Skip to content

[icloud] Clear persisted session storage on dispose so disable/enable performs a full 2FA re-authentication #21796

Description

@powerk1977

Scope note

The 409/SMS-fallback defect originally described in this issue (section below) is already fixed by PR #21176 (merged 2026-07-15, milestone 5.3) — getMfaAuthOptions() and requestSmsCode() now treat 409 as part of the successful 2FA flow. This issue therefore remains open only for the session-storage/dispose gap, which #21176 does not address.

Problem

When the iCloud session is invalidated by Apple (password change, security event, auth-scheme change), the icloud:account bridge cannot perform a fresh re-authentication without deleting/recreating the thing or restarting openHAB entirely. Disable → enable of the thing does not help, and restarting only the binding bundle does not help either.

Root cause (from source analysis)

  1. ICloudSession persists its session state (scnt, sessionId, sessionToken, trustToken) through a Storage<String> under key SESSION_DATA, loaded at construction and written back after every request.
  2. ICloudAccountBridgeHandler.dispose() only cancels jobs — it does not clear the persisted session state, and the handler's iCloudService/ICloudSession instance (holding the stale session in memory) is reused on the next initialize().
  3. openHAB's JSON storage service caches storage in memory, so the persisted session survives even a bundle:restart of the binding — only a full openHAB restart re-reads the (deleted) storage file from disk.

Net effect: a stale session cannot be cleared at runtime. The binding keeps presenting session context Apple has already invalidated, in which state Apple does not deliver a 2FA code. The user's only workarounds are the delete-and-recreate ritual, or deleting /var/lib/openhab/jsondb/icloud%3Aaccount%3A<uid>.json and restarting openHAB.

Steps to reproduce

  1. Let the iCloud session expire / be invalidated (e.g. after an Apple auth-scheme change or password change).
  2. Bridge goes OFFLINE (CONFIGURATION_ERROR).
  3. Disable → enable the thing: still offline, stale session reused.
  4. bundle:restart the binding from the Karaf console: still offline (storage cache survives).
  5. Delete the thing and create a new one with the same credentials: fresh per-thing storage → fresh login → 2FA code delivered → online. Same result by deleting the jsondb storage file and restarting openHAB.

Proposed fix

In ICloudAccountBridgeHandler.dispose() (or on thing disable), remove the persisted session state (storage.remove(SESSION_DATA_KEY) / equivalent) and null out iCloudService, so the next initialize() starts a clean session and a complete re-authentication — making disable → enable a full recovery path without restarting openHAB and without recreating the thing.

Environment

  • openHAB: 5.1.5-SNAPSHOT runtime (also observed on official 5.1.x/5.2.1)
  • Binding: org.openhab.binding.icloud 5.1.5.202605070733 (maihacke release 20425-sms-auth-1, includes the SRP and SMS-auth fixes)
  • Account uses trusted-device + SMS 2FA; app-specific passwords not in use

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions