Context
authService writes AUTH_TOKEN through the general-purpose AsyncStorage wrapper. AsyncStorage is not an appropriate protected store for bearer tokens on native devices; the starter should demonstrate a secure default.
Acceptance criteria
- On iOS and Android, login tokens are stored, read, and deleted through a platform-secure mechanism (for example Expo SecureStore), not AsyncStorage.
- Non-sensitive values, including user profile/cache data, may remain in the existing AsyncStorage wrapper.
- The implementation defines and tests behavior when secure storage is unavailable or fails, without treating the user as authenticated.
- Documentation distinguishes secure credential storage from general application storage and gives an accurate web-platform caveat.
npm run lint, npm run type-check, and npm run test:ci pass.
Context
authServicewritesAUTH_TOKENthrough the general-purpose AsyncStorage wrapper. AsyncStorage is not an appropriate protected store for bearer tokens on native devices; the starter should demonstrate a secure default.Acceptance criteria
npm run lint,npm run type-check, andnpm run test:cipass.