Changeset 292176 in webkit
- Timestamp:
- Mar 31, 2022, 2:22:25 PM (5 years ago)
- Location:
- branches/safari-613-branch
- Files:
-
- 3 added
- 20 edited
-
LayoutTests/ChangeLog (modified) (1 diff)
-
LayoutTests/http/wpt/webauthn/public-key-credential-cross-origin.https-expected.txt (added)
-
LayoutTests/http/wpt/webauthn/public-key-credential-cross-origin.https.html (added)
-
LayoutTests/http/wpt/webauthn/public-key-credential-same-origin-with-ancestors.https-expected.txt (modified) (1 diff)
-
LayoutTests/http/wpt/webauthn/public-key-credential-same-origin-with-ancestors.https.html (modified) (2 diffs)
-
LayoutTests/http/wpt/webauthn/resources/public-key-credential-cross-origin.https.html (added)
-
Source/WebCore/ChangeLog (modified) (1 diff)
-
Source/WebCore/Modules/credentialmanagement/CredentialsContainer.cpp (modified) (3 diffs)
-
Source/WebCore/Modules/credentialmanagement/CredentialsContainer.h (modified) (1 diff)
-
Source/WebCore/Modules/webauthn/AuthenticatorCoordinator.cpp (modified) (6 diffs)
-
Source/WebCore/Modules/webauthn/AuthenticatorCoordinator.h (modified) (2 diffs)
-
Source/WebCore/Modules/webauthn/AuthenticatorCoordinatorClient.h (modified) (3 diffs)
-
Source/WebKit/ChangeLog (modified) (1 diff)
-
Source/WebKit/Platform/spi/Cocoa/AuthenticationServicesCoreSPI.h (modified) (1 diff)
-
Source/WebKit/UIProcess/API/Cocoa/_WKWebAuthenticationPanel.mm (modified) (4 diffs)
-
Source/WebKit/UIProcess/WebAuthentication/Cocoa/WebAuthenticatorCoordinatorProxy.mm (modified) (4 diffs)
-
Source/WebKit/UIProcess/WebAuthentication/WebAuthenticationRequestData.h (modified) (2 diffs)
-
Source/WebKit/UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.cpp (modified) (2 diffs)
-
Source/WebKit/UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.h (modified) (1 diff)
-
Source/WebKit/UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.messages.in (modified) (1 diff)
-
Source/WebKit/WebAuthnProcess/WebAuthnConnectionToWebProcess.cpp (modified) (1 diff)
-
Source/WebKit/WebProcess/WebAuthentication/WebAuthenticatorCoordinator.cpp (modified) (3 diffs)
-
Source/WebKit/WebProcess/WebAuthentication/WebAuthenticatorCoordinator.h (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
branches/safari-613-branch/LayoutTests/ChangeLog
r292089 r292176 1 2022-03-31 Alan Coon <alancoon@apple.com> 2 3 Apply patch. rdar://problem/90957317 4 5 2022-03-08 J Pascoe <j_pascoe@apple.com> 6 7 [WebAuthn] Using WebAuthn within cross-origin iframe elements 8 https://bugs.webkit.org/show_bug.cgi?id=222240 9 rdar://problem/74830748 10 11 Reviewed by Brent Fulgham. 12 13 Update existing tests and create new test for cross-origin, non same-site i-frames. 14 15 * http/wpt/webauthn/public-key-credential-cross-origin.https-expected.txt: Added. 16 * http/wpt/webauthn/public-key-credential-cross-origin.https.html: Added. 17 * http/wpt/webauthn/public-key-credential-same-origin-with-ancestors.https-expected.txt: 18 * http/wpt/webauthn/public-key-credential-same-origin-with-ancestors.https.html: 19 * http/wpt/webauthn/resources/public-key-credential-cross-origin.https.html: Added. 20 1 21 2022-03-29 Russell Epstein <repstein@apple.com> 2 22 -
branches/safari-613-branch/LayoutTests/http/wpt/webauthn/public-key-credential-same-origin-with-ancestors.https-expected.txt
r287116 r292176 5 5 PASS Tests that a frame that is same-site, cross-origin without publickey-credentials-get feature policy cannot use get(). 6 6 PASS Tests that a frame that is same-site, cross-origin with publickey-credentials-get feature policy can use get(). 7 PASS Tests that a frame that is cross-origin, NOT same-sitewith publickey-credentials-get feature policy cannot use get().7 PASS Tests that a frame using an ip address that is cross-origin, NOT same-site with publickey-credentials-get feature policy cannot use get(). 8 8 -
branches/safari-613-branch/LayoutTests/http/wpt/webauthn/public-key-credential-same-origin-with-ancestors.https.html
r287116 r292176 1 <!DOCTYPE html><!-- webkit-test-runner [ WebAuthenticationModernEnabled= true ] -->1 <!DOCTYPE html><!-- webkit-test-runner [ WebAuthenticationModernEnabled=false ] --> 2 2 <html> 3 3 <head> … … 38 38 promise_test(t => { 39 39 return withCrossOriginIframe("samesite-iframe.html", "publickey-credentials-get").then((message) => { 40 assert_equals(message.data, "Throw NotAllowedError: The origin of the document is not the same as its ancestors.");40 assert_equals(message.data, "Throw SecurityError: The effective domain of the document is not a valid domain."); 41 41 }); 42 }, "Tests that a frame that is cross-origin, NOT same-sitewith publickey-credentials-get feature policy cannot use get().");42 }, "Tests that a frame using an ip address that is cross-origin, NOT same-site with publickey-credentials-get feature policy cannot use get()."); 43 43 </script> 44 44 </body> -
branches/safari-613-branch/Source/WebCore/ChangeLog
r292093 r292176 1 2022-03-31 Alan Coon <alancoon@apple.com> 2 3 Apply patch. rdar://problem/90957317 4 5 2022-03-08 J Pascoe <j_pascoe@apple.com> 6 7 [WebAuthn] Using WebAuthn within cross-origin iframe elements 8 https://bugs.webkit.org/show_bug.cgi?id=222240 9 rdar://problem/74830748 10 11 Reviewed by Brent Fulgham. 12 13 This patch relaxes the requirement to perform a Web Authentication assertion 14 inside an i-frame with the "publickey-credentials-get" feature policy from 15 'same-site' to 'cross-origin with consent'. 16 17 There is an additional requirement that there is only a single cross-origin 18 parent to present to the user in the prompt. If we can't display the updated 19 prompt, then cross-origin assertions are not allowed. 20 21 Test: http/wpt/webauthn/public-key-credential-cross-origin.https.html 22 23 * Modules/credentialmanagement/CredentialsContainer.cpp: 24 (WebCore::CredentialsContainer::scopeAndSingleParent): 25 (WebCore::CredentialsContainer::get): 26 (WebCore::CredentialsContainer::isCreate): 27 (WebCore::CredentialsContainer::scope): Deleted. 28 * Modules/credentialmanagement/CredentialsContainer.h: 29 * Modules/webauthn/AuthenticatorCoordinator.cpp: 30 (WebCore::AuthenticatorCoordinator::discoverFromExternalSource const): 31 * Modules/webauthn/AuthenticatorCoordinator.h: 32 * Modules/webauthn/AuthenticatorCoordinatorClient.h: 33 1 34 2022-03-29 Alan Coon <alancoon@apple.com> 2 35 -
branches/safari-613-branch/Source/WebCore/Modules/credentialmanagement/CredentialsContainer.cpp
r287116 r292176 47 47 } 48 48 49 WebAuthn::Scope CredentialsContainer::scope() 49 ScopeAndCrossOriginParent CredentialsContainer::scopeAndCrossOriginParent() const 50 50 { 51 51 if (!m_document) 52 return WebAuthn::Scope::CrossOrigin;52 return std::pair { WebAuthn::Scope::CrossOrigin, std::nullopt }; 53 53 54 bool isSameOrigin = true;55 54 bool isSameSite = true; 56 55 auto& origin = m_document->securityOrigin(); 57 56 auto& url = m_document->url(); 57 std::optional<SecurityOriginData> crossOriginParent; 58 58 for (auto* document = m_document->parentDocument(); document; document = document->parentDocument()) { 59 59 if (!origin.isSameOriginDomain(document->securityOrigin()) && !areRegistrableDomainsEqual(url, document->url())) 60 60 isSameSite = false; 61 if (! origin.isSameOriginAs(document->securityOrigin()))62 isSameOrigin = false;61 if (!crossOriginParent && !origin.isSameOriginAs(document->securityOrigin())) 62 crossOriginParent = origin.data(); 63 63 } 64 64 65 if ( isSameOrigin)66 return WebAuthn::Scope::SameOrigin;65 if (!crossOriginParent) 66 return std::pair { WebAuthn::Scope::SameOrigin, std::nullopt }; 67 67 if (isSameSite) 68 return WebAuthn::Scope::SameSite;69 return WebAuthn::Scope::CrossOrigin;68 return std::pair { WebAuthn::Scope::SameSite, std::nullopt }; 69 return std::pair { WebAuthn::Scope::CrossOrigin, crossOriginParent }; 70 70 } 71 71 … … 99 99 } 100 100 101 m_document->page()->authenticatorCoordinator().discoverFromExternalSource(*m_document, options.publicKey.value(), scope(), WTFMove(options.signal), WTFMove(promise));101 m_document->page()->authenticatorCoordinator().discoverFromExternalSource(*m_document, WTFMove(options), scopeAndCrossOriginParent(), WTFMove(promise)); 102 102 } 103 103 … … 134 134 } 135 135 136 m_document->page()->authenticatorCoordinator().create(*m_document, options.publicKey.value(), scope (), WTFMove(options.signal), WTFMove(promise));136 m_document->page()->authenticatorCoordinator().create(*m_document, options.publicKey.value(), scopeAndCrossOriginParent().first, WTFMove(options.signal), WTFMove(promise)); 137 137 } 138 138 -
branches/safari-613-branch/Source/WebCore/Modules/credentialmanagement/CredentialsContainer.h
r287116 r292176 59 59 CredentialsContainer(WeakPtr<Document>&&); 60 60 61 WebAuthn::Scope scope();61 ScopeAndCrossOriginParent scopeAndCrossOriginParent() const; 62 62 63 63 WeakPtr<Document> m_document; -
branches/safari-613-branch/Source/WebCore/Modules/webauthn/AuthenticatorCoordinator.cpp
r292089 r292176 37 37 #include "FeaturePolicy.h" 38 38 #include "JSBasicCredential.h" 39 #include "JSCredentialRequestOptions.h" 39 40 #include "JSDOMPromiseDeferred.h" 40 41 #include "PublicKeyCredential.h" … … 183 184 } 184 185 185 void AuthenticatorCoordinator::discoverFromExternalSource(const Document& document, const PublicKeyCredentialRequestOptions& options, WebAuthn::Scope scope, RefPtr<AbortSignal>&& abortSignal, CredentialPromise&& promise) const186 void AuthenticatorCoordinator::discoverFromExternalSource(const Document& document, CredentialRequestOptions&& requestOptions, const ScopeAndCrossOriginParent& scopeAndCrossOriginParent, CredentialPromise&& promise) const 186 187 { 187 188 using namespace AuthenticatorCoordinatorInternal; … … 189 190 auto& callerOrigin = document.securityOrigin(); 190 191 auto* frame = document.frame(); 192 const auto& options = requestOptions.publicKey.value(); 191 193 ASSERT(frame); 192 194 // The following implements https://www.w3.org/TR/webauthn/#createCredential as of 5 December 2017. 193 195 // Step 1, 3, 13 are handled by the caller. 194 196 // Step 2. 195 // This implements https://www.w3.org/TR/webauthn-2/#sctn-permissions-policy except only same-site, cross-origin is permitted.196 if (scope != WebAuthn::Scope::SameOrigin && !(scope == WebAuthn::Scope::SameSite && isFeaturePolicyAllowedByDocumentAndAllOwners(FeaturePolicy::Type::PublickeyCredentialsGetRule, document, LogFeaturePolicyFailure::No))) {197 // This implements https://www.w3.org/TR/webauthn-2/#sctn-permissions-policy 198 if (scopeAndCrossOriginParent.first != WebAuthn::Scope::SameOrigin && !isFeaturePolicyAllowedByDocumentAndAllOwners(FeaturePolicy::Type::PublickeyCredentialsGetRule, document, LogFeaturePolicyFailure::No)) { 197 199 promise.reject(Exception { NotAllowedError, "The origin of the document is not the same as its ancestors."_s }); 198 200 return; … … 228 230 229 231 // Step 10-12. 230 auto clientDataJson = buildClientDataJson(ClientDataType::Get, options.challenge, callerOrigin, scope );232 auto clientDataJson = buildClientDataJson(ClientDataType::Get, options.challenge, callerOrigin, scopeAndCrossOriginParent.first); 231 233 auto clientDataJsonHash = buildClientDataJsonHash(clientDataJson); 232 234 … … 237 239 } 238 240 239 auto callback = [clientDataJson = WTFMove(clientDataJson), promise = WTFMove(promise), abortSignal = WTFMove( abortSignal)] (AuthenticatorResponseData&& data, AuthenticatorAttachment attachment, ExceptionData&& exception) mutable {241 auto callback = [clientDataJson = WTFMove(clientDataJson), promise = WTFMove(promise), abortSignal = WTFMove(requestOptions.signal)] (AuthenticatorResponseData&& data, AuthenticatorAttachment attachment, ExceptionData&& exception) mutable { 240 242 if (abortSignal && abortSignal->aborted()) { 241 243 promise.reject(Exception { AbortError, "Aborted by AbortSignal."_s }); … … 252 254 }; 253 255 // Async operations are dispatched and handled in the messenger. 254 m_client->getAssertion(*frame, callerOrigin, clientDataJsonHash, options, WTFMove(callback));256 m_client->getAssertion(*frame, callerOrigin, clientDataJsonHash, options, scopeAndCrossOriginParent, WTFMove(callback)); 255 257 } 256 258 -
branches/safari-613-branch/Source/WebCore/Modules/webauthn/AuthenticatorCoordinator.h
r287116 r292176 46 46 struct PublicKeyCredentialRequestOptions; 47 47 48 struct CredentialRequestOptions; 49 struct SecurityOriginData; 50 48 51 template<typename IDLType> class DOMPromiseDeferred; 49 52 50 53 using CredentialPromise = DOMPromiseDeferred<IDLNullable<IDLInterface<BasicCredential>>>; 54 using ScopeAndCrossOriginParent = std::pair<WebAuthn::Scope, std::optional<SecurityOriginData>>; 51 55 52 56 class AuthenticatorCoordinator final { … … 59 63 // The following methods implement static methods of PublicKeyCredential. 60 64 void create(const Document&, const PublicKeyCredentialCreationOptions&, WebAuthn::Scope, RefPtr<AbortSignal>&&, CredentialPromise&&) const; 61 void discoverFromExternalSource(const Document&, const PublicKeyCredentialRequestOptions&, WebAuthn::Scope, RefPtr<AbortSignal>&&, CredentialPromise&&) const; 65 66 void discoverFromExternalSource(const Document&, CredentialRequestOptions&& requestOptions, const ScopeAndCrossOriginParent&, CredentialPromise&&) const; 62 67 void isUserVerifyingPlatformAuthenticatorAvailable(DOMPromiseDeferred<IDLBoolean>&&) const; 63 68 -
branches/safari-613-branch/Source/WebCore/Modules/webauthn/AuthenticatorCoordinatorClient.h
r278358 r292176 28 28 #if ENABLE(WEB_AUTHN) 29 29 30 #include "AuthenticatorCoordinator.h" 30 31 #include "ExceptionData.h" 31 32 #include <wtf/CompletionHandler.h> 32 33 #include <wtf/WeakPtr.h> 34 35 namespace WebAuthn { 36 enum class Scope; 37 } 33 38 34 39 namespace WebCore { … … 43 48 struct PublicKeyCredentialCreationOptions; 44 49 struct PublicKeyCredentialRequestOptions; 50 struct SecurityOriginData; 45 51 46 52 using RequestCompletionHandler = CompletionHandler<void(WebCore::AuthenticatorResponseData&&, WebCore::AuthenticatorAttachment, WebCore::ExceptionData&&)>; … … 54 60 virtual ~AuthenticatorCoordinatorClient() = default; 55 61 56 virtual void makeCredential(const Frame&, const SecurityOrigin&, const Vector<uint8_t>&, const PublicKeyCredentialCreationOptions&, RequestCompletionHandler&&) { };57 virtual void getAssertion(const Frame&, const SecurityOrigin&, const Vector<uint8_t>&, const PublicKeyCredentialRequestOptions&, RequestCompletionHandler&&) { };58 virtual void isUserVerifyingPlatformAuthenticatorAvailable(QueryCompletionHandler&&) { };62 virtual void makeCredential(const Frame&, const SecurityOrigin&, const Vector<uint8_t>&, const PublicKeyCredentialCreationOptions&, RequestCompletionHandler&&) = 0; 63 virtual void getAssertion(const Frame&, const SecurityOrigin&, const Vector<uint8_t>&, const PublicKeyCredentialRequestOptions&, const ScopeAndCrossOriginParent&, RequestCompletionHandler&&) = 0; 64 virtual void isUserVerifyingPlatformAuthenticatorAvailable(QueryCompletionHandler&&) = 0; 59 65 60 66 virtual void resetUserGestureRequirement() { } -
branches/safari-613-branch/Source/WebKit/ChangeLog
r292129 r292176 1 2022-03-31 Alan Coon <alancoon@apple.com> 2 3 Apply patch. rdar://problem/90957317 4 5 2022-03-08 J Pascoe <j_pascoe@apple.com> 6 7 [WebAuthn] Using WebAuthn within cross-origin iframe elements 8 https://bugs.webkit.org/show_bug.cgi?id=222240 9 rdar://problem/74830748 10 11 Reviewed by Brent Fulgham. 12 13 This patch relaxes the requirement to perform a Web Authentication assertion 14 inside an i-frame with the "publickey-credentials-get" feature policy from 15 'same-site' to 'cross-origin with consent'. 16 17 There is an additional requirement that there is only a single cross-origin 18 parent to present to the user in the prompt. If we can't display the updated 19 prompt, then cross-origin assertions are not allowed. 20 21 * Platform/spi/Cocoa/AuthenticationServicesCoreSPI.h: 22 * UIProcess/WebAuthentication/Cocoa/WebAuthenticatorCoordinatorProxy.mm: 23 (WebKit::configureAssertionOptions): 24 (WebKit::configurationAssertionRequestContext): 25 (WebKit::WebAuthenticatorCoordinatorProxy::contextForRequest): 26 * UIProcess/WebAuthentication/WebAuthenticationRequestData.h: 27 * UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.cpp: 28 (WebKit::WebAuthenticatorCoordinatorProxy::makeCredential): 29 (WebKit::WebAuthenticatorCoordinatorProxy::getAssertion): 30 (WebKit::WebAuthenticatorCoordinatorProxy::handleRequest): 31 * UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.h: 32 * UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.messages.in: 33 * WebProcess/WebAuthentication/WebAuthenticatorCoordinator.cpp: 34 (WebKit::WebAuthenticatorCoordinator::getAssertion): 35 * WebProcess/WebAuthentication/WebAuthenticatorCoordinator.h: 36 1 37 2022-03-29 Alan Coon <alancoon@apple.com> 2 38 -
branches/safari-613-branch/Source/WebKit/Platform/spi/Cocoa/AuthenticationServicesCoreSPI.h
r288852 r292176 168 168 @property (nonatomic, nullable, readonly, copy) NSArray<ASCPublicKeyCredentialDescriptor *> *allowedCredentials; 169 169 170 @property (nonatomic, nullable, copy) NSString *destinationSiteForCrossSiteAssertion; 171 170 172 @end 171 173 -
branches/safari-613-branch/Source/WebKit/UIProcess/API/Cocoa/_WKWebAuthenticationPanel.mm
r288852 r292176 584 584 }); 585 585 }; 586 _panel->handleRequest({ WTFMove(hash), [_WKWebAuthenticationPanel convertToCoreCreationOptionsWithOptions:options], nullptr, WebKit::WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, true, String(), nullptr }, WTFMove(callback));586 _panel->handleRequest({ WTFMove(hash), [_WKWebAuthenticationPanel convertToCoreCreationOptionsWithOptions:options], nullptr, WebKit::WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, true, String(), nullptr, std::nullopt }, WTFMove(callback)); 587 587 #endif 588 588 } … … 598 598 }); 599 599 }; 600 _panel->handleRequest({ vectorFromNSData(clientDataHash), [_WKWebAuthenticationPanel convertToCoreCreationOptionsWithOptions:options], nullptr, WebKit::WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, true, String(), nullptr }, WTFMove(callback));600 _panel->handleRequest({ vectorFromNSData(clientDataHash), [_WKWebAuthenticationPanel convertToCoreCreationOptionsWithOptions:options], nullptr, WebKit::WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, true, String(), nullptr, std::nullopt }, WTFMove(callback)); 601 601 #endif 602 602 } … … 648 648 }); 649 649 }; 650 _panel->handleRequest({ WTFMove(hash), [_WKWebAuthenticationPanel convertToCoreRequestOptionsWithOptions:options], nullptr, WebKit::WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, true, String(), nullptr }, WTFMove(callback));650 _panel->handleRequest({ WTFMove(hash), [_WKWebAuthenticationPanel convertToCoreRequestOptionsWithOptions:options], nullptr, WebKit::WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, true, String(), nullptr, std::nullopt }, WTFMove(callback)); 651 651 #endif 652 652 } … … 662 662 }); 663 663 }; 664 _panel->handleRequest({ vectorFromNSData(clientDataHash), [_WKWebAuthenticationPanel convertToCoreRequestOptionsWithOptions:options], nullptr, WebKit::WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, true, String(), nullptr }, WTFMove(callback));664 _panel->handleRequest({ vectorFromNSData(clientDataHash), [_WKWebAuthenticationPanel convertToCoreRequestOptionsWithOptions:options], nullptr, WebKit::WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, true, String(), nullptr, std::nullopt }, WTFMove(callback)); 665 665 #endif 666 666 } -
branches/safari-613-branch/Source/WebKit/UIProcess/WebAuthentication/Cocoa/WebAuthenticatorCoordinatorProxy.mm
r288852 r292176 173 173 } 174 174 175 static RetainPtr<ASCCredentialRequestContext> configureRegistrationRequestContext(const PublicKeyCredentialCreationOptions& options, Vector<uint8_t>hash)175 static RetainPtr<ASCCredentialRequestContext> configureRegistrationRequestContext(const PublicKeyCredentialCreationOptions& options, const Vector<uint8_t>& hash) 176 176 { 177 177 ASCCredentialRequestTypes requestTypes = ASCCredentialRequestTypePlatformPublicKeyRegistration | ASCCredentialRequestTypeSecurityKeyPublicKeyRegistration; … … 237 237 } 238 238 239 static RetainPtr<ASCCredentialRequestContext> configurationAssertionRequestContext(const PublicKeyCredentialRequestOptions& options, Vector<uint8_t> hash) 239 static inline RetainPtr<ASCPublicKeyCredentialAssertionOptions> configureAssertionOptions(const PublicKeyCredentialRequestOptions& options, const Vector<uint8_t>& hash, ASCPublicKeyCredentialKind kind, const std::optional<SecurityOriginData>& parentOrigin, RetainPtr<NSMutableArray<ASCPublicKeyCredentialDescriptor *>> allowedCredentials, RetainPtr<NSString> userVerification) 240 { 241 auto assertionOptions = adoptNS(allocASCPublicKeyCredentialAssertionOptionsInstance()); 242 if ([assertionOptions respondsToSelector:@selector(initWithKind:relyingPartyIdentifier:clientDataHash:userVerificationPreference:allowedCredentials:)]) { 243 auto nsHash = toNSData(hash); 244 [assertionOptions initWithKind:kind relyingPartyIdentifier:options.rpId clientDataHash:nsHash.get() userVerificationPreference:userVerification.get() allowedCredentials:allowedCredentials.get()]; 245 } else { 246 auto challenge = WebCore::toNSData(options.challenge); 247 [assertionOptions initWithKind:kind relyingPartyIdentifier:options.rpId challenge:challenge.get() userVerificationPreference:userVerification.get() allowedCredentials:allowedCredentials.get()]; 248 } 249 if (options.extensions && [assertionOptions respondsToSelector:@selector(setExtensions:)]) 250 [assertionOptions setExtensions:toASCExtensions(*options.extensions).get()]; 251 if (parentOrigin && [assertionOptions respondsToSelector:@selector(setDestinationSiteForCrossSiteAssertion:)]) 252 assertionOptions.get().destinationSiteForCrossSiteAssertion = parentOrigin->toString(); 253 else if (parentOrigin && ![assertionOptions respondsToSelector:@selector(setDestinationSiteForCrossSiteAssertion:)]) 254 return nil; 255 return assertionOptions; 256 } 257 258 static RetainPtr<ASCCredentialRequestContext> configurationAssertionRequestContext(const PublicKeyCredentialRequestOptions& options, const Vector<uint8_t>& hash, std::optional<WebCore::SecurityOriginData>& parentOrigin) 240 259 { 241 260 ASCCredentialRequestTypes requestTypes = ASCCredentialRequestTypePlatformPublicKeyAssertion | ASCCredentialRequestTypeSecurityKeyPublicKeyAssertion; … … 263 282 264 283 if (requestTypes & ASCCredentialRequestTypePlatformPublicKeyAssertion) { 265 auto assertionOptions = adoptNS(allocASCPublicKeyCredentialAssertionOptionsInstance()); 266 if ([assertionOptions respondsToSelector:@selector(initWithKind:relyingPartyIdentifier:clientDataHash:userVerificationPreference:allowedCredentials:)]) { 267 auto nsHash = toNSData(hash); 268 [assertionOptions initWithKind:ASCPublicKeyCredentialKindPlatform relyingPartyIdentifier:options.rpId clientDataHash:nsHash.get() userVerificationPreference:userVerification.get() allowedCredentials:allowedCredentials.get()]; 269 } else { 270 auto challenge = WebCore::toNSData(options.challenge); 271 [assertionOptions initWithKind:ASCPublicKeyCredentialKindPlatform relyingPartyIdentifier:options.rpId challenge:challenge.get() userVerificationPreference:userVerification.get() allowedCredentials:allowedCredentials.get()]; 272 } 273 if (options.extensions && [assertionOptions respondsToSelector:@selector(setExtensions:)]) 274 [assertionOptions setExtensions:toASCExtensions(*options.extensions).get()]; 275 284 auto assertionOptions = configureAssertionOptions(options, hash, ASCPublicKeyCredentialKindPlatform, parentOrigin, allowedCredentials, userVerification); 285 if (!assertionOptions) 286 return nil; 276 287 [requestContext setPlatformKeyCredentialAssertionOptions:assertionOptions.get()]; 277 288 } 278 289 279 290 if (requestTypes & ASCCredentialRequestTypeSecurityKeyPublicKeyAssertion) { 280 auto assertionOptions = adoptNS(allocASCPublicKeyCredentialAssertionOptionsInstance()); 281 if ([assertionOptions respondsToSelector:@selector(initWithKind:relyingPartyIdentifier:clientDataHash:userVerificationPreference:allowedCredentials:)]) { 282 auto nsHash = toNSData(hash); 283 [assertionOptions initWithKind:ASCPublicKeyCredentialKindSecurityKey relyingPartyIdentifier:options.rpId clientDataHash:nsHash.get() userVerificationPreference:userVerification.get() allowedCredentials:allowedCredentials.get()]; 284 } else { 285 auto challenge = WebCore::toNSData(options.challenge); 286 [assertionOptions initWithKind:ASCPublicKeyCredentialKindSecurityKey relyingPartyIdentifier:options.rpId challenge:challenge.get() userVerificationPreference:userVerification.get() allowedCredentials:allowedCredentials.get()]; 287 } 288 if (options.extensions && [assertionOptions respondsToSelector:@selector(setExtensions:)]) 289 [assertionOptions setExtensions:toASCExtensions(*options.extensions).get()]; 290 291 auto assertionOptions = configureAssertionOptions(options, hash, ASCPublicKeyCredentialKindSecurityKey, parentOrigin, allowedCredentials, userVerification); 292 if (!assertionOptions) 293 return nil; 291 294 [requestContext setSecurityKeyCredentialAssertionOptions:assertionOptions.get()]; 292 295 } … … 301 304 result = configureRegistrationRequestContext(options, requestData.hash); 302 305 }, [&](const PublicKeyCredentialRequestOptions& options) { 303 result = configurationAssertionRequestContext(options, requestData.hash );306 result = configurationAssertionRequestContext(options, requestData.hash, requestData.parentOrigin); 304 307 }); 305 308 return result; -
branches/safari-613-branch/Source/WebKit/UIProcess/WebAuthentication/WebAuthenticationRequestData.h
r284213 r292176 39 39 #include <wtf/WeakPtr.h> 40 40 41 namespace WebCore { 42 struct SecurityOriginData; 43 } 44 41 45 namespace WebKit { 42 46 … … 57 61 String cachedPin; // Only used to improve NFC Client PIN experience. 58 62 WeakPtr<API::WebAuthenticationPanel> weakPanel; 63 std::optional<WebCore::SecurityOriginData> parentOrigin; 59 64 }; 60 65 -
branches/safari-613-branch/Source/WebKit/UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.cpp
r286785 r292176 59 59 void WebAuthenticatorCoordinatorProxy::makeCredential(FrameIdentifier frameId, FrameInfoData&& frameInfo, Vector<uint8_t>&& hash, PublicKeyCredentialCreationOptions&& options, bool processingUserGesture, RequestCompletionHandler&& handler) 60 60 { 61 handleRequest({ WTFMove(hash), WTFMove(options), m_webPageProxy, WebAuthenticationPanelResult::Unavailable, nullptr, GlobalFrameIdentifier { m_webPageProxy.webPageID(), frameId }, WTFMove(frameInfo), processingUserGesture, String(), nullptr }, WTFMove(handler));61 handleRequest({ WTFMove(hash), WTFMove(options), m_webPageProxy, WebAuthenticationPanelResult::Unavailable, nullptr, GlobalFrameIdentifier { m_webPageProxy.webPageID(), frameId }, WTFMove(frameInfo), processingUserGesture, String(), nullptr, std::nullopt }, WTFMove(handler)); 62 62 } 63 63 64 void WebAuthenticatorCoordinatorProxy::getAssertion(FrameIdentifier frameId, FrameInfoData&& frameInfo, Vector<uint8_t>&& hash, PublicKeyCredentialRequestOptions&& options, bool processingUserGesture, RequestCompletionHandler&& handler)64 void WebAuthenticatorCoordinatorProxy::getAssertion(FrameIdentifier frameId, FrameInfoData&& frameInfo, Vector<uint8_t>&& hash, PublicKeyCredentialRequestOptions&& options, std::optional<WebCore::SecurityOriginData> parentOrigin, bool processingUserGesture, RequestCompletionHandler&& handler) 65 65 { 66 handleRequest({ WTFMove(hash), WTFMove(options), m_webPageProxy, WebAuthenticationPanelResult::Unavailable, nullptr, GlobalFrameIdentifier { m_webPageProxy.webPageID(), frameId }, WTFMove(frameInfo), processingUserGesture, String(), nullptr }, WTFMove(handler));66 handleRequest({ WTFMove(hash), WTFMove(options), m_webPageProxy, WebAuthenticationPanelResult::Unavailable, nullptr, GlobalFrameIdentifier { m_webPageProxy.webPageID(), frameId }, WTFMove(frameInfo), processingUserGesture, String(), nullptr, parentOrigin }, WTFMove(handler)); 67 67 } 68 68 … … 75 75 if (result) { 76 76 #if HAVE(UNIFIED_ASC_AUTH_UI) 77 if (!authenticatorManager.isMock() && !authenticatorManager.isVirtual()) { 78 auto context = contextForRequest(WTFMove(data)); 79 // performRequest calls out to ASCAgent which will then call [_WKWebAuthenticationPanel makeCredential/getAssertionWithChallenge] 80 // which calls authenticatorManager.handleRequest(..) 81 performRequest(context, WTFMove(handler)); 77 if (!authenticatorManager.isMock() && !authenticatorManager.isVirtual()) { 78 auto context = contextForRequest(WTFMove(data)); 79 if (context.get() == nullptr) { 80 handler({ }, (AuthenticatorAttachment)0, ExceptionData { NotAllowedError, "The origin of the document is not the same as its ancestors."_s }); 82 81 return; 83 82 } 83 // performRequest calls out to ASCAgent which will then call [_WKWebAuthenticationPanel makeCredential/getAssertionWithChallenge] 84 // which calls authenticatorManager.handleRequest(..) 85 performRequest(context, WTFMove(handler)); 86 return; 87 } 88 #else 89 if (data.parentOrigin && !authenticatorManager.isMock() && !authenticatorManager.isVirtual()) { 90 handler({ }, (AuthenticatorAttachment)0, ExceptionData { NotAllowedError, "The origin of the document is not the same as its ancestors."_s }); 91 return; 92 } 84 93 #endif // HAVE(UNIFIED_ASC_AUTH_UI) 85 94 -
branches/safari-613-branch/Source/WebKit/UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.h
r288852 r292176 70 70 // Receivers. 71 71 void makeCredential(WebCore::FrameIdentifier, FrameInfoData&&, Vector<uint8_t>&& hash, WebCore::PublicKeyCredentialCreationOptions&&, bool processingUserGesture, RequestCompletionHandler&&); 72 void getAssertion(WebCore::FrameIdentifier, FrameInfoData&&, Vector<uint8_t>&& hash, WebCore::PublicKeyCredentialRequestOptions&&, bool processingUserGesture, RequestCompletionHandler&&);72 void getAssertion(WebCore::FrameIdentifier, FrameInfoData&&, Vector<uint8_t>&& hash, WebCore::PublicKeyCredentialRequestOptions&&, std::optional<WebCore::SecurityOriginData>, bool processingUserGesture, RequestCompletionHandler&&); 73 73 void isUserVerifyingPlatformAuthenticatorAvailable(QueryCompletionHandler&&); 74 74 -
branches/safari-613-branch/Source/WebKit/UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.messages.in
r278358 r292176 26 26 27 27 messages -> WebAuthenticatorCoordinatorProxy NotRefCounted { 28 29 28 MakeCredential(WebCore::FrameIdentifier frameID, struct WebKit::FrameInfoData frameInfo, Vector<uint8_t> hash, struct WebCore::PublicKeyCredentialCreationOptions options, bool processingUserGesture) -> (struct WebCore::AuthenticatorResponseData data, enum:int WebCore::AuthenticatorAttachment attachment, struct WebCore::ExceptionData exception) Async 30 GetAssertion(WebCore::FrameIdentifier frameID, struct WebKit::FrameInfoData frameInfo, Vector<uint8_t> hash, struct WebCore::PublicKeyCredentialRequestOptions options, bool processingUserGesture) -> (struct WebCore::AuthenticatorResponseData data, enum:int WebCore::AuthenticatorAttachment attachment, struct WebCore::ExceptionData exception) Async29 GetAssertion(WebCore::FrameIdentifier frameID, struct WebKit::FrameInfoData frameInfo, Vector<uint8_t> hash, struct WebCore::PublicKeyCredentialRequestOptions options, std::optional<WebCore::SecurityOriginData> parentOrigin, bool processingUserGesture) -> (struct WebCore::AuthenticatorResponseData data, enum:int WebCore::AuthenticatorAttachment attachment, struct WebCore::ExceptionData exception) Async 31 30 IsUserVerifyingPlatformAuthenticatorAvailable() -> (bool result) Async 32 31 } -
branches/safari-613-branch/Source/WebKit/WebAuthnProcess/WebAuthnConnectionToWebProcess.cpp
r284075 r292176 70 70 void WebAuthnConnectionToWebProcess::makeCredential(Vector<uint8_t>&& hash, PublicKeyCredentialCreationOptions&& options, bool processingUserGesture, RequestCompletionHandler&& handler) 71 71 { 72 handleRequest({ WTFMove(hash), WTFMove(options), nullptr, WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, processingUserGesture, String(), nullptr }, WTFMove(handler));72 handleRequest({ WTFMove(hash), WTFMove(options), nullptr, WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, processingUserGesture, String(), nullptr, std::nullopt }, WTFMove(handler)); 73 73 } 74 74 75 75 void WebAuthnConnectionToWebProcess::getAssertion(Vector<uint8_t>&& hash, PublicKeyCredentialRequestOptions&& options, bool processingUserGesture, RequestCompletionHandler&& handler) 76 76 { 77 handleRequest({ WTFMove(hash), WTFMove(options), nullptr, WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, processingUserGesture, String(), nullptr }, WTFMove(handler));77 handleRequest({ WTFMove(hash), WTFMove(options), nullptr, WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, processingUserGesture, String(), nullptr, std::nullopt }, WTFMove(handler)); 78 78 } 79 79 -
branches/safari-613-branch/Source/WebKit/WebProcess/WebAuthentication/WebAuthenticatorCoordinator.cpp
r290949 r292176 47 47 #include <WebCore/SecurityOrigin.h> 48 48 #include <WebCore/UserGestureIndicator.h> 49 #include <WebCore/WebAuthenticationConstants.h> 49 50 50 51 #undef WEBAUTHN_RELEASE_LOG … … 94 95 } 95 96 96 void WebAuthenticatorCoordinator::getAssertion(const Frame& frame, const SecurityOrigin&, const Vector<uint8_t>& hash, const PublicKeyCredentialRequestOptions& options, RequestCompletionHandler&& handler)97 void WebAuthenticatorCoordinator::getAssertion(const Frame& frame, const SecurityOrigin&, const Vector<uint8_t>& hash, const PublicKeyCredentialRequestOptions& options, const ScopeAndCrossOriginParent& scopeAndCrossOriginParent, RequestCompletionHandler&& handler) 97 98 { 98 99 auto* webFrame = WebFrame::fromCoreFrame(frame); … … 107 108 #endif 108 109 if (!useWebAuthnProcess) { 109 m_webPage.sendWithAsyncReply(Messages::WebAuthenticatorCoordinatorProxy::GetAssertion(webFrame->frameID(), webFrame->info(), hash, options, isProcessingUserGesture), WTFMove(handler)); 110 m_webPage.sendWithAsyncReply(Messages::WebAuthenticatorCoordinatorProxy::GetAssertion(webFrame->frameID(), webFrame->info(), hash, options, scopeAndCrossOriginParent.second, isProcessingUserGesture), WTFMove(handler)); 111 return; 112 } 113 if (scopeAndCrossOriginParent.first == WebAuthn::Scope::CrossOrigin) { 114 handler({ }, (AuthenticatorAttachment)0, ExceptionData { NotAllowedError, "The origin of the document is not the same as its ancestors."_s }); 110 115 return; 111 116 } -
branches/safari-613-branch/Source/WebKit/WebProcess/WebAuthentication/WebAuthenticatorCoordinator.h
r272345 r292176 42 42 // WebCore::AuthenticatorCoordinatorClient 43 43 void makeCredential(const WebCore::Frame&, const WebCore::SecurityOrigin&, const Vector<uint8_t>&, const WebCore::PublicKeyCredentialCreationOptions&, WebCore::RequestCompletionHandler&&) final; 44 void getAssertion(const WebCore::Frame&, const WebCore::SecurityOrigin&, const Vector<uint8_t>& hash, const WebCore::PublicKeyCredentialRequestOptions&, WebCore::RequestCompletionHandler&&) final;44 void getAssertion(const WebCore::Frame&, const WebCore::SecurityOrigin&, const Vector<uint8_t>& hash, const WebCore::PublicKeyCredentialRequestOptions&, const std::pair<WebAuthn::Scope, std::optional<WebCore::SecurityOriginData>>&, WebCore::RequestCompletionHandler&&) final; 45 45 void isUserVerifyingPlatformAuthenticatorAvailable(WebCore::QueryCompletionHandler&&) final; 46 46 void resetUserGestureRequirement() final { m_requireUserGesture = false; }
Note:
See TracChangeset
for help on using the changeset viewer.