feat(appstore): script the provisioning, listing and TestFlight setup

The listing copy lives in text files rather than in a web form, so changing a description is a diff
someone can read and the store listing is reviewable next to the code it describes. Field lengths
are checked before sending, because Apple rejects an over-length field with an error that never
names the limit.

apple-provision.rb drives the Developer Portal through spaceship and is find-or-create throughout.
That matters most for the Developer ID certificate: an account may hold only a handful, they cannot
be un-revoked, and every copy of the app already signed by one stops verifying if it goes away.

Both scripts pin the App Store Connect team. This Apple ID can see more than one, and the other
belongs to somebody else entirely, so letting spaceship choose is how a listing ends up on the
wrong account.

The reviewer phone number and email are deliberately not in here. Apple requires a real number and
this repo is public.

Claude-Session: https://claude.ai/code/session_018HwEWvoE1NkkUjJCMLSnup
This commit is contained in:
pj committed 2026-08-31 17:26:14 +05:30
1 parent 92b446973f
commit 6ddb3ac43e
23 files changed
+790

No files matched your search

+13
View File
@@ -0,0 +1,13 @@
Margin has no accounts, so no demo credentials are needed. Open the app and start writing.
Two entitlements may look worth questioning, so here is why each is there:
com.apple.security.network.server is for the Google Drive backup. Google's installed-app OAuth flow
redirects to a loopback listener on 127.0.0.1, which is the only flow Google still supports for a
desktop app, and the sandbox refuses to bind that socket without this entitlement. Nothing listens
on a routable interface and nothing accepts a connection from another machine.
com.apple.security.network.client is used only to reach googleapis.com for that same backup. The
backup is optional and off until the user connects their own Google account. Nothing else the app
does uses the network: writing, the page preview, spelling, grammar, and every export run entirely
on the machine.