Skip to content

[AI-2131] Retire the machine pairing channel - #630

Merged
George-Payne merged 1 commit into
mainfrom
georgepayne/ai-2131-retire-pairing
Aug 20, 2026
Merged

George-Payne merged 1 commit into
mainfrom
georgepayne/ai-2131-retire-pairing

Conversation

@George-Payne

Copy link
Copy Markdown
Member

Deletes the CLI half of the machine pairing channel (#605). The server half never reached main, and this half is untagged — v0.11.28 predates it — so no released artefact contains any of it.

A pairing that carries no token cannot authenticate a headless CLI, and the interactive path never needed one: it signs in moments later, so there is nothing to consent to. What remained was RFC 8628's device authorization grant with the payoff removed. WorkOS has shipped the real device grant since June 2025, which is what replaces this.

Nothing here changes behaviour for a user. The step already skipped on headless, --no-prompt and the None provider, BrowserPairingFlow treated 404/401/403/405 as "no channel here" and continued, and no deployed server serves the routes.

  • Capacitor.Cli.Core/Auth/ — 8 of the 9 files [AI-2027] Open the browser from setup and poll a machine pairing #605 added. SystemBrowser.cs stays: LoopbackBrowser.cs:16 is its caller on the live OAuth path, so deleting it would be a CS0103 on a shipped flow.
  • SetupCommand.cs — loses step 1b, the two identity checks around it (AssertPairingIdentityAsync, CompletePairingAsync) and the SpectrePairingProgress renderer. Step labels are untouched: the pairing was "1b", so 1..6 stand.
  • Models.cs / HttpClientExtensions.cs — the three JsonSerializable registrations and the PairingSecretHeader constant.
  • help-setup.txt / README.md — the "approving this machine" copy in both, and its quick-reference restatement.
  • Capacitor.Cli.Core.Tests.Unit.csproj — drops Microsoft.Extensions.TimeProvider.Testing, which [AI-2027] Open the browser from setup and poll a machine pairing #605 added and only BrowserPairingFlowTests used. TelemetryClientTests declares its own local FakeTimeProvider and is unaffected.

1,490 deletions, no insertions, against #605's +1512/−10.

Verified before deleting: every type declared in the removed files (IPairingChannel, MintOutcome, PollOutcome, PairingContinuity, MintPairing*, PairingStatusResponse, PairingVerdict, IPairingProgress) is referenced only from within the delete set, SetupCommand.cs, or Models.cs. JwtPayload had exactly one caller, PairingIdentity.

Capacitor.Cli.Core.Tests.Unit is green (1932 passed). Capacitor.Cli.Tests.Unit has one failure, LaunchdStartStopTests.WriteAndBootstrap_writes_the_unit_and_bootstraps_without_a_leading_bootout — confirmed pre-existing by stashing this change and re-running on a clean tree. It is environmental: the devcontainer's umask is 0002, so the test's temp dir is created group-writable and ServiceFiles.RequireNotWorldWritable refuses it by design.

Design: docs/superpowers/specs/2026-08-19-ai2025-retire-pairing-design.md §7, in kcap-server. The server half, the machine_pairings DROP and the feature gate follow there.

A pairing that carries no token cannot authenticate a headless CLI, and the
interactive path never needed one - it signs in moments later, so there is
nothing to consent to. What remained was RFC 8628's device authorization grant
with the payoff removed. WorkOS has shipped the real device grant since June
2025, which is what replaces this.

The code is inert, so nothing here is a behaviour change for a user: the step
already skipped on headless, --no-prompt and the None provider, treated
404/401/403/405 as "no channel here", and no deployed server serves the routes.
It is also untagged - v0.11.28 predates it.

- 8 of the 9 Auth/ files the original commit added. SystemBrowser.cs stays:
  LoopbackBrowser.cs:16 is its caller on the live OAuth path.
- SetupCommand.cs loses step 1b, its two identity checks and the progress
  renderer. Steps stay numbered 1..6 - the pairing was "1b".
- Models.cs's three JsonSerializable registrations, the PairingSecretHeader
  constant, and the setup copy in help-setup.txt and README.md.
- Microsoft.Extensions.TimeProvider.Testing, which only BrowserPairingFlowTests
  used - TelemetryClientTests declares its own FakeTimeProvider.

Design: docs/superpowers/specs/2026-08-19-ai2025-retire-pairing-design.md section 7,
in kcap-server. The server half and the DROP follow there.
@George-Payne George-Payne self-assigned this Aug 20, 2026
@linear-code

linear-code Bot commented Aug 20, 2026

Copy link
Copy Markdown

AI-2131

@qodo-code-review

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can copy the agent prompt from any finding and feed it to your IDE agent

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Retire CLI machine pairing channel and remove setup-step remnants

✨ Enhancement 📝 Documentation 🧪 Tests ⚙️ Configuration changes 🕐 20-40 Minutes

Grey Divider

AI Description

• Remove unused machine-pairing setup step and its client-side channel implementation.
• Drop pairing wire models/JSON registrations and related header constant.
• Delete pairing docs text and remove now-unused unit-test dependency.
Diagram

graph TD
  SC["SetupCommand"] --> Auth["OAuth login flow"]
  SC --> JsonCtx["JSON source-gen"]
  SC --> Docs["Docs: setup copy"]
  SC -. "removed step 1b" .-> Pairing["Pairing channel (deleted)"]
  Pairing --> Tests["Core unit tests"] --> Dep["TimeProvider.Testing (removed)"]
Loading
High-Level Assessment

Given the server-side pairing channel never shipped and the intended replacement is WorkOS’s real device grant, removing the inert CLI pairing channel is the simplest and lowest-maintenance option. Alternatives like keeping stubs/feature flags would preserve dead surface area without providing user value.

Files changed (6) +0 / -192

Refactor (3) +0 / -168
HttpClientExtensions.csDrop pairing secret header constant +0/-4

Drop pairing secret header constant

• Removes 'PairingSecretHeader' since pairing requests/polls are no longer issued by the CLI.

src/Capacitor.Cli.Core/HttpClientExtensions.cs

Models.csRemove pairing DTO JsonSerializable registrations +0/-3

Remove pairing DTO JsonSerializable registrations

• Deletes source-generator registrations for the pairing request/response DTOs, reflecting removal of the pairing channel contracts.

src/Capacitor.Cli.Core/Models.cs

SetupCommand.csRemove setup step 1b pairing flow and continuity checks +0/-161

Remove setup step 1b pairing flow and continuity checks

• Eliminates the browser pairing step, including its progress renderer, approval/expiry handling, post-login identity continuity check, and final completion call. Setup proceeds directly from Step 1 (Server) to Step 2 (Login), keeping step numbering 1..6 intact.

src/Capacitor.Cli/Commands/SetupCommand.cs

Documentation (2) +0 / -23
README.mdRemove machine-approval/pairing setup documentation +0/-14

Remove machine-approval/pairing setup documentation

• Deletes the README sections describing the browser pairing approval code and identity check during 'kcap setup'. The rest of the setup flow documentation remains unchanged.

README.md

help-setup.txtRemove pairing/approval copy from setup help text +0/-9

Remove pairing/approval copy from setup help text

• Deletes the help text describing the browser-based approval step and code comparison during setup.

src/Capacitor.Cli.Core/Resources/help-setup.txt

Other (1) +0 / -1
Capacitor.Cli.Core.Tests.Unit.csprojRemove unused TimeProvider.Testing package reference +0/-1

Remove unused TimeProvider.Testing package reference

• Drops 'Microsoft.Extensions.TimeProvider.Testing', which was only used by now-deleted pairing flow tests.

test/Capacitor.Cli.Core.Tests.Unit/Capacitor.Cli.Core.Tests.Unit.csproj

@realtonyyoung

Copy link
Copy Markdown
Collaborator

NO FINDINGS

@George-Payne
George-Payne merged commit d4de51e into main Aug 20, 2026
6 checks passed
@George-Payne
George-Payne deleted the georgepayne/ai-2131-retire-pairing branch August 20, 2026 15:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants