Skip to content

fix(server): pairing links no longer fail with HTTP 500 - #16799

Closed
BOTKooper wants to merge 1 commit into
pingdotgg:mainfrom
BOTKooper:fix/pairing-link-boolean-binding
Closed

BOTKooper wants to merge 1 commit into
pingdotgg:mainfrom
BOTKooper:fix/pairing-link-boolean-binding

Conversation

@BOTKooper

@BOTKooper BOTKooper commented Oct 7, 2026 •

Copy link
Copy Markdown

Problem

Since #10298, pairing any client with a database-backed token fails with HTTP 500 (browser_session_issuance_failed). The pairing-link consume query binds ${requestedScopes === undefined}, a raw JavaScript boolean, and node:sqlite rejects boolean parameters before Node 24.21.0. Boolean binding arrived in nodejs/node#62001, backported to 24.21.0, so CI and the desktop app (both on 24.21.0) never saw it, but engines allows ^24.13.1. Fixes #16797.

Change

Bind 1/0 instead (${requestedScopes === undefined ? 1 : 0}), the same way the server's other queries bind booleans.

Scope and approval

Tracked in #16797. A one-line fix for a pairing regression: it restores the query's intended behavior and changes nothing else.

Verification

  • apps/server/src/auth/PairingGrantStore.test.ts already covers this path. On main with Node 24.18.0, five of its tests fail (e.g. "issues one-time bootstrap tokens that can only be consumed once"). With this change, all 10 pass.
  • Manual: on a dev server, POST /api/auth/browser-session with a valid unused token returned 500 before and 200 after. A browser then paired over the tailnet with the startup pairing link.

Done with Claude Opus 5.5 in Claude Code, running inside T3 Code.

The pairing-link consume query bound a raw JavaScript boolean
(`${requestedScopes === undefined}`), which node:sqlite rejects, so every
database-backed pairing token failed with browser_session_issuance_failed.
Bind 1/0 like the server's other boolean parameters.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@BOTKooper

Copy link
Copy Markdown
Author

Closing in favour of #16730, which was opened first and makes the same one-line fix.

@BOTKooper BOTKooper closed this Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS 0-9 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Pairing fails with HTTP 500 since #10298 because the consume query binds a boolean

1 participant