Skip to content

Store authentication tokens in platform-secure storage #11

Description

@koniz-dev

Context

authService writes AUTH_TOKEN through the general-purpose AsyncStorage wrapper. AsyncStorage is not an appropriate protected store for bearer tokens on native devices; the starter should demonstrate a secure default.

Acceptance criteria

  1. On iOS and Android, login tokens are stored, read, and deleted through a platform-secure mechanism (for example Expo SecureStore), not AsyncStorage.
  2. Non-sensitive values, including user profile/cache data, may remain in the existing AsyncStorage wrapper.
  3. The implementation defines and tests behavior when secure storage is unavailable or fails, without treating the user as authenticated.
  4. Documentation distinguishes secure credential storage from general application storage and gives an accurate web-platform caveat.
  5. npm run lint, npm run type-check, and npm run test:ci pass.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestepic:servicesAPI client, auth, storage, hooks, typespriority:P1High prioritystatus:needs-uatAwaiting human verification of criteria

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions