Files
keevault/MyPassCore/Sources/MyPassCore/AutoFill/CredentialMatcher.swift
T
kriss a8d612f745 fix: resolve real-device blockers for vault open, biometrics, and AutoFill
- FileBookmarkService: hold a security scope while creating the bookmark,
  fixing "file doesn't exist" on iCloud Drive-backed vaults (NSCocoaErrorDomain
  Code=4), which only surfaced on a real device since the Simulator strips
  entitlements needed to reproduce this.
- Fix Keychain access group missing the Team ID prefix, which silently broke
  saving the master password so Face ID was never offered after backgrounding.
- Add the autofill-credential-provider entitlement to the main app target
  (previously only on the extension) and declare ProvidesPasswords in the
  extension's Info.plist, so MyPass now registers as a selectable AutoFill
  Passwords provider.
- CredentialMatcher: fall back to a scheme-prefixed re-parse when extracting a
  host, since KDBX entries commonly store bare domains (e.g. "allocine.fr")
  that URL(string:).host can't parse without an authority component. Fixes
  AutoFill suggestions being unranked/wrong for such entries.
2026-09-20 12:39:45 +02:00

50 lines
1.9 KiB
Swift

import Foundation
public enum CredentialMatcher {
public static func matches(entry: Entry, serviceIdentifier: String) -> Bool {
guard !entry.url.isEmpty else { return false }
guard let entryHost = host(from: entry.url),
let serviceHost = host(from: serviceIdentifier)
else {
return entry.url.lowercased().contains(serviceIdentifier.lowercased())
}
return hostsMatch(entryHost, serviceHost)
}
public static func filter(
entries: [Entry],
for serviceIdentifiers: [String]
) -> (suggested: [Entry], all: [Entry]) {
guard !serviceIdentifiers.isEmpty else { return ([], entries) }
let suggested = entries.filter { entry in
serviceIdentifiers.contains { matches(entry: entry, serviceIdentifier: $0) }
}
let suggestedIDs = Set(suggested.map(\.id))
let rest = entries.filter { !suggestedIDs.contains($0.id) }
return (suggested: suggested, all: rest)
}
private static func host(from urlString: String) -> String? {
// KDBX entries and AutoFill service identifiers commonly omit the scheme
// (e.g. "allocine.fr"), but URL(string:) only populates `.host` when an
// authority component ("//") is present -- without it, the whole string
// is parsed as a relative path and `.host` is nil.
if let host = URL(string: urlString)?.host, !host.isEmpty {
return host
}
return URL(string: "https://" + urlString)?.host
}
private static func hostsMatch(_ a: String, _ b: String) -> Bool {
let na = stripped(a)
let nb = stripped(b)
return na == nb
|| na.hasSuffix("." + nb)
|| nb.hasSuffix("." + na)
}
private static func stripped(_ host: String) -> String {
host.hasPrefix("www.") ? String(host.dropFirst(4)).lowercased() : host.lowercased()
}
}