Skip to content

Arena/01a0a076 ipatool sapfix webgui - #28

Merged
pdx15 merged 18 commits into
mainfrom
arena/01a0a076-ipatool-sapfix-webgui
Sep 30, 2026
Merged

pdx15 merged 18 commits into
mainfrom
arena/01a0a076-ipatool-sapfix-webgui

Conversation

@pdx15

@pdx15 pdx15 commented Sep 30, 2026

Copy link
Copy Markdown
Owner

No description provided.

pdx15 and others added 18 commits September 15, 2026 20:02
Brings the first 11 upstream commits (30b2909..5c522b6 of majd/ipatool)
into the fork in one reconstructed commit after a sandbox history reset:

- 73fabcc, abdb590, e6acb9c, b8bac29, 843f5c6, a814a71: download/resume,
  zip framing/headers, state directory, ranged responses
- 24f93d3: .github/FUNDING.yml (fork README kept)
- d1845ba: authentication transport isolation (DisableKeepAlives for auth
  client), 429/Retry-After handling, auth retry with backoff in login flow,
  stage-aware error messages; fork MZFinance pod redirect flow preserved
  (parseLoginResponse stays 2-arg; no endpoint validation)
- ba180d7: visionos/macos platform support, owned-apps platform filtering,
  multi-storefront (34/13) fetch + mergeOwnedApps, --platform CLI flag
  (fork All flag and SignAction-based signing preserved)
- 5c522b6: macOS external version lookup via Mac product page
  (storefrontClient added to appstore), wired into Download() for
  PlatformMacOS; fork download flow (fetchDownloadItem/redownload) kept

Co-authored-by: arena-agent <[email protected]>
Cherry-pick of upstream e5211d6 (adapted):
- lookupLatestExternalVersionID now tries the enterprise catalog first
  and falls back to the iphone/ipad consumer catalogs for iOS platforms
- platformVersionLookupRequest takes the catalog string directly
- visionOS lookup split out to the storefront product page; ported
  visionProductURL/visionExternalVersionID helpers into storefront.go
- skipped appstore_download_product_test.go changes (file does not
  exist in this fork)
- added upstream appstore_platform_version_lookup_test.go

Co-authored-by: arena-agent <[email protected]>
Cherry-pick of upstream 735b689 (adapted to the fork layout):
- normalizeAuthCode strips whitespace, bracketed-paste markers and
  validates the six-digit format; applied in both Login entry points
  (Login and LoginMZFinance) so every downstream path (legacy, GSA)
  receives the normalized code
- parseLoginResponse now distinguishes a missing 2FA code from a
  failed verification with a dedicated error message
- dropped the incoming parseLoginResponse/loginRequest duplicates
  (upstream's SAP-signer variants) in favor of the fork's versions
- adopted all four test additions (malformed-code table, password
  normalization table, incomplete-verification case)

Co-authored-by: arena-agent <[email protected]>
Cherry-pick of upstream 387d1a4 (adapted to the fork layout):
- platform version lookup failures are now sentinel errors
  (errPlatformAppNotFound / errPlatformOffersNotFound) and appstore.Error
  gained Unwrap so errors.Is reaches them through metadata wrappers
- Lookup exposes ErrAppNotFound
- Download no longer aborts when a tvOS app has no catalog offer: the
  package is fetched anyway and its declared platform is validated
- validatePackagePlatform now runs against the raw .tmp package before
  patching/renaming, and the .tmp file is removed on failure, so a
  platform mismatch leaves the previously downloaded file intact
- download command falls back to the numeric app ID (with the bundle ID
  kept on the app) when the bundle lookup reports the app as not found
- tests: new 'Downloading delisted tvOS apps' suite (adapted: the fork's
  redownload endpoint is hardcoded instead of coming from the bag, and
  the ensureSinfs guard adds a primary+redownload re-request) and a new
  cmd/download_test.go covering app resolution (adapted to the fork's
  downloadCmd + dependencies.AppStore injection)

Co-authored-by: arena-agent <[email protected]>
Ports the endpoint-fallback mechanism that upstream introduced in
30b2909 (and extended in 747d66f for macOS and acd9e7a for tvOS),
which the fork skipped when it kept its own download flow:

- urlBag now parses the redownloadProduct/updateProduct endpoints and
  fetchURLBag returns the raw bag without the auth-specific SAP config
- new appstore_download_product.go: sendUpdateProduct asks the bag's
  updateProduct endpoint for a pinned version (appExtVrsId) and verifies
  the response (single item, matching app id / version / bundle id);
  bag endpoints are validated against the trusted download dispatch
  domain
- fetchDownloadItem takes the platform and, after the redownload
  endpoint gives up on a pinned version (empty HTTP 500 or a
  message-only 'no longer available' response), falls back to
  updateProduct for iphone, ipad, macos, tvOS and unspecified platforms
- the fork's redownload URL and its primary-retry + ensureSinfs
  behaviour are preserved, and the bag is only fetched when the update
  fallback is actually needed, so existing download/check-download
  flows and tests are unchanged
- new appstore_update_product_test.go covering the fallback: empty-500
  and unavailable tvOS pins, unpinned availability responses left as-is,
  response mismatch and untrusted-endpoint rejection, license error
  propagation, and missing update endpoint

Co-authored-by: arena-agent <[email protected]>
First CI run (unit tests) failed to compile with:
- undefined: strings (appstore_search.go)
- undefined: joinCleanupError x3 (appstore_download.go)

The helper lives upstream in appstore_replicate_sinf.go; the fork's copy
of that file predates it, so append the same implementation.

Co-authored-by: arena-agent <[email protected]>
- appstore_download_test: local mock helper 'redownload' shadowed the
  table's bool parameter, breaking declaration and calls; rename the
  helper to redownloadCall.
- appstore_macos_version_lookup_test: the ported test called upstream's
  sendDownloadProduct method which the fork does not have; test the
  fork's lookupLatestMacOSExternalVersionID instead (same mocked
  storefront fetch, same failure entries).

Co-authored-by: arena-agent <[email protected]>
@pdx15
pdx15 merged commit 55c9e8c into main Sep 30, 2026
1 check failed
@pdx15
pdx15 deleted the arena/01a0a076-ipatool-sapfix-webgui branch September 30, 2026 04:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants