10 ms·
I really appreciate this link. I would have never seen this otherwise. It's kind of a disappointment for us on the enterprise side. Our main offering is an offl
by bg0 7y ago
I really appreciate this link. I would have never seen this otherwise. It's kind of a disappointment for us on the enterprise side. Our main offering is an offline app where people are disconnected from the internet for weeks and we use localStorage to validate who they are. It's a bit vague about how this affects apps that don't use safari. Nevertheless, we might have to start to really think about the user experience here now that this update is out.
- yohannparis 7y agoWebkit's website says: "[..] deleting all of a website’s script-writable storage after seven days of Safari use without user interaction on the site." It is not clear that a user coming to your website before the 7 days, even offline, is exempt of it.
- bg0 7y agoYea, we actually don't use safari at all in our app. So this might not have an effect but it's pretty vague.
- lonelappde 7y agoIf you don't use Safari you can patch webkit to change the policy, right? Change 7 to 10000000
- tssva 7y agoApple only allows apps to use their webkit implementation.
- tomnipotent 7y agoEven for other browsers. Chrome, Edge, Opera etc. on iOS all use webkit under the hood.
- chrisfinazzo 7y agoYou could...but it's a change that the Webkit project would never accept and you would be forever diddling this value every time an update came along. Sisyphus says 'Hi!'
- vbezhenar 7y agoUser not coming to website 7 days can't be invalid use-case. Losing important data simply because someone went on vacation is unacceptable.
- im3w1l 7y agoSo store this data on the server.
- tssva 7y agoThe original comment referenced an app where the users are offline for weeks at a time. Storing data on a server is not really possible in this use case.
- matsemann 7y agoBut wouldn't that make it have less privacy? Now my webapp cannot be used offline and anonymously, user has to be logged in and tracked
- im3w1l 7y agoIt doesn't change the status quo. Important data wasn't put in cookies before, and it wont be after. It was always a recipe for data loss. Server side, or if you need privacy, have the user export to / import from a local file.
- felixfbecker 7y agoThis is also about IndexedDB. Imagine native apps had all their data wiped if you don't open them (with an active internet connection) every 7 days. Not just on an iPhone, but also on macOS.
- Grimm1 7y agoThis impacts an app I've built for reading academic papers but I imagine the work around here is to write to a file periodically and then load the file in if you don't detect indexedDB having the data you think it should. Obviously this has error cases all its own and makes it more difficult to manage but it doesn't seem like Apple is killing it to me, just making us jump through hoops and add extra complexity. Don't mistake me though this seems like an anti-competitive move from them to prevent people from circumventing the app store.
- diggan 7y agoYeah, as far as I understand, cookies is the only storage method that will be left to use for long-term storage of user data. If I'm wrong, someone please correct me. Edit: getting downvoted without any reasoning provided, so I assume I'm incorrect, there are more/less ways of storing data in the future for Safari users?
- gsnedders 7y agoCookies expire in the same way.
- diggan 7y agoWith cookies you can set the expire time yourself, as a developer. And looking at the list of the original blogpost from webkit (https://webkit.org/blog/10218/full-third-party-cookie-blocking-and-more/ https://webkit.org/blog/10218/full-third-party-cookie-blocki...) it shows the following will be affected by the 7 day cap: Indexed DB, LocalStorage, Media keys, SessionStorage, Service Worker registrations Since cookies are not mentioned, I'm assuming it's NOT affected by the 7 day cap but will instead continue to work as normal (except for the fact that 3rd party cookies will stop working, which is a Good Thing)
- tyingq 7y agoIf the cookie is set by http headers, yes. If it's set with client side js, though, it's capped at 7 days (since ITP 2.1).
- diggan 7y agoInteresting, I did not know that. Thanks for clarifying!
- Dylan16807 7y agoWhat if you have a cookie set by http and try to update it with js? Will it self-destruct now?
- nradov 7y agoHave you considered porting to a native application?
- vetinari 7y agoUsers are using other than macOS/iOS devices too. Most of them are not willing to pay extra for native app that runs on only one of the platforms used.
- gridlockd 7y agoWhy would users have to pay extra? If right now you have a web app with paying users, that means you have an accounting system of paying users. You could publish a "native" app that simply serves that web app through a web view, using those same accounts.
- vetinari 7y agoThe issue is elsewhere: you need to pay your developers to develop the second app. You would most probably need to bring in one more team, for each native platform. Will you get new users from that? If yes, they will pay for that (in principle). If not, just some existing users would migrate? Then you just increased your cost without increasing your revenues. So you would need to gain enough new users to make it worthwhile. * * * In a nutshell, it is the same reason why Adobe won't port their apps to Linux. They already have all the users that need their software, and while it would be nice for some of their users to migrate, it won't bring anything to Adobe.
- gridlockd 7y agoYou don't need a dedicated developer to ship a WebView app. That's the whole selling point behind tech like Cordova. Most of your code can stay the same and most likely all of it will stay Javascript (or whatever you are transpiling to it). Again, if you are actually affected by this issue right now, you have a web app that is more or less trivially ported to a web view app. Your user don't have to migrate, they already have accounts, they just need to download the app again, this time from the App Store. > In a nutshell, it is the same reason why Adobe won't port their apps to Linux. Linux is a non-market for Adobe apps. On the other hand, if you have an offline PWA right now, you most likely already have iOS users that you would probably lose if you start confronting them with this "7 days and your data is gone" bullshit.
- roywashere 7y agoTo be honest, HTML5 LocalStorage was always different on iOS when compared to other platforms. The iOS browser localstorage is stored in /caches so it is cleaned when the device goes low on disk space. I found out the hard way, had a cordova app which ran on Android and iOS (and web) and saved an account token in LocalStorage. Some iOS users kept on getting logged out, mostly users with smaller size iPhones! Now we store the account token in iOS keyring and that works. ref: https://stackoverflow.com/questions/32927070/complete-data-loss-ionic-cordova-localstorage-and-websql-ios-8-4-1 https://stackoverflow.com/questions/32927070/complete-data-l...
- DaiPlusPlus 7y agoHow do you use the iOS Keyring from within a PWA or website in Safari?
- jeremyjh 7y agoThey already explained that they are using Cordova. This bridges native APIs to web apps. What you deploy is a native app through the app store.
- DaiPlusPlus 7y agoRight, but Cordova isn’t PWA.
- roywashere 7y agoSure! In a PWA, storing login tokens in the keyring would not be possible. So as I said, on iOS the localstorage (and cookies) would be cleared in low disk space conditions anyway. So the PWA experience was already not good!
- duxup 7y agoYeah I've got a lot of users with very shaky internet and intermittent involvement with a given application (not using it for a month, more). This presents some serious challenges / impossibilities for those user's use of a web app when they're not online. I hope they come up with some good options as this news settles. It's hard to see this as anything but even just a accidental push ('well you should always have written an app for the app store') to force folks to write a native app / participate in the app store.
- yesimahuman 7y agoIf you're using Cordova or Capacitor this is why, at Ionic, we recommend never using localStorage for storing important data. Better to use an explicit filesystem storage solution like SQLite.