-
Notifications
You must be signed in to change notification settings - Fork 0
Authentication profiles: durable login state across restarts #155
Copy link
Copy link
Closed
Labels
area:linux-hostChromium host (LinuxHost/, CDP)Chromium host (LinuxHost/, CDP)area:macos-hostWKWebView host (main.swift, Host/)WKWebView host (main.swift, Host/)priority:highBlocks a roadmap phaseBlocks a roadmap phasestatus:needs-designRequires an architecture-decision entry firstRequires an architecture-decision entry firsttype:featureNew capability or commandNew capability or commandtype:securitySecurity boundary or hardeningSecurity boundary or hardening
Description
Activity
Metadata
Metadata
Assignees
Labels
area:linux-hostChromium host (LinuxHost/, CDP)Chromium host (LinuxHost/, CDP)area:macos-hostWKWebView host (main.swift, Host/)WKWebView host (main.swift, Host/)priority:highBlocks a roadmap phaseBlocks a roadmap phasestatus:needs-designRequires an architecture-decision entry firstRequires an architecture-decision entry firsttype:featureNew capability or commandNew capability or commandtype:securitySecurity boundary or hardeningSecurity boundary or hardening
Problem
Normal sessions share browser state, but persistence is not equivalent across engines. WKWebView uses persistent website storage, while Linux places Chromium's profile under the runtime directory. Linux login state therefore lacks a durable cross-reboot contract.
Proposed contract
Define a normal-profile storage location and lifecycle for both engines. Cookies and storage should survive host and machine restarts until the user clears them, logs out, or chooses a nonpersistent context.
Linux should use an XDG data location with a private directory, atomic setup, migration from the current runtime profile where safe, single-owner locking, and corruption recovery. macOS behavior should be made explicit and tested rather than relying on an implicit default.
Boundaries
Profile directories remain per-user and inaccessible to other users. No cookie import or unrestricted profile-path option is introduced. Sensitive diagnostics remain double-gated. Private contexts are handled by #35 and must never inherit normal profile state.
This changes persistence behavior and requires an architecture-decision entry.
Acceptance criteria