⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 292176 in webkit


Ignore:
Timestamp:
Mar 31, 2022, 2:22:25 PM (5 years ago)
Author:
Alan Coon
Message:

Apply patch. rdar://problem/90957317

Location:
branches/safari-613-branch
Files:
3 added
20 edited

Legend:

Unmodified
Added
Removed
  • branches/safari-613-branch/LayoutTests/ChangeLog

    r292089 r292176  
     12022-03-31  Alan Coon  <alancoon@apple.com>
     2
     3        Apply patch. rdar://problem/90957317
     4
     5    2022-03-08  J Pascoe  <j_pascoe@apple.com>
     6
     7            [WebAuthn] Using WebAuthn within cross-origin iframe elements
     8            https://bugs.webkit.org/show_bug.cgi?id=222240
     9            rdar://problem/74830748
     10
     11            Reviewed by Brent Fulgham.
     12
     13            Update existing tests and create new test for cross-origin, non same-site i-frames.
     14
     15            * http/wpt/webauthn/public-key-credential-cross-origin.https-expected.txt: Added.
     16            * http/wpt/webauthn/public-key-credential-cross-origin.https.html: Added.
     17            * http/wpt/webauthn/public-key-credential-same-origin-with-ancestors.https-expected.txt:
     18            * http/wpt/webauthn/public-key-credential-same-origin-with-ancestors.https.html:
     19            * http/wpt/webauthn/resources/public-key-credential-cross-origin.https.html: Added.
     20
    1212022-03-29  Russell Epstein  <repstein@apple.com>
    222
  • branches/safari-613-branch/LayoutTests/http/wpt/webauthn/public-key-credential-same-origin-with-ancestors.https-expected.txt

    r287116 r292176  
    55PASS Tests that a frame that is same-site, cross-origin without publickey-credentials-get feature policy cannot use get().
    66PASS Tests that a frame that is same-site, cross-origin with publickey-credentials-get feature policy can use get().
    7 PASS Tests that a frame that is cross-origin, NOT same-site with publickey-credentials-get feature policy cannot use get().
     7PASS Tests that a frame using an ip address that is cross-origin, NOT same-site with publickey-credentials-get feature policy cannot use get().
    88
  • branches/safari-613-branch/LayoutTests/http/wpt/webauthn/public-key-credential-same-origin-with-ancestors.https.html

    r287116 r292176  
    1 <!DOCTYPE html><!-- webkit-test-runner [ WebAuthenticationModernEnabled=true ] -->
     1<!DOCTYPE html><!-- webkit-test-runner [ WebAuthenticationModernEnabled=false ] -->
    22<html>
    33<head>
    … …  
    3838        promise_test(t => {
    3939            return withCrossOriginIframe("samesite-iframe.html", "publickey-credentials-get").then((message) => {
    40                 assert_equals(message.data, "Throw NotAllowedError: The origin of the document is not the same as its ancestors.");
     40                assert_equals(message.data, "Throw SecurityError: The effective domain of the document is not a valid domain.");
    4141            });
    42         }, "Tests that a frame that is cross-origin, NOT same-site with publickey-credentials-get feature policy cannot use get().");
     42        }, "Tests that a frame using an ip address that is cross-origin, NOT same-site with publickey-credentials-get feature policy cannot use get().");
    4343    </script>
    4444</body>
  • branches/safari-613-branch/Source/WebCore/ChangeLog

    r292093 r292176  
     12022-03-31  Alan Coon  <alancoon@apple.com>
     2
     3        Apply patch. rdar://problem/90957317
     4
     5    2022-03-08  J Pascoe  <j_pascoe@apple.com>
     6
     7            [WebAuthn] Using WebAuthn within cross-origin iframe elements
     8            https://bugs.webkit.org/show_bug.cgi?id=222240
     9            rdar://problem/74830748
     10
     11            Reviewed by Brent Fulgham.
     12
     13            This patch relaxes the requirement to perform a Web Authentication assertion
     14            inside an i-frame with the "publickey-credentials-get" feature policy from
     15            'same-site' to 'cross-origin with consent'.
     16
     17            There is an additional requirement that there is only a single cross-origin
     18            parent to present to the user in the prompt. If we can't display the updated
     19            prompt, then cross-origin assertions are not allowed.
     20
     21            Test: http/wpt/webauthn/public-key-credential-cross-origin.https.html
     22
     23            * Modules/credentialmanagement/CredentialsContainer.cpp:
     24            (WebCore::CredentialsContainer::scopeAndSingleParent):
     25            (WebCore::CredentialsContainer::get):
     26            (WebCore::CredentialsContainer::isCreate):
     27            (WebCore::CredentialsContainer::scope): Deleted.
     28            * Modules/credentialmanagement/CredentialsContainer.h:
     29            * Modules/webauthn/AuthenticatorCoordinator.cpp:
     30            (WebCore::AuthenticatorCoordinator::discoverFromExternalSource const):
     31            * Modules/webauthn/AuthenticatorCoordinator.h:
     32            * Modules/webauthn/AuthenticatorCoordinatorClient.h:
     33
    1342022-03-29  Alan Coon  <alancoon@apple.com>
    235
  • branches/safari-613-branch/Source/WebCore/Modules/credentialmanagement/CredentialsContainer.cpp

