4 ms·
What was supposed to happen on January 1st: https://datatheorem.github.io/ios/ssl/2016/08/14/ats-enforced-2017/ https://datatheorem.github.io/ios/ssl/2016/08/14
by cyb3rl0l 10y ago
What was supposed to happen on January 1st: https://datatheorem.github.io/ios/ssl/2016/08/14/ats-enforced-2017/ https://datatheorem.github.io/ios/ssl/2016/08/14/ats-enforce... .
"The overall approach the App Store review team will take when it comes to ATS exemptions was summed up on the Apple developer forums:
“The goal here is to flush out those folks who, when ATS was first released, simply turned it off globally and moved on. That will no longer be allowed.”
Hence, for a given App going through the App Store review process:
* An easy policy to justify is to have NSAllowsArbitraryLoads disabled and a list of domain-specific exemptions for third-party domains the App connects to.
* A policy that will be harder to justify is to have NSAllowsArbitraryLoads enabled and a list of domain-specific “un-exemptions” for the domains you control.
* Lastly, a policy that will definitely trigger a rejection, as stated by Apple, is to have NSAllowsArbitraryLoads enabled with no additional ATS settings.
"
Since most Apps are not compliant yet, the App Store review team would have had to review every justification for every App and make a decision on whether to allow the App on the Store or not.