fix(desktop): select Windows encryption profile before startup yields - #14265
widingmarcus-cyber wants to merge 1 commit into
Conversation
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This Windows startup change selects the Electron encryption profile earlier and initializes safeStorage before readiness, affecting decryption of locally stored connection data and credentials. Despite its narrow scope and focused tests, the sensitive-data runtime impact warrants human review. You can add or adjust custom eligibility rules. Learn more. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: pingdotgg/t3code/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughOn Windows, startup selects a legacy profile when it exists and otherwise uses the current profile. It sets Electron’s ChangesWindows startup profile selection
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~12 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant DesktopPreReadyPlatform
participant fs.statSync
participant Electron.app
participant safeStorage
DesktopPreReadyPlatform->>fs.statSync: Inspect the legacy profile
fs.statSync-->>DesktopPreReadyPlatform: Return whether the profile exists
DesktopPreReadyPlatform->>Electron.app: Set userData to the selected profile
DesktopPreReadyPlatform->>Electron.app: Register the ready listener
Electron.app->>safeStorage: Check encryption availability on ready
Suggested reviewers: Merge Risk: ⚪ Minimal · up to On Windows, startup now chooses the existing legacy or current profile directory before startup can yield to Electron readiness, and checks encryption availability once Electron is ready. A fresh install still starts normally, because Electron accepts a profile directory that does not exist yet. No outstanding issues block merging. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change addresses a sensitive startup-ordering issue for encrypted local data. The reviewed paths do not establish a new remote route to that data, but handling of an error during the new readiness check remains uncertain. Retained concerns
Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
What Changed
Select the existing Windows Electron
userDataprofile synchronously inDesktopPreReadyPlatform, before asynchronous startup can yield to Electron readiness. Initialize safeStorage availability onreadywith that profile selected.Preserve the existing legacy/current and development/packaged profile choices and APPDATA/home fallback. A filesystem error inspecting the legacy profile is not treated as a missing profile. Linux and macOS behavior is unchanged.
Why
Addresses #8341; related to #13656.
A Windows Alpha 0.0.42 installation repeatedly reported
decrypt-catalogfailures and displayed no projects. The same encrypted catalogs were successfully decrypted using the existing Windows Local State key in an isolated Electron process. A local installed-app patch selecting the profile before asynchronous startup and initializing secure storage after ready restored the existing project without resetting the catalog, and passed two consecutive restarts.This points to startup ordering as a contributor, but does not establish the exact intermittent trigger or explain the original crash. This PR moves that ordering into the existing pre-ready setup. It does not reset, migrate, or back up credentials. #13656 separately proposes recovery after a decryption failure; this PR is independent of it and preserves the existing catalog.
Validation
Checklist
Prepared with GPT-6 in the Codex desktop harness.
Summary by CodeRabbit