Skip to content

Support SMS 2FA for legacy "hsa" accounts - #25

Open
rworang wants to merge 1 commit into
nab138:mainfrom
rworang:fix/legacy-hsa-sms-2fa
Open

rworang wants to merge 1 commit into
nab138:mainfrom
rworang:fix/legacy-hsa-sms-2fa

Conversation

@rworang

@rworang rworang commented Oct 1, 2026 •

Copy link
Copy Markdown

Fix for login with old Apple ID.

My 2019 Apple ID uses hsa with a 4-digit SMS code over the hsa2 6-digit device for newer 2FA used by new accounts.

The current apple_account.rs does not deal with the format of the hsa response nor the 4-digit text message verification.

I've made this fix with Claude Code and have had it reduce the output multiple times. I have made it follow your code and use the rustfmt to make sure everything is proper.

It added minimal changes just to support the legacy hsa format. And I have tested a built version multiple times with hsa & hsa2 accounts. I have used it to load a known failing ipa with the hsa account because it failed on my supposedly team blocked hsa2 account.

I only saw the disclaimer after the PR's were made so I am re-writing the PR description. Though I will leave the original written description for reference below.


Fixes login for legacy "hsa" Apple IDs that only have an SMS number. Apple's replies and details: nab138/iloader#787.

Problem. For these accounts /auth returns "authType": "hsa" with the number under trustedDevices instead of trustedPhoneNumbers, so get_trusted_numbers bails. And PUT /auth/verify/phone returns 200 without sending a code.

Change (72 lines, one file, no API changes):

  • get_trusted_numbers: if trustedPhoneNumbers is missing and trustedDevices has a type: "sms" entry, store its id in a new hsa_sms_device_id field and return an empty list.
  • send_sms_2fa / verify_sms_2fa: if that field is set, return early through hsa_security_code, which does PUT (send) or POST {"code": ...} (verify) on /auth/verify/device/<id>/securitycode. Codes are 4 digits; the iloader dialog change is Accept 4-digit 2FA codes iloader#788.

hsa2 accounts never set the field, so their path is unchanged. A wrong code ends the login with an error rather than re-prompting; happy to add a retry if you prefer.

Tested with iloader main built against this branch: an hsa account (fresh anisette, 4-digit SMS, login) and an hsa2 account (trusted-device 2FA, unchanged) both log in. cargo check --workspace --all-targets --all-features passes, clippy warnings are the same as main, rustfmt is clean.

How this was made. I don't write Rust, so I built this with Claude Code. I kept it small on purpose. A first version was 287 lines (an i64 id change, a number picker fallback, extra logging, unit tests). I cut it down to what the hsa login actually needs, and left out the tests given your note on #607. I tested every version myself on both account types.

🤖 Generated with Claude Code

Older Apple IDs answer /auth with authType "hsa" and list their SMS
number under trustedDevices instead of trustedPhoneNumbers, so
get_trusted_numbers bailed. /auth/verify/phone also returns 200 for
these accounts without sending a code.

When trustedPhoneNumbers is missing and trustedDevices has an sms
entry, remember its id, and have send_sms_2fa / verify_sms_2fa use
/auth/verify/device/<id>/securitycode instead. hsa2 accounts are
unaffected.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@rworang
rworang force-pushed the fix/legacy-hsa-sms-2fa branch from 06f8d36 to 5b4eee5 Compare October 1, 2026 23:54
@rworang rworang mentioned this pull request Oct 2, 2026
5 tasks done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant