Repository navigation
Read the Apple service key from the sign out redirect (fixes #161) - #162
Merged
Merged
Conversation
Apple removed the olympus config endpoint in September 2026; it now returns 404, so getAppleServicekey() could no longer fetch the widget key and authenticate failed before it started (see fastlane#30199). Read the key from where App Store Connect keeps it now: the /logout route answers with a 302 whose Location carries widgetKey=<key>. The request must not follow the redirect and must send no cookies, since the target is a real signout (asop=destroy-session). The olympus call is kept as a fallback in case Apple restores it.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #161.
Problem
xcodeinstall authenticatefails at the very first step withunableToRetrieveAppleServiceKey. Apple removed the olympus config endpoint in September 2026:getAppleServicekey()relied on that endpoint to fetch the widget key (authServiceKey) required by every subsequent auth call, so login dies before it can start. Same break as fastlane/fastlane#30199; the upstream fix is fastlane/fastlane#30206.Fix
The widget key is a public, static front-end identifier, not a credential. Apple's own App Store Connect front end now reads it from the sign-out redirect:
getAppleServicekey()now tries that source first and falls back to the olympus endpoint (kept in case Apple restores it):fetchServiceKeyFromSignout()readswidgetKeyout of the/logout302Locationheader, returningnilon any expected miss so the caller falls through to olympus rather than making this a new single point of failure.signoutRedirectLocation()issues the request over a dedicated ephemeralURLSessionwith a redirect-suppressing delegate and no cookie storage. This is deliberate: the redirect target carriesasop=destroy-session, so following it (or sending the session cookies) would actually sign the session out. We stop at the 302 and read only the header.fetchServiceKeyFromOlympus()is the previous behaviour, unchanged, now the fallback.NoRedirectDelegateis a stateless,Sendabledelegate returningnilfromwillPerformHTTPRedirection.Tests
New cases mirror the upstream fix; the seam is stubbed via a
StubbedSignoutAuthenticatortest subclass so no live network is hit:Locationredirect;widgetKey;Built and tested locally on macOS with Xcode 26.6:
swift buildclean,swift testgreen (207 tests, 19 suites).