Search results for

“sandbox”

10,540 results found

Post

Replies

Boosts

Views

Activity

Sandboxed SMAppService LaunchDaemon: supported identity and persistent storage?
Technology: Service Management (SMAppService), App Sandbox, launchd, Foundation file URLs. This is a documentation/support question based on a standalone signed probe. It is not an assertion of a confirmed Apple defect, and it is not a duplicate of the launchd enhancement FB24726121 referenced in DTS thread 844906. Request Please clarify the supported identity and persistent-storage architecture for this combination of requirements. We need a sandboxed Mac App Store app to install its bundled, sandboxed SMAppService LaunchDaemon through one in-app action and the required native approval. The LAN listener must be unprivileged and remain available after logout and at boot. On macOS 27.2 beta 1 (26B5086k), our signed app-like probe launches and accesses its private container as the default root identity. We have read DTS thread 844906’s single-process privilege-drop guidance; this request concerns the additional sandbox, storage, and distribution limits. Observations • UserNam
2
0
285
2w
Reply to AppTransaction.refresh() fails before authentication: SKInternalErrorDomain 14 on a development-installed app
You need to sign in to your Sandbox Apple Account in Settings > Developer. A Sandbox Test Account was subsequently created, but has not been signed in on the device. The user could not find the Sandbox Apple Account entry. From Sign in to your Sandbox Apple Account for a development-signed app: In iOS and iPadOS, the sandbox account appears in Settings > Developer after the first time you use the device to attempt a purchase in a development-signed app. There’s no need to sign out of the non-Sandbox Apple Account. Sign in using a Sandbox Apple Account.
Topic: App & System Services SubTopic: StoreKit Tags:
2w
Reply to Supported lifecycle and termination guarantees for an embedded macOS XPC service
[quote='847615021, Alihan1, /thread/847615, /profile/Alihan1'] Does the documented client-lifetime relationship cover client termination, including SIGKILL, during service startup before the first reply? [/quote] Yes. There’s an obvious race condition here, leaving potentially four potential outcomes: The service does not start. The service starts but doesn’t get any messages. The service starts but the connection is invalidated before it replies. (Note that this can only happen in the escaping case, see below, because messages to the service are serialised on the services queue.) The service starts and replies but the reply fails. There’s no explicit indication of this, although the service will see the connection be invalidated. [quote='847615021, Alihan1, /thread/847615, /profile/Alihan1'] Does it also cover an already running service that is blocked or stopped with SIGSTOP? [/quote] SIGSTOP isn’t part of the XPC service world and you should not be using it in this context. As to what happens if the servic
2w
Reply to Can a Mac App Store app open a bundled, signed MCPB for installation in Claude Desktop?
Would a Mac App Store application be permitted to: Apple never pre-approves apps. Sometimes it's obvious (to everyone except the developer) that a given app idea would be immediately rejected. I'm not familiar with any of these AI platforms. Can you explain more about what this thing does? It sounds like you'll need to explain that to App Review too. The .mcpb and the helper executable it contains From what I've heard, I doubt the bundled helper executable would be sandboxed. If not, then you can't include it. And even if it is sandboxed, it would still have to comply with Mac App Store guidelines. If that leads the user to a situation where the app presents its own installation, then that would be right out.
2w
Supported lifecycle and termination guarantees for an embedded macOS XPC service
We are evaluating a lifecycle architecture for a local macOS application and would appreciate guidance on supported public APIs. Proposed architecture: A normally signed, non-root host application. One embedded XPC service with exactly one intended client. No application-created subprocesses inside the service. No privileged helper, persistent LaunchAgent, exported endpoints, private APIs, or reduced system security. One bounded operation per session. Failed or interrupted operations must not automatically be retried. Initial validation would use synthetic workloads only. Our current evaluation target is macOS 15.6 on Apple silicon, using the macOS 15.5 SDK. Please identify any relevant deployment-version limitations. The XPC overview (https://developer.apple.com/documentation/xpc) describes an embedded service as tied to its client's lifetime. We also understand that xpc_connection_cancel (https://developer.apple.com/documentation/xpc/xpc_connection_cancel(_:)) is asynchronous and non-preemptive; we are not
3
0
214
2w
Can a Mac App Store app open a bundled, signed MCPB for installation in Claude Desktop?
