[app-attest-env] Clear stale App Attest key on local DCError, not just server 403
Root cause of the permanent stuck-at-challenge symptom: a stale appAttestKeyId in Keychain (Secure Enclave key invalidated by an app reinstall or signing change) makes generateAssertion fail every time with DCError code 2 (invalidInput). Only NetworkError 403 was clearing the stored key, so this local rejection was never recovered from - every guest-authed call kept retrying the same broken key forever. Catch DCError here too and fall through to fresh attestation.
This commit is contained in:
@@ -113,6 +113,15 @@ actor GuestSessionService {
|
||||
// other error (network blip, timeout, decode issue) must
|
||||
// NOT wipe a perfectly valid registered key.
|
||||
store.appAttestKeyId = nil
|
||||
} catch let error as DCError {
|
||||
// DeviceCheck itself rejects the key locally (e.g. the app
|
||||
// was reinstalled and the Secure Enclave key backing this
|
||||
// keyId no longer exists) - distinct from the server
|
||||
// rejecting it, but equally unrecoverable without a fresh
|
||||
// key. Without this, generateAssertion fails the same way
|
||||
// forever since appAttestKeyId is never cleared.
|
||||
print("[GuestSessionService] existing key rejected locally, re-attesting with a fresh key: \(error)")
|
||||
store.appAttestKeyId = nil
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user