Conversation
|
This is very cool, thank you very much for working on this! I see a lot of example code and tests, but no additions or changes to the library itself. It's awesome that you got this working, but I feel like it would be more useful for end users if FIDO auth was integrated into the library itself. There are existing base classes for this (e.g. Do you think you could retrofit your solution into the existing 2FA model? Or would we need API changes / additions to properly implement this? |
|
Yes, I agree that native integration would be much more useful for end users. I think the protocol can be retrofitted into the existing 2FA model, but not cleanly through the current My preferred approach would be a small, backward-compatible API addition:
I would avoid forcing the assertion through So the short answer is: yes, I can rework this into the library's 2FA model, but I recommend a small additive API extension rather than fitting it into the code-based interface unchanged. If that direction works for you, I can retrofit the PR around it. |
Refs malmeloo#159. Opt-in Linux HSA2 FIDO2/WebAuthn adapter, checked authentication transport, private CLI and synthetic tests. No default SDK API changes. Coding-Model: gpt-6-astra
Move the proven HSA2 challenge, assertion, and authentication flow into FindMy's native BaseSecondFactorMethod model with async and sync APIs. Keep python-fido2 optional through a signer callback, preserve code-based factors, bound the 2FA transport, and update docs/tests. Coding-Model: gpt-5.6-sol-900k
3ad09f3 to
58b5c84
Compare
|
Thanks — I reworked the PR around the existing second-factor model as suggested. The native library now exposes The Apple HSA2 parser, assertion codec, continuation handling, bounded verified-TLS 2FA transport and post-key GrandSlam/MobileMe transitions are now in Verification on the rebased branch: 173 tests passed on Python 3.10–3.14, Ruff, basedpyright and pre-commit passed, and the built wheel contains the native security-key modules. I also kept the real-account evidence and universal-compatibility limitations explicit in the PR description; no account data or session material is included. |
|
Thanks, I agree that this is probably the correct approach. I can't review your changes in detail right now so give me some time to look into it. One more thing: I'd suggest that we drop the current example additions entirely. It doesn't add a whole lot to the library (they appear to bypass the library entirely), and while it's certainly interesting, I think it serves more as documentation on how the spec works. It definitely has a purpose somewhere (dedicated FindMy docs, anyone???), but probably not in this library. |
Summary
Related to #159 and parawanderer/OpenTagViewer#18.
This update responds to the maintainer's request on the original example PR: the Apple HSA2 security-key flow is now integrated into FindMy.py's existing second-factor model instead of living only in an example-local account subclass.
Native library integration
SecurityKeyChallengeandSecurityKeyAssertionvalue types.SecurityKeySecondFactorMethod,AsyncSecurityKeySecondFactor, andSyncSecurityKeySecondFactoralongside the existing SMS/trusted-device methods.get_2fa_methods()can return the native security-key factor when Apple's auth page advertises the supported HSA2 layout.submit(code: str)code-oriented; security keys use additiveauthenticate(signer)instead of a dummy code.python-fido2remains optional and is used only by the Linux USB example.BaseAppleAccountimplementations by making the new account methods concreteNotImplementedErrorhooks rather than new abstract requirements.Example changes
AsyncAppleAccountand nativeAsyncSecurityKeySecondFactor.python-fido2; it no longer duplicates the account, Apple HTTP transport, parser, or authentication state machine.Evidence and limitations
The original adapter successfully completed login on one real Apple Account protected by a Yubico USB Security Key on Linux: assertion accepted, post-key GrandSlam authenticated, MobileMe issued a FindMy session, and the saved session excluded the password. A separate private integration subsequently reused the session and fetched owned accessory locations. Those private integrations and data are not included here.
This public contribution is tested offline against the current upstream source. It does not claim universal hardware/account compatibility, official Apple support, legacy FSA1/U2F support, primary-FSA2/passwordless login, or a second real-account trial of this extracted branch. No account-security changes, key removal, macOS SIP/AMFI changes or weaker fallback were used.
Verification
uv run --group test pytest -q: 173 passeduv run basedpyright: 0 errors, 0 warnings, 0 notesuv run ruff check .: passeduv run ruff format --check .: passeduv run pre-commit run --all-files: passeduv build: source distribution and wheel built; the wheel containsfindmy/reports/security_key.py,account.pyandtwofactor.py.Tests use explicitly synthetic accounts, challenges, credentials, assertions, signatures, transports and HTTP responses. The CTAP test exercises real
python-fido2and ECDSA against a synthetic authenticator, not a physical key or Apple. No account data, session, token, exported accessory bundle, location or homelab configuration is included.API example
The
signercallback receives a validatedSecurityKeyChallengeand returns aSecurityKeyAssertion. The async API uses the same model with an async callback.Contributed by Olafejs with AI-assisted implementation and testing. Existing FindMy.py GrandSlam/MobileMe code, python-fido2 and other dependencies retain their authorship and licenses; this contribution follows the repository's MIT license.