[PR #5101] [MERGED] Use Google's Digital Asset Links API to verify digital asset links #5481

Closed
opened 2025-11-27 00:03:59 -06:00 by GiteaMirror · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/bitwarden/android/pull/5101
Author: @SaintPatrck
Created: 4/25/2025
Status: Merged
Merged: 4/30/2025
Merged by: @SaintPatrck

Base: mainHead: digital-asset-link-api


📝 Commits (1)

  • e81134d Use Google's Digital Asset Links API to verify digital asset links

📊 Changes

19 files changed (+163 additions, -515 deletions)

View changed files

📝 app/src/main/java/com/x8bit/bitwarden/data/autofill/fido2/manager/Fido2CredentialManagerImpl.kt (+2 -4)
📝 app/src/main/java/com/x8bit/bitwarden/data/autofill/fido2/manager/Fido2OriginManager.kt (+0 -2)
📝 app/src/main/java/com/x8bit/bitwarden/data/autofill/fido2/manager/Fido2OriginManagerImpl.kt (+24 -67)
📝 app/src/main/java/com/x8bit/bitwarden/data/autofill/fido2/model/Fido2CredentialAssertionResult.kt (+0 -15)
📝 app/src/main/java/com/x8bit/bitwarden/data/autofill/fido2/model/Fido2ValidateOriginResult.kt (+0 -10)
📝 app/src/main/java/com/x8bit/bitwarden/ui/vault/feature/itemlisting/VaultItemListingViewModel.kt (+1 -27)
📝 app/src/main/java/com/x8bit/bitwarden/ui/vault/feature/itemlisting/util/Fido2CredentialAssertionResultExtensions.kt (+0 -8)
📝 app/src/main/java/com/x8bit/bitwarden/ui/vault/feature/itemlisting/util/Fido2ValidateOriginResultExtensions.kt (+0 -8)
📝 app/src/test/java/com/x8bit/bitwarden/MainViewModelTest.kt (+0 -17)
📝 app/src/test/java/com/x8bit/bitwarden/data/autofill/fido2/manager/Fido2CredentialManagerTest.kt (+0 -19)
📝 app/src/test/java/com/x8bit/bitwarden/data/autofill/fido2/manager/Fido2OriginManagerTest.kt (+28 -87)
📝 app/src/test/java/com/x8bit/bitwarden/ui/vault/feature/itemlisting/VaultItemListingViewModelTest.kt (+14 -149)
📝 network/src/main/kotlin/com/bitwarden/network/BitwardenServiceClientImpl.kt (+3 -1)
📝 network/src/main/kotlin/com/bitwarden/network/api/DigitalAssetLinkApi.kt (+19 -8)
network/src/main/kotlin/com/bitwarden/network/model/DigitalAssetLinkCheckResponseJson.kt (+28 -0)
network/src/main/kotlin/com/bitwarden/network/model/DigitalAssetLinkResponseJson.kt (+0 -32)
📝 network/src/main/kotlin/com/bitwarden/network/service/DigitalAssetLinkService.kt (+8 -7)
📝 network/src/main/kotlin/com/bitwarden/network/service/DigitalAssetLinkServiceImpl.kt (+14 -10)
📝 network/src/test/kotlin/com/bitwarden/network/service/DigitalAssetLinkServiceTest.kt (+22 -44)

📄 Description

🎟️ Tracking

TBD

📔 Objective

Refactor DigitalAssetLinkApi and DigitalAssetLinkService implementations to use Google's digital asset link REST API.

By using Google's REST API, we no longer have to derive the host URL ourselves, and move the responsibility of validating asset link files to Google.

Additionally, relyingPartyId is no longer needed to check asset links and has been removed from corresponding argument lists.

Reminders before review

  • Contributor guidelines followed
  • All formatters and local linters executed and passed
  • Written new unit and / or integration tests where applicable
  • Protected functional changes with optionality (feature flags)
  • Used internationalization (i18n) for all UI strings
  • CI builds passed
  • Communicated to DevOps any deployment requirements
  • Updated any necessary documentation (Confluence, contributing docs) or informed the documentation team

🦮 Reviewer guidelines

  • 👍 (:+1:) or similar for great changes
  • 📝 (:memo:) or ℹ️ (:information_source:) for notes or general info
  • (:question:) for questions
  • 🤔 (:thinking:) or 💭 (:thought_balloon:) for more open inquiry that's not quite a confirmed issue and could potentially benefit from discussion
  • 🎨 (:art:) for suggestions / improvements
  • (:x:) or ⚠️ (:warning:) for more significant problems or concerns needing attention
  • 🌱 (:seedling:) or ♻️ (:recycle:) for future improvements or indications of technical debt
  • ⛏ (:pick:) for minor or nitpick changes

🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/bitwarden/android/pull/5101 **Author:** [@SaintPatrck](https://github.com/SaintPatrck) **Created:** 4/25/2025 **Status:** ✅ Merged **Merged:** 4/30/2025 **Merged by:** [@SaintPatrck](https://github.com/SaintPatrck) **Base:** `main` ← **Head:** `digital-asset-link-api` --- ### 📝 Commits (1) - [`e81134d`](https://github.com/bitwarden/android/commit/e81134de606f379bffeeb2df6ab2eb7ecfb307f5) Use Google's Digital Asset Links API to verify digital asset links ### 📊 Changes **19 files changed** (+163 additions, -515 deletions) <details> <summary>View changed files</summary> 📝 `app/src/main/java/com/x8bit/bitwarden/data/autofill/fido2/manager/Fido2CredentialManagerImpl.kt` (+2 -4) 📝 `app/src/main/java/com/x8bit/bitwarden/data/autofill/fido2/manager/Fido2OriginManager.kt` (+0 -2) 📝 `app/src/main/java/com/x8bit/bitwarden/data/autofill/fido2/manager/Fido2OriginManagerImpl.kt` (+24 -67) 📝 `app/src/main/java/com/x8bit/bitwarden/data/autofill/fido2/model/Fido2CredentialAssertionResult.kt` (+0 -15) 📝 `app/src/main/java/com/x8bit/bitwarden/data/autofill/fido2/model/Fido2ValidateOriginResult.kt` (+0 -10) 📝 `app/src/main/java/com/x8bit/bitwarden/ui/vault/feature/itemlisting/VaultItemListingViewModel.kt` (+1 -27) 📝 `app/src/main/java/com/x8bit/bitwarden/ui/vault/feature/itemlisting/util/Fido2CredentialAssertionResultExtensions.kt` (+0 -8) 📝 `app/src/main/java/com/x8bit/bitwarden/ui/vault/feature/itemlisting/util/Fido2ValidateOriginResultExtensions.kt` (+0 -8) 📝 `app/src/test/java/com/x8bit/bitwarden/MainViewModelTest.kt` (+0 -17) 📝 `app/src/test/java/com/x8bit/bitwarden/data/autofill/fido2/manager/Fido2CredentialManagerTest.kt` (+0 -19) 📝 `app/src/test/java/com/x8bit/bitwarden/data/autofill/fido2/manager/Fido2OriginManagerTest.kt` (+28 -87) 📝 `app/src/test/java/com/x8bit/bitwarden/ui/vault/feature/itemlisting/VaultItemListingViewModelTest.kt` (+14 -149) 📝 `network/src/main/kotlin/com/bitwarden/network/BitwardenServiceClientImpl.kt` (+3 -1) 📝 `network/src/main/kotlin/com/bitwarden/network/api/DigitalAssetLinkApi.kt` (+19 -8) ➕ `network/src/main/kotlin/com/bitwarden/network/model/DigitalAssetLinkCheckResponseJson.kt` (+28 -0) ➖ `network/src/main/kotlin/com/bitwarden/network/model/DigitalAssetLinkResponseJson.kt` (+0 -32) 📝 `network/src/main/kotlin/com/bitwarden/network/service/DigitalAssetLinkService.kt` (+8 -7) 📝 `network/src/main/kotlin/com/bitwarden/network/service/DigitalAssetLinkServiceImpl.kt` (+14 -10) 📝 `network/src/test/kotlin/com/bitwarden/network/service/DigitalAssetLinkServiceTest.kt` (+22 -44) </details> ### 📄 Description ## 🎟️ Tracking TBD ## 📔 Objective Refactor DigitalAssetLinkApi and DigitalAssetLinkService implementations to use Google's digital asset link REST API. By using Google's REST API, we no longer have to derive the host URL ourselves, and move the responsibility of validating asset link files to Google. Additionally, relyingPartyId is no longer needed to check asset links and has been removed from corresponding argument lists. ## ⏰ Reminders before review - Contributor guidelines followed - All formatters and local linters executed and passed - Written new unit and / or integration tests where applicable - Protected functional changes with optionality (feature flags) - Used internationalization (i18n) for all UI strings - CI builds passed - Communicated to DevOps any deployment requirements - Updated any necessary documentation (Confluence, contributing docs) or informed the documentation team ## 🦮 Reviewer guidelines <!-- Suggested interactions but feel free to use (or not) as you desire! --> - 👍 (`:+1:`) or similar for great changes - 📝 (`:memo:`) or ℹ️ (`:information_source:`) for notes or general info - ❓ (`:question:`) for questions - 🤔 (`:thinking:`) or 💭 (`:thought_balloon:`) for more open inquiry that's not quite a confirmed issue and could potentially benefit from discussion - 🎨 (`:art:`) for suggestions / improvements - ❌ (`:x:`) or ⚠️ (`:warning:`) for more significant problems or concerns needing attention - 🌱 (`:seedling:`) or ♻️ (`:recycle:`) for future improvements or indications of technical debt - ⛏ (`:pick:`) for minor or nitpick changes --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
GiteaMirror added the pull-request label 2025-11-27 00:03:59 -06:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/android#5481