feat: add deviceBoundSessions fuse for Device Bound Session Credentials - #54074
MarshallOfSound wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
API LGTM
I think this is fine as a first step, but there are several things that probably should be addressed in follow ups:
-
There's no way to ask whether it worked. The fuse can be on and DBSC still be entirely inert. Maybe add something like
session.isDeviceBoundSessionsAvailable(). -
No per-origin logout.
cookies.remove()doesn't end a session; the only way out is clearing all cookies for the session. Chromium's DBSC service can enumerate and terminate individual session — none of that is surfaced. -
session.clearData'scookiestype now means also clearing device bound sessions. It makes sense given how they are tied together, but maybe we should adddeviceBoundSessions. -
No per-session granularity. Maybe we could add something like
session.fromPartition(name, { deviceBoundSessions: true }). -
No runtime observability. No events for register, refresh, or terminate.
|
Agree on the potential follow ups. Specifically didn't want to expose new JS APIs here as they aren't required for actually surfacing the raw DBSC capability. Will look into JS APIs as a follow up |
3cdddfe to
6605f38
Compare
Adds an opt-in fuse that lets websites bind sessions to a hardware-backed key (TPM on Windows, Secure Enclave on macOS) so a stolen cookie cannot be replayed from another device. Keys are managed by a key service in the browser process. On macOS it uses a keychain access group derived from the app's code signature. With the fuse on, software keys can never be enabled by a command line flag; with it off, that flag is the way to try DBSC in development. Clearing cookies also ends the sessions bound to them.
6605f38 to
d2f8aad
Compare
Description of Change
Adds an opt-in
deviceBoundSessionsfuse that lets websites bind sessions to a hardware-backed key (TPM on Windows, Secure Enclave on macOS), so a stolen cookie can't be replayed from another device.FuseV1Options.EnableDeviceBoundSessions, off by default. On, it enables DBSC for every session and keeps sessions on disk for persistent partitions.<TeamID>.<BundleID>.unexportable-keysis derived from the app's code signature. If the app is unsigned or lacks the entitlement, DBSC stays off and the reason is logged. In-memory partitions aren't supported.EnableBoundSessionCredentialsSoftwareKeysForManualTestingis ignored. With it off, that flag enables DBSC with mock keys for development, including Linux.clearStorageData/clearDatawithcookiesnow also end DBSC sessions, otherwise a session would re-issue the cleared cookie.fuses-spec.tsagainst a local HTTPS DBSC server, including rebinding after a network service restart.Draft notes:
FuseV1Options.EnableDeviceBoundSessions(index 9) is added to@electron/fusesin feat: add FuseV1Options.EnableDeviceBoundSessions fuses#138, so the documented name resolves once that ships.Checklist
npm testpassesRelease Notes
Notes: Added the
deviceBoundSessionsfuse for Device Bound Session Credentials.