diff --git a/NucleicRemote/Shared/ApproveFromActivityIntent.swift b/NucleicRemote/Shared/ApproveFromActivityIntent.swift index ef7c62f..747baad 100644 --- a/NucleicRemote/Shared/ApproveFromActivityIntent.swift +++ b/NucleicRemote/Shared/ApproveFromActivityIntent.swift @@ -7,12 +7,18 @@ import NucleicProtocol /// "resolve from the lock screen without unlocking" path (docs/APP_INTENTS_OPPORTUNITIES ยง4.1). /// /// It lives in the **Shared** group so both the app and the widget extension can reference it in -/// `Button(intent:)`. The widget extension links no `NucleicProtocol`, so this intent carries plain -/// `String` ids and compiles its real work only into the app (`#if canImport(NucleicProtocol)`). -/// That's sound because iOS runs a widget/Live-Activity button's intent in the **app's background +/// `Button(intent:)`. It carries plain `String` ids and compiles its real work only into the app, +/// gated on `#if NUCLEIC_APP` (a custom compilation condition set on the app target only). That's +/// sound because iOS runs a widget/Live-Activity button's intent in the **app's background /// process** โ€” where `RemoteStore` owns the live E2EE channel โ€” never in the extension. The /// extension-side copy exists solely to satisfy the `Button(intent:)` type reference. /// +/// NB: the guard is `#if NUCLEIC_APP`, *not* `#if canImport(NucleicProtocol)`. `canImport` tests +/// module findability, not linkage โ€” and because the app builds `NucleicProtocol` into the shared +/// DerivedData products dir, it's findable from the widget extension too. So `canImport` is `true` +/// in the extension, which would compile this branch there and fail on the app-only `RemoteStore` +/// / `IntentError` types. `NUCLEIC_APP` tracks target membership, which is what we actually mean. +/// /// Not discoverable in Shortcuts/Spotlight: it's button-only, driven by ids embedded at render time /// (a human uses `AnswerApprovalIntent` for the spoken/Shortcuts path). struct ApproveFromActivityIntent: AppIntent {