Bug 259861 - [iOS] Attempting to load Wallet pass from api.americaspharmacy.com results in Safari showing a failure alert
Summary: [iOS] Attempting to load Wallet pass from api.americaspharmacy.com results in...
Status: RESOLVED INVALID
Alias: None
Product: WebKit
Classification: Unclassified
Component: Page Loading (show other bugs)
Version: Other
Hardware: iPhone / iPad iOS 16
: P2 Normal
Assignee: Nobody
URL: https://api.americaspharmacy.com/wall...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-08-05 06:10 PDT by andy
Modified: 2023-08-09 11:10 PDT (History)
5 users (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description andy 2023-08-05 06:10:04 PDT
Steps to reproduce 

Go to any WebKit broswer

Then go to https://api.americaspharmacy.com/wallet/samsclub-card-pass

Website fails to load
Comment 1 andy 2023-08-05 06:11:00 PDT
This only fails on iOS
Comment 2 Alexey Proskuryakov 2023-08-09 10:51:56 PDT
When this website sees an iOS user agent, it attempts to provide a Wallet pass instead of an HTML document that it sends to other browsers. 

$ curl -i 'https://api.americaspharmacy.com/wallet/samsclub-card-pass' --header 'User-Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Mobile/15E148 Safari/604.1'
HTTP/1.1 200 OK
Date: Wed, 09 Aug 2023 17:41:47 GMT
Server: Apache
Strict-Transport-Security: max-age=31536000; includeSubDomains
X-Powered-By: Express
Content-Type: application/vnd.apple.pkpass
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Content-Security-Policy: frame-ancestors 'self' *.medimpact.com;
Transfer-Encoding: chunked


Not yet certain if this is a bug in Safari or WebKit, or something wrong with the website. But this explains why the behavior is different between iOS and desktop.
Comment 3 Alexey Proskuryakov 2023-08-09 11:10:05 PDT
I can see that the Wallet pass being downloaded is signed with an expired certificate, and that's what is almost certainly causing the problem.

The UI could be better, but any UI enhancement in this area would be in Safari, outside the WebKit open source project.