Entitlements 的作用
Entitlements 是代码签名中的能力声明,涉及 App Groups、iCloud、推送通知、钥匙串访问组及 App Sandbox 等。文件通常使用 XML plist,但声明并不会自动赋予开发者账号相应权限。
示例:修正类型与关联域名
以下为 plist 字典内部的片段。这两处写法都会触发诊断:
<key>com.apple.security.app-sandbox</key>
<string>true</string>
<key>com.apple.developer.associated-domains</key>
<array><string>https://example.com</string></array>app-sandbox 需要布尔值;associated-domains 需要带服务前缀的域名:
<key>com.apple.security.app-sandbox</key>
<true/>
<key>com.apple.developer.associated-domains</key>
<array><string>applinks:example.com</string></array>这样能修正这两项本地检查,但不会验证域名的关联文件、账号权限或应用签名。关联域名的完整配置见 Apple 文档
在 macOS 上对照已签名应用
codesign --display --entitlements - --xml "/path/to/App.app" > app.entitlements在此打开导出的文件进行对照。Xcode 源文件中的构建变量应按项目需要保留;签名后的输出用于核对最终值。允许的能力可通过预置描述文件查看器检查。