Skip to content

[flutter_appauth] feat(android): allow restricting which browser handles auth requests - #682

Open
ddfreiling wants to merge 1 commit into
MaikuB:masterfrom
Notalib:feat/android-browser-matcher
Open

ddfreiling wants to merge 1 commit into
MaikuB:masterfrom
Notalib:feat/android-browser-matcher

Conversation

@ddfreiling

Copy link
Copy Markdown

What

Adds an androidAllowedBrowsers property to AuthorizationRequest, AuthorizationTokenRequest and EndSessionRequest. Each entry is either one of six presets that map to AppAuth's VersionedBrowserMatcher constants, or a custom descriptor naming any browser by package name and signature hashes. The list becomes a BrowserAllowList on the AppAuthConfiguration. A null or empty list keeps the existing behaviour of allowing any installed browser.

The browser matcher is fixed when an AuthorizationService is built, so the two pre-built services are replaced with a cache keyed by connection security and browser list. Caching rather than recreating avoids disposing a service while an authorization flow is still in progress.

Also wraps the end session intent launch in the same ActivityNotFoundException handling that performAuthorization already had. Without it, an allow list that matches no installed browser would throw instead of returning a no_browser_available error.

Why

Discussed here as an improvement: #537

Adds an `androidAllowedBrowsers` property to `AuthorizationRequest`,
`AuthorizationTokenRequest` and `EndSessionRequest`. Each entry is either
one of six presets that map to AppAuth's `VersionedBrowserMatcher`
constants, or a custom descriptor naming any browser by package name and
signature hashes. The list becomes a `BrowserAllowList` on the
`AppAuthConfiguration`. A null or empty list keeps the existing behaviour
of allowing any installed browser.

The browser matcher is fixed when an `AuthorizationService` is built, so
the two pre-built services are replaced with a cache keyed by connection
security and browser list. Caching rather than recreating avoids
disposing a service while an authorization flow is still in progress.

Also wraps the end session intent launch in the same
`ActivityNotFoundException` handling that `performAuthorization` already
had. Without it, an allow list that matches no installed browser would
throw instead of returning a `no_browser_available` error.

Refs MaikuB#537

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant