Repository navigation
fix(server): pairing tokens work on Node versions that cannot bind booleans - #16730
Conversation
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This one-line fix preserves pairing-scope logic while replacing boolean SQLite bindings with compatible integer values, addressing failures on affected Node versions. Because it changes authentication and pairing-token persistence behavior, the sensitive-authentication review requirement applies despite the narrow scope. You can add or adjust custom eligibility rules. Learn more. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughThe consume query now uses numeric values for its optional requested-scope condition. The overlap check remains unchanged. ChangesPairing link consumption
Priority: ➖ Normal Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to Pairing continues to handle omitted and supplied scopes as intended while avoiding boolean SQLite binds. No actionable user-facing risk remains before merge. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
Caution Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional.
❌ Failed checks (1 error)
✅ Passed checks (4 passed)
Full details: ApprovabilityExplanation The PR changes pairing behavior in
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
[Responding] on behalf of Anton (Claude Opus 5.5) Also hitting this on macOS arm64 with an installed server build (bundled Node 24.13.1), not just a dev server: every pairing link fails with It compounds with #9789: sessions paired before |
…oleans The pairing link consume query bound a JavaScript boolean. node:sqlite in Node 24.18.1 rejects that, so every one-time pairing failed with HTTP 500. package.json allows ^24.13.1. Bind 1 or 0 instead.
0dd644d to
16c0009
Compare
## What's Changed * fix(server): pairing tokens work on Node versions that cannot bind booleans by @chisewaguri in pingdotgg/t3code#16730 * fix(mobile): HTML pages in a thread no longer trap scrolling on Android by @SunkenInTime in pingdotgg/t3code#17211 * fix(web): centered scrollers no longer shift when the scrollbar appears by @maria-rcks in pingdotgg/t3code#17077 * fix(web): distinguish thread search matches from code tints by @Yash-Singh1 in pingdotgg/t3code#17263 * fix(server): Pi extension wakes get an owned continuation turn by @StiensWout in pingdotgg/t3code#17214 * fix(server): Pi discovers optional T3 tools on demand by @StiensWout in pingdotgg/t3code#17220 * fix(web): stack merge dialog closes as soon as you confirm by @flamboh in pingdotgg/t3code#17116 * fix(server): Pi editor dialogs prefill the answer composer by @StiensWout in pingdotgg/t3code#17206 * fix(desktop): generate valid User-Agent that follows RFC 9110 guidelines by @jztmanyl in pingdotgg/t3code#17264 * fix(server): Pi discovers workspace skills and commands by @StiensWout in pingdotgg/t3code#17190 * fix(mobile): preserve navigation after native swipe back by @juliusmarminge in pingdotgg/t3code#17268 * fix(server): keep newly discovered models out of legacy groups by @Bil0000 in pingdotgg/t3code#14314 * feat(editors): open remote projects in JetBrains IDEs over SSH by @juliusmarminge in pingdotgg/t3code#17271 * test(desktop): expect JetBrains IDEs among remote editors by @juliusmarminge in pingdotgg/t3code#17291 * fix(server): recognize authenticated GitHub Enterprise hosts by @alimek in pingdotgg/t3code#11059 * fix(connect): relay client updates itself and skips incompatible cloudflared by @juliusmarminge in pingdotgg/t3code#17275 * fix(shared): relay client install waits out a brief Windows file lock by @ScottN-PV in pingdotgg/t3code#16998 * fix(shared): release relay install locks on cancellation by @yashranaway in pingdotgg/t3code#10585 * chore(shared): bump managed cloudflared to 2026.10.0 by @bompus in pingdotgg/t3code#11184 * fix(shared): bound cloudflared download with 10-minute timeout by @kvnloo in pingdotgg/t3code#14139 * refactor(provider-core): add provider-core and provider-testing packages by @juliusmarminge in pingdotgg/t3code#17299 * refactor(settings): drop the legacy per-driver providers map by @juliusmarminge in pingdotgg/t3code#17300 * refactor(provider-pi): move Pi into its own provider package by @juliusmarminge in pingdotgg/t3code#17302 * feat(models): tell users when a CLI update unlocks a new model by @juliusmarminge in pingdotgg/t3code#17307 * fix(web): collapsed composer reserves room for wide send actions by @maria-rcks in pingdotgg/t3code#17016 * fix(muse): workflow subagents no longer stall on hidden approvals by @t3dotgg in pingdotgg/t3code#17329 ## New Contributors * @chisewaguri made their first contribution in pingdotgg/t3code#16730 * @jztmanyl made their first contribution in pingdotgg/t3code#17264 * @alimek made their first contribution in pingdotgg/t3code#11059 * @kvnloo made their first contribution in pingdotgg/t3code#14139 **Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261008.2833...v0.0.46-nightly.20261008.2849 Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261008.2849
## What's Changed * fix(server): pairing tokens work on Node versions that cannot bind booleans by @chisewaguri in pingdotgg/t3code#16730 * fix(mobile): HTML pages in a thread no longer trap scrolling on Android by @SunkenInTime in pingdotgg/t3code#17211 * fix(web): centered scrollers no longer shift when the scrollbar appears by @maria-rcks in pingdotgg/t3code#17077 * fix(web): distinguish thread search matches from code tints by @Yash-Singh1 in pingdotgg/t3code#17263 * fix(server): Pi extension wakes get an owned continuation turn by @StiensWout in pingdotgg/t3code#17214 * fix(server): Pi discovers optional T3 tools on demand by @StiensWout in pingdotgg/t3code#17220 * fix(web): stack merge dialog closes as soon as you confirm by @flamboh in pingdotgg/t3code#17116 * fix(server): Pi editor dialogs prefill the answer composer by @StiensWout in pingdotgg/t3code#17206 * fix(desktop): generate valid User-Agent that follows RFC 9110 guidelines by @jztmanyl in pingdotgg/t3code#17264 * fix(server): Pi discovers workspace skills and commands by @StiensWout in pingdotgg/t3code#17190 * fix(mobile): preserve navigation after native swipe back by @juliusmarminge in pingdotgg/t3code#17268 * fix(server): keep newly discovered models out of legacy groups by @Bil0000 in pingdotgg/t3code#14314 * feat(editors): open remote projects in JetBrains IDEs over SSH by @juliusmarminge in pingdotgg/t3code#17271 * test(desktop): expect JetBrains IDEs among remote editors by @juliusmarminge in pingdotgg/t3code#17291 * fix(server): recognize authenticated GitHub Enterprise hosts by @alimek in pingdotgg/t3code#11059 * fix(connect): relay client updates itself and skips incompatible cloudflared by @juliusmarminge in pingdotgg/t3code#17275 * fix(shared): relay client install waits out a brief Windows file lock by @ScottN-PV in pingdotgg/t3code#16998 * fix(shared): release relay install locks on cancellation by @yashranaway in pingdotgg/t3code#10585 * chore(shared): bump managed cloudflared to 2026.10.0 by @bompus in pingdotgg/t3code#11184 * fix(shared): bound cloudflared download with 10-minute timeout by @kvnloo in pingdotgg/t3code#14139 * refactor(provider-core): add provider-core and provider-testing packages by @juliusmarminge in pingdotgg/t3code#17299 * refactor(settings): drop the legacy per-driver providers map by @juliusmarminge in pingdotgg/t3code#17300 * refactor(provider-pi): move Pi into its own provider package by @juliusmarminge in pingdotgg/t3code#17302 * feat(models): tell users when a CLI update unlocks a new model by @juliusmarminge in pingdotgg/t3code#17307 * fix(web): collapsed composer reserves room for wide send actions by @maria-rcks in pingdotgg/t3code#17016 * fix(muse): workflow subagents no longer stall on hidden approvals by @t3dotgg in pingdotgg/t3code#17329 ## New Contributors * @chisewaguri made their first contribution in pingdotgg/t3code#16730 * @jztmanyl made their first contribution in pingdotgg/t3code#17264 * @alimek made their first contribution in pingdotgg/t3code#11059 * @kvnloo made their first contribution in pingdotgg/t3code#14139 **Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261008.2833...v0.0.46-nightly.20261008.2849 Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261008.2849
* fix(web): link pull requests to threads in folders that aren't Git repos (pingdotgg#15946) Co-authored-by: PR Batch Tester <agent@local.test> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(web): find messages and plans in the current thread (pingdotgg#10439) Co-authored-by: Yash Singh <saiansh2525@gmail.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(web): improve terminal scrollback navigation and snapshots (pingdotgg#17091) * docs(internals): add a checklist for adding a provider (pingdotgg#17229) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(mobile): keep native screens ordered during stack pops (pingdotgg#17231) * fix(server): pairing tokens work on Node versions that cannot bind booleans (pingdotgg#16730) * fix(mobile): HTML pages in a thread no longer trap scrolling on Android (pingdotgg#17211) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): centered scrollers no longer shift when the scrollbar appears (pingdotgg#17077) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): distinguish thread search matches from code tints (pingdotgg#17263) * fix(server): Pi extension wakes get an owned continuation turn (pingdotgg#17214) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): Pi discovers optional T3 tools on demand (pingdotgg#17220) * fix(web): stack merge dialog closes as soon as you confirm (pingdotgg#17116) * fix(server): Pi editor dialogs prefill the answer composer (pingdotgg#17206) * fix(desktop): generate valid User-Agent that follows RFC 9110 guidelines (pingdotgg#17264) * fix(server): Pi discovers workspace skills and commands (pingdotgg#17190) * fix(mobile): preserve navigation after native swipe back (pingdotgg#17268) * fix(server): keep newly discovered models out of legacy groups (pingdotgg#14314) Co-authored-by: PR Batch Tester <agent@local.test> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(editors): open remote projects in JetBrains IDEs over SSH (pingdotgg#17271) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * test(desktop): expect JetBrains IDEs among remote editors (pingdotgg#17291) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): recognize authenticated GitHub Enterprise hosts (pingdotgg#11059) Co-authored-by: Claude Code <noreply@anthropic.