fix: store GitHub API token encrypted via SecretStore (AES-256-GCM) - #116
Open
mock1ngbb wants to merge 1 commit into
Open
fix: store GitHub API token encrypted via SecretStore (AES-256-GCM)#116mock1ngbb wants to merge 1 commit into
mock1ngbb wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The Problem
The GitHub API token (personal access token) is stored as plaintext in
settings.jsonalongside the app binary. This means:<app>/settings.jsonhas full use of the tokenThe GitHub API token is used to authenticate requests to the GitHub API. With a plaintext token on disk, the credential boundary is reduced to "can this process read a JSON file?" — which is nearly everything on a desktop OS.
The Fix
1. Encrypted token storage (
Services/SecretStore.cs)~/.local/share/GithubLauncher/outside the app directory2. JsonIgnore on AppSettings (
Services/AppSettings.cs)GitHubApiTokengains[System.Text.Json.Serialization.JsonIgnore]— it is never serialized tosettings.jsonSecretStore.ReadToken()/SecretStore.WriteToken()3. Password masking (
MainWindow.axaml.cs)PasswordChar = '*'— the token is masked in the UISecretStore(decrypted in memory)4. Direct SecretStore access (
Models/GameInfo.cs)GetGitHubApiToken()reads directly fromSecretStore.ReadToken()instead of re-loadingAppSettings.Load()every callBackward Compatibility
settings.jsonwill be ignored (the[JsonIgnore]property won't read from JSON)SecretStoreSecurity Trade-offs
~/.local/share/GithubLauncher/\*can decrypt the token. This is still strictly better than plaintext in the app directory where any process or user-accessible path can read it