Conversation
This was referenced Oct 1, 2026
rworang
force-pushed
the
fix/legacy-hsa-sms-2fa
branch
from
October 1, 2026 23:44
baeed47 to
06f8d36
Compare
Older Apple IDs answer /auth with authType "hsa" and list their SMS number under trustedDevices instead of trustedPhoneNumbers, so get_trusted_numbers bailed. /auth/verify/phone also returns 200 for these accounts without sending a code. When trustedPhoneNumbers is missing and trustedDevices has an sms entry, remember its id, and have send_sms_2fa / verify_sms_2fa use /auth/verify/device/<id>/securitycode instead. hsa2 accounts are unaffected. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
rworang
force-pushed
the
fix/legacy-hsa-sms-2fa
branch
from
October 1, 2026 23:54
06f8d36 to
5b4eee5
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fix for login with old Apple ID.
My 2019 Apple ID uses
hsawith a 4-digit SMS code over thehsa26-digit device for newer 2FA used by new accounts.The current
apple_account.rsdoes not deal with the format of thehsaresponse nor the 4-digit text message verification.I've made this fix with Claude Code and have had it reduce the output multiple times. I have made it follow your code and use the rustfmt to make sure everything is proper.
It added minimal changes just to support the legacy
hsaformat. And I have tested a built version multiple times withhsa&hsa2accounts. I have used it to load a known failing ipa with thehsaaccount because it failed on my supposedly team blockedhsa2account.I only saw the disclaimer after the PR's were made so I am re-writing the PR description. Though I will leave the original written description for reference below.
Fixes login for legacy "hsa" Apple IDs that only have an SMS number. Apple's replies and details: nab138/iloader#787.
Problem. For these accounts
/authreturns"authType": "hsa"with the number undertrustedDevicesinstead oftrustedPhoneNumbers, soget_trusted_numbersbails. AndPUT /auth/verify/phonereturns 200 without sending a code.Change (72 lines, one file, no API changes):
get_trusted_numbers: iftrustedPhoneNumbersis missing andtrustedDeviceshas atype: "sms"entry, store its id in a newhsa_sms_device_idfield and return an empty list.send_sms_2fa/verify_sms_2fa: if that field is set, return early throughhsa_security_code, which doesPUT(send) orPOST {"code": ...}(verify) on/auth/verify/device/<id>/securitycode. Codes are 4 digits; the iloader dialog change is Accept 4-digit 2FA codes iloader#788.hsa2 accounts never set the field, so their path is unchanged. A wrong code ends the login with an error rather than re-prompting; happy to add a retry if you prefer.
Tested with iloader
mainbuilt against this branch: an hsa account (fresh anisette, 4-digit SMS, login) and an hsa2 account (trusted-device 2FA, unchanged) both log in.cargo check --workspace --all-targets --all-featurespasses, clippy warnings are the same asmain, rustfmt is clean.How this was made. I don't write Rust, so I built this with Claude Code. I kept it small on purpose. A first version was 287 lines (an
i64id change, a number picker fallback, extra logging, unit tests). I cut it down to what the hsa login actually needs, and left out the tests given your note on #607. I tested every version myself on both account types.🤖 Generated with Claude Code