    r287116 r292176  
    4747}
    4848
    49 WebAuthn::Scope CredentialsContainer::scope()
     49ScopeAndCrossOriginParent CredentialsContainer::scopeAndCrossOriginParent() const
    5050{
    5151    if (!m_document)
    52         return WebAuthn::Scope::CrossOrigin;
     52        return std::pair { WebAuthn::Scope::CrossOrigin, std::nullopt };
    5353
    54     bool isSameOrigin = true;
    5554    bool isSameSite = true;
    5655    auto& origin = m_document->securityOrigin();
    5756    auto& url = m_document->url();
     57    std::optional<SecurityOriginData> crossOriginParent;
    5858    for (auto* document = m_document->parentDocument(); document; document = document->parentDocument()) {
    5959        if (!origin.isSameOriginDomain(document->securityOrigin()) && !areRegistrableDomainsEqual(url, document->url()))
    6060            isSameSite = false;
    61         if (!origin.isSameOriginAs(document->securityOrigin()))
    62             isSameOrigin = false;
     61        if (!crossOriginParent && !origin.isSameOriginAs(document->securityOrigin()))
     62            crossOriginParent = origin.data();
    6363    }
    6464
    65     if (isSameOrigin)
    66         return WebAuthn::Scope::SameOrigin;
     65    if (!crossOriginParent)
     66        return std::pair { WebAuthn::Scope::SameOrigin, std::nullopt };
    6767    if (isSameSite)
    68         return WebAuthn::Scope::SameSite;
    69     return WebAuthn::Scope::CrossOrigin;
     68        return std::pair { WebAuthn::Scope::SameSite, std::nullopt };
     69    return std::pair { WebAuthn::Scope::CrossOrigin, crossOriginParent };
    7070}
    7171
    … …  
    9999    }
    100100
    101     m_document->page()->authenticatorCoordinator().discoverFromExternalSource(*m_document, options.publicKey.value(), scope(), WTFMove(options.signal), WTFMove(promise));
     101    m_document->page()->authenticatorCoordinator().discoverFromExternalSource(*m_document, WTFMove(options), scopeAndCrossOriginParent(), WTFMove(promise));
    102102}
    103103
    … …  
    134134    }
    135135
    136     m_document->page()->authenticatorCoordinator().create(*m_document, options.publicKey.value(), scope(), WTFMove(options.signal), WTFMove(promise));
     136    m_document->page()->authenticatorCoordinator().create(*m_document, options.publicKey.value(), scopeAndCrossOriginParent().first, WTFMove(options.signal), WTFMove(promise));
    137137}
    138138
  • branches/safari-613-branch/Source/WebCore/Modules/credentialmanagement/CredentialsContainer.h

    r287116 r292176  
    5959    CredentialsContainer(WeakPtr<Document>&&);
    6060
    61     WebAuthn::Scope scope();
     61    ScopeAndCrossOriginParent scopeAndCrossOriginParent() const;
    6262
    6363    WeakPtr<Document> m_document;
  • branches/safari-613-branch/Source/WebCore/Modules/webauthn/AuthenticatorCoordinator.cpp

    r292089 r292176  
    3737#include "FeaturePolicy.h"
    3838#include "JSBasicCredential.h"
     39#include "JSCredentialRequestOptions.h"
    3940#include "JSDOMPromiseDeferred.h"
    4041#include "PublicKeyCredential.h"
    … …  
    183184}
    184185
    185 void AuthenticatorCoordinator::discoverFromExternalSource(const Document& document, const PublicKeyCredentialRequestOptions& options, WebAuthn::Scope scope, RefPtr<AbortSignal>&& abortSignal, CredentialPromise&& promise) const
     186void AuthenticatorCoordinator::discoverFromExternalSource(const Document& document, CredentialRequestOptions&& requestOptions, const ScopeAndCrossOriginParent& scopeAndCrossOriginParent, CredentialPromise&& promise) const
    186187{
    187188    using namespace AuthenticatorCoordinatorInternal;
    … …  
    189190    auto& callerOrigin = document.securityOrigin();
    190191    auto* frame = document.frame();
     192    const auto& options = requestOptions.publicKey.value();
    191193    ASSERT(frame);
    192194    // The following implements https://www.w3.org/TR/webauthn/#createCredential as of 5 December 2017.
    193195    // Step 1, 3, 13 are handled by the caller.
    194196    // Step 2.
    195     // This implements https://www.w3.org/TR/webauthn-2/#sctn-permissions-policy except only same-site, cross-origin is permitted.
    196     if (scope != WebAuthn::Scope::SameOrigin && !(scope == WebAuthn::Scope::SameSite && isFeaturePolicyAllowedByDocumentAndAllOwners(FeaturePolicy::Type::PublickeyCredentialsGetRule, document, LogFeaturePolicyFailure::No))) {
     197    // This implements https://www.w3.org/TR/webauthn-2/#sctn-permissions-policy
     198    if (scopeAndCrossOriginParent.first != WebAuthn::Scope::SameOrigin && !isFeaturePolicyAllowedByDocumentAndAllOwners(FeaturePolicy::Type::PublickeyCredentialsGetRule, document, LogFeaturePolicyFailure::No)) {
    197199        promise.reject(Exception { NotAllowedError, "The origin of the document is not the same as its ancestors."_s });
    198200        return;
    … …  
    228230
    229231    // Step 10-12.
    230     auto clientDataJson = buildClientDataJson(ClientDataType::Get, options.challenge, callerOrigin, scope);
     232    auto clientDataJson = buildClientDataJson(ClientDataType::Get, options.challenge, callerOrigin, scopeAndCrossOriginParent.first);
    231233    auto clientDataJsonHash = buildClientDataJsonHash(clientDataJson);
    232234
    … …  
    237239    }
    238240
    239     auto callback = [clientDataJson = WTFMove(clientDataJson), promise = WTFMove(promise), abortSignal = WTFMove(abortSignal)] (AuthenticatorResponseData&& data, AuthenticatorAttachment attachment, ExceptionData&& exception) mutable {
     241    auto callback = [clientDataJson = WTFMove(clientDataJson), promise = WTFMove(promise), abortSignal = WTFMove(requestOptions.signal)] (AuthenticatorResponseData&& data, AuthenticatorAttachment attachment, ExceptionData&& exception) mutable {
    240242        if (abortSignal && abortSignal->aborted()) {
    241243            promise.reject(Exception { AbortError, "Aborted by AbortSignal."_s });
    … …  
    252254    };
    253255    // Async operations are dispatched and handled in the messenger.
    254     m_client->getAssertion(*frame, callerOrigin, clientDataJsonHash, options, WTFMove(callback));
     256    m_client->getAssertion(*frame, callerOrigin, clientDataJsonHash, options, scopeAndCrossOriginParent, WTFMove(callback));
    255257}
    256258
  • branches/safari-613-branch/Source/WebCore/Modules/webauthn/AuthenticatorCoordinator.h

    r287116 r292176  
    4646struct PublicKeyCredentialRequestOptions;
    4747
     48struct CredentialRequestOptions;
     49struct SecurityOriginData;
     50
    4851template<typename IDLType> class DOMPromiseDeferred;
    4952
    5053using CredentialPromise = DOMPromiseDeferred<IDLNullable<IDLInterface<BasicCredential>>>;
     54using ScopeAndCrossOriginParent = std::pair<WebAuthn::Scope, std::optional<SecurityOriginData>>;
    5155
    5256class AuthenticatorCoordinator final {
    … …  
    5963    // The following methods implement static methods of PublicKeyCredential.
    6064    void create(const Document&, const PublicKeyCredentialCreationOptions&, WebAuthn::Scope, RefPtr<AbortSignal>&&, CredentialPromise&&) const;
    61     void discoverFromExternalSource(const Document&, const PublicKeyCredentialRequestOptions&, WebAuthn::Scope, RefPtr<AbortSignal>&&, CredentialPromise&&) const;
     65
     66    void discoverFromExternalSource(const Document&, CredentialRequestOptions&& requestOptions, const ScopeAndCrossOriginParent&, CredentialPromise&&) const;
    6267    void isUserVerifyingPlatformAuthenticatorAvailable(DOMPromiseDeferred<IDLBoolean>&&) const;
    6368
  • branches/safari-613-branch/Source/WebCore/Modules/webauthn/AuthenticatorCoordinatorClient.h

    r278358 r292176  
    2828#if ENABLE(WEB_AUTHN)
    2929
     30#include "AuthenticatorCoordinator.h"
    3031#include "ExceptionData.h"
    3132#include <wtf/CompletionHandler.h>
    3233#include <wtf/WeakPtr.h>
     34
     35namespace WebAuthn {
     36enum class Scope;
     37}
    3338
    3439namespace WebCore {
    … …  
    4348struct PublicKeyCredentialCreationOptions;
    4449struct PublicKeyCredentialRequestOptions;
     50struct SecurityOriginData;
    4551
    4652using RequestCompletionHandler = CompletionHandler<void(WebCore::AuthenticatorResponseData&&, WebCore::AuthenticatorAttachment, WebCore::ExceptionData&&)>;
    … …  
    5460    virtual ~AuthenticatorCoordinatorClient() = default;
    5561
    56     virtual void makeCredential(const Frame&, const SecurityOrigin&, const Vector<uint8_t>&, const PublicKeyCredentialCreationOptions&, RequestCompletionHandler&&) { };
    57     virtual void getAssertion(const Frame&, const SecurityOrigin&, const Vector<uint8_t>&, const PublicKeyCredentialRequestOptions&, RequestCompletionHandler&&) { };
    58     virtual void isUserVerifyingPlatformAuthenticatorAvailable(QueryCompletionHandler&&) { };
     62    virtual void makeCredential(const Frame&, const SecurityOrigin&, const Vector<uint8_t>&, const PublicKeyCredentialCreationOptions&, RequestCompletionHandler&&) = 0;
     63    virtual void getAssertion(const Frame&, const SecurityOrigin&, const Vector<uint8_t>&, const PublicKeyCredentialRequestOptions&, const ScopeAndCrossOriginParent&, RequestCompletionHandler&&) = 0;
     64    virtual void isUserVerifyingPlatformAuthenticatorAvailable(QueryCompletionHandler&&) = 0;
    5965
    6066    virtual void resetUserGestureRequirement() { }
  • branches/safari-613-branch/Source/WebKit/ChangeLog

