Skip to content

chore: drop unused CloudKit entitlements and browser ATS exceptions - #410

Merged
arzafran merged 3 commits into
mainfrom
chore/drop-cloudkit-entitlements
Oct 8, 2026
Merged

arzafran merged 3 commits into
mainfrom
chore/drop-cloudkit-entitlements

Conversation

@arzafran

@arzafran arzafran commented Oct 8, 2026

Copy link
Copy Markdown
Member

What this does

The app no longer asks macOS for iCloud/CloudKit access it never uses. Those entitlements were added for the mobile companion, which was removed on 2026-09-02, and they were the only reason the app needed a provisioning profile to launch. The network exceptions kept for the built-in browser go too, since the browser was removed on 2026-10-05.

Summary

  • programa.entitlements: remove com.apple.developer.icloud-services and icloud-container-identifiers. No code references CloudKit or iCloud.
  • Resources/Info.plist: remove the NSAppTransportSecurity block (NSAllowsArbitraryLoadsInWebContent and the programa-loopback.localtest.me exception). The only WKWebView left is the Mermaid renderer, which loads a local HTML string and cancels other navigations.
  • The release workflow still embeds the provisioning profile as a safety net. verify-provision-profile.sh passes with no restricted entitlements declared. Comments and the docs/release.md row now say so.
  • Kept: camera, microphone and Apple Events entitlements. Nothing in the app uses them directly, but programs run inside the terminal get their permission prompts attributed to Programa through them.

Test plan

  • CI builds the app.
  • The release run after merge passes verify-release-entitlements.sh and verify-provision-profile.sh.
  • Open the released build once and confirm it launches (AMFI kills an app at launch, not at signing, so only a real launch proves this).

@arzafran
arzafran merged commit dba9a37 into main Oct 8, 2026
10 checks passed
@arzafran
arzafran deleted the chore/drop-cloudkit-entitlements branch October 8, 2026 15:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant