feat(browser): enable the Touch ID passkey authenticator on signed macOS builds

Sites gate passkey sign-in on isUserVerifyingPlatformAuthenticatorAvailable(),
which Electron reports as false until the app opts into the Touch ID
authenticator. GitHub's two-factor page then shows 'partial passkey support'
and the credential request waits on USB keys for Chromium's three-minute floor.

Configure the authenticator after ready from the keychain group in the signed
entitlements, render that entitlement at packaging time from APPLE_TEAM_ID, and
embed the Developer ID provisioning profile that macOS requires before it will
launch a binary claiming keychain-access-groups. Builds without the profile keep
the plain entitlements and today's behavior.
This commit is contained in:
Jinwoo-H
2026-09-07 01:47:34 -04:00
parent f1d8545024
commit febd6a4e64
12 changed files with 635 additions and 3 deletions
+12
View File
@@ -205,6 +205,18 @@ jobs:
retry_wait_seconds: 30
command: pnpm install --frozen-lockfile
# Why: the Touch ID passkey authenticator needs a restricted keychain entitlement
# that only an embedded Developer ID provisioning profile can authorise. Without
# the profile the packager keeps the plain entitlements and passkeys stay off.
- name: Materialize macOS provisioning profile
if: env.MAC_PROVISIONING_PROFILE_BASE64 != ''
shell: bash
run: |
printf '%s' "$MAC_PROVISIONING_PROFILE_BASE64" | base64 --decode > "$RUNNER_TEMP/orca.provisionprofile"
echo "ORCA_MAC_PROVISIONING_PROFILE=$RUNNER_TEMP/orca.provisionprofile" >> "$GITHUB_ENV"
env:
MAC_PROVISIONING_PROFILE_BASE64: ${{ secrets.MAC_PROVISIONING_PROFILE }}
# Why: signing is what makes an adhoc build installable over an existing
# Orca, so a missing cert must fail here rather than after a 20-minute build.
- name: Verify macOS signing environment
+12
View File
@@ -176,6 +176,18 @@ jobs:
retry_wait_seconds: 30
command: pnpm install --frozen-lockfile
# Why: the Touch ID passkey authenticator needs a restricted keychain entitlement
# that only an embedded Developer ID provisioning profile can authorise. Without
# the profile the packager keeps the plain entitlements and passkeys stay off.
- name: Materialize macOS provisioning profile
if: steps.freshness.outputs.should_build == 'true' && env.MAC_PROVISIONING_PROFILE_BASE64 != ''
shell: bash
run: |
printf '%s' "$MAC_PROVISIONING_PROFILE_BASE64" | base64 --decode > "$RUNNER_TEMP/orca.provisionprofile"
echo "ORCA_MAC_PROVISIONING_PROFILE=$RUNNER_TEMP/orca.provisionprofile" >> "$GITHUB_ENV"
env:
MAC_PROVISIONING_PROFILE_BASE64: ${{ secrets.MAC_PROVISIONING_PROFILE }}
# Why: signing is what makes a daily installable over an existing Orca, so
# a missing cert must fail here rather than after a 20-minute build.
- name: Verify macOS signing environment
+12
View File
@@ -182,6 +182,18 @@ jobs:
retry_wait_seconds: 30
command: pnpm install --frozen-lockfile
# Why: the Touch ID passkey authenticator needs a restricted keychain entitlement
# that only an embedded Developer ID provisioning profile can authorise. Without
# the profile the packager keeps the plain entitlements and passkeys stay off.
- name: Materialize macOS provisioning profile
if: env.MAC_PROVISIONING_PROFILE_BASE64 != ''
shell: bash
run: |
printf '%s' "$MAC_PROVISIONING_PROFILE_BASE64" | base64 --decode > "$RUNNER_TEMP/orca.provisionprofile"
echo "ORCA_MAC_PROVISIONING_PROFILE=$RUNNER_TEMP/orca.provisionprofile" >> "$GITHUB_ENV"
env:
MAC_PROVISIONING_PROFILE_BASE64: ${{ secrets.MAC_PROVISIONING_PROFILE }}
# Why: signing is what makes an hourly installable over an existing Orca, so
# a missing cert must fail here rather than after a 20-minute build.
- name: Verify macOS signing environment
+12
View File
@@ -72,6 +72,18 @@ jobs:
retry_wait_seconds: 30
command: pnpm install --frozen-lockfile
# Why: the Touch ID passkey authenticator needs a restricted keychain entitlement
# that only an embedded Developer ID provisioning profile can authorise. Without
# the profile the packager keeps the plain entitlements and passkeys stay off.
- name: Materialize macOS provisioning profile
if: env.MAC_PROVISIONING_PROFILE_BASE64 != ''
shell: bash
run: |
printf '%s' "$MAC_PROVISIONING_PROFILE_BASE64" | base64 --decode > "$RUNNER_TEMP/orca.provisionprofile"
echo "ORCA_MAC_PROVISIONING_PROFILE=$RUNNER_TEMP/orca.provisionprofile" >> "$GITHUB_ENV"
env:
MAC_PROVISIONING_PROFILE_BASE64: ${{ secrets.MAC_PROVISIONING_PROFILE }}
- name: Verify macOS signing environment
run: node config/scripts/verify-macos-release-env.mjs
env: