Allow each browsing context to have a in-flight conditional get request. A "conditionally mediated" WebAuthn request is a site's intention to submit a request in response to user interaction with browser-presented autofill UI. The WebAuthn spec only allows one active request at a time, but a conditional request can stay pending while another request is active. Prior to this patch we incorrectly applied the uniqueness requirement to conditional requests. The previous design had some other deficiencies as well. We held pending requests at the level of the platform nsIWebAuthnService, which meant we had duplicate logic for dispatching a pending request at each service. This patch hoists the pending request management up to the top level WebAuthnService, adds a new GetAutoFillEntriesForRpId method which allows WebAuthnService to request autofill entries from the platform-specific service, and simplifies the state management at the platform level. As part of this refactor it was natural to also remove some unnecessary synchronization mechanisms from the platform-specific nsIWebAuthnServices. Back when WebAuthnTransactionParent ran on the IPDL Background Thread we needed these synchronization mechanisms to allow prompts / main thread UI to cancel WebAuthn operations. This has not been necessary since Bug 1945969, which moved WebAuthnTransactionParent to the main thread. Differential Revision: https://phabricator.services.mozilla.com/D301134
119 lines
3.7 KiB
C++
119 lines
3.7 KiB
C++
/* This Source Code Form is subject to the terms of the Mozilla Public
|
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
|
|
|
|
#ifndef mozilla_dom_WebAuthnService_h_
|
|
#define mozilla_dom_WebAuthnService_h_
|
|
|
|
#include "AuthrsBridge_ffi.h"
|
|
#include "WebAuthnArgs.h"
|
|
#include "mozilla/StaticPrefs_security.h"
|
|
#include "mozilla/dom/WebAuthnPromiseHolder.h"
|
|
#include "nsIWebAuthnService.h"
|
|
|
|
#ifdef MOZ_WIDGET_ANDROID
|
|
# include "AndroidWebAuthnService.h"
|
|
#endif
|
|
|
|
#ifdef XP_MACOSX
|
|
# include "MacOSWebAuthnService.h"
|
|
#endif
|
|
|
|
#ifdef XP_WIN
|
|
# include "WinWebAuthnService.h"
|
|
#endif
|
|
|
|
namespace mozilla::dom {
|
|
|
|
already_AddRefed<nsIWebAuthnService> NewWebAuthnService();
|
|
|
|
class WebAuthnService final : public nsIWebAuthnService {
|
|
public:
|
|
NS_DECL_THREADSAFE_ISUPPORTS
|
|
NS_DECL_NSIWEBAUTHNSERVICE
|
|
|
|
WebAuthnService() {
|
|
(void)authrs_service_constructor(getter_AddRefs(mAuthrsService));
|
|
#if defined(XP_WIN)
|
|
if (WinWebAuthnService::AreWebAuthNApisAvailable()) {
|
|
mPlatformService = new WinWebAuthnService();
|
|
} else {
|
|
mPlatformService = mAuthrsService;
|
|
}
|
|
#elif defined(MOZ_WIDGET_ANDROID)
|
|
mPlatformService = new AndroidWebAuthnService();
|
|
#elif defined(XP_MACOSX)
|
|
if (__builtin_available(macos 13.3, *)) {
|
|
mPlatformService = NewMacOSWebAuthnServiceIfAvailable();
|
|
}
|
|
if (!mPlatformService) {
|
|
mPlatformService = mAuthrsService;
|
|
}
|
|
#else
|
|
mPlatformService = mAuthrsService;
|
|
#endif
|
|
}
|
|
|
|
private:
|
|
~WebAuthnService() = default;
|
|
|
|
struct TransactionState {
|
|
nsCOMPtr<nsIWebAuthnService> service;
|
|
uint64_t transactionId;
|
|
Maybe<nsCOMPtr<nsIWebAuthnRegisterPromise>> parentRegisterPromise;
|
|
Maybe<nsCOMPtr<nsIWebAuthnRegisterResult>> registerResult;
|
|
MozPromiseRequestHolder<WebAuthnRegisterPromise> childRegisterRequest;
|
|
};
|
|
|
|
struct ConditionalGet {
|
|
uint64_t transactionId;
|
|
uint64_t browsingContextId;
|
|
nsCOMPtr<nsIWebAuthnSignArgs> signArgs;
|
|
nsCOMPtr<nsIWebAuthnSignPromise> signPromise;
|
|
};
|
|
|
|
// Main thread only:
|
|
// The current modal operation.
|
|
Maybe<TransactionState> mActiveTransaction;
|
|
// Pending conditional (autofill) GetAssertion requests, at most one per
|
|
// tab.
|
|
nsTArray<ConditionalGet> mConditionalGets;
|
|
|
|
void ShowAttestationConsentPrompt(const nsString& aOrigin,
|
|
uint64_t aTransactionId,
|
|
uint64_t aBrowsingContextId);
|
|
void RejectActiveRegisterPromise();
|
|
void ResetActiveTransaction();
|
|
Maybe<ConditionalGet> TakeConditionalByTid(uint64_t aTransactionId);
|
|
nsresult DispatchConditionalGetAssertion(const ConditionalGet& aPending,
|
|
nsIWebAuthnSignArgs* aArgs);
|
|
|
|
nsIWebAuthnService* DefaultService() {
|
|
if (StaticPrefs::security_webauth_webauthn_enable_softtoken()) {
|
|
return mAuthrsService;
|
|
}
|
|
return mPlatformService;
|
|
}
|
|
|
|
// Returns the authrs_bridge service. This is the default service on some
|
|
// platforms, and it is used as a fallback to workaround platform specific
|
|
// bugs on others. It is also used for all commands related to the WebDriver
|
|
// Virtual Authenticator extension.
|
|
nsIWebAuthnService* AuthrsService() { return mAuthrsService; }
|
|
|
|
// Returns the service backing the current active transaction. The caller is
|
|
// responsible for ensuring that there is an active transaction.
|
|
nsIWebAuthnService* ActiveService() {
|
|
MOZ_ASSERT(NS_IsMainThread());
|
|
MOZ_ASSERT(mActiveTransaction.isSome());
|
|
return mActiveTransaction.ref().service;
|
|
}
|
|
|
|
nsCOMPtr<nsIWebAuthnService> mAuthrsService;
|
|
nsCOMPtr<nsIWebAuthnService> mPlatformService;
|
|
};
|
|
|
|
} // namespace mozilla::dom
|
|
|
|
#endif // mozilla_dom_WebAuthnService_h_
|