⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 288501 in webkit


Ignore:
Timestamp:
Jan 24, 2022, 5:55:01 PM (5 years ago)
Author:
Russell Epstein
Message:

Cherry-pick r288010. rdar://problem/87557846

Expose way to encode CTAP commands with only the hash of ClientDataJSON
​https://bugs.webkit.org/show_bug.cgi?id=235191
<rdar://problem/87557846>

Reviewed by Brent Fulgham.

Source/WebKit:

CTAP command encoding covered by existing tests (see CtapRequestTest) and the SPI
in new API tests.

  • UIProcess/API/Cocoa/_WKWebAuthenticationPanel.h:
  • UIProcess/API/Cocoa/_WKWebAuthenticationPanel.mm: (+[_WKWebAuthenticationPanel encodeMakeCredentialCommandWithClientDataHash:options:userVerificationAvailability:]): (+[_WKWebAuthenticationPanel encodeGetAssertionCommandWithClientDataHash:options:userVerificationAvailability:]):

Tools:

  • TestWebKitAPI/Tests/WebKitCocoa/_WKWebAuthenticationPanel.mm: (TestWebKitAPI::TEST): Tests for new SPIs.

git-svn-id: ​https://svn.webkit.org/repository/webkit/trunk@288010 268f45cc-cd09-0410-ab3c-d52691b4dbfc

Location:
branches/safari-613-branch
Files:
5 edited

Legend:

Unmodified
Added
Removed
  • branches/safari-613-branch/Source/WebKit/ChangeLog

    r288321 r288501  
     12022-01-24  Alan Coon  <alancoon@apple.com>
     2
     3        Cherry-pick r288010. rdar://problem/87557846
     4
     5    Expose way to encode CTAP commands with only the hash of ClientDataJSON
     6    https://bugs.webkit.org/show_bug.cgi?id=235191
     7    <rdar://problem/87557846>
     8   
     9    Reviewed by Brent Fulgham.
     10   
     11    Source/WebKit:
     12   
     13    CTAP command encoding covered by existing tests (see CtapRequestTest) and the SPI
     14    in new API tests.
     15   
     16    * UIProcess/API/Cocoa/_WKWebAuthenticationPanel.h:
     17    * UIProcess/API/Cocoa/_WKWebAuthenticationPanel.mm:
     18    (+[_WKWebAuthenticationPanel encodeMakeCredentialCommandWithClientDataHash:options:userVerificationAvailability:]):
     19    (+[_WKWebAuthenticationPanel encodeGetAssertionCommandWithClientDataHash:options:userVerificationAvailability:]):
     20   
     21    Tools:
     22   
     23    * TestWebKitAPI/Tests/WebKitCocoa/_WKWebAuthenticationPanel.mm:
     24    (TestWebKitAPI::TEST):
     25    Tests for new SPIs.
     26   
     27   
     28    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@288010 268f45cc-cd09-0410-ab3c-d52691b4dbfc
     29
     30    2022-01-14  J Pascoe  <j_pascoe@apple.com>
     31
     32            Expose way to encode CTAP commands with only the hash of ClientDataJSON
     33            https://bugs.webkit.org/show_bug.cgi?id=235191
     34            <rdar://problem/87557846>
     35
     36            Reviewed by Brent Fulgham.
     37
     38            CTAP command encoding covered by existing tests (see CtapRequestTest) and the SPI
     39            in new API tests.
     40
     41            * UIProcess/API/Cocoa/_WKWebAuthenticationPanel.h:
     42            * UIProcess/API/Cocoa/_WKWebAuthenticationPanel.mm:
     43            (+[_WKWebAuthenticationPanel encodeMakeCredentialCommandWithClientDataHash:options:userVerificationAvailability:]):
     44            (+[_WKWebAuthenticationPanel encodeGetAssertionCommandWithClientDataHash:options:userVerificationAvailability:]):
     45
    1462022-01-20  Russell Epstein  <repstein@apple.com>
    247
  • branches/safari-613-branch/Source/WebKit/UIProcess/API/Cocoa/_WKWebAuthenticationPanel.h

