feat(browser): enable the Touch ID passkey authenticator on signed macOS builds

Sites gate passkey sign-in on isUserVerifyingPlatformAuthenticatorAvailable(),
which Electron reports as false until the app opts into the Touch ID
authenticator. GitHub's two-factor page then shows 'partial passkey support'
and the credential request waits on USB keys for Chromium's three-minute floor.

Configure the authenticator after ready from the keychain group in the signed
entitlements, render that entitlement at packaging time from APPLE_TEAM_ID, and
embed the Developer ID provisioning profile that macOS requires before it will
launch a binary claiming keychain-access-groups. Builds without the profile keep
the plain entitlements and today's behavior.
This commit is contained in:
Jinwoo-H
2026-09-07 01:47:34 -04:00
parent f1d8545024
commit febd6a4e64
12 changed files with 635 additions and 3 deletions
+9 -1
View File
@@ -15,7 +15,15 @@ Browser-use profiles let you run the Orca browser with a specific identity — a
Import cookies from Chrome or Edge (or from a cookie file) into a profile from Settings or the browser toolbar. Orca replaces existing cookies only for domains included in the import, so sign-ins for unrelated sites in the same profile stay intact. Google cookies are excluded — import menus show **Google logins aren't imported** and tell you to **Sign in to Google directly in Orca.** After an import that skipped Google cookies, a separate warning names the host that ran the import: open a browser in Orca on that host with the same profile, then sign in.
When a site requests a discoverable passkey from a USB security key and the key offers multiple accounts, Orca opens an account picker instead of silently canceling the sign-in. Choose the account you want or cancel the request. Platform passkeys stored by the operating system are not available in Orca yet; this flow is for external FIDO security keys.
## Passkeys
Sites can sign you in with a passkey inside Orca's browser. What is available depends on the platform:
- **macOS**: signed Orca builds offer a Touch ID passkey authenticator. When a site asks you to register a passkey, macOS shows the Touch ID sheet and stores the passkey in this Mac's Secure Enclave, scoped to the browser profile that created it. These passkeys are device-bound: they do not sync through iCloud Keychain, and passkeys you already keep in iCloud Keychain, Safari, or a password manager are not offered to sites in Orca. Register a new passkey for the site in Orca when it offers to, or use the site's other sign-in method.
- **Windows**: Windows handles passkey requests natively, so Windows Hello, security keys, and a phone via QR code all work as they do in other browsers.
- **Linux**: USB security keys only.
USB security keys work on every platform. When a security key or Touch ID offers more than one account for a site, Orca opens an account picker instead of silently canceling the sign-in. Choose the account you want or cancel the request.
## Use a profile