4 ms·
They allow Wechat and Alipay to pull in code after publishing (See Mini-Apps). Regardless there's no evidence that Safari would do a better job at protecting u
by mtomweb 4y ago
They allow Wechat and Alipay to pull in code after publishing (See Mini-Apps). Regardless there's no evidence that Safari would do a better job at protecting user's security than Firefox or Chrome/Edge.
- judge2020 4y agoBased on this video[0], it looks like "mini-apps" are just webviews, as everything is either .js, .css, or .wxml (html). Thus, anything that integrates with WeChat or system APIs is going through some API within the wechat binary itself which allows Apple's static analysis to inspect the API usage during App Store review. 0: https://youtu.be/cOm9XKga7l0 https://youtu.be/cOm9XKga7l0
- mtomweb 4y agoIsh. There's bridges to native functions and there are a lot of functions. For example you can write a mini-app that connects to bluetooth. It's essentially loading dynamic code that bridges to native code.
- paulmd 4y agoSo your point is... that bluetooth is accessible via browser api? Yes, that's true, Bluefy is a whole browser built around that API, for example. https://developer.mozilla.org/en-US/docs/Web/API/Web_Bluetooth_API https://developer.mozilla.org/en-US/docs/Web/API/Web_Bluetoo... https://apps.apple.com/us/app/bluefy-web-ble-browser/id1492822055 https://apps.apple.com/us/app/bluefy-web-ble-browser/id14928... So what? Apple has never required review of every web page you load with safari, regardless of which browser APIs they use... the browser is the browser. That is the farthest Apple goes on "dynamic content" but yes, it is potentially a pretty wide net given the various APIs and extensions. But from Apple's perspective it is also a defined boundary.
- mtomweb 4y agoExpressly forbidden: - install, or execute code which introduces or changes features or functionality of the app The only exception they've crafted is for educational purposes. 2.5.2 Apps should be self-contained in their bundles, and may not read or write data outside the designated container area, nor may they download, install, or execute code which introduces or changes features or functionality of the app, including other apps. Educational apps designed to teach, develop, or allow students to test executable code may, in limited circumstances, download code provided that such code is not used for other purposes. Such apps must make the source code provided by the app completely viewable and editable by the user.