Author SHA1 Message Date
buzzert 90233b6a21 Simplify TestFlight automation
TestFlight / Build and upload (push) Successful in 1m33s
2026-07-27 17:30:02 -07:00
buzzertandClaude Sonnet 5 45b09a13d3 ci: put CI keychain first in codesign search list
TestFlight / testflight (push) Successful in 1m27s
codesign resolves signing identities through the user keychain search
list (first match wins) and ignores --keychain for the lookup. This
runner hosts another project (Sybil-2) whose keychain holds the same
Apple Distribution identity, so if that keychain is locked and appears
earlier in the search list, codesign fails with errSecInternalComponent
no matter how correctly our own keychain is set up. Prepend the fresh
CI keychain to the search list for the build and always delete it
afterward, which restores the original list.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-11 13:16:41 -07:00
buzzert 1632e5fbd4 ITSexempt
TestFlight / testflight (push) Successful in 1m12s
2026-07-06 09:24:36 -07:00
buzzert 18b63cbd19 Attempt to fix stale tabs losing info 2026-07-06 09:24:36 -07:00
buzzert 4371f051aa Switch to using content blockers instead of scheme handlers 2026-07-06 09:24:36 -07:00
14 changed files with 329 additions and 387 deletions
+3 -14
View File
@@ -1,16 +1,5 @@
FASTLANE_SKIP_UPDATE_CHECK=1 ASC_KEY_ID=
FASTLANE_HIDE_CHANGELOG=1 ASC_ISSUER_ID=
FASTLANE_TEAM_ID=DQQH5H6GBD ASC_KEY=
APP_STORE_CONNECT_KEY_ID=
APP_STORE_CONNECT_ISSUER_ID=
APP_STORE_CONNECT_KEY_CONTENT=
MATCH_GIT_URL=
MATCH_PASSWORD= MATCH_PASSWORD=
MATCH_GIT_BASIC_AUTHORIZATION= MATCH_GIT_BASIC_AUTHORIZATION=
MATCH_GIT_BRANCH=master
ATTRACTOR_PROVISIONING_PROFILE_SPECIFIER=Attractor AppStore CI
ATTRACTOR_VERSION_TAG=
ATTRACTOR_BUILD_NUMBER=
+12 -22
View File
@@ -1,7 +1,6 @@
name: TestFlight name: TestFlight
on: on:
workflow_dispatch:
push: push:
tags: tags:
- "release/ios/v*" - "release/ios/v*"
@@ -9,37 +8,28 @@ on:
jobs: jobs:
testflight: testflight:
runs-on: xcode name: Build and upload
defaults: runs-on: macos-arm64
run: timeout-minutes: 90
shell: bash
steps: steps:
- name: Checkout - name: Check out the release tag
uses: actions/checkout@v4 uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Setup Ruby - name: Set up Ruby
uses: ruby/setup-ruby@v1 uses: ruby/setup-ruby@v1
with: with:
ruby-version: "3.1.7" ruby-version: "3.3.11"
bundler-cache: true bundler-cache: true
- name: Upload to TestFlight - name: Build and upload to TestFlight
env: env:
HOME: /var/lib/act_runner ASC_KEY_ID: ${{ secrets.ASC_KEY_ID }}
APP_STORE_CONNECT_KEY_ID: ${{ secrets.APP_STORE_CONNECT_KEY_ID }} ASC_ISSUER_ID: ${{ secrets.ASC_ISSUER_ID }}
APP_STORE_CONNECT_ISSUER_ID: ${{ secrets.APP_STORE_CONNECT_ISSUER_ID }} ASC_KEY: ${{ secrets.ASC_KEY }}
APP_STORE_CONNECT_KEY_CONTENT: ${{ secrets.APP_STORE_CONNECT_KEY_CONTENT }}
MATCH_PASSWORD: ${{ secrets.MATCH_PASSWORD }} MATCH_PASSWORD: ${{ secrets.MATCH_PASSWORD }}
MATCH_GIT_URL: ${{ secrets.MATCH_GIT_URL }}
MATCH_GIT_BASIC_AUTHORIZATION: ${{ secrets.MATCH_GIT_BASIC_AUTHORIZATION }} MATCH_GIT_BASIC_AUTHORIZATION: ${{ secrets.MATCH_GIT_BASIC_AUTHORIZATION }}
ATTRACTOR_VERSION_TAG: ${{ github.ref_name }} CI: "true"
FASTLANE_SKIP_UPDATE_CHECK: "1" FASTLANE_SKIP_UPDATE_CHECK: "1"
FASTLANE_HIDE_CHANGELOG: "1" FASTLANE_HIDE_CHANGELOG: "1"
FASTLANE_XCODEBUILD_SETTINGS_TIMEOUT: "120" run: bundle exec fastlane ios beta
run: |
export PATH="/Users/runner/hostedtoolcache/Ruby/3.1.7/arm64/bin:${PATH}"
ruby --version
bundle exec fastlane ios beta
+2
View File
@@ -34,6 +34,8 @@
</array> </array>
<key>CFBundleVersion</key> <key>CFBundleVersion</key>
<string>$(CURRENT_PROJECT_VERSION)</string> <string>$(CURRENT_PROJECT_VERSION)</string>
<key>ITSAppUsesNonExemptEncryption</key>
<false/>
<key>LSApplicationCategoryType</key> <key>LSApplicationCategoryType</key>
<string>public.app-category.utilities</string> <string>public.app-category.utilities</string>
<key>LSRequiresIPhoneOS</key> <key>LSRequiresIPhoneOS</key>
@@ -2,6 +2,8 @@
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0"> <plist version="1.0">
<dict> <dict>
<key>com.apple.developer.web-browser</key>
<true/>
<key>com.apple.security.app-sandbox</key> <key>com.apple.security.app-sandbox</key>
<true/> <true/>
<key>com.apple.security.network.client</key> <key>com.apple.security.network.client</key>
+10 -20
View File
@@ -19,7 +19,6 @@ class Tab: NSObject, SBRProcessBundleBridgeDelegate
public var tabInfo: TabInfo { public var tabInfo: TabInfo {
get { get {
updateMetadata()
return _tabInfo return _tabInfo
} }
} }
@@ -39,18 +38,14 @@ class Tab: NSObject, SBRProcessBundleBridgeDelegate
} }
public var policyManager: ResourcePolicyManager public var policyManager: ResourcePolicyManager
private var _tabInfo: TabInfo = TabInfo() // Persisted snapshot of visible tab metadata; do not recompute on read.
var _tabInfo: TabInfo = TabInfo()
private var loadedWebView: WKWebView? = nil private var loadedWebView: WKWebView? = nil
public var title: String? { get { tabInfo.title } } public var title: String? { get { tabInfo.title } }
public var url: URL? { public var url: URL? {
get { if let urlString = tabInfo.urlString { return URL(string: urlString) }
if let urlString = tabInfo.urlString { return nil
return URL(string: urlString)
}
return nil
}
} }
public var javaScriptEnabled: Bool = false { public var javaScriptEnabled: Bool = false {
@@ -110,6 +105,10 @@ class Tab: NSObject, SBRProcessBundleBridgeDelegate
super.init() super.init()
bridge.delegate = self bridge.delegate = self
// Initialize snapshot metadata
_tabInfo.identifier = self.identifier
if let url { _tabInfo.urlString = url.absoluteString }
} }
deinit { deinit {
@@ -117,6 +116,8 @@ class Tab: NSObject, SBRProcessBundleBridgeDelegate
} }
func beginLoadingURL(_ url: URL) { func beginLoadingURL(_ url: URL) {
// Update snapshot immediately so UI keeps URL even if process jettisons.
