Files
makelore/.project-docs/30-worklog/tasks/20260820-makelore-remember-password-b63e1c.md

3.9 KiB

Task: Add remember password to Makelore client

Identity

  • Task ID: 20260820-makelore-remember-password-b63e1c
  • Mode: Feature
  • Branch: codex/20260820-makelore-remember-password-b63e1c-remember-password
  • Worktree: D:\w\makelore-remember-password-b63e1c
  • Base commit: 1c6b004436
  • Owner: codex
  • Status: Ready for Integration

Scope

  • Add an optional remember-password control to the native password login form.
  • Keep remembered credentials in Electron Main and encrypt them with Electron safeStorage before writing them to disk.
  • Restore remembered credentials on the login page without adding passwords to Renderer persistence or sending the remember flag upstream.
  • Cover secure persistence, Host API projection, and login-page behavior with focused tests.

Intent And Constraints

  • The feature remembers the username and password themselves; it is separate from the existing seven-day Main-owned login session.
  • Works Square remains the authentication authority and must not persist the desktop password.
  • Secure persistence is available only where the existing packaged-app credential policy enables OS encryption. Unpackaged development remains memory-only and exposes the control as unavailable.
  • SMS login does not modify a previously remembered password. A successful password login with the control cleared removes the remembered credentials.
  • Do not add password fields to Zustand/localStorage, logs, or the public token/session projection.

Outcome

  • Added a native “记住密码” option to password login. The Renderer reads the Main projection for prefill but does not persist the username or password.
  • Added an independent Electron Main credential store backed by safeStorage and electron-store. The disk record contains only encrypted ciphertext and is enabled only by the existing packaged-app secure credential policy.
  • Successful password login saves or clears the record according to the checkbox without forwarding rememberPassword to Works Square. SMS login and logout leave the remembered password unchanged.
  • Unreadable encrypted records are discarded without permanently disabling future saves. An unavailable secure-storage backend projects the feature as disabled.
  • Updated README product and architecture descriptions.

Verification

  • pnpm exec vitest run tests/unit/remembered-password-persistence.test.ts tests/unit/auth-routes.test.ts tests/unit/login-page.test.tsx — 3 files / 54 tests passed.
  • pnpm exec vitest run tests/unit/auth-store.test.ts — 1 file / 25 tests passed.
  • pnpm run typecheck — passed.
  • pnpm exec eslint electron/services/remembered-password.ts electron/api/routes/auth.ts electron/main/index.ts src/pages/Login/index.tsx src/stores/auth.ts tests/unit/remembered-password-persistence.test.ts tests/unit/auth-routes.test.ts tests/unit/login-page.test.tsx — passed.
  • pnpm exec eslint tests/unit/auth-store.test.ts — passed.
  • pnpm run build:vite — passed for Renderer, Electron Main, preload, and utility worker. Existing Vite dynamic-import and large-chunk warnings remain unchanged.
  • git diff --check — passed; Git reported only the repository's LF-to-CRLF checkout warning.

Follow-ups

  • Run one packaged Windows and signed macOS smoke to confirm OS-protected save, app restart prefill, successful unremembered-login clear, and the absence of a development Keychain prompt. No packaged artifact or real-account smoke was run in this task.

Promotion Candidates

  • On integration, add the remembered-password boundary to 30-worklog/current-state.md and 40-domain/business-rules.md: Main-only OS-encrypted persistence, packaged-app availability, logout preservation, and successful unchecked-password-login clearing.
  • Consider extending ADR-004 with the separate optional password-record lifecycle; the existing token lifecycle and seven-day inactivity decision remain unchanged.