Title: [288501] branches/safari-613-branch
Revision
288501
Author
[email protected]
Date
2022-01-24 17:55:01 -0800 (Mon, 24 Jan 2022)

Log Message

Cherry-pick r288010. rdar://problem/87557846

    Expose way to encode CTAP commands with only the hash of ClientDataJSON
    https://bugs.webkit.org/show_bug.cgi?id=235191
    <rdar://problem/87557846>

    Reviewed by Brent Fulgham.

    Source/WebKit:

    CTAP command encoding covered by existing tests (see CtapRequestTest) and the SPI
    in new API tests.

    * UIProcess/API/Cocoa/_WKWebAuthenticationPanel.h:
    * UIProcess/API/Cocoa/_WKWebAuthenticationPanel.mm:
    (+[_WKWebAuthenticationPanel encodeMakeCredentialCommandWithClientDataHash:options:userVerificationAvailability:]):
    (+[_WKWebAuthenticationPanel encodeGetAssertionCommandWithClientDataHash:options:userVerificationAvailability:]):

    Tools:

    * TestWebKitAPI/Tests/WebKitCocoa/_WKWebAuthenticationPanel.mm:
    (TestWebKitAPI::TEST):
    Tests for new SPIs.

    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@288010 268f45cc-cd09-0410-ab3c-d52691b4dbfc

Modified Paths

Diff

Modified: branches/safari-613-branch/Source/WebKit/ChangeLog (288500 => 288501)


--- branches/safari-613-branch/Source/WebKit/ChangeLog	2022-01-25 01:54:57 UTC (rev 288500)
+++ branches/safari-613-branch/Source/WebKit/ChangeLog	2022-01-25 01:55:01 UTC (rev 288501)
@@ -1,3 +1,48 @@
+2022-01-24  Alan Coon  <[email protected]>
+
+        Cherry-pick r288010. rdar://problem/87557846
+
+    Expose way to encode CTAP commands with only the hash of ClientDataJSON
+    https://bugs.webkit.org/show_bug.cgi?id=235191
+    <rdar://problem/87557846>
+    
+    Reviewed by Brent Fulgham.
+    
+    Source/WebKit:
+    
+    CTAP command encoding covered by existing tests (see CtapRequestTest) and the SPI
+    in new API tests.
+    
+    * UIProcess/API/Cocoa/_WKWebAuthenticationPanel.h:
+    * UIProcess/API/Cocoa/_WKWebAuthenticationPanel.mm:
+    (+[_WKWebAuthenticationPanel encodeMakeCredentialCommandWithClientDataHash:options:userVerificationAvailability:]):
+    (+[_WKWebAuthenticationPanel encodeGetAssertionCommandWithClientDataHash:options:userVerificationAvailability:]):
+    
+    Tools:
+    
+    * TestWebKitAPI/Tests/WebKitCocoa/_WKWebAuthenticationPanel.mm:
+    (TestWebKitAPI::TEST):
+    Tests for new SPIs.
+    
+    
+    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@288010 268f45cc-cd09-0410-ab3c-d52691b4dbfc
+
+    2022-01-14  J Pascoe  <[email protected]>
+
+            Expose way to encode CTAP commands with only the hash of ClientDataJSON
+            https://bugs.webkit.org/show_bug.cgi?id=235191
+            <rdar://problem/87557846>
+
+            Reviewed by Brent Fulgham.
+
+            CTAP command encoding covered by existing tests (see CtapRequestTest) and the SPI
+            in new API tests.
+
+            * UIProcess/API/Cocoa/_WKWebAuthenticationPanel.h:
+            * UIProcess/API/Cocoa/_WKWebAuthenticationPanel.mm:
+            (+[_WKWebAuthenticationPanel encodeMakeCredentialCommandWithClientDataHash:options:userVerificationAvailability:]):
+            (+[_WKWebAuthenticationPanel encodeGetAssertionCommandWithClientDataHash:options:userVerificationAvailability:]):
+
 2022-01-20  Russell Epstein  <[email protected]>
 
         Cherry-pick r288293. rdar://problem/87777915

Modified: branches/safari-613-branch/Source/WebKit/UIProcess/API/Cocoa/_WKWebAuthenticationPanel.h (288500 => 288501)


--- branches/safari-613-branch/Source/WebKit/UIProcess/API/Cocoa/_WKWebAuthenticationPanel.h	2022-01-25 01:54:57 UTC (rev 288500)
+++ branches/safari-613-branch/Source/WebKit/UIProcess/API/Cocoa/_WKWebAuthenticationPanel.h	2022-01-25 01:55:01 UTC (rev 288501)
@@ -123,6 +123,9 @@
 + (NSData *)encodeMakeCredentialCommandWithClientDataJSON:(NSData *)clientDataJSON options:(_WKPublicKeyCredentialCreationOptions *)options userVerificationAvailability:(_WKWebAuthenticationUserVerificationAvailability)userVerificationAvailability WK_API_AVAILABLE(macos(WK_MAC_TBA), ios(WK_IOS_TBA));
 + (NSData *)encodeGetAssertionCommandWithClientDataJSON:(NSData *)clientDataJSON options:(_WKPublicKeyCredentialRequestOptions *)options userVerificationAvailability:(_WKWebAuthenticationUserVerificationAvailability)userVerificationAvailability WK_API_AVAILABLE(macos(WK_MAC_TBA), ios(WK_IOS_TBA));
 
++ (NSData *)encodeMakeCredentialCommandWithClientDataHash:(NSData *)clientDataHash options:(_WKPublicKeyCredentialCreationOptions *)options userVerificationAvailability:(_WKWebAuthenticationUserVerificationAvailability)userVerificationAvailability WK_API_AVAILABLE(macos(WK_MAC_TBA), ios(WK_IOS_TBA));
++ (NSData *)encodeGetAssertionCommandWithClientDataHash:(NSData *)clientDataHash options:(_WKPublicKeyCredentialRequestOptions *)options userVerificationAvailability:(_WKWebAuthenticationUserVerificationAvailability)userVerificationAvailability WK_API_AVAILABLE(macos(WK_MAC_TBA), ios(WK_IOS_TBA));
+
 - (instancetype)init;
 
 // FIXME: <rdar://problem/71509485> Adds detailed NSError.

Modified: branches/safari-613-branch/Source/WebKit/UIProcess/API/Cocoa/_WKWebAuthenticationPanel.mm (288500 => 288501)


--- branches/safari-613-branch/Source/WebKit/UIProcess/API/Cocoa/_WKWebAuthenticationPanel.mm	2022-01-25 01:54:57 UTC (rev 288500)
+++ branches/safari-613-branch/Source/WebKit/UIProcess/API/Cocoa/_WKWebAuthenticationPanel.mm	2022-01-25 01:55:01 UTC (rev 288501)
@@ -711,6 +711,29 @@
     return encodedCommand.autorelease();
 }
 
+
++ (NSData *)encodeMakeCredentialCommandWithClientDataHash:(NSData *)clientDataHash options:(_WKPublicKeyCredentialCreationOptions *)options userVerificationAvailability:(_WKWebAuthenticationUserVerificationAvailability)userVerificationAvailability
+{
+    RetainPtr<NSData> encodedCommand;
+#if ENABLE(WEB_AUTHN)
+    auto encodedVector = fido::encodeMakeCredenitalRequestAsCBOR(vectorFromNSData(clientDataHash), [_WKWebAuthenticationPanel convertToCoreCreationOptionsWithOptions:options], coreUserVerificationAvailability(userVerificationAvailability), std::nullopt);
+    encodedCommand = adoptNS([[NSData alloc] initWithBytes:encodedVector.data() length:encodedVector.size()]);
+#endif
+
+    return encodedCommand.autorelease();
+}
+
++ (NSData *)encodeGetAssertionCommandWithClientDataHash:(NSData *)clientDataHash options:(_WKPublicKeyCredentialRequestOptions *)options userVerificationAvailability:(_WKWebAuthenticationUserVerificationAvailability)userVerificationAvailability
+{
+    RetainPtr<NSData> encodedCommand;
+#if ENABLE(WEB_AUTHN)
+    auto encodedVector = fido::encodeGetAssertionRequestAsCBOR(vectorFromNSData(clientDataHash), [_WKWebAuthenticationPanel convertToCoreRequestOptionsWithOptions:options], coreUserVerificationAvailability(userVerificationAvailability), std::nullopt);
+    encodedCommand = adoptNS([[NSData alloc] initWithBytes:encodedVector.data() length:encodedVector.size()]);
+#endif
+
+    return encodedCommand.autorelease();
+}
+
 - (void)setMockConfiguration:(NSDictionary *)configuration
 {
 #if ENABLE(WEB_AUTHN)

Modified: branches/safari-613-branch/Tools/ChangeLog (288500 => 288501)


--- branches/safari-613-branch/Tools/ChangeLog	2022-01-25 01:54:57 UTC (rev 288500)
+++ branches/safari-613-branch/Tools/ChangeLog	2022-01-25 01:55:01 UTC (rev 288501)
@@ -1,3 +1,44 @@
+2022-01-24  Alan Coon  <[email protected]>
+
+        Cherry-pick r288010. rdar://problem/87557846
+
+    Expose way to encode CTAP commands with only the hash of ClientDataJSON
+    https://bugs.webkit.org/show_bug.cgi?id=235191
+    <rdar://problem/87557846>
+    
+    Reviewed by Brent Fulgham.
+    
+    Source/WebKit:
+    
+    CTAP command encoding covered by existing tests (see CtapRequestTest) and the SPI
+    in new API tests.
+    
+    * UIProcess/API/Cocoa/_WKWebAuthenticationPanel.h:
+    * UIProcess/API/Cocoa/_WKWebAuthenticationPanel.mm:
+    (+[_WKWebAuthenticationPanel encodeMakeCredentialCommandWithClientDataHash:options:userVerificationAvailability:]):
+    (+[_WKWebAuthenticationPanel encodeGetAssertionCommandWithClientDataHash:options:userVerificationAvailability:]):
+    
+    Tools:
+    
+    * TestWebKitAPI/Tests/WebKitCocoa/_WKWebAuthenticationPanel.mm:
+    (TestWebKitAPI::TEST):
+    Tests for new SPIs.
+    
+    
+    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@288010 268f45cc-cd09-0410-ab3c-d52691b4dbfc
+
+    2022-01-14  J Pascoe  <[email protected]>
+
+            Expose way to encode CTAP commands with only the hash of ClientDataJSON
+            https://bugs.webkit.org/show_bug.cgi?id=235191
+            <rdar://problem/87557846>
+
+            Reviewed by Brent Fulgham.
+
+            * TestWebKitAPI/Tests/WebKitCocoa/_WKWebAuthenticationPanel.mm:
+            (TestWebKitAPI::TEST):
+            Tests for new SPIs.
+
 2022-01-20  Russell Epstein  <[email protected]>
 
         Cherry-pick r287957. rdar://problem/87327557

Modified: branches/safari-613-branch/Tools/TestWebKitAPI/Tests/WebKitCocoa/_WKWebAuthenticationPanel.mm (288500 => 288501)


--- branches/safari-613-branch/Tools/TestWebKitAPI/Tests/WebKitCocoa/_WKWebAuthenticationPanel.mm	2022-01-25 01:54:57 UTC (rev 288500)
+++ branches/safari-613-branch/Tools/TestWebKitAPI/Tests/WebKitCocoa/_WKWebAuthenticationPanel.mm	2022-01-25 01:55:01 UTC (rev 288501)
@@ -2168,6 +2168,40 @@
     cleanUpKeychain("example.com");
 }
 
+TEST(WebAuthenticationPanel, EncodeCTAPAssertion)
+{
+    uint8_t hash[] = { 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04 };
+    auto nsHash = adoptNS([[NSData alloc] initWithBytes:hash length:sizeof(hash)]);
+    auto options = adoptNS([[_WKPublicKeyCredentialRequestOptions alloc] init]);
+
+    auto *command = [_WKWebAuthenticationPanel encodeGetAssertionCommandWithClientDataHash:nsHash.get() options: options.get() userVerificationAvailability:_WKWebAuthenticationUserVerificationAvailabilityNotSupported];
+
+    // Base64 of the following CBOR:
+    // 2, {1: "", 2: h'0102030401020304010203040102030401020304010203040102030401020304', 5: {"up": true}}
+    EXPECT_WK_STREQ([command base64EncodedStringWithOptions:0], "AqMBYAJYIAECAwQBAgMEAQIDBAECAwQBAgMEAQIDBAECAwQBAgMEBaFidXD1");
+}
+
+TEST(WebAuthenticationPanel, EncodeCTAPCreation)
+{
+    uint8_t hash[] = { 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04, 0x01, 0x02, 0x03, 0x04 };
+    auto nsHash = adoptNS([[NSData alloc] initWithBytes:hash length:sizeof(hash)]);
+    uint8_t identifier[] = { 0x01, 0x02, 0x03, 0x04 };
+    NSData *nsIdentifier = [NSData dataWithBytes:identifier length:sizeof(identifier)];
+    auto parameters = adoptNS([[_WKPublicKeyCredentialParameters alloc] initWithAlgorithm:@-7]);
+
+    auto rp = adoptNS([[_WKPublicKeyCredentialRelyingPartyEntity alloc] initWithName:@"example.com"]);
+    auto user = adoptNS([[_WKPublicKeyCredentialUserEntity alloc] initWithName:@"[email protected]" identifier:nsIdentifier displayName:@"J Appleseed"]);
+    NSArray<_WKPublicKeyCredentialParameters *> *publicKeyCredentialParamaters = @[ parameters.get() ];
+
+    auto options = adoptNS([[_WKPublicKeyCredentialCreationOptions alloc] initWithRelyingParty:rp.get() user:user.get() publicKeyCredentialParamaters:publicKeyCredentialParamaters]);
+
+    auto *command = [_WKWebAuthenticationPanel encodeMakeCredentialCommandWithClientDataHash:nsHash.get() options: options.get() userVerificationAvailability:_WKWebAuthenticationUserVerificationAvailabilityNotSupported];
+
+    // Base64 of the following CBOR:
+    // 1, {1: h'0102030401020304010203040102030401020304010203040102030401020304', 2: {"name": "example.com"}, 3: {"id": h'01020304', "name": "[email protected]", "displayName": "J Appleseed"}, 4: [{"alg": -7, "type": "public-key"}]}
+    EXPECT_WK_STREQ([command base64EncodedStringWithOptions:0], "AaQBWCABAgMEAQIDBAECAwQBAgMEAQIDBAECAwQBAgMEAQIDBAKhZG5hbWVrZXhhbXBsZS5jb20Do2JpZEQBAgMEZG5hbWV2amFwcGxlc2VlZEBleGFtcGxlLmNvbWtkaXNwbGF5TmFtZWtKIEFwcGxlc2VlZASBomNhbGcmZHR5cGVqcHVibGljLWtleQ==");
+}
+
 TEST(WebAuthenticationPanel, UpdateCredentialUsername)
 {
     reset();
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes

Reply via email to