_tabInfo.urlString = url.absoluteString
let request = URLRequest(url: url) let request = URLRequest(url: url)
webView.load(request) webView.load(request)
} }
@@ -150,15 +151,4 @@ class Tab: NSObject, SBRProcessBundleBridgeDelegate
.assign(to: \.favicon, on: self) .assign(to: \.favicon, on: self)
} }
} }
private func updateMetadata() {
guard contentProcessTerminated == false else { return }
_tabInfo = TabInfo(
title: loadedWebView?.title,
urlString: loadedWebView?.url?.absoluteString ?? self.homeURL?.absoluteString,
faviconData: self.favicon?.pngData(),
identifier: self.identifier
)
}
} }
+15 -3
View File
@@ -49,16 +49,28 @@ class TabController
tabs.append(tab) tabs.append(tab)
} }
// Title observation // Title observation: update snapshot and notify delegate.
tab.titleObservation = tab.webView.observe(\.title, changeHandler: { [weak tab, weak self] (webView, change) in tab.titleObservation = tab.webView.observe(\.title, changeHandler: { [weak tab, weak self] (webView, change) in
if let tab = tab, let self = self, let delegate = self.controllerDelegate { guard let tab = tab else { return }
if let newTitle = webView.title, !newTitle.isEmpty {
tab._tabInfo.title = newTitle
}
if let self = self, let delegate = self.controllerDelegate {
delegate.tabController(self, didUpdateTitle: webView.title ?? "", forTab: tab) delegate.tabController(self, didUpdateTitle: webView.title ?? "", forTab: tab)
} }
}) })
// URL observation: persist the latest URL in the snapshot.
tab.urlObservation = tab.webView.observe(\.url, changeHandler: { [weak tab] (webView, change) in
guard let tab = tab else { return }
tab._tabInfo.urlString = webView.url?.absoluteString ?? tab._tabInfo.urlString
})
// Favicon Observation // Favicon Observation
tab.faviconObservation = tab.$favicon.receive(on: RunLoop.main).sink { [weak tab, weak self] val in tab.faviconObservation = tab.$favicon.receive(on: RunLoop.main).sink { [weak tab, weak self] val in
if let tab = tab, let self = self, let delegate = self.controllerDelegate { guard let tab = tab else { return }
tab._tabInfo.faviconData = val?.pngData()
if let self = self, let delegate = self.controllerDelegate {
delegate.tabController(self, didUpdateFavicon: val, forTab: tab) delegate.tabController(self, didUpdateFavicon: val, forTab: tab)
} }
} }
@@ -11,6 +11,7 @@
#import "Hacks.h" #import "Hacks.h"
#import <OSLog/OSLog.h> #import <OSLog/OSLog.h>
#import <stdatomic.h>
#import <WebKit/_WKRemoteObjectInterface.h> #import <WebKit/_WKRemoteObjectInterface.h>
#import <WebKit/_WKRemoteObjectRegistry.h> #import <WebKit/_WKRemoteObjectRegistry.h>
@@ -19,10 +20,28 @@
#import <WebKit/WKProcessPoolPrivate.h> #import <WebKit/WKProcessPoolPrivate.h>
#import <WebKit/WKWebViewPrivate.h> #import <WebKit/WKWebViewPrivate.h>
#import <WebKit/WKWebViewConfigurationPrivate.h> #import <WebKit/WKWebViewConfigurationPrivate.h>
#import <WebKit/WKContentRuleListStore.h>
#define WKUserStyleSheet id #define WKUserStyleSheet id
#define WKUserStyleSheetEncodedClassName "X1dLVXNlclN0eWxlU2hlZXQ=" #define WKUserStyleSheetEncodedClassName "X1dLVXNlclN0eWxlU2hlZXQ="
NSArray<NSString *> *CommonCDNList(void) {
static dispatch_once_t onceToken;
static NSArray<NSString *> *commonCDNList = nil;
dispatch_once(&onceToken, ^{
commonCDNList = @[
@"cdn.jsdelivr.net",
@"fsdn.net",
@"cdnjs.com",
@"osscdn.com",
@"code.jquery.com",
@"bootstrapcdn.com"
];
});
return commonCDNList;
}
@interface StyleSheet : NSObject <NSCopying> @interface StyleSheet : NSObject <NSCopying>
@property (nonatomic, readonly, copy) NSString *source; @property (nonatomic, readonly, copy) NSString *source;
@property (nonatomic, readonly, copy) NSURL *baseURL; @property (nonatomic, readonly, copy) NSURL *baseURL;
@@ -31,6 +50,9 @@
- (instancetype)initWithSource:(NSString *)source forMainFrameOnly:(BOOL)forMainFrameOnly; - (instancetype)initWithSource:(NSString *)source forMainFrameOnly:(BOOL)forMainFrameOnly;
@end @end
// Note: We no longer proxy http/https via WKURLSchemeHandler; we use
// WebKit content blocking rules instead.
