Skip to content

Upstream/typed authentication context - #264

Open
LucaCappelletti94 wants to merge 2 commits into
kornelski:mainfrom
LucaCappelletti94:upstream/typed-authentication-context
Open

LucaCappelletti94 wants to merge 2 commits into
kornelski:mainfrom
LucaCappelletti94:upstream/typed-authentication-context

Conversation

@LucaCappelletti94

Copy link
Copy Markdown

This PR is "stacked" on #263 and adds an AuthenticationContext behind an opt-in local-authentication feature, accepted by both ItemSearchOptions and PasswordOptions, so callers need no unsafe bridging and cannot pass a non-LAContext object. Its builder sets the prompt text, since kSecUseOperationPrompt is deprecated in favour of localizedReason.

I am unsure whether AuthenticationContext should be Send + Sync, as it currently is. An app often wants one context for all its threads, the context cannot change once built, and the crate only passes it to SecItem* without calling its methods, but Apple's SDK headers mark several LocalAuthentication types NS_SWIFT_SENDABLE and LAContext is not marked as such. Without these impls, an app that needs sharing can still write its own unsafe impl and takes on that assumption itself.

Measured on an iPhone 15 Pro Max through apple-native-keyring-store, a shared context gave one Face ID sheet for the first read in ~2s, and none for the later reads and update, which took ~10ms each. The unsafe on LAContext goes away with madsmtm/objc2#864.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant