Files
OSGKeyboard/project.yml
T
Zhongshu Audit 784446ea4b chore: declare ITSAppUsesNonExemptEncryption=NO for App Store upload
Apple's annual encryption self-classification questionnaire
pops up for every build that does not declare this key. All
network calls in OSGKeyboard are HTTPS (the LLM polish call
hits a user-configured OpenAI-compatible endpoint) and Apple
classifies standard HTTPS as exempt under EAR Category 5 Part
2 Note 4, so the app does not need an encryption registration.

The Info.plist properties live in project.yml (XcodeGen), which
is what xcodebuild actually consumes. The Info.plist stub on
disk is regenerated from project.yml by xcodegen and is
gitignored in spirit (it is checked in for tool compatibility
but XcodeGen treats it as the canonical source).

Verified by:
  plutil -p .derivedData/.../OSGKeyboard.app/Info.plist | grep -i encrypt
  -> "ITSAppUsesNonExemptEncryption" => 0

Refs: AUDIT_APPSTORE.md P0-4
2026-06-20 21:33:44 +08:00

256 lines
9.1 KiB
YAML
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# XcodeGen configuration for OSGKeyboard
# Run `xcodegen generate` to create OSGKeyboard.xcodeproj
# Repo only tracks project.yml; .xcodeproj is gitignored.
name: OSGKeyboard
options:
bundleIdPrefix: com.osgkeyboard
# Minimum OS: iOS 26. We dropped older iOS support so the
# legacy speech + AVAudioSession branching could be removed in
# favour of iOS 26's `SpeechAnalyzer` (always on-device) and
# `AVAudioApplication.requestRecordPermission` (iOS 17+). iPhone
# only — no Mac Catalyst, no visionOS.
deploymentTarget:
iOS: "26.0"
developmentLanguage: en
createIntermediateGroups: true
generateEmptyDirectories: true
groupSortPosition: top
settings:
base:
SWIFT_VERSION: "6.0"
IPHONEOS_DEPLOYMENT_TARGET: "26.0"
ENABLE_USER_SCRIPT_SANDBOXING: YES
SWIFT_STRICT_CONCURRENCY: complete
GENERATE_INFOPLIST_FILE: NO
ENABLE_MODULE_VERIFIER: YES
MARKETING_VERSION: "0.1.2"
CURRENT_PROJECT_VERSION: "3"
# 签名配置来自 Signing.local.xcconfiggitignored,不会被覆盖)
# 项目级签名 xcconfig,适用于所有 target
configFiles:
Debug: Signing.local.xcconfig
Release: Signing.local.xcconfig
targets:
# =========================================================
# 主 App
# =========================================================
OSGKeyboard:
type: application
platform: iOS
sources:
- path: OSGKeyboard
excludes:
- "AppIcon.icon"
- "OSGKeyboard.icon"
entitlements:
path: OSGKeyboard/OSGKeyboard.entitlements
properties:
com.apple.security.application-groups:
- group.com.osgkeyboard.shared
com.apple.security.device.audio-input: true
# Shared Keychain access group: the host app writes the LLM API
# key here in Settings; the keyboard extension reads it before
# each request. The first entry below becomes each process's
# default access group, so the Keychain helper does not need to
# specify kSecAttrAccessGroup explicitly.
keychain-access-groups:
- $(AppIdentifierPrefix)com.osgkeyboard.shared
resources:
- path: OSGKeyboard/Assets.xcassets
- path: OSGKeyboard/en.lproj
- path: OSGKeyboard/zh-Hans.lproj
- path: OSGKeyboard/Resources/Fonts/MaterialIcons-Regular.ttf
info:
path: OSGKeyboard/Info.plist
properties:
CFBundleDisplayName: OSGKeyboard
CFBundleShortVersionString: "$(MARKETING_VERSION)"
CFBundleVersion: "$(CURRENT_PROJECT_VERSION)"
LSApplicationCategoryType: public.app-category.utilities
# English is the development language; zh-Hans is the only
# translation right now. The list also tells iOS to surface
# the keyboard in the per-app language picker for both.
CFBundleDevelopmentRegion: en
CFBundleLocalizations:
- en
- zh-Hans
UILaunchScreen:
UIColorName: "BackgroundColor"
UISupportedInterfaceOrientations:
- UIInterfaceOrientationPortrait
UIApplicationSceneManifest:
UIApplicationSupportsMultipleScenes: false
NSMicrophoneUsageDescription: "OSGKeyboard uses the microphone for voice dictation and keeps a background audio session active while a voice session is running."
NSSpeechRecognitionUsageDescription: "OSGKeyboard uses on-device speech recognition to transcribe your voice. Audio is processed on your device and is not uploaded for transcription."
UIBackgroundModes:
- audio
NSAppTransportSecurity:
NSAllowsArbitraryLoads: false
CFBundleURLTypes:
- CFBundleURLName: com.osgkeyboard.ios.settings
CFBundleURLSchemes:
- osgkeyboard
# All network calls are HTTPS (NSAppTransportSecurity above);
# nothing in the app uses non-exempt encryption. Declaring
# `ITSAppUsesNonExemptEncryption: false` lets us skip the
# annual self-classification questionnaire in App Store
# Connect on every upload.
ITSAppUsesNonExemptEncryption: false
settings:
base:
PRODUCT_BUNDLE_IDENTIFIER: com.osgkeyboard.ios
TARGETED_DEVICE_FAMILY: "1"
INFOPLIST_KEY_UIApplicationSupportsIndirectInputEvents: YES
INFOPLIST_KEY_LSApplicationCategoryType: public.app-category.utilities
SUPPORTS_MACCATALYST: NO
SUPPORTS_MAC_DESIGNED_FOR_IPHONE_IPAD: NO
SUPPORTS_XR_DESIGNED_FOR_IPHONE_IPAD: NO
# Use AppIcon.appiconset only. AppIcon.icon (Icon Composer) must not
# be passed to actool alongside the asset catalog — it crashes actool.
dependencies:
- target: OSGKeyboardShared
embed: true
- target: OSGKeyboardExt
# Keyboard Extension is a plugin of the main App; embed it.
- sdk: Speech.framework
# =========================================================
# Keyboard Extension
# =========================================================
OSGKeyboardExt:
type: app-extension
platform: iOS
sources:
- path: OSGKeyboardExt
excludes:
- "en.lproj"
- "zh-Hans.lproj"
- path: OSGKeyboardExt/en.lproj/Keyboard.strings
buildPhase: resources
- path: OSGKeyboardExt/zh-Hans.lproj/Keyboard.strings
buildPhase: resources
resources:
- path: OSGKeyboardExt/PrivacyInfo.xcprivacy
settings:
base:
IPHONEOS_DEPLOYMENT_TARGET: "26.0"
entitlements:
path: OSGKeyboardExt/OSGKeyboardExt.entitlements
properties:
com.apple.security.application-groups:
- group.com.osgkeyboard.shared
# Shared with the host app so the keyboard extension can read the
# user's LLM API key. See OSGKeyboard/OSGKeyboard.entitlements
# for the full rationale.
keychain-access-groups:
- $(AppIdentifierPrefix)com.osgkeyboard.shared
info:
path: OSGKeyboardExt/Info.plist
properties:
CFBundleDisplayName: OSGKeyboard
CFBundleShortVersionString: "$(MARKETING_VERSION)"
CFBundleVersion: "$(CURRENT_PROJECT_VERSION)"
CFBundleDevelopmentRegion: en
CFBundleLocalizations:
- en
- zh-Hans
NSMicrophoneUsageDescription: "OSGKeyboard uses the microphone for voice dictation and keeps a background audio session active while a voice session is running."
NSSpeechRecognitionUsageDescription: "OSGKeyboard uses on-device speech recognition to transcribe your voice. Audio is processed on your device and is not uploaded for transcription."
NSExtension:
NSExtensionAttributes:
IsASCIICapable: false
PrefersRightToLeft: false
PrimaryLanguage: "en-US"
RequestsOpenAccess: true
NSExtensionPointIdentifier: com.apple.keyboard-service
NSExtensionPrincipalClass: $(PRODUCT_MODULE_NAME).KeyboardViewController
settings:
base:
PRODUCT_BUNDLE_IDENTIFIER: com.osgkeyboard.ios.keyboard
TARGETED_DEVICE_FAMILY: "1"
SUPPORTS_MACCATALYST: NO
SUPPORTS_MAC_DESIGNED_FOR_IPHONE_IPAD: NO
SUPPORTS_XR_DESIGNED_FOR_IPHONE_IPAD: NO
dependencies:
- target: OSGKeyboardShared
embed: false
# =========================================================
# Shared Framework (主 App 与扩展共用)
# =========================================================
OSGKeyboardShared:
type: framework
platform: iOS
sources:
- path: OSGKeyboardShared
info:
path: OSGKeyboardShared/Info.plist
settings:
base:
PRODUCT_BUNDLE_IDENTIFIER: com.osgkeyboard.ios.shared
TARGETED_DEVICE_FAMILY: "1"
DEFINES_MODULE: YES
SKIP_INSTALL: YES
BUILD_LIBRARY_FOR_DISTRIBUTION: NO
DYLIB_INSTALL_NAME_BASE: "@rpath"
APPLICATION_EXTENSION_API_ONLY: YES
ENABLE_MODULE_VERIFIER: YES
dependencies:
- sdk: Speech.framework
- sdk: AVFoundation.framework
# =========================================================
# 单元测试
# =========================================================
OSGKeyboardTests:
type: bundle.unit-test
platform: iOS
sources:
- path: OSGKeyboardTests
info:
path: OSGKeyboardTests/Info.plist
dependencies:
- target: OSGKeyboard
settings:
base:
PRODUCT_BUNDLE_IDENTIFIER: com.osgkeyboard.ios.tests
TARGETED_DEVICE_FAMILY: "1"
# =========================================================
# 键盘扩展单元测试 (TEST-4)
# =========================================================
OSGKeyboardExtTests:
type: bundle.unit-test
platform: iOS
sources:
- path: OSGKeyboardExtTests
info:
path: OSGKeyboardExtTests/Info.plist
dependencies:
- target: OSGKeyboardShared
settings:
base:
PRODUCT_BUNDLE_IDENTIFIER: com.osgkeyboard.ios.ext.tests
TARGETED_DEVICE_FAMILY: "1"
schemes:
OSGKeyboard:
build:
targets:
OSGKeyboard: all
OSGKeyboardExt: all
run:
config: Debug
test:
config: Debug
targets:
- OSGKeyboardTests
- OSGKeyboardExtTests
archive:
config: Release