One read of a device's link: state::credentials, with the client's seal
Five places read the server address and token straight from sync_state: sharing, autosync, sync_unlink, update's download token, and the ffi. Reading it raw is how Android came to send its sealed token to the share routes (#5381). state::credentials(conn, seal) now holds that read. With a seal it opens the token (open_token), and without one (the desktop keeps it plain) it returns it as stored. Every site calls it. DRY pass #2, batch 1, F1 (#5372). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -753,14 +753,8 @@ impl Inkwell {
|
||||
/// it (`state::open_token`), so the app asks to sign in again.
|
||||
fn credentials(&self) -> Result<(String, String), CoreError> {
|
||||
let conn = self.db.conn().map_err(CoreError::store)?;
|
||||
let current = state::read(&conn).map_err(CoreError::store)?;
|
||||
let (Some(url), Some(stored)) = (current.server_url, current.device_token) else {
|
||||
return Err(CoreError::NotLinked);
|
||||
};
|
||||
match state::open_token(&conn, &stored, &self.seal).map_err(CoreError::store)? {
|
||||
Some(token) => Ok((url, token)),
|
||||
None => Err(CoreError::NotLinked),
|
||||
}
|
||||
let link = state::credentials(&conn, Some(&self.seal)).map_err(CoreError::store)?;
|
||||
link.ok_or(CoreError::NotLinked)
|
||||
}
|
||||
|
||||
/// Persist a fresh link, adopting the server's retention window at the same time
|
||||
|
||||
Reference in New Issue
Block a user