[PM-10373] Fix FIDO 2 credential creation from unprivileged apps #3658
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🎟️ Tracking
PM-10373
📔 Objective
This pull request fixes incorrect arguments passed to Bitwarden SDK when handling passkey registration and authentication requests from unprivileged applications.
When registering a passkey from an unprivileged application, Bitwarden SDK expects
ClientData.DefaultWithExtraData.androidPackageName
to be the calling application package name. However, during authenticationClientData.DefaultWithExtraData.androidPackageName
is the apk-key-hash.Bitwarden SDK requires
origin
to be a valid HTTP URL, including the protocol preamble, when performing registration and authentication.⏰ Reminders before review
🦮 Reviewer guidelines
:+1:
) or similar for great changes:memo:
) or ℹ️ (:information_source:
) for notes or general info:question:
) for questions:thinking:
) or 💭 (:thought_balloon:
) for more open inquiry that's not quite a confirmedissue and could potentially benefit from discussion
:art:
) for suggestions / improvements:x:
) or:warning:
) for more significant problems or concerns needing attention:seedling:
) or ♻️ (:recycle:
) for future improvements or indications of technical debt:pick:
) for minor or nitpick changes