Compare commits

...

3 commits

Author SHA1 Message Date
Aleksandr Kolbasov
2014e79cd2
Merge aea8ac548c into b01af22fd1 2026-03-03 03:45:52 +03:00
Aleksandr Kolbasov
aea8ac548c Add debug logs to isAllowedByPolicy() 2026-02-12 23:01:11 +03:00
Aleksandr Kolbasov
4c5d82c94c Passkeys: Permissions Policy support 2026-02-07 03:20:24 +03:00

View file

@ -7,7 +7,8 @@ const PASSKEYS_WAIT_FOR_LIFETIMER = 30;
// Apply a script to the page for intercepting Passkeys (WebAuthn) requests
const enablePasskeys = async function() {
const passkeysLogDebug = function(message, extra) {
if (kpxcPasskeysUtils.debugLogging) {
// `global.js` runs at `document_idle`
if (kpxcPasskeysUtils.debugLogging && typeof debugLogMessage === 'function') {
debugLogMessage(message, extra);
}
};
@ -63,8 +64,21 @@ const enablePasskeys = async function() {
}
};
const isSameOriginWithAncestors = function () {
/**
* @param {'create' | 'get'} action
* @returns {boolean}
*/
const isAllowedByPolicy = function (action) {
// https://www.w3.org/TR/webauthn-2/#sctn-permissions-policy
const policy = document.featurePolicy || document.permissionsPolicy;
if (policy) {
passkeysLogDebug('Checking Permissions Policy');
return policy.allowsFeature(`publickey-credentials-${action}`);
}
// fallback to sameOriginWithAncestors
try {
passkeysLogDebug('Checking sameOriginWithAncestors');
return window.origin === window.top.origin;
} catch (_err) {
return false;
@ -80,14 +94,14 @@ const enablePasskeys = async function() {
if (ev.detail.action === 'passkeys_create') {
const publicKey = kpxcPasskeysUtils.buildCredentialCreationOptions(
ev.detail.publicKey,
isSameOriginWithAncestors(),
isAllowedByPolicy('create'),
);
passkeysLogDebug('Passkey request', publicKey);
await sendResponse('passkeys_register', publicKey);
} else if (ev.detail.action === 'passkeys_get') {
const publicKey = kpxcPasskeysUtils.buildCredentialRequestOptions(
ev.detail.publicKey,
isSameOriginWithAncestors(),
isAllowedByPolicy('get'),
);
passkeysLogDebug('Passkey request', publicKey);
await sendResponse('passkeys_get', publicKey);