Skip to content

feat(connect): manage account hosts and renew authorization reliably - #359

Merged
ronak-guliani merged 4 commits into
mainfrom
feat/connect-account-reliability
Sep 13, 2026
Merged

ronak-guliani merged 4 commits into
mainfrom
feat/connect-account-reliability

Conversation

@ronak-guliani

@ronak-guliani ronak-guliani commented Sep 12, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Add explicit account-wide deregistration in mobile, CLI, and a hosted account page linked from desktop/web Connections. Offline hosts can be removed without contacting them; stable IDs, default-cancel confirmations, and consequence text distinguish client removal, host exposure disable, and account deregistration.
  • Renew shared-runtime HTTP authorization once per environment without closing healthy WebSockets. Isolate credentials by account/session, relay, environment, scopes, and proof key; validate endpoint identity before cached reconnects; resolve a fresh single-use ticket on every CLI socket connection.
  • Allow actual browser DPoP preflights, reject replayed proofs, classify malformed initial configuration as blocked compatibility failures, and initialize authenticated routes immediately after pairing. Transient recovery does not remove connections, drafts, outbox entries, or active work.
  • Protect both Windows file-backed secret stores with current-user-only ACLs and add native existing/future-file ACL coverage to Windows Smoke.

Upstream reuse

Adapted the identity-owned, single-flight HTTP renewal design from pingdotgg/t3code#9594, rather than cherry-picking incompatible runtime wiring. This fork still has separate shared/mobile and legacy web connection runtimes. Also inspected pingdotgg/t3code#9602; the fork retains its existing explicit setup/preflight diagnostics.

Scope and rollout

This implements the repository-supported portion of backlog items 33–48. Items 35–36 remain partially blocked by the external relay API: it does not expose actual quota usage/limits, last-seen time, installation type, or build. The UI reports unavailable metadata; CLI JSON returns tunnelQuota: null. Registration count is not presented as tunnel usage, and old registrations are never automatically declared stale or deleted.

Deregistration does not revoke already-issued sessions or delete server data/local drafts. Disable an enabled host first to prevent re-registration. Desktop/web account management requires deploying the new hosted /connect/environments route with public Clerk/relay configuration. Old cached credentials are safely refreshed; legacy bearer connections remain supported.

Windows native ACL coverage is included in CI but cannot run on this macOS workstation. No production account registrations were modified; hosted-account browser scenarios used local test fixtures and intercepted relay requests.

Testing

  • pnpm fmt:check, pnpm lint, pnpm typecheck
  • pnpm test — repository Vite Plus suite passed
  • Targeted authorization, HTTP renewal, malformed RPC configuration, CLI reconnect/cache, web account API, and auth-bootstrap regressions
  • Real HTTP DPoP preflight, proof-bound ticket issuance, and replay rejection
  • Worktree-isolated browser pass: fresh live CLI pairing initializes without reload; Connections management link; offline deregistration confirmation/cancel, visible failure/retry, account switch, and narrow viewport
  • Screenshots and token-free initialization recording attached below; the account page uses synthetic fixture data

connect-account-settings.png

connect-account-confirmation.png

connect-account-initialization.webm

Self-test evidence

Tested commit: 4a12cfe2b1b2626df023069ff80a0b5f0a3ae862. Scope: production web pairing/reconnect baseline, not native Electron or feature-specific coverage.

  • One-time URL pairing establishes an authenticated browser session.

  • Consumed credentials fail visibly and are cleared.

  • Malformed pairing links show format-neutral guidance for query and fragment tokens.

  • A fresh same-origin pairing link can be pasted into the recovery form.

  • The authenticated project remains visible after reload.

  • The browser recovers from a forced WebSocket disconnect without reloading and receives live project updates.

  • Node client live synchronization and involuntary reconnect preserve project state.

Self-test screenshot: pairing-invalid-link.png

Self-test screenshot: pairing-recovery.png

Self-test screenshot: authenticated.png

pairing-reload.webm

Adapt upstream single-flight HTTP renewal, isolate account credentials, issue fresh CLI reconnect tickets, and add explicit cross-client deregistration. Harden browser pairing/CORS compatibility and Windows secret-store ACLs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 12, 2026 01:59
@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL labels Sep 12, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The hosted route is incorrectly tied to CLI OAuth configuration, and non-schema RPC defects are incorrectly made non-retryable.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Adds account-wide T3 Connect environment management and strengthens authorization, reconnect, compatibility, and Windows secret-storage behavior.

Changes:

  • Adds hosted, mobile, and CLI environment deregistration.
  • Introduces account-bound DPoP renewal and fresh reconnect tickets.
  • Adds DPoP CORS/replay coverage and Windows ACL protection.
File summaries
File Description
packages/shared/src/connectManagement.ts Adds shared management guidance.
packages/shared/package.json Exports management constants.
packages/client-runtime/src/state/threadSnapshotHttp.ts Uses renewable authenticated reads.
packages/client-runtime/src/state/shellSnapshotHttp.ts Uses renewable authenticated reads.
packages/client-runtime/src/state/pullRequestDiffHttp.ts Renews read-only POST authorization.
packages/client-runtime/src/state/environmentHttpAuth.ts Implements HTTP renewal and retry.
packages/client-runtime/src/state/environmentHttpAuth.test.ts Tests renewal behavior.
packages/client-runtime/src/rpc/session.ts Classifies configuration failures.
packages/client-runtime/src/rpc/session.test.ts Tests malformed configuration.
packages/client-runtime/src/connection/resolver.ts Passes relay identity context.
packages/client-runtime/src/connection/model.ts Adds renewable authorization callback.
packages/client-runtime/src/connection/errors.ts Maps incompatible responses.
packages/client-runtime/src/authorization/tokenStore.ts Persists token ownership metadata.
packages/client-runtime/src/authorization/service.ts Adds scoped single-flight authorization.
packages/client-runtime/src/authorization/layer.test.ts Tests isolation and renewal.
docs/background-service.md Documents management and security behavior.
apps/web/vite.config.ts Exposes hosted relay configuration.
apps/web/src/routeTree.gen.ts Registers account-management route.
apps/web/src/routes/pair.tsx Revalidates after pairing.
apps/web/src/routes/connect_.environments.tsx Adds hosted management route.
apps/web/src/routes/__root.tsx Exempts hosted management from local auth.
apps/web/src/environments/primary/auth.ts Bootstraps authenticated state immediately.
apps/web/src/components/settings/ConnectionsSettings.tsx Links to account management.
apps/web/src/components/ConnectAccountSurface.tsx Implements hosted registration management.
apps/web/src/components/auth/PairingRouteSurface.tsx Awaits post-pair authentication handling.
apps/web/src/cloud/connectCliAuth.ts Builds hosted management URL.
apps/web/src/cloud/accountEnvironments.ts Implements relay list/delete requests.
apps/web/src/cloud/accountEnvironments.test.ts Tests hosted management API behavior.
apps/server/src/server.test.ts Tests DPoP CORS and replay rejection.
apps/server/src/httpCors.ts Allows the DPoP header.
apps/server/src/cli/connect.ts Adds list, deregister, and disable commands.
apps/server/src/cli/client.ts Resolves tickets per socket connection.
apps/server/src/cli/client.test.ts Tests reconnect ticket freshness.
apps/server/src/cli/accountEnvironment.ts Secures CLI token reuse and deregistration.
apps/server/src/cli/accountEnvironment.test.ts Updates token isolation coverage.
apps/server/src/auth/windowsSecretProtection.ts Adds Windows ACL hardening.
apps/server/src/auth/windowsSecretProtection.test.ts Tests existing and future file ACLs.
apps/server/src/auth/ServerSecretStore.ts Protects legacy Windows secret storage.
apps/server/src/auth/Layers/ServerSecretStore.ts Protects layered Windows secret storage.
apps/server/package.json Adds ACL tests to Windows Smoke.
apps/mobile/src/features/connection/CloudEnvironmentRows.tsx Adds mobile deregistration controls.
apps/mobile/src/features/cloud/deregisterEnvironment.ts Implements account-safe deregistration.
.agents/references/scars/full.md Records compatibility invariants.
Review details
  • Files reviewed: 43/43 changed files
  • Comments generated: 2
  • Review effort level: Balanced (auto)

Note

Copilot is running an experiment and ran this review at Balanced.


💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread apps/web/src/routes/connect_.environments.tsx Outdated
Comment thread packages/client-runtime/src/rpc/session.ts Outdated
Decouple hosted account management from CLI OAuth configuration, keep non-schema RPC failures retryable, and establish per-user ownership in the native Windows ACL fixture without weakening production checks.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Preserve main's pairing-link parsing and credential clearing together with awaited authenticated initialization.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

CLI deregistration can use a stale refreshed credential, and mobile retains a stale deregistration action after successful removal.

Get a fresh assessment by requesting another Copilot review.

Review details

Suppressed comments (1)

Previously missed (1) — in code that hasn't changed since the last review.

apps/server/src/cli/accountEnvironment.ts:517

  • Use the session returned by assertSameAccount for the unlink request. getAccountSession refreshes credentials near expiry, so this second check can return a newer access token while the code still sends the stale session.accessToken, causing a confirmed deregistration to fail with an avoidable 401.
  • Files reviewed: 45/45 changed files
  • Comments generated: 1
  • Review effort level: Balanced (auto)

Note

Copilot is running an experiment and ran this review at Balanced.

Comment thread apps/mobile/src/features/connection/CloudEnvironmentRows.tsx
Gate connected-row deregistration on the current full relay account list while preserving healthy local connections. Cover refreshed removal and signed-out rendering.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@ronak-guliani
ronak-guliani merged commit 3b1e5d2 into main Sep 13, 2026
5 of 10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants