Google Calendar Phase 2: redesign M7 as QR-link auth transfer - #290
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Security Review Conclusion
The original M7 design was blocked: durable synced refresh-token blobs in
calendar_sourcesand the normal encrypted sync pipeline were rejected.Approved redesign: transfer Google refresh tokens only during trusted QR device linking through the existing short-lived encrypted linking session. Tokens remain device-local during normal operation, access tokens never leave the device, and stale devices recover via
Reconnect Googleinstead of durable cross-device token sync.Verification
pnpm --dir apps/desktop exec vitest run --config config/vitest.config.ts src/main/calendar src/main/sync src/main/crypto src/renderer/src/components/calendar src/renderer/src/components/settingspnpm typecheckpnpm ipc:checkpnpm lint(repo-wide warning-only baseline remains; touched Google files were checked clean)Notes
docs/superpowers/specs/2026-04-18-google-calendar-phase-2-design.md