Solves the core usability problem of zero-knowledge encryption: on page reload the in-memory DEK is lost, so the user can't decrypt their data even though their JWT is still valid. Previously they had to close the tab and re-login from scratch. Changes: - Persist wrapped_dek/wrapped_dek_iv in the auth store (zustand persist). Safe: it's AES-GCM ciphertext, useless without the password KEK — the server already stores the same ciphertext. login/register/recover all save the wrapped DEK; logout clears it. - New UnlockPage: minimal password-only form. Re-derives the DEK locally via unlockWithPassword (no API call — the JWT is still valid). Falls back to deriveAuthAndEncKeys for Phase 1 compat accounts. Links to /login and /recover. - ProtectedRoute now checks hasEncKey() after isAuthenticated: authenticated but no in-memory DEK → redirect to /unlock. - /unlock route in App.tsx (public, alongside login/register/recover). Flow: login → browse → reload page → unlock screen → enter password → dashboard loads with decrypted data. No full re-login needed. Verified: npm build clean, 20 tests pass.
36 lines
1.1 KiB
TypeScript
36 lines
1.1 KiB
TypeScript
import { BrowserRouter, Routes, Route, Navigate } from 'react-router-dom';
|
|
import { LoginPage } from './pages/LoginPage';
|
|
import { RegisterPage } from './pages/RegisterPage';
|
|
import { RecoveryPage } from './pages/RecoveryPage';
|
|
import { UnlockPage } from './pages/UnlockPage';
|
|
import { Dashboard } from './pages/Dashboard';
|
|
import { ProtectedRoute } from './components/common/ProtectedRoute';
|
|
|
|
function App() {
|
|
return (
|
|
<BrowserRouter>
|
|
<Routes>
|
|
{/* Public routes */}
|
|
<Route path="/login" element={<LoginPage />} />
|
|
<Route path="/register" element={<RegisterPage />} />
|
|
<Route path="/recover" element={<RecoveryPage />} />
|
|
<Route path="/unlock" element={<UnlockPage />} />
|
|
|
|
{/* Protected routes */}
|
|
<Route
|
|
path="/"
|
|
element={
|
|
<ProtectedRoute>
|
|
<Dashboard />
|
|
</ProtectedRoute>
|
|
}
|
|
/>
|
|
|
|
{/* Catch-all -> redirect home */}
|
|
<Route path="*" element={<Navigate to="/" replace />} />
|
|
</Routes>
|
|
</BrowserRouter>
|
|
);
|
|
}
|
|
|
|
export default App;
|