mirror of
https://github.com/stablyai/orca.git
synced 2026-09-29 08:03:20 +00:00
feat(browser): enable the Touch ID passkey authenticator on signed macOS builds
Sites gate passkey sign-in on isUserVerifyingPlatformAuthenticatorAvailable(), which Electron reports as false until the app opts into the Touch ID authenticator. GitHub's two-factor page then shows 'partial passkey support' and the credential request waits on USB keys for Chromium's three-minute floor. Configure the authenticator after ready from the keychain group in the signed entitlements, render that entitlement at packaging time from APPLE_TEAM_ID, and embed the Developer ID provisioning profile that macOS requires before it will launch a binary claiming keychain-access-groups. Builds without the profile keep the plain entitlements and today's behavior.
This commit is contained in:
@@ -205,6 +205,18 @@ jobs:
|
||||
retry_wait_seconds: 30
|
||||
command: pnpm install --frozen-lockfile
|
||||
|
||||
# Why: the Touch ID passkey authenticator needs a restricted keychain entitlement
|
||||
# that only an embedded Developer ID provisioning profile can authorise. Without
|
||||
# the profile the packager keeps the plain entitlements and passkeys stay off.
|
||||
- name: Materialize macOS provisioning profile
|
||||
if: env.MAC_PROVISIONING_PROFILE_BASE64 != ''
|
||||
shell: bash
|
||||
run: |
|
||||
printf '%s' "$MAC_PROVISIONING_PROFILE_BASE64" | base64 --decode > "$RUNNER_TEMP/orca.provisionprofile"
|
||||
echo "ORCA_MAC_PROVISIONING_PROFILE=$RUNNER_TEMP/orca.provisionprofile" >> "$GITHUB_ENV"
|
||||
env:
|
||||
MAC_PROVISIONING_PROFILE_BASE64: ${{ secrets.MAC_PROVISIONING_PROFILE }}
|
||||
|
||||
# Why: signing is what makes an adhoc build installable over an existing
|
||||
# Orca, so a missing cert must fail here rather than after a 20-minute build.
|
||||
- name: Verify macOS signing environment
|
||||
|
||||
@@ -176,6 +176,18 @@ jobs:
|
||||
retry_wait_seconds: 30
|
||||
command: pnpm install --frozen-lockfile
|
||||
|
||||
# Why: the Touch ID passkey authenticator needs a restricted keychain entitlement
|
||||
# that only an embedded Developer ID provisioning profile can authorise. Without
|
||||
# the profile the packager keeps the plain entitlements and passkeys stay off.
|
||||
- name: Materialize macOS provisioning profile
|
||||
if: steps.freshness.outputs.should_build == 'true' && env.MAC_PROVISIONING_PROFILE_BASE64 != ''
|
||||
shell: bash
|
||||
run: |
|
||||
printf '%s' "$MAC_PROVISIONING_PROFILE_BASE64" | base64 --decode > "$RUNNER_TEMP/orca.provisionprofile"
|
||||
echo "ORCA_MAC_PROVISIONING_PROFILE=$RUNNER_TEMP/orca.provisionprofile" >> "$GITHUB_ENV"
|
||||
env:
|
||||
MAC_PROVISIONING_PROFILE_BASE64: ${{ secrets.MAC_PROVISIONING_PROFILE }}
|
||||
|
||||
# Why: signing is what makes a daily installable over an existing Orca, so
|
||||
# a missing cert must fail here rather than after a 20-minute build.
|
||||
- name: Verify macOS signing environment
|
||||
|
||||
@@ -182,6 +182,18 @@ jobs:
|
||||
retry_wait_seconds: 30
|
||||
command: pnpm install --frozen-lockfile
|
||||
|
||||
# Why: the Touch ID passkey authenticator needs a restricted keychain entitlement
|
||||
# that only an embedded Developer ID provisioning profile can authorise. Without
|
||||
# the profile the packager keeps the plain entitlements and passkeys stay off.
|
||||
- name: Materialize macOS provisioning profile
|
||||
if: env.MAC_PROVISIONING_PROFILE_BASE64 != ''
|
||||
shell: bash
|
||||
run: |
|
||||
printf '%s' "$MAC_PROVISIONING_PROFILE_BASE64" | base64 --decode > "$RUNNER_TEMP/orca.provisionprofile"
|
||||
echo "ORCA_MAC_PROVISIONING_PROFILE=$RUNNER_TEMP/orca.provisionprofile" >> "$GITHUB_ENV"
|
||||
env:
|
||||
MAC_PROVISIONING_PROFILE_BASE64: ${{ secrets.MAC_PROVISIONING_PROFILE }}
|
||||
|
||||
# Why: signing is what makes an hourly installable over an existing Orca, so
|
||||
# a missing cert must fail here rather than after a 20-minute build.
|
||||
- name: Verify macOS signing environment
|
||||
|
||||
@@ -72,6 +72,18 @@ jobs:
|
||||
retry_wait_seconds: 30
|
||||
command: pnpm install --frozen-lockfile
|
||||
|
||||
# Why: the Touch ID passkey authenticator needs a restricted keychain entitlement
|
||||
# that only an embedded Developer ID provisioning profile can authorise. Without
|
||||
# the profile the packager keeps the plain entitlements and passkeys stay off.
|
||||
- name: Materialize macOS provisioning profile
|
||||
if: env.MAC_PROVISIONING_PROFILE_BASE64 != ''
|
||||
shell: bash
|
||||
run: |
|
||||
printf '%s' "$MAC_PROVISIONING_PROFILE_BASE64" | base64 --decode > "$RUNNER_TEMP/orca.provisionprofile"
|
||||
echo "ORCA_MAC_PROVISIONING_PROFILE=$RUNNER_TEMP/orca.provisionprofile" >> "$GITHUB_ENV"
|
||||
env:
|
||||
MAC_PROVISIONING_PROFILE_BASE64: ${{ secrets.MAC_PROVISIONING_PROFILE }}
|
||||
|
||||
- name: Verify macOS signing environment
|
||||
run: node config/scripts/verify-macos-release-env.mjs
|
||||
env:
|
||||
|
||||
Reference in New Issue
Block a user