<feed xmlns='http://www.w3.org/2005/Atom'>
<title>domain-dig.git/DomainDig/OwnerAccess.swift, branch chore/owner-record-id-reveal</title>
<subtitle>local-first ios domain inspection toolkit. dns, tls, rdap, audit.
</subtitle>
<id>http://git.krz.sh/krz/domain-dig.git/atom?h=chore%2Fowner-record-id-reveal</id>
<link rel='self' href='http://git.krz.sh/krz/domain-dig.git/atom?h=chore%2Fowner-record-id-reveal'/>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/domain-dig.git/'/>
<updated>2026-07-25T16:59:44+00:00</updated>
<entry>
<title>chore: add DEBUG reveal of the CloudKit owner record ID</title>
<updated>2026-07-25T16:59:44+00:00</updated>
<author>
<name>Christian Cleberg</name>
<email>hello@cleberg.net</email>
</author>
<published>2026-07-25T16:59:44+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/domain-dig.git/commit/?id=030187ece649f3a6e28b298126884602aef16cf0'/>
<id>urn:sha1:030187ece649f3a6e28b298126884602aef16cf0</id>
<content type='text'>
Groundwork for the owner Pro+ allowlist. Adds OwnerAccess, which identifies the
app owner by their CloudKit user-record ID (a stable, opaque per-Apple-ID value
that cannot be guessed or spoofed), plus a DEBUG-only "Developer" row in
Settings → App Info that fetches and copies the current iCloud user's record ID
for the app's container.

OwnerAccess.ownerUserRecordID is empty, so isOwner() is inert until the real
value is filled in. A follow-up will hardcode the owner ID, wire isOwner() into
PurchaseService to grant .proPlus on a match, remove this reveal, and cut 5.0.1.

DEBUG-only UI; release builds are unaffected.
</content>
</entry>
</feed>
