[PR #6183] [PM-28157] Add string extension to prefix URIs with www #6385

Closed
opened 2025-11-27 00:23:02 -06:00 by GiteaMirror · 0 comments
Owner

Original Pull Request: https://github.com/bitwarden/android/pull/6183

State: closed
Merged: Yes


🎟️ Tracking

PM-28157
Relates to Issue #6164

📔 Objective

This PR adds support for prefixing relying party IDs (rpIds) with "www." during passkey Digital Asset Link validation to improve compatibility with web origins that use the www subdomain.

When validating passkey requests, the Android Credential Manager may receive rpIds in various formats (e.g., example.com, www.example.com, https://example.com). However, Digital Asset Link files are often hosted at https://www.example.com/.well-known/assetlinks.json. Without proper www prefixing, the validation can fail even when valid DAL relationships exist.

Changes:

  • Implements prefixWwwIfNecessaryOrNull() and prefixWwwIfNecessary() string extension functions that intelligently add "www." prefix to URIs while preserving existing schemes
  • Updates OriginManagerImpl.validateCallingApplicationAssetLinks() to apply www prefixing before https prefixing during DAL validation
  • Adds comprehensive unit test coverage for all www-prefixing scenarios

This ensures rpIds are properly normalized to https://www.{domain} format before querying Digital Asset Links, improving passkey authentication success rates for websites using www subdomains.

Reminders before review

  • Contributor guidelines followed
  • All formatters and local linters executed and passed
  • Written new unit and / or integration tests where applicable
  • Protected functional changes with optionality (feature flags)
  • Used internationalization (i18n) for all UI strings
  • CI builds passed
  • Communicated to DevOps any deployment requirements
  • Updated any necessary documentation (Confluence, contributing docs) or informed the documentation team

🦮 Reviewer guidelines

  • 👍 (:+1:) or similar for great changes
  • 📝 (:memo:) or ℹ️ (:information_source:) for notes or general info
  • (:question:) for questions
  • 🤔 (:thinking:) or 💭 (:thought_balloon:) for more open inquiry that's not quite a confirmed issue and could potentially benefit from discussion
  • 🎨 (:art:) for suggestions / improvements
  • (:x:) or ⚠️ (:warning:) for more significant problems or concerns needing attention
  • 🌱 (:seedling:) or ♻️ (:recycle:) for future improvements or indications of technical debt
  • ⛏ (:pick:) for minor or nitpick changes
**Original Pull Request:** https://github.com/bitwarden/android/pull/6183 **State:** closed **Merged:** Yes --- ## 🎟️ Tracking PM-28157 Relates to Issue #6164 ## 📔 Objective This PR adds support for prefixing relying party IDs (rpIds) with "www." during passkey Digital Asset Link validation to improve compatibility with web origins that use the www subdomain. When validating passkey requests, the Android Credential Manager may receive rpIds in various formats (e.g., `example.com`, `www.example.com`, `https://example.com`). However, Digital Asset Link files are often hosted at `https://www.example.com/.well-known/assetlinks.json`. Without proper www prefixing, the validation can fail even when valid DAL relationships exist. **Changes:** - Implements `prefixWwwIfNecessaryOrNull()` and `prefixWwwIfNecessary()` string extension functions that intelligently add "www." prefix to URIs while preserving existing schemes - Updates `OriginManagerImpl.validateCallingApplicationAssetLinks()` to apply www prefixing before https prefixing during DAL validation - Adds comprehensive unit test coverage for all www-prefixing scenarios This ensures rpIds are properly normalized to `https://www.{domain}` format before querying Digital Asset Links, improving passkey authentication success rates for websites using www subdomains. ## ⏰ Reminders before review - Contributor guidelines followed - All formatters and local linters executed and passed - Written new unit and / or integration tests where applicable - Protected functional changes with optionality (feature flags) - Used internationalization (i18n) for all UI strings - CI builds passed - Communicated to DevOps any deployment requirements - Updated any necessary documentation (Confluence, contributing docs) or informed the documentation team ## 🦮 Reviewer guidelines <!-- Suggested interactions but feel free to use (or not) as you desire! --> - 👍 (`:+1:`) or similar for great changes - 📝 (`:memo:`) or ℹ️ (`:information_source:`) for notes or general info - ❓ (`:question:`) for questions - 🤔 (`:thinking:`) or 💭 (`:thought_balloon:`) for more open inquiry that's not quite a confirmed issue and could potentially benefit from discussion - 🎨 (`:art:`) for suggestions / improvements - ❌ (`:x:`) or ⚠️ (`:warning:`) for more significant problems or concerns needing attention - 🌱 (`:seedling:`) or ♻️ (`:recycle:`) for future improvements or indications of technical debt - ⛏ (`:pick:`) for minor or nitpick changes
GiteaMirror added the pull-request label 2025-11-27 00:23:02 -06:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/android#6385