Repository navigation
feat(connect): manage account hosts and renew authorization reliably - #359
Conversation
Adapt upstream single-flight HTTP renewal, isolate account credentials, issue fresh CLI reconnect tickets, and add explicit cross-client deregistration. Harden browser pairing/CORS compatibility and Windows secret-store ACLs. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
🟡 Changes recommended
The hosted route is incorrectly tied to CLI OAuth configuration, and non-schema RPC defects are incorrectly made non-retryable.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Adds account-wide T3 Connect environment management and strengthens authorization, reconnect, compatibility, and Windows secret-storage behavior.
Changes:
- Adds hosted, mobile, and CLI environment deregistration.
- Introduces account-bound DPoP renewal and fresh reconnect tickets.
- Adds DPoP CORS/replay coverage and Windows ACL protection.
File summaries
| File | Description |
|---|---|
packages/shared/src/connectManagement.ts |
Adds shared management guidance. |
packages/shared/package.json |
Exports management constants. |
packages/client-runtime/src/state/threadSnapshotHttp.ts |
Uses renewable authenticated reads. |
packages/client-runtime/src/state/shellSnapshotHttp.ts |
Uses renewable authenticated reads. |
packages/client-runtime/src/state/pullRequestDiffHttp.ts |
Renews read-only POST authorization. |
packages/client-runtime/src/state/environmentHttpAuth.ts |
Implements HTTP renewal and retry. |
packages/client-runtime/src/state/environmentHttpAuth.test.ts |
Tests renewal behavior. |
packages/client-runtime/src/rpc/session.ts |
Classifies configuration failures. |
packages/client-runtime/src/rpc/session.test.ts |
Tests malformed configuration. |
packages/client-runtime/src/connection/resolver.ts |
Passes relay identity context. |
packages/client-runtime/src/connection/model.ts |
Adds renewable authorization callback. |
packages/client-runtime/src/connection/errors.ts |
Maps incompatible responses. |
packages/client-runtime/src/authorization/tokenStore.ts |
Persists token ownership metadata. |
packages/client-runtime/src/authorization/service.ts |
Adds scoped single-flight authorization. |
packages/client-runtime/src/authorization/layer.test.ts |
Tests isolation and renewal. |
docs/background-service.md |
Documents management and security behavior. |
apps/web/vite.config.ts |
Exposes hosted relay configuration. |
apps/web/src/routeTree.gen.ts |
Registers account-management route. |
apps/web/src/routes/pair.tsx |
Revalidates after pairing. |
apps/web/src/routes/connect_.environments.tsx |
Adds hosted management route. |
apps/web/src/routes/__root.tsx |
Exempts hosted management from local auth. |
apps/web/src/environments/primary/auth.ts |
Bootstraps authenticated state immediately. |
apps/web/src/components/settings/ConnectionsSettings.tsx |
Links to account management. |
apps/web/src/components/ConnectAccountSurface.tsx |
Implements hosted registration management. |
apps/web/src/components/auth/PairingRouteSurface.tsx |
Awaits post-pair authentication handling. |
apps/web/src/cloud/connectCliAuth.ts |
Builds hosted management URL. |
apps/web/src/cloud/accountEnvironments.ts |
Implements relay list/delete requests. |
apps/web/src/cloud/accountEnvironments.test.ts |
Tests hosted management API behavior. |
apps/server/src/server.test.ts |
Tests DPoP CORS and replay rejection. |
apps/server/src/httpCors.ts |
Allows the DPoP header. |
apps/server/src/cli/connect.ts |
Adds list, deregister, and disable commands. |
apps/server/src/cli/client.ts |
Resolves tickets per socket connection. |
apps/server/src/cli/client.test.ts |
Tests reconnect ticket freshness. |
apps/server/src/cli/accountEnvironment.ts |
Secures CLI token reuse and deregistration. |
apps/server/src/cli/accountEnvironment.test.ts |
Updates token isolation coverage. |
apps/server/src/auth/windowsSecretProtection.ts |
Adds Windows ACL hardening. |
apps/server/src/auth/windowsSecretProtection.test.ts |
Tests existing and future file ACLs. |
apps/server/src/auth/ServerSecretStore.ts |
Protects legacy Windows secret storage. |
apps/server/src/auth/Layers/ServerSecretStore.ts |
Protects layered Windows secret storage. |
apps/server/package.json |
Adds ACL tests to Windows Smoke. |
apps/mobile/src/features/connection/CloudEnvironmentRows.tsx |
Adds mobile deregistration controls. |
apps/mobile/src/features/cloud/deregisterEnvironment.ts |
Implements account-safe deregistration. |
.agents/references/scars/full.md |
Records compatibility invariants. |
Review details
- Files reviewed: 43/43 changed files
- Comments generated: 2
- Review effort level: Balanced (auto)
Note
Copilot is running an experiment and ran this review at Balanced.
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Decouple hosted account management from CLI OAuth configuration, keep non-schema RPC failures retryable, and establish per-user ownership in the native Windows ACL fixture without weakening production checks. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Preserve main's pairing-link parsing and credential clearing together with awaited authenticated initialization. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
🟡 Changes recommended
CLI deregistration can use a stale refreshed credential, and mobile retains a stale deregistration action after successful removal.
Get a fresh assessment by requesting another Copilot review.
Review details
Suppressed comments (1)
Previously missed (1) — in code that hasn't changed since the last review.
apps/server/src/cli/accountEnvironment.ts:517
- Use the session returned by
assertSameAccountfor the unlink request.getAccountSessionrefreshes credentials near expiry, so this second check can return a newer access token while the code still sends the stalesession.accessToken, causing a confirmed deregistration to fail with an avoidable 401.
- Files reviewed: 45/45 changed files
- Comments generated: 1
- Review effort level: Balanced (auto)
Note
Copilot is running an experiment and ran this review at Balanced.
Gate connected-row deregistration on the current full relay account list while preserving healthy local connections. Cover refreshed removal and signed-out rendering. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Summary
Upstream reuse
Adapted the identity-owned, single-flight HTTP renewal design from pingdotgg/t3code#9594, rather than cherry-picking incompatible runtime wiring. This fork still has separate shared/mobile and legacy web connection runtimes. Also inspected pingdotgg/t3code#9602; the fork retains its existing explicit setup/preflight diagnostics.
Scope and rollout
This implements the repository-supported portion of backlog items 33–48. Items 35–36 remain partially blocked by the external relay API: it does not expose actual quota usage/limits, last-seen time, installation type, or build. The UI reports unavailable metadata; CLI JSON returns
tunnelQuota: null. Registration count is not presented as tunnel usage, and old registrations are never automatically declared stale or deleted.Deregistration does not revoke already-issued sessions or delete server data/local drafts. Disable an enabled host first to prevent re-registration. Desktop/web account management requires deploying the new hosted
/connect/environmentsroute with public Clerk/relay configuration. Old cached credentials are safely refreshed; legacy bearer connections remain supported.Windows native ACL coverage is included in CI but cannot run on this macOS workstation. No production account registrations were modified; hosted-account browser scenarios used local test fixtures and intercepted relay requests.
Testing
pnpm fmt:check,pnpm lint,pnpm typecheckpnpm test— repository Vite Plus suite passedconnect-account-initialization.webm
Self-test evidence
Tested commit:
4a12cfe2b1b2626df023069ff80a0b5f0a3ae862. Scope: production web pairing/reconnect baseline, not native Electron or feature-specific coverage.One-time URL pairing establishes an authenticated browser session.
Consumed credentials fail visibly and are cleared.
Malformed pairing links show format-neutral guidance for query and fragment tokens.
A fresh same-origin pairing link can be pasted into the recovery form.
The authenticated project remains visible after reload.
The browser recovers from a forced WebSocket disconnect without reloading and receives live project updates.
Node client live synchronization and involuntary reconnect preserve project state.
pairing-reload.webm