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> * fix(connect): relay client updates itself and skips incompatible cloudflared (pingdotgg#17275) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(shared): relay client install waits out a brief Windows file lock (pingdotgg#16998) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(shared): release relay install locks on cancellation (pingdotgg#10585) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * chore(shared): bump managed cloudflared to 2026.10.0 (pingdotgg#11184) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(shared): bound cloudflared download with 10-minute timeout (pingdotgg#14139) Co-authored-by: Kevin Rajan <kevin@kvnloo.dev> * refactor(provider-core): add provider-core and provider-testing packages (pingdotgg#17299) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(settings): drop the legacy per-driver providers map (pingdotgg#17300) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-pi): move Pi into its own provider package (pingdotgg#17302) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * feat(models): tell users when a CLI update unlocks a new model (pingdotgg#17307) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): collapsed composer reserves room for wide send actions (pingdotgg#17016) * fix(muse): workflow subagents no longer stall on hidden approvals (pingdotgg#17329) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-core): share attachment prompts, notifications, and event loggers (pingdotgg#17330) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): file previews handle downloads, in-page links, and repo paths, and favicons stop leaking internal hosts (pingdotgg#16950) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): environment-hosted browser tabs behave like a normal browser (pingdotgg#16963) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(desktop): browser tab fixes for fullscreen, shortcuts, links, reload and hidden tabs (pingdotgg#16961) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(web): desktop opens remote environments' browser tabs locally (pingdotgg#17316) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(desktop): the t3 command warns instead of installing behind another t3 (pingdotgg#17351) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): images, video, HTML and PDF preview in a thread before its first message (pingdotgg#17352) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-muse): move Muse Code into its own provider package (pingdotgg#17331) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): semantic branch naming hint lines up with its setting (pingdotgg#16972) * fix(mobile): restore chat image previews in the v5 stack (pingdotgg#17361) * feat(mobile): fade working threads and match web's status labels (pingdotgg#17368) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): agent browser tools stop bloating history, fall back sensibly, and respect ownership (pingdotgg#16956) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(web): add room for thread timeline markers (pingdotgg#17372) * fix(web): drop sidebar context before cancelling pointer drag (pingdotgg#17373) * refactor(providers): namespace-import service modules in core, Muse, Pi, and testing (pingdotgg#17375) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(auth): show connection permissions and enforce session lifetime (pingdotgg#17370) Co-authored-by: Bear Huddleston <bear@bearhuddleston.dev> * refactor(provider-opencode): move OpenCode into its own provider package (pingdotgg#17345) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-cursor): move Cursor into its own provider package (pingdotgg#17349) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-acp): move the shared ACP adapter into its own package (pingdotgg#17354) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-grok): move Grok into its own provider package (pingdotgg#17357) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): speed up long thread message sync (pingdotgg#17387) * fix(desktop): cancel backend pipe reads to avoid slow shutdown (pingdotgg#17386) * refactor(providers): adapter factories yield their services (pingdotgg#17381) * fix(web): show a row spinner instead of a banner when expanding a folder (pingdotgg#17378) * fix(server): a timed-out browser drag no longer exits the server (pingdotgg#17360) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): a logged-out Claude CLI no longer reports as authenticated (pingdotgg#15459) * fix(server): Pi loads every selected skill without losing prompt text (pingdotgg#17194) * fix(server): keep the Claude MCP token out of process arguments (pingdotgg#17408) * fix(server): reconcile Pi native session rewinds (pingdotgg#13839) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * test(provider-pi): cover continuation offers through the driver (pingdotgg#17407) * refactor(provider-acp-registry): move the ACP Registry into its own package (pingdotgg#17405) * fix(server): relay client updates no longer drop the host off T3 Connect (pingdotgg#17366) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com> Co-authored-by: PR Batch Tester <agent@local.test> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Co-authored-by: Jono Kemball <Noojuno@users.noreply.github.com> Co-authored-by: Yash Singh <saiansh2525@gmail.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com> Co-authored-by: chise <lqff.yt@gmail.com> Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com> Co-authored-by: maria <maria@kuuro.net> Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> Co-authored-by: oliver <97427849+flamboh@users.noreply.github.com> Co-authored-by: jztmanyl <jztmanyl@gmail.com> Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com> Co-authored-by: Grzegorz Mandziak <4248465+alimek@users.noreply.github.com> Co-authored-by: Scott Norteman <snorteman@gmail.com> Co-authored-by: Aditya Garud <153842990+yashranaway@users.noreply.github.com> Co-authored-by: Aaron Queen <bompus@users.noreply.github.com> Co-authored-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com> Co-authored-by: Kevin Rajan <kevin@kvnloo.dev> Co-authored-by: Theo Browne <me@t3.gg> Co-authored-by: Daniel Alvim <danielalvim@tuta.io> Co-authored-by: Bear Huddleston <bear@bearhuddleston.dev> Co-authored-by: Yordis Prieto <yordis.prieto@gmail.com>
Range personal f93ae9c + origin/main 6497246, merge base 611132c. 57 conflicts (52 content, 3 modify/delete, 2 rename/delete), 192 upstream renames. Shape: upstream moved every provider but Codex and Claude into packages (provider-core/acp/acp-registry/cursor/grok/opencode/pi/muse/testing), drivers read settings through ProviderHost, and pingdotgg#17300 dropped the legacy providers settings map. Resolutions: - Fork-only files re-pointed at moved modules by package specifier (git rename map). - Legacy providers map: upstream's migration taken; fork patch mirrors and their tests (configDirPath, outputStyle, Codex setupMode) removed; trust rule follows upstream's decode. - Scoped settings: upstream's per-environment failure messages replace the fork's refusal copy. - Composer: upstream's Compact/Full chip and measured resting padding; fork send/stop row, offline-queue label and threadPanelSummary kept; attention dot dropped with upstream. - Migrations: upstream 059/060 applied as ids 68/69; preview-migration test stays rejected. - AuthPairingLinks: upstream pingdotgg#16730 fixed the boolean bind itself; fork patch retired. - ClaudeDriver offer-to-compact setting reads host.settings; tests build on ProviderHostLive. - OpenCodeRuntime back to upstream's inline encoder; fork diagnosticsJson.ts deleted. - Find-highlight cases (pingdotgg#10439) split into a jsdom file, as upstream runs them. - UsageService v4-upgrade test awaits its second persist (temp-dir removal race). Invariants: all re-probed; pingdotgg#38 caught resolveClaudeCatalogContextWindow losing export again. Sweeps (mid-merge): resurrected 4, dropped 283, fork-loss 370, both-kept 0; after filtering relocations, every residual line tied to a resolution (resurrected: 2 lockfile, 2 upstream test lines ported to the fork's fold-aware toggle helper). Gate: pnpm verify EXIT=0, 23/23 test packages, 25,310 tests, 0 failed (Node 24.16). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Problem
One-time pairing fails with HTTP 500 on Node 24.18.1.
AuthPairingLinkRepository.consumeAvailablebindsrequestedScopes === undefined, a JavaScript boolean, andnode:sqlitein that version rejects it withProvided value cannot be bound to SQLite parameter 5. The pairing page shows "Primary environment request failed during exchange-bootstrap-credential (HTTP 500)".package.jsonallows^24.13.1. CI resolves to 24.21.0, which accepts booleans, so CI passed when #9785 added the bind.Change
Bind
1or0instead of the boolean. SQLite has no boolean type, so theORcheck behaves the same.Scope and approval
This is a one-line fix for an obvious regression from #9785. Pairing a browser or phone with a one-time token fails on any Node version that rejects boolean binds.
Verification
vp test run apps/server/src/auth/PairingGrantStore.test.tsfails 6 of 10 tests onmainwith the bind error and passes 10 of 10 with this change.node:sqlitewithprepare("select ? as v").get(true): Node 24.18.1 throwsProvided value cannot be bound to SQLite parameter 1, and Node 24.21.0 returns{ v: 1 }./api/auth/browser-session.