Capawesome 178,914 's Secure Preferences is the drop-in replacement Ionic 20,753 names for its Secure Storage (Secure Storage Wind-Down). Its API mirrors Preferences, and per its documentation it encrypts each value with AES-256-GCM under a Keystore key into CAPAWESOME_SECURE_PREFERENCES.xml on Android, stores Keychain items with kSecAttrAccessibleWhenUnlocked on iOS, and falls back to unencrypted localStorage on the web, for development only:
import { SecurePreferences } from '@capawesome-team/capacitor-secure-preferences';
await SecurePreferences.set({ key: 'refreshToken', value: 'eyJhbGciOi...' });
const { value } = await SecurePreferences.get({ key: 'refreshToken' });It is an Insiders plugin (Capawesome): npm 2,036 view @capawesome-team/capacitor-secure-preferences returns 404 from the public registry, because it installs from Capawesome's private registry with a license key. BookNest therefore uses an MIT-licensed plugin with the same design, github.com/aparajita/capacitor-secure-storage (https://github.com/aparajita/capacitor-secure-storage 169 ) (npm install @aparajita/capacitor-secure-storage, version 8.0.1), whose SecureStorage.set() appears in Preferences Isn't Secure. Its Java code creates one AES/GCM/NoPadding key per entry in the AndroidKeyStore and writes Base64 ciphertext, a separator character (0x10, escaped by the XML writer as ) and the random IV:
adb -s emulator-5558 shell run-as com.example.booknest \
cat shared_prefs/WSSecureStorageSharedPreferences.xml<?xml version='1.0' encoding='utf-8' standalone='yes' ?>
<map>
<string name="capacitor-storage_authToken">wCh/v7/tmfGuXDbGPDHCOzdBhAfp2ZmUIwsmEPzCOKpSzw&#
16;N7C06L9kQMHiXjY/</string>
</map>The file is still readable, but useless without the Keystore key, which cannot be exported, so a backup or a copied file reveals nothing; inside the app, SecureStorage.get() returned bn_live_7f3a9c21. On Android the key belongs to this install, so the secret is gone after a reinstall or on a new phone: treat it as a cache of something the server can issue again.