Skip to content

[Bug]: Authorized clients accumulates duplicate 'T3 Code Desktop' entries per relaunch #7977

Description

@ImBIOS

Description

Every bearer bootstrap exchange minted a brand-new auth_sessions row and sessions live for 30 days, so Settings → Authorized clients fills with duplicate "T3 Code Desktop" entries from repeated desktop launches, window reloads, and dev restarts — all from a single machine.

A heavy user sees dozens of stale authorized clients, all labeled "T3 Code Desktop" on the same host.

Root cause

  • exchangeBootstrapCredentialForAccessToken in apps/server/src/auth/EnvironmentAuth.ts calls sessions.issue() unconditionally — no client identity key.
  • DesktopLocalEnvironmentAuth (apps/desktop/src/backend/DesktopLocalEnvironmentAuth.ts) caches its bearer token in memory only (Ref), so every app relaunch adds a row that lingers for the 30-day TTL.
  • The web renderer's clientMetadata() in apps/web/src/connection/platform.ts does the same per window reload for secondary backends.
  • Nothing prunes expired or revoked rows, so auth_sessions grows forever.

Expected behavior

  • Clients present a stable per-install client_instance_id on /oauth/token exchanges.
  • Server reuses the existing compatible session (same subject + method + instance_id): extend expiry, re-sign token against the same row. No new row on relaunch.
  • Scope-widening issues a replacement and revokes the stale session.
  • DPoP exchanges are exempt (key thumbprint not persisted).
  • Issuance prunes expired and revoked rows.
  • Wire format is additive: clients that never send client_instance_id behave exactly as before.

Patch

Managed via fh as fix-auth-stop-accumulating-authorized-client-sessi-p5zy3k6c:

  • POST /oauth/token now accepts optional client_instance_id (contracts + deriveAuthClientMetadata + http handler)
  • Migration 041_AuthSessionClientInstanceId adds auth_sessions.client_instance_id
  • SessionStore.issue implements reuse-or-rotate + piggyback pruning
  • Desktop persists <stateDir>/client-instance-id, web uses localStorage, mobile uses secure storage

Verify:

pnpm exec vp test run apps/server/src/auth/SessionStore.test.ts
pnpm exec vp test run apps/server/src/server.test.ts -t "collapses repeated token exchanges"

Manual: pair once, restart the desktop app repeatedly — Settings → Authorized clients shows exactly one "T3 Code Desktop" row.

Tracking

Activity

  1. t3dotgg commented on Aug 27, 2026

    @t3dotgg
    Member

    Thanks for the detailed report. This looks like the same issue tracked in issue #6283.

    This is the same unconditional bootstrap-session creation and memory-only desktop token cache already documented in issue #6283. That earlier report includes database evidence and both macOS and Linux reproduction. The proposed stable instance ID is a repair design, not another defect. PR #7978 was closed without merge and must not be described as a fix.

    I'm closing this as a duplicate as part of an automated pass on all open issues. I linked this report from issue #6283 so its extra details remain available. This does not mean the underlying bug is fixed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions