fix(auth): store bearer tokens in native credentials

This commit is contained in:
2026-07-10 07:57:44 -04:00
parent 34ac842078
commit 94afa23a69
26 changed files with 2316 additions and 286 deletions
+10 -6
View File
@@ -3,6 +3,7 @@ use std::{
time::{SystemTime, UNIX_EPOCH},
};
use ely_domain::ProfileId;
use ely_sync_client::{
AccountKey, ApiClientConfig, AuthenticatedSnapshotHead, BearerToken, BearerTokenStore,
DeviceIdentity, SNAPSHOT_ENCRYPTION_VERSION, SnapshotCryptoContext, SnapshotDownloadResult,
@@ -34,6 +35,7 @@ impl SyncEngine {
/// fresh device identity on first use, then keeps it stable across
/// runs so the server's `user_devices` row stays bound.
pub fn for_profile_dir(
profile_id: &ProfileId,
profile_data_dir: &Path,
device_name: impl Into<String>,
platform: impl Into<String>,
@@ -46,7 +48,7 @@ impl SyncEngine {
.join(".sync-key-locks");
let identity =
DeviceIdentity::load_or_create(&sync_dir.join("device.json"), device_name, platform)?;
let bearer_store = BearerTokenStore::new(sync_dir.join("bearer.token"));
let bearer_store = BearerTokenStore::new(profile_id, profile_data_dir);
Ok(Self {
api_config: ApiClientConfig::production(),
bearer_store,
@@ -60,10 +62,6 @@ impl SyncEngine {
&self.identity
}
pub fn bearer_path(&self) -> &Path {
self.bearer_store.path()
}
pub fn last_outcome(&self) -> Option<&SyncOutcome> {
self.last_outcome.as_ref()
}
@@ -436,6 +434,7 @@ fn device_registration_idempotency_key(identity: &DeviceIdentity) -> String {
#[derive(Debug)]
pub struct SyncEngineBuilder {
pub profile_id: ProfileId,
pub profile_data_dir: PathBuf,
pub device_name: String,
pub platform: String,
@@ -443,7 +442,12 @@ pub struct SyncEngineBuilder {
impl SyncEngineBuilder {
pub fn build(self) -> Result<SyncEngine, SyncClientError> {
SyncEngine::for_profile_dir(&self.profile_data_dir, self.device_name, self.platform)
SyncEngine::for_profile_dir(
&self.profile_id,
&self.profile_data_dir,
self.device_name,
self.platform,
)
}
}
+11
View File
@@ -38,6 +38,17 @@ fn default_sync_status_reflects_local_browser_state() -> Result<(), Box<dyn Erro
Ok(())
}
#[test]
fn unavailable_credentials_disable_cloud_uploads() -> Result<(), Box<dyn Error>> {
let mut core = BrowserCore::new(InitialBrowserConfig::ely_defaults()?)?;
core.set_sync_connection_state(SyncConnectionState::CredentialUnavailable {
message: "credential unavailable".to_string(),
});
assert!(!core.cloud_sync_upload_enabled());
Ok(())
}
#[test]
fn sync_object_policy_pauses_object_kind() -> Result<(), Box<dyn Error>> {
let mut core = BrowserCore::new(InitialBrowserConfig::ely_defaults()?)?;