Skip to content

web crypto - #57

Merged
gjwgit merged 3 commits into
devfrom
jess/56_webcrypto
Sep 27, 2026
Merged

gjwgit merged 3 commits into
devfrom
jess/56_webcrypto

Conversation

@jesscmoore

Copy link
Copy Markdown
Collaborator

Pull Request Details

Description

Signs DPoP proofs with the browser's Web Crypto on web (about 250 ms → 0.7 ms per request).

Does solidpod need a change?

No. solidpod only calls DpopTokenGenerator.generateForRequest, which is already async and now takes the fast path. solidpod 1.0.24 allows solid_auth: ^1.0.11, which includes the new 1.1.0. Once 1.1.0 is published, any app gets it by running flutter pub upgrade solid_auth, with no solidpod release. Optionally, solidpod could raise its minimum to ^1.1.0 in its next release so no app stays on the slow signer by accident, but nothing breaks without that.

What changed in solid_auth

  • dpop_signer*.dart (new): RS256 signing, picked per platform:
    • web: the browser's Web Crypto via package:web, with the key imported once, non-extractable and usable only for signing
    • everywhere else: the same pure-Dart signer as before, but the PEM is parsed once instead of on every proof
  • dpop_token_generator.dart:
    • The proof's signing input is built in one shared, public method, signingInput.
    • generateForRequest and generateForTokenEndpoint now sign with the platform signer.
    • generate keeps its synchronous signature, so nothing that calls it breaks, and still signs in pure Dart.
  • Fix found along the way: dart_jsonwebtoken's JWT.sign was replacing the proof's iat with the device's clock, so the 1.0.10 server-clock fix never reached the server. Proofs now carry the server's time.
  • Why not the webcrypto package, as I first suggested:
    • It would make every app that uses solid_auth compile BoringSSL with CMake.
    • It would force the same objective_c 9.4.0 pin Podmail needed.
    • On native platforms the gain would only be about 2 ms per request.
  • Dependencies: added web ^1.1.1, plus pointycastle for tests only.
  • Version: bumped to 1.1.0, with a CHANGELOG entry.

Tests (test/dpop_token_generator_test.dart)

  • A proof verifies against the key, and its htu has the query and fragment removed, htm is upper case and ath is correct.
  • iat follows the server's clock (tested with the server an hour ahead).
  • The platform signer's output is byte-identical to the pure-Dart signer's. This passes in both the Dart VM and Chrome, so it checks the Web Crypto path directly.
  • All 10 solid_auth tests pass; analyze and format are clean.

Related Issues

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • This change requires a documentation update

How To Test?

  • Use on web build of app, and compare list loads

Checklist

  • Screenshots included here/in linked issue #
  • Changes adhere to the style and coding guidelines
  • I have performed a self-review of my code
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • Any dependent changes have been merged and published in downstream modules
  • The update contains no confidential information
  • The update has no duplicated content
  • No lint check errors are related to these changes (make prep or flutter analyze lib)
  • Integration test dart test output or screenshot included in issue #
  • I tested the PR on these devices:
    • Android
    • iOS
    • Linux
    • MacOS
    • Windows
    • Web
  • I have identified reviewers
  • The PR has been approved by reviewers

Finalising

  • Merge dev into the this branch
  • Resolve any conflicts
  • Add a one line summary into the CHANGELOG.md
  • Push to the git repository and review
  • Merge the PR into dev

@jesscmoore
jesscmoore requested a review from gjwgit September 25, 2026 11:27
@gjwgit
gjwgit merged commit fc03ae1 into dev Sep 27, 2026
20 checks passed
@gjwgit
gjwgit deleted the jess/56_webcrypto branch September 27, 2026 23:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants