commit 390e6a9a6184fde43c7307e8d3e02fa3211cbed3
parent 43f5bedb974a06b0e2da1f24aeaf0bea0d61403b
Author: triesap <tyson@radroots.org>
Date: Thu, 20 Aug 2026 19:31:33 +0000
privacy: declare selected local network access
- explain local-network use for trusted physical development services
- keep Bonjour discovery absent from the public application
- guard both properties in the standalone package contract
- preserve camera photo-library and Face ID privacy boundaries
Diffstat:
2 files changed, 7 insertions(+), 0 deletions(-)
diff --git a/Radroots/Info.plist b/Radroots/Info.plist
@@ -24,6 +24,8 @@
<string>Radroots uses the camera only when you choose to add a farm photo.</string>
<key>NSFaceIDUsageDescription</key>
<string>Radroots uses Face ID only to unlock the local Nostr identity or approve a post or media upload you choose to sign.</string>
+ <key>NSLocalNetworkUsageDescription</key>
+ <string>Radroots uses your local network only when you explicitly select a trusted physical-device development service.</string>
<key>UIApplicationSceneManifest</key>
<dict>
<key>UIApplicationSupportsMultipleScenes</key>
diff --git a/scripts/verify-package-contract.sh b/scripts/verify-package-contract.sh
@@ -43,6 +43,11 @@ plutil -lint "$repo_root/Radroots/Info.plist" >/dev/null
grep -Fq '<key>NSCameraUsageDescription</key>' "$repo_root/Radroots/Info.plist"
grep -Fq '<key>NSFaceIDUsageDescription</key>' "$repo_root/Radroots/Info.plist"
+grep -Fq '<key>NSLocalNetworkUsageDescription</key>' "$repo_root/Radroots/Info.plist"
+if grep -Fq '<key>NSBonjourServices</key>' "$repo_root/Radroots/Info.plist"; then
+ echo "error: physical-device development must not enable Bonjour discovery" >&2
+ exit 1
+fi
if grep -Fq '<key>NSPhotoLibraryUsageDescription</key>' "$repo_root/Radroots/Info.plist"; then
echo "error: PHPicker must not claim broad photo-library access" >&2
exit 1