Repository navigation
[AI-2131] Retire the machine pairing channel - #630
Conversation
A pairing that carries no token cannot authenticate a headless CLI, and the interactive path never needed one - it signs in moments later, so there is nothing to consent to. What remained was RFC 8628's device authorization grant with the payoff removed. WorkOS has shipped the real device grant since June 2025, which is what replaces this. The code is inert, so nothing here is a behaviour change for a user: the step already skipped on headless, --no-prompt and the None provider, treated 404/401/403/405 as "no channel here", and no deployed server serves the routes. It is also untagged - v0.11.28 predates it. - 8 of the 9 Auth/ files the original commit added. SystemBrowser.cs stays: LoopbackBrowser.cs:16 is its caller on the live OAuth path. - SetupCommand.cs loses step 1b, its two identity checks and the progress renderer. Steps stay numbered 1..6 - the pairing was "1b". - Models.cs's three JsonSerializable registrations, the PairingSecretHeader constant, and the setup copy in help-setup.txt and README.md. - Microsoft.Extensions.TimeProvider.Testing, which only BrowserPairingFlowTests used - TelemetryClientTests declares its own FakeTimeProvider. Design: docs/superpowers/specs/2026-08-19-ai2025-retire-pairing-design.md section 7, in kcap-server. The server half and the DROP follow there.
Code Review by Qodo🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)
Great, no issues found!Qodo reviewed your code and found no material issues that require reviewTip of the day💡 Did you know, you can copy the agent prompt from any finding and feed it to your IDE agent |
PR Summary by QodoRetire CLI machine pairing channel and remove setup-step remnants
AI Description
Diagram
High-Level Assessment
Files changed (6)
|
|
NO FINDINGS |
Deletes the CLI half of the machine pairing channel (#605). The server half never reached
main, and this half is untagged —v0.11.28predates it — so no released artefact contains any of it.A pairing that carries no token cannot authenticate a headless CLI, and the interactive path never needed one: it signs in moments later, so there is nothing to consent to. What remained was RFC 8628's device authorization grant with the payoff removed. WorkOS has shipped the real device grant since June 2025, which is what replaces this.
Nothing here changes behaviour for a user. The step already skipped on headless,
--no-promptand theNoneprovider,BrowserPairingFlowtreated 404/401/403/405 as "no channel here" and continued, and no deployed server serves the routes.Capacitor.Cli.Core/Auth/— 8 of the 9 files [AI-2027] Open the browser from setup and poll a machine pairing #605 added.SystemBrowser.csstays:LoopbackBrowser.cs:16is its caller on the live OAuth path, so deleting it would be a CS0103 on a shipped flow.SetupCommand.cs— loses step 1b, the two identity checks around it (AssertPairingIdentityAsync,CompletePairingAsync) and theSpectrePairingProgressrenderer. Step labels are untouched: the pairing was "1b", so 1..6 stand.Models.cs/HttpClientExtensions.cs— the threeJsonSerializableregistrations and thePairingSecretHeaderconstant.help-setup.txt/README.md— the "approving this machine" copy in both, and its quick-reference restatement.Capacitor.Cli.Core.Tests.Unit.csproj— dropsMicrosoft.Extensions.TimeProvider.Testing, which [AI-2027] Open the browser from setup and poll a machine pairing #605 added and onlyBrowserPairingFlowTestsused.TelemetryClientTestsdeclares its own localFakeTimeProviderand is unaffected.1,490 deletions, no insertions, against #605's +1512/−10.
Verified before deleting: every type declared in the removed files (
IPairingChannel,MintOutcome,PollOutcome,PairingContinuity,MintPairing*,PairingStatusResponse,PairingVerdict,IPairingProgress) is referenced only from within the delete set,SetupCommand.cs, orModels.cs.JwtPayloadhad exactly one caller,PairingIdentity.Capacitor.Cli.Core.Tests.Unitis green (1932 passed).Capacitor.Cli.Tests.Unithas one failure,LaunchdStartStopTests.WriteAndBootstrap_writes_the_unit_and_bootstraps_without_a_leading_bootout— confirmed pre-existing by stashing this change and re-running on a clean tree. It is environmental: the devcontainer's umask is0002, so the test's temp dir is created group-writable andServiceFiles.RequireNotWorldWritablerefuses it by design.Design:
docs/superpowers/specs/2026-08-19-ai2025-retire-pairing-design.md§7, inkcap-server. The server half, themachine_pairingsDROP and the feature gate follow there.