Repository navigation
Generate unique Keychain-backed RDP credentials per baseline - #5
Conversation
Co-authored-by: rkttu <1297346+rkttu@users.noreply.github.com>
|
|
There was a problem hiding this comment.
🟡 Changes recommended
There are at least two verified correctness/security issues in the updated run/provisioning flow that should be addressed before merging.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
This PR replaces the repository-wide fixed Windows Sandbox RDP password with per-baseline, cryptographically generated credentials stored in macOS Keychain, and threads that credential through unattended provisioning and the embedded FreeRDP session while updating test tooling to accept injected credentials.
Changes:
- Generate a per-baseline password, store it in Keychain under a baseline-specific UUID, and persist only
schemaVersion+credentialIDinmetadata.json. - Pass the per-baseline password into the unattended setup flow and ensure provisioning artifacts are removed.
- Update embedded RDP view + C FreeRDP test utilities to accept credentials (via Swift wiring /
MSBX_RDP_USERNAME+MSBX_RDP_PASSWORDfor test tools).
File summaries
| File | Description |
|---|---|
| src/MacSandbox/Views/SandboxView.swift | Passes the runtime Keychain-backed password into the embedded RDP view. |
| src/MacSandbox/Views/RDPHostView.swift | Makes the embedded RDP view require an explicit password (no longer sourced from a constant). |
| src/MacSandbox/MacSandboxApp.swift | Injects test-tool credentials from environment variables and wires them into CFreeRDP utilities. |
| src/MacSandbox/Core/UnattendBuilder.swift | Accepts per-baseline password and applies it during FirstLogonCommands; removes unattend.xml afterward. |
| src/MacSandbox/Core/SandboxRunner.swift | Validates baseline schema + Keychain credential presence; loads/clears password for embedded RDP. |
| src/MacSandbox/Core/SandboxModels.swift | Adds metadata schema versioning and a Keychain credential identifier. |
| src/MacSandbox/Core/SandboxConfig.swift | Removes the fixed password constant; keeps only the account name. |
| src/MacSandbox/Core/RDPSession.swift | Narrows responsibility to local port selection for embedded RDP. |
| src/MacSandbox/Core/BaselineCredentialStore.swift | Implements Keychain-backed credential generation/save/load/delete. |
| src/MacSandbox/Core/BaselineBuilder.swift | Generates/saves credentials per build, updates metadata, and deletes credentials on failure/rebuild. |
| src/MacSandbox/Core/BaselineAdmin.swift | Deletes the Keychain credential when destroying the baseline. |
| src/CFreeRDP/rdp_filetest.c | Removes hard-coded credentials; accepts injected username/password. |
| src/CFreeRDP/rdp_cliptest.c | Removes hard-coded credentials; accepts injected username/password. |
| src/CFreeRDP/rdp_capture.c | Removes hard-coded credentials; accepts injected username/password. |
| src/CFreeRDP/include/CFreeRDP.h | Updates headers to match new credential-injected function signatures. |
| Package.swift | Links the Security framework for Keychain access. |
| ARCHITECTURE.md | Updates documentation to reflect Keychain-backed per-baseline RDP credentials. |
Review details
- Files reviewed: 17/17 changed files
- Comments generated: 2
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| defer { | ||
| rdpPassword = "" | ||
| isRunning = false | ||
| } |
| <Order>11</Order> | ||
| <CommandLine>reg add "HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa" /v LimitBlankPasswordUse /t REG_DWORD /d 0 /f</CommandLine> | ||
| <Description>allow blank password over RDP</Description> | ||
| <Description>configure RDP password policy</Description> | ||
| </SynchronousCommand> |
Baseline images previously shared a source-coded administrator password. This change generates a unique credential per build and requires legacy baselines to be rebuilt.
Credential lifecycle
Metadata and migration
metadata.json.Provisioning and RDP
Test utilities
MSBX_RDP_USERNAMEandMSBX_RDP_PASSWORD.