    r292129 r292176  
     12022-03-31  Alan Coon  <alancoon@apple.com>
     2
     3        Apply patch. rdar://problem/90957317
     4
     5    2022-03-08  J Pascoe  <j_pascoe@apple.com>
     6
     7            [WebAuthn] Using WebAuthn within cross-origin iframe elements
     8            https://bugs.webkit.org/show_bug.cgi?id=222240
     9            rdar://problem/74830748
     10
     11            Reviewed by Brent Fulgham.
     12
     13            This patch relaxes the requirement to perform a Web Authentication assertion
     14            inside an i-frame with the "publickey-credentials-get" feature policy from
     15            'same-site' to 'cross-origin with consent'.
     16
     17            There is an additional requirement that there is only a single cross-origin
     18            parent to present to the user in the prompt. If we can't display the updated
     19            prompt, then cross-origin assertions are not allowed.
     20
     21            * Platform/spi/Cocoa/AuthenticationServicesCoreSPI.h:
     22            * UIProcess/WebAuthentication/Cocoa/WebAuthenticatorCoordinatorProxy.mm:
     23            (WebKit::configureAssertionOptions):
     24            (WebKit::configurationAssertionRequestContext):
     25            (WebKit::WebAuthenticatorCoordinatorProxy::contextForRequest):
     26            * UIProcess/WebAuthentication/WebAuthenticationRequestData.h:
     27            * UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.cpp:
     28            (WebKit::WebAuthenticatorCoordinatorProxy::makeCredential):
     29            (WebKit::WebAuthenticatorCoordinatorProxy::getAssertion):
     30            (WebKit::WebAuthenticatorCoordinatorProxy::handleRequest):
     31            * UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.h:
     32            * UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.messages.in:
     33            * WebProcess/WebAuthentication/WebAuthenticatorCoordinator.cpp:
     34            (WebKit::WebAuthenticatorCoordinator::getAssertion):
     35            * WebProcess/WebAuthentication/WebAuthenticatorCoordinator.h:
     36
    1372022-03-29  Alan Coon  <alancoon@apple.com>
    238
  • branches/safari-613-branch/Source/WebKit/Platform/spi/Cocoa/AuthenticationServicesCoreSPI.h

    r288852 r292176  
    168168@property (nonatomic, nullable, readonly, copy) NSArray<ASCPublicKeyCredentialDescriptor *> *allowedCredentials;
    169169
     170@property (nonatomic, nullable, copy) NSString *destinationSiteForCrossSiteAssertion;
     171
    170172@end
    171173
  • branches/safari-613-branch/Source/WebKit/UIProcess/API/Cocoa/_WKWebAuthenticationPanel.mm

    r288852 r292176  
    584584        });
    585585    };
    586     _panel->handleRequest({ WTFMove(hash), [_WKWebAuthenticationPanel convertToCoreCreationOptionsWithOptions:options], nullptr, WebKit::WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, true, String(), nullptr }, WTFMove(callback));
     586    _panel->handleRequest({ WTFMove(hash), [_WKWebAuthenticationPanel convertToCoreCreationOptionsWithOptions:options], nullptr, WebKit::WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, true, String(), nullptr, std::nullopt }, WTFMove(callback));
    587587#endif
    588588}
    … …  
    598598        });
    599599    };
    600     _panel->handleRequest({ vectorFromNSData(clientDataHash), [_WKWebAuthenticationPanel convertToCoreCreationOptionsWithOptions:options], nullptr, WebKit::WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, true, String(), nullptr }, WTFMove(callback));
     600    _panel->handleRequest({ vectorFromNSData(clientDataHash), [_WKWebAuthenticationPanel convertToCoreCreationOptionsWithOptions:options], nullptr, WebKit::WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, true, String(), nullptr, std::nullopt }, WTFMove(callback));
    601601#endif
    602602}
    … …  
    648648        });
    649649    };
    650     _panel->handleRequest({ WTFMove(hash), [_WKWebAuthenticationPanel convertToCoreRequestOptionsWithOptions:options], nullptr, WebKit::WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, true, String(), nullptr }, WTFMove(callback));
     650    _panel->handleRequest({ WTFMove(hash), [_WKWebAuthenticationPanel convertToCoreRequestOptionsWithOptions:options], nullptr, WebKit::WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, true, String(), nullptr, std::nullopt }, WTFMove(callback));
    651651#endif
    652652}
    … …  
    662662        });
    663663    };
    664     _panel->handleRequest({ vectorFromNSData(clientDataHash), [_WKWebAuthenticationPanel convertToCoreRequestOptionsWithOptions:options], nullptr, WebKit::WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, true, String(), nullptr }, WTFMove(callback));
     664    _panel->handleRequest({ vectorFromNSData(clientDataHash), [_WKWebAuthenticationPanel convertToCoreRequestOptionsWithOptions:options], nullptr, WebKit::WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, true, String(), nullptr, std::nullopt }, WTFMove(callback));
    665665#endif
    666666}
  • branches/safari-613-branch/Source/WebKit/UIProcess/WebAuthentication/Cocoa/WebAuthenticatorCoordinatorProxy.mm

    r288852 r292176  
    173173}
    174174
    175 static RetainPtr<ASCCredentialRequestContext> configureRegistrationRequestContext(const PublicKeyCredentialCreationOptions& options, Vector<uint8_t> hash)
     175static RetainPtr<ASCCredentialRequestContext> configureRegistrationRequestContext(const PublicKeyCredentialCreationOptions& options, const Vector<uint8_t>& hash)
    176176{
    177177    ASCCredentialRequestTypes requestTypes = ASCCredentialRequestTypePlatformPublicKeyRegistration | ASCCredentialRequestTypeSecurityKeyPublicKeyRegistration;
    … …  
    237237}
    238238
    239 static RetainPtr<ASCCredentialRequestContext> configurationAssertionRequestContext(const PublicKeyCredentialRequestOptions& options, Vector<uint8_t> hash)
     239static inline RetainPtr<ASCPublicKeyCredentialAssertionOptions> configureAssertionOptions(const PublicKeyCredentialRequestOptions& options, const Vector<uint8_t>& hash, ASCPublicKeyCredentialKind kind, const std::optional<SecurityOriginData>& parentOrigin, RetainPtr<NSMutableArray<ASCPublicKeyCredentialDescriptor *>> allowedCredentials, RetainPtr<NSString> userVerification)
     240{
     241    auto assertionOptions = adoptNS(allocASCPublicKeyCredentialAssertionOptionsInstance());
     242    if ([assertionOptions respondsToSelector:@selector(initWithKind:relyingPartyIdentifier:clientDataHash:userVerificationPreference:allowedCredentials:)]) {
     243        auto nsHash = toNSData(hash);
     244        [assertionOptions initWithKind:kind relyingPartyIdentifier:options.rpId clientDataHash:nsHash.get() userVerificationPreference:userVerification.get() allowedCredentials:allowedCredentials.get()];
     245    } else {
     246        auto challenge = WebCore::toNSData(options.challenge);
     247        [assertionOptions initWithKind:kind relyingPartyIdentifier:options.rpId challenge:challenge.get() userVerificationPreference:userVerification.get() allowedCredentials:allowedCredentials.get()];
     248    }
     249    if (options.extensions && [assertionOptions respondsToSelector:@selector(setExtensions:)])
     250        [assertionOptions setExtensions:toASCExtensions(*options.extensions).get()];
     251    if (parentOrigin && [assertionOptions respondsToSelector:@selector(setDestinationSiteForCrossSiteAssertion:)])
     252        assertionOptions.get().destinationSiteForCrossSiteAssertion = parentOrigin->toString();
     253    else if (parentOrigin && ![assertionOptions respondsToSelector:@selector(setDestinationSiteForCrossSiteAssertion:)])
     254        return nil;
     255    return assertionOptions;
     256}
     257
     258static RetainPtr<ASCCredentialRequestContext> configurationAssertionRequestContext(const PublicKeyCredentialRequestOptions& options, const Vector<uint8_t>& hash, std::optional<WebCore::SecurityOriginData>& parentOrigin)
    240259{
    241260    ASCCredentialRequestTypes requestTypes = ASCCredentialRequestTypePlatformPublicKeyAssertion | ASCCredentialRequestTypeSecurityKeyPublicKeyAssertion;
    … …  
    263282
    264283    if (requestTypes & ASCCredentialRequestTypePlatformPublicKeyAssertion) {
    265         auto assertionOptions = adoptNS(allocASCPublicKeyCredentialAssertionOptionsInstance());
    266         if ([assertionOptions respondsToSelector:@selector(initWithKind:relyingPartyIdentifier:clientDataHash:userVerificationPreference:allowedCredentials:)]) {
    267             auto nsHash = toNSData(hash);
    268             [assertionOptions initWithKind:ASCPublicKeyCredentialKindPlatform relyingPartyIdentifier:options.rpId clientDataHash:nsHash.get() userVerificationPreference:userVerification.get() allowedCredentials:allowedCredentials.get()];
    269         } else {
    270             auto challenge = WebCore::toNSData(options.challenge);
    271             [assertionOptions initWithKind:ASCPublicKeyCredentialKindPlatform relyingPartyIdentifier:options.rpId challenge:challenge.get() userVerificationPreference:userVerification.get() allowedCredentials:allowedCredentials.get()];
    272         }
    273         if (options.extensions && [assertionOptions respondsToSelector:@selector(setExtensions:)])
    274             [assertionOptions setExtensions:toASCExtensions(*options.extensions).get()];
    275 
     284        auto assertionOptions = configureAssertionOptions(options, hash, ASCPublicKeyCredentialKindPlatform, parentOrigin, allowedCredentials, userVerification);
     285        if (!assertionOptions)
     286            return nil;
    276287        [requestContext setPlatformKeyCredentialAssertionOptions:assertionOptions.get()];
    277288    }
    278289
    279290    if (requestTypes & ASCCredentialRequestTypeSecurityKeyPublicKeyAssertion) {
    280         auto assertionOptions = adoptNS(allocASCPublicKeyCredentialAssertionOptionsInstance());
    281         if ([assertionOptions respondsToSelector:@selector(initWithKind:relyingPartyIdentifier:clientDataHash:userVerificationPreference:allowedCredentials:)]) {
    282             auto nsHash = toNSData(hash);
    283             [assertionOptions initWithKind:ASCPublicKeyCredentialKindSecurityKey relyingPartyIdentifier:options.rpId clientDataHash:nsHash.get() userVerificationPreference:userVerification.get() allowedCredentials:allowedCredentials.get()];
    284         } else {
    285             auto challenge = WebCore::toNSData(options.challenge);
    286             [assertionOptions initWithKind:ASCPublicKeyCredentialKindSecurityKey relyingPartyIdentifier:options.rpId challenge:challenge.get() userVerificationPreference:userVerification.get() allowedCredentials:allowedCredentials.get()];
    287         }
    288         if (options.extensions && [assertionOptions respondsToSelector:@selector(setExtensions:)])
    289             [assertionOptions setExtensions:toASCExtensions(*options.extensions).get()];
    290 
     291        auto assertionOptions = configureAssertionOptions(options, hash, ASCPublicKeyCredentialKindSecurityKey, parentOrigin, allowedCredentials, userVerification);
     292        if (!assertionOptions)
     293            return nil;
    291294        [requestContext setSecurityKeyCredentialAssertionOptions:assertionOptions.get()];
    292295    }
    … …  
    301304        result = configureRegistrationRequestContext(options, requestData.hash);
    302305    }, [&](const PublicKeyCredentialRequestOptions& options) {
    303         result = configurationAssertionRequestContext(options, requestData.hash);
     306        result = configurationAssertionRequestContext(options, requestData.hash, requestData.parentOrigin);
    304307    });
    305308    return result;
  • branches/safari-613-branch/Source/WebKit/UIProcess/WebAuthentication/WebAuthenticationRequestData.h

    r284213 r292176  
    3939#include <wtf/WeakPtr.h>
    4040
     41namespace WebCore {
     42struct SecurityOriginData;
     43}
     44
    4145namespace WebKit {
    4246
    … …  
    5761    String cachedPin; // Only used to improve NFC Client PIN experience.
    5862    WeakPtr<API::WebAuthenticationPanel> weakPanel;
     63    std::optional<WebCore::SecurityOriginData> parentOrigin;
    5964};
    6065
  • branches/safari-613-branch/Source/WebKit/UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.cpp

    r286785 r292176  
    5959void WebAuthenticatorCoordinatorProxy::makeCredential(FrameIdentifier frameId, FrameInfoData&& frameInfo, Vector<uint8_t>&& hash, PublicKeyCredentialCreationOptions&& options, bool processingUserGesture, RequestCompletionHandler&& handler)
    6060{
    61     handleRequest({ WTFMove(hash), WTFMove(options), m_webPageProxy, WebAuthenticationPanelResult::Unavailable, nullptr, GlobalFrameIdentifier { m_webPageProxy.webPageID(), frameId }, WTFMove(frameInfo), processingUserGesture, String(), nullptr }, WTFMove(handler));
     61    handleRequest({ WTFMove(hash), WTFMove(options), m_webPageProxy, WebAuthenticationPanelResult::Unavailable, nullptr, GlobalFrameIdentifier { m_webPageProxy.webPageID(), frameId }, WTFMove(frameInfo), processingUserGesture, String(), nullptr, std::nullopt }, WTFMove(handler));
    6262}
    6363
    64 void WebAuthenticatorCoordinatorProxy::getAssertion(FrameIdentifier frameId, FrameInfoData&& frameInfo, Vector<uint8_t>&& hash, PublicKeyCredentialRequestOptions&& options, bool processingUserGesture, RequestCompletionHandler&& handler)
     64void WebAuthenticatorCoordinatorProxy::getAssertion(FrameIdentifier frameId, FrameInfoData&& frameInfo, Vector<uint8_t>&& hash, PublicKeyCredentialRequestOptions&& options, std::optional<WebCore::SecurityOriginData> parentOrigin, bool processingUserGesture, RequestCompletionHandler&& handler)
    6565{
    66     handleRequest({ WTFMove(hash), WTFMove(options), m_webPageProxy, WebAuthenticationPanelResult::Unavailable, nullptr, GlobalFrameIdentifier { m_webPageProxy.webPageID(), frameId }, WTFMove(frameInfo), processingUserGesture, String(), nullptr }, WTFMove(handler));
     66    handleRequest({ WTFMove(hash), WTFMove(options), m_webPageProxy, WebAuthenticationPanelResult::Unavailable, nullptr, GlobalFrameIdentifier { m_webPageProxy.webPageID(), frameId }, WTFMove(frameInfo), processingUserGesture, String(), nullptr, parentOrigin }, WTFMove(handler));
    6767}
    6868
    … …  
    7575        if (result) {
    7676#if HAVE(UNIFIED_ASC_AUTH_UI)
    77                 if (!authenticatorManager.isMock() && !authenticatorManager.isVirtual()) {
    78                     auto context = contextForRequest(WTFMove(data));
    79                     // performRequest calls out to ASCAgent which will then call [_WKWebAuthenticationPanel makeCredential/getAssertionWithChallenge]
    80                     // which calls authenticatorManager.handleRequest(..)
    81                     performRequest(context, WTFMove(handler));
     77            if (!authenticatorManager.isMock() && !authenticatorManager.isVirtual()) {
     78                auto context = contextForRequest(WTFMove(data));
     79                if (context.get() == nullptr) {
     80                    handler({ }, (AuthenticatorAttachment)0, ExceptionData { NotAllowedError, "The origin of the document is not the same as its ancestors."_s });
    8281                    return;
    8382                }
     83                // performRequest calls out to ASCAgent which will then call [_WKWebAuthenticationPanel makeCredential/getAssertionWithChallenge]
     84                // which calls authenticatorManager.handleRequest(..)
     85                performRequest(context, WTFMove(handler));
     86                return;
     87            }
     88#else
     89            if (data.parentOrigin && !authenticatorManager.isMock() && !authenticatorManager.isVirtual()) {
     90                handler({ }, (AuthenticatorAttachment)0, ExceptionData { NotAllowedError, "The origin of the document is not the same as its ancestors."_s });
     91                return;
     92            }
    8493#endif // HAVE(UNIFIED_ASC_AUTH_UI)
    8594
  • branches/safari-613-branch/Source/WebKit/UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.h

    r288852 r292176  
    7070    // Receivers.
    7171    void makeCredential(WebCore::FrameIdentifier, FrameInfoData&&, Vector<uint8_t>&& hash, WebCore::PublicKeyCredentialCreationOptions&&, bool processingUserGesture, RequestCompletionHandler&&);
    72     void getAssertion(WebCore::FrameIdentifier, FrameInfoData&&, Vector<uint8_t>&& hash, WebCore::PublicKeyCredentialRequestOptions&&, bool processingUserGesture, RequestCompletionHandler&&);
     72    void getAssertion(WebCore::FrameIdentifier, FrameInfoData&&, Vector<uint8_t>&& hash, WebCore::PublicKeyCredentialRequestOptions&&, std::optional<WebCore::SecurityOriginData>, bool processingUserGesture, RequestCompletionHandler&&);
    7373    void isUserVerifyingPlatformAuthenticatorAvailable(QueryCompletionHandler&&);
    7474
  • branches/safari-613-branch/Source/WebKit/UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.messages.in

    r278358 r292176  
    2626
    2727messages -> WebAuthenticatorCoordinatorProxy NotRefCounted {
    28 
    2928    MakeCredential(WebCore::FrameIdentifier frameID, struct WebKit::FrameInfoData frameInfo, Vector<uint8_t> hash, struct WebCore::PublicKeyCredentialCreationOptions options, bool processingUserGesture) -> (struct WebCore::AuthenticatorResponseData data, enum:int WebCore::AuthenticatorAttachment attachment, struct WebCore::ExceptionData exception) Async
    30     GetAssertion(WebCore::FrameIdentifier frameID, struct WebKit::FrameInfoData frameInfo, Vector<uint8_t> hash, struct WebCore::PublicKeyCredentialRequestOptions options, bool processingUserGesture) -> (struct WebCore::AuthenticatorResponseData data, enum:int WebCore::AuthenticatorAttachment attachment, struct WebCore::ExceptionData exception) Async
     29    GetAssertion(WebCore::FrameIdentifier frameID, struct WebKit::FrameInfoData frameInfo, Vector<uint8_t> hash, struct WebCore::PublicKeyCredentialRequestOptions options, std::optional<WebCore::SecurityOriginData> parentOrigin, bool processingUserGesture) -> (struct WebCore::AuthenticatorResponseData data, enum:int WebCore::AuthenticatorAttachment attachment, struct WebCore::ExceptionData exception) Async
    3130    IsUserVerifyingPlatformAuthenticatorAvailable() -> (bool result) Async
    3231}
  • branches/safari-613-branch/Source/WebKit/WebAuthnProcess/WebAuthnConnectionToWebProcess.cpp

