[app-attest-env] Merge production-environment fix into opt-in-prompts, port to flat layout
Resolves the App Attest env/entitlements changes onto the flattened PediFoods.xcodeproj structure (Darwin/PediFoods.xcodeproj no longer exists on this branch). Also restores Release signing to Manual / Apple Distribution / AppStore provisioning profile - the merged-in fix had switched it to Automatic / Apple Development, which breaks headless CI archiving.
This commit is contained in:
@@ -93,6 +93,7 @@ actor GuestSessionService {
|
||||
|
||||
#if os(iOS)
|
||||
private func refreshTokenWithAppAttest() async throws -> String {
|
||||
print("[GuestSessionService] DCAppAttestService.isSupported = \(DCAppAttestService.shared.isSupported), existingKeyId = \(store.appAttestKeyId ?? "nil")")
|
||||
guard DCAppAttestService.shared.isSupported else {
|
||||
// Simulator can never support App Attest (hardware limitation,
|
||||
// not environment-specific) — server has its own documented
|
||||
@@ -112,6 +113,15 @@ actor GuestSessionService {
|
||||
// other error (network blip, timeout, decode issue) must
|
||||
// NOT wipe a perfectly valid registered key.
|
||||
store.appAttestKeyId = nil
|
||||
} catch let error as DCError {
|
||||
// DeviceCheck itself rejects the key locally (e.g. the app
|
||||
// was reinstalled and the Secure Enclave key backing this
|
||||
// keyId no longer exists) - distinct from the server
|
||||
// rejecting it, but equally unrecoverable without a fresh
|
||||
// key. Without this, generateAssertion fails the same way
|
||||
// forever since appAttestKeyId is never cleared.
|
||||
print("[GuestSessionService] existing key rejected locally, re-attesting with a fresh key: \(error)")
|
||||
store.appAttestKeyId = nil
|
||||
}
|
||||
}
|
||||
|
||||
@@ -141,9 +151,22 @@ actor GuestSessionService {
|
||||
}
|
||||
|
||||
private func handshakeWithFreshAttestation(challenge: String) async throws -> String {
|
||||
let keyId = try await DCAppAttestService.shared.generateKey()
|
||||
let keyId: String
|
||||
do {
|
||||
keyId = try await DCAppAttestService.shared.generateKey()
|
||||
} catch {
|
||||
print("[GuestSessionService] generateKey failed: \(error)")
|
||||
throw error
|
||||
}
|
||||
|
||||
let clientDataHash = Data(SHA256.hash(data: Data(challenge.utf8)))
|
||||
let attestationObject = try await DCAppAttestService.shared.attestKey(keyId, clientDataHash: clientDataHash)
|
||||
let attestationObject: Data
|
||||
do {
|
||||
attestationObject = try await DCAppAttestService.shared.attestKey(keyId, clientDataHash: clientDataHash)
|
||||
} catch {
|
||||
print("[GuestSessionService] attestKey failed: \(error)")
|
||||
throw error
|
||||
}
|
||||
|
||||
let payload = GuestSessionAttestPayload(
|
||||
platform: "ios",
|
||||
@@ -175,7 +198,13 @@ actor GuestSessionService {
|
||||
|
||||
private func handshakeWithAssertion(keyId: String, challenge: String) async throws -> String {
|
||||
let clientDataHash = Data(SHA256.hash(data: Data(challenge.utf8)))
|
||||
let assertionObject = try await DCAppAttestService.shared.generateAssertion(keyId, clientDataHash: clientDataHash)
|
||||
let assertionObject: Data
|
||||
do {
|
||||
assertionObject = try await DCAppAttestService.shared.generateAssertion(keyId, clientDataHash: clientDataHash)
|
||||
} catch {
|
||||
print("[GuestSessionService] generateAssertion failed: \(error)")
|
||||
throw error
|
||||
}
|
||||
|
||||
let payload = GuestSessionAttestPayload(
|
||||
platform: "ios",
|
||||
|
||||
Reference in New Issue
Block a user