[PR #3190] [PM-7658] Implement Fido2 privileged apps verification #4081

Closed
opened 2025-11-26 23:40:21 -06:00 by GiteaMirror · 0 comments
Owner

Original Pull Request: https://github.com/bitwarden/android/pull/3190

State: closed
Merged: Yes


Type of change

  • Bug fix
  • New feature development
  • Tech debt (refactoring, code cleanup, dependency upgrades, etc)
  • Build/deploy pipeline (DevOps)
  • Other

Objective

Implement Fido2 privileged apps verification on Android

Note: Wait for #3188 to be merged in order to merge this one.

Code changes

  • fido2_priviliged_allow_list.json: Json file with all the allowed privileged apps to be used in the Fido2 flows.
  • CredentialHelpers: Added helper methods to load the aforementioned file and do the verifications getting the proper origin at the end.
  • Others: Implemented the verifications for the calling app and to get the origin correctly

Before you submit

  • Please check for formatting errors (dotnet format --verify-no-changes) (required)
  • Please add unit tests where it makes sense to do so (encouraged but not required)
  • If this change requires a documentation update - notify the documentation team
  • If this change has particular deployment requirements - notify the DevOps team
**Original Pull Request:** https://github.com/bitwarden/android/pull/3190 **State:** closed **Merged:** Yes --- ## Type of change - [ ] Bug fix - [X] New feature development - [ ] Tech debt (refactoring, code cleanup, dependency upgrades, etc) - [ ] Build/deploy pipeline (DevOps) - [ ] Other ## Objective <!--Describe what the purpose of this PR is. For example: what bug you're fixing or what new feature you're adding--> Implement Fido2 privileged apps verification on Android Note: Wait for #3188 to be merged in order to merge this one. ## Code changes <!--Explain the changes you've made to each file or major component. This should help the reviewer understand your changes--> <!--Also refer to any related changes or PRs in other repositories--> * **fido2_priviliged_allow_list.json:** Json file with all the allowed privileged apps to be used in the Fido2 flows. * **CredentialHelpers:** Added helper methods to load the aforementioned file and do the verifications getting the proper origin at the end. * **Others:** Implemented the verifications for the calling app and to get the origin correctly ## Before you submit - Please check for formatting errors (`dotnet format --verify-no-changes`) (required) - Please add **unit tests** where it makes sense to do so (encouraged but not required) - If this change requires a **documentation update** - notify the documentation team - If this change has particular **deployment requirements** - notify the DevOps team
GiteaMirror added the pull-request label 2025-11-26 23:40:21 -06:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/android#4081