Arena/01a0a076 ipatool sapfix webgui - #28
Merged
Merged
Conversation
Brings the first 11 upstream commits (30b2909..5c522b6 of majd/ipatool) into the fork in one reconstructed commit after a sandbox history reset: - 73fabcc, abdb590, e6acb9c, b8bac29, 843f5c6, a814a71: download/resume, zip framing/headers, state directory, ranged responses - 24f93d3: .github/FUNDING.yml (fork README kept) - d1845ba: authentication transport isolation (DisableKeepAlives for auth client), 429/Retry-After handling, auth retry with backoff in login flow, stage-aware error messages; fork MZFinance pod redirect flow preserved (parseLoginResponse stays 2-arg; no endpoint validation) - ba180d7: visionos/macos platform support, owned-apps platform filtering, multi-storefront (34/13) fetch + mergeOwnedApps, --platform CLI flag (fork All flag and SignAction-based signing preserved) - 5c522b6: macOS external version lookup via Mac product page (storefrontClient added to appstore), wired into Download() for PlatformMacOS; fork download flow (fetchDownloadItem/redownload) kept Co-authored-by: arena-agent <[email protected]>
Co-authored-by: arena-agent <[email protected]>
Co-authored-by: arena-agent <[email protected]>
Co-authored-by: arena-agent <[email protected]>
Co-authored-by: arena-agent <[email protected]>
Co-authored-by: arena-agent <[email protected]>
Co-authored-by: arena-agent <[email protected]>
Cherry-pick of upstream e5211d6 (adapted): - lookupLatestExternalVersionID now tries the enterprise catalog first and falls back to the iphone/ipad consumer catalogs for iOS platforms - platformVersionLookupRequest takes the catalog string directly - visionOS lookup split out to the storefront product page; ported visionProductURL/visionExternalVersionID helpers into storefront.go - skipped appstore_download_product_test.go changes (file does not exist in this fork) - added upstream appstore_platform_version_lookup_test.go Co-authored-by: arena-agent <[email protected]>
Cherry-pick of upstream 735b689 (adapted to the fork layout): - normalizeAuthCode strips whitespace, bracketed-paste markers and validates the six-digit format; applied in both Login entry points (Login and LoginMZFinance) so every downstream path (legacy, GSA) receives the normalized code - parseLoginResponse now distinguishes a missing 2FA code from a failed verification with a dedicated error message - dropped the incoming parseLoginResponse/loginRequest duplicates (upstream's SAP-signer variants) in favor of the fork's versions - adopted all four test additions (malformed-code table, password normalization table, incomplete-verification case) Co-authored-by: arena-agent <[email protected]>
Co-authored-by: arena-agent <[email protected]>
Cherry-pick of upstream 387d1a4 (adapted to the fork layout): - platform version lookup failures are now sentinel errors (errPlatformAppNotFound / errPlatformOffersNotFound) and appstore.Error gained Unwrap so errors.Is reaches them through metadata wrappers - Lookup exposes ErrAppNotFound - Download no longer aborts when a tvOS app has no catalog offer: the package is fetched anyway and its declared platform is validated - validatePackagePlatform now runs against the raw .tmp package before patching/renaming, and the .tmp file is removed on failure, so a platform mismatch leaves the previously downloaded file intact - download command falls back to the numeric app ID (with the bundle ID kept on the app) when the bundle lookup reports the app as not found - tests: new 'Downloading delisted tvOS apps' suite (adapted: the fork's redownload endpoint is hardcoded instead of coming from the bag, and the ensureSinfs guard adds a primary+redownload re-request) and a new cmd/download_test.go covering app resolution (adapted to the fork's downloadCmd + dependencies.AppStore injection) Co-authored-by: arena-agent <[email protected]>
Ports the endpoint-fallback mechanism that upstream introduced in 30b2909 (and extended in 747d66f for macOS and acd9e7a for tvOS), which the fork skipped when it kept its own download flow: - urlBag now parses the redownloadProduct/updateProduct endpoints and fetchURLBag returns the raw bag without the auth-specific SAP config - new appstore_download_product.go: sendUpdateProduct asks the bag's updateProduct endpoint for a pinned version (appExtVrsId) and verifies the response (single item, matching app id / version / bundle id); bag endpoints are validated against the trusted download dispatch domain - fetchDownloadItem takes the platform and, after the redownload endpoint gives up on a pinned version (empty HTTP 500 or a message-only 'no longer available' response), falls back to updateProduct for iphone, ipad, macos, tvOS and unspecified platforms - the fork's redownload URL and its primary-retry + ensureSinfs behaviour are preserved, and the bag is only fetched when the update fallback is actually needed, so existing download/check-download flows and tests are unchanged - new appstore_update_product_test.go covering the fallback: empty-500 and unavailable tvOS pins, unpinned availability responses left as-is, response mismatch and untrusted-endpoint rejection, license error propagation, and missing update endpoint Co-authored-by: arena-agent <[email protected]>
First CI run (unit tests) failed to compile with: - undefined: strings (appstore_search.go) - undefined: joinCleanupError x3 (appstore_download.go) The helper lives upstream in appstore_replicate_sinf.go; the fork's copy of that file predates it, so append the same implementation. Co-authored-by: arena-agent <[email protected]>
- appstore_download_test: local mock helper 'redownload' shadowed the table's bool parameter, breaking declaration and calls; rename the helper to redownloadCall. - appstore_macos_version_lookup_test: the ported test called upstream's sendDownloadProduct method which the fork does not have; test the fork's lookupLatestMacOSExternalVersionID instead (same mocked storefront fetch, same failure entries). Co-authored-by: arena-agent <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.