Skip to content

fix(content-server): serve real Fenix fingerprints in assetlinks.json - #21216

Merged
dschom merged 1 commit into
mainfrom
fxa-14084
Sep 16, 2026
Merged

dschom merged 1 commit into
mainfrom
fxa-14084

Conversation

@dschom

@dschom dschom commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Because

  • Android App Links only verify against the real SHA-256 signing certificate fingerprints of Firefox Android. The route served a placeholder string.
  • Release and Beta share a signing certificate while Nightly uses a different one, so a single shared list cannot be correct.

This pull request

  • Replaces the placeholder with fingerprints read via apksigner from the 155.0.1, 157.0b1 and 158.0a1 APKs on ftp.mozilla.org.
  • Maps fingerprints per package name instead of one shared list.
  • Formats fingerprints as upper-case colon-separated hex, the form Digital Asset Links requires.
  • Adds a Playwright smoke spec in packages/functional-tests/tests/misc.spec.ts covering the endpoint's status, package list, relation and fingerprint format.

Issue that this pull request solves

Closes: FXA-14084

Checklist

Put an x in the boxes that apply

  • My commit is GPG signed.
  • If applicable, I have modified or added tests which pass locally.
  • I have added necessary documentation (if appropriate).
  • I have verified that my changes render correctly in RTL (if appropriate).
  • I have manually reviewed all AI generated code.

How to review (Optional)

App Links cannot be exercised locally (see below). Verify on stage once this deploys:

  1. Confirm the file is served over https on port 443 with no redirect and Content-Type: application/json:
    curl -si https://accounts.stage.mozaws.net/.well-known/assetlinks.json
    
  2. Ask Google's Digital Asset Links API what it sees for the host. Each of the three packages should come back with its fingerprint:
    https://digitalassetlinks.googleapis.com/v1/statements:list?source.web.site=https://accounts.stage.mozaws.net&relation=delegate_permission/common.handle_all_urls
    
  3. Confirm Fenix declares that host in its manifest with android:autoVerify="true". If Fenix only declares accounts.firefox.com, stage will never verify and step 4 only works against prod.
  4. On an Android 12+ device with Firefox installed, force re-verification and check the result. Each declared host should show verified:
    adb shell pm verify-app-links --re-verify org.mozilla.firefox
    adb shell pm get-app-links org.mozilla.firefox
    
  5. Scan a pairing QR code from that host with the camera app. It should open directly in Firefox rather than the default browser.

Repeat with org.mozilla.firefox_beta and org.mozilla.fenix to cover the Beta and Nightly certificates.

Screenshots (Optional)

Other information (Optional)

Why this cannot be tested on localhost: Android verifies App Links at app install or update time, not when a link is opened. The system verifier fetches https://<host>/.well-known/assetlinks.json for each host Fenix declares with autoVerify, https only, port 443 only, no redirects, and caches the result. A local server fails every one of those conditions, localhost on the phone is the phone itself, and Fenix does not declare localhost as a host. The QR code also encodes the current origin, so locally it is an http URL, and http URLs never participate in App Links. Scanning a local QR code will always open the default browser regardless of what this route serves.

@dschom
dschom marked this pull request as ready for review September 15, 2026 02:33
@dschom
dschom requested a review from a team as a code owner September 15, 2026 02:33
Because:

- Android App Links only verify against the real SHA-256 signing
  certificate fingerprints of Firefox Android. The route served a
  placeholder string.
- Release and Beta share a signing certificate while Nightly uses a
  different one, so a single shared list cannot be correct.

This commit:

- Replaces the placeholder with fingerprints read via apksigner from the
  155.0.1, 157.0b1 and 158.0a1 APKs on ftp.mozilla.org.
- Maps fingerprints per package name instead of one shared list.
- Formats fingerprints as upper-case colon-separated hex, the form
  Digital Asset Links requires.
- Adds a Playwright smoke spec for the endpoint's shape and format.

Closes FXA-14084
@dschom
dschom merged commit fedebdd into main Sep 16, 2026
18 of 20 checks passed
@dschom
dschom deleted the fxa-14084 branch September 16, 2026 16:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants