Repository navigation
Handle TLS auth challenges to fix Microsoft device compliance - #806
lawrencecchen merged 1 commit into
Conversation
WKWebView rejects all authentication challenges by default when webView(_:didReceive:completionHandler:) is not implemented, using .rejectProtectionSpace. This silently breaks TLS client-certificate flows like Microsoft Entra ID Conditional Access, which verifies device compliance via a certificate stored in the system keychain by MDM enrollment. By implementing the delegate method and returning .performDefaultHandling, the system's standard URL-loading behaviour takes over: the keychain is searched for matching client identities, MDM-installed root CAs are trusted, and any configured SSO extensions (e.g. Microsoft Enterprise SSO) can intercept the challenge. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
|
@ConnorCallison is attempting to deploy a commit to the Manaflow Team on Vercel. A member of the Team first needs to authorize it. |
📝 WalkthroughWalkthroughA new WKNavigationDelegate method is added to BrowserNavigationDelegate to handle TLS and authentication challenges from WKWebView by performing default system handling with nil credentials. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~8 minutes Poem
🚥 Pre-merge checks | ✅ 2 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (2 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Tip Try Coding Plans. Let us write the prompt for your AI agent so you can ship faster (with fewer bugs). Comment |
Greptile SummaryThis PR implements TLS authentication challenge handling in the cmux browser to fix Microsoft Entra ID device compliance verification on MDM-enrolled Macs. Key Changes:
Impact: Confidence Score: 5/5
Important Files Changed
Last reviewed commit: 577dd7c |
…ce (manaflow-ai#806) WKWebView rejects all authentication challenges by default when webView(_:didReceive:completionHandler:) is not implemented, using .rejectProtectionSpace. This silently breaks TLS client-certificate flows like Microsoft Entra ID Conditional Access, which verifies device compliance via a certificate stored in the system keychain by MDM enrollment. By implementing the delegate method and returning .performDefaultHandling, the system's standard URL-loading behaviour takes over: the keychain is searched for matching client identities, MDM-installed root CAs are trusted, and any configured SSO extensions (e.g. Microsoft Enterprise SSO) can intercept the challenge. Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
WKWebView's .performDefaultHandling does not search the system keychain for client identities the way Safari does — Safari's web content process has special entitlements that third-party apps lack. On MDM-enrolled Macs, Microsoft Entra ID (Conditional Access) issues a TLS client- certificate challenge to verify device compliance. The previous fix (manaflow-ai#806) returned .performDefaultHandling, which works for server trust evaluation but does not trigger the keychain lookup needed for client certificate challenges. Use SecIdentityCopyPreferred to explicitly find the preferred client identity matching the server's host and acceptable CA distinguished names. This is the same lookup Safari performs internally. Non-MDM machines are unaffected — SecIdentityCopyPreferred returns nil when no matching identity exists, and the fallback to .performDefaultHandling preserves all other authentication flows. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Summary
webView(_:didReceive:completionHandler:)onBrowserNavigationDelegatewith.performDefaultHandlingdispositionProblem
When signing into GitHub (or any Microsoft Entra ID-protected resource) via the cmux browser on an MDM-enrolled Mac, Microsoft's Conditional Access shows "this device needs to be under policy" — even though Safari and Chrome on the same machine work fine.
Root Cause
WKWebViewsilently rejects all TLS authentication challenges when the navigation delegate doesn't implementwebView(_:didReceive:completionHandler:). Apple's default disposition is.rejectProtectionSpace, not.performDefaultHandling.This means:
Safari and Chrome handle this automatically because they implement their own authentication challenge handling that searches the system keychain for matching device identity certificates.
Fix
Add the delegate method and return
.performDefaultHandling, which tells WebKit to use the system's standard URL-loading behavior:Test plan
github.com(or any Microsoft Entra ID-protected SSO).performDefaultHandlinggracefully falls through when no client certificates exist)🤖 Generated with Claude Code
Summary by cubic
Fixes Microsoft Entra ID sign-in showing "device needs to be under policy" in the cmux browser on MDM-enrolled Macs by handling TLS auth challenges in WKWebView. We now let WebKit perform its default handling so device certificates and SSO plugins work.
Written for commit 577dd7c. Summary will update on new commits.
Summary by CodeRabbit
Bug Fixes