aboutsummaryrefslogtreecommitdiff
path: root/DomainDig/OwnerAccess.swift
blob: be39a6c0de1bf34df24923c4cdfe1ff7cd4ffed7 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
import CloudKit

/// Owner-only entitlement support. The app owner is identified by their CloudKit
/// user-record ID — a stable, opaque per-Apple-ID value for this app's container
/// that other users cannot guess or spoof — so a release build can grant the
/// owner Pro+ without a purchase.
///
/// `ownerUserRecordID` is empty until configured; an empty value never matches,
/// so the allowlist is inert until the owner's real record ID is filled in. Read
/// your own value from the DEBUG "Developer" row in Settings → App Info.
enum OwnerAccess {
    /// The owner's CloudKit user-record name. Empty = unconfigured (inert).
    static let ownerUserRecordID = ""

    static var isConfigured: Bool { !ownerUserRecordID.isEmpty }

    /// The current iCloud user's record name for this app's container, or nil if
    /// it is unavailable (not signed into iCloud, restricted, or offline before
    /// the first fetch).
    static func currentUserRecordName() async -> String? {
        do {
            return try await CKContainer.default().userRecordID().recordName
        } catch {
            return nil
        }
    }

    /// True only when the allowlist is configured and the current iCloud user is
    /// the owner.
    static func isOwner() async -> Bool {
        guard isConfigured else { return false }
        return await currentUserRecordName() == ownerUserRecordID
    }
}