That's a 401 vs 403 distinction. They know who you are, they don't know that you're authorized to do this.
That's a 401 vs 403 distinction. They know who you are, they don't know that you're authorized to do this.
Are you willing to provide signed proof that the user consented to this action? The same way you provide signed code to prove you're the one uploading the code. Presumably this would have to be via a key that you don't have access to (only the user would be able to consent to this).
Because that seems like the parallel here.
Technically, apple should be auditing your flows at that point too, to make sure there aren't any dark patterns.
But, yeah, at that point, I think you could make that argument stick.
They do not have the capability to exhaustively check all uses thereof in a way that obviates the need for a user to consent to having you monitor their pasteboard.
They could develop it, expending significant resources on an edge-case for a tiny fraction of app developers, or they could ask the user for permission because the user has the context to expect this request (or to not).
What I'm suggesting is a predicate like only allow NSPasteboard access without prompting iff the predicate passes something like let predicate = NSPredicate(format: "SELF MATCHES %@", "^/.\\?var=.$")
I don't think you know what you're talking about.