Repository navigation
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Apps can opt in to authenticated, encrypted debugging with
NectoSDK.start(publicKey:). The SDK pins a P-256 public key and verifies the Mac through TLS 1.3; the matching private key stays in Mac Keychain. Failed authentication closes the session without a plaintext fallback.NectoSDK.start()and existing SDK apps keep their current connection protocol.Add per-bundle credential registration, an Unauthorized sidebar state with setup guidance, CLI rejection for unauthorized targets, and English/Korean setup documentation. Include the complete BoringSSL license in packaged notices.
The SDK now requires Swift 6.1, and the public
start(port:)argument is removed in favor of automatic port selection.Changelog
Add optional public-key authentication and TLS encryption for SDK connections while preserving unconfigured and older SDK connections.
Test Plan
script/test swift: passed on the latest commit (328 Swift tests plus the SDK consumer).script/test-e2e build-mac: passed locally; hosted simulator connection and CLI E2E passed on the latest commit.script/test web: typecheck, tests, and panel assets passed.script/test native: passed.script/test release: passed, including both release-path handling and BoringSSL license checks.0.1.1SDK app and verified connection, seven-plugin discovery, read/write, streaming, disconnection, and app-relaunch reconnection on an iPhone simulator and a USB-connected iPhone 15 Pro. No fixture credential registration was needed. Authentication and transport implementation files were unchanged by the rebase.