    r286746 r288501  
    124124+ (NSData *)encodeGetAssertionCommandWithClientDataJSON:(NSData *)clientDataJSON options:(_WKPublicKeyCredentialRequestOptions *)options userVerificationAvailability:(_WKWebAuthenticationUserVerificationAvailability)userVerificationAvailability WK_API_AVAILABLE(macos(WK_MAC_TBA), ios(WK_IOS_TBA));
    125125
     126+ (NSData *)encodeMakeCredentialCommandWithClientDataHash:(NSData *)clientDataHash options:(_WKPublicKeyCredentialCreationOptions *)options userVerificationAvailability:(_WKWebAuthenticationUserVerificationAvailability)userVerificationAvailability WK_API_AVAILABLE(macos(WK_MAC_TBA), ios(WK_IOS_TBA));
     127+ (NSData *)encodeGetAssertionCommandWithClientDataHash:(NSData *)clientDataHash options:(_WKPublicKeyCredentialRequestOptions *)options userVerificationAvailability:(_WKWebAuthenticationUserVerificationAvailability)userVerificationAvailability WK_API_AVAILABLE(macos(WK_MAC_TBA), ios(WK_IOS_TBA));
     128
    126129- (instancetype)init;
    127130
  • branches/safari-613-branch/Source/WebKit/UIProcess/API/Cocoa/_WKWebAuthenticationPanel.mm

    r287116 r288501  
    712712}
    713713
     714
     715+ (NSData *)encodeMakeCredentialCommandWithClientDataHash:(NSData *)clientDataHash options:(_WKPublicKeyCredentialCreationOptions *)options userVerificationAvailability:(_WKWebAuthenticationUserVerificationAvailability)userVerificationAvailability
     716{
     717    RetainPtr<NSData> encodedCommand;
     718#if ENABLE(WEB_AUTHN)
     719    auto encodedVector = fido::encodeMakeCredenitalRequestAsCBOR(vectorFromNSData(clientDataHash), [_WKWebAuthenticationPanel convertToCoreCreationOptionsWithOptions:options], coreUserVerificationAvailability(userVerificationAvailability), std::nullopt);
     720    encodedCommand = adoptNS([[NSData alloc] initWithBytes:encodedVector.data() length:encodedVector.size()]);
     721#endif
     722
     723    return encodedCommand.autorelease();
     724}
     725
     726+ (NSData *)encodeGetAssertionCommandWithClientDataHash:(NSData *)clientDataHash options:(_WKPublicKeyCredentialRequestOptions *)options userVerificationAvailability:(_WKWebAuthenticationUserVerificationAvailability)userVerificationAvailability
     727{
     728    RetainPtr<NSData> encodedCommand;
     729#if ENABLE(WEB_AUTHN)
     730    auto encodedVector = fido::encodeGetAssertionRequestAsCBOR(vectorFromNSData(clientDataHash), [_WKWebAuthenticationPanel convertToCoreRequestOptionsWithOptions:options], coreUserVerificationAvailability(userVerificationAvailability), std::nullopt);
     731    encodedCommand = adoptNS([[NSData alloc] initWithBytes:encodedVector.data() length:encodedVector.size()]);
     732#endif
     733
     734    return encodedCommand.autorelease();
     735}
     736
    714737- (void)setMockConfiguration:(NSDictionary *)configuration
    715738{
  • branches/safari-613-branch/Tools/ChangeLog

    r288318 r288501  
     12022-01-24  Alan Coon  <alancoon@apple.com>
     2
     3        Cherry-pick r288010. rdar://problem/87557846
     4
     5    Expose way to encode CTAP commands with only the hash of ClientDataJSON
     6    https://bugs.webkit.org/show_bug.cgi?id=235191
     7    <rdar://problem/87557846>
     8   
     9    Reviewed by Brent Fulgham.
     10   
     11    Source/WebKit:
     12   
     13    CTAP command encoding covered by existing tests (see CtapRequestTest) and the SPI
     14    in new API tests.
     15   
     16    * UIProcess/API/Cocoa/_WKWebAuthenticationPanel.h:
     17    * UIProcess/API/Cocoa/_WKWebAuthenticationPanel.mm:
     18    (+[_WKWebAuthenticationPanel encodeMakeCredentialCommandWithClientDataHash:options:userVerificationAvailability:]):
     19    (+[_WKWebAuthenticationPanel encodeGetAssertionCommandWithClientDataHash:options:userVerificationAvailability:]):
     20   
     21    Tools:
     22   
     23    * TestWebKitAPI/Tests/WebKitCocoa/_WKWebAuthenticationPanel.mm:
     24    (TestWebKitAPI::TEST):
     25    Tests for new SPIs.
     26   
     27   
     28    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@288010 268f45cc-cd09-0410-ab3c-d52691b4dbfc
     29
     30    2022-01-14  J Pascoe  <j_pascoe@apple.com>
     31
     32            Expose way to encode CTAP commands with only the hash of ClientDataJSON
     33            https://bugs.webkit.org/show_bug.cgi?id=235191
     34            <rdar://problem/87557846>
     35
     36            Reviewed by Brent Fulgham.
     37
     38            * TestWebKitAPI/Tests/WebKitCocoa/_WKWebAuthenticationPanel.mm:
     39            (TestWebKitAPI::TEST):
     40            Tests for new SPIs.
     41
    1422022-01-20  Russell Epstein  <repstein@apple.com>
    243
  • branches/safari-613-branch/Tools/TestWebKitAPI/Tests/WebKitCocoa/_WKWebAuthenticationPanel.mm

