Repository navigation
feat(desktop): passkeys in the in-app browser on macOS - #16370
Draft
bmdavis419 wants to merge 1 commit into
Draft
bmdavis419 wants to merge 1 commit into
bmdavis419 wants to merge 1 commit into
Conversation
Electron has no WebAuthn UI on macOS, so passkey prompts in preview tabs hung until they timed out. Signed builds now enable Electron's Touch ID authenticator, and, once Apple grants the managed browser passkey entitlement, route preview pages' WebAuthn through the system passkey sheet with the frame's real origin. Each path turns on only when the provisioning profile authorizes its entitlement. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
Thread transfer impact✅ Thread transfer remains within every enforced ceiling.
Baseline: Scenario and decoded snapshot size10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.
Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed. |
This was referenced Oct 7, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Passkeys in the in-app browser on macOS. Electron has no WebAuthn UI on macOS, so a passkey prompt in a preview tab (for example Google's "Complete sign-in using your passkey") showed nothing and hung until it timed out. Windows was already fine, because Chromium hands passkeys to Windows Hello there.
There are two paths. Each turns on only when the signed build's provisioning profile authorizes its entitlement, so unsigned and dev builds are unaffected.
app.configureWebAuthn({ touchID }), the Electron 42+ API, and adds a native account picker forselect-webauthn-account.navigator.credentials.create/getgo over a per-guest IPC handler to macOS AuthenticationServices, usingelectron-webauthn.senderFrame.origin, never from the page. It rejects subframes, public-suffix RP IDs, unfocused or insecure pages, overlapping requests, and results for pages that navigated mid-ceremony.Apple steps needed
1. Touch ID: verify only, no Apple request
keychain-access-groups=<TEAM_ID>.com.t3tools.t3code.webauthn, but only when the provisioning profile grants it. Developer ID profiles normally include<TEAM_ID>.*. If the profile doesn't grant it, the build leaves the entitlement off, because macOS refuses to launch an app that claims unauthorized entitlements.security cms -D -i t3code.provisionprofile | plutil -extract Entitlements.keychain-access-groups xml1 -o - -[desktop-artifact] In-app browser passkeys: Touch ID enabled, ….codesign -d --entitlements :- "/Applications/T3 Code.app"should list the keychain group.2. System passkey sheet: needs Apple's managed entitlement
com.apple.developer.web-browser.public-key-credentiallets a browser make passkey and security-key requests for any relying party. This is what Chrome, Firefox and Flow Browser use. Without it, macOS limits an app to its own associated domains (today that's only the Clerk domain).com.t3tools.t3code. Apple reviews it against the criteria documented here:httpandhttpsURL schemes in its Info.plist.t3codeandt3code-dev. Addinghttp/httpsmakes T3 a default-browser candidate in macOS, which also means handlingopen-urlfor web links. Decide this before or alongside the request.MACOS_PROVISIONING_PROFILEsecret. Bothrelease-desktop.ymlanddesktop-macos-preview-publish.ymluse it.browser passkeys enabled.codesign -d --entitlements :- "/Applications/T3 Code.app"listscom.apple.developer.web-browser.public-key-credential.The same steps are summarized in
docs/operations/release.md.Known gaps
electron-webauthndoesn't expose cancel.Important files:
apps/desktop/src/preview/Passkeys.tsPreviewPasskeysservice: Touch ID setup, account picker, and the per-guest ceremony handler (origin pinning, ES256-only registration,rpIddefault, focus and single-flight gates, deadline).t3codeWebAuthnfrom the packagedpackage.jsonto decide what's enabled.apps/desktop/src/preview/PasskeyBridge.tsPublicKeyCredentialobjects (instanceof,toJSON, extensions) and leaves conditional mediation native.apps/desktop/src/preview/PasskeyAttestation.tsauthDataout of attestation objects. The library returns JSON instead.apps/desktop/src/preview-pick-preload.ts,apps/desktop/src/window/DesktopWindow.ts,apps/desktop/src/preview/Manager.tsadditionalArguments, and attach and detach the handlers with each guest and session.scripts/build-desktop-artifact.tspackage.json.electron-webauthn's TypeScript peer, about 24 MB.pnpm-workspace.yaml,third-party-licenses.config.jsonobjc-jsprebuilds are allowed without running its install script.Testing
authDataextraction, and the hang deadline.falsevalues.vp test run apps/desktop/src scripts/build-desktop-artifact.test.ts scripts/lib/third-party-licenses.test.ts: 111 files, all passing. Desktop and scripts typecheck and lint are clean.objc-jsprebuilds present for arm64 and x64.Reviewed by a Claude Opus 5.5 subagent and GPT 6.1 Sol (security and correctness); their findings are addressed above or listed as known gaps.
Built with Claude Opus 5.5 in Claude Code, running inside T3 Code.
🤖 Generated with Claude Code
Fixes #5665
Related: #14398 (phone / cross-device passkeys need the system passkey sheet path, which stays dormant until Apple grants the browser passkey entitlement)