◉RORK LABJP
●EXPO — EAS Observe now records native crashes (Oct 7). On SDK 57, update to 57.0.21 or later●SDK 58 — SDK 58 Beta has been out since Sep 15. The stable date is still unconfirmed●RN 0.88 — React Native 0.88.x is scheduled for Oct 12, 3 days left●Q&A — People are asking why expo-widgets render blank only in production builds●RORK — GPT-6.1 Sol was added on Sep 29, available on Pro and Max plans●NEW — Building an app for a client? Decide who owns the publishing account first●EXPO — EAS Observe now records native crashes (Oct 7). On SDK 57, update to 57.0.21 or later●SDK 58 — SDK 58 Beta has been out since Sep 15. The stable date is still unconfirmed●RN 0.88 — React Native 0.88.x is scheduled for Oct 12, 3 days left●Q&A — People are asking why expo-widgets render blank only in production builds●RORK — GPT-6.1 Sol was added on Sep 29, available on Pro and Max plans●NEW — Building an app for a client? Decide who owns the publishing account first
Articles/Dev Tools
⬡ Dev Tools/2026-07-04Advanced

Your Rork Max App Loses the Photos a User Picked After Relaunch — The Trap of Holding Onto URLs Under Limited Photo Access

In a native Swift app generated by Rork Max, photos picked via PHPickerViewController become unreadable after relaunch — because holding onto a URL or PHAsset no longer works in the age of limited access. Here's a design that copies the actual bytes into your own storage the instant they're picked.

Rork Max235PHPickerViewControllerPhotoKitlimited accessSwift48iOS115

✦ Premium Article

I was adding a feature to a Rork Max app that just uses a few user-picked photos for a collage. Photos chosen through PHPickerViewController displayed fine on the spot and edits worked. But relaunch the app, and the photos I'd just picked came back black or failed to load. Pick them again and it's fixed, but the state I thought I'd saved was broken — that's the shape of the reports. Nothing that looks like an error appears.

The cause was holding onto the temporary reference PHPicker returns, thinking "I'll just read it later." On today's iOS, where limited access is the norm, you have to design on the assumption that a URL or PHAsset identifier valid at selection time won't be readable next time. As an indie developer who's worked on photo apps for a long time, I've learned that missing this "valid only at the moment of selection" nature of limited access means data quietly goes missing in production. This walks through adding photo import to a Rork Max native app with the smallest diff: how to avoid the holding-on trap, and an import layer you can use as-is.

What PHPicker hands you instead of "not asking for permission"

The big advantage of PHPickerViewController is that it works without the photo-library permission dialog. Only the photos the user selects inside the system UI reach the app, so the app holds no access to the whole library. That's the decisive difference from the older UIImagePickerController.

What arrives is a spout, not the bytes

The NSItemProvider PHPicker returns isn't the photo itself — it's "a spout you can draw from right now." You can read it on the spot with loadFileRepresentation or loadDataRepresentation, but the temporary file URL you get back expires after the callback returns. Think "I'll save the URL and open it later" and you drop into an unreadable state on next launch.

A PHAsset identifier is no guarantee of persistence either

You can configure preferredAssetRepresentationMode on PHPickerConfiguration to reach a PHAsset, but under limited access there's no guarantee the asset the app could see then will be visible next time. If the user later changes their selection, the identifier remains but you can no longer resolve it to the bytes. Running photo apps, I've moved away from any design that leans on persisting asset identifiers.

The core of the fix: copy the bytes the moment they're picked

Stop trying to hold on. Inside the selection callback, copy the bytes fully into your own persistent area (like Application Support). Reference only that local file afterward. This is the straightforward design for the limited-access era. Pay the cost once at import, then treat it as your own file — and URL expiry and selection changes become irrelevant.

import PhotosUI
import UniformTypeIdentifiers
import os
 
let picLog = Logger(subsystem: "net.rorklab.sample", category: "photo")
 
enum PhotoImportError: Error { case noImageRep, copyFailed }
 
final class PhotoImporter {
    private let dir: URL = {
        let base = FileManager.default.urls(for: .applicationSupportDirectory,
                                            in: .userDomainMask)[0]
        let d = base.appendingPathComponent("imported", isDirectory: true)
        try? FileManager.default.createDirectory(at: d, withIntermediateDirectories: true)
        return d
    }()
 
    // Take PHPicker results, return an array of persistent paths
    func importItems(_ results: [PHPickerResult]) async -> [URL] {
        var saved: [URL] = []
        for result in results {
            do {
                let url = try await copyToLocal(result.itemProvider)
                saved.append(url)
                picLog.info("imported: \(url.lastPathComponent)")
            } catch {
                picLog.error("import failed: \(error.localizedDescription)")
            }
        }
        return saved
    }
}
✦

Thank you for reading this far.

Continue Reading

What follows includes implementation code, benchmarks, and practical content we hope you'll find useful. This site runs without ads — server and development costs are supported entirely by members like you. If it's been helpful, we'd be truly grateful for your support.

WHAT YOU'LL LEARN
✦You can isolate why PHPicker photos vanish after relaunch: limited access, temporary-URL expiry, or the non-persistence of PHAsset
✦You get an import layer that copies the bytes into the app's persistent area right after selection and references only local files afterward, ready to drop into Rork Max's generated code
✦You'll keep PHPicker's strength of not requesting library permission while getting the export, orientation, and size details right for production
Secure payment via Stripe · Cancel anytime
✦

Unlock This Article

Get full access to the rest of this article. Buy once, read anytime. This site is ad-free — your support goes directly toward keeping it running.

or
Unlock all articles with Membership →
Share

Thank You for Reading

Rork Lab is ad-free, supported entirely by members like you. We publish practical guides daily with implementation code, benchmarks, and production-ready patterns. If you've found it useful, we'd love to have you on board.

  • ✦Copy-paste ready implementation code
  • ✦New advanced guides published daily
  • ✦$5/mo or $15 for lifetime access
View Membership →

Related Articles

⬡ Dev Tools2026-04-05
Rork Max × WidgetKit & Live Activities in Practice — From Home Screen to Dynamic Island
A complete guide to implementing iOS Widgets, Lock Screen widgets, and Dynamic Island Live Activities with Rork Max. Covers WidgetKit fundamentals, Timeline update strategies, App Intents integration, and monetization.
⬡ Dev Tools2026-05-16
Migrating Firebase CocoaPods to SPM in Rork Max Apps
Firebase Apple SDK's CocoaPods distribution ends in October 2026. Here's a detailed migration log from moving 4 Rork Max iOS apps to Swift Package Manager — including dSYM failures, module errors, and the Dropbox conflict copy problem you'll definitely hit.
⬡ Dev Tools2026-05-01
Adding a Notification Service Extension to a Rork App — Rich Push, Encrypted Payloads, and Dynamic Rewriting
Wiring a Notification Service Extension into a Rork-built iOS app — image attachments, end-to-end encrypted payloads, and dynamic APNs payload rewriting — with working Swift code and the production pitfalls that bit me along the way.
📚RECOMMENDED BOOKS
Build a Large Language Model (From Scratch)
Sebastian Raschka
LLM Dev
Prompt Engineering for LLMs
Berryman & Ziegler
Prompting
AI Engineering
Chip Huyen
AI Eng
* Contains affiliate links