Before submitting
Area
apps/server
Steps to reproduce
- Run the server from
main (e.g. vp run dev) on Node 24.
- Pair a client with any one-time pairing token stored in the database: the startup pairing URL, a token from
node apps/server/src/bin.ts pair, or a link issued from Connections settings.
Or run the existing tests: vp test run src/auth/PairingGrantStore.test.ts in apps/server. Five tests fail, including "issues one-time bootstrap tokens that can only be consumed once".
Expected behavior
A valid token pairs the client. An unknown or used token is rejected as unknown.
Actual behavior
POST /api/auth/browser-session returns HTTP 500 with browser_session_issuance_failed, so the client cannot pair at all.
Cause: #10298 changed the consume query in apps/server/src/persistence/AuthPairingLinks.ts to bind ${requestedScopes === undefined}, a raw JavaScript boolean. node:sqlite rejects boolean parameters before Node 24.21.0 ("Provided value cannot be bound to SQLite parameter"), so the UPDATE ... RETURNING fails for every database-backed token. Boolean binding arrived in nodejs/node#62001, backported to 24.21.0. CI and the desktop app (Electron 44.4.2) both run Node 24.21.0, which is why the tests pass there, but engines allows ^24.13.1, so npx t3 and dev servers on Node 24.13.1–24.20.x hit this. The server's other boolean parameters are bound as 1/0 (? 1 : 0 or Schema.BooleanFromBit).
Impact
Major degradation or frequent failure
Version or commit
main @ cd41c4a
Environment
Arch Linux, Node 24.18.0, server started with vp run dev
Logs or stack traces
ERROR environment api operation failed
reason: 'browser_session_issuance_failed'
cause: {
_tag: 'ServerAuthBootstrapCredentialValidationError',
cause: { _tag: 'BootstrapCredentialConsumeAvailableError', cause: [Object] }
}
POST /api/auth/browser-session -> 500
# node:sqlite directly:
Provided value cannot be bound to SQLite parameter 3.
Workaround
None for database-backed tokens. Binding 1/0 in the query fixes it.
Before submitting
Area
apps/server
Steps to reproduce
main(e.g.vp run dev) on Node 24.node apps/server/src/bin.ts pair, or a link issued from Connections settings.Or run the existing tests:
vp test run src/auth/PairingGrantStore.test.tsinapps/server. Five tests fail, including "issues one-time bootstrap tokens that can only be consumed once".Expected behavior
A valid token pairs the client. An unknown or used token is rejected as unknown.
Actual behavior
POST /api/auth/browser-sessionreturns HTTP 500 withbrowser_session_issuance_failed, so the client cannot pair at all.Cause: #10298 changed the consume query in
apps/server/src/persistence/AuthPairingLinks.tsto bind${requestedScopes === undefined}, a raw JavaScript boolean.node:sqliterejects boolean parameters before Node 24.21.0 ("Provided value cannot be bound to SQLite parameter"), so theUPDATE ... RETURNINGfails for every database-backed token. Boolean binding arrived in nodejs/node#62001, backported to 24.21.0. CI and the desktop app (Electron 44.4.2) both run Node 24.21.0, which is why the tests pass there, butenginesallows^24.13.1, sonpx t3and dev servers on Node 24.13.1–24.20.x hit this. The server's other boolean parameters are bound as1/0(? 1 : 0orSchema.BooleanFromBit).Impact
Major degradation or frequent failure
Version or commit
main @ cd41c4a
Environment
Arch Linux, Node 24.18.0, server started with
vp run devLogs or stack traces
Workaround
None for database-backed tokens. Binding
1/0in the query fixes it.