fix(security): harden auth and secret handling (HH-444) (#101)

* fix(security): harden auth and credential handling (HH-444)

* fix(security): address HH-444 review blockers

* fix(security): close remaining HH-444 review blockers

---------

Co-authored-by: Rogee <rogee@ipao.vip>
This commit is contained in:
Rogee
2026-08-22 15:45:06 +08:00
committed by GitHub
co-authored by rogee
parent e1557e7f21
commit f719529d66
81 changed files with 2149 additions and 474 deletions
@@ -38,23 +38,6 @@ window.globalConfig = Object.assign(
window.errorLoggingConfig = '';
window.browserConfig = { browser_name: navigator.userAgent };
try {
const sessionCookie = document.cookie
.split('; ')
.find(cookie => cookie.startsWith('cw_d_session_info='));
if (sessionCookie) {
const raw = decodeURIComponent(sessionCookie.split('=').slice(1).join('='));
const extract = key =>
raw.match(new RegExp(`"${key}":"([^"]+)"`))?.[1] || '';
const token = extract('access-token');
if (token) {
localStorage.setItem('access-token', token);
localStorage.setItem('client', extract('client'));
localStorage.setItem('uid', extract('uid'));
localStorage.setItem('token-type', extract('token-type') || 'Bearer');
localStorage.setItem('expiry', extract('expiry'));
}
}
} catch {
// Ignore malformed legacy session cookies.
}
['access-token', 'client', 'uid', 'token-type', 'expiry'].forEach(key =>
localStorage.removeItem(key)
);