Skip to content
This repository has been archived by the owner on May 10, 2024. It is now read-only.

Fix #5543: Relax SSL Certificate Validation to match all other browsers #7588

Merged
merged 1 commit into from Jun 13, 2023
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
38 changes: 33 additions & 5 deletions Sources/Brave/Frontend/Browser/BrowserViewController.swift
Expand Up @@ -1721,17 +1721,45 @@ public class BrowserViewController: UIViewController {
break
}

let host = tab.webView?.url?.host
guard let scheme = tab.webView?.url?.scheme,
let host = tab.webView?.url?.host else {
tab.secureContentState = .insecure
self.updateURLBar()
return
}

Task {
let port: Int
if let urlPort = tab.webView?.url?.port {
port = urlPort
} else if scheme == "https" {
port = 443
} else {
port = 80
}

Task.detached {
do {
try await BraveCertificateUtils.evaluateTrust(serverTrust, for: host)
tab.secureContentState = .secure
let result = BraveCertificateUtility.verifyTrust(serverTrust,
host: host,
port: port)
// Cert is valid!
if result == 0 {
tab.secureContentState = .secure
} else if result == Int32.min {
// Cert is valid but should be validated by the system
// Let the system handle it and we'll show an error if the system cannot validate it
stoletheminerals marked this conversation as resolved.
Show resolved Hide resolved
try await BraveCertificateUtils.evaluateTrust(serverTrust, for: host)
tab.secureContentState = .secure
} else {
tab.secureContentState = .insecure
}
} catch {
tab.secureContentState = .insecure
}

self.updateURLBar()
Task { @MainActor in
self.updateURLBar()
}
}
case ._sampledPageTopColor:
updateStatusBarOverlayColor()
Expand Down
1 change: 0 additions & 1 deletion Sources/CertificateUtilities/BraveCertificateUtils.swift
Expand Up @@ -206,7 +206,6 @@ public extension BraveCertificateUtils {

static func evaluateTrust(_ trust: SecTrust, for host: String?) async throws {
let policies = [
SecPolicyCreateBasicX509(),
SecPolicyCreateSSL(true, host as CFString?),
]

Expand Down