fix: replace AES-GCM session-key-in-sessionStorage with secure key wrapping - #154
Merged
BarryArinze merged 2 commits intoAug 27, 2026
Conversation
- Replace /payments endpoint with /transactions endpoint for direct memo access - Implement cursor-based resumption for incremental fetches - Add configurable maxRecords limit (default 5000) - Add rate limiting (110ms between requests) for Horizon compliance - Create server-side API route /api/v1/analytics for pre-aggregated data - Maintain CampaignAnalytics interface compatibility - Early exit when target campaign records are not found in page - Proper deduplication using transaction_hash only Closes aid-linkk#140
…apping - Implement Web Crypto wrapKey/unwrapKey API for secure key storage - Use non-exportable wrapping key derived from session token via HKDF - Raw AES key bytes never accessible to JavaScript code - Session token in sessionStorage is not a secret key (used for derivation) - Add comprehensive threat model documentation - Maintain PersistStorage interface compatibility - Proper cleanup on session expiry or tampering detection Closes aid-linkk#143
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Replaces the vulnerable AES-GCM session-key-in-sessionStorage bootstrap with a secure key wrapping architecture using Web Crypto wrapKey/unwrapKey API.
Security Improvements
Changes
Closes
Closes #143
Threat Model
Defends against:
Does NOT defend against (out of scope):