Applications
Shortcut Map
Native macOS app
What it does
- Built and shipped a native macOS menu bar app that answers a question macOS exposes no API for — which keyboard shortcuts are actually bound on this machine right now — by reconciling four independent, mutually disagreeing sources into one searchable map with conflict detection.
- Wrote the discovery engine in Swift 6 with zero external dependencies: a live Accessibility-API walk of every running app’s menus, isolated in an actor behind messaging timeouts and a depth cap so a hung app can never wedge a scan; the system hotkey preference domain, backed by a curated catalog because macOS ships no readable defaults; per-app user overrides; and a read-only reader for BetterTouchTool’s undocumented store, which binds hotkeys globally and is therefore invisible to every other source while being the most likely thing to silently shadow an app’s own binding.
- Confined the entire Accessibility surface to one small auditable file, so the app’s stated use of that permission — menu titles and their key equivalents, never keystrokes — can be checked rather than taken on trust, and documented plainly which categories of shortcut the app structurally cannot see. No telemetry; the version check is disableable.
- Diagnosed and fixed the code-signing defect behind repeated loss of that permission — macOS pins a privacy grant to an app’s designated requirement, which under ad-hoc signing is the per-build code hash, so every rebuild read as a different app — then built a signature-verified in-place updater on the stable identity the fix created: each download checked against the running app’s own requirement, anything not strictly newer refused, and every failure path falling back to the website rather than a half-installed app.
- Shipped it publicly through a curl-piped installer that sidesteps the Gatekeeper quarantine dead-end, with a matching uninstaller, rolling and versioned releases, and continuous integration that proves the distribution path rather than only the code — linting the install scripts, exercising install, signature-verify, run, and uninstall end to end, and mirroring the releases and project site from a private repository to a public one. The whole project — first commit through v0.7.0, across ten tagged releases — was designed, built, and shipped in a single day.