Skip to content

CLI auth pairing create writes tokens to wrong DB subdirectory (userdata vs dev) #112

Description

@harrryyd

Problem

t3 auth pairing create writes the pairing token to a subdirectory of the server's persistent state. The subdirectory depends on whether --dev-url is passed:

  • Without --dev-url: writes to userdata/ subdirectory
  • With --dev-url: writes to dev/ subdirectory

The dev server started with --dev-url http://localhost:5734 reads tokens from the dev/ subdirectory. If the token was minted without --dev-url, it was written to userdata/ and the dev server never sees it.

Impact

# This writes to userdata/ — token will be silently invalid against the dev server
node apps/server/src/bin.ts auth pairing create --base-dir ~/.t3-hcode

# This works correctly (writes to dev/)
node apps/server/src/bin.ts auth pairing create \
  --base-dir ~/.t3-hcode --dev-url http://localhost:5734

The pairing URL appears to work — the user pastes it into the browser, the pair page loads — but the token is never recognized by the server. No error or warning explains the mismatch.

Fix

At minimum, the CLI should print a warning when --dev-url is absent but the configured server uses one (or vice versa). Ideally, deriveServerPaths (apps/server/src/cli/config.ts:282) should surface the subdirectory choice in the pairing token output so the user can verify alignment.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingneeds-triageNeeds initial triage

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions