mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-06 03:38:23 +00:00
Step 5a. SecureKeyStorage's Android actual was EncryptedSharedPreferences from androidx.security.crypto — the same deprecated library, and the same MasterKey.DEFAULT_MASTER_KEY_ALIAS, that EncryptedStorage uses. It now runs on EncryptedDataStore sealed with SecretEncryption, which talks to the AndroidKeyStore directly, so the key still never enters app memory and the library leaves this module. Verified: androidx.security no longer appears on commons' androidCompileClasspath. Worth recording, because it corrects the plan this series was working to: migrating the Android app's private keys *into* SecureKeyStorage would have gained nothing. Both sides were the same deprecated implementation under different filenames. The OS-keychain backing its KDoc describes is the JVM actual, which desktop uses; Android never had it. No migration, and none needed: SecureKeyStorage has 42 references in desktopApp and none in amethyst, so `amethyst_secure_keys` has never been written on an Android install. Were that to change, a migration would have to land first — the class says so. Also fixes a hazard this move would otherwise have introduced. EncryptedDataStore.get() flattens a read failure into null, which is fine for settings but wrong for getPrivateKeyOrThrow — the probe whose whole purpose is telling "no key" apart from "backend failed", used before creating a replacement key. Reading a merely unreadable store as absent there overwrites a live key. getOrThrow() now propagates instead, and a test truncates a store to prove the two reads diverge on it. Not verified here: the Android actual itself. It needs an instrumented test for the real AndroidKeyStore, and this environment has no device or emulator (commons has no Robolectric either). The contract underneath it — EncryptedDataStore over SecretEncryption — is covered by 14 jvmTest cases against the JVM actual. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AXvKXakvup4inNFfAhhr4L