@interface WKUserContentController (Private) @interface WKUserContentController (Private)
- (void)__addUserStyleSheet:(WKUserStyleSheet)userStyleSheet; - (void)__addUserStyleSheet:(WKUserStyleSheet)userStyleSheet;
- (void)__removeUserStyleSheet:(WKUserStyleSheet)userStyleSheet; - (void)__removeUserStyleSheet:(WKUserStyleSheet)userStyleSheet;
@@ -68,6 +90,13 @@
#define LOG_DEBUG(format, ...) os_log_debug(_log, format, ##__VA_ARGS__) #define LOG_DEBUG(format, ...) os_log_debug(_log, format, ##__VA_ARGS__)
#define LOG_ERROR(format, ...) os_log_error(_log, format, ##__VA_ARGS__) #define LOG_ERROR(format, ...) os_log_error(_log, format, ##__VA_ARGS__)
static os_log_t _log;
__attribute__((constructor))
static void initialize_log(void) {
_log = os_log_create("net.buzzert.attractor.webview", "bridge");
}
@interface NSURLResponse (BridgeAdditions) @interface NSURLResponse (BridgeAdditions)
@property (nonatomic, readonly) BOOL isJavascriptResponse; @property (nonatomic, readonly) BOOL isJavascriptResponse;
@end @end
@@ -91,13 +120,11 @@
@end @end
@interface SBRProcessBundleBridge () <WKURLSchemeHandler> @interface SBRProcessBundleBridge ()
@end @end
@implementation SBRProcessBundleBridge { @implementation SBRProcessBundleBridge {
os_log_t _log;
WKWebView *_webView; WKWebView *_webView;
WKWebViewConfiguration *_webViewConfiguration; WKWebViewConfiguration *_webViewConfiguration;
WKProcessPool *_processPool; WKProcessPool *_processPool;
@@ -107,17 +134,21 @@
NSArray<WKUserScript *> *_userScripts; NSArray<WKUserScript *> *_userScripts;
dispatch_queue_t _dataTasksAccessQueue;
NSMutableDictionary<NSURLRequest *, NSURLSessionDataTask *> *_dataTasks;
// These come from settings. // These come from settings.
WKUserStyleSheet _customizedUserStylesheet; WKUserStyleSheet _customizedUserStylesheet;
WKUserScript *_customizedUserScript; WKUserScript *_customizedUserScript;
// Content blocking
WKContentRuleList *_activeScriptRuleList;
void *_urlKVOContext;
} }
- (void)tearDown - (void)tearDown
{ {
// This was used to unregister the delegate with the web process. if (_webView) {
@try { [_webView removeObserver:self forKeyPath:@"URL" context:_urlKVOContext]; }
@catch (__unused NSException *ex) {}
}
} }
- (instancetype)initWithWebViewConfiguration:(WKWebViewConfiguration *)webViewConfiguration - (instancetype)initWithWebViewConfiguration:(WKWebViewConfiguration *)webViewConfiguration
@@ -125,8 +156,6 @@
self = [super init]; self = [super init];
if (self) { if (self) {
if (!webViewConfiguration) { if (!webViewConfiguration) {
_log = os_log_create("net.buzzert.attractor.webview", "bridge");
webViewConfiguration = [[WKWebViewConfiguration alloc] init]; webViewConfiguration = [[WKWebViewConfiguration alloc] init];
// Set up process pool // Set up process pool
@@ -135,12 +164,7 @@
webViewConfiguration._waitsForPaintAfterViewDidMoveToWindow = NO; webViewConfiguration._waitsForPaintAfterViewDidMoveToWindow = NO;
webViewConfiguration._applePayEnabled = YES; webViewConfiguration._applePayEnabled = YES;
// No http/https interception — rely on content blocking rules instead.
_dataTasks = [NSMutableDictionary dictionary];
_dataTasksAccessQueue = dispatch_queue_create("net.buzzert.attractor.dataTasksAccess", DISPATCH_QUEUE_SERIAL);
[webViewConfiguration setURLSchemeHandler:self forURLScheme:@"http"];
[webViewConfiguration setURLSchemeHandler:self forURLScheme:@"https"];
} }
_webViewConfiguration = webViewConfiguration; _webViewConfiguration = webViewConfiguration;
@@ -161,6 +185,11 @@
} }
_webView = webView; _webView = webView;
_urlKVOContext = &_urlKVOContext; // unique context pointer
[_webView addObserver:self forKeyPath:@"URL" options:(NSKeyValueObservingOptionNew) context:_urlKVOContext];
// Initialize content blocking rules for current host
[self rebuildContentBlockingRulesForCurrentHost];
} }
return self; return self;
@@ -223,97 +252,18 @@
}); });
} }
#pragma mark <WKURLSchemeHandler>
- (void)webView:(WKWebView *)webView startURLSchemeTask:(id<WKURLSchemeTask>)urlSchemeTask
{
NSString *hostOrigin = [[_webView URL] host];
NSURLRequest *request = [urlSchemeTask request];
LOG_DEBUG("Start URL scheme task: request: %@", request);
__weak __auto_type welf = self;
NSURLSessionDataTask *dataTask = [[NSURLSession sharedSession] dataTaskWithRequest:request completionHandler:^(NSData * _Nullable data, NSURLResponse * _Nullable response, NSError * _Nullable error)
{
if (!welf) return;
__strong __auto_type sself = welf;
if (error != nil) {
[urlSchemeTask didFailWithError:error];
} else if ([response isKindOfClass:[NSHTTPURLResponse class]]) {
NSURL *requestURL = [request URL];
NSString *resourceOrigin = [requestURL host];
const __auto_type allowResource = ^{
os_log_debug(sself->_log, "Allowing resource: %@", requestURL.lastPathComponent);
[urlSchemeTask didReceiveResponse:response];
[urlSchemeTask didReceiveData:data];
[urlSchemeTask didFinish];
[self webProcessDidAllowScriptWithOrigin:resourceOrigin];
};
const __auto_type denyResource = ^{
os_log_debug(sself->_log, "Blocking resource: %@", requestURL.lastPathComponent);
NSHTTPURLResponse *altResponse = [[NSHTTPURLResponse alloc] initWithURL:requestURL
MIMEType:@"application/javascript"
expectedContentLength:0 textEncodingName:@"utf8"];
[urlSchemeTask didReceiveResponse:altResponse];
[urlSchemeTask didReceiveData:[NSData data]];
[urlSchemeTask didFinish];
[self webProcessDidBlockScriptWithOrigin:resourceOrigin];
};
// Check MIME type for JavaScript responses.
if ([response isJavascriptResponse] && ![sself allowAllScripts]) {
dispatch_async(sself->_dataTasksAccessQueue, ^{
NSDictionary<NSString *, NSNumber *> *policyTypes = [sself->_policyDataSource scriptPolicyTypeByOrigin];
NSNumber *policyType = [policyTypes objectForKey:hostOrigin];
SBRScriptPolicy *policy = [[SBRScriptPolicy alloc] initWithSecurityOrigin:hostOrigin policyType:[policyType integerValue]];
if ([policy allowsExternalJavaScriptResourceOrigin:resourceOrigin]) {
allowResource();
} else {
denyResource();
}
});
} else {
allowResource();
}
} else {
[urlSchemeTask didFailWithError:[NSError errorWithDomain:NSURLErrorDomain code:0 userInfo:nil]];
}
[sself->_dataTasks removeObjectForKey:request];
}];
[_dataTasks setObject:dataTask forKey:request];
[dataTask resume];
}
- (void)webView:(WKWebView *)webView stopURLSchemeTask:(id<WKURLSchemeTask>)urlSchemeTask
{
NSURLRequest *request = [urlSchemeTask request];
NSURLSessionDataTask *dataTask = [_dataTasks objectForKey:request];
if (dataTask) {
if ([dataTask state] != NSURLSessionTaskStateCanceling) {
[dataTask cancel];
}
[_dataTasks removeObjectForKey:request];
}
}
#pragma mark Actions #pragma mark Actions
- (void)policyDataSourceDidChange - (void)policyDataSourceDidChange
{ {
// This was used when we had to signal the process bundle. // Rebuild content blocking rules when policy changes.
[self rebuildContentBlockingRulesForCurrentHost];
} }
- (void)setAllowAllScripts:(BOOL)allowAllScripts - (void)setAllowAllScripts:(BOOL)allowAllScripts
{ {
_allowAllScripts = allowAllScripts; _allowAllScripts = allowAllScripts;
[self rebuildContentBlockingRulesForCurrentHost];
} }
- (void)setDarkModeEnabled:(BOOL)darkModeEnabled - (void)setDarkModeEnabled:(BOOL)darkModeEnabled
@@ -360,4 +310,119 @@
}]; }];
} }
// MARK: - Content Blocking Rules
- (void)observeValueForKeyPath:(NSString *)keyPath ofObject:(id)object change:(NSDictionary<NSKeyValueChangeKey,id> *)change context:(void *)context
{
if (context == _urlKVOContext && [keyPath isEqualToString:@"URL"]) {
[self rebuildContentBlockingRulesForCurrentHost];
return;
}
[super observeValueForKeyPath:keyPath ofObject:object change:change context:context];
}
- (void)rebuildContentBlockingRulesForCurrentHost
{
NSString *hostOrigin = _webView.URL.host;
if (!hostOrigin) {
// No page loaded yet; clear any existing rules
[self applyContentRuleListJSON:nil withName:nil];
return;
}
// Determine policy for this host
NSNumber *policyType = nil;
@synchronized (_policyDataSource) {
NSDictionary<NSString *, NSNumber *> *policyTypes = [_policyDataSource scriptPolicyTypeByOrigin];
policyType = [policyTypes objectForKey:hostOrigin] ?: @(0);
}
// Alpha=0 Bravo=1 Charlie=2 Delta=3 Echo=4
SBRScriptOriginPolicyType type = [policyType integerValue];
if (_allowAllScripts || type >= SBRScriptOriginPolicyTypeEcho) {
// Echo or shields down: no blocking
[self applyContentRuleListJSON:nil withName:nil];
return;
}
// Base trigger applies only to this page's domain
NSMutableArray *rules = [NSMutableArray array];
NSDictionary *baseScriptTrigger = @{
@"resource-type" : @[ @"script" ],
@"if-domain" : @[ hostOrigin ]
};
if (type <= SBRScriptOriginPolicyTypeBravo) {
// Alpha or Bravo: block all external script subresources (inline JS is controlled via preferences elsewhere)
[rules addObject:@{ @"trigger": baseScriptTrigger, @"action": @{ @"type": @"block" } }];
} else {
// Charlie/Delta: block third-party scripts
NSMutableDictionary *trigger = [baseScriptTrigger mutableCopy];
trigger[@"load-type"] = @[ @"third-party" ];
[rules addObject:@{ @"trigger": trigger, @"action": @{ @"type": @"block" } }];
if (type >= SBRScriptOriginPolicyTypeDelta) {
// Delta: add allowlist for common CDNs
for (NSString *cdn in CommonCDNList()) {
NSString *escaped = [NSRegularExpression escapedPatternForString:cdn];
NSString *pattern = [NSString stringWithFormat:@".*://([^.]*\\.)?%@/", escaped];
[rules addObject:@{
@"trigger": @{
@"url-filter": pattern,
@"if-domain": @[ hostOrigin ],
@"resource-type": @[ @"script" ]
},
@"action": @{ @"type": @"ignore-previous-rules" }
}];
}
// Heuristic: allow cdn.<anything-with-family-name>/* where family name is the second-level label
NSArray<NSString *> *components = [hostOrigin componentsSeparatedByString:@"."];
if (components.count > 1) {
NSString *family = components[components.count - 2];
NSString *escapedFamily = [NSRegularExpression escapedPatternForString:family];
NSString *familyPattern = [NSString stringWithFormat:@".*://cdn\\.[^/]*%@[^/]*/", escapedFamily];
[rules addObject:@{
@"trigger": @{
@"url-filter": familyPattern,
@"if-domain": @[ hostOrigin ],
@"resource-type": @[ @"script" ]
},
@"action": @{ @"type": @"ignore-previous-rules" }
}];
}
}
}
NSData *jsonData = [NSJSONSerialization dataWithJSONObject:rules options:0 error:nil];
NSString *json = [[NSString alloc] initWithData:jsonData encoding:NSUTF8StringEncoding];
NSString *name = [NSString stringWithFormat:@"net.buzzert.attractor.rules.%@", hostOrigin];
[self applyContentRuleListJSON:json withName:name];
}
- (void)applyContentRuleListJSON:(NSString *)json withName:(NSString *)name
{
WKUserContentController *controller = [_webViewConfiguration userContentController];
if (_activeScriptRuleList) {
[controller removeContentRuleList:_activeScriptRuleList];
_activeScriptRuleList = nil;
}
if (!json || !name) { return; }
WKContentRuleListStore *store = [WKContentRuleListStore defaultStore];
[store compileContentRuleListForIdentifier:name encodedContentRuleList:json completionHandler:^(WKContentRuleList * _Nullable ruleList, NSError * _Nullable error) {
if (error) {
LOG_ERROR("Failed to compile content rule list: %@", error.localizedDescription);
return;
}
dispatch_async(dispatch_get_main_queue(), ^{
self->_activeScriptRuleList = ruleList;
[controller addContentRuleList:ruleList];
LOG_DEBUG("Applied content rule list: %@", name);
});
}];
}
@end @end
+1 -1
View File
@@ -1,3 +1,3 @@
source "https://rubygems.org" source "https://rubygems.org"
gem "fastlane" gem "fastlane", "2.237.0"
+75 -62
View File
@@ -1,46 +1,49 @@
GEM GEM
remote: https://rubygems.org/ remote: https://rubygems.org/
specs: specs:
CFPropertyList (3.0.9) CFPropertyList (3.0.8)
abbrev (0.1.2) abbrev (0.1.2)
addressable (2.9.0) addressable (2.9.0)
public_suffix (>= 2.0.2, < 8.0) public_suffix (>= 2.0.2, < 8.0)
artifactory (3.0.17) artifactory (3.0.17)
atomos (0.1.3) atomos (0.1.3)
aws-eventstream (1.3.2) aws-eventstream (1.4.0)
aws-partitions (1.1109.0) aws-partitions (1.1274.0)
aws-sdk-core (3.224.1) aws-sdk-core (3.254.0)
aws-eventstream (~> 1, >= 1.3.0) aws-eventstream (~> 1, >= 1.3.0)
aws-partitions (~> 1, >= 1.992.0) aws-partitions (~> 1, >= 1.992.0)
aws-sigv4 (~> 1.9) aws-sigv4 (~> 1.9)
base64 base64
bigdecimal
jmespath (~> 1, >= 1.6.1) jmespath (~> 1, >= 1.6.1)
logger logger
aws-sdk-kms (1.101.0) aws-sdk-kms (1.130.0)
aws-sdk-core (~> 3, >= 3.216.0) aws-sdk-core (~> 3, >= 3.254.0)
aws-sigv4 (~> 1.5) aws-sigv4 (~> 1.5)
aws-sdk-s3 (1.188.0) aws-sdk-s3 (1.228.1)
aws-sdk-core (~> 3, >= 3.224.1) aws-sdk-core (~> 3, >= 3.254.0)
aws-sdk-kms (~> 1) aws-sdk-kms (~> 1)
aws-sigv4 (~> 1.5) aws-sigv4 (~> 1.5)
aws-sigv4 (1.11.0) aws-sigv4 (1.12.1)
aws-eventstream (~> 1, >= 1.0.2) aws-eventstream (~> 1, >= 1.0.2)
babosa (1.0.4) babosa (1.0.4)
base64 (0.2.0) base64 (0.3.0)
benchmark (0.5.0)
bigdecimal (4.1.2)
claide (1.1.0) claide (1.1.0)
colored (1.2) colored (1.2)
colored2 (3.1.2) colored2 (3.1.2)
commander (4.6.0) commander (4.6.0)
highline (~> 2.0.0) highline (~> 2.0.0)
csv (3.3.5) csv (3.3.6)
declarative (0.0.20) declarative (0.0.20)
digest-crc (0.7.0) digest-crc (0.7.0)
rake (>= 12.0.0, < 14.0.0) rake (>= 12.0.0, < 14.0.0)
domain_name (0.5.20190701) domain_name (0.6.20240107)
unf (>= 0.0.5, < 1.0.0)
dotenv (2.8.1) dotenv (2.8.1)
emoji_regex (3.2.3) emoji_regex (3.2.3)
excon (0.109.0) excon (1.6.0)
logger
faraday (1.10.6) faraday (1.10.6)
faraday-em_http (~> 1.0) faraday-em_http (~> 1.0)
faraday-em_synchrony (~> 1.0) faraday-em_synchrony (~> 1.0)
@@ -70,42 +73,45 @@ GEM
faraday_middleware (1.2.1) faraday_middleware (1.2.1)
faraday (~> 1.0) faraday (~> 1.0)
fastimage (2.4.1) fastimage (2.4.1)
fastlane (2.230.0) fastlane (2.237.0)
CFPropertyList (>= 2.3, < 4.0.0) CFPropertyList (>= 2.3, < 5.0.0)
abbrev (~> 0.1.2) abbrev (~> 0.1)
addressable (>= 2.8, < 3.0.0) addressable (>= 2.9.0, < 3.0.0)
artifactory (~> 3.0) artifactory (~> 3.0)
aws-sdk-s3 (~> 1.0) aws-sdk-s3 (~> 1.197)
babosa (>= 1.0.3, < 2.0.0) babosa (>= 1.0.3, < 2.0.0)
base64 (~> 0.2.0) base64 (~> 0.2)
bundler (>= 1.12.0, < 3.0.0) benchmark (>= 0.1.0)
bundler (>= 2.4.0, < 5.0.0)
colored (~> 1.2) colored (~> 1.2)
commander (~> 4.6) commander (~> 4.6)
csv (~> 3.3) csv (~> 3.3)
dotenv (>= 2.1.1, < 3.0.0) dotenv (>= 2.1.1, < 3.0.0)
emoji_regex (>= 0.1, < 4.0) emoji_regex (>= 0.1, < 4.0)
excon (>= 0.71.0, < 1.0.0) excon (>= 0.71.0, < 2.0.0)
faraday (~> 1.0) faraday (~> 1.0)
faraday-cookie_jar (~> 0.0.6) faraday-cookie_jar (~> 0.0.6)
faraday_middleware (~> 1.0) faraday_middleware (~> 1.0)
fastimage (>= 2.1.0, < 3.0.0) fastimage (>= 2.1.0, < 3.0.0)
fastlane-sirp (>= 1.0.0) fastlane-sirp (>= 1.1.0)
gh_inspector (>= 1.1.2, < 2.0.0) gh_inspector (>= 1.1.2, < 2.0.0)
google-apis-androidpublisher_v3 (~> 0.3) google-apis-androidpublisher_v3 (~> 0.3)
google-apis-playcustomapp_v1 (~> 0.1) google-apis-playcustomapp_v1 (~> 0.1)
google-cloud-env (>= 1.6.0, < 2.0.0) google-cloud-env (>= 1.6.0, < 2.3.0)
google-cloud-storage (~> 1.31) google-cloud-storage (~> 1.31)
highline (~> 2.0) highline (~> 2.0)
http-cookie (~> 1.0.5) http-cookie (~> 1.0.5)
json (< 3.0.0) json (< 3.0.0)
jwt (>= 2.1.0, < 3) jwt (>= 2.10.3, < 4)
logger (>= 1.6, < 2.0) logger (>= 1.6, < 2.0)
mini_magick (>= 4.9.4, < 5.0.0) mini_magick (>= 4.9.4, < 5.0.0)
multi_json (~> 1.12)
multipart-post (>= 2.0.0, < 3.0.0) multipart-post (>= 2.0.0, < 3.0.0)
mutex_m (~> 0.3.0) mutex_m (~> 0.3)
naturally (~> 2.2) naturally (~> 2.2)
nkf (~> 0.2.0) nkf (~> 0.2)
optparse (>= 0.1.1, < 1.0.0) optparse (>= 0.1.1, < 1.0.0)
ostruct (>= 0.1.0)
plist (>= 3.1.0, < 4.0.0) plist (>= 3.1.0, < 4.0.0)
rubyzip (>= 2.0.0, < 3.0.0) rubyzip (>= 2.0.0, < 3.0.0)
security (= 0.1.5) security (= 0.1.5)
@@ -120,41 +126,46 @@ GEM
xcpretty-travis-formatter (>= 0.0.3, < 2.0.0) xcpretty-travis-formatter (>= 0.0.3, < 2.0.0)
fastlane-sirp (1.1.0) fastlane-sirp (1.1.0)
