fix(security): move session credentials to sessionStorage#547
fix(security): move session credentials to sessionStorage#547Namraa310806 wants to merge 1 commit into
Conversation
|
@Namraa310806 is attempting to deploy a commit to the firefistisdead's projects Team on Vercel. A member of the Team first needs to authorize it. |
|
Warning Review limit reached
More reviews will be available in 44 minutes and 16 seconds. Learn how PR review limits work. Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file). ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
This PR fixes a security-related credential persistence issue where session credentials were documented as being stored in
sessionStorage, but legacy behavior could still result in credential persistence throughlocalStorage.The implementation now fully aligns with the intended security model by storing session credentials in
sessionStorage, adding a safe migration path for existing users, and introducing regression tests to prevent future regressions.Changes Made
Session Credential Storage
sessionStorage.localStoragefor active session credentials.Legacy Migration Support
localStoragetosessionStorage.localStorage.Data Validation Improvements
Regression Test Coverage
Added tests covering:
sessionStoragelocalStorageentriesSecurity Impact
This change reduces credential exposure by ensuring:
Files Modified
frontend/src/App.jsfrontend/src/App.test.jsVerification Checklist
sessionStoragelocalStoragemigration implementedlocalStorageRelated Issue
Fixes: #499