Update dependency eu.anifantakis:ksafe to v3.3.0 - #1047
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.2.0→3.3.0Release Notes
ioannisa/ksafe (eu.anifantakis:ksafe)
v3.3.0Compare Source
Added
(#37). Every typed call was
inlinewith areifiedtype, so the type had to be known at the place KSafe was called. A generic layer inbetween — an app-level
SecureStoreyou inject and replace with a fake in unit tests — did notcompile ("Cannot use 'T' as reified type parameter").
get,getDirect,getFlow,getStateFlow,putandputDirectnow each have a non-inline overload that takes aKSerializer<T>right after the value, with the samemodeandonWriteFailedoptions:ksafe.put("user", user, User.serializer()). They run the same code as the reified calls andshare their entries, so either form reads what the other wrote. For a nullable
T, pass anullable serializer (
String.serializer().nullable): the serializer, not the default, decideswhether a stored
nullreads back asnull. The reified API is unchanged and the change isbinary-compatible (additions only). The mode-typed views and the delegates stay reified, because
their type is fixed where they are declared. The pattern, with a fake for unit tests, is in
docs/USAGE.md.
Fixed
With an
appNamespaceset, KSafe copies the existing un-namespaced store into the namespacedirectory on the first launch. When that copy failed (a full disk, an antivirus lock, a
permission error), 3.2.0 ran the session from the un-namespaced store itself. On the default
base directory that store is shared by every un-namespaced KSafe app of the same OS user, so the
session's writes could overwrite another app's values and its
clearAll()wiped another app'sdata. The session now starts empty in its own namespace directory and leaves the shared store
untouched. The next launch whose copy succeeds brings the data back and replaces what the
session wrote, unless the session called
clearAll(), which stays in effect. A store that anolder namespace spelling of the same app left behind is not shared, so a session still runs
from it.
under an older namespace. When the bridge to the OS key vault failed to load for one session,
that session minted a provisional key and kept it locally. On the next healthy launch, KSafe
checked only the current namespace for a real key before moving the provisional one into the OS
vault. A real key that still sat under an older namespace (the launcher-derived one, or a
namespace spelled differently by an older release) was not found, so the provisional key took
its place and every value written before that session became permanently unreadable. KSafe now
also checks the older namespaces before it moves a provisional key in. When it finds the real
key, the real key wins and the provisional key is kept, so values from both sides of the failure
still read.
Android 9 to 14 without a secure lock screen, KSafe mints a
requireUnlockedDevicekey withoutthe lock-screen binding and records that in the store, so
protectionInfo.notescan sayandroid_lock_screen_absent. Android Auto Backup and device transfer restore the store but notthe Keystore keys. On the new device KSafe minted a properly bound key, but the restored record
stayed, so the note was reported for the life of the store although no unbound key existed. A
bound mint now removes the record for its alias. The note was diagnostic only: no key was weaker
than reported.
permissive
verifyBiometriccall returnstruewithout a prompt when Windows Hello is notavailable or not configured; the same holds on macOS and Windows when the native bridge failed
to load. That answer is unchanged, but with an
authorizationDurationit also filled theauthorization cache as if the user had authenticated. If the user then set up Windows Hello in
the same session, the next call in that scope returned
truewith no prompt until the durationran out, although no one had ever authenticated. A pass-through now leaves the cache empty, so
the next call prompts.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.