⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 292177 in webkit


Ignore:
Timestamp:
Mar 31, 2022, 2:22:29 PM (5 years ago)
Author:
Alan Coon
Message:

Apply patch. rdar://problem/90957287

Location:
branches/safari-613-branch/Source/WebKit
Files:
5 edited

Legend:

Unmodified
Added
Removed
  • branches/safari-613-branch/Source/WebKit/ChangeLog

    r292176 r292177  
     12022-03-31  Alan Coon  <alancoon@apple.com>
     2
     3        Apply patch. rdar://problem/90957287
     4
     5    2022-03-11  J Pascoe  <j_pascoe@apple.com>
     6
     7            [WebAuthn] Cancel running operations in ASA on navigation
     8            https://bugs.webkit.org/show_bug.cgi?id=237452
     9            rdar://problem/89781990
     10
     11            Reviewed by Brent Fulgham.
     12
     13            Pre-ASA WebAuthn calls cancel requests on navigation via calling authenticatorManager.cancelRequest
     14            in WebPageProxy. In WebAuthn calls that go through ASA, the authenticatorManager lives in the ASA
     15            process, so calls won't be cancelled on navigation.
     16
     17            This patch attempts to cancel ongoing operations whenever a WebAuthenticatorCoordinatorProxy that
     18            uses ASA is destroyed, effectively cancelling requests on reload or navigation.
     19
     20            * Platform/spi/Cocoa/AuthenticationServicesCoreSPI.h:
     21            * UIProcess/WebAuthentication/Cocoa/WebAuthenticatorCoordinatorProxy.mm:
     22            * UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.cpp:
     23            (WebKit::WebAuthenticatorCoordinatorProxy::~WebAuthenticatorCoordinatorProxy):
     24            * UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.h:
     25
    1262022-03-31  Alan Coon  <alancoon@apple.com>
    227
  • branches/safari-613-branch/Source/WebKit/Platform/spi/Cocoa/AuthenticationServicesCoreSPI.h

    r292176 r292177  
    325325#endif
    326326
     327- (void)cancelCurrentRequest;
     328
    327329@end
    328330
  • branches/safari-613-branch/Source/WebKit/UIProcess/WebAuthentication/Cocoa/WebAuthenticatorCoordinatorProxy.mm

    r292176 r292177  
    309309}
    310310
     311static inline void continueAfterRequest(RetainPtr<id <ASCCredentialProtocol>> credential, RetainPtr<NSError> error, RequestCompletionHandler&& handler)
     312{
     313    AuthenticatorResponseData response = { };
     314    AuthenticatorAttachment attachment;
     315    ExceptionData exceptionData = { };
     316
     317    if ([credential isKindOfClass:getASCPlatformPublicKeyCredentialRegistrationClass()]) {
     318        attachment = AuthenticatorAttachment::Platform;
     319        response.isAuthenticatorAttestationResponse = true;
     320
     321        ASCPlatformPublicKeyCredentialRegistration *registrationCredential = credential.get();
     322        response.rawId = toArrayBuffer(registrationCredential.credentialID);
     323        response.attestationObject = toArrayBuffer(registrationCredential.attestationObject);
     324    } else if ([credential isKindOfClass:getASCSecurityKeyPublicKeyCredentialRegistrationClass()]) {
     325        attachment = AuthenticatorAttachment::CrossPlatform;
     326        response.isAuthenticatorAttestationResponse = true;
     327
     328        ASCSecurityKeyPublicKeyCredentialRegistration *registrationCredential = credential.get();
     329        response.rawId = toArrayBuffer(registrationCredential.credentialID);
     330        response.attestationObject = toArrayBuffer(registrationCredential.attestationObject);
     331    } else if ([credential isKindOfClass:getASCPlatformPublicKeyCredentialAssertionClass()]) {
     332        attachment = AuthenticatorAttachment::Platform;
     333        response.isAuthenticatorAttestationResponse = false;
     334
     335        ASCPlatformPublicKeyCredentialAssertion *assertionCredential = credential.get();
     336        response.rawId = toArrayBuffer(assertionCredential.credentialID);
     337        response.authenticatorData = toArrayBuffer(assertionCredential.authenticatorData);
     338        response.signature = toArrayBuffer(assertionCredential.signature);
     339        response.userHandle = toArrayBuffer(assertionCredential.userHandle);
     340    } else if ([credential isKindOfClass:getASCSecurityKeyPublicKeyCredentialAssertionClass()]) {
     341        attachment = AuthenticatorAttachment::CrossPlatform;
     342        response.isAuthenticatorAttestationResponse = false;
     343
     344        ASCSecurityKeyPublicKeyCredentialAssertion *assertionCredential = credential.get();
     345        response.rawId = toArrayBuffer(assertionCredential.credentialID);
     346        response.authenticatorData = toArrayBuffer(assertionCredential.authenticatorData);
     347        response.signature = toArrayBuffer(assertionCredential.signature);
     348        response.userHandle = toArrayBuffer(assertionCredential.userHandle);
     349    } else {
     350        attachment = (AuthenticatorAttachment) 0;
     351        ExceptionCode exceptionCode;
     352        NSString *errorMessage = nil;
     353        if ([error.get().domain isEqualToString:WKErrorDomain]) {
     354            exceptionCode = toExceptionCode(error.get().code);
     355            errorMessage = error.get().userInfo[NSLocalizedDescriptionKey];
     356        } else {
     357            exceptionCode = NotAllowedError;
     358
     359            if ([error.get().domain isEqualToString:ASCAuthorizationErrorDomain] && error.get().code == ASCAuthorizationErrorUserCanceled)
     360                errorMessage = @"This request has been cancelled by the user.";
     361            else
     362                errorMessage = @"Operation failed.";
     363        }
     364
     365        exceptionData = { exceptionCode, errorMessage };
     366    }
     367
     368    handler(response, attachment, exceptionData);
     369}
     370
    311371void WebAuthenticatorCoordinatorProxy::performRequest(RetainPtr<ASCCredentialRequestContext> requestContext, RequestCompletionHandler&& handler)
    312372{
    313     auto proxy = adoptNS([allocASCAgentProxyInstance() init]);
    314 
     373    m_proxy = adoptNS([allocASCAgentProxyInstance() init]);
     374#if PLATFORM(IOS)
     375    [m_proxy performAuthorizationRequestsForContext:requestContext.get() withCompletionHandler:makeBlockPtr([handler = WTFMove(handler)](id<ASCCredentialProtocol> credential, NSError *error) mutable {
     376        callOnMainRunLoop([handler = WTFMove(handler), proxy = WTFMove(proxy), credential = retainPtr(credential), error = retainPtr(error)] () mutable {
     377#elif PLATFORM(MAC)
    315378    RetainPtr<NSWindow> window = m_webPageProxy.platformWindow();
    316     [proxy performAuthorizationRequestsForContext:requestContext.get() withClearanceHandler:makeBlockPtr([weakThis = WeakPtr { *this }, handler = WTFMove(handler), window = WTFMove(window), proxy = WTFMove(proxy)](NSXPCListenerEndpoint *daemonEndpoint, NSError *error) mutable {
    317         callOnMainRunLoop([weakThis, handler = WTFMove(handler), window = WTFMove(window), proxy = WTFMove(proxy), daemonEndpoint = retainPtr(daemonEndpoint), error = retainPtr(error)] () mutable {
     379    [m_proxy performAuthorizationRequestsForContext:requestContext.get() withClearanceHandler:makeBlockPtr([weakThis = WeakPtr { *this }, handler = WTFMove(handler), window = WTFMove(window)](NSXPCListenerEndpoint *daemonEndpoint, NSError *error) mutable {
     380        callOnMainRunLoop([weakThis, handler = WTFMove(handler), window = WTFMove(window), daemonEndpoint = retainPtr(daemonEndpoint), error = retainPtr(error)] () mutable {
    318381            if (!weakThis || !daemonEndpoint) {
    319382                LOG_ERROR("Could not connect to authorization daemon: %@\n", error.get());
    … …  
    323386
    324387            weakThis->m_presenter = adoptNS([allocASCAuthorizationRemotePresenterInstance() init]);
    325             [weakThis->m_presenter presentWithWindow:window.get() daemonEndpoint:daemonEndpoint.get() completionHandler:makeBlockPtr([handler = WTFMove(handler), proxy = WTFMove(proxy)](id <ASCCredentialProtocol> credential, NSError *error) mutable {
    326                 AuthenticatorResponseData response = { };
    327                 AuthenticatorAttachment attachment;
    328                 ExceptionData exceptionData = { };
    329 
    330                 if ([credential isKindOfClass:getASCPlatformPublicKeyCredentialRegistrationClass()]) {
    331                     attachment = AuthenticatorAttachment::Platform;
    332                     response.isAuthenticatorAttestationResponse = true;
    333 
    334                     ASCPlatformPublicKeyCredentialRegistration *registrationCredential = credential;
    335                     response.rawId = toArrayBuffer(registrationCredential.credentialID);
    336                     response.attestationObject = toArrayBuffer(registrationCredential.attestationObject);
    337                 } else if ([credential isKindOfClass:getASCSecurityKeyPublicKeyCredentialRegistrationClass()]) {
    338                     attachment = AuthenticatorAttachment::CrossPlatform;
    339                     response.isAuthenticatorAttestationResponse = true;
    340 
    341                     ASCSecurityKeyPublicKeyCredentialRegistration *registrationCredential = credential;
    342                     response.rawId = toArrayBuffer(registrationCredential.credentialID);
    343                     response.attestationObject = toArrayBuffer(registrationCredential.attestationObject);
    344                 } else if ([credential isKindOfClass:getASCPlatformPublicKeyCredentialAssertionClass()]) {
    345                     attachment = AuthenticatorAttachment::Platform;
    346                     response.isAuthenticatorAttestationResponse = false;
    347 
    348                     ASCPlatformPublicKeyCredentialAssertion *assertionCredential = credential;
    349                     response.rawId = toArrayBuffer(assertionCredential.credentialID);
    350                     response.authenticatorData = toArrayBuffer(assertionCredential.authenticatorData);
    351                     response.signature = toArrayBuffer(assertionCredential.signature);
    352                     response.userHandle = toArrayBuffer(assertionCredential.userHandle);
    353                 } else if ([credential isKindOfClass:getASCSecurityKeyPublicKeyCredentialAssertionClass()]) {
    354                     attachment = AuthenticatorAttachment::CrossPlatform;
    355                     response.isAuthenticatorAttestationResponse = false;
    356 
    357                     ASCSecurityKeyPublicKeyCredentialAssertion *assertionCredential = credential;
    358                     response.rawId = toArrayBuffer(assertionCredential.credentialID);
    359                     response.authenticatorData = toArrayBuffer(assertionCredential.authenticatorData);
    360                     response.signature = toArrayBuffer(assertionCredential.signature);
    361                     response.userHandle = toArrayBuffer(assertionCredential.userHandle);
    362                 } else {
    363                     attachment = (AuthenticatorAttachment) 0;
    364                     ExceptionCode exceptionCode;
    365                     NSString *errorMessage = nil;
    366                     if ([error.domain isEqualToString:WKErrorDomain]) {
    367                         exceptionCode = toExceptionCode(error.code);
    368                         errorMessage = error.userInfo[NSLocalizedDescriptionKey];
    369                     } else {
    370                         exceptionCode = NotAllowedError;
    371 
    372                         if ([error.domain isEqualToString:ASCAuthorizationErrorDomain] && error.code == ASCAuthorizationErrorUserCanceled)
    373                             errorMessage = @"This request has been cancelled by the user.";
    374                         else
    375                             errorMessage = @"Operation failed.";
    376                     }
    377 
    378                     exceptionData = { exceptionCode, errorMessage };
    379                 }
    380 
    381                 handler(response, attachment, exceptionData);
     388            [weakThis->m_presenter presentWithWindow:window.get() daemonEndpoint:daemonEndpoint.get() completionHandler:makeBlockPtr([handler = WTFMove(handler)](id<ASCCredentialProtocol> credentialNotRetain, NSError *errorNotRetain) mutable {
     389                auto credential = retainPtr(credentialNotRetain);
     390                auto error = retainPtr(errorNotRetain);
     391#endif
     392                continueAfterRequest(credential, error, WTFMove(handler));
     393#if PLATFORM(MAC)
    382394            }).get()];
     395#endif
    383396        });
    384397    }).get()];
    … …  
    395408}
    396409
     410void WebAuthenticatorCoordinatorProxy::cancel()
     411{
     412    if (m_proxy)
     413        [m_proxy cancelCurrentRequest];
     414}
     415
    397416} // namespace WebKit
    398417
  • branches/safari-613-branch/Source/WebKit/UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.cpp

    r292176 r292177  
    5454WebAuthenticatorCoordinatorProxy::~WebAuthenticatorCoordinatorProxy()
    5555{
     56#if HAVE(UNIFIED_ASC_AUTH_UI)
     57    cancel();
     58#endif // HAVE(UNIFIED_ASC_AUTH_UI)
    5659    m_webPageProxy.process().removeMessageReceiver(Messages::WebAuthenticatorCoordinatorProxy::messageReceiverName(), m_webPageProxy.webPageID());
    5760}
  • branches/safari-613-branch/Source/WebKit/UIProcess/WebAuthentication/WebAuthenticatorCoordinatorProxy.h

    r292176 r292177  
    4545OBJC_CLASS ASCAuthorizationRemotePresenter;
    4646OBJC_CLASS ASCCredentialRequestContext;
     47OBJC_CLASS ASCAgentProxy;
    4748#endif
    4849
    … …  
    5455struct WebAuthenticationRequestData;
    5556
     57using RequestCompletionHandler = CompletionHandler<void(const WebCore::AuthenticatorResponseData&, WebCore::AuthenticatorAttachment, const WebCore::ExceptionData&)>;
     58
    5659class WebAuthenticatorCoordinatorProxy : public IPC::MessageReceiver {
    5760    WTF_MAKE_FAST_ALLOCATED;
    … …  
    6265
    6366private:
    64     using RequestCompletionHandler = CompletionHandler<void(const WebCore::AuthenticatorResponseData&, WebCore::AuthenticatorAttachment, const WebCore::ExceptionData&)>;
    6567    using QueryCompletionHandler = CompletionHandler<void(bool)>;
    6668
    … …  
    7880
    7981#if HAVE(UNIFIED_ASC_AUTH_UI)
     82    void cancel();
    8083    RetainPtr<ASCCredentialRequestContext> contextForRequest(WebAuthenticationRequestData&&);
    8184    void performRequest(RetainPtr<ASCCredentialRequestContext>, RequestCompletionHandler&&);
    8285    RetainPtr<ASCAuthorizationRemotePresenter> m_presenter;
     86    RetainPtr<ASCAgentProxy> m_proxy;
    8387#endif // HAVE(UNIFIED_ASC_AUTH_UI)
    8488};
Note: See TracChangeset for help on using the changeset viewer.