One read of a device's link: state::credentials, with the client's seal
Five places read the server address and token straight from sync_state: sharing, autosync, sync_unlink, update's download token, and the ffi. Reading it raw is how Android came to send its sealed token to the share routes (#5381). state::credentials(conn, seal) now holds that read. With a seal it opens the token (open_token), and without one (the desktop keeps it plain) it returns it as stored. Every site calls it. DRY pass #2, batch 1, F1 (#5372). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -175,6 +175,27 @@ pub fn open_token(
|
||||
Ok(Some(stored.to_string()))
|
||||
}
|
||||
|
||||
/// The server address and the token to send it, or None when this device isn't
|
||||
/// linked. The ONE read of a link for a call to the server: every client goes
|
||||
/// through here, so none can send a token as stored when it is sealed (#5381).
|
||||
///
|
||||
/// With a `seal`, the stored token is opened ([`open_token`]); a client without one
|
||||
/// (the desktop keeps its token plain) passes None and gets it as stored.
|
||||
pub fn credentials(
|
||||
conn: &Connection,
|
||||
seal: Option<&dyn TokenSeal>,
|
||||
) -> rusqlite::Result<Option<(String, String)>> {
|
||||
let link = read(conn)?;
|
||||
let (Some(url), Some(stored)) = (link.server_url, link.device_token) else {
|
||||
return Ok(None);
|
||||
};
|
||||
let token = match seal {
|
||||
Some(seal) => open_token(conn, &stored, seal)?,
|
||||
None => Some(stored),
|
||||
};
|
||||
Ok(token.map(|token| (url, token)))
|
||||
}
|
||||
|
||||
/// Replace the stored token alone, leaving the server and cursor as they are.
|
||||
fn store_token(conn: &Connection, token: Option<&str>) -> rusqlite::Result<()> {
|
||||
conn.execute(
|
||||
|
||||
Reference in New Issue
Block a user