fix: resolve real-device blockers for vault open, biometrics, and AutoFill

- FileBookmarkService: hold a security scope while creating the bookmark,
  fixing "file doesn't exist" on iCloud Drive-backed vaults (NSCocoaErrorDomain
  Code=4), which only surfaced on a real device since the Simulator strips
  entitlements needed to reproduce this.
- Fix Keychain access group missing the Team ID prefix, which silently broke
  saving the master password so Face ID was never offered after backgrounding.
- Add the autofill-credential-provider entitlement to the main app target
  (previously only on the extension) and declare ProvidesPasswords in the
  extension's Info.plist, so MyPass now registers as a selectable AutoFill
  Passwords provider.
- CredentialMatcher: fall back to a scheme-prefixed re-parse when extracting a
  host, since KDBX entries commonly store bare domains (e.g. "allocine.fr")
  that URL(string:).host can't parse without an authority component. Fixes
  AutoFill suggestions being unranked/wrong for such entries.
This commit is contained in:
2026-09-20 12:39:45 +02:00
parent 5a59867d48
commit a8d612f745
7 changed files with 40 additions and 3 deletions
@@ -31,6 +31,21 @@ final class CredentialMatcherTests: XCTestCase {
XCTAssertFalse(CredentialMatcher.matches(entry: e, serviceIdentifier: "https://github.com"))
}
func test_bareDomainSubdomainMatch() {
let e = makeEntry(url: "allocine.fr")
XCTAssertTrue(CredentialMatcher.matches(entry: e, serviceIdentifier: "mon.allocine.fr"))
}
func test_bareDomainExactMatch() {
let e = makeEntry(url: "allocine.fr")
XCTAssertTrue(CredentialMatcher.matches(entry: e, serviceIdentifier: "allocine.fr"))
}
func test_bareDomainDifferentDomain_noMatch() {
let e = makeEntry(url: "allocine.fr")
XCTAssertFalse(CredentialMatcher.matches(entry: e, serviceIdentifier: "notallocine.fr"))
}
func test_filter_suggestedAndRest() {
let entries = [
makeEntry(url: "https://github.com"),