Skip to content

Handle TLS auth challenges to fix Microsoft device compliance - #806

Merged
lawrencecchen merged 1 commit into
manaflow-ai:mainfrom
ConnorCallison:fix/device-policy-auth-challenge
Mar 4, 2026
Merged

lawrencecchen merged 1 commit into
manaflow-ai:mainfrom
ConnorCallison:fix/device-policy-auth-challenge

Conversation

@ConnorCallison

@ConnorCallison ConnorCallison commented Mar 3, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Implements webView(_:didReceive:completionHandler:) on BrowserNavigationDelegate with .performDefaultHandling disposition

Problem

When signing into GitHub (or any Microsoft Entra ID-protected resource) via the cmux browser on an MDM-enrolled Mac, Microsoft's Conditional Access shows "this device needs to be under policy" — even though Safari and Chrome on the same machine work fine.

Root Cause

WKWebView silently rejects all TLS authentication challenges when the navigation delegate doesn't implement webView(_:didReceive:completionHandler:). Apple's default disposition is .rejectProtectionSpace, not .performDefaultHandling.

This means:

  1. Microsoft's server issues a TLS client-certificate challenge to verify device compliance
  2. WKWebView rejects it (no delegate method → reject)
  3. The TLS handshake completes without a client certificate
  4. Microsoft sees an unmanaged device → blocks access with "device needs to be under policy"

Safari and Chrome handle this automatically because they implement their own authentication challenge handling that searches the system keychain for matching device identity certificates.

Fix

Add the delegate method and return .performDefaultHandling, which tells WebKit to use the system's standard URL-loading behavior:

  • Searches the system keychain for matching client identities (device certificates installed by MDM)
  • Trusts MDM-installed root CAs during server trust evaluation
  • Allows configured SSO extensions (e.g. Microsoft Enterprise SSO plug-in) to intercept and handle challenges

Test plan

  • On an MDM-enrolled Mac, open cmux browser and navigate to github.com (or any Microsoft Entra ID-protected SSO)
  • Sign in with corporate credentials — should no longer show "this device needs to be under policy"
  • Verify regular HTTPS sites still load normally (no regressions in server trust handling)
  • Verify non-MDM Macs are unaffected (.performDefaultHandling gracefully falls through when no client certificates exist)

🤖 Generated with Claude Code


Summary by cubic

Fixes Microsoft Entra ID sign-in showing "device needs to be under policy" in the cmux browser on MDM-enrolled Macs by handling TLS auth challenges in WKWebView. We now let WebKit perform its default handling so device certificates and SSO plugins work.

  • Bug Fixes
    • Implemented webView(_:didReceive:completionHandler:) in BrowserNavigationDelegate and return .performDefaultHandling.
    • Restores TLS client-certificate flows (uses system keychain and MDM roots) and allows Enterprise SSO plugins to intercept.
    • No change for non-MDM Macs; standard HTTPS sites behave as before.

Written for commit 577dd7c. Summary will update on new commits.

Summary by CodeRabbit

Bug Fixes

  • Improved handling of browser authentication challenges to properly support TLS connections, client certificate authentication, and single sign-on flows through enhanced system integration.

WKWebView rejects all authentication challenges by default when
webView(_:didReceive:completionHandler:) is not implemented, using
.rejectProtectionSpace. This silently breaks TLS client-certificate
flows like Microsoft Entra ID Conditional Access, which verifies
device compliance via a certificate stored in the system keychain
by MDM enrollment.

By implementing the delegate method and returning
.performDefaultHandling, the system's standard URL-loading behaviour
takes over: the keychain is searched for matching client identities,
MDM-installed root CAs are trusted, and any configured SSO extensions
(e.g. Microsoft Enterprise SSO) can intercept the challenge.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@vercel

vercel Bot commented Mar 3, 2026

Copy link
Copy Markdown

@ConnorCallison is attempting to deploy a commit to the Manaflow Team on Vercel.

A member of the Team first needs to authorize it.

@coderabbitai

coderabbitai Bot commented Mar 3, 2026 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

A new WKNavigationDelegate method is added to BrowserNavigationDelegate to handle TLS and authentication challenges from WKWebView by performing default system handling with nil credentials.

Changes

Cohort / File(s) Summary
WKNavigationDelegate Challenge Handler
Sources/Panels/BrowserPanel.swift
Added a new delegate method to handle TLS/authentication challenges from WKWebView, configured to use .performDefaultHandling for system-level certificate validation and SSO extensions.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Poem

🐰 A delegate springs forth with gentle care,
To let the system's defaults handle there,
TLS handshakes meet their destined way,
As challenges are passed without delay! 🔐

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check name Status Explanation
Title check ✅ Passed The title 'Handle TLS auth challenges to fix Microsoft device compliance' clearly and concisely describes the main change: implementing TLS authentication challenge handling for Microsoft device compliance issues.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment

Tip

Try Coding Plans. Let us write the prompt for your AI agent so you can ship faster (with fewer bugs).
Share your feedback on Discord.


Comment @coderabbitai help to get the list of available commands and usage tips.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

@greptile-apps

greptile-apps Bot commented Mar 3, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR implements TLS authentication challenge handling in the cmux browser to fix Microsoft Entra ID device compliance verification on MDM-enrolled Macs.

Key Changes:

  • Added webView(_:didReceive:completionHandler:) delegate method to BrowserNavigationDelegate
  • Returns .performDefaultHandling to delegate authentication to the system's URL loading behavior
  • Enables WKWebView to search the system keychain for MDM-installed client certificates
  • Allows Microsoft's Conditional Access to verify device compliance via TLS client certificates

Impact:
This change aligns cmux's WKWebView behavior with Safari and Chrome, which already handle authentication challenges through the system. Without this method, WKWebView's default behavior is to reject all authentication challenges (.rejectProtectionSpace), breaking TLS client-certificate flows needed for enterprise SSO and device compliance verification.

Confidence Score: 5/5

  • This PR is safe to merge with minimal risk
  • The implementation is minimal, well-documented, and uses Apple's recommended approach (.performDefaultHandling) which delegates to the system's secure URL loading behavior. The change only improves compatibility without introducing security risks or breaking existing functionality. No authentication challenges were handled before this PR, so the change is purely additive.
  • No files require special attention

Important Files Changed

Filename Overview
Sources/Panels/BrowserPanel.swift Added TLS authentication challenge handler with .performDefaultHandling to enable MDM client certificate flows for Microsoft Entra ID compliance

Last reviewed commit: 577dd7c

@lawrencecchen
lawrencecchen merged commit 80eca0d into manaflow-ai:main Mar 4, 2026
10 of 11 checks passed
@coderabbitai coderabbitai Bot mentioned this pull request Apr 1, 2026
2 tasks
bn-l pushed a commit to bn-l/cmux that referenced this pull request Apr 3, 2026
…ce (manaflow-ai#806)

WKWebView rejects all authentication challenges by default when
webView(_:didReceive:completionHandler:) is not implemented, using
.rejectProtectionSpace. This silently breaks TLS client-certificate
flows like Microsoft Entra ID Conditional Access, which verifies
device compliance via a certificate stored in the system keychain
by MDM enrollment.

By implementing the delegate method and returning
.performDefaultHandling, the system's standard URL-loading behaviour
takes over: the keychain is searched for matching client identities,
MDM-installed root CAs are trusted, and any configured SSO extensions
(e.g. Microsoft Enterprise SSO) can intercept the challenge.

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
ConnorCallison added a commit to ConnorCallison/cmux that referenced this pull request Apr 8, 2026
WKWebView's .performDefaultHandling does not search the system keychain
for client identities the way Safari does — Safari's web content process
has special entitlements that third-party apps lack. On MDM-enrolled
Macs, Microsoft Entra ID (Conditional Access) issues a TLS client-
certificate challenge to verify device compliance. The previous fix
(manaflow-ai#806) returned .performDefaultHandling, which works for server trust
evaluation but does not trigger the keychain lookup needed for client
certificate challenges.

Use SecIdentityCopyPreferred to explicitly find the preferred client
identity matching the server's host and acceptable CA distinguished
names. This is the same lookup Safari performs internally. Non-MDM
machines are unaffected — SecIdentityCopyPreferred returns nil when
no matching identity exists, and the fallback to .performDefaultHandling
preserves all other authentication flows.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants