Repository navigation
Wire zig-ctap2 for direct USB HID FIDO2 (no Apple entitlements needed) - #27
Merged
Merged
Conversation
Replace AuthenticationServices-based security key handling in WebAuthnCoordinator with direct CTAP2 calls via the zig-ctap2 C library. This enables USB HID communication with FIDO2 security keys (YubiKey etc.) without relying on Apple's ASAuthorization framework for the cross-platform authenticator path. Changes: - Add vendor/ctap2 submodule (zig-ctap2 static library) - Build libctap2.a and copy to project root for linking - Create Sources/FIDO2/module.modulemap for Swift C interop - Rewrite WebAuthnCoordinator to use ctap2_make_credential/ctap2_get_assertion C functions with SHA-256 client data hashing and CBOR response parsing - Update project.pbxproj: add libctap2.a as linked library, add library search paths, Swift import paths for the module map, and IOKit/CoreFoundation framework dependencies - Update fork-ci.yml and fork-release.yml to build libctap2 before xcodebuild
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replace ASAuthorizationController (which requires restricted entitlements + provisioning profile) with direct CTAP2 over USB HID via the new zig-ctap2 library.
What changed
vendor/ctap2submodule (jesssullivan/zig-ctap2)libctap2.astatic library built from Zig, linked into Xcode projectWebAuthnCoordinator.swiftrewritten to call C FFI (ctap2_make_credential,ctap2_get_assertion)Sources/FIDO2/module.modulemapWhy
ASAuthorizationController requires
com.apple.developer.web-browser.public-key-credential(restricted entitlement + provisioning profile) for general-purpose browsers. Without it, every domain gets "not associated" errors. Direct CTAP2 over USB HID bypasses this entirely.What works
What doesn't