Add gated development App Attest bypass - #3438
Conversation
Co-authored-by: npub1tquskdu6yc4h8l7xxtceculxw600grekeq0xg2ukqfrwl7vrzg3quz3gmp <58390b379a262b73ffc632f19c73e6769ef40f36c81e642b960246eff9831222@buzz.block.builderlab.xyz> Signed-off-by: npub1tquskdu6yc4h8l7xxtceculxw600grekeq0xg2ukqfrwl7vrzg3quz3gmp <58390b379a262b73ffc632f19c73e6769ef40f36c81e642b960246eff9831222@buzz.block.builderlab.xyz>
|
@codex review |
|
@builderbot review |
|
To use Codex here, create a Codex account and connect to github. |
|
🤖 Superseded, closing. This work landed on the single feature branch Where it went: three commits ( Adversarial review happened against the branch version, not this one, and produced one landing condition that this PR does not carry: the |
What changed?
Add a non-default development App Attest policy for iOS Simulator enrollment. The bypass accepts only the versioned development sentinels and is unavailable unless the gateway is explicitly compiled with
dev-app-attest-bypass.At runtime, enabling the bypass now fails closed unless both gateway listeners are loopback addresses and
buzz-ios-sandboxis the only enabled profile. Default builds continue to use Apple's verifier. The gateway also records attempts that reach the APNs HTTP send seam.Why?
The iOS Simulator cannot perform Apple App Attest, which otherwise makes local push enrollment structurally impossible. This provides a narrowly gated development path without adding bypass behavior to the production gateway build.
How is it tested?
Build and run.
Added tests:
dev_app_attestconfigAppAttestPolicycompile-fail test🤖 This PR was authored with an agent.