I’m developing a sandboxed macOS application intended for distribution through the Mac App Store. The app integrates with Claude Desktop using Anthropic’s official Desktop Extension format (.mcpb). Anthropic supports installing a Desktop Extension by opening the .mcpb file, after which Claude Desktop presents its own installation and user-consent UI. I’m trying to clarify one Mac App Store distribution point before we commit to the final onboarding flow. Would a Mac App Store application be permitted to: include its own pre-signed .mcpb Desktop Extension as a resource inside the application bundle; and after an explicit user action, open that bundled resource using standard macOS APIs so that Claude Desktop presents its installation dialog? The Mac App Store application would not: silently install software; modify Claude Desktop configuration; automate Claude Desktop’s UI; download or modify executable code after App Review; bypass Claude’s installation or tool-consent prompts. The .mcpb and the help
9
0
784
2w
AppTransaction.refresh() fails before authentication: SKInternalErrorDomain 14 on a development-installed app
I need the supported way to obtain an Apple-signed AppTransaction for a development-installed iOS app without initiating an in-app purchase. DTS directed me to ask on the forums. Environment at the time of reproduction Physical iPhone 17e, iOS 27.0 (24A437). Xcode 27.0 (27A266a), macOS 27.0 (26A428). Swift / SwiftUI / StoreKit; version 0.1.0, build 1. Explicit bundle identifier registered with App Store Connect; development signing. The executable signature, embedded profile and installed executable hash were checked. Installed and launched using devicectl. Network access allowed. No StoreKit Configuration file or StoreKitTest session. No IAP products or TestFlight builds. App Store Connect version 1.0: Prepare for Submission. Observed behavior Call try await AppTransaction.shared once. It throws; no verified transaction is returned. From a separate visible button, the user explicitly calls try await AppTransaction.refresh() once. No Apple Account authentication prompt appears. The refresh fails immediately.
1
0
184
2w
Reply to CTFontManagerCreateFontRequestRunLoopSource does not receive events in macOS 27
I’m not sure why you had problems with this, but I’ve done this myself and it worked for me. Your relationship to these technologies and APIs is much different than mine. I will only ship, and recommend, those techniques that I can get to work. It took me about 2 years, 1.5 apps, significant effort, and many attempts to get a sandboxed app to talk to a sandboxed launch agent via XPC. I have utterly no idea why I couldn't get it working at first. As far as I know, I'm not doing anything differently now. There must have been some subtle difference or bug, but I don't know what. I just tried turning sandbox off on my launch agent on macOS 27 and it worked! So I guess I've continued to make subtle improvements. It will be a few days before I can test that on 13-26 and remove the XPC service. This stuff ain't rocket science. In my experience, putting satellites in orbit is much easier than this.
Topic: App & System Services SubTopic: General Tags:
2w
Reply to StoreKit 2 returns USD product metadata in TestFlight while the storefront is FRA/EUR
I’m seeing the same thing with my app in TestFlight. My sandbox account is set to Japan, and the storefront returns JPN, but the product price comes back as $4.99 in USD. When I tap Buy, Apple’s purchase sheet correctly shows ¥800. I checked the response used by my paywall, so the dollar price isn’t hardcoded. Installing a development build on the same iPhone returns the correct Japanese price through both StoreKit 1 and StoreKit 2. I’ve already tried reinstalling and signing out of Media & Purchases, but TestFlight still returns USD. I’m using Flutter’s in_app_purchase package. Have you heard anything back from Apple or found a workaround?
Topic: App & System Services SubTopic: StoreKit Tags:
2w
Reply to CTFontManagerCreateFontRequestRunLoopSource does not receive events in macOS 27
[quote='906056022, floorish, /thread/845853?answerId=906056022#906056022, /profile/floorish'] The API has been deprecated since macOS 11, not 10.6. [/quote] Indeed. Sorry for the confusion. I’ve gone back and corrected my previous post. [quote='906056022, floorish, /thread/845853?answerId=906056022#906056022, /profile/floorish'] You seem to imply that this XPC connection is not always allowed? [/quote] At a technical level, sandboxed apps are allowed to make IPC connections via an app group, regardless of whether the other end of the IPC connection is sandboxed or not. That’s what’s expected (per that doc you found) and it matches my experience. [quote='906045022, Etresoft, /thread/845853?answerId=906045022#906045022, /profile/Etresoft'] I could not get a sandboxed app to talk directly to a non-sandboxed launch agent [/quote] I’m not sure why you had problems with this, but I’ve done this myself and it worked for me. I’ve also seen other developers take advantage of it. I’m
Topic: App & System Services SubTopic: General Tags:
2w
Request a Test Notification returns 401 with an active In-App Purchase key and Apple Java Server Library
Hello Apple Developer Forums, We are unable to authorize the Production App Store Server API Request a Test Notification endpoint. Environment: Production API: Request a Test Notification Library: Apple App Store Server Library for Java 5.2.0 Client: AppStoreServerAPIClient Result: HTTP 401 Unauthorized before a testNotificationToken is returned. We have verified the following: The key is an active In-App Purchase key created in App Store Connect under Users and Access > Integrations > In-App Purchase. The production server uses the matching .p8 private key, Key ID, Issuer ID, and bundle ID. The bundle ID is com.ansio.serviceproof.ios. The server clock is NTP-synchronized. The request uses the official Apple Java Server Library rather than a manually generated JWT. We rotated the production In-App Purchase key once and received the same 401 result. The notification URL is configured for the Production environment, uses HTTPS, and is reachable. Sandbox uses an independent key and notification co
0
0
97
2w
Reply to sysextd: "no policy, cannot allow apps outside /Applications" - NEFilterDataProvider system extension on macOS 26
Adding a data point since our config is a step further than the OP's and still fails — might narrow this down. Setup: NEFilterDataProvider system extension, Developer ID Application signed, fully notarized (Accepted) and stapled, running on macOS 27.0 Golden Gate (26A428) — the public GM release, not a beta. Unlike the OP, our entitlements already use the -systemextension suffix on both sides: Container app: com.apple.developer.networking.networkextension = [content-filter-provider-systemextension], com.apple.developer.system-extension.install = true Extension: com.apple.developer.networking.networkextension = [content-filter-provider-systemextension], app-sandbox = true, application-groups set And unlike the OP's finding, our Developer Portal-issued profiles DO contain content-filter-provider-systemextension — confirmed by decoding the embedded provisioning profile directly (security cms -D) on both the container and the extension. So in our case the portal is generating the right entitlement value;
2w
Reply to CTFontManagerCreateFontRequestRunLoopSource does not receive events in macOS 27
The API has been deprecated since macOS 11, not 10.6 Sorry. I read it wrong. But that's still Big Sur. The oldest reasonable OS these days is Ventura. many users (designers) depend on this functionality What's the functionality? Why does your app need this function? How would you do whatever this functionality is on iOS? Just curious: in the proposed workaround the sandboxed app submitted to the Mac App Store would only try to create an XPC connection to a mach service with the app group identifier (user opt in). My understanding was that this is allowed, due to the app group. The app is still fully sandboxed and the user can optionally download an external Helper. Setting aside the App Review complications, that's a bit tricky. I tried to see if I could implement something like this in an app I'm developing. I could not get a sandboxed app to talk directly to a non-sandboxed launch agent, even if both were in the same app group. This was a technical limitation. If the laun
Topic: App & System Services SubTopic: General Tags:
2w
Reply to CTFontManagerCreateFontRequestRunLoopSource does not receive events in macOS 27
[quote='906035022, DTS Engineer, /thread/845853?answerId=906035022#906035022'] I was hoping to see an obvious sandbox violation [/quote] I couldn't see those either, that's why I filed a bug report. Thanks again for looking into it though! The API has been deprecated since macOS 11, not 10.6. I understand that it may be removed in the future, but: There seems to be no alternative and many users (designers) depend on this functionality. The API still works fine for non-sandboxed apps. It appears that both requesting app and the listening app need to be non-sandboxed. So this indicates it's a sandboxing issue, not an API deprecation/removal issue. I can’t offer any opinions as to what App Review will think about it. Totally understand you're not part of App Review. Just curious: in the proposed workaround the sandboxed app submitted to the Mac App Store would only try to create an XPC connection to a mach service with the app group identifier (user opt in). My unders
Topic: App & System Services SubTopic: General Tags:
2w
Sandboxed SMAppService LaunchDaemon: supported identity and persistent storage?
Technology: Service Management (SMAppService), App Sandbox, launchd, Foundation file URLs. This is a documentation/support question based on a standalone signed probe. It is not an assertion of a confirmed Apple defect, and it is not a duplicate of the launchd enhancement FB24726121 referenced in DTS thread 844906. Request Please clarify the supported identity and persistent-storage architecture for this combination of requirements. We need a sandboxed Mac App Store app to install its bundled, sandboxed SMAppService LaunchDaemon through one in-app action and the required native approval. The LAN listener must be unprivileged and remain available after logout and at boot. On macOS 27.2 beta 1 (26B5086k), our signed app-like probe launches and accesses its private container as the default root identity. We have read DTS thread 844906’s single-process privilege-drop guidance; this request concerns the additional sandbox, storage, and distribution limits. Observations • UserNam
Replies
2
Boosts
0
Views
285
Activity
2w
Reply to AppTransaction.refresh() fails before authentication: SKInternalErrorDomain 14 on a development-installed app
You need to sign in to your Sandbox Apple Account in Settings > Developer. A Sandbox Test Account was subsequently created, but has not been signed in on the device. The user could not find the Sandbox Apple Account entry. From Sign in to your Sandbox Apple Account for a development-signed app: In iOS and iPadOS, the sandbox account appears in Settings > Developer after the first time you use the device to attempt a purchase in a development-signed app. There’s no need to sign out of the non-Sandbox Apple Account. Sign in using a Sandbox Apple Account.
Topic: App & System Services SubTopic: StoreKit Tags:
Replies
Boosts
Views
Activity
2w
Reply to Supported lifecycle and termination guarantees for an embedded macOS XPC service
[quote='847615021, Alihan1, /thread/847615, /profile/Alihan1'] Does the documented client-lifetime relationship cover client termination, including SIGKILL, during service startup before the first reply? [/quote] Yes. There’s an obvious race condition here, leaving potentially four potential outcomes: The service does not start. The service starts but doesn’t get any messages. The service starts but the connection is invalidated before it replies. (Note that this can only happen in the escaping case, see below, because messages to the service are serialised on the services queue.) The service starts and replies but the reply fails. There’s no explicit indication of this, although the service will see the connection be invalidated. [quote='847615021, Alihan1, /thread/847615, /profile/Alihan1'] Does it also cover an already running service that is blocked or stopped with SIGSTOP? [/quote] SIGSTOP isn’t part of the XPC service world and you should not be using it in this context. As to what happens if the servic
Replies
Boosts
Views
Activity
2w
Reply to SecItemAdd returns OSStatus 100001 from JXA launched by a sandboxed development tool
Thank you. I confirmed that this Mac is running macOS 26.6.2 (build 25G83). This is a new Keychain integration. We have not tested it on earlier macOS versions, so we cannot confirm whether this is an OS regression. What diagnostic logs or checks would you recommend to distinguish an inherited App Sandbox restriction from MAC?
Topic: Privacy & Security SubTopic: General Tags:
Replies
Boosts
Views
Activity
2w
Reply to Can a Mac App Store app open a bundled, signed MCPB for installation in Claude Desktop?
Would a Mac App Store application be permitted to: Apple never pre-approves apps. Sometimes it's obvious (to everyone except the developer) that a given app idea would be immediately rejected. I'm not familiar with any of these AI platforms. Can you explain more about what this thing does? It sounds like you'll need to explain that to App Review too. The .mcpb and the helper executable it contains From what I've heard, I doubt the bundled helper executable would be sandboxed. If not, then you can't include it. And even if it is sandboxed, it would still have to comply with Mac App Store guidelines. If that leads the user to a situation where the app presents its own installation, then that would be right out.
Replies
Boosts
Views
Activity
2w
Supported lifecycle and termination guarantees for an embedded macOS XPC service
We are evaluating a lifecycle architecture for a local macOS application and would appreciate guidance on supported public APIs. Proposed architecture: A normally signed, non-root host application. One embedded XPC service with exactly one intended client. No application-created subprocesses inside the service. No privileged helper, persistent LaunchAgent, exported endpoints, private APIs, or reduced system security. One bounded operation per session. Failed or interrupted operations must not automatically be retried. Initial validation would use synthetic workloads only. Our current evaluation target is macOS 15.6 on Apple silicon, using the macOS 15.5 SDK. Please identify any relevant deployment-version limitations. The XPC overview (https://developer.apple.com/documentation/xpc) describes an embedded service as tied to its client's lifetime. We also understand that xpc_connection_cancel (https://developer.apple.com/documentation/xpc/xpc_connection_cancel(_:)) is asynchronous and non-preemptive; we are not
Replies
3
Boosts
0
Views
214
Activity
2w
Can a Mac App Store app open a bundled, signed MCPB for installation in Claude Desktop?
I’m developing a sandboxed macOS application intended for distribution through the Mac App Store. The app integrates with Claude Desktop using Anthropic’s official Desktop Extension format (.mcpb). Anthropic supports installing a Desktop Extension by opening the .mcpb file, after which Claude Desktop presents its own installation and user-consent UI. I’m trying to clarify one Mac App Store distribution point before we commit to the final onboarding flow. Would a Mac App Store application be permitted to: include its own pre-signed .mcpb Desktop Extension as a resource inside the application bundle; and after an explicit user action, open that bundled resource using standard macOS APIs so that Claude Desktop presents its installation dialog? The Mac App Store application would not: silently install software; modify Claude Desktop configuration; automate Claude Desktop’s UI; download or modify executable code after App Review; bypass Claude’s installation or tool-consent prompts. The .mcpb and the help
Replies
9
Boosts
0
Views
784
Activity
2w
AppTransaction.refresh() fails before authentication: SKInternalErrorDomain 14 on a development-installed app
I need the supported way to obtain an Apple-signed AppTransaction for a development-installed iOS app without initiating an in-app purchase. DTS directed me to ask on the forums. Environment at the time of reproduction Physical iPhone 17e, iOS 27.0 (24A437). Xcode 27.0 (27A266a), macOS 27.0 (26A428). Swift / SwiftUI / StoreKit; version 0.1.0, build 1. Explicit bundle identifier registered with App Store Connect; development signing. The executable signature, embedded profile and installed executable hash were checked. Installed and launched using devicectl. Network access allowed. No StoreKit Configuration file or StoreKitTest session. No IAP products or TestFlight builds. App Store Connect version 1.0: Prepare for Submission. Observed behavior Call try await AppTransaction.shared once. It throws; no verified transaction is returned. From a separate visible button, the user explicitly calls try await AppTransaction.refresh() once. No Apple Account authentication prompt appears. The refresh fails immediately.
Replies
1
Boosts
0
Views
184
Activity
2w
Reply to CTFontManagerCreateFontRequestRunLoopSource does not receive events in macOS 27
I’m not sure why you had problems with this, but I’ve done this myself and it worked for me. Your relationship to these technologies and APIs is much different than mine. I will only ship, and recommend, those techniques that I can get to work. It took me about 2 years, 1.5 apps, significant effort, and many attempts to get a sandboxed app to talk to a sandboxed launch agent via XPC. I have utterly no idea why I couldn't get it working at first. As far as I know, I'm not doing anything differently now. There must have been some subtle difference or bug, but I don't know what. I just tried turning sandbox off on my launch agent on macOS 27 and it worked! So I guess I've continued to make subtle improvements. It will be a few days before I can test that on 13-26 and remove the XPC service. This stuff ain't rocket science. In my experience, putting satellites in orbit is much easier than this.
Topic: App & System Services SubTopic: General Tags:
Replies
Boosts
Views
Activity
2w
Reply to StoreKit 2 returns USD product metadata in TestFlight while the storefront is FRA/EUR
I’m seeing the same thing with my app in TestFlight. My sandbox account is set to Japan, and the storefront returns JPN, but the product price comes back as $4.99 in USD. When I tap Buy, Apple’s purchase sheet correctly shows ¥800. I checked the response used by my paywall, so the dollar price isn’t hardcoded. Installing a development build on the same iPhone returns the correct Japanese price through both StoreKit 1 and StoreKit 2. I’ve already tried reinstalling and signing out of Media & Purchases, but TestFlight still returns USD. I’m using Flutter’s in_app_purchase package. Have you heard anything back from Apple or found a workaround?
Topic: App & System Services SubTopic: StoreKit Tags:
Replies
Boosts
Views
Activity
2w
Reply to CTFontManagerCreateFontRequestRunLoopSource does not receive events in macOS 27
[quote='906056022, floorish, /thread/845853?answerId=906056022#906056022, /profile/floorish'] The API has been deprecated since macOS 11, not 10.6. [/quote] Indeed. Sorry for the confusion. I’ve gone back and corrected my previous post. [quote='906056022, floorish, /thread/845853?answerId=906056022#906056022, /profile/floorish'] You seem to imply that this XPC connection is not always allowed? [/quote] At a technical level, sandboxed apps are allowed to make IPC connections via an app group, regardless of whether the other end of the IPC connection is sandboxed or not. That’s what’s expected (per that doc you found) and it matches my experience. [quote='906045022, Etresoft, /thread/845853?answerId=906045022#906045022, /profile/Etresoft'] I could not get a sandboxed app to talk directly to a non-sandboxed launch agent [/quote] I’m not sure why you had problems with this, but I’ve done this myself and it worked for me. I’ve also seen other developers take advantage of it. I’m
Topic: App & System Services SubTopic: General Tags:
Replies
Boosts
Views
Activity
2w
Request a Test Notification returns 401 with an active In-App Purchase key and Apple Java Server Library
Hello Apple Developer Forums, We are unable to authorize the Production App Store Server API Request a Test Notification endpoint. Environment: Production API: Request a Test Notification Library: Apple App Store Server Library for Java 5.2.0 Client: AppStoreServerAPIClient Result: HTTP 401 Unauthorized before a testNotificationToken is returned. We have verified the following: The key is an active In-App Purchase key created in App Store Connect under Users and Access > Integrations > In-App Purchase. The production server uses the matching .p8 private key, Key ID, Issuer ID, and bundle ID. The bundle ID is com.ansio.serviceproof.ios. The server clock is NTP-synchronized. The request uses the official Apple Java Server Library rather than a manually generated JWT. We rotated the production In-App Purchase key once and received the same 401 result. The notification URL is configured for the Production environment, uses HTTPS, and is reachable. Sandbox uses an independent key and notification co
Replies
0
Boosts
0
Views
97
Activity
2w
Reply to sysextd: "no policy, cannot allow apps outside /Applications" - NEFilterDataProvider system extension on macOS 26
Adding a data point since our config is a step further than the OP's and still fails — might narrow this down. Setup: NEFilterDataProvider system extension, Developer ID Application signed, fully notarized (Accepted) and stapled, running on macOS 27.0 Golden Gate (26A428) — the public GM release, not a beta. Unlike the OP, our entitlements already use the -systemextension suffix on both sides: Container app: com.apple.developer.networking.networkextension = [content-filter-provider-systemextension], com.apple.developer.system-extension.install = true Extension: com.apple.developer.networking.networkextension = [content-filter-provider-systemextension], app-sandbox = true, application-groups set And unlike the OP's finding, our Developer Portal-issued profiles DO contain content-filter-provider-systemextension — confirmed by decoding the embedded provisioning profile directly (security cms -D) on both the container and the extension. So in our case the portal is generating the right entitlement value;
Replies
Boosts
Views
Activity
2w
Reply to CTFontManagerCreateFontRequestRunLoopSource does not receive events in macOS 27
The API has been deprecated since macOS 11, not 10.6 Sorry. I read it wrong. But that's still Big Sur. The oldest reasonable OS these days is Ventura. many users (designers) depend on this functionality What's the functionality? Why does your app need this function? How would you do whatever this functionality is on iOS? Just curious: in the proposed workaround the sandboxed app submitted to the Mac App Store would only try to create an XPC connection to a mach service with the app group identifier (user opt in). My understanding was that this is allowed, due to the app group. The app is still fully sandboxed and the user can optionally download an external Helper. Setting aside the App Review complications, that's a bit tricky. I tried to see if I could implement something like this in an app I'm developing. I could not get a sandboxed app to talk directly to a non-sandboxed launch agent, even if both were in the same app group. This was a technical limitation. If the laun
Topic: App & System Services SubTopic: General Tags:
Replies
Boosts
Views
Activity
2w
Reply to CTFontManagerCreateFontRequestRunLoopSource does not receive events in macOS 27
[quote='906035022, DTS Engineer, /thread/845853?answerId=906035022#906035022'] I was hoping to see an obvious sandbox violation [/quote] I couldn't see those either, that's why I filed a bug report. Thanks again for looking into it though! The API has been deprecated since macOS 11, not 10.6. I understand that it may be removed in the future, but: There seems to be no alternative and many users (designers) depend on this functionality. The API still works fine for non-sandboxed apps. It appears that both requesting app and the listening app need to be non-sandboxed. So this indicates it's a sandboxing issue, not an API deprecation/removal issue. I can’t offer any opinions as to what App Review will think about it. Totally understand you're not part of App Review. Just curious: in the proposed workaround the sandboxed app submitted to the Mac App Store would only try to create an XPC connection to a mach service with the app group identifier (user opt in). My unders
Topic: App & System Services SubTopic: General Tags:
Replies
Boosts
Views
Activity
2w