Skip to content

[Bug]: Pairing fails with HTTP 500 since #10298 because the consume query binds a boolean #16797

Description

@BOTKooper

Before submitting

  • I searched existing issues and did not find a duplicate.
  • I included enough detail to reproduce or investigate the problem.

Area

apps/server

Steps to reproduce

  1. Run the server from main (e.g. vp run dev) on Node 24.
  2. Pair a client with any one-time pairing token stored in the database: the startup pairing URL, a token from node apps/server/src/bin.ts pair, or a link issued from Connections settings.

Or run the existing tests: vp test run src/auth/PairingGrantStore.test.ts in apps/server. Five tests fail, including "issues one-time bootstrap tokens that can only be consumed once".

Expected behavior

A valid token pairs the client. An unknown or used token is rejected as unknown.

Actual behavior

POST /api/auth/browser-session returns HTTP 500 with browser_session_issuance_failed, so the client cannot pair at all.

Cause: #10298 changed the consume query in apps/server/src/persistence/AuthPairingLinks.ts to bind ${requestedScopes === undefined}, a raw JavaScript boolean. node:sqlite rejects boolean parameters before Node 24.21.0 ("Provided value cannot be bound to SQLite parameter"), so the UPDATE ... RETURNING fails for every database-backed token. Boolean binding arrived in nodejs/node#62001, backported to 24.21.0. CI and the desktop app (Electron 44.4.2) both run Node 24.21.0, which is why the tests pass there, but engines allows ^24.13.1, so npx t3 and dev servers on Node 24.13.1–24.20.x hit this. The server's other boolean parameters are bound as 1/0 (? 1 : 0 or Schema.BooleanFromBit).

Impact

Major degradation or frequent failure

Version or commit

main @ cd41c4a

Environment

Arch Linux, Node 24.18.0, server started with vp run dev

Logs or stack traces

ERROR environment api operation failed
  reason: 'browser_session_issuance_failed'
  cause: {
    _tag: 'ServerAuthBootstrapCredentialValidationError',
    cause: { _tag: 'BootstrapCredentialConsumeAvailableError', cause: [Object] }
  }
POST /api/auth/browser-session -> 500

# node:sqlite directly:
Provided value cannot be bound to SQLite parameter 3.

Workaround

None for database-backed tokens. Binding 1/0 in the query fixes it.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions