Skip to content

Add WebAuthn/FIDO2/YubiKey passthrough for browser panel - #2

Merged
Jesssullivan merged 1 commit into
mainfrom
sid/yubi-webauthn-fido2
Mar 20, 2026
Merged

Jesssullivan merged 1 commit into
mainfrom
sid/yubi-webauthn-fido2

Conversation

@Jesssullivan

Copy link
Copy Markdown
Owner

Summary

  • Full JS bridge + AuthenticationServices coordinator for WebAuthn in WKWebView
  • Hardware security key (YubiKey) and passkey support via ASAuthorizationController
  • Works without restricted Apple entitlement (public API path)
  • Entitlement split + codesign order fix for release builds
  • Popup window support for OAuth-based WebAuthn flows
  • NSBluetoothAlwaysUsageDescription for cross-device passkey flows

Addresses upstream #124, manaflow-ai#1278. Supersedes approach from upstream manaflow-ai#1021, manaflow-ai#1823.

Test plan

  • Build with ./scripts/reload.sh --tag webauthn
  • Test registration at https://webauthn.io
  • Test assertion at https://demo.yubico.com
  • Test GSuite sign-in with YubiKey 2FA
  • Test GitHub sign-in with security key
  • Test popup-based WebAuthn (OAuth flow)
  • Verify no typing latency regression

Implement full WebAuthn support via JS bridge + AuthenticationServices,
enabling hardware security key (YubiKey) and passkey authentication
in the cmux browser for GSuite, GitHub, GitLab, etc.

- WebAuthnBridgeJavaScript: intercepts navigator.credentials.create/get,
  serializes ArrayBuffer↔base64url, constructs spec-compliant clientDataJSON
  and PublicKeyCredential response objects
- WebAuthnCoordinator: native bridge using ASAuthorizationController with
  both SecurityKey and Platform credential providers, state machine,
  origin validation, exhaustive error mapping
- Integrated into BrowserPanel.bindWebView and BrowserPopupWindowController
  so WebAuthn works in both main browser and popup OAuth flows
- Added com.apple.developer.web-browser.public-key-credential entitlement
- Created cmux.embedded.entitlements for CLI/helper (narrow, no passkey)
- Fixed codesign order in release/nightly/build scripts: sign app --deep
  first, then re-sign embedded binaries with narrow entitlements
- Added NSBluetoothAlwaysUsageDescription for cross-device passkey flows

Addresses #124, manaflow-ai#1278. Supersedes approach from manaflow-ai#1021, manaflow-ai#1823.
@Jesssullivan
Jesssullivan merged commit 89e1506 into main Mar 20, 2026
3 of 9 checks passed
@Jesssullivan
Jesssullivan deleted the sid/yubi-webauthn-fido2 branch March 27, 2026 14:12
Jesssullivan added a commit that referenced this pull request Mar 29, 2026
- Update .gitmodules URL from manaflow-ai/ghostty to Jesssullivan/ghostty
- Submodule at 90a26469 with GHOSTTY_PLATFORM_LINUX in embedded.zig
  (Jesssullivan/ghostty#1) and #undef linux macro fix (#2)
- Update docs/ghostty-fork.md: document patch #8 (linux Platform variant)
  and switch header from manaflow-ai to Jesssullivan
Jesssullivan added a commit that referenced this pull request Mar 29, 2026
* Switch ghostty submodule to Jesssullivan/ghostty with linux Platform

- Update .gitmodules URL from manaflow-ai/ghostty to Jesssullivan/ghostty
- Submodule at 90a26469 with GHOSTTY_PLATFORM_LINUX in embedded.zig
  (Jesssullivan/ghostty#1) and #undef linux macro fix (#2)
- Update docs/ghostty-fork.md: document patch #8 (linux Platform variant)
  and switch header from manaflow-ai to Jesssullivan

* Scaffold cmux-linux GTK4 application (#77-83)

12 Zig source files implementing the full M5a Terminal MVP scope:

Sprint 1 - Foundation:
- main.zig: GtkApplication + libghostty init/wakeup/tick integration
- app.zig: Runtime callbacks (action, clipboard, close_surface)
- surface.zig: GtkGLArea + GHOSTTY_PLATFORM_LINUX surface creation
- c_api.zig: @cImport bindings for GTK4, libadwaita, ghostty.h
- config.zig: JSON config parser matching macOS schema (427 lines)
- build.zig: Links libghostty.so + GTK4 + libadwaita + OpenGL