    r287360 r288501  
    21692169}
    21702170
     2171TEST(WebAuthenticationPanel, EncodeCTAPAssertion)
     2172{
     2173    uint8_t hash[] = { 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04 };
     2174    auto nsHash = adoptNS([[NSData alloc] initWithBytes:hash length:sizeof(hash)]);
     2175    auto options = adoptNS([[_WKPublicKeyCredentialRequestOptions alloc] init]);
     2176
     2177    auto *command = [_WKWebAuthenticationPanel encodeGetAssertionCommandWithClientDataHash:nsHash.get() options: options.get() userVerificationAvailability:_WKWebAuthenticationUserVerificationAvailabilityNotSupported];
     2178
     2179    // Base64 of the following CBOR:
     2180    // 2, {1: "", 2: h'0102030401020304010203040102030401020304010203040102030401020304', 5: {"up": true}}
     2181    EXPECT_WK_STREQ([command base64EncodedStringWithOptions:0], "AqMBYAJYIAECAwQBAgMEAQIDBAECAwQBAgMEAQIDBAECAwQBAgMEBaFidXD1");
     2182}
     2183
     2184TEST(WebAuthenticationPanel, EncodeCTAPCreation)
     2185{
     2186    uint8_t hash[] = { 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04 };
     2187    auto nsHash = adoptNS([[NSData alloc] initWithBytes:hash length:sizeof(hash)]);
     2188    uint8_t identifier[] = { 0x01, 0x02, 0x03, 0x04 };
     2189    NSData *nsIdentifier = [NSData dataWithBytes:identifier length:sizeof(identifier)];
     2190    auto parameters = adoptNS([[_WKPublicKeyCredentialParameters alloc] initWithAlgorithm:@-7]);
     2191
     2192    auto rp = adoptNS([[_WKPublicKeyCredentialRelyingPartyEntity alloc] initWithName:@"example.com"]);
     2193    auto user = adoptNS([[_WKPublicKeyCredentialUserEntity alloc] initWithName:@"jappleseed@example.com" identifier:nsIdentifier displayName:@"J Appleseed"]);
     2194    NSArray<_WKPublicKeyCredentialParameters *> *publicKeyCredentialParamaters = @[ parameters.get() ];
     2195
     2196    auto options = adoptNS([[_WKPublicKeyCredentialCreationOptions alloc] initWithRelyingParty:rp.get() user:user.get() publicKeyCredentialParamaters:publicKeyCredentialParamaters]);
     2197
     2198    auto *command = [_WKWebAuthenticationPanel encodeMakeCredentialCommandWithClientDataHash:nsHash.get() options: options.get() userVerificationAvailability:_WKWebAuthenticationUserVerificationAvailabilityNotSupported];
     2199
     2200    // Base64 of the following CBOR:
     2201    // 1, {1: h'0102030401020304010203040102030401020304010203040102030401020304', 2: {"name": "example.com"}, 3: {"id": h'01020304', "name": "jappleseed@example.com", "displayName": "J Appleseed"}, 4: [{"alg": -7, "type": "public-key"}]}
     2202    EXPECT_WK_STREQ([command base64EncodedStringWithOptions:0], "AaQBWCABAgMEAQIDBAECAwQBAgMEAQIDBAECAwQBAgMEAQIDBAKhZG5hbWVrZXhhbXBsZS5jb20Do2JpZEQBAgMEZG5hbWV2amFwcGxlc2VlZEBleGFtcGxlLmNvbWtkaXNwbGF5TmFtZWtKIEFwcGxlc2VlZASBomNhbGcmZHR5cGVqcHVibGljLWtleQ==");
     2203}
     2204
    21712205TEST(WebAuthenticationPanel, UpdateCredentialUsername)
    21722206{
Note: See TracChangeset for help on using the changeset viewer.