Skip to content

feat(security): add optional authenticated SDK connections - #13

Open
heoblitz wants to merge 11 commits into
mainfrom
feature/sdk-connection-authentication
Open

heoblitz wants to merge 11 commits into
mainfrom
feature/sdk-connection-authentication

Conversation

@heoblitz

@heoblitz heoblitz commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Apps can opt in to authenticated, encrypted debugging with NectoSDK.start(publicKey:). The SDK pins a P-256 public key and verifies the Mac through TLS 1.3; the matching private key stays in Mac Keychain. Failed authentication closes the session without a plaintext fallback. NectoSDK.start() and existing SDK apps keep their current connection protocol.

Add per-bundle credential registration, an Unauthorized sidebar state with setup guidance, CLI rejection for unauthorized targets, and English/Korean setup documentation. Include the complete BoringSSL license in packaged notices.

The SDK now requires Swift 6.1, and the public start(port:) argument is removed in favor of automatic port selection.

Changelog

Add optional public-key authentication and TLS encryption for SDK connections while preserving unconfigured and older SDK connections.

Test Plan

  • script/test swift: passed on the latest commit (328 Swift tests plus the SDK consumer).
  • A disconnect regression test forces socket close to stall: target discovery blocked before the fix and answered immediately after it.
  • script/test-e2e build-mac: passed locally; hosted simulator connection and CLI E2E passed on the latest commit.
  • script/test web: typecheck, tests, and panel assets passed.
  • script/test native: passed.
  • script/test release: passed, including both release-path handling and BoringSSL license checks.
  • Authentication tests cover missing/wrong keys, plaintext imitation, TLS tampering/replay, Keychain storage and shared-key registrations, cancellation/timeouts, CLI denial, and legacy compatibility.
  • Before rebasing: built the unchanged released 0.1.1 SDK app and verified connection, seven-plugin discovery, read/write, streaming, disconnection, and app-relaunch reconnection on an iPhone simulator and a USB-connected iPhone 15 Pro. No fixture credential registration was needed. Authentication and transport implementation files were unchanged by the rebase.
  • Earlier physical-device checks exercised protected connections, first Keychain approval, denial, and timeout.
  • Scanned all 59 changed files for private keys, internal identifiers/URLs, and temporary tracing code; no matches. Local test artifacts are excluded.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant