Passkeys: Permissions Policy support

This commit is contained in:
Aleksandr Kolbasov 2026-02-07 03:20:24 +03:00
parent 6414dd24b7
commit 4c5d82c94c

View file

@ -63,7 +63,18 @@ const enablePasskeys = async function() {
}
};
const isSameOriginWithAncestors = function () {
/**
* @param {'create' | 'get'} action
* @returns {boolean}
*/
const isAllowedByPolicy = function (action) {
// https://www.w3.org/TR/webauthn-2/#sctn-permissions-policy
const policy = document.featurePolicy || document.permissionsPolicy;
if (policy) {
return policy.allowsFeature(`publickey-credentials-${action}`);
}
// fallback to sameOriginWithAncestors
try {
return window.origin === window.top.origin;
} catch (_err) {
@ -80,14 +91,14 @@ const enablePasskeys = async function() {
if (ev.detail.action === 'passkeys_create') {
const publicKey = kpxcPasskeysUtils.buildCredentialCreationOptions(
ev.detail.publicKey,
isSameOriginWithAncestors(),
isAllowedByPolicy('create'),
);
passkeysLogDebug('Passkey request', publicKey);
await sendResponse('passkeys_register', publicKey);
} else if (ev.detail.action === 'passkeys_get') {
const publicKey = kpxcPasskeysUtils.buildCredentialRequestOptions(
ev.detail.publicKey,
isSameOriginWithAncestors(),
isAllowedByPolicy('get'),
);
passkeysLogDebug('Passkey request', publicKey);
await sendResponse('passkeys_get', publicKey);