Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion .github/workflows/nightly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -372,13 +372,15 @@ jobs:
do
CLI_PATH="$APP_PATH/Contents/Resources/bin/cmux"
HELPER_PATH="$APP_PATH/Contents/Resources/bin/ghostty"
# Sign app bundle first (--deep signs all nested content with full entitlements),
# then re-sign embedded binaries with narrower entitlements.
/usr/bin/codesign --force --options runtime --timestamp --sign "$APPLE_SIGNING_IDENTITY" --entitlements "$APP_ENTITLEMENTS" --deep "$APP_PATH"
if [ -f "$CLI_PATH" ]; then
/usr/bin/codesign --force --options runtime --timestamp --sign "$APPLE_SIGNING_IDENTITY" --entitlements "$EMBEDDED_ENTITLEMENTS" "$CLI_PATH"
fi
if [ -f "$HELPER_PATH" ]; then
/usr/bin/codesign --force --options runtime --timestamp --sign "$APPLE_SIGNING_IDENTITY" --entitlements "$EMBEDDED_ENTITLEMENTS" "$HELPER_PATH"
fi
/usr/bin/codesign --force --options runtime --timestamp --sign "$APPLE_SIGNING_IDENTITY" --entitlements "$APP_ENTITLEMENTS" --deep "$APP_PATH"
/usr/bin/codesign --verify --deep --strict --verbose=2 "$APP_PATH"
done

Expand Down
4 changes: 3 additions & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -238,13 +238,15 @@ jobs:
EMBEDDED_ENTITLEMENTS="cmux.embedded.entitlements"
CLI_PATH="$APP_PATH/Contents/Resources/bin/cmux"
HELPER_PATH="$APP_PATH/Contents/Resources/bin/ghostty"
# Sign app bundle first (--deep signs all nested content with full entitlements),
# then re-sign embedded binaries with narrower entitlements.
/usr/bin/codesign --force --options runtime --timestamp --sign "$APPLE_SIGNING_IDENTITY" --entitlements "$APP_ENTITLEMENTS" --deep "$APP_PATH"
if [ -f "$CLI_PATH" ]; then
/usr/bin/codesign --force --options runtime --timestamp --sign "$APPLE_SIGNING_IDENTITY" --entitlements "$EMBEDDED_ENTITLEMENTS" "$CLI_PATH"
fi
if [ -f "$HELPER_PATH" ]; then
/usr/bin/codesign --force --options runtime --timestamp --sign "$APPLE_SIGNING_IDENTITY" --entitlements "$EMBEDDED_ENTITLEMENTS" "$HELPER_PATH"
fi
/usr/bin/codesign --force --options runtime --timestamp --sign "$APPLE_SIGNING_IDENTITY" --entitlements "$APP_ENTITLEMENTS" --deep "$APP_PATH"
/usr/bin/codesign --verify --deep --strict --verbose=2 "$APP_PATH"

- name: Notarize app
Expand Down
3 changes: 3 additions & 0 deletions Sources/Panels/BrowserPanel.swift
Original file line number Diff line number Diff line change
Expand Up @@ -1755,6 +1755,7 @@ private struct BrowserPasskeyAuthorizationReply {
}
}

@available(macOS 15.0, *)
@MainActor
private final class BrowserPasskeyAuthorizationCoordinator: NSObject, WKScriptMessageHandlerWithReply {
weak var panel: BrowserPanel?
Expand Down Expand Up @@ -1972,6 +1973,7 @@ final class BrowserPanel: Panel, ObservableObject {

/// Popup windows owned by this panel (for lifecycle cleanup)
private var popupControllers: [BrowserPopupWindowController] = []
@available(macOS 15.0, *)
private lazy var passkeyAuthorizationCoordinator = BrowserPasskeyAuthorizationCoordinator(panel: self)
Comment on lines +1976 to 1977

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 @available on a lazy stored property in a non-restricted class

Placing @available(macOS 15.0, *) on a lazy var inside a class that itself has no availability restriction is valid in Swift 5.7+ but worth a quick note: unlike a function, the backing storage for a lazy var is part of the class's instance layout regardless of OS version. The guard in configurePasskeyAuthorizationBridge ensures the property is only ever accessed on macOS 15+, so the runtime behaviour is safe as written.

No change required — just noting this for future readers who might wonder why the pattern looks unusual. A brief comment above the property explaining the intent (e.g. "Only accessed after a #available(macOS 15.0, *) check in configurePasskeyAuthorizationBridge") would improve clarity.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!


static let telemetryHookBootstrapScriptSource = """
Expand Down Expand Up @@ -2935,6 +2937,7 @@ final class BrowserPanel: Panel, ObservableObject {
}

func configurePasskeyAuthorizationBridge(on configuration: WKWebViewConfiguration) {
guard #available(macOS 15.0, *) else { return }
let userContentController = configuration.userContentController
if !userContentController.userScripts.contains(where: { $0.source == Self.passkeyAuthorizationBootstrapScriptSource }) {
userContentController.addUserScript(
Expand Down
1 change: 0 additions & 1 deletion Sources/Panels/BrowserPopupWindowController.swift
Original file line number Diff line number Diff line change
Expand Up @@ -298,7 +298,6 @@ final class BrowserPopupWindowController: NSObject, NSWindowDelegate {
#endif
return nil
}
openerPanel?.configurePasskeyAuthorizationBridge(on: configuration)
let child = BrowserPopupWindowController(
configuration: configuration,
windowFeatures: windowFeatures,
Expand Down
5 changes: 4 additions & 1 deletion scripts/build-sign-upload.sh
Original file line number Diff line number Diff line change
Expand Up @@ -94,13 +94,16 @@ echo "Sparkle keys injected"
# --- Codesign ---
echo "Codesigning..."
CLI_PATH="$APP_PATH/Contents/Resources/bin/cmux"
# Sign app bundle first (--deep signs all nested content with full entitlements),
# then re-sign embedded binaries with narrower entitlements so they don't inherit
# the restricted public-key-credential entitlement.
/usr/bin/codesign --force --options runtime --timestamp --sign "$SIGN_HASH" --entitlements "$APP_ENTITLEMENTS" --deep "$APP_PATH"
if [ -f "$CLI_PATH" ]; then
/usr/bin/codesign --force --options runtime --timestamp --sign "$SIGN_HASH" --entitlements "$EMBEDDED_ENTITLEMENTS" "$CLI_PATH"
fi
if [ -f "$HELPER_PATH" ]; then
/usr/bin/codesign --force --options runtime --timestamp --sign "$SIGN_HASH" --entitlements "$EMBEDDED_ENTITLEMENTS" "$HELPER_PATH"
fi
/usr/bin/codesign --force --options runtime --timestamp --sign "$SIGN_HASH" --entitlements "$APP_ENTITLEMENTS" --deep "$APP_PATH"
/usr/bin/codesign --verify --deep --strict --verbose=2 "$APP_PATH"
echo "Codesign verified"

Expand Down