That page describes a couple of other scenarios, so Apple at least has given this some thought.
So, developers will have to do more. I think that’s acceptable for the additional security that the users get, but that’s another discussion.
Do what? As I said at the end of the article, there's no way for a non-sandboxed app to preserve the granted file access across launches.
Just sandbox a non-sandboxed app. Yeah, thanks for your input.
> and configure it properly.
This is nonsense. A sandboxed app only has access to its own container, so it's a non-solution to the problem of accessing the container of another app.
Another example: sometimes a developer has a sandboxed sub-application embedded inside the main non-sandboxed application, for the purposes of security or crash protection, if the sub-app is loading arbitrary content from the internet. So now there would be a scary dialog every time the main application is launched and needs to access the container of the sub-application.
There are countless scenarios that you've never thought of, and that Apple has never thought of. In fact, that's one of the main purposes of having a 3rd party developer ecosystem. You never know exactly what could be useful until someone clever and imaginative makes it. I've personally worked on a lot of software that users love but that would be banned by simple-minded fearmongering about "security". This is one of the reasons why the once thriving Mac software ecosystem is becoming quite barren nowadays. It won't be long before the Mac becomes nothing more than an ultra-expensive iPad.