Files
hermes-agent/apps
Zeus-Deus e879d133da fix(desktop): allow remote gateway token storage on keyring-less Linux
On Linux without a Secret Service keyring (e.g. Hyprland/Sway with no
GNOME Keyring or KWallet), safeStorage.isEncryptionAvailable() is false,
so saving a remote gateway session token from Settings -> Gateway failed
hard with no in-app way forward.

- encryptDesktopSecret gains an explicit allowPlainText opt-in: when
  secure storage is unavailable and the user confirmed the prompt, the
  token persists as { encoding: 'plain' } in connection.json (which
  decryptDesktopSecret already round-trips).
- Settings -> Gateway now surfaces the opt-in: a destructive confirm
  dialog before persisting a token in plain text, and a persistent
  warning banner while the saved token is stored unencrypted. Localized
  in en/ja/zh/zh-hant.
- The connection-config IPC response reports secureTokenStorage and
  remoteTokenPlainText so the renderer can drive both affordances.
- Launching with --password-store=basic now works: on Linux the app
  calls safeStorage.setUsePlainTextEncryption(true) at startup when the
  switch is set, which Electron requires for the basic backend to count
  as available.
- The no-opt-in error now spells out all three remedies (enable an OS
  keyring, confirm plain-text storage, or use HERMES_DESKTOP_REMOTE_URL/
  HERMES_DESKTOP_REMOTE_TOKEN).

Fixes #62294
2026-07-19 20:25:03 +02:00
..