gh_inspector (1.1.3) gh_inspector (1.1.3)
google-apis-androidpublisher_v3 (0.54.0) google-apis-androidpublisher_v3 (0.106.0)
google-apis-core (>= 0.11.0, < 2.a) google-apis-core (>= 0.15.0, < 2.a)
google-apis-core (0.11.3) google-apis-core (0.18.0)
addressable (~> 2.5, >= 2.5.1) addressable (~> 2.5, >= 2.5.1)
googleauth (>= 0.16.2, < 2.a) googleauth (~> 1.9)
httpclient (>= 2.8.1, < 3.a) httpclient (>= 2.8.3, < 3.a)
mini_mime (~> 1.0) mini_mime (~> 1.0)
mutex_m
representable (~> 3.0) representable (~> 3.0)
retriable (>= 2.0, < 4.a) retriable (>= 2.0, < 4.a)
rexml google-apis-iamcredentials_v1 (0.28.0)
google-apis-iamcredentials_v1 (0.17.0) google-apis-core (>= 0.15.0, < 2.a)
google-apis-core (>= 0.11.0, < 2.a) google-apis-playcustomapp_v1 (0.18.0)
google-apis-playcustomapp_v1 (0.13.0) google-apis-core (>= 0.15.0, < 2.a)
google-apis-core (>= 0.11.0, < 2.a) google-apis-storage_v1 (0.65.0)
google-apis-storage_v1 (0.29.0) google-apis-core (>= 0.15.0, < 2.a)
google-apis-core (>= 0.11.0, < 2.a) google-cloud-core (1.9.0)
google-cloud-core (1.6.1)
google-cloud-env (>= 1.0, < 3.a) google-cloud-env (>= 1.0, < 3.a)
google-cloud-errors (~> 1.0) google-cloud-errors (~> 1.0)
google-cloud-env (1.6.0) google-cloud-env (2.2.2)
faraday (>= 0.17.3, < 3.0) base64 (~> 0.2)
google-cloud-errors (1.3.1) faraday (>= 1.0, < 3.a)
google-cloud-storage (1.45.0) google-cloud-errors (1.7.0)
google-cloud-storage (1.62.0)
addressable (~> 2.8) addressable (~> 2.8)
digest-crc (~> 0.4) digest-crc (~> 0.4)
google-apis-iamcredentials_v1 (~> 0.1) google-apis-core (>= 0.18, < 2)
google-apis-storage_v1 (~> 0.29.0) google-apis-iamcredentials_v1 (~> 0.18)
google-apis-storage_v1 (>= 0.42)
google-cloud-core (~> 1.6) google-cloud-core (~> 1.6)
googleauth (>= 0.16.2, < 2.a) googleauth (~> 1.9)
mini_mime (~> 1.0) mini_mime (~> 1.0)
googleauth (1.8.1) google-logging-utils (0.2.0)
faraday (>= 0.17.3, < 3.a) googleauth (1.17.2)
jwt (>= 1.4, < 3.0) faraday (>= 1.0, < 3.a)
multi_json (~> 1.11) google-cloud-env (~> 2.2)
google-logging-utils (~> 0.1)
jwt (>= 1.4, < 4.0)
os (>= 0.9, < 2.0) os (>= 0.9, < 2.0)
pstore (~> 0.1)
signet (>= 0.16, < 2.a) signet (>= 0.16, < 2.a)
highline (2.0.3) highline (2.0.3)
http-cookie (1.0.8) http-cookie (1.0.8)
@@ -162,22 +173,24 @@ GEM
httpclient (2.9.0) httpclient (2.9.0)
mutex_m mutex_m
jmespath (1.6.2) jmespath (1.6.2)
json (2.7.6) json (2.21.1)
jwt (2.10.3) jwt (3.2.0)
base64 base64
logger (1.7.0) logger (1.7.0)
mini_magick (4.13.2) mini_magick (4.13.2)
mini_mime (1.1.5) mini_mime (1.1.5)
multi_json (1.15.0) multi_json (1.21.1)
multipart-post (2.4.1) multipart-post (2.4.1)
mutex_m (0.3.0) mutex_m (0.3.0)
nanaimo (0.4.0) nanaimo (0.4.0)
naturally (2.3.0) naturally (2.3.0)
nkf (0.2.0) nkf (0.3.0)
optparse (0.8.1) optparse (0.8.1)
os (1.1.4) os (1.1.4)
ostruct (0.6.3)
plist (3.7.2) plist (3.7.2)
public_suffix (5.1.1) pstore (0.2.1)
public_suffix (7.0.5)
rake (13.4.2) rake (13.4.2)
representable (3.2.0) representable (3.2.0)
declarative (< 0.1.0) declarative (< 0.1.0)
@@ -189,11 +202,10 @@ GEM
ruby2_keywords (0.0.5) ruby2_keywords (0.0.5)
rubyzip (2.4.1) rubyzip (2.4.1)
security (0.1.5) security (0.1.5)
signet (0.18.0) signet (0.22.0)
addressable (~> 2.8) addressable (~> 2.8)
faraday (>= 0.17.5, < 3.a) faraday (>= 0.17.5, < 3.a)
jwt (>= 1.5, < 3.0) jwt (>= 1.5, < 4.0)
multi_json (~> 1.10)
simctl (1.6.10) simctl (1.6.10)
CFPropertyList CFPropertyList
naturally naturally
@@ -206,15 +218,16 @@ GEM
tty-spinner (0.9.3) tty-spinner (0.9.3)
tty-cursor (~> 0.7) tty-cursor (~> 0.7)
uber (0.1.0) uber (0.1.0)
unf (0.2.0)
unicode-display_width (2.6.0) unicode-display_width (2.6.0)
word_wrap (1.0.0) word_wrap (1.0.0)
xcodeproj (1.27.0) xcodeproj (1.28.1)
CFPropertyList (>= 2.3.3, < 4.0) CFPropertyList (>= 2.3.3, < 4.0)
atomos (~> 0.1.3) atomos (~> 0.1.3)
base64
claide (>= 1.0.2, < 2.0) claide (>= 1.0.2, < 2.0)
colored2 (~> 3.1) colored2 (~> 3.1)
nanaimo (~> 0.4.0) nanaimo (~> 0.4.0)
nkf
rexml (>= 3.3.6, < 4.0) rexml (>= 3.3.6, < 4.0)
xcpretty (0.4.1) xcpretty (0.4.1)
rouge (~> 3.28.0) rouge (~> 3.28.0)
@@ -225,7 +238,7 @@ PLATFORMS
ruby ruby
DEPENDENCIES DEPENDENCIES
fastlane fastlane (= 2.237.0)
BUNDLED WITH BUNDLED WITH
2.5.23 2.5.23
+2 -2
View File
@@ -30,6 +30,6 @@ Attractor operates in five "security modes":
TestFlight deployment is handled by Fastlane and the Gitea workflow at `.gitea/workflows/testflight.yml`. TestFlight deployment is handled by Fastlane and the Gitea workflow at `.gitea/workflows/testflight.yml`.
