Skip to content

[Bug]: Headless connect page accepts malformed state and PKCE challenge values #4934

Description

@Zeus-Deus

Area

packages/shared / apps/web

Steps to reproduce

  1. Run t3 connect in a headless SSH session.
  2. Take the printed /connect#state=...&challenge=... URL.
  3. Insert an invalid character such as a space or │ into the state or challenge fragment value, simulating corruption while copying a visually wrapped URL from a terminal multiplexer.
  4. Open the modified URL in a browser.
  5. Complete the browser authorization flow.
  6. Paste the resulting code into the waiting CLI.

Expected behavior

The /connect page should reject the malformed request before opening the sign-in or authorization flow.

Because T3-generated values have known formats, the page can validate them before use:

  • state: 22 base64url characters
  • PKCE challenge: 43 base64url characters

The page should explain that the copied connect URL may be incomplete or corrupted and instruct the user to re-copy the freshly printed URL.

Actual behavior

The browser currently accepts any non-empty state and challenge, completes the authorization flow, and displays an authorization code.

The waiting CLI later rejects that code with:

That code belongs to a different connect request. Open the URL above and try again.

The CLI correctly fails closed, so this does not appear to bypass authorization. However, the malformed request is detected only after the full browser flow, and the resulting message does not identify likely URL corruption.

Impact

Minor bug or occasional failure. It can be confusing and difficult to diagnose when a long connect URL wraps in a narrow terminal and terminal UI characters are included during native text selection.

Environment

  • T3 Connect headless authorization over SSH
  • Narrow terminal viewport
  • Terminal multiplexer with visible pane frames

The problem is independently reproducible by manually inserting a non-base64url character, so it is not specific to one terminal application or multiplexer.

Workaround

Disable multiplexer pane frames, widen the terminal, or verify that copied state and challenge values contain only base64url characters before opening the URL.

Activity

  1. added a commit that references this issue on Aug 15, 2026
    f3886d7
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions