Skip to content

fix: identify as akd in GSA requests to avoid HTTP 503 - #270

Closed
lonsdaleite wants to merge 2 commits into
malmeloo:mainfrom
lonsdaleite:fix/gsa-client-info-akd
Closed

lonsdaleite wants to merge 2 commits into
malmeloo:mainfrom
lonsdaleite:fix/gsa-client-info-akd

Conversation

@lonsdaleite

Copy link
Copy Markdown

Problem

Since early September 2026 every login fails on the very first GSA call ("o": "init", before any password or 2FA is used):

findmy.errors.UnhandledProtocolError: Error response for GSA request: 503

Reported in #268, #269, malmeloo/hass-FindMy#55; the same symptom is hitting other reimplementations of this protocol (dchristl/macless-haystack#245, parawanderer/OpenTagViewer#176).

Root cause

Apple's GSA edge now refuses any POST https://gsa.apple.com/grandslam/GsService2 whose X-MMe-Client-Info header names com.apple.dt.Xcode. The response is a 190-byte HTML page from the edge, not a GSA plist, and it does not depend on anisette data, account, IP or connection reuse. altstoreio/AltStore#1790 isolated the same thing by elimination (version bumps, user agent, hardware/OS portion of the header all make no difference; only the app bundle does).

Reproducible with plain curl, same request, only the bundle changed:

com.apple.dt.Xcode/3594.4.19  -> 503 (190 B HTML)
com.apple.akd/1.0             -> 404 (passes the edge; 404 only because the body is a stub plist)

_gsa_request already sends User-Agent: akd/1.0 ..., but X-MMe-Client-Info came from BaseAnisetteProvider.client, which says Xcode.

Fix

  • Add BaseAnisetteProvider.client_akd: same platform string as client, app bundle com.apple.akd/1.0.
  • Use it in _gsa_request, so both identity headers agree. Nothing else changes; the other requests (2FA endpoints, iCloud login) keep the Xcode client string.

Verification

Applied the same change to a Home Assistant 2026.9.1 install running FindMy 0.10.1 through hass-FindMy (remote anisette-v3-server). Login went from a 503 on every attempt to reaching 2FA and completing account setup.

lonsdaleite and others added 2 commits September 13, 2026 14:27
Apple's Grand Slam endpoint now refuses any request whose X-MMe-Client-Info
names com.apple.dt.Xcode, answering with a bare HTTP 503 before credentials
are checked. Every login therefore fails with
"UnhandledProtocolError: Error response for GSA request: 503".

_gsa_request already sends an akd user agent; send a matching client info
string via the new BaseAnisetteProvider.client_akd property. Other requests
keep using the Xcode client string.
@lonsdaleite
lonsdaleite marked this pull request as ready for review September 13, 2026 13:36
@malmeloo

Copy link
Copy Markdown
Owner

Thanks a lot, this looks promising. I'll test it out either today or tomorrow.

@malmeloo

Copy link
Copy Markdown
Owner

Fixed in #271, so this PR is now redundant. I chose to merge that one because it modifies the existing client string rather than adding a new one. We don't really have a reason to keep the Xcode one, in fact it would probably get confusing. But thanks for submitting a fix anyway!

@malmeloo malmeloo closed this Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants