Skip to content

feat(cli): init apns --reset signs in to Apple again - #1999

Merged
ArnabChatterjee20k merged 2 commits into
messaging-provider-cli-apnsfrom
messaging-provider-cli-apns-reset
Oct 9, 2026
Merged

ArnabChatterjee20k merged 2 commits into
messaging-provider-cli-apnsfrom
messaging-provider-cli-apns-reset

Conversation

@ArnabChatterjee20k

Copy link
Copy Markdown
Member

Stacked on #1963. Adds init apns --reset, so you can sign in to Apple again without deleting files by hand.

Why

A saved Apple sign-in is reused until Apple expires it, about 30 days. Until now the only way to sign in again, or to switch to another Apple ID, was to delete ~/.appwrite/apns/<setup>/session.json by hand.

What

appwrite init apns --reset
  • Signs in from scratch: Apple ID, password and two-factor code. APPWRITE_APPLE_ID / APPWRITE_APPLE_PASSWORD still answer the first two. The new session replaces the saved one, so later runs reuse it.
  • Implies --create-key: signing in is only for creating a key. It doesn't stop at "APNs is already set up", and it can't be combined with --key-path or --key-id.
  • Prints Signing in again: the saved Apple sign-in is not used (--reset).
Setup What --reset does
appwrite Loads none of the saved cookies, not even the one that marks the machine as trusted, so Apple asks for a code. The new session overwrites session.json.
expo The helper calls apple-utils' Auth.logoutAsync, which deletes its saved session for that Apple ID in ~/.app-store/, before signing in.
fastlane The lane deletes spaceship's saved session for that Apple ID (PortalClient#persistent_cookie_path, under ~/.fastlane/spaceship/) before Spaceship::Portal.login.

apns.Request gains Reset bool, so each setup handles it in its own way.

Tests

  • TestInitApnsResetSignsInAgainAndCreatesAKey: on an already set-up app, --reset alone (no --create-key or --force) creates a key with Request.Reset, writes it to the providers and logs the reset. --reset with --key-path is rejected.
  • TestResetSignsInAgain (appwrite, fake Apple with real SRP):
    • after a normal sign-in, a reset run does the password check and asks for a code again
    • a following normal run reuses the new session with no sign-in
  • TestCreateKeyPassesResetToTheHelper (expo) and TestCreateKeyPassesResetToTheLane (fastlane): the flag reaches the helper and the lane.
  • Full CLI suite (-race), gofmt, the WebAssembly browser build, GOOS=windows go vet, ruby -c on the Fastfile and node --check on the helper all pass.

A saved Apple sign-in was reused until Apple expired it, and the only
way to sign in again, or as another Apple ID, was to delete a file by
hand. --reset signs in from scratch, two-factor included, and the new
session replaces the saved one. It implies --create-key, as signing in
is only for creating a key, so it is not stopped by APNs being set up
already, and it cannot be combined with --key-path or --key-id.

apns.Request gains Reset. The appwrite setup loads none of the saved
cookies, not even the one that marks the machine as trusted. The expo
helper runs apple-utils' Auth.logoutAsync, which deletes its saved
session for the Apple ID, and the fastlane lane deletes spaceship's
saved session for the Apple ID before signing in.
@hansi-codes

hansi-codes Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

🟢 Tier S · Ready to merge

The incremental changes have no actionable defects.

Adds appwrite init apns --reset to sign in to Apple again and create a replacement APNs key, with reset handling for the appwrite, Expo, and fastlane setups. The CLI treats reset as key creation, validates incompatible flags, and continues to save the created key and configure push providers. The tests cover the CLI flow, adapter reset propagation, and session reuse for the appwrite setup.

Latest changes: The latest commits make the Expo adapter ask for a missing Apple ID before starting a reset and pass it to the helper, with tests for prompted and already-provided IDs.

Verdict New comments Fixed Still open
✅ Approved 0 0 0
📂 Walkthrough · 11
File Change
templates/cli/internal/apns/apns.go Adds Reset to the APNs key-creation request.
templates/cli/internal/apns/appwrite/adapter.go Bypasses saved cookies on reset so the appwrite adapter signs in again.
templates/cli/internal/apns/appwrite/adapter_test.go Tests a fresh reset sign-in and reuse of the newly saved session.
templates/cli/internal/apns/expo/adapter.go Forwards reset to the helper and prompts for a missing Apple ID before reset.
templates/cli/internal/apns/expo/adapter_test.go Tests reset forwarding and the Apple ID prompt behavior.
templates/cli/internal/apns/expo/helper/helper.js Logs out of the saved apple-utils session before reset sign-in.
templates/cli/internal/apns/fastlane/adapter.go Passes reset and credentials through to the fastlane lane.
templates/cli/internal/apns/fastlane/adapter_test.go Tests reset argument forwarding to fastlane.
templates/cli/internal/apns/fastlane/helper/Fastfile Deletes the saved spaceship session before reset sign-in.
templates/cli/internal/cmd/initpush.go Adds the reset flag, constraints, and flow that creates and configures a replacement key.
templates/cli/internal/cmd/initpush_test.go Tests reset key creation on an already-configured app and rejects incompatible flags.

Reviewed the commits since 2b546c1 · Details · Comment @hansi-codes review to re-run, or mention @hansi-codes with a question.

@hansi-codes hansi-codes Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Tier S · Looks good to merge. Summary

With --reset and no APPWRITE_APPLE_ID, the expo setup asked for the
Apple ID twice: apple-utils' Auth.logoutAsync asks for it to find the
session and forgets it, and the sign-in that follows asked again. The
adapter now asks once and passes it as EXPO_APPLE_ID, which both read
(resolveCredentialsAsync takes the given username, then EXPO_APPLE_ID,
and prompts only without either).
@ArnabChatterjee20k
ArnabChatterjee20k merged commit e7cdbea into messaging-provider-cli-apns Oct 9, 2026
52 of 61 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant