fix(web): encrypt localStorage secret key with WebCrypto AES-GCM non-extractable key (Closes #347) - #353
Open
waterWang wants to merge 1 commit into
Open
Conversation
…able key) Replaces the plaintext webStore with a webCryptoStore that encrypts all values before writing to localStorage using AES-GCM with a non-extractable CryptoKey stored in IndexedDB. Key design: - AES-GCM 256-bit key, generated with extractable: false — key material never leaves the WebCrypto subsystem - CryptoKey is persisted in IndexedDB (structured-cloneable) - Each write uses a random 12-byte IV prepended to the ciphertext - Legacy plaintext data (stellar_keypair, micopay_users) is detected and re-encrypted on first load after upgrade - Native (Capacitor) path unchanged — uses @aparajita/capacitor-secure-storage Closes Micopay#347
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements Option B (non-extractable CryptoKey) for the Web/PWA build, replacing the plaintext
localStoragestorage of the Stellar secret key with AES-GCM encryption using a non-extractable WebCrypto key.Changes
micopay/frontend/src/services/secureStorage.tswebCryptoStore— a new KvStore implementation that encrypts all values with AES-GCM before writing tolocalStorage, and decrypts on readextractable: false— the key material can never be exported from the WebCrypto subsystemlocalStorage.stellar_keypairandmicopay_usersentries are detected and re-encrypted on first load after upgrade@aparajita/capacitor-secure-storageSecurity Properties
Acceptance Criteria
secretKeynever written tolocalStoragein plaintextSubtleCryptonon-extractable key for encryptionlocalStorage.stellar_keypairdetected → re-encrypted on next loadreadJSON,writeJSON,removeKey) unchangedCloses #347