From 2e3565bc05e9a87f9eff87adabc1f274184938af Mon Sep 17 00:00:00 2001 From: Ziyi Zhang Date: Wed, 23 Sep 2026 15:41:05 -0400 Subject: [PATCH 1/2] fix(levelplay): recommend scoped ATS exceptions only, never NSAllowsArbitraryLoads --- .../references/ios-setup.md | 22 +++++-------------- 1 file changed, 5 insertions(+), 17 deletions(-) diff --git a/skills/levelplay-unity-integration/references/ios-setup.md b/skills/levelplay-unity-integration/references/ios-setup.md index 8bff456..50ccee2 100644 --- a/skills/levelplay-unity-integration/references/ios-setup.md +++ b/skills/levelplay-unity-integration/references/ios-setup.md @@ -290,22 +290,8 @@ LevelPlay SDK requires certain capabilities to function properly: ### App Transport Security (ATS) Configuration -To ensure ads load correctly, configure App Transport Security in your Info.plist: +App Transport Security requires encrypted, certificate-verified connections by default. Keep it on for the app as a whole and only add exceptions for the specific ad-network domains that still serve legacy cleartext creatives: -**Option 1: Allow arbitrary loads (easiest, less secure)** - -Add this to your Info.plist: -```xml -NSAppTransportSecurity - - NSAllowsArbitraryLoads - - -``` - -**Option 2: Allow specific domains (more secure)** - -If you prefer to only allow specific ad network domains: ```xml NSAppTransportSecurity @@ -318,12 +304,14 @@ If you prefer to only allow specific ad network domains: NSExceptionAllowsInsecureHTTPLoads - + ``` -**Note:** Most ad networks require HTTP access for legacy ad creatives. Without proper ATS configuration, some ads may fail to load. +**Do not set `NSAllowsArbitraryLoads` to `true`.** It turns off transport security for every connection the app makes, including its own backend and login traffic, not just ads, and App Review commonly rejects it without a justification. If the user asks for it, explain this and add scoped exceptions instead. When only in-app web content or media needs relaxed rules, prefer `NSAllowsArbitraryLoadsInWebContent` or `NSAllowsArbitraryLoadsForMedia`, which keep enforcement on for everything else. + +**Note:** Some ad networks still serve legacy creatives over HTTP. Add a scoped exception for each such network's domain; don't relax ATS globally to make those ads load. **When to configure:** Before building for iOS. This can be done in Unity's PostProcessBuild or manually in Xcode after export. From 3fbae6357e26ddf99628eb840e368c5de8f10dd4 Mon Sep 17 00:00:00 2001 From: Ziyi Zhang Date: Wed, 23 Sep 2026 17:32:59 -0400 Subject: [PATCH 2/2] fix(levelplay): recommend no ATS settings and flag the expected validation warning --- .../references/ios-setup.md | 28 ++++--------------- .../references/testing-and-validation.md | 1 + 2 files changed, 7 insertions(+), 22 deletions(-) diff --git a/skills/levelplay-unity-integration/references/ios-setup.md b/skills/levelplay-unity-integration/references/ios-setup.md index 50ccee2..ef652f3 100644 --- a/skills/levelplay-unity-integration/references/ios-setup.md +++ b/skills/levelplay-unity-integration/references/ios-setup.md @@ -290,30 +290,14 @@ LevelPlay SDK requires certain capabilities to function properly: ### App Transport Security (ATS) Configuration -App Transport Security requires encrypted, certificate-verified connections by default. Keep it on for the app as a whole and only add exceptions for the specific ad-network domains that still serve legacy cleartext creatives: +**No ATS configuration is needed. Leave App Transport Security at its iOS default.** With ATS on, the LevelPlay SDK tells the auction to return secure ads only, so ads load without any `Info.plist` changes. -```xml -NSAppTransportSecurity - - NSExceptionDomains - - ironsrc.com - - NSIncludesSubdomains - - NSExceptionAllowsInsecureHTTPLoads - - - - - -``` - -**Do not set `NSAllowsArbitraryLoads` to `true`.** It turns off transport security for every connection the app makes, including its own backend and login traffic, not just ads, and App Review commonly rejects it without a justification. If the user asks for it, explain this and add scoped exceptions instead. When only in-app web content or media needs relaxed rules, prefer `NSAllowsArbitraryLoadsInWebContent` or `NSAllowsArbitraryLoadsForMedia`, which keep enforcement on for everything else. - -**Note:** Some ad networks still serve legacy creatives over HTTP. Add a scoped exception for each such network's domain; don't relax ATS globally to make those ads load. +**Do not add ATS exceptions for ads:** +- **Never set `NSAllowsArbitraryLoads` to `true`.** It turns off transport security for every connection the app makes, including its own backend and login traffic, not just ads, and App Review commonly rejects it without a justification. If the user asks for it, explain this and leave ATS at the default. +- **Don't set `NSAllowsArbitraryLoadsInWebContent` either.** On its own it makes the SDK request insecure ads, which iOS still blocks outside web views. +- **Don't add `NSExceptionDomains` entries for ad networks.** The SDK doesn't read them. -**When to configure:** Before building for iOS. This can be done in Unity's PostProcessBuild or manually in Xcode after export. +**Expected validation warning:** LevelPlay's integration validation reports "App Transport Security settings MISSING" when these keys are absent. That warning is expected with the default configuration. Don't resolve it by adding `NSAllowsArbitraryLoads`. ### Recommended Xcode Build Settings diff --git a/skills/levelplay-unity-integration/references/testing-and-validation.md b/skills/levelplay-unity-integration/references/testing-and-validation.md index 753a9bf..b39be20 100644 --- a/skills/levelplay-unity-integration/references/testing-and-validation.md +++ b/skills/levelplay-unity-integration/references/testing-and-validation.md @@ -122,6 +122,7 @@ real ad networks on device. **Before running the Test Suite:** - **Unity Ads is pre-installed** — the Ads Mediation package includes the Unity Ads adapter by default, so you have at least one network ready without any additional setup. For ads to fill on device, verify your LevelPlay dashboard has active instances configured for your ad units. - **Enable Development Build** in **Build Profiles** (called **Build Settings** in Unity versions before Unity 6) before building to device. Without it, SDK console output won't be visible, making it very difficult to diagnose issues if something doesn't work as expected. +- **Expect an ATS warning on iOS.** Integration validation reports "App Transport Security settings MISSING" when the app uses the default ATS configuration, which is the recommended setup. Ignore it; don't add `NSAllowsArbitraryLoads` to make it go away. See [ios-setup.md](ios-setup.md#app-transport-security-ats-configuration). ## Test Suite Setup