Review each extension separately

A share extension, notification service extension, and widget have different data needs. For each one, list its App Group access, keychain group, network calls, and visible content. Test on a locked phone and after account switch. A widget that caches a balance can show a previous customer’s data even if the main app has signed out. Keep shared storage narrow and clear it when account ownership changes.

Switch accounts while extensions stay installed

Give account A a fake balance marker and account B a different one. Open the widget, notification extension, and share extension as supported. Switch the main app to B and inspect each extension again, including on a locked screen. Search shared App Group storage for A’s marker and any token. An extension should receive only the data it needs. A clean main-app view does not prove the extension cleared its earlier cache.

Test cases and proof

Use test accounts and test data
CaseExpected resultProof to keep
Notification extension opens shared storeOnly needed fields appearContainer inventory
User switches accountClear prior account dataExtension view
Share input includes private fileValidate before uploadServer request

Check the shared container boundary

Create a test share extension that receives a fake receipt. Inspect the App Group container and keychain access groups used by the host and extension. Put a fake session token in host-only storage and verify the extension cannot read it. Put only the minimum receipt fields in the shared container and clear them under a written rule. Save entitlement IDs, file list, keychain group, extension process result, and receipt output. An App Group grants both processes access to its shared container; the entitlement does not decide which record is safe to share. (Apple App Groups).

Check file and keychain sharing independently

App Group containers and keychain access groups are separate sharing settings. Inspect the built host and each extension, then test one fake file marker and one fake keychain item. Give the widget the shared display marker while keeping the session item in the host-only keychain group. The widget must read the first and fail to read the second. Change accounts while the host is closed and refresh the widget. A delivered notification that already contains private text cannot be made unseen by a later remote lock. Prevent that exposure by limiting the original payload and test cleanup of local pending and delivered notifications under the product rule.

Reject stale account revisions

Use a shared widget record with synthetic account reference A and cache revision 7. Switch the host app to B and write revision 8 with a cleared display record. Refresh the widget using a delayed revision-7 result. It must not overwrite revision 8 or show A’s balance again. Keep the account reference and revision in the small shared data contract. Test the same ordering for a notification service response that arrives after logout. An extension unable to confirm freshness should show neutral content under the product policy. A cache clear that succeeds once is insufficient if an old network response can repopulate the shared file.

Related reading

Source