From 6ea908dae86fe2d57f7bf72d57d5141c81fc32b7 Mon Sep 17 00:00:00 2001 From: crStiv Date: Tue, 21 Jan 2025 03:13:55 +0100 Subject: [PATCH] Update ClientTrustVerifier.java --- .../adapter/trust/ClientTrustVerifier.java | 17 ++++++++++++++--- 1 file changed, 14 insertions(+), 3 deletions(-) diff --git a/android/app/src/main/java/com/salmonwallet/adapter/trust/ClientTrustVerifier.java b/android/app/src/main/java/com/salmonwallet/adapter/trust/ClientTrustVerifier.java index 1eb08fe9..2ccd469b 100644 --- a/android/app/src/main/java/com/salmonwallet/adapter/trust/ClientTrustVerifier.java +++ b/android/app/src/main/java/com/salmonwallet/adapter/trust/ClientTrustVerifier.java @@ -51,9 +51,20 @@ public VerificationState verifyAuthorizationSource(Uri clientIdentityUri) { switch (associationType) { case LOCAL_FROM_BROWSER: if (clientIdentityUri != null) { - // TODO: kick off web-based client verification here - Log.d(TAG, "Web-scoped authorization verification not yet implemented"); - return succeeded(associationType.getScopeTag(), clientIdentityUri.getAuthority()); + String authority = clientIdentityUri.getAuthority(); + if (authority == null || authority.isEmpty()) { + Log.w(TAG, "Web-scoped authorization failed: invalid authority in URI"); + return failed(associationType.getScopeTag()); + } + + // Verify that the URI uses HTTPS scheme for security + if (!"https".equalsIgnoreCase(clientIdentityUri.getScheme())) { + Log.w(TAG, "Web-scoped authorization failed: non-HTTPS URI scheme"); + return failed(associationType.getScopeTag()); + } + + Log.d(TAG, "Web-scoped authorization succeeded for domain: " + authority); + return succeeded(associationType.getScopeTag(), authority); } else { Log.d(TAG, "Client did not provide an identity URI; not verifiable"); return notVerifiable(associationType.getScopeTag());