Files
amethyst/commons
Claude d2d1d813d1 refactor: drop androidx.security from commons' key storage
Step 5a. SecureKeyStorage's Android actual was EncryptedSharedPreferences
from androidx.security.crypto — the same deprecated library, and the same
MasterKey.DEFAULT_MASTER_KEY_ALIAS, that EncryptedStorage uses. It now
runs on EncryptedDataStore sealed with SecretEncryption, which talks to
the AndroidKeyStore directly, so the key still never enters app memory
and the library leaves this module. Verified: androidx.security no longer
appears on commons' androidCompileClasspath.

Worth recording, because it corrects the plan this series was working to:
migrating the Android app's private keys *into* SecureKeyStorage would
have gained nothing. Both sides were the same deprecated implementation
under different filenames. The OS-keychain backing its KDoc describes is
the JVM actual, which desktop uses; Android never had it.

No migration, and none needed: SecureKeyStorage has 42 references in
desktopApp and none in amethyst, so `amethyst_secure_keys` has never been
written on an Android install. Were that to change, a migration would
have to land first — the class says so.

Also fixes a hazard this move would otherwise have introduced.
EncryptedDataStore.get() flattens a read failure into null, which is fine
for settings but wrong for getPrivateKeyOrThrow — the probe whose whole
purpose is telling "no key" apart from "backend failed", used before
creating a replacement key. Reading a merely unreadable store as absent
there overwrites a live key. getOrThrow() now propagates instead, and a
test truncates a store to prove the two reads diverge on it.

Not verified here: the Android actual itself. It needs an instrumented
test for the real AndroidKeyStore, and this environment has no device or
emulator (commons has no Robolectric either). The contract underneath it
— EncryptedDataStore over SecretEncryption — is covered by 14 jvmTest
cases against the JVM actual.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AXvKXakvup4inNFfAhhr4L
2026-09-23 20:14:04 +00:00
..