Scope note
The 409/SMS-fallback defect originally described in this issue (section below) is already fixed by PR #21176 (merged 2026-07-15, milestone 5.3) — getMfaAuthOptions() and requestSmsCode() now treat 409 as part of the successful 2FA flow. This issue therefore remains open only for the session-storage/dispose gap, which #21176 does not address.
Problem
When the iCloud session is invalidated by Apple (password change, security event, auth-scheme change), the icloud:account bridge cannot perform a fresh re-authentication without deleting/recreating the thing or restarting openHAB entirely. Disable → enable of the thing does not help, and restarting only the binding bundle does not help either.
Root cause (from source analysis)
ICloudSession persists its session state (scnt, sessionId, sessionToken, trustToken) through a Storage<String> under key SESSION_DATA, loaded at construction and written back after every request.
ICloudAccountBridgeHandler.dispose() only cancels jobs — it does not clear the persisted session state, and the handler's iCloudService/ICloudSession instance (holding the stale session in memory) is reused on the next initialize().
- openHAB's JSON storage service caches storage in memory, so the persisted session survives even a
bundle:restart of the binding — only a full openHAB restart re-reads the (deleted) storage file from disk.
Net effect: a stale session cannot be cleared at runtime. The binding keeps presenting session context Apple has already invalidated, in which state Apple does not deliver a 2FA code. The user's only workarounds are the delete-and-recreate ritual, or deleting /var/lib/openhab/jsondb/icloud%3Aaccount%3A<uid>.json and restarting openHAB.
Steps to reproduce
- Let the iCloud session expire / be invalidated (e.g. after an Apple auth-scheme change or password change).
- Bridge goes
OFFLINE (CONFIGURATION_ERROR).
- Disable → enable the thing: still offline, stale session reused.
bundle:restart the binding from the Karaf console: still offline (storage cache survives).
- Delete the thing and create a new one with the same credentials: fresh per-thing storage → fresh login → 2FA code delivered → online. Same result by deleting the jsondb storage file and restarting openHAB.
Proposed fix
In ICloudAccountBridgeHandler.dispose() (or on thing disable), remove the persisted session state (storage.remove(SESSION_DATA_KEY) / equivalent) and null out iCloudService, so the next initialize() starts a clean session and a complete re-authentication — making disable → enable a full recovery path without restarting openHAB and without recreating the thing.
Environment
- openHAB: 5.1.5-SNAPSHOT runtime (also observed on official 5.1.x/5.2.1)
- Binding:
org.openhab.binding.icloud 5.1.5.202605070733 (maihacke release 20425-sms-auth-1, includes the SRP and SMS-auth fixes)
- Account uses trusted-device + SMS 2FA; app-specific passwords not in use
Scope note
The 409/SMS-fallback defect originally described in this issue (section below) is already fixed by PR #21176 (merged 2026-07-15, milestone 5.3) —
getMfaAuthOptions()andrequestSmsCode()now treat 409 as part of the successful 2FA flow. This issue therefore remains open only for the session-storage/dispose gap, which #21176 does not address.Problem
When the iCloud session is invalidated by Apple (password change, security event, auth-scheme change), the
icloud:accountbridge cannot perform a fresh re-authentication without deleting/recreating the thing or restarting openHAB entirely. Disable → enable of the thing does not help, and restarting only the binding bundle does not help either.Root cause (from source analysis)
ICloudSessionpersists its session state (scnt,sessionId,sessionToken,trustToken) through aStorage<String>under keySESSION_DATA, loaded at construction and written back after every request.ICloudAccountBridgeHandler.dispose()only cancels jobs — it does not clear the persisted session state, and the handler'siCloudService/ICloudSessioninstance (holding the stale session in memory) is reused on the nextinitialize().bundle:restartof the binding — only a full openHAB restart re-reads the (deleted) storage file from disk.Net effect: a stale session cannot be cleared at runtime. The binding keeps presenting session context Apple has already invalidated, in which state Apple does not deliver a 2FA code. The user's only workarounds are the delete-and-recreate ritual, or deleting
/var/lib/openhab/jsondb/icloud%3Aaccount%3A<uid>.jsonand restarting openHAB.Steps to reproduce
OFFLINE (CONFIGURATION_ERROR).bundle:restartthe binding from the Karaf console: still offline (storage cache survives).Proposed fix
In
ICloudAccountBridgeHandler.dispose()(or on thing disable), remove the persisted session state (storage.remove(SESSION_DATA_KEY)/ equivalent) and null outiCloudService, so the nextinitialize()starts a clean session and a complete re-authentication — making disable → enable a full recovery path without restarting openHAB and without recreating the thing.Environment
org.openhab.binding.icloud5.1.5.202605070733 (maihacke release20425-sms-auth-1, includes the SRP and SMS-auth fixes)