens.json`), 0o600);
}).pipe(Effect.provide(NodeServices.layer), Effect.scoped),
);

it.effect("tightens a token file left world-writable by an earlier version", () =>
Effect.gen(function* () {
if ((yield* HostProcess.Platform) === "win32") return;
const fileSystem = yield* FileSystem.FileSystem;
const stateDir = yield* fileSystem.makeTempDirectoryScoped({ prefix: "t3-clerk-tokens-" });
const tokenFile = `${stateDir}/clerk-tokens.json`;
yield* fileSystem.writeFileString(tokenFile, "{}");
yield* fileSystem.chmod(tokenFile, 0o666);

storage({ path: stateDir });

assert.equal(yield* fileMode(tokenFile), 0o600);
}).pipe(Effect.provide(NodeServices.layer), Effect.scoped),
);
});
43 changes: 43 additions & 0 deletions patches/@clerk__electron@0.0.44.patch
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
diff --git a/dist/cjs/storage/index.js b/dist/cjs/storage/index.js
index 7adc3a0df931931393e2336631f3b3f4c60fdbab..f628e546e5514e039b2bf91e87385d28a4e9c9e2 100644
--- a/dist/cjs/storage/index.js
+++ b/dist/cjs/storage/index.js
@@ -98,8 +98,12 @@ async function resolveCipher() {
function storage(options = {}) {
const store = new electron_store.default({
name: options.name ?? "clerk-tokens",
- ...options.path ? { cwd: options.path } : {}
+ ...options.path ? { cwd: options.path } : {},
+ configFileMode: 0o600
});
+ try {
+ require("node:fs").chmodSync(store.path, 0o600);
+ } catch {}
const memoryFallback = /* @__PURE__ */ new Map();
const mutationVersions = /* @__PURE__ */ new Map();
const beginMutation = (key) => {
diff --git a/dist/esm/storage/index.js b/dist/esm/storage/index.js
index d289bd84ca4dc6a5e2fc4c6b8f9de5bef1d7a175..195996714ecc36d818ecd480fcdeaf8e5a830d4d 100644
--- a/dist/esm/storage/index.js
+++ b/dist/esm/storage/index.js
@@ -1,5 +1,6 @@
import { safeStorage } from "electron";
import Store from "electron-store";
+import { chmodSync } from "node:fs";

//#region src/storage/index.ts
/**
@@ -69,8 +70,12 @@ async function resolveCipher() {
function storage(options = {}) {
const store = new Store({
name: options.name ?? "clerk-tokens",
- ...options.path ? { cwd: options.path } : {}
+ ...options.path ? { cwd: options.path } : {},
+ configFileMode: 0o600
});
+ try {
+ chmodSync(store.path, 0o600);
+ } catch {}
const memoryFallback = /* @__PURE__ */ new Map();
const mutationVersions = /* @__PURE__ */ new Map();
const beginMutation = (key) => {
9 changes: 5 additions & 4 deletions pnpm-lock.yaml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 2 additions & 0 deletions pnpm-workspace.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -287,6 +287,8 @@ patchedDependencies:
expo-glass-effect@58.0.3: patches/expo-glass-effect@58.0.3.patch
expo-blur@58.0.3: patches/expo-blur@58.0.3.patch
expo-audio@58.0.4: patches/expo-audio@58.0.4.patch
# Keep Clerk's token file owner-only; electron-store writes 0666 by default.
"@clerk/electron@0.0.44": patches/@clerk__electron@0.0.44.patch
"@clerk/expo@4.6.8": patches/@clerk__expo@4.6.8.patch
"@effect/vitest@4.0.2": patches/@effect__vitest@4.0.2.patch
"@expo/metro-config@58.0.6": patches/@expo__metro-config@58.0.6.patch
Expand Down