3.9 KiB
3.9 KiB
Task: Add remember password to Makelore client
Identity
- Task ID: 20260820-makelore-remember-password-b63e1c
- Mode: Feature
- Branch: codex/20260820-makelore-remember-password-b63e1c-remember-password
- Worktree: D:\w\makelore-remember-password-b63e1c
- Base commit:
1c6b004436 - Owner: codex
- Status: Ready for Integration
Scope
- Add an optional remember-password control to the native password login form.
- Keep remembered credentials in Electron Main and encrypt them with Electron
safeStoragebefore writing them to disk. - Restore remembered credentials on the login page without adding passwords to Renderer persistence or sending the remember flag upstream.
- Cover secure persistence, Host API projection, and login-page behavior with focused tests.
Intent And Constraints
- The feature remembers the username and password themselves; it is separate from the existing seven-day Main-owned login session.
- Works Square remains the authentication authority and must not persist the desktop password.
- Secure persistence is available only where the existing packaged-app credential policy enables OS encryption. Unpackaged development remains memory-only and exposes the control as unavailable.
- SMS login does not modify a previously remembered password. A successful password login with the control cleared removes the remembered credentials.
- Do not add password fields to Zustand/localStorage, logs, or the public token/session projection.
Outcome
- Added a native “记住密码” option to password login. The Renderer reads the Main projection for prefill but does not persist the username or password.
- Added an independent Electron Main credential store backed by
safeStorageandelectron-store. The disk record contains only encrypted ciphertext and is enabled only by the existing packaged-app secure credential policy. - Successful password login saves or clears the record according to the checkbox without forwarding
rememberPasswordto Works Square. SMS login and logout leave the remembered password unchanged. - Unreadable encrypted records are discarded without permanently disabling future saves. An unavailable secure-storage backend projects the feature as disabled.
- Updated README product and architecture descriptions.
Verification
pnpm exec vitest run tests/unit/remembered-password-persistence.test.ts tests/unit/auth-routes.test.ts tests/unit/login-page.test.tsx— 3 files / 54 tests passed.pnpm exec vitest run tests/unit/auth-store.test.ts— 1 file / 25 tests passed.pnpm run typecheck— passed.pnpm exec eslint electron/services/remembered-password.ts electron/api/routes/auth.ts electron/main/index.ts src/pages/Login/index.tsx src/stores/auth.ts tests/unit/remembered-password-persistence.test.ts tests/unit/auth-routes.test.ts tests/unit/login-page.test.tsx— passed.pnpm exec eslint tests/unit/auth-store.test.ts— passed.pnpm run build:vite— passed for Renderer, Electron Main, preload, and utility worker. Existing Vite dynamic-import and large-chunk warnings remain unchanged.git diff --check— passed; Git reported only the repository's LF-to-CRLF checkout warning.
Follow-ups
- Run one packaged Windows and signed macOS smoke to confirm OS-protected save, app restart prefill, successful unremembered-login clear, and the absence of a development Keychain prompt. No packaged artifact or real-account smoke was run in this task.
Promotion Candidates
- On integration, add the remembered-password boundary to
30-worklog/current-state.mdand40-domain/business-rules.md: Main-only OS-encrypted persistence, packaged-app availability, logout preservation, and successful unchecked-password-login clearing. - Consider extending ADR-004 with the separate optional password-record lifecycle; the existing token lifecycle and seven-day inactivity decision remain unchanged.