Repository navigation
fix: explicitly look up MDM client identity for TLS auth challenges - #2732
ConnorCallison wants to merge 1 commit into
Conversation
WKWebView's .performDefaultHandling does not search the system keychain for client identities the way Safari does — Safari's web content process has special entitlements that third-party apps lack. On MDM-enrolled Macs, Microsoft Entra ID (Conditional Access) issues a TLS client- certificate challenge to verify device compliance. The previous fix (manaflow-ai#806) returned .performDefaultHandling, which works for server trust evaluation but does not trigger the keychain lookup needed for client certificate challenges. Use SecIdentityCopyPreferred to explicitly find the preferred client identity matching the server's host and acceptable CA distinguished names. This is the same lookup Safari performs internally. Non-MDM machines are unaffected — SecIdentityCopyPreferred returns nil when no matching identity exists, and the fallback to .performDefaultHandling preserves all other authentication flows. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
|
@ConnorCallison is attempting to deploy a commit to the Manaflow Team on Vercel. A member of the Team first needs to authorize it. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughThe changes enhance client-certificate authentication handling in two browser navigation delegate implementations. Rather than uniformly deferring to WebKit's default challenge handling, the code now attempts to locate a matching client identity from the system keychain using Changes
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Greptile SummaryThis PR replaces the blanket Confidence Score: 5/5Safe to merge — targeted, correct fix with no regressions on the non-MDM path. All changes are P2 or lower. The API usage is correct: SecIdentityCopyPreferred parameters match the expected types, nil certificates in URLCredential is the documented pattern for identity-only credentials, Security is properly imported in both files, and the fallback preserves existing behavior for all other challenge types. No files require special attention.
|
| Filename | Overview |
|---|---|
| Sources/Panels/BrowserPanel.swift | Replaces performDefaultHandling with explicit SecIdentityCopyPreferred lookup for client certificate challenges; Security framework was already imported; fallback path preserved. |
| Sources/Panels/BrowserPopupWindowController.swift | Parity update matching BrowserPanel; adds missing import Security and applies the same SecIdentityCopyPreferred pattern correctly. |
Sequence Diagram
sequenceDiagram
participant Server as MDM-Protected Server
participant WKWebView as WKWebView
participant Delegate as NavigationDelegate
participant Keychain as System Keychain
Server->>WKWebView: TLS ClientCertificate challenge
WKWebView->>Delegate: didReceive challenge
alt authMethod == ClientCertificate
Delegate->>Keychain: SecIdentityCopyPreferred(host, nil, issuers)
alt Identity found
Keychain-->>Delegate: SecIdentity
Delegate->>WKWebView: .useCredential(identity)
WKWebView->>Server: Client certificate presented
Server-->>WKWebView: Auth success (device compliant)
else No matching identity (non-MDM)
Keychain-->>Delegate: nil
Delegate->>WKWebView: .performDefaultHandling
end
else Other challenge (serverTrust, NTLM, SSO)
Delegate->>WKWebView: .performDefaultHandling
end
Reviews (1): Last reviewed commit: "fix: explicitly look up MDM client ident..." | Re-trigger Greptile
|
Thanks for this! Browser client-certificate sign-in (with a certificate picker) landed on main in #7040. You opened this first, so you got there first. Closing since main covers it now. |
Summary
.performDefaultHandlingwith explicitSecIdentityCopyPreferredkeychain lookup forNSURLAuthenticationMethodClientCertificatechallengesBrowserNavigationDelegateandPopupNavigationDelegatefor parityProblem
PR #806 added
webView(_:didReceive:completionHandler:)returning.performDefaultHandlingto fix Microsoft managed device authentication. While this works for server trust evaluation (validating MDM-installed root CAs), it does not trigger the system keychain lookup needed for client certificate challenges in WKWebView.Safari's web content process has special entitlements that allow
.performDefaultHandlingto automatically search the keychain for matching client identities. Third-party apps' WKWebViews lack these entitlements, so.performDefaultHandlingforNSURLAuthenticationMethodClientCertificateeffectively sends no certificate — making it functionally identical to the pre-#806 behavior for this specific challenge type.Fix
When a
NSURLAuthenticationMethodClientCertificatechallenge arrives, explicitly callSecIdentityCopyPreferred(_:_:_:)with the server's host and acceptable CA distinguished names. This runs in the app process (which has keychain access) and returns the MDM device identity certificate. The credential is then provided to WebKit via.useCredential.SecIdentityCopyPreferredreturns nil when no matching identity exists, and the fallback to.performDefaultHandlingpreserves all other authentication flows (server trust, NTLM, Kerberos, SSO extensions, etc.)Test plan
github.com(or any Microsoft Entra ID-protected SSO)🤖 Generated with Claude Code
Summary by cubic
Explicitly resolve the MDM client certificate from the system keychain for TLS client‑cert challenges in
WKWebView, fixing Microsoft Entra ID “this device needs to be under policy” errors. Applied to both the main browser and popup windows; other auth flows remain unchanged.NSURLAuthenticationMethodClientCertificate, useSecIdentityCopyPreferredwith the host and acceptable CA DNs, then pass the identity via.useCredential..performDefaultHandlingwhen no identity is found, preserving server trust, NTLM/Kerberos, and SSO behavior acrossBrowserNavigationDelegateandPopupNavigationDelegate.Written for commit 9c35c8d. Summary will update on new commits.
Summary by CodeRabbit