From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id F0E041FF0AE for ; Tue, 01 Sep 2026 11:30:17 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 11F3C21540; Tue, 01 Sep 2026 11:30:17 +0200 (CEST) Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Tue, 01 Sep 2026 11:30:11 +0200 Message-Id: Subject: Re: [PATCH 0/2] android: register OpenID Connect callback activity for #4281 From: "Shan Shaji" To: "Azharul Haque" , X-Mailer: aerc 0.20.0 References: <20260810054037.17184-1-haque@azharul.com> In-Reply-To: <20260810054037.17184-1-haque@azharul.com> X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1788255008955 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.489 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: NDA22TSU25IXQR7WS5HO7NQW3TVQE7AB X-Message-ID-Hash: NDA22TSU25IXQR7WS5HO7NQW3TVQE7AB X-MailFrom: s.shaji@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Hi Azharul, After reading through this [RFC 8252][0], it is a must to always use PKCE with native apps. > Public native app clients MUST implement the Proof Key for Code > Exchange (PKCE RFC7636 [1]) extension to OAuth, and authorization > servers MUST support PKCE for such clients, for the reasons detailed > in Section 8.1 [2]. Section 8.1 > The redirect URI options documented in Section 7 share the benefit > that only a native app on the same device or the app's own website > can receive the authorization code, which limits the attack surface. > However, code interception by a different native app running on the > same device may be possible. > A limitation of using private-use URI schemes for redirect URIs is > that multiple apps can typically register the same scheme, which > makes it indeterminate as to which app will receive the authorization > code. In Android, if there are multiple apps with the same URI schemes, it will show a disambiguation dialog [3], which will allow the user to select the app. AFAIU, this behaviour happens if the app is using custom tabs instead of the custom auth tabs which was released with chrome 132 [4][5]. As for the custom auth tabs [7]: > Authentication strategies built on Custom Tabs offer a vast improvement > from prior solutions, but challenges still remain: > > - Communication between the browser tab and the app relies on > Activity intents, which can expose your app to potential > interference to your intent > - Using Activity intents to manage information transfer from the > tab is less idiomatic than using Android APIs > > Auth Tab solves these problems. A dedicated callback adds a layer of > security and eliminates the need for Activity intents. On iOS, as the plugin is using (iOS 12+) ASWebAuthenticationSession [6] only the calling app's session will receive the authentication callback. > `ASWebAuthenticationSession` ensures that only the calling app's session > receives the authentication callback, even when more than one app > registers the same callback URL scheme. Unless I have missed something, the new APIs does protect from code interception attack. Although, IMHO to be on the safe side we should also support PKCE at the client side. WDYT? - [0] https://www.rfc-editor.org/info/rfc8252/#section-6 - [1] https://www.rfc-editor.org/info/rfc7636/#section-1.1 - [2] https://www.rfc-editor.org/info/rfc8252/#section-8.1 - [3] https://developer.android.com/training/app-links/create-deeplinks#how= -deep - [4] https://developer.chrome.com/docs/android/custom-tabs/guide-auth-tab - [5] https://developer.chrome.com/blog/android-auth-tab - [6] https://developer.apple.com/documentation/authenticationservices/aswe= bauthenticationsession - [7] https://developer.chrome.com/blog/android-auth-tab#auth_tab_versus_cu= stom_tabs On Mon Aug 10, 2026 at 7:40 AM CEST, Azharul Haque wrote: > The native Flutter "Proxmox VE Companion" app never implemented OpenID > Connect / OAuth realm login (bug #4281[0]): selecting an OAuth realm > just showed username/password fields that could never work. > > Android requires an app to explicitly declare, in AndroidManifest.xml, > which activity should handle a given custom URL scheme. This series > registers flutter_web_auth_2's CallbackActivity for the > com.proxmox.app.openid:// redirect scheme used by the OAuth flow, and > fixes it up to match a later rename of that scheme. > > No iOS-side changes are needed: ASWebAuthenticationSession resolves > the custom-scheme redirect at runtime without a static declaration > equivalent to this manifest entry. > > Depends on the companion proxmox_dart_api_client and > proxmox_login_manager series, which implement the OIDC API calls and > login-form/OAuth-flow UI respectively. > > Verified end-to-end against a real PVE server with an Authentik OIDC > realm, on both Android and iOS. > > [0] https://bugzilla.proxmox.com/show_bug.cgi?id=3D4281 > > Azharul Haque (2): > fix #4281: android: register OpenID Connect callback activity > fix #4281: android: match renamed OpenID callback scheme > > android/app/src/main/AndroidManifest.xml | 16 ++ > linux/flutter/generated_plugin_registrant.cc | 8 + > linux/flutter/generated_plugins.cmake | 2 + > pubspec.lock | 184 +++++++++++-------- > 4 files changed, 138 insertions(+), 72 deletions(-)