One read of a device's link: state::credentials, with the client's seal
Five places read the server address and token straight from sync_state: sharing, autosync, sync_unlink, update's download token, and the ffi. Reading it raw is how Android came to send its sealed token to the share routes (#5381). state::credentials(conn, seal) now holds that read. With a seal it opens the token (open_token), and without one (the desktop keeps it plain) it returns it as stored. Every site calls it. DRY pass #2, batch 1, F1 (#5372). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -176,8 +176,7 @@ fn backoff(failures: u32) -> Duration {
|
||||
/// The server URL and token, or None when this device isn't linked.
|
||||
fn credentials(db: &Db) -> Result<Option<(String, String)>, String> {
|
||||
let conn = db.conn()?;
|
||||
let current = state::read(&conn).map_err(|e| e.to_string())?;
|
||||
Ok(current.server_url.zip(current.device_token))
|
||||
state::credentials(&conn, None).map_err(|e| e.to_string())
|
||||
}
|
||||
|
||||
/// What is waiting to be sent, as [`push::pending_fingerprint`] sees it. A store
|
||||
|
||||
@@ -136,8 +136,7 @@ pub async fn sync_unlink(db: State<'_, Db>) -> Result<UnlinkResult, String> {
|
||||
// the UI.
|
||||
let link = {
|
||||
let conn = db.conn()?;
|
||||
let current = state::read(&conn).map_err(|e| e.to_string())?;
|
||||
current.server_url.zip(current.device_token)
|
||||
state::credentials(&conn, None).map_err(|e| e.to_string())?
|
||||
};
|
||||
let revoked = match &link {
|
||||
Some((base_url, token)) => client::revoke_self(base_url, token).await,
|
||||
|
||||
@@ -343,13 +343,10 @@ fn read_source(db: &Db) -> Result<Source, String> {
|
||||
/// the link is the one credential this app already holds for it.
|
||||
fn token_for(db: &Db, base: &str) -> Result<Option<String>, String> {
|
||||
let conn = db.conn()?;
|
||||
let link = state::read(&conn).map_err(|e| e.to_string())?;
|
||||
let linked = link.server_url.as_deref().and_then(normalize_server);
|
||||
if linked.as_deref() == Some(base) {
|
||||
Ok(link.device_token)
|
||||
} else {
|
||||
Ok(None)
|
||||
}
|
||||
let Some((url, token)) = state::credentials(&conn, None).map_err(|e| e.to_string())? else {
|
||||
return Ok(None);
|
||||
};
|
||||
Ok((normalize_server(&url).as_deref() == Some(base)).then_some(token))
|
||||
}
|
||||
|
||||
/// An updater pointed at `source`, carrying `token` when there is one. The plugin
|
||||
|
||||
Reference in New Issue
Block a user