e879d133da
On Linux without a Secret Service keyring (e.g. Hyprland/Sway with no
GNOME Keyring or KWallet), safeStorage.isEncryptionAvailable() is false,
so saving a remote gateway session token from Settings -> Gateway failed
hard with no in-app way forward.
- encryptDesktopSecret gains an explicit allowPlainText opt-in: when
secure storage is unavailable and the user confirmed the prompt, the
token persists as { encoding: 'plain' } in connection.json (which
decryptDesktopSecret already round-trips).
- Settings -> Gateway now surfaces the opt-in: a destructive confirm
dialog before persisting a token in plain text, and a persistent
warning banner while the saved token is stored unencrypted. Localized
in en/ja/zh/zh-hant.
- The connection-config IPC response reports secureTokenStorage and
remoteTokenPlainText so the renderer can drive both affordances.
- Launching with --password-store=basic now works: on Linux the app
calls safeStorage.setUsePlainTextEncryption(true) at startup when the
switch is set, which Electron requires for the basic backend to count
as available.
- The no-opt-in error now spells out all three remedies (enable an OS
keyring, confirm plain-text storage, or use HERMES_DESKTOP_REMOTE_URL/
HERMES_DESKTOP_REMOTE_TOKEN).
Fixes #62294