Required Gitea secrets match the local `.env.example`: `APP_STORE_CONNECT_KEY_ID`, `APP_STORE_CONNECT_ISSUER_ID`, `APP_STORE_CONNECT_KEY_CONTENT`, `MATCH_GIT_URL`, `MATCH_PASSWORD`, and `MATCH_GIT_BASIC_AUTHORIZATION`. Required Gitea secrets match the local `.env.example`: `ASC_KEY_ID`, `ASC_ISSUER_ID`, `ASC_KEY`, `MATCH_PASSWORD`, and `MATCH_GIT_BASIC_AUTHORIZATION`.
Push a tag like `release/ios/v4.2` or `Attractor-4.2` to build and upload to TestFlight. To prepare signing assets locally, run `bundle exec fastlane ios setup_signing`; to upload manually, run `bundle exec fastlane ios beta`. Push a tag like `release/ios/v4.2` or `Attractor-4.2` to build and upload to TestFlight.
+8 -8
View File
@@ -790,7 +790,7 @@
CODE_SIGN_ENTITLEMENTS = "App/Supporting Files/SBrowser.entitlements"; CODE_SIGN_ENTITLEMENTS = "App/Supporting Files/SBrowser.entitlements";
CODE_SIGN_IDENTITY = "Apple Development"; CODE_SIGN_IDENTITY = "Apple Development";
CODE_SIGN_STYLE = Automatic; CODE_SIGN_STYLE = Automatic;
CURRENT_PROJECT_VERSION = 5; CURRENT_PROJECT_VERSION = 6;
DEAD_CODE_STRIPPING = YES; DEAD_CODE_STRIPPING = YES;
DEVELOPMENT_TEAM = 3SJALV9BQ7; DEVELOPMENT_TEAM = 3SJALV9BQ7;
INFOPLIST_FILE = "App/Supporting Files/Info.plist"; INFOPLIST_FILE = "App/Supporting Files/Info.plist";
@@ -801,7 +801,7 @@
"$(inherited)", "$(inherited)",
"@executable_path/Frameworks", "@executable_path/Frameworks",
); );
MARKETING_VERSION = 4.0; MARKETING_VERSION = 4.1;
PRODUCT_BUNDLE_IDENTIFIER = net.buzzert.attractor; PRODUCT_BUNDLE_IDENTIFIER = net.buzzert.attractor;
PRODUCT_NAME = Attractor; PRODUCT_NAME = Attractor;
PROVISIONING_PROFILE_SPECIFIER = ""; PROVISIONING_PROFILE_SPECIFIER = "";
@@ -823,11 +823,11 @@
ASSETCATALOG_COMPILER_GLOBAL_ACCENT_COLOR_NAME = AccentColor; ASSETCATALOG_COMPILER_GLOBAL_ACCENT_COLOR_NAME = AccentColor;
CLANG_ENABLE_MODULES = YES; CLANG_ENABLE_MODULES = YES;
CODE_SIGN_ENTITLEMENTS = "App/Supporting Files/SBrowser.entitlements"; CODE_SIGN_ENTITLEMENTS = "App/Supporting Files/SBrowser.entitlements";
CODE_SIGN_IDENTITY = "Apple Development"; CODE_SIGN_IDENTITY = "Apple Distribution";
CODE_SIGN_STYLE = Automatic; CODE_SIGN_STYLE = Manual;
CURRENT_PROJECT_VERSION = 5; CURRENT_PROJECT_VERSION = 6;
DEAD_CODE_STRIPPING = YES; DEAD_CODE_STRIPPING = YES;
DEVELOPMENT_TEAM = 3SJALV9BQ7; DEVELOPMENT_TEAM = DQQH5H6GBD;
INFOPLIST_FILE = "App/Supporting Files/Info.plist"; INFOPLIST_FILE = "App/Supporting Files/Info.plist";
INFOPLIST_KEY_CFBundleDisplayName = Attractor; INFOPLIST_KEY_CFBundleDisplayName = Attractor;
INFOPLIST_KEY_LSApplicationCategoryType = "public.app-category.utilities"; INFOPLIST_KEY_LSApplicationCategoryType = "public.app-category.utilities";
@@ -836,10 +836,10 @@
"$(inherited)", "$(inherited)",
"@executable_path/Frameworks", "@executable_path/Frameworks",
); );
MARKETING_VERSION = 4.0; MARKETING_VERSION = 4.1;
PRODUCT_BUNDLE_IDENTIFIER = net.buzzert.attractor; PRODUCT_BUNDLE_IDENTIFIER = net.buzzert.attractor;
PRODUCT_NAME = Attractor; PRODUCT_NAME = Attractor;
PROVISIONING_PROFILE_SPECIFIER = ""; PROVISIONING_PROFILE_SPECIFIER = "Attractor AppStore CI";
SUPPORTED_PLATFORMS = "iphoneos iphonesimulator"; SUPPORTED_PLATFORMS = "iphoneos iphonesimulator";
SUPPORTS_MACCATALYST = YES; SUPPORTS_MACCATALYST = YES;
SUPPORTS_MAC_DESIGNED_FOR_IPHONE_IPAD = NO; SUPPORTS_MAC_DESIGNED_FOR_IPHONE_IPAD = NO;
+2
View File
@@ -0,0 +1,2 @@
app_identifier("net.buzzert.attractor")
team_id("DQQH5H6GBD")
+28 -158
View File
@@ -1,170 +1,40 @@
require "shellwords"
require "xcodeproj"
default_platform(:ios) default_platform(:ios)
APP_IDENTIFIER = "net.buzzert.attractor"
SCHEME = "Attractor"
TARGET_NAME = "App"
TEAM_ID = ENV["FASTLANE_TEAM_ID"].to_s.strip.empty? ? "DQQH5H6GBD" : ENV["FASTLANE_TEAM_ID"]
PROFILE_NAME = ENV["ATTRACTOR_PROVISIONING_PROFILE_SPECIFIER"].to_s.strip.empty? ? "Attractor AppStore CI" : ENV["ATTRACTOR_PROVISIONING_PROFILE_SPECIFIER"]
CI_KEYCHAIN_NAME = "attractor_ci_keychain"
CI_KEYCHAIN_PASSWORD = "attractor-ci-keychain-password"
CI_KEYCHAIN_DB_PATH = File.expand_path("~/Library/Keychains/#{CI_KEYCHAIN_NAME}-db")
PROJECT_FILE = File.expand_path("../SBrowser.xcodeproj", __dir__)
def present?(value)
!value.to_s.strip.empty?
end
def ci?
present?(ENV["CI"])
end
def version_from_tag(tag)
patterns = [
%r{\Arelease/ios/v(\d+(?:\.\d+){1,2})\z},
%r{\AAttractor-(\d+(?:\.\d+){1,2})\z},
%r{\Av(\d+(?:\.\d+){1,2})\z}
]
patterns.each do |pattern|
match = tag.to_s.match(pattern)
return match[1] if match
end
nil
end
def release_version
candidates = [
ENV["ATTRACTOR_VERSION_TAG"],
ENV["GITHUB_REF_NAME"],
ENV["GITHUB_REF"].to_s.sub(%r{\Arefs/tags/}, "")
]
candidates.each do |tag|
version = version_from_tag(tag)
return version if version
end
latest_tag = sh("git describe --tags --abbrev=0").strip
version = version_from_tag(latest_tag)
return version if version
candidates << latest_tag
UI.user_error!("Release tag must look like release/ios/v4.1, Attractor-4.1, or v4.1; got #{candidates.compact.inspect}")
end
# App Store Connect requires CFBundleVersion to be unique and strictly
# increasing app-wide. Attractor already has historical builds, so use a UTC
# timestamp by default instead of assuming a fresh CI run number is high enough.
def build_number
value = ENV["ATTRACTOR_BUILD_NUMBER"]
value = Time.now.utc.strftime("%Y%m%d%H%M%S") unless present?(value)
unless value.to_s.match?(/\A\d+\z/)
UI.user_error!("Build number must be numeric; got #{value.inspect}")
end
value.to_s
end
def stamp_project_versions(version:, build:)
project = Xcodeproj::Project.open(PROJECT_FILE)
target = project.targets.find { |candidate| candidate.name == TARGET_NAME }
UI.user_error!("Could not find target #{TARGET_NAME.inspect} in #{PROJECT_FILE}") unless target
target.build_configurations.each do |configuration|
configuration.build_settings["MARKETING_VERSION"] = version
configuration.build_settings["CURRENT_PROJECT_VERSION"] = build
end
project.save
end
platform :ios do platform :ios do
private_lane :app_store_api_key do desc "Build a release tag and upload it to TestFlight"
app_store_connect_api_key( lane :beta do
key_id: ENV.fetch("APP_STORE_CONNECT_KEY_ID"), setup_ci
issuer_id: ENV.fetch("APP_STORE_CONNECT_ISSUER_ID"),
key_content: ENV.fetch("APP_STORE_CONNECT_KEY_CONTENT"), match(type: "appstore")
tag = ENV.fetch("GITHUB_REF_NAME")
version = tag[%r{\A(?:release/ios/v|Attractor-)(\d+(?:\.\d+){1,2})\z}, 1]
UI.user_error!("Expected a tag like release/ios/v4.2 or Attractor-4.2; got #{tag.inspect}") unless version
build_number = ENV.fetch("GITHUB_RUN_NUMBER")
UI.user_error!("GITHUB_RUN_NUMBER must be a positive integer") unless build_number.match?(/\A[1-9]\d*\z/)
update_info_plist(
plist_path: "App/Supporting Files/Info.plist",
block: proc do |plist|
plist["CFBundleShortVersionString"] = version
plist["CFBundleVersion"] = build_number
end
)
api_key = app_store_connect_api_key(
key_id: ENV.fetch("ASC_KEY_ID"),
issuer_id: ENV.fetch("ASC_ISSUER_ID"),
key_content: ENV.fetch("ASC_KEY"),
is_key_content_base64: true is_key_content_base64: true
) )
end
private_lane :prepare_ci_keychain do build_app(scheme: "Attractor")
next unless ci?
delete_keychain(name: CI_KEYCHAIN_NAME) if File.file?(CI_KEYCHAIN_DB_PATH)
create_keychain(
name: CI_KEYCHAIN_NAME,
password: CI_KEYCHAIN_PASSWORD,
unlock: true,
timeout: 3600,
add_to_search_list: true
)
ENV["MATCH_KEYCHAIN_NAME"] = CI_KEYCHAIN_NAME
ENV["MATCH_KEYCHAIN_PASSWORD"] = CI_KEYCHAIN_PASSWORD
end
private_lane :sync_signing do |options|
match(
type: "appstore",
readonly: options.fetch(:readonly),
app_identifier: APP_IDENTIFIER,
team_id: TEAM_ID,
profile_name: PROFILE_NAME,
git_url: ENV.fetch("MATCH_GIT_URL"),
git_branch: ENV.fetch("MATCH_GIT_BRANCH", "master"),
git_full_name: "Attractor Release Bot",
git_user_email: "james.magahern@me.com",
api_key: options.fetch(:api_key)
)
end
desc "Create or update match signing assets"
lane :setup_signing do
sync_signing(api_key: app_store_api_key, readonly: false)
end
desc "Build and upload to TestFlight"
lane :beta do
prepare_ci_keychain
api_key = app_store_api_key
version = release_version
build = build_number
stamp_project_versions(version: version, build: build)
sync_signing(api_key: api_key, readonly: true)
build_app(
project: PROJECT_FILE,
scheme: SCHEME,
destination: "generic/platform=iOS",
export_method: "app-store",
codesigning_identity: "Apple Distribution",
xcargs: [
"DEVELOPMENT_TEAM=#{TEAM_ID.shellescape}",
"CODE_SIGN_STYLE=Manual",
"CODE_SIGN_IDENTITY=Apple\\ Distribution",
"PROVISIONING_PROFILE_SPECIFIER=#{PROFILE_NAME.shellescape}"
].join(" "),
export_options: {
signingStyle: "manual",
teamID: TEAM_ID,
provisioningProfiles: {
APP_IDENTIFIER => PROFILE_NAME
}
}
)
upload_to_testflight( upload_to_testflight(
api_key: api_key, api_key: api_key,
skip_waiting_for_build_processing: true skip_waiting_for_build_processing: true,
uses_non_exempt_encryption: false
) )
end end
end end
+7
View File
@@ -0,0 +1,7 @@
git_url("https://code.buzzert.dev/buzzert/fastlane-match.git")
storage_mode("git")
type("appstore")
app_identifier(["net.buzzert.attractor"])
team_id("DQQH5H6GBD")
profile_name("Attractor AppStore CI")