Skip to content

Wire zig-ctap2 for direct USB HID FIDO2 (no Apple entitlements needed) - #27

Merged
Jesssullivan merged 1 commit into
mainfrom
sid/ctap2-integration
Mar 22, 2026
Merged

Jesssullivan merged 1 commit into
mainfrom
sid/ctap2-integration

Conversation

@Jesssullivan

Copy link
Copy Markdown
Owner

Replace ASAuthorizationController (which requires restricted entitlements + provisioning profile) with direct CTAP2 over USB HID via the new zig-ctap2 library.

What changed

  • Added vendor/ctap2 submodule (jesssullivan/zig-ctap2)
  • libctap2.a static library built from Zig, linked into Xcode project
  • WebAuthnCoordinator.swift rewritten to call C FFI (ctap2_make_credential, ctap2_get_assertion)
  • CI workflows build libctap2 before xcodebuild
  • Module map for Swift bridging at Sources/FIDO2/module.modulemap

Why

ASAuthorizationController requires com.apple.developer.web-browser.public-key-credential (restricted entitlement + provisioning profile) for general-purpose browsers. Without it, every domain gets "not associated" errors. Direct CTAP2 over USB HID bypasses this entirely.

What works

  • Any build (unsigned, ad-hoc, developer-signed)
  • USB security keys (YubiKey, SoloKeys, etc.)
  • macOS (IOKit) and Linux (hidraw) transport

What doesn't

  • Platform authenticators (Touch ID / iCloud Keychain) — those still need AuthenticationServices

Replace AuthenticationServices-based security key handling in
WebAuthnCoordinator with direct CTAP2 calls via the zig-ctap2 C library.
This enables USB HID communication with FIDO2 security keys (YubiKey etc.)
without relying on Apple's ASAuthorization framework for the cross-platform
authenticator path.

Changes:
- Add vendor/ctap2 submodule (zig-ctap2 static library)
- Build libctap2.a and copy to project root for linking
- Create Sources/FIDO2/module.modulemap for Swift C interop
- Rewrite WebAuthnCoordinator to use ctap2_make_credential/ctap2_get_assertion
  C functions with SHA-256 client data hashing and CBOR response parsing
- Update project.pbxproj: add libctap2.a as linked library, add library
  search paths, Swift import paths for the module map, and IOKit/CoreFoundation
  framework dependencies
- Update fork-ci.yml and fork-release.yml to build libctap2 before xcodebuild
@Jesssullivan
Jesssullivan merged commit 890579f into main Mar 22, 2026
2 of 4 checks passed
@Jesssullivan
Jesssullivan deleted the sid/ctap2-integration branch March 27, 2026 14:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant