Description
In src/utils/credentials.ts, the OpenAI API key may be stored in chrome.storage.sync which syncs across all Chrome devices linked to the user's Google account. If any of those devices are compromised, the API key is exposed.
Suggested Fix
- Use
chrome.storage.local (not sync) for sensitive API keys
- Encrypt the key before storage using the Web Crypto API
- Add a note in the UI warning users about API key sensitivity
cc @shouri123
Description
In
src/utils/credentials.ts, the OpenAI API key may be stored inchrome.storage.syncwhich syncs across all Chrome devices linked to the user's Google account. If any of those devices are compromised, the API key is exposed.Suggested Fix
chrome.storage.local(notsync) for sensitive API keyscc @shouri123