Commit df69393f7e
Verified · cmc
Layout: unified · split
DomainDig/OwnerAccess.swift +21 −2
| @@ -14,10 +14,29 @@ enum OwnerAccess { | ||
| 14 | 14 | |
| 15 | 15 | static var isConfigured: Bool { !ownerUserRecordID.isEmpty } |
| 16 | 16 | |
| 17 | /// Whether this build actually carries its entitlements. | |
| 18 | /// | |
| 19 | /// Touching CloudKit without the iCloud container entitlement does not | |
| 20 | /// return an error — it raises an Objective-C exception from inside a | |
| 21 | /// `dispatch_once`, which Swift cannot catch, so the process aborts before | |
| 22 | /// the first screen draws. That is what any unsigned build does, including | |
| 23 | /// CI: `xcodebuild ... CODE_SIGNING_ALLOWED=NO` embeds no entitlements. | |
| 24 | /// | |
| 25 | /// The App Group is declared in the same entitlements file and is stripped | |
| 26 | /// by the same mechanism, but asking for its container returns nil rather | |
| 27 | /// than raising. So it answers the question CloudKit will not: does this | |
| 28 | /// process have its entitlements at all? | |
| 29 | private static var hasEntitlements: Bool { | |
| 30 | FileManager.default.containerURL( | |
| 31 | forSecurityApplicationGroupIdentifier: DomainDigWidgetStore.appGroupID | |
| 32 | ) != nil | |
| 33 | } | |
| 34 | ||
| 17 | 35 | /// The current iCloud user's record name for this app's container, or nil if |
| 18 | /// it is unavailable (not signed into iCloud, restricted, or offline before | |
| 19 | /// the first fetch). | |
| 36 | /// it is unavailable (not signed into iCloud, restricted, offline before the | |
| 37 | /// first fetch, or running from a build without entitlements). | |
| 20 | 38 | static func currentUserRecordName() async -> String? { |
| 39 | guard hasEntitlements else { return nil } | |
| 21 | 40 | do { |
| 22 | 41 | return try await CKContainer.default().userRecordID().recordName |
| 23 | 42 | } catch { |