fix: route APNs delivery per-token by registered environment

Issue: after defaulting APNs delivery to production (#2381), development
builds installed from Xcode stopped receiving notifications entirely:
their sandbox device tokens were sent to the production APNs endpoint,
rejected as BadDeviceToken, and dropped as dead.

Fix: the iOS shell reads the aps-environment entitlement from the
embedded provisioning profile and exposes it to the web layer as a
document-start user script (added in capacitorDidLoad, since Capacitor
replaces the userContentController after webViewConfiguration(for:)).
Token registration reports the environment to the server, which stores
it per token and groups delivery by environment for both relay and
direct APNs sends. OPENCHAMBER_APNS_ENVIRONMENT remains as an explicit
override forcing every send to one environment.

TestFlight/App Store builds and older clients without the field default
to production, preserving released behavior; the relay already accepts
env per send request.
This commit is contained in:
Bohdan Triapitsyn
2026-07-25 01:18:41 +03:00
parent fe0ef0d1da
commit 9f1bd0dfa0
9 changed files with 204 additions and 54 deletions
@@ -76,7 +76,11 @@ device token of a server sees the same badge.
Server (`apns-runtime.js`):
- `OPENCHAMBER_PUSH_RELAY_URL` (default the public relay), `OPENCHAMBER_APNS_ENVIRONMENT`
(`production` default / `sandbox` for development builds). The signing keypair is auto-generated — nothing to set.
(optional override forcing every send to `sandbox` or `production`; normally unset — each
token is delivered to the environment it registered with: the iOS shell reads the
`aps-environment` entitlement from the embedded provisioning profile and reports it at
registration, so Xcode dev builds go to sandbox and TestFlight/App Store to production).
The signing keypair is auto-generated — nothing to set.
- Direct fallback: `OPENCHAMBER_APNS_KEY_ID`, `OPENCHAMBER_APNS_TEAM_ID`, `OPENCHAMBER_APNS_P8`
(or `_P8_PATH`), `OPENCHAMBER_APNS_BUNDLE_ID`, `OPENCHAMBER_PUSH_RELAY_DISABLED=true`.