Storing Auth Tokens

Storing BookNest's Auth Token Safely

AuthTokenStore, a Hilt @Singleton, wraps Encrypting Data's encrypted store (auth.bin) in three suspend calls: save(token, validForMillis), current() (the token while unexpired, else null) and clear(). A test stage (--es stage secure) saves a sample token and reads it back; its log and file, read with run-as (debuggable builds only):

Inspecting the encrypted token fileShell
adb -s emulator-5556 shell run-as com.example.booknest ls -l files/datastore
adb -s emulator-5556 shell run-as com.example.booknest od -A d -t x1 -N 48 files/datastore/auth.bin
adb -s emulator-5556 shell run-as com.example.booknest cat files/datastore/auth.bin | strings -n 6
Output
D/BookNestSec( 4257): auth.bin: 90 bytes on disk
D/BookNestSec( 4257): token read back: bn_at_4f9c2e71d0a8
...
-rw------- 1 u0_a216 u0_a216 90 2026-09-25 06:53 auth.bin
0000000 79 f4 85 57 7f 18 2c 0d 10 04 52 31 0a b4 ab 54
0000016 bf 3f 12 6e 52 81 90 9d 7b c1 d5 1e 15 0a 00 11
0000032 60 dc 6e 12 84 32 26 73 cc 1f e2 fe bc ee a5 c4

strings found nothing readable: 12 bytes of IV, 62 of ciphertext (the JSON {"accessToken":...}) and a 16-byte tag. The demo logs the token only to prove the round trip; real code never should. Keep tokens short-lived, and exclude auth.bin from Auto Backup (<exclude domain="file" path="datastore/auth.bin"/>), since a restored copy can't be decrypted anyway.