Jul 31 - Fix primary server (jqc) login issue

This commit is contained in:
Nguyen Ngo
2026-07-31 10:38:54 -04:00
parent dac7e6c597
commit d9a6ffcca2
3 changed files with 27 additions and 5 deletions
+24 -2
View File
@@ -17,10 +17,32 @@
<array>
<string>com.jqc.sync</string>
</array>
<!-- App Transport Security.
Both real servers (jqc / jqc1) are HTTPS and need no exception at all.
This block exists ONLY so a developer can point ServerOption.primary at
a local http backend (http://127.0.0.1:5055) while working on the API.
It is deliberately scoped to loopback. The previous version of this key
was a blanket NSAllowsArbitraryLoads=true, which disables ATS for EVERY
host — it turns off certificate and TLS validation for the production
servers too, and App Store review requires a justification for it. Do
not reintroduce the blanket flag; add a specific domain here instead. -->
<key>NSAppTransportSecurity</key>
<dict>
<key>NSAllowsArbitraryLoads</key>
<true/>
<key>NSExceptionDomains</key>
<dict>
<key>127.0.0.1</key>
<dict>
<key>NSExceptionAllowsInsecureHTTPLoads</key>
<true/>
</dict>
<key>localhost</key>
<dict>
<key>NSExceptionAllowsInsecureHTTPLoads</key>
<true/>
</dict>
</dict>
</dict>
<key>UIBackgroundModes</key>
<array>