From 4f691e4e69780b2bc4763a66466a95dbb96d9d4e Mon Sep 17 00:00:00 2001 From: Max Goedjen Date: Sun, 24 Aug 2025 00:36:59 -0700 Subject: [PATCH] Remove verify. --- Sources/Packages/Localizable.xcstrings | 3 -- .../SecureEnclaveCryptoKitStore.swift | 35 ------------------- 2 files changed, 38 deletions(-) diff --git a/Sources/Packages/Localizable.xcstrings b/Sources/Packages/Localizable.xcstrings index 4eedebe..53e3397 100644 --- a/Sources/Packages/Localizable.xcstrings +++ b/Sources/Packages/Localizable.xcstrings @@ -1329,9 +1329,6 @@ } } } - }, - "auth_context_request_verify_description_%@" : { - }, "copyable_click_to_copy_button" : { "extractionState" : "manual", diff --git a/Sources/Packages/Sources/SecureEnclaveSecretKit/SecureEnclaveStores/SecureEnclaveCryptoKitStore.swift b/Sources/Packages/Sources/SecureEnclaveSecretKit/SecureEnclaveStores/SecureEnclaveCryptoKitStore.swift index 79c95d4..19fbccb 100644 --- a/Sources/Packages/Sources/SecureEnclaveSecretKit/SecureEnclaveStores/SecureEnclaveCryptoKitStore.swift +++ b/Sources/Packages/Sources/SecureEnclaveSecretKit/SecureEnclaveStores/SecureEnclaveCryptoKitStore.swift @@ -84,41 +84,6 @@ extension SecureEnclave { } - func verify(signature: Data, for data: Data, with secret: Secret) throws -> Bool { - let context = LAContext() - context.localizedReason = String(localized: "auth_context_request_verify_description_\(secret.name)") - context.localizedCancelTitle = String(localized: "auth_context_request_deny_button") - let attributes = KeychainDictionary([ - kSecClass: kSecClassKey, - kSecAttrKeyClass: kSecAttrKeyClassPrivate, - kSecAttrApplicationLabel: secret.id as CFData, - kSecAttrKeyType: Constants.keyClass, - kSecAttrTokenID: kSecAttrTokenIDSecureEnclave, - kSecAttrApplicationTag: SecureEnclave.Constants.keyTag, - kSecUseAuthenticationContext: context, - kSecReturnRef: true - ]) - var verifyError: SecurityError? - var untyped: CFTypeRef? - let status = SecItemCopyMatching(attributes, &untyped) - if status != errSecSuccess { - throw KeychainError(statusCode: status) - } - guard let untypedSafe = untyped else { - throw KeychainError(statusCode: errSecSuccess) - } - let key = untypedSafe as! SecKey - let verified = SecKeyVerifySignature(key, .ecdsaSignatureMessageX962SHA256, data as CFData, signature as CFData, &verifyError) - if !verified, let verifyError { - if verifyError.takeUnretainedValue() ~= .verifyError { - return false - } else { - throw SigningError(error: verifyError) - } - } - return verified - } - func existingPersistedAuthenticationContext(secret: Secret) async -> PersistedAuthenticationContext? { await persistentAuthenticationHandler.existingPersistedAuthenticationContext(secret: secret) }