Kuidas me Parallelsis Apple'i sisselogimise vallutasime

Kuidas me Parallelsis Apple'i sisselogimise vallutasime

Usun, et paljusid huvitab pĂ€rast WWDC 2019 Sign In with Apple (lĂŒhidalt SIWA). Selles artiklis rÀÀgin, millised konkreetsed takistused pidid meid meie litsentsiportaalis selle funktsiooni integreerimisel ootama. See artikkel pole mĂ”eldud neile, kes just alles SIWA-ga tutvuma hakkavad (neile olen lĂ”pus jaganud mitmeid tutvustavaid linke). Sellest materjalist leiavad tĂ”enĂ€oliselt paljud vastuseid kĂŒsimustele, mis vĂ”ivad tekkida Apple'i uue teenuse integreerimisel.

Apple ei luba kohandatud suunamisi

Tegelikult ei nĂ€e ma siiani sellele kĂŒsimusele vastust arendajate foorumites. Üksikasjad on sellised: kui soovite kasutada SIWA JS API-d, st mitte töötada lĂ€bi natiivse SDK, kuna see pole mingil pĂ”hjusel saadaval (ei macOS/iOS vĂ”i vanad versioonid), siis on teil vaja oma avalikku portaali, muidu ei saa. Sest WWDR-portaalis peate registreerima ja kinnitama, et olete oma domeeni omanik, ja ainult sellele domeenile saab panna Apple'i vaatepunktist lubatud suunamisi:

Kuidas me Parallelsis Apple'i sisselogimise vallutasime

Mis siis, kui on soov suunamist rakenduses kinni pĂŒĂŒda? Me lahendasime selle probleemi ÀÀrmiselt lihtsalt: lĂ”ime oma portaali loendi lubatud suunamistest oma rakenduste jaoks, mille me tellime enne SIWA autentimisse lehe kuvamist. Ja lihtsalt suuname andmed, mis on saadud Apple'ilt, portaalist rakendusse. Lihtne ja tĂ”hus.

Probleemid e-kirjadega

Vaatame, kuidas me lahendasime kasutaja e-kirja probleemid. Esiteks, pole olemas REST API-d, mis vÔimaldaks saada seda teavet tagaplaanilt - ainult klient saab neid andmeid kÀtte ja vÔib need koos autentimiskoodiga edastada.

Teiseks, kasutaja nime ja e-kirja teave edastatakse vaid ĂŒhe korra, esimesel sisselogimisel rakendusse lĂ€bi Apple'i, kus kasutaja valib oma isiklike andmete jagamise valikud.

Needless to say, these issues are not critical if a connection with the social profile has been successfully established on the portal — the user ID remains the same and is linked to the Team ID — meaning it is consistent across all applications integrated with SIWA. However, if the login was completed via Apple, and then an error occurred leading to the connection not being made on the portal, the only option is to direct the user to appleid.apple.com, sever the link with the application, and try again. Essentially, the issue is addressed by writing the relevant KB article and providing a link to it.

The next, more unpleasant issue is that Apple has introduced a new concept with proxy email. In our case, if a user has already logged into the licensing portal with their real email and chooses the option to hide their email upon their first login through Apple, a new account is created with this proxy email, which obviously doesn’t contain any licenses, leaving the end user in a difficult situation.

The solution to this problem is quite simple: since the user ID remains the same in SIWA and does not depend on the selected options/application during sign in, we allow via a special script to switch this link from Apple to another account with the real email of the user, thereby 'restoring their purchases.' After this procedure, the user starts to access the different account on the portal through SIWA and everything works correctly for them.

There is no application icon during Sign In via the web portal.

To resolve another issue, we reached out for clarification from Apple representatives, and we are sharing the knowledge we gained:

https://forums.developer.apple.com/thread/123054
Kuidas me Parallelsis Apple'i sisselogimise vallutasime

In other words, the essence is as follows: at the head of the SIWA group, only a macOS/iOS application can be placed, into which the required service IDs of the portals are added. Consequently, for the icon to appear for the main application, there must be published versions in the App Store with media that have passed Apple's review. The icon will be taken from there.

Therefore, if you only have a portal and no App Store application, there won't be a nice icon, but you can make do with the application name — in the absence of media for the main application, this information is taken from the Description of the service ID:
Kuidas me Parallelsis Apple'i sisselogimise vallutasime
Kuidas me Parallelsis Apple'i sisselogimise vallutasime

The number of elements in the SIWA group is limited to 5.

Selle probleemi jaoks ei ole hetkel muud lahendust kui kasutada mitmeid gruppe; kui sul on puudu 6 identifikaatorist: 1 peamine rakendus ja 5 sÔltuvat, siis jÀrgmise registreerimise katsel nÀed sellist teadet:

Kuidas me Parallelsis Apple'i sisselogimise vallutasime

Oleme loonud grupid meie litsentsimisportaalile ja igale rakendusele, mis selle portaaliga opereerib. Teema slotide piirangutest oleme juba teavitanud Apple'it ja ootame nende vastust.

Kasulikud lingid

KÔige kasulikum link, minu arvates, mille abil ma kogu asja tegin. Apple'i poolikult kasulik dokumentatsioon siin.

Naudi! KĂŒsimused, mĂ”tted, ideed ja ettepanekud on kommentaarides oodatud.

Allikas: habr.com

Osta usaldusvÀÀrne hostimine veebilehtede jaoks DDoS-i kaitsega, VPS VDS serverid đŸ”„ Osta usaldusvÀÀrne hostimine veebilehtede jaoks DDoS-i kaitsega, VPS VDS serverid | ProHoster