feat(appstore): script the provisioning, listing and TestFlight setup

The listing copy lives in text files rather than in a web form, so changing a description is a diff
someone can read and the store listing is reviewable next to the code it describes. Field lengths
are checked before sending, because Apple rejects an over-length field with an error that never
names the limit.

apple-provision.rb drives the Developer Portal through spaceship and is find-or-create throughout.
That matters most for the Developer ID certificate: an account may hold only a handful, they cannot
be un-revoked, and every copy of the app already signed by one stops verifying if it goes away.

Both scripts pin the App Store Connect team. This Apple ID can see more than one, and the other
belongs to somebody else entirely, so letting spaceship choose is how a listing ends up on the
wrong account.

The reviewer phone number and email are deliberately not in here. Apple requires a real number and
this repo is public.

Claude-Session: https://claude.ai/code/session_018HwEWvoE1NkkUjJCMLSnup
This commit is contained in:
pj committed 2026-08-31 17:26:14 +05:30
1 parent 92b446973f
commit 6ddb3ac43e
23 files changed
+790

No files matched your search

@@ -0,0 +1 @@
[email protected]
+1
View File
@@ -0,0 +1 @@
2026 Priyanshu Jain
@@ -0,0 +1,5 @@
Margin is an offline writing studio. Write without anything in the way, see your words set in real typography as you go, and export a print-ready PDF or an EPUB when you are ready.
This build runs in the App Store sandbox, which is new, so the things most worth trying are the ones that touch the file system: importing, exporting a PDF or EPUB, and the optional Google Drive backup. If any of those fail where they used to work, that is the bug worth reporting.
There is no account and nothing to sign up for.
+13
View File
@@ -0,0 +1,13 @@
Margin is a calm, offline writing studio. Write without anything in the way, see your words set in real typography as you go, and keep every one of them on your own machine.
WRITE
A quiet editor that stays out of the way, with your work down one side and a live page preview down the other, showing your words as they will actually appear rather than as a word processor imagines them.
PROOF
Spelling and grammar are checked as you write, using the same system engine as the rest of macOS. Your words are never sent anywhere to be checked.
PUBLISH
When you are ready, export a print-ready PDF set in real typography, with proper margins, page numbers and running heads. Or export EPUB, ready for Apple Books, Kindle, Kobo and the rest.
YOURS
No account. No sign-up. No subscription. Your work is a single file on your computer that you can copy, rename, back up, or move to another machine. Nothing is locked inside a library you cannot get out of. If you would like a backup, Margin can save one to your own Google Drive, in your account and under your control.
+1
View File
@@ -0,0 +1 @@
writing,writer,editor,text,document,offline,grammar,typography,epub,pdf,author,manuscript,draft
@@ -0,0 +1 @@
https://margin.73ai.org
+1
View File
@@ -0,0 +1 @@
Margin: The Writing App
+1
View File
@@ -0,0 +1 @@
https://margin.73ai.org/privacy
@@ -0,0 +1 @@
Write without anything in the way. Real typography, spelling and grammar on your own machine, and export to PDF or EPUB when you are ready.
@@ -0,0 +1 @@
First release.
+1
View File
@@ -0,0 +1 @@
A calm, offline writing studio
+1
View File
@@ -0,0 +1 @@
https://margin.73ai.org
+1
View File
@@ -0,0 +1 @@
PRODUCTIVITY
+1
View File
@@ -0,0 +1 @@
Priyanshu
+1
View File
@@ -0,0 +1 @@
Jain
+13
View File
@@ -0,0 +1,13 @@
Margin has no accounts, so no demo credentials are needed. Open the app and start writing.
Two entitlements may look worth questioning, so here is why each is there:
com.apple.security.network.server is for the Google Drive backup. Google's installed-app OAuth flow
redirects to a loopback listener on 127.0.0.1, which is the only flow Google still supports for a
desktop app, and the sandbox refuses to bind that socket without this entitlement. Nothing listens
on a routable interface and nothing accepts a connection from another machine.
com.apple.security.network.client is used only to reach googleapis.com for that same backup. The
backup is optional and off until the user connects their own Google account. Nothing else the app
does uses the network: writing, the page preview, spelling, grammar, and every export run entirely
on the machine.