Skip to content

feat: add deviceBoundSessions fuse for Device Bound Session Credentials - #54074

Open
MarshallOfSound wants to merge 1 commit into
mainfrom
sam/dbsc-fuse
Open

MarshallOfSound wants to merge 1 commit into
mainfrom
sam/dbsc-fuse

Conversation

@MarshallOfSound

@MarshallOfSound MarshallOfSound commented Sep 18, 2026 •

Copy link
Copy Markdown
Member

Description of Change

Adds an opt-in deviceBoundSessions fuse that lets websites bind sessions to a hardware-backed key (TPM on Windows, Secure Enclave on macOS), so a stolen cookie can't be replayed from another device.

  • Fuse: FuseV1Options.EnableDeviceBoundSessions, off by default. On, it enables DBSC for every session and keeps sessions on disk for persistent partitions.
  • Key service: runs in the browser process on every platform and is handed to the network service, so key operations stay out of the sandboxed network process.
  • macOS: the keychain access group <TeamID>.<BundleID>.unexportable-keys is derived from the app's code signature. If the app is unsigned or lacks the entitlement, DBSC stays off and the reason is logged. In-memory partitions aren't supported.
  • Software keys: with the fuse on, EnableBoundSessionCredentialsSoftwareKeysForManualTesting is ignored. With it off, that flag enables DBSC with mock keys for development, including Linux.
  • Cookie clearing: clearStorageData / clearData with cookies now also end DBSC sessions, otherwise a session would re-issue the cleared cookie.
  • DevTools: the Device bound sessions panel is enabled.
  • Docs: fuse reference, macOS setup, and a code-signing note.
  • Tests: 12 specs in fuses-spec.ts against a local HTTPS DBSC server, including rebinding after a network service restart.

Draft notes:

Checklist

Release Notes

Notes: Added the deviceBoundSessions fuse for Device Bound Session Credentials.

@MarshallOfSound MarshallOfSound added semver/minor backwards-compatible functionality target/44-x-y PR should also be added to the "44-x-y" branch. target/45-x-y PR should also be added to the "45-x-y" branch. labels Sep 18, 2026
@MarshallOfSound
MarshallOfSound marked this pull request as ready for review September 18, 2026 06:37

@erickzhao erickzhao left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

API LGTM

@jkleinsc jkleinsc left a comment •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

API LGTM

I think this is fine as a first step, but there are several things that probably should be addressed in follow ups:

  1. There's no way to ask whether it worked. The fuse can be on and DBSC still be entirely inert. Maybe add something like session.isDeviceBoundSessionsAvailable().

  2. No per-origin logout. cookies.remove() doesn't end a session; the only way out is clearing all cookies for the session. Chromium's DBSC service can enumerate and terminate individual session — none of that is surfaced.

  3. session.clearData's cookies type now means also clearing device bound sessions. It makes sense given how they are tied together, but maybe we should add deviceBoundSessions.

  4. No per-session granularity. Maybe we could add something like session.fromPartition(name, { deviceBoundSessions: true }).

  5. No runtime observability. No events for register, refresh, or terminate.

@MarshallOfSound

Copy link
Copy Markdown
Member Author

Agree on the potential follow ups. Specifically didn't want to expose new JS APIs here as they aren't required for actually surfacing the raw DBSC capability. Will look into JS APIs as a follow up

Adds an opt-in fuse that lets websites bind sessions to a hardware-backed
key (TPM on Windows, Secure Enclave on macOS) so a stolen cookie cannot be
replayed from another device.

Keys are managed by a key service in the browser process. On macOS it uses
a keychain access group derived from the app's code signature. With the
fuse on, software keys can never be enabled by a command line flag; with
it off, that flag is the way to try DBSC in development. Clearing cookies
also ends the sessions bound to them.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api-review/approved ✅ semver/minor backwards-compatible functionality target/44-x-y PR should also be added to the "44-x-y" branch. target/45-x-y PR should also be added to the "45-x-y" branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants