aboutsummaryrefslogtreecommitdiff
path: root/DomainDig/OwnerAccess.swift
diff options
context:
space:
mode:
authorChristian Cleberg <[email protected]>2026-07-25 11:59:44 -0500
committerChristian Cleberg <[email protected]>2026-07-25 11:59:44 -0500
commit030187ece649f3a6e28b298126884602aef16cf0 (patch)
tree2e2506a7d1db92c8195b50294a5e121bda7cb352 /DomainDig/OwnerAccess.swift
parent7156c088a438526182c517fafa35d31990d44f18 (diff)
downloaddomain-dig-chore/owner-record-id-reveal.tar.gz
domain-dig-chore/owner-record-id-reveal.tar.bz2
domain-dig-chore/owner-record-id-reveal.zip
chore: add DEBUG reveal of the CloudKit owner record IDchore/owner-record-id-reveal
Groundwork for the owner Pro+ allowlist. Adds OwnerAccess, which identifies the app owner by their CloudKit user-record ID (a stable, opaque per-Apple-ID value that cannot be guessed or spoofed), plus a DEBUG-only "Developer" row in Settings → App Info that fetches and copies the current iCloud user's record ID for the app's container. OwnerAccess.ownerUserRecordID is empty, so isOwner() is inert until the real value is filled in. A follow-up will hardcode the owner ID, wire isOwner() into PurchaseService to grant .proPlus on a match, remove this reveal, and cut 5.0.1. DEBUG-only UI; release builds are unaffected.
Diffstat (limited to 'DomainDig/OwnerAccess.swift')
-rw-r--r--DomainDig/OwnerAccess.swift34
1 files changed, 34 insertions, 0 deletions
diff --git a/DomainDig/OwnerAccess.swift b/DomainDig/OwnerAccess.swift
new file mode 100644
index 0000000..be39a6c
--- /dev/null
+++ b/DomainDig/OwnerAccess.swift
@@ -0,0 +1,34 @@
+import CloudKit
+
+/// Owner-only entitlement support. The app owner is identified by their CloudKit
+/// user-record ID — a stable, opaque per-Apple-ID value for this app's container
+/// that other users cannot guess or spoof — so a release build can grant the
+/// owner Pro+ without a purchase.
+///
+/// `ownerUserRecordID` is empty until configured; an empty value never matches,
+/// so the allowlist is inert until the owner's real record ID is filled in. Read
+/// your own value from the DEBUG "Developer" row in Settings → App Info.
+enum OwnerAccess {
+ /// The owner's CloudKit user-record name. Empty = unconfigured (inert).
+ static let ownerUserRecordID = ""
+
+ static var isConfigured: Bool { !ownerUserRecordID.isEmpty }
+
+ /// The current iCloud user's record name for this app's container, or nil if
+ /// it is unavailable (not signed into iCloud, restricted, or offline before
+ /// the first fetch).
+ static func currentUserRecordName() async -> String? {
+ do {
+ return try await CKContainer.default().userRecordID().recordName
+ } catch {
+ return nil
+ }
+ }
+
+ /// True only when the allowlist is configured and the current iCloud user is
+ /// the owner.
+ static func isOwner() async -> Bool {
+ guard isConfigured else { return false }
+ return await currentUserRecordName() == ownerUserRecordID
+ }
+}