Skip to content

iOS TestFlight build 110 requests only legacy scopes from granular-auth nightlies #17256

Description

@martin-lacko-rebood

What happened

When connecting the iOS T3 Code Preview app through T3 Connect, the authorized mobile client receives only four scopes:

  • orchestration:read
  • orchestration:operate
  • terminal:operate
  • relay:read

As a result, source-control actions such as committing changes are unavailable. The desktop client has 16 scopes, while the connected iOS client consistently shows only four.

This previously worked. Revoking and reconnecting the iOS client does not restore the missing scopes, and there is no UI for changing them.

Diagnosis

The regression coincides with the granular authorization changes introduced in nightly v0.0.46-nightly.20261007.2761, including separating source-control write permissions.

The T3 Connect pairing grant contains the full standard permission set, including source-control:write. However, iOS TestFlight Preview 2.0.0 (110) narrows the token exchange to four legacy scopes. The server then stores those exact four permissions, leaving the mobile session unable to perform Git writes.

Re-pairing produces the same result, including through direct pairing.

PR #10298 was intended to keep older clients working across scope changes, but it does not appear to cover newly created sessions from this TestFlight build.

Current main-branch mobile code uses the expanded standard scopes, including source-control:write. This suggests that the TestFlight/OTA bundle is stale or that the new-session compatibility path is incomplete:

Steps to reproduce

  1. Run T3 Code Desktop Nightly with the granular authorization changes (.2761 or later).
  2. Install or open T3 Code Preview 2.0.0 (110) from TestFlight.
  3. Connect to the desktop environment through T3 Connect.
  4. Open Settings → Connections → Authorized clients on desktop.
  5. Observe that the iOS client has four scopes.
  6. Attempt to commit changes from iOS.
  7. Revoke and reconnect the client.

Expected: The Preview client requests the complete standard scope set, including source-control:write.

Actual: Every new session receives only four legacy scopes, so Git write actions are unavailable.

Version

  • Desktop: 0.0.46-nightly.20261008.2833
  • Desktop release commit: a6ec88f7a716fc421bd22c2484881c44110f9375
  • iOS Preview: 2.0.0 (110)
  • Regression boundary in authorization records: .2752 → .2761+

Environment

  • Host: macOS 27.0.0, arm64
  • Node.js: v24.21.0
  • Client: iOS, TestFlight Preview
  • Connection: T3 Connect managed relay

Evidence

# Active mobile session
client: T3 Connect connect
device: mobile / iOS
app: 2.0.0 (build 110)
authentication_method: dpop-access-token
granted_permission_count: 4

permissions:
  orchestration:read
  orchestration:operate
  terminal:operate
  relay:read

# Pairing grant consumed when creating the session
grant_permission_count: 13

grant includes:
  source-control:write
  filesystem:read
  filesystem:write

# Sessions from the same mobile build
2026-10-07 16:05Z  build 110 -> 5 legacy scopes (pre-granular server)
2026-10-07 18:41Z  build 110 -> 4 legacy scopes (post-granular server)
2026-10-08 17:15Z  build 110 -> 4 legacy scopes (latest reproduction)

Related issues

No exact existing issue was found. This is not a general relay connectivity failure: the connection succeeds, but the resulting authorization is too narrow.

Fix applied or workaround

No fix has been applied.

  • Re-pairing the current TestFlight build does not help.
  • Git operations can still be performed from the desktop client.
  • An updated TestFlight or OTA build containing the current standard scope list may resolve the problem.

Filed by

Codex (GPT-5) through T3 Code triage.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    duplicateThis issue or pull request already exists

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions