Skip to content

Fix Apple sign-in service-key retrieval and align auth with Fastlane - #188

Merged
joshdholtz merged 3 commits into
mainfrom
fix/apple-auth-service-key
Oct 6, 2026
Merged

joshdholtz merged 3 commits into
mainfrom
fix/apple-auth-service-key

Conversation

@joshdholtz

@joshdholtz joshdholtz commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Checklist

  • Tests added or updated, if applicable
  • go build ./..., go test ./..., and gofmt pass

Motivation

rc setup apple fails before authenticating because Apple's Olympus configuration endpoint returns 404. Fixes #185.

Description

Fetch the current service key from HEAD /logout, following Fastlane's replacement flow, so Apple setup and the read-only check can continue to sign-in. The request sends no session cookies and doesn't follow the signout redirect. Keep Olympus as a fallback and report both failures if neither source works.

Also align sign-in headers with Fastlane, reject invalid SRP server public values, and report Apple SMS and verification errors even when the HTTP response is 200. Failed verification stops before trusting or fetching the session.

This doesn't add saved sessions, cached service keys, or legacy four-digit verification.

Implementation and validation
  • Compared against Fastlane's client.rb, two_step_or_factor_client.rb, and fastlane-sirp.
  • Added a proof fixture generated with Fastlane's Ruby SRP implementation, with pinned source and reproduction instructions. SRP request contracts and login-status handling have separate tests.
  • Covered cookie isolation, redirect blocking, fresh lookup, fallback, cancellation, SRP requests, hashcash, DES cookies, login status handling, and 2FA errors.
  • make check passed (formatting, vet, race tests, lint), as did native and Windows builds.
  • Live service-key lookup returned 302 with widgetKey. Full account login and 2FA haven't been tested live.

Reference: fastlane/fastlane#30206


Note

High Risk
Changes Apple authentication flows (service key, SRP, sign-in/2FA error handling), which are security-critical and can block or misreport login if Apple’s behavior diverges.

Overview
Fixes Apple Connect sign-in when Olympus no longer returns a service key by fetching widgetKey from a cookieless HEAD /logout redirect (Fastlane-style), with Olympus config as fallback and combined errors if both fail.

Sign-in is tightened to match Fastlane: Accept: application/json, text/javascript on SRP init/complete, invalid SRP server public values rejected, and appleAuthErrorMessage surfaces Apple serviceErrors / validation failures even on HTTP 200 (including SMS and bad verification codes, stopping before session trust).

Adds broad httptest coverage plus a fastlane-sirp proof fixture for SRP alignment.

Reviewed by Cursor Bugbot for commit 14aea8a. Bugbot is set up for automated code reviews on this repo. Configure here.

@joshdholtz
joshdholtz marked this pull request as ready for review October 6, 2026 18:00
@joshdholtz
joshdholtz requested review from a team and a balanced review from Copilot October 6, 2026 18:00

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@joshdholtz
joshdholtz merged commit b5eae77 into main Oct 6, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Apple setup fails fetching auth service key: Olympus app/config returns HTTP 404

3 participants