2 * Copyright (c) 2017 Apple Inc. All Rights Reserved.
4 * @APPLE_LICENSE_HEADER_START@
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. Please obtain a copy of the License at
10 * http://www.opensource.apple.com/apsl/ and read it before using this
13 * The Original Code and all software distributed under the License are
14 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
15 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
16 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
17 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
18 * Please see the License for the specific language governing rights and
19 * limitations under the License.
21 * @APPLE_LICENSE_HEADER_END@
24 // You must be 64-bit to use this class.
27 #import <Foundation/Foundation.h>
28 #import <Security/OTConstants.h>
30 NS_ASSUME_NONNULL_BEGIN
32 @interface OTControl
: NSObject
33 + (OTControl
* _Nullable
)controlObject
:(NSError
* _Nullable __autoreleasing
* _Nullable
)error
;
34 - (instancetype
)initWithConnection
:(NSXPCConnection
*)connection
;
36 - (void)restore
:(NSString
*)contextID dsid
:(NSString
*)dsid secret
:(NSData
*)secret escrowRecordID
:(NSString
*)escrowRecordID
37 reply
:(void (^)(NSData
* signingKeyData
, NSData
* encryptionKeyData
, NSError
* _Nullable error
))reply
;
38 - (void)encryptionKey
:(void (^)(NSData
* result
, NSError
* _Nullable error
))reply
;
39 - (void)signingKey
:(void (^)(NSData
* result
, NSError
* _Nullable error
))reply
;
40 - (void)listOfRecords
:(void (^)(NSArray
* list
, NSError
* _Nullable error
))reply
;
41 - (void)signOut
:(void (^)(BOOL result
, NSError
* _Nullable error
))reply
;
42 - (void)signIn
:(NSString
*)dsid reply
:(void (^)(BOOL result
, NSError
* _Nullable error
))reply
;
43 - (void)reset
:(void (^)(BOOL result
, NSError
* _Nullable error
))reply
;
45 // Call this to 'preflight' a bottled peer entry. This will create sufficient entropy, derive and save all relevant keys,
46 // then return the entropy to the caller. If something goes wrong during this process, do not store the returned entropy.
47 - (void)preflightBottledPeer
:(NSString
*)contextID
49 reply
:(void (^)(NSData
* _Nullable entropy
,
50 NSString
* _Nullable bottleID
,
51 NSData
* _Nullable signingPublicKey
,
52 NSError
* _Nullable error
))reply
;
54 // Call this to 'launch' a preflighted bottled peer entry. This indicates that you've successfully stored the entropy,
55 // and we should save the bottled peer entry off-device for later retrieval.
56 - (void)launchBottledPeer
:(NSString
*)contextID
57 bottleID
:(NSString
*)bottleID
58 reply
:(void (^ _Nullable
)(NSError
* _Nullable error
))reply
;
60 // Call this to scrub the launch of a preflighted bottled peer entry. This indicates you've terminally failed to store the
61 // preflighted entropy, and this bottled peer will never be used again and can be deleted.
62 - (void)scrubBottledPeer
:(NSString
*)contextID
63 bottleID
:(NSString
*)bottleID
64 reply
:(void (^ _Nullable
)(NSError
* _Nullable error
))reply
;