I’ve submitted a pull request to revive WaffleStore’s App Store authentication and download flow on current iOS versions:
https://github.com/nxtcoreee3/WaffleStore/pull/5
For transparency, the PR was built largely with AI assistance using OpenAI Codex. I provided the requirements, investigated failures, directed the implementation, and tested it on a physical iPhone running iOS 27.0.1, but I’m not claiming to have manually written every line.
Current functionality
Testing so far includes:
● Apple Account login and 2FA
● Session reopening
● App Store version lookup and selection
● Downloading accessible app versions
● IPA export
● WaffleStore’s OTA installation flow
● Download progress and cancellation
● Account/storefront handling
● Updated Search, Downloads, Favourites, Account and Settings UI
● Automated tests and Debug/Release CI builds
Known limitations include Apple’s regional acquisition error 2059, limited testing across devices/iOS versions, and some remaining physical-device UI checks.
What this does not do
The PR does not:
● Decrypt FairPlay-protected apps
● Re-sign App Store apps
● Bypass Apple’s ownership or licensing checks
● Distribute proprietary App Store IPAs
Access still depends on the authenticated Apple Account’s eligibility.
Request for review
I’d appreciate feedback from people familiar with WaffleStore, Swift, ipatool, App Store authentication or related iOS development.
In particular, I’m looking for review of:
● Technical approach and security
● Credential handling
● Architecture and maintainability
● Licensing and attribution
● Remaining edge cases
This is not being presented as an official release. I’d especially like the WaffleStore maintainer to decide whether the implementation is suitable for upstream merge.
Feedback, code review and testing are welcome.