    r284075 r292176  
    7070void WebAuthnConnectionToWebProcess::makeCredential(Vector<uint8_t>&& hash, PublicKeyCredentialCreationOptions&& options, bool processingUserGesture, RequestCompletionHandler&& handler)
    7171{
    72     handleRequest({ WTFMove(hash), WTFMove(options), nullptr, WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, processingUserGesture, String(), nullptr }, WTFMove(handler));
     72    handleRequest({ WTFMove(hash), WTFMove(options), nullptr, WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, processingUserGesture, String(), nullptr, std::nullopt }, WTFMove(handler));
    7373}
    7474
    7575void WebAuthnConnectionToWebProcess::getAssertion(Vector<uint8_t>&& hash, PublicKeyCredentialRequestOptions&& options, bool processingUserGesture, RequestCompletionHandler&& handler)
    7676{
    77     handleRequest({ WTFMove(hash), WTFMove(options), nullptr, WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, processingUserGesture, String(), nullptr }, WTFMove(handler));
     77    handleRequest({ WTFMove(hash), WTFMove(options), nullptr, WebAuthenticationPanelResult::Unavailable, nullptr, std::nullopt, { }, processingUserGesture, String(), nullptr, std::nullopt }, WTFMove(handler));
    7878}
    7979
  • branches/safari-613-branch/Source/WebKit/WebProcess/WebAuthentication/WebAuthenticatorCoordinator.cpp

    r290949 r292176  
    4747#include <WebCore/SecurityOrigin.h>
    4848#include <WebCore/UserGestureIndicator.h>
     49#include <WebCore/WebAuthenticationConstants.h>
    4950
    5051#undef WEBAUTHN_RELEASE_LOG
    … …  
    9495}
    9596
    96 void WebAuthenticatorCoordinator::getAssertion(const Frame& frame, const SecurityOrigin&, const Vector<uint8_t>& hash, const PublicKeyCredentialRequestOptions& options, RequestCompletionHandler&& handler)
     97void WebAuthenticatorCoordinator::getAssertion(const Frame& frame, const SecurityOrigin&, const Vector<uint8_t>& hash, const PublicKeyCredentialRequestOptions& options, const ScopeAndCrossOriginParent& scopeAndCrossOriginParent, RequestCompletionHandler&& handler)
    9798{
    9899    auto* webFrame = WebFrame::fromCoreFrame(frame);
    … …  
    107108#endif
    108109    if (!useWebAuthnProcess) {
    109         m_webPage.sendWithAsyncReply(Messages::WebAuthenticatorCoordinatorProxy::GetAssertion(webFrame->frameID(), webFrame->info(), hash, options, isProcessingUserGesture), WTFMove(handler));
     110        m_webPage.sendWithAsyncReply(Messages::WebAuthenticatorCoordinatorProxy::GetAssertion(webFrame->frameID(), webFrame->info(), hash, options, scopeAndCrossOriginParent.second, isProcessingUserGesture), WTFMove(handler));
     111        return;
     112    }
     113    if (scopeAndCrossOriginParent.first == WebAuthn::Scope::CrossOrigin) {
     114        handler({ }, (AuthenticatorAttachment)0, ExceptionData { NotAllowedError, "The origin of the document is not the same as its ancestors."_s });
    110115        return;
    111116    }
  • branches/safari-613-branch/Source/WebKit/WebProcess/WebAuthentication/WebAuthenticatorCoordinator.h

    r272345 r292176  
    4242    // WebCore::AuthenticatorCoordinatorClient
    4343    void makeCredential(const WebCore::Frame&, const WebCore::SecurityOrigin&, const Vector<uint8_t>&, const WebCore::PublicKeyCredentialCreationOptions&, WebCore::RequestCompletionHandler&&) final;
    44     void getAssertion(const WebCore::Frame&, const WebCore::SecurityOrigin&, const Vector<uint8_t>& hash, const WebCore::PublicKeyCredentialRequestOptions&, WebCore::RequestCompletionHandler&&) final;
     44    void getAssertion(const WebCore::Frame&, const WebCore::SecurityOrigin&, const Vector<uint8_t>& hash, const WebCore::PublicKeyCredentialRequestOptions&, const std::pair<WebAuthn::Scope, std::optional<WebCore::SecurityOriginData>>&, WebCore::RequestCompletionHandler&&) final;
    4545    void isUserVerifyingPlatformAuthenticatorAvailable(WebCore::QueryCompletionHandler&&) final;
    4646    void resetUserGestureRequirement() final { m_requireUserGesture = false; }
Note: See TracChangeset for help on using the changeset viewer.