Sprint 2 - Core UI:
- window.zig: AdwApplicationWindow + AdwTabView + AdwTabBar
- tab_manager.zig: Workspace list mapped to AdwTabView pages
- split_tree.zig: Binary tree split pane model with GtkPaned
- workspace.zig: Workspace data model (panels, title, color, status)
- sidebar.zig: AdwNavigationSplitView + GtkListBox workspace list

Sprint 3 - Platform Integration:
- socket.zig: Unix domain socket JSON-RPC server (XDG paths)
- session.zig: Session snapshot/restore (autosave 8s, atomic writes)

Compiles and links on Ubuntu, Fedora 42, and Arch Linux.
Closes #77, #78, #79, #80, #81, #82, #83.

* Add libghostty + cmux-linux build to CI, fix macOS xcframework

linux-ci.yml: Add libghostty build (-Dapp-runtime=none -Drenderer=opengl)
and cmux-linux build steps to all 3 Linux jobs (Ubuntu, Fedora, Arch).
Add font/rendering deps (freetype, harfbuzz, fontconfig, libpng, mesa).
Add zig build test step for config parser unit tests.

fork-ci.yml: Build GhosttyKit.xcframework from source instead of
downloading from manaflow-ai/ghostty releases. Uses native target
for faster CI builds.

* Add cmux-linux-build-check NixOS VM test

Verify GTK4 + libadwaita runtime libs are present in the NixOS VM.
Stepping stone toward full graphical cmux-linux tests (blocked on
Nix packaging of the libghostty build chain).

Update basic-window-check-gnome TODO to reflect PR #104 progress.
Jesssullivan added a commit that referenced this pull request Mar 29, 2026
* Switch ghostty submodule to Jesssullivan/ghostty with linux Platform

- Update .gitmodules URL from manaflow-ai/ghostty to Jesssullivan/ghostty
- Submodule at 90a26469 with GHOSTTY_PLATFORM_LINUX in embedded.zig
  (Jesssullivan/ghostty#1) and #undef linux macro fix (#2)
- Update docs/ghostty-fork.md: document patch #8 (linux Platform variant)
  and switch header from manaflow-ai to Jesssullivan

* Scaffold cmux-linux GTK4 application (#77-83)

12 Zig source files implementing the full M5a Terminal MVP scope:

Sprint 1 - Foundation:
- main.zig: GtkApplication + libghostty init/wakeup/tick integration
- app.zig: Runtime callbacks (action, clipboard, close_surface)
- surface.zig: GtkGLArea + GHOSTTY_PLATFORM_LINUX surface creation
- c_api.zig: @cImport bindings for GTK4, libadwaita, ghostty.h
- config.zig: JSON config parser matching macOS schema (427 lines)
- build.zig: Links libghostty.so + GTK4 + libadwaita + OpenGL

Sprint 2 - Core UI:
- window.zig: AdwApplicationWindow + AdwTabView + AdwTabBar
- tab_manager.zig: Workspace list mapped to AdwTabView pages
- split_tree.zig: Binary tree split pane model with GtkPaned
- workspace.zig: Workspace data model (panels, title, color, status)
- sidebar.zig: AdwNavigationSplitView + GtkListBox workspace list

Sprint 3 - Platform Integration:
- socket.zig: Unix domain socket JSON-RPC server (XDG paths)
- session.zig: Session snapshot/restore (autosave 8s, atomic writes)

Compiles and links on Ubuntu, Fedora 42, and Arch Linux.
Closes #77, #78, #79, #80, #81, #82, #83.

* Add libghostty + cmux-linux build to CI, fix macOS xcframework

linux-ci.yml: Add libghostty build (-Dapp-runtime=none -Drenderer=opengl)
and cmux-linux build steps to all 3 Linux jobs (Ubuntu, Fedora, Arch).
Add font/rendering deps (freetype, harfbuzz, fontconfig, libpng, mesa).
Add zig build test step for config parser unit tests.

fork-ci.yml: Build GhosttyKit.xcframework from source instead of
downloading from manaflow-ai/ghostty releases. Uses native target
for faster CI builds.

* Add cmux-linux-build-check NixOS VM test

Verify GTK4 + libadwaita runtime libs are present in the NixOS VM.
Stepping stone toward full graphical cmux-linux tests (blocked on
Nix packaging of the libghostty build chain).

Update basic-window-check-gnome TODO to reflect PR #104 progress.

* M5d: Linux packaging — desktop file, Flatpak, DEB, COPR (#97-100)

dist/linux/:
- com.jesssullivan.cmux.desktop — desktop entry for app launchers
- com.jesssullivan.cmux.metainfo.xml — AppStream metadata
- icons/ — 16x16, 128x128, 256x256, 512x512 PNGs

flatpak/:
- com.jesssullivan.cmux.yml — Flatpak manifest targeting
  org.gnome.Platform 47, builds libghostty + cmux-linux

debian/:
- control, rules, changelog, copyright — DEB packaging for
  Ubuntu 24.04+ (libgtk-4-1, libadwaita-1-0 deps)

dist/:
- cmux.spec — Fedora COPR RPM spec file

App ID: com.jesssullivan.cmux (consistent across all formats)

Closes #97, #98, #99, #100.
github-actions Bot pushed a commit that referenced this pull request Apr 13, 2026
The Ghostty upgrade made paste_from_clipboard a performable binding.
In performKeyEquivalent, the !isPerformable guard prevented the menu
from handling Cmd+V, so keyDown was called directly. Inside keyDown,
interpretKeyEvents triggered paste: (clipboard request #1) and then
ghostty_surface_key fired the same binding (clipboard request #2),
causing a double-paste race that corrupted the output.

Remove the !isPerformable exclusion so performable bindings like paste
also try the Edit menu first, restoring the single-request flow.
Jesssullivan added a commit that referenced this pull request Apr 18, 2026
…others

Promotes the three relative-close surface.action variants from stub
"not implemented" errors to working handlers.

Semantics match macOS v2TabAction:
  - close_left: remove all surfaces left of the anchor in ordered_panels
  - close_right: remove all surfaces right of the anchor
  - close_others: remove all surfaces except the anchor
  - Pinned surfaces are skipped in all three (skipped_pinned count echoed)
  - Focus is forced to the anchor surface after batch removal
  - Split tree and widget tree are rebuilt after mutations

Returns {action, surface_id, closed, skipped_pinned} matching the macOS
response shape.

Adds tests_v2/test_surface_action_close_variants.py covering the full
matrix: close_right from middle, close_left from middle, close_others,
pinned-surface skip, and no-op close_left at index 0.

Refs #220 (Sprint A item #2).
Jesssullivan added a commit that referenced this pull request Apr 18, 2026
…others

Promotes the three relative-close surface.action variants from stub
"not implemented" errors to working handlers.

Semantics match macOS v2TabAction:
  - close_left: remove all surfaces left of the anchor in ordered_panels
  - close_right: remove all surfaces right of the anchor
  - close_others: remove all surfaces except the anchor
  - Pinned surfaces are skipped in all three (skipped_pinned count echoed)
  - Focus is forced to the anchor surface after batch removal
  - Split tree and widget tree are rebuilt after mutations

Returns {action, surface_id, closed, skipped_pinned} matching the macOS
response shape.

Adds tests_v2/test_surface_action_close_variants.py covering the full
matrix: close_right from middle, close_left from middle, close_others,
pinned-surface skip, and no-op close_left at index 0.

Refs #220 (Sprint A item #2).
Jesssullivan added a commit that referenced this pull request Apr 18, 2026
…others (#227)

Promotes the three relative-close surface.action variants from stub
"not implemented" errors to working handlers.

Semantics match macOS v2TabAction:
  - close_left: remove all surfaces left of the anchor in ordered_panels
  - close_right: remove all surfaces right of the anchor
  - close_others: remove all surfaces except the anchor
  - Pinned surfaces are skipped in all three (skipped_pinned count echoed)
  - Focus is forced to the anchor surface after batch removal
  - Split tree and widget tree are rebuilt after mutations

Returns {action, surface_id, closed, skipped_pinned} matching the macOS
response shape.

Adds tests_v2/test_surface_action_close_variants.py covering the full
matrix: close_right from middle, close_left from middle, close_others,
pinned-surface skip, and no-op close_left at index 0.

Refs #220 (Sprint A item #2).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant