Skip to content

Add local pairing bridge for web-based iOS signers - #2

Merged
Mora140 merged 3 commits into
mainfrom
ios27/pairing-api
Aug 28, 2026
Merged

Add local pairing bridge for web-based iOS signers#2
Mora140 merged 3 commits into
mainfrom
ios27/pairing-api

Conversation

@Mora140

@Mora140Mora140 commented Aug 28, 2026

Copy link
Copy Markdown
Owner

Summary

Adds a loopback-only HTTP bridge so a web-based iOS signer running in Safari can ask LocalDevVPN to run the device pairing flow and hand back the resulting pairing record — the native piece a web app can't provide for itself.

The app already had two ways in (localdevvpn://enable/disable and the App Intent), but both are one-shot commands with no way to return data. This extends the URL scheme with a pair verb as the entry point from a website, and adds the missing return path as a 127.0.0.1-only HTTP server. The packet tunnel is untouched — loopback traffic never enters it, so pairing works whether or not the VPN is connected.

Authorization, not an anonymous read

GET /v1/pairing-record never answers a page that just probes localhost:

  • It requires a bearer token from a session the user approved in the app. Probing without one gets a 401.
  • The prompt shows the browser-supplied Origin (which a page can't forge) plus a six-digit code the requesting page must display, so the user confirms the tab in front of them rather than a hidden one.
  • Every request needs a non-CORS-safelisted header, forcing a preflight, and Host must be the literal loopback authority, which blocks DNS rebinding.
  • Tokens are 256-bit, in memory only, constant-time compared, and expire. Prompts expire after two minutes, one at a time, rate limited.
  • The record is stored with complete data protection, excluded from backups, never logged (only a truncated fingerprint), and never sent anywhere.

The bridge is off by default and only listens while the app is in the foreground, with a short background assertion so a page that was just handed a token can still fetch the record after Safari comes forward.

On the pairing flow itself

No public iOS API lets an app mint a lockdown pairing record for the device it runs on — iOS ≤16 needs a trusted host driving lockdownd, iOS 17+ uses remotepairingd behind an Apple-internal entitlement, and DeviceDiscoveryUI yields an NWEndpoint, not a pairing record. So the system-flow provider reports its availability honestly instead of reaching for private API, and the shipped path falls back to a user-driven pairing-file import through the document picker. A PairingFlowProvider seam behind -D LOCALDEVVPN_NATIVE_PAIRING lets an entitled build drop in a real PIN flow later without changing the API, the states, or the UI.

No new entitlements, no .pbxproj changes (the project uses synchronized folder groups).

Test plan

  • Builds clean in Xcode for iOS and tvOS
  • Enable Settings → Pairing Bridge → Allow local web clients; confirm the server comes up on one of 1984219844
  • Serve docs/pairing-bridge-demo.html and run both flows end to end: the localdevvpn://pair deep link and the polling/verification-code flow
  • Confirm GET /v1/pairing-record returns 401 with no token, and only succeeds after approving in the app
  • Import a pairing file in Settings and confirm the bridge serves it back to an authorized session
  • Confirm revoking access, disabling the bridge, and backgrounding the app each tear down sessions and the listener

docs/pairing-bridge.md has the full API reference, the security model, and the iOS API, entitlement, App Store, background-execution, Safari/CORS and networking limitations worth knowing about.

…device's pairing record over 127.0.0.1, gated behind explicit in-app approval + a per-session bearer token
…r into its own Foundation-only file so the wire format can be tested without Network
@Mora140
Mora140 merged commit 5b5ee5f into mainAug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Mora140
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Add local pairing bridge for web-based iOS signers by Mora140 · Pull Request #2 · Mora140/LocalDevVPN · GitHub
Skip to content

Add local pairing bridge for web-based iOS signers - #2

Merged
Mora140 merged 3 commits into
mainfrom
ios27/pairing-api
Aug 28, 2026
Merged

Add local pairing bridge for web-based iOS signers#2
Mora140 merged 3 commits into
mainfrom
ios27/pairing-api

Conversation

@Mora140

@Mora140Mora140 commented Aug 28, 2026

Copy link
Copy Markdown
Owner

Summary

Adds a loopback-only HTTP bridge so a web-based iOS signer running in Safari can ask LocalDevVPN to run the device pairing flow and hand back the resulting pairing record — the native piece a web app can't provide for itself.

The app already had two ways in (localdevvpn://enable/disable and the App Intent), but both are one-shot commands with no way to return data. This extends the URL scheme with a pair verb as the entry point from a website, and adds the missing return path as a 127.0.0.1-only HTTP server. The packet tunnel is untouched — loopback traffic never enters it, so pairing works whether or not the VPN is connected.

Authorization, not an anonymous read

GET /v1/pairing-record never answers a page that just probes localhost:

  • It requires a bearer token from a session the user approved in the app. Probing without one gets a 401.
  • The prompt shows the browser-supplied Origin (which a page can't forge) plus a six-digit code the requesting page must display, so the user confirms the tab in front of them rather than a hidden one.
  • Every request needs a non-CORS-safelisted header, forcing a preflight, and Host must be the literal loopback authority, which blocks DNS rebinding.
  • Tokens are 256-bit, in memory only, constant-time compared, and expire. Prompts expire after two minutes, one at a time, rate limited.
  • The record is stored with complete data protection, excluded from backups, never logged (only a truncated fingerprint), and never sent anywhere.

The bridge is off by default and only listens while the app is in the foreground, with a short background assertion so a page that was just handed a token can still fetch the record after Safari comes forward.

On the pairing flow itself

No public iOS API lets an app mint a lockdown pairing record for the device it runs on — iOS ≤16 needs a trusted host driving lockdownd, iOS 17+ uses remotepairingd behind an Apple-internal entitlement, and DeviceDiscoveryUI yields an NWEndpoint, not a pairing record. So the system-flow provider reports its availability honestly instead of reaching for private API, and the shipped path falls back to a user-driven pairing-file import through the document picker. A PairingFlowProvider seam behind -D LOCALDEVVPN_NATIVE_PAIRING lets an entitled build drop in a real PIN flow later without changing the API, the states, or the UI.

No new entitlements, no .pbxproj changes (the project uses synchronized folder groups).

Test plan

  • Builds clean in Xcode for iOS and tvOS
  • Enable Settings → Pairing Bridge → Allow local web clients; confirm the server comes up on one of 1984219844
  • Serve docs/pairing-bridge-demo.html and run both flows end to end: the localdevvpn://pair deep link and the polling/verification-code flow
  • Confirm GET /v1/pairing-record returns 401 with no token, and only succeeds after approving in the app
  • Import a pairing file in Settings and confirm the bridge serves it back to an authorized session
  • Confirm revoking access, disabling the bridge, and backgrounding the app each tear down sessions and the listener

docs/pairing-bridge.md has the full API reference, the security model, and the iOS API, entitlement, App Store, background-execution, Safari/CORS and networking limitations worth knowing about.

…device's pairing record over 127.0.0.1, gated behind explicit in-app approval + a per-session bearer token
…r into its own Foundation-only file so the wire format can be tested without Network
@Mora140
Mora140 merged commit 5b5ee5f into mainAug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Mora140
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Add local pairing bridge for web-based iOS signers by Mora140 · Pull Request #2 · Mora140/LocalDevVPN · GitHub
Skip to content

Add local pairing bridge for web-based iOS signers - #2

Merged
Mora140 merged 3 commits into
mainfrom
ios27/pairing-api
Aug 28, 2026
Merged

Add local pairing bridge for web-based iOS signers#2
Mora140 merged 3 commits into
mainfrom
ios27/pairing-api

Conversation

@Mora140

@Mora140Mora140 commented Aug 28, 2026

Copy link
Copy Markdown
Owner

Summary

Adds a loopback-only HTTP bridge so a web-based iOS signer running in Safari can ask LocalDevVPN to run the device pairing flow and hand back the resulting pairing record — the native piece a web app can't provide for itself.

The app already had two ways in (localdevvpn://enable/disable and the App Intent), but both are one-shot commands with no way to return data. This extends the URL scheme with a pair verb as the entry point from a website, and adds the missing return path as a 127.0.0.1-only HTTP server. The packet tunnel is untouched — loopback traffic never enters it, so pairing works whether or not the VPN is connected.

Authorization, not an anonymous read

GET /v1/pairing-record never answers a page that just probes localhost:

  • It requires a bearer token from a session the user approved in the app. Probing without one gets a 401.
  • The prompt shows the browser-supplied Origin (which a page can't forge) plus a six-digit code the requesting page must display, so the user confirms the tab in front of them rather than a hidden one.
  • Every request needs a non-CORS-safelisted header, forcing a preflight, and Host must be the literal loopback authority, which blocks DNS rebinding.
  • Tokens are 256-bit, in memory only, constant-time compared, and expire. Prompts expire after two minutes, one at a time, rate limited.
  • The record is stored with complete data protection, excluded from backups, never logged (only a truncated fingerprint), and never sent anywhere.

The bridge is off by default and only listens while the app is in the foreground, with a short background assertion so a page that was just handed a token can still fetch the record after Safari comes forward.

On the pairing flow itself

No public iOS API lets an app mint a lockdown pairing record for the device it runs on — iOS ≤16 needs a trusted host driving lockdownd, iOS 17+ uses remotepairingd behind an Apple-internal entitlement, and DeviceDiscoveryUI yields an NWEndpoint, not a pairing record. So the system-flow provider reports its availability honestly instead of reaching for private API, and the shipped path falls back to a user-driven pairing-file import through the document picker. A PairingFlowProvider seam behind -D LOCALDEVVPN_NATIVE_PAIRING lets an entitled build drop in a real PIN flow later without changing the API, the states, or the UI.

No new entitlements, no .pbxproj changes (the project uses synchronized folder groups).

Test plan

  • Builds clean in Xcode for iOS and tvOS
  • Enable Settings → Pairing Bridge → Allow local web clients; confirm the server comes up on one of 1984219844
  • Serve docs/pairing-bridge-demo.html and run both flows end to end: the localdevvpn://pair deep link and the polling/verification-code flow
  • Confirm GET /v1/pairing-record returns 401 with no token, and only succeeds after approving in the app
  • Import a pairing file in Settings and confirm the bridge serves it back to an authorized session
  • Confirm revoking access, disabling the bridge, and backgrounding the app each tear down sessions and the listener

docs/pairing-bridge.md has the full API reference, the security model, and the iOS API, entitlement, App Store, background-execution, Safari/CORS and networking limitations worth knowing about.

…device's pairing record over 127.0.0.1, gated behind explicit in-app approval + a per-session bearer token
…r into its own Foundation-only file so the wire format can be tested without Network
@Mora140
Mora140 merged commit 5b5ee5f into mainAug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Mora140
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Add local pairing bridge for web-based iOS signers by Mora140 · Pull Request #2 · Mora140/LocalDevVPN · GitHub
Skip to content

Add local pairing bridge for web-based iOS signers - #2

Merged
Mora140 merged 3 commits into
mainfrom
ios27/pairing-api
Aug 28, 2026
Merged

Add local pairing bridge for web-based iOS signers#2
Mora140 merged 3 commits into
mainfrom
ios27/pairing-api

Conversation

@Mora140

@Mora140Mora140 commented Aug 28, 2026

Copy link
Copy Markdown
Owner

Summary

Adds a loopback-only HTTP bridge so a web-based iOS signer running in Safari can ask LocalDevVPN to run the device pairing flow and hand back the resulting pairing record — the native piece a web app can't provide for itself.

The app already had two ways in (localdevvpn://enable/disable and the App Intent), but both are one-shot commands with no way to return data. This extends the URL scheme with a pair verb as the entry point from a website, and adds the missing return path as a 127.0.0.1-only HTTP server. The packet tunnel is untouched — loopback traffic never enters it, so pairing works whether or not the VPN is connected.

Authorization, not an anonymous read

GET /v1/pairing-record never answers a page that just probes localhost:

  • It requires a bearer token from a session the user approved in the app. Probing without one gets a 401.
  • The prompt shows the browser-supplied Origin (which a page can't forge) plus a six-digit code the requesting page must display, so the user confirms the tab in front of them rather than a hidden one.
  • Every request needs a non-CORS-safelisted header, forcing a preflight, and Host must be the literal loopback authority, which blocks DNS rebinding.
  • Tokens are 256-bit, in memory only, constant-time compared, and expire. Prompts expire after two minutes, one at a time, rate limited.
  • The record is stored with complete data protection, excluded from backups, never logged (only a truncated fingerprint), and never sent anywhere.

The bridge is off by default and only listens while the app is in the foreground, with a short background assertion so a page that was just handed a token can still fetch the record after Safari comes forward.

On the pairing flow itself

No public iOS API lets an app mint a lockdown pairing record for the device it runs on — iOS ≤16 needs a trusted host driving lockdownd, iOS 17+ uses remotepairingd behind an Apple-internal entitlement, and DeviceDiscoveryUI yields an NWEndpoint, not a pairing record. So the system-flow provider reports its availability honestly instead of reaching for private API, and the shipped path falls back to a user-driven pairing-file import through the document picker. A PairingFlowProvider seam behind -D LOCALDEVVPN_NATIVE_PAIRING lets an entitled build drop in a real PIN flow later without changing the API, the states, or the UI.

No new entitlements, no .pbxproj changes (the project uses synchronized folder groups).

Test plan

  • Builds clean in Xcode for iOS and tvOS
  • Enable Settings → Pairing Bridge → Allow local web clients; confirm the server comes up on one of 1984219844
  • Serve docs/pairing-bridge-demo.html and run both flows end to end: the localdevvpn://pair deep link and the polling/verification-code flow
  • Confirm GET /v1/pairing-record returns 401 with no token, and only succeeds after approving in the app
  • Import a pairing file in Settings and confirm the bridge serves it back to an authorized session
  • Confirm revoking access, disabling the bridge, and backgrounding the app each tear down sessions and the listener

docs/pairing-bridge.md has the full API reference, the security model, and the iOS API, entitlement, App Store, background-execution, Safari/CORS and networking limitations worth knowing about.

…device's pairing record over 127.0.0.1, gated behind explicit in-app approval + a per-session bearer token
…r into its own Foundation-only file so the wire format can be tested without Network
@Mora140
Mora140 merged commit 5b5ee5f into mainAug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Mora140
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Add local pairing bridge for web-based iOS signers by Mora140 · Pull Request #2 · Mora140/LocalDevVPN · GitHub
Skip to content

Add local pairing bridge for web-based iOS signers - #2

Merged
Mora140 merged 3 commits into
mainfrom
ios27/pairing-api
Aug 28, 2026
Merged

Add local pairing bridge for web-based iOS signers#2
Mora140 merged 3 commits into
mainfrom
ios27/pairing-api

Conversation

@Mora140

@Mora140Mora140 commented Aug 28, 2026

Copy link
Copy Markdown
Owner

Summary

Adds a loopback-only HTTP bridge so a web-based iOS signer running in Safari can ask LocalDevVPN to run the device pairing flow and hand back the resulting pairing record — the native piece a web app can't provide for itself.

The app already had two ways in (localdevvpn://enable/disable and the App Intent), but both are one-shot commands with no way to return data. This extends the URL scheme with a pair verb as the entry point from a website, and adds the missing return path as a 127.0.0.1-only HTTP server. The packet tunnel is untouched — loopback traffic never enters it, so pairing works whether or not the VPN is connected.

Authorization, not an anonymous read

GET /v1/pairing-record never answers a page that just probes localhost:

  • It requires a bearer token from a session the user approved in the app. Probing without one gets a 401.
  • The prompt shows the browser-supplied Origin (which a page can't forge) plus a six-digit code the requesting page must display, so the user confirms the tab in front of them rather than a hidden one.
  • Every request needs a non-CORS-safelisted header, forcing a preflight, and Host must be the literal loopback authority, which blocks DNS rebinding.
  • Tokens are 256-bit, in memory only, constant-time compared, and expire. Prompts expire after two minutes, one at a time, rate limited.
  • The record is stored with complete data protection, excluded from backups, never logged (only a truncated fingerprint), and never sent anywhere.

The bridge is off by default and only listens while the app is in the foreground, with a short background assertion so a page that was just handed a token can still fetch the record after Safari comes forward.

On the pairing flow itself

No public iOS API lets an app mint a lockdown pairing record for the device it runs on — iOS ≤16 needs a trusted host driving lockdownd, iOS 17+ uses remotepairingd behind an Apple-internal entitlement, and DeviceDiscoveryUI yields an NWEndpoint, not a pairing record. So the system-flow provider reports its availability honestly instead of reaching for private API, and the shipped path falls back to a user-driven pairing-file import through the document picker. A PairingFlowProvider seam behind -D LOCALDEVVPN_NATIVE_PAIRING lets an entitled build drop in a real PIN flow later without changing the API, the states, or the UI.

No new entitlements, no .pbxproj changes (the project uses synchronized folder groups).

Test plan

  • Builds clean in Xcode for iOS and tvOS
  • Enable Settings → Pairing Bridge → Allow local web clients; confirm the server comes up on one of 1984219844
  • Serve docs/pairing-bridge-demo.html and run both flows end to end: the localdevvpn://pair deep link and the polling/verification-code flow
  • Confirm GET /v1/pairing-record returns 401 with no token, and only succeeds after approving in the app
  • Import a pairing file in Settings and confirm the bridge serves it back to an authorized session
  • Confirm revoking access, disabling the bridge, and backgrounding the app each tear down sessions and the listener

docs/pairing-bridge.md has the full API reference, the security model, and the iOS API, entitlement, App Store, background-execution, Safari/CORS and networking limitations worth knowing about.

…device's pairing record over 127.0.0.1, gated behind explicit in-app approval + a per-session bearer token
…r into its own Foundation-only file so the wire format can be tested without Network
@Mora140
Mora140 merged commit 5b5ee5f into mainAug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Mora140
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Add local pairing bridge for web-based iOS signers by Mora140 · Pull Request #2 · Mora140/LocalDevVPN · GitHub
Skip to content

Add local pairing bridge for web-based iOS signers - #2

Merged
Mora140 merged 3 commits into
mainfrom
ios27/pairing-api
Aug 28, 2026
Merged

Add local pairing bridge for web-based iOS signers#2
Mora140 merged 3 commits into
mainfrom
ios27/pairing-api

Conversation

@Mora140

@Mora140Mora140 commented Aug 28, 2026

Copy link
Copy Markdown
Owner

Summary

Adds a loopback-only HTTP bridge so a web-based iOS signer running in Safari can ask LocalDevVPN to run the device pairing flow and hand back the resulting pairing record — the native piece a web app can't provide for itself.

The app already had two ways in (localdevvpn://enable/disable and the App Intent), but both are one-shot commands with no way to return data. This extends the URL scheme with a pair verb as the entry point from a website, and adds the missing return path as a 127.0.0.1-only HTTP server. The packet tunnel is untouched — loopback traffic never enters it, so pairing works whether or not the VPN is connected.

Authorization, not an anonymous read

GET /v1/pairing-record never answers a page that just probes localhost:

  • It requires a bearer token from a session the user approved in the app. Probing without one gets a 401.
  • The prompt shows the browser-supplied Origin (which a page can't forge) plus a six-digit code the requesting page must display, so the user confirms the tab in front of them rather than a hidden one.
  • Every request needs a non-CORS-safelisted header, forcing a preflight, and Host must be the literal loopback authority, which blocks DNS rebinding.
  • Tokens are 256-bit, in memory only, constant-time compared, and expire. Prompts expire after two minutes, one at a time, rate limited.
  • The record is stored with complete data protection, excluded from backups, never logged (only a truncated fingerprint), and never sent anywhere.

The bridge is off by default and only listens while the app is in the foreground, with a short background assertion so a page that was just handed a token can still fetch the record after Safari comes forward.

On the pairing flow itself

No public iOS API lets an app mint a lockdown pairing record for the device it runs on — iOS ≤16 needs a trusted host driving lockdownd, iOS 17+ uses remotepairingd behind an Apple-internal entitlement, and DeviceDiscoveryUI yields an NWEndpoint, not a pairing record. So the system-flow provider reports its availability honestly instead of reaching for private API, and the shipped path falls back to a user-driven pairing-file import through the document picker. A PairingFlowProvider seam behind -D LOCALDEVVPN_NATIVE_PAIRING lets an entitled build drop in a real PIN flow later without changing the API, the states, or the UI.

No new entitlements, no .pbxproj changes (the project uses synchronized folder groups).

Test plan

  • Builds clean in Xcode for iOS and tvOS
  • Enable Settings → Pairing Bridge → Allow local web clients; confirm the server comes up on one of 1984219844
  • Serve docs/pairing-bridge-demo.html and run both flows end to end: the localdevvpn://pair deep link and the polling/verification-code flow
  • Confirm GET /v1/pairing-record returns 401 with no token, and only succeeds after approving in the app
  • Import a pairing file in Settings and confirm the bridge serves it back to an authorized session
  • Confirm revoking access, disabling the bridge, and backgrounding the app each tear down sessions and the listener

docs/pairing-bridge.md has the full API reference, the security model, and the iOS API, entitlement, App Store, background-execution, Safari/CORS and networking limitations worth knowing about.

…device's pairing record over 127.0.0.1, gated behind explicit in-app approval + a per-session bearer token
…r into its own Foundation-only file so the wire format can be tested without Network
@Mora140
Mora140 merged commit 5b5ee5f into mainAug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Mora140
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Add local pairing bridge for web-based iOS signers by Mora140 · Pull Request #2 · Mora140/LocalDevVPN · GitHub
Skip to content

Add local pairing bridge for web-based iOS signers - #2

Merged
Mora140 merged 3 commits into
mainfrom
ios27/pairing-api
Aug 28, 2026
Merged

Add local pairing bridge for web-based iOS signers#2
Mora140 merged 3 commits into
mainfrom
ios27/pairing-api

Conversation

@Mora140

@Mora140Mora140 commented Aug 28, 2026

Copy link
Copy Markdown
Owner

Summary

Adds a loopback-only HTTP bridge so a web-based iOS signer running in Safari can ask LocalDevVPN to run the device pairing flow and hand back the resulting pairing record — the native piece a web app can't provide for itself.

The app already had two ways in (localdevvpn://enable/disable and the App Intent), but both are one-shot commands with no way to return data. This extends the URL scheme with a pair verb as the entry point from a website, and adds the missing return path as a 127.0.0.1-only HTTP server. The packet tunnel is untouched — loopback traffic never enters it, so pairing works whether or not the VPN is connected.

Authorization, not an anonymous read

GET /v1/pairing-record never answers a page that just probes localhost:

  • It requires a bearer token from a session the user approved in the app. Probing without one gets a 401.
  • The prompt shows the browser-supplied Origin (which a page can't forge) plus a six-digit code the requesting page must display, so the user confirms the tab in front of them rather than a hidden one.
  • Every request needs a non-CORS-safelisted header, forcing a preflight, and Host must be the literal loopback authority, which blocks DNS rebinding.
  • Tokens are 256-bit, in memory only, constant-time compared, and expire. Prompts expire after two minutes, one at a time, rate limited.
  • The record is stored with complete data protection, excluded from backups, never logged (only a truncated fingerprint), and never sent anywhere.

The bridge is off by default and only listens while the app is in the foreground, with a short background assertion so a page that was just handed a token can still fetch the record after Safari comes forward.

On the pairing flow itself

No public iOS API lets an app mint a lockdown pairing record for the device it runs on — iOS ≤16 needs a trusted host driving lockdownd, iOS 17+ uses remotepairingd behind an Apple-internal entitlement, and DeviceDiscoveryUI yields an NWEndpoint, not a pairing record. So the system-flow provider reports its availability honestly instead of reaching for private API, and the shipped path falls back to a user-driven pairing-file import through the document picker. A PairingFlowProvider seam behind -D LOCALDEVVPN_NATIVE_PAIRING lets an entitled build drop in a real PIN flow later without changing the API, the states, or the UI.

No new entitlements, no .pbxproj changes (the project uses synchronized folder groups).

Test plan

  • Builds clean in Xcode for iOS and tvOS
  • Enable Settings → Pairing Bridge → Allow local web clients; confirm the server comes up on one of 1984219844
  • Serve docs/pairing-bridge-demo.html and run both flows end to end: the localdevvpn://pair deep link and the polling/verification-code flow
  • Confirm GET /v1/pairing-record returns 401 with no token, and only succeeds after approving in the app
  • Import a pairing file in Settings and confirm the bridge serves it back to an authorized session
  • Confirm revoking access, disabling the bridge, and backgrounding the app each tear down sessions and the listener

docs/pairing-bridge.md has the full API reference, the security model, and the iOS API, entitlement, App Store, background-execution, Safari/CORS and networking limitations worth knowing about.

…device's pairing record over 127.0.0.1, gated behind explicit in-app approval + a per-session bearer token
…r into its own Foundation-only file so the wire format can be tested without Network
@Mora140
Mora140 merged commit 5b5ee5f into mainAug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Mora140
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Add local pairing bridge for web-based iOS signers by Mora140 · Pull Request #2 · Mora140/LocalDevVPN · GitHub
Skip to content

Add local pairing bridge for web-based iOS signers - #2

Merged
Mora140 merged 3 commits into
mainfrom
ios27/pairing-api
Aug 28, 2026
Merged

Add local pairing bridge for web-based iOS signers#2
Mora140 merged 3 commits into
mainfrom
ios27/pairing-api

Conversation

@Mora140

@Mora140Mora140 commented Aug 28, 2026

Copy link
Copy Markdown
Owner

Summary

Adds a loopback-only HTTP bridge so a web-based iOS signer running in Safari can ask LocalDevVPN to run the device pairing flow and hand back the resulting pairing record — the native piece a web app can't provide for itself.

The app already had two ways in (localdevvpn://enable/disable and the App Intent), but both are one-shot commands with no way to return data. This extends the URL scheme with a pair verb as the entry point from a website, and adds the missing return path as a 127.0.0.1-only HTTP server. The packet tunnel is untouched — loopback traffic never enters it, so pairing works whether or not the VPN is connected.

Authorization, not an anonymous read

GET /v1/pairing-record never answers a page that just probes localhost:

  • It requires a bearer token from a session the user approved in the app. Probing without one gets a 401.
  • The prompt shows the browser-supplied Origin (which a page can't forge) plus a six-digit code the requesting page must display, so the user confirms the tab in front of them rather than a hidden one.
  • Every request needs a non-CORS-safelisted header, forcing a preflight, and Host must be the literal loopback authority, which blocks DNS rebinding.
  • Tokens are 256-bit, in memory only, constant-time compared, and expire. Prompts expire after two minutes, one at a time, rate limited.
  • The record is stored with complete data protection, excluded from backups, never logged (only a truncated fingerprint), and never sent anywhere.

The bridge is off by default and only listens while the app is in the foreground, with a short background assertion so a page that was just handed a token can still fetch the record after Safari comes forward.

On the pairing flow itself

No public iOS API lets an app mint a lockdown pairing record for the device it runs on — iOS ≤16 needs a trusted host driving lockdownd, iOS 17+ uses remotepairingd behind an Apple-internal entitlement, and DeviceDiscoveryUI yields an NWEndpoint, not a pairing record. So the system-flow provider reports its availability honestly instead of reaching for private API, and the shipped path falls back to a user-driven pairing-file import through the document picker. A PairingFlowProvider seam behind -D LOCALDEVVPN_NATIVE_PAIRING lets an entitled build drop in a real PIN flow later without changing the API, the states, or the UI.

No new entitlements, no .pbxproj changes (the project uses synchronized folder groups).

Test plan

  • Builds clean in Xcode for iOS and tvOS
  • Enable Settings → Pairing Bridge → Allow local web clients; confirm the server comes up on one of 1984219844
  • Serve docs/pairing-bridge-demo.html and run both flows end to end: the localdevvpn://pair deep link and the polling/verification-code flow
  • Confirm GET /v1/pairing-record returns 401 with no token, and only succeeds after approving in the app
  • Import a pairing file in Settings and confirm the bridge serves it back to an authorized session
  • Confirm revoking access, disabling the bridge, and backgrounding the app each tear down sessions and the listener

docs/pairing-bridge.md has the full API reference, the security model, and the iOS API, entitlement, App Store, background-execution, Safari/CORS and networking limitations worth knowing about.

…device's pairing record over 127.0.0.1, gated behind explicit in-app approval + a per-session bearer token
…r into its own Foundation-only file so the wire format can be tested without Network
@Mora140
Mora140 merged commit 5b5ee5f into mainAug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Mora140