Sorry Quinn, I'll try to be more specific: We want the key to be usable with either biometry or device passcode - hence .userPresence - but we want to be able to decide whether to allow biometry in some cases or not. With .userPresence this does not seem to be possible out of the box since this always seems to prefer biometry if available.
We tried passing a LAContext which has been used to access a (different) keychain item protected with .devicePasscode, but to no avail.
Topic:
App & System Services
SubTopic:
Core OS
Tags: