[lcfeaturecontrol-review-fixes] Fix JWT log leak, drop macOS/tvOS, coalesce requests

- FeatureControlManager/NotificationsClient: pass debug: false at every
  api.request(...) call site — the API default (debug: true) was printing
  Authorization: Bearer <jwt> on every request, release builds included.
- Package.swift: drop macOS/tvOS from platforms — LCEssentials.API (used by
  LCFeatureControl) is iOS/watchOS-only and the vendored xcframework has no
  macOS/tvOS slice.
- FeatureControlManager: coalesce concurrent evaluate() calls on a cold cache
  into a single in-flight request per key instead of firing one per caller.
- FeatureControlManager/NotificationsClient: treat a 200 response carrying
  {"error": true} as a failure instead of caching/returning it as success.
- FeatureControlNotificationsClient: thread a cursor param through list() so
  the already-decoded nextCursor can actually be used to page.
- Tests: 9 new tests (coalescing, envelope-error-on-200, cursor param, a real
  object payload decoded through a full evaluate response, date-decode
  failures) and removed the 7 remaining force-unwraps in test scaffolding.
- Documentation/FeatureControl.md: new guide for the LCFeatureControl product,
  cross-linked from README.md and Extensions.md.
This commit is contained in:
Daniel Arantes Loverde
2026-09-16 13:21:10 -03:00
parent 2ba487a6e8
commit c6e9803c75
12 changed files with 392 additions and 69 deletions

View File

@@ -3,18 +3,19 @@ import PackageDescription
// LCECryptoKit ships as a prebuilt .xcframework (`Frameworks/LCECryptoKit.xcframework`)
// vendored locally in this repo, no remote package dependency. iOS device + simulator slices
// only; consumers who need macOS/tvOS/watchOS simply don't link the `LCECryptoKit` product.
// only.
//
// Sub-SPM rule: `LCEssentials` installs standalone (no sub required). Every sub
// (`LCECryptoKit` here) target-depends on `LCEssentials`, so linking the sub's product always
// pulls `LCEssentials` in too a consumer never has to declare it separately.
// (`LCECryptoKit`, `LCFeatureControl`) target-depends on `LCEssentials`, so linking the sub's
// product always pulls `LCEssentials` in too a consumer never has to declare it separately.
//
// Platforms are iOS + watchOS only: `LCEssentials.API` (used by `LCFeatureControl`) is
// `#if os(iOS) || os(watchOS)`, and the vendored xcframework has no macOS/tvOS slice.
let package = Package(
name: "LCEssentials",
platforms: [
.iOS(.v15),
.macOS(.v10_15),
.tvOS(.v13),
.watchOS(.v8)
],
products: [