feat: Phase 3+4 — security hardening + polish + offline + Electron push
Phase 3 (security): - P3.1: Feature gate server-side enforcement (403 on disabled features) - P3.2: Unified auth error interceptor (401→logout) - P3.3: Store-level state isolation via StoreSnapshot contract (added message-list-tabs + task stores to snapshot/restore cycle) - P3.4: Push event bus extraction — email-store no longer imports calendar/contact/filter/file stores directly - P1.3: Auth localStorage AES-GCM encryption via custom Zustand adapter Phase 4 (polish): - P4.1: Offline write queue — pending operations in localStorage, auto-retry on reconnect, offline-queue-indicator banner - P4.2: Identity spoofing — fromOverrideEmail domain validation - P4.3: WebSocket push for Electron via main-process IPC bridge (ws package with Authorization headers)
This commit is contained in:
@@ -1,5 +1,6 @@
|
||||
import { create } from 'zustand';
|
||||
import { persist } from 'zustand/middleware';
|
||||
import { persist, createJSONStorage } from 'zustand/middleware';
|
||||
import { encryptedStorage } from '@/stores/encrypted-storage';
|
||||
import { JMAPClient, RateLimitError } from '@/lib/jmap/client';
|
||||
import { withOfflineFallback } from '@/lib/offline-fallback-client';
|
||||
import type { IJMAPClient } from '@/lib/jmap/client-interface';
|
||||
@@ -2010,6 +2011,7 @@ export const useAuthStore = create<AuthState>()(
|
||||
}),
|
||||
{
|
||||
name: 'auth-storage',
|
||||
storage: createJSONStorage(() => encryptedStorage),
|
||||
partialize: (state) => {
|
||||
// Don't persist unauthenticated state - prevents resurrecting stale sessions
|
||||
if (!state.isAuthenticated) return {};
|
||||
|
||||
Reference in New Issue
Block a user