fix: resolve real-device blockers for vault open, biometrics, and AutoFill
- FileBookmarkService: hold a security scope while creating the bookmark, fixing "file doesn't exist" on iCloud Drive-backed vaults (NSCocoaErrorDomain Code=4), which only surfaced on a real device since the Simulator strips entitlements needed to reproduce this. - Fix Keychain access group missing the Team ID prefix, which silently broke saving the master password so Face ID was never offered after backgrounding. - Add the autofill-credential-provider entitlement to the main app target (previously only on the extension) and declare ProvidesPasswords in the extension's Info.plist, so MyPass now registers as a selectable AutoFill Passwords provider. - CredentialMatcher: fall back to a scheme-prefixed re-parse when extracting a host, since KDBX entries commonly store bare domains (e.g. "allocine.fr") that URL(string:).host can't parse without an authority component. Fixes AutoFill suggestions being unranked/wrong for such entries.
This commit is contained in:
@@ -13,7 +13,7 @@ final class CredentialProviderViewController: ASCredentialProviderViewController
|
|||||||
|
|
||||||
private let session = VaultSession()
|
private let session = VaultSession()
|
||||||
private let bookmarkService = FileBookmarkService()
|
private let bookmarkService = FileBookmarkService()
|
||||||
private let keychainStore = KeychainStore(accessGroup: "org.antiloop222.mypass")
|
private let keychainStore = KeychainStore(accessGroup: "F2KB6W8N4R.org.antiloop222.mypass")
|
||||||
private let biometricService = BiometricAuthService()
|
private let biometricService = BiometricAuthService()
|
||||||
|
|
||||||
// Called when the user selects MyPass from the QuickType bar.
|
// Called when the user selects MyPass from the QuickType bar.
|
||||||
|
|||||||
@@ -4,6 +4,14 @@
|
|||||||
<dict>
|
<dict>
|
||||||
<key>NSExtension</key>
|
<key>NSExtension</key>
|
||||||
<dict>
|
<dict>
|
||||||
|
<key>NSExtensionAttributes</key>
|
||||||
|
<dict>
|
||||||
|
<key>ASCredentialProviderExtensionCapabilities</key>
|
||||||
|
<dict>
|
||||||
|
<key>ProvidesPasswords</key>
|
||||||
|
<true/>
|
||||||
|
</dict>
|
||||||
|
</dict>
|
||||||
<key>NSExtensionMainStoryboard</key>
|
<key>NSExtensionMainStoryboard</key>
|
||||||
<string>MainInterface</string>
|
<string>MainInterface</string>
|
||||||
<key>NSExtensionPointIdentifier</key>
|
<key>NSExtensionPointIdentifier</key>
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
|
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
|
||||||
<plist version="1.0">
|
<plist version="1.0">
|
||||||
<dict>
|
<dict>
|
||||||
|
<key>com.apple.developer.authentication-services.autofill-credential-provider</key>
|
||||||
|
<true/>
|
||||||
<key>com.apple.security.application-groups</key>
|
<key>com.apple.security.application-groups</key>
|
||||||
<array>
|
<array>
|
||||||
<string>group.org.antiloop222.mypass</string>
|
<string>group.org.antiloop222.mypass</string>
|
||||||
|
|||||||
@@ -33,6 +33,11 @@ public final class FileBookmarkService {
|
|||||||
}
|
}
|
||||||
|
|
||||||
public func save(url: URL) throws {
|
public func save(url: URL) throws {
|
||||||
|
// For File Provider-backed URLs (e.g. iCloud Drive), creating a bookmark without
|
||||||
|
// an active security scope produces one that resolves later with
|
||||||
|
// NSCocoaErrorDomain Code=4 ("The file doesn't exist"), even immediately after picking.
|
||||||
|
let accessing = url.startAccessingSecurityScopedResource()
|
||||||
|
defer { if accessing { url.stopAccessingSecurityScopedResource() } }
|
||||||
let data = try url.bookmarkData(
|
let data = try url.bookmarkData(
|
||||||
options: Self.creationOptions,
|
options: Self.creationOptions,
|
||||||
includingResourceValuesForKeys: nil,
|
includingResourceValuesForKeys: nil,
|
||||||
|
|||||||
@@ -24,7 +24,7 @@ final class UnlockViewModel: ObservableObject {
|
|||||||
init(
|
init(
|
||||||
session: VaultSession,
|
session: VaultSession,
|
||||||
bookmarkService: FileBookmarkService = .init(),
|
bookmarkService: FileBookmarkService = .init(),
|
||||||
keychainStore: KeychainStore = .init(accessGroup: "org.antiloop222.mypass"),
|
keychainStore: KeychainStore = .init(accessGroup: "F2KB6W8N4R.org.antiloop222.mypass"),
|
||||||
biometricService: BiometricAuthService = .init()
|
biometricService: BiometricAuthService = .init()
|
||||||
) {
|
) {
|
||||||
self.session = session
|
self.session = session
|
||||||
|
|||||||
@@ -25,7 +25,14 @@ public enum CredentialMatcher {
|
|||||||
}
|
}
|
||||||
|
|
||||||
private static func host(from urlString: String) -> String? {
|
private static func host(from urlString: String) -> String? {
|
||||||
URL(string: urlString)?.host
|
// KDBX entries and AutoFill service identifiers commonly omit the scheme
|
||||||
|
// (e.g. "allocine.fr"), but URL(string:) only populates `.host` when an
|
||||||
|
// authority component ("//") is present -- without it, the whole string
|
||||||
|
// is parsed as a relative path and `.host` is nil.
|
||||||
|
if let host = URL(string: urlString)?.host, !host.isEmpty {
|
||||||
|
return host
|
||||||
|
}
|
||||||
|
return URL(string: "https://" + urlString)?.host
|
||||||
}
|
}
|
||||||
|
|
||||||
private static func hostsMatch(_ a: String, _ b: String) -> Bool {
|
private static func hostsMatch(_ a: String, _ b: String) -> Bool {
|
||||||
|
|||||||
@@ -31,6 +31,21 @@ final class CredentialMatcherTests: XCTestCase {
|
|||||||
XCTAssertFalse(CredentialMatcher.matches(entry: e, serviceIdentifier: "https://github.com"))
|
XCTAssertFalse(CredentialMatcher.matches(entry: e, serviceIdentifier: "https://github.com"))
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func test_bareDomainSubdomainMatch() {
|
||||||
|
let e = makeEntry(url: "allocine.fr")
|
||||||
|
XCTAssertTrue(CredentialMatcher.matches(entry: e, serviceIdentifier: "mon.allocine.fr"))
|
||||||
|
}
|
||||||
|
|
||||||
|
func test_bareDomainExactMatch() {
|
||||||
|
let e = makeEntry(url: "allocine.fr")
|
||||||
|
XCTAssertTrue(CredentialMatcher.matches(entry: e, serviceIdentifier: "allocine.fr"))
|
||||||
|
}
|
||||||
|
|
||||||
|
func test_bareDomainDifferentDomain_noMatch() {
|
||||||
|
let e = makeEntry(url: "allocine.fr")
|
||||||
|
XCTAssertFalse(CredentialMatcher.matches(entry: e, serviceIdentifier: "notallocine.fr"))
|
||||||
|
}
|
||||||
|
|
||||||
func test_filter_suggestedAndRest() {
|
func test_filter_suggestedAndRest() {
|
||||||
let entries = [
|
let entries = [
|
||||||
makeEntry(url: "https://github.com"),
|
makeEntry(url: "https://github.com"),
|
||||||
|
|||||||
Reference in New Issue
Block a user