Add reusable loopback development auth - #4360

Closed
t3dotgg wants to merge 3 commits into
mainfrom
t3code/53440ffe
Closed

Add reusable loopback development auth#4360
t3dotgg wants to merge 3 commits into
mainfrom
t3code/53440ffe

Conversation

@t3dotgg

@t3dotggt3dotgg commented Jul 23, 2026

Copy link
Copy Markdown
Member

Summary

  • derive a stable public development key from the canonical worktree path and print reusable web/iOS/Android pairing URLs from the dev runner
  • seed that key as a process-lifetime administrative bootstrap grant only when explicitly enabled on a loopback bind
  • namespace dev browser cookies by backend port and auto-submit mobile pairing deep links through the existing onboarding flow
  • update the web/mobile agent testing skills and include the reviewed implementation plan

The development key intentionally assumes a single-user development machine. It is not a production secret, and server config rejects it on wildcard, LAN, Tailnet, or other non-loopback binds. Real pairing remains unchanged.

Verification

  • vp test run scripts/dev-runner.test.ts apps/server/src/cli/config.test.ts apps/server/src/auth/PairingGrantStore.test.ts apps/server/src/auth/EnvironmentAuthPolicy.test.ts apps/server/src/startupAccess.test.ts apps/mobile/src/features/connection/pairing.test.ts (66 tests)
  • affected package typechecks: shared, server, mobile, scripts
  • targeted lint, formatting, and git diff --check
  • web: reused the same printed pairing URL in two fresh browser tabs; both reached the authenticated home
  • iOS Simulator: rebuilt the dev client, opened the printed iOS pairing URL, and confirmed the app connected to the isolated backend
  • Fable review via Claude Code; addressed lifetime, shared loopback predicate, and repeated deep-link findings

Note

Add reusable loopback development auth for simulators and emulators

  • Introduces a dev auth system where T3CODE_DEV_AUTH=1 and a stable T3CODE_DEV_AUTH_KEY (SHA-256 of the worktree root) are injected by the dev runner when binding to the loopback host, enabling reusable pairing without one-time tokens.
  • The server seeds a reusable administrative desktop-bootstrap grant under devAuthKey at startup with unbounded uses and a far-future expiration, so simulators/emulators can reconnect via a stable deep link.
  • Adds isLoopbackAddress, isLoopbackHost, isWildcardHost, and formatHostForUrl utilities to @t3tools/shared/networkHost, and migrates startupAccess.ts to use them; renames the preview-scoped isLoopbackHost to isPreviewLocalHost to avoid collision.
  • Session cookie names are port-namespaced when devAuthKey is configured, isolating dev sessions by port.
  • Risk: the reusable credential is refused on non-loopback hosts and when Tailscale Serve is enabled; physical devices must still use real one-time pairing.

Macroscope summarized 7c9a298.


Note

High Risk
Introduces a reusable administrative bootstrap grant and dev-only auth wiring; risk is mitigated by explicit env flags, loopback-only binding checks, and Tailscale Serve rejection, but misconfiguration could still widen local privilege.

Overview
Adds worktree-scoped reusable dev authentication so agents and local tooling can pair web and simulators without burning one-time tokens.

The dev runner derives a stable key from the canonical worktree path (sha256("t3-dev:" + root)), sets T3CODE_DEV_AUTH / T3CODE_DEV_AUTH_KEY only for dev / dev:server bound to 127.0.0.1, and logs reusable web, iOS, and Android pairing URLs. Non-127.0.0.1 hosts skip dev auth (physical LAN still uses real pairing).

The server reads devAuthKey from config, seeds an unlimited administrative bootstrap grant in PairingGrantStore (same exchange path as desktop bootstrap), and suffixes session cookies by port when dev auth is on so parallel backends do not clobber cookies. Startup rejects dev auth without a key, on non-loopback binds, or with Tailscale Serve.

Mobileconnections/new accepts a pairingUrl param and auto-runs the existing connect flow once per URL. Agent skills and a new implementation plan document describe reusable URLs vs one-time recovery.

Shared adds @t3tools/shared/networkHost with a strict isLoopbackAddress for dev-auth policy; preview code renames loopback checks to isPreviewLocalHost so preview behavior stays separate.

Reviewed by Cursor Bugbot for commit 7c9a298. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added reusable development authentication for loopback web servers.
    • Dev tools now display reusable web, iOS, and Android connection URLs.
    • Mobile simulators and emulators can automatically connect using pairing URLs.
    • Physical-device pairing continues to support fresh, one-time credentials.
    • Added safeguards requiring development authentication to use loopback hosts.
  • Bug Fixes

    • Prevented repeated automatic pairing attempts in the mobile connection flow.
  • Documentation

    • Updated web and mobile testing guidance, troubleshooting steps, and authentication security recommendations.
    • Added an implementation plan for development authentication.

@coderabbitai

coderabbitaiBot commented Jul 23, 2026

Copy link
Copy Markdown
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Title check✅ PassedThe title is concise and accurately summarizes the main change: reusable loopback development auth.
Description check✅ PassedIt explains what changed, why, and how it was verified, though it doesn't follow the exact template headings.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch t3code/53440ffe

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Jul 23, 2026
Comment threadscripts/dev-runner.ts
Comment threadpackages/shared/src/networkHost.ts Outdated
@t3dotgg
t3dotgg marked this pull request as ready for review July 23, 2026 11:10

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 6ddeaf0. Configure here.

Comment threadpackages/shared/src/networkHost.ts
Comment threadpackages/shared/src/networkHost.ts
@macroscopeapp

macroscopeappBot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

This PR modifies authentication logic in apps/server/src/auth/, adding a new reusable development authentication mechanism. Changes to auth directories are treated as sensitive and warrant human review regardless of the guardrails in place.

You can customize Macroscope's approvability policy. Learn more.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
apps/server/src/auth/PairingGrantStore.test.ts (1)

201-221: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Assert the reusable grant’s full shape on the second consume.

The test checks only second.subject; a regression could return the wrong method or reduced scopes after reuse while still passing.

Suggested assertions
 expect(second.subject).toBe("development-bootstrap");
+ expect(second.method).toBe("desktop-bootstrap");+ expect(second.scopes).toEqual(first.scopes);
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@apps/server/src/auth/PairingGrantStore.test.ts` around lines 201 - 221,
Expand the assertions for the second consume in the “seeds the development
credential” test to verify its full grant shape, including method, subject, and
complete scopes. Match the existing first-grant expectations so reuse is
confirmed to preserve all grant fields.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/shared/src/networkHost.ts`:
- Around line 1-13: Update packages/shared/src/networkHost.ts at lines 1-13 so
isLoopbackHost accepts only validated loopback address literals, returning false
for omitted hosts and rejecting hostname-like values such as
127.attacker.example; update apps/server/src/cli/config.ts at lines 362-368 to
require an explicit validated loopback bind before enabling dev auth; update
scripts/dev-runner.ts at lines 326-334 to provision dev auth only with an
explicit 127.0.0.1 bind, otherwise leave it disabled; add regression coverage
for an omitted host and 127.attacker.example.
---
Nitpick comments:
In `@apps/server/src/auth/PairingGrantStore.test.ts`:
- Around line 201-221: Expand the assertions for the second consume in the
“seeds the development credential” test to verify its full grant shape,
including method, subject, and complete scopes. Match the existing first-grant
expectations so reuse is confirmed to preserve all grant fields.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: e6601f36-61f6-4463-aa10-624815e2af0c

📥 Commits

Reviewing files that changed from the base of the PR and between 1c9a6de and 6ddeaf0.

📒 Files selected for processing (21)
  • .agents/skills/test-t3-app/SKILL.md
  • .agents/skills/test-t3-mobile/SKILL.md
  • .plans/21-agent-dev-auth.html
  • apps/mobile/src/features/connection/ConnectionsNewRouteScreen.tsx
  • apps/server/src/auth/EnvironmentAuthPolicy.test.ts
  • apps/server/src/auth/EnvironmentAuthPolicy.ts
  • apps/server/src/auth/PairingGrantStore.test.ts
  • apps/server/src/auth/PairingGrantStore.ts
  • apps/server/src/auth/SessionStore.ts
  • apps/server/src/auth/utils.ts
  • apps/server/src/bin.test.ts
  • apps/server/src/cli/config.test.ts
  • apps/server/src/cli/config.ts
  • apps/server/src/config.ts
  • apps/server/src/environment/ServerEnvironment.test.ts
  • apps/server/src/server.test.ts
  • apps/server/src/startupAccess.ts
  • packages/shared/package.json
  • packages/shared/src/networkHost.ts
  • scripts/dev-runner.test.ts
  • scripts/dev-runner.ts

Comment threadpackages/shared/src/networkHost.ts Outdated
@t3dotgg

Copy link
Copy Markdown
MemberAuthor

Closing because reusable loopback admin credentials have been overtaken by isolated dev state, safe sharing, and recoverable one-time pairing in #4555/#4556/#4955. The explicit pairing model is simpler and matches the current testing workflow.

@t3dotggt3dotgg closed this Jul 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL500-999 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Add reusable loopback development auth - #4360

Closed
t3dotgg wants to merge 3 commits into
mainfrom
t3code/53440ffe
Closed

Add reusable loopback development auth#4360
t3dotgg wants to merge 3 commits into
mainfrom
t3code/53440ffe

Conversation

@t3dotgg

@t3dotggt3dotgg commented Jul 23, 2026

Copy link
Copy Markdown
Member

Summary

  • derive a stable public development key from the canonical worktree path and print reusable web/iOS/Android pairing URLs from the dev runner
  • seed that key as a process-lifetime administrative bootstrap grant only when explicitly enabled on a loopback bind
  • namespace dev browser cookies by backend port and auto-submit mobile pairing deep links through the existing onboarding flow
  • update the web/mobile agent testing skills and include the reviewed implementation plan

The development key intentionally assumes a single-user development machine. It is not a production secret, and server config rejects it on wildcard, LAN, Tailnet, or other non-loopback binds. Real pairing remains unchanged.

Verification

  • vp test run scripts/dev-runner.test.ts apps/server/src/cli/config.test.ts apps/server/src/auth/PairingGrantStore.test.ts apps/server/src/auth/EnvironmentAuthPolicy.test.ts apps/server/src/startupAccess.test.ts apps/mobile/src/features/connection/pairing.test.ts (66 tests)
  • affected package typechecks: shared, server, mobile, scripts
  • targeted lint, formatting, and git diff --check
  • web: reused the same printed pairing URL in two fresh browser tabs; both reached the authenticated home
  • iOS Simulator: rebuilt the dev client, opened the printed iOS pairing URL, and confirmed the app connected to the isolated backend
  • Fable review via Claude Code; addressed lifetime, shared loopback predicate, and repeated deep-link findings

Note

Add reusable loopback development auth for simulators and emulators

  • Introduces a dev auth system where T3CODE_DEV_AUTH=1 and a stable T3CODE_DEV_AUTH_KEY (SHA-256 of the worktree root) are injected by the dev runner when binding to the loopback host, enabling reusable pairing without one-time tokens.
  • The server seeds a reusable administrative desktop-bootstrap grant under devAuthKey at startup with unbounded uses and a far-future expiration, so simulators/emulators can reconnect via a stable deep link.
  • Adds isLoopbackAddress, isLoopbackHost, isWildcardHost, and formatHostForUrl utilities to @t3tools/shared/networkHost, and migrates startupAccess.ts to use them; renames the preview-scoped isLoopbackHost to isPreviewLocalHost to avoid collision.
  • Session cookie names are port-namespaced when devAuthKey is configured, isolating dev sessions by port.
  • Risk: the reusable credential is refused on non-loopback hosts and when Tailscale Serve is enabled; physical devices must still use real one-time pairing.

Macroscope summarized 7c9a298.


Note

High Risk
Introduces a reusable administrative bootstrap grant and dev-only auth wiring; risk is mitigated by explicit env flags, loopback-only binding checks, and Tailscale Serve rejection, but misconfiguration could still widen local privilege.

Overview
Adds worktree-scoped reusable dev authentication so agents and local tooling can pair web and simulators without burning one-time tokens.

The dev runner derives a stable key from the canonical worktree path (sha256("t3-dev:" + root)), sets T3CODE_DEV_AUTH / T3CODE_DEV_AUTH_KEY only for dev / dev:server bound to 127.0.0.1, and logs reusable web, iOS, and Android pairing URLs. Non-127.0.0.1 hosts skip dev auth (physical LAN still uses real pairing).

The server reads devAuthKey from config, seeds an unlimited administrative bootstrap grant in PairingGrantStore (same exchange path as desktop bootstrap), and suffixes session cookies by port when dev auth is on so parallel backends do not clobber cookies. Startup rejects dev auth without a key, on non-loopback binds, or with Tailscale Serve.

Mobileconnections/new accepts a pairingUrl param and auto-runs the existing connect flow once per URL. Agent skills and a new implementation plan document describe reusable URLs vs one-time recovery.

Shared adds @t3tools/shared/networkHost with a strict isLoopbackAddress for dev-auth policy; preview code renames loopback checks to isPreviewLocalHost so preview behavior stays separate.

Reviewed by Cursor Bugbot for commit 7c9a298. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added reusable development authentication for loopback web servers.
    • Dev tools now display reusable web, iOS, and Android connection URLs.
    • Mobile simulators and emulators can automatically connect using pairing URLs.
    • Physical-device pairing continues to support fresh, one-time credentials.
    • Added safeguards requiring development authentication to use loopback hosts.
  • Bug Fixes

    • Prevented repeated automatic pairing attempts in the mobile connection flow.
  • Documentation

    • Updated web and mobile testing guidance, troubleshooting steps, and authentication security recommendations.
    • Added an implementation plan for development authentication.

@coderabbitai

coderabbitaiBot commented Jul 23, 2026

Copy link
Copy Markdown
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Title check✅ PassedThe title is concise and accurately summarizes the main change: reusable loopback development auth.
Description check✅ PassedIt explains what changed, why, and how it was verified, though it doesn't follow the exact template headings.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch t3code/53440ffe

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Jul 23, 2026
Comment threadscripts/dev-runner.ts
Comment threadpackages/shared/src/networkHost.ts Outdated
@t3dotgg
t3dotgg marked this pull request as ready for review July 23, 2026 11:10

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 6ddeaf0. Configure here.

Comment threadpackages/shared/src/networkHost.ts
Comment threadpackages/shared/src/networkHost.ts
@macroscopeapp

macroscopeappBot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

This PR modifies authentication logic in apps/server/src/auth/, adding a new reusable development authentication mechanism. Changes to auth directories are treated as sensitive and warrant human review regardless of the guardrails in place.

You can customize Macroscope's approvability policy. Learn more.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
apps/server/src/auth/PairingGrantStore.test.ts (1)

201-221: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Assert the reusable grant’s full shape on the second consume.

The test checks only second.subject; a regression could return the wrong method or reduced scopes after reuse while still passing.

Suggested assertions
 expect(second.subject).toBe("development-bootstrap");
+ expect(second.method).toBe("desktop-bootstrap");+ expect(second.scopes).toEqual(first.scopes);
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@apps/server/src/auth/PairingGrantStore.test.ts` around lines 201 - 221,
Expand the assertions for the second consume in the “seeds the development
credential” test to verify its full grant shape, including method, subject, and
complete scopes. Match the existing first-grant expectations so reuse is
confirmed to preserve all grant fields.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/shared/src/networkHost.ts`:
- Around line 1-13: Update packages/shared/src/networkHost.ts at lines 1-13 so
isLoopbackHost accepts only validated loopback address literals, returning false
for omitted hosts and rejecting hostname-like values such as
127.attacker.example; update apps/server/src/cli/config.ts at lines 362-368 to
require an explicit validated loopback bind before enabling dev auth; update
scripts/dev-runner.ts at lines 326-334 to provision dev auth only with an
explicit 127.0.0.1 bind, otherwise leave it disabled; add regression coverage
for an omitted host and 127.attacker.example.
---
Nitpick comments:
In `@apps/server/src/auth/PairingGrantStore.test.ts`:
- Around line 201-221: Expand the assertions for the second consume in the
“seeds the development credential” test to verify its full grant shape,
including method, subject, and complete scopes. Match the existing first-grant
expectations so reuse is confirmed to preserve all grant fields.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: e6601f36-61f6-4463-aa10-624815e2af0c

📥 Commits

Reviewing files that changed from the base of the PR and between 1c9a6de and 6ddeaf0.

📒 Files selected for processing (21)
  • .agents/skills/test-t3-app/SKILL.md
  • .agents/skills/test-t3-mobile/SKILL.md
  • .plans/21-agent-dev-auth.html
  • apps/mobile/src/features/connection/ConnectionsNewRouteScreen.tsx
  • apps/server/src/auth/EnvironmentAuthPolicy.test.ts
  • apps/server/src/auth/EnvironmentAuthPolicy.ts
  • apps/server/src/auth/PairingGrantStore.test.ts
  • apps/server/src/auth/PairingGrantStore.ts
  • apps/server/src/auth/SessionStore.ts
  • apps/server/src/auth/utils.ts
  • apps/server/src/bin.test.ts
  • apps/server/src/cli/config.test.ts
  • apps/server/src/cli/config.ts
  • apps/server/src/config.ts
  • apps/server/src/environment/ServerEnvironment.test.ts
  • apps/server/src/server.test.ts
  • apps/server/src/startupAccess.ts
  • packages/shared/package.json
  • packages/shared/src/networkHost.ts
  • scripts/dev-runner.test.ts
  • scripts/dev-runner.ts

Comment threadpackages/shared/src/networkHost.ts Outdated
@t3dotgg

Copy link
Copy Markdown
MemberAuthor

Closing because reusable loopback admin credentials have been overtaken by isolated dev state, safe sharing, and recoverable one-time pairing in #4555/#4556/#4955. The explicit pairing model is simpler and matches the current testing workflow.

@t3dotggt3dotgg closed this Jul 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL500-999 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add reusable loopback development auth - #4360

Closed
t3dotgg wants to merge 3 commits into
mainfrom
t3code/53440ffe
Closed

Add reusable loopback development auth#4360
t3dotgg wants to merge 3 commits into
mainfrom
t3code/53440ffe

Conversation

@t3dotgg

@t3dotggt3dotgg commented Jul 23, 2026

Copy link
Copy Markdown
Member

Summary

  • derive a stable public development key from the canonical worktree path and print reusable web/iOS/Android pairing URLs from the dev runner
  • seed that key as a process-lifetime administrative bootstrap grant only when explicitly enabled on a loopback bind
  • namespace dev browser cookies by backend port and auto-submit mobile pairing deep links through the existing onboarding flow
  • update the web/mobile agent testing skills and include the reviewed implementation plan

The development key intentionally assumes a single-user development machine. It is not a production secret, and server config rejects it on wildcard, LAN, Tailnet, or other non-loopback binds. Real pairing remains unchanged.

Verification

  • vp test run scripts/dev-runner.test.ts apps/server/src/cli/config.test.ts apps/server/src/auth/PairingGrantStore.test.ts apps/server/src/auth/EnvironmentAuthPolicy.test.ts apps/server/src/startupAccess.test.ts apps/mobile/src/features/connection/pairing.test.ts (66 tests)
  • affected package typechecks: shared, server, mobile, scripts
  • targeted lint, formatting, and git diff --check
  • web: reused the same printed pairing URL in two fresh browser tabs; both reached the authenticated home
  • iOS Simulator: rebuilt the dev client, opened the printed iOS pairing URL, and confirmed the app connected to the isolated backend
  • Fable review via Claude Code; addressed lifetime, shared loopback predicate, and repeated deep-link findings

Note

Add reusable loopback development auth for simulators and emulators

  • Introduces a dev auth system where T3CODE_DEV_AUTH=1 and a stable T3CODE_DEV_AUTH_KEY (SHA-256 of the worktree root) are injected by the dev runner when binding to the loopback host, enabling reusable pairing without one-time tokens.
  • The server seeds a reusable administrative desktop-bootstrap grant under devAuthKey at startup with unbounded uses and a far-future expiration, so simulators/emulators can reconnect via a stable deep link.
  • Adds isLoopbackAddress, isLoopbackHost, isWildcardHost, and formatHostForUrl utilities to @t3tools/shared/networkHost, and migrates startupAccess.ts to use them; renames the preview-scoped isLoopbackHost to isPreviewLocalHost to avoid collision.
  • Session cookie names are port-namespaced when devAuthKey is configured, isolating dev sessions by port.
  • Risk: the reusable credential is refused on non-loopback hosts and when Tailscale Serve is enabled; physical devices must still use real one-time pairing.

Macroscope summarized 7c9a298.


Note

High Risk
Introduces a reusable administrative bootstrap grant and dev-only auth wiring; risk is mitigated by explicit env flags, loopback-only binding checks, and Tailscale Serve rejection, but misconfiguration could still widen local privilege.

Overview
Adds worktree-scoped reusable dev authentication so agents and local tooling can pair web and simulators without burning one-time tokens.

The dev runner derives a stable key from the canonical worktree path (sha256("t3-dev:" + root)), sets T3CODE_DEV_AUTH / T3CODE_DEV_AUTH_KEY only for dev / dev:server bound to 127.0.0.1, and logs reusable web, iOS, and Android pairing URLs. Non-127.0.0.1 hosts skip dev auth (physical LAN still uses real pairing).

The server reads devAuthKey from config, seeds an unlimited administrative bootstrap grant in PairingGrantStore (same exchange path as desktop bootstrap), and suffixes session cookies by port when dev auth is on so parallel backends do not clobber cookies. Startup rejects dev auth without a key, on non-loopback binds, or with Tailscale Serve.

Mobileconnections/new accepts a pairingUrl param and auto-runs the existing connect flow once per URL. Agent skills and a new implementation plan document describe reusable URLs vs one-time recovery.

Shared adds @t3tools/shared/networkHost with a strict isLoopbackAddress for dev-auth policy; preview code renames loopback checks to isPreviewLocalHost so preview behavior stays separate.

Reviewed by Cursor Bugbot for commit 7c9a298. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added reusable development authentication for loopback web servers.
    • Dev tools now display reusable web, iOS, and Android connection URLs.
    • Mobile simulators and emulators can automatically connect using pairing URLs.
    • Physical-device pairing continues to support fresh, one-time credentials.
    • Added safeguards requiring development authentication to use loopback hosts.
  • Bug Fixes

    • Prevented repeated automatic pairing attempts in the mobile connection flow.
  • Documentation

    • Updated web and mobile testing guidance, troubleshooting steps, and authentication security recommendations.
    • Added an implementation plan for development authentication.

@coderabbitai

coderabbitaiBot commented Jul 23, 2026

Copy link
Copy Markdown
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Title check✅ PassedThe title is concise and accurately summarizes the main change: reusable loopback development auth.
Description check✅ PassedIt explains what changed, why, and how it was verified, though it doesn't follow the exact template headings.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch t3code/53440ffe

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Jul 23, 2026
Comment threadscripts/dev-runner.ts
Comment threadpackages/shared/src/networkHost.ts Outdated
@t3dotgg
t3dotgg marked this pull request as ready for review July 23, 2026 11:10

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 6ddeaf0. Configure here.

Comment threadpackages/shared/src/networkHost.ts
Comment threadpackages/shared/src/networkHost.ts
@macroscopeapp

macroscopeappBot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

This PR modifies authentication logic in apps/server/src/auth/, adding a new reusable development authentication mechanism. Changes to auth directories are treated as sensitive and warrant human review regardless of the guardrails in place.

You can customize Macroscope's approvability policy. Learn more.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
apps/server/src/auth/PairingGrantStore.test.ts (1)

201-221: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Assert the reusable grant’s full shape on the second consume.

The test checks only second.subject; a regression could return the wrong method or reduced scopes after reuse while still passing.

Suggested assertions
 expect(second.subject).toBe("development-bootstrap");
+ expect(second.method).toBe("desktop-bootstrap");+ expect(second.scopes).toEqual(first.scopes);
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@apps/server/src/auth/PairingGrantStore.test.ts` around lines 201 - 221,
Expand the assertions for the second consume in the “seeds the development
credential” test to verify its full grant shape, including method, subject, and
complete scopes. Match the existing first-grant expectations so reuse is
confirmed to preserve all grant fields.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/shared/src/networkHost.ts`:
- Around line 1-13: Update packages/shared/src/networkHost.ts at lines 1-13 so
isLoopbackHost accepts only validated loopback address literals, returning false
for omitted hosts and rejecting hostname-like values such as
127.attacker.example; update apps/server/src/cli/config.ts at lines 362-368 to
require an explicit validated loopback bind before enabling dev auth; update
scripts/dev-runner.ts at lines 326-334 to provision dev auth only with an
explicit 127.0.0.1 bind, otherwise leave it disabled; add regression coverage
for an omitted host and 127.attacker.example.
---
Nitpick comments:
In `@apps/server/src/auth/PairingGrantStore.test.ts`:
- Around line 201-221: Expand the assertions for the second consume in the
“seeds the development credential” test to verify its full grant shape,
including method, subject, and complete scopes. Match the existing first-grant
expectations so reuse is confirmed to preserve all grant fields.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: e6601f36-61f6-4463-aa10-624815e2af0c

📥 Commits

Reviewing files that changed from the base of the PR and between 1c9a6de and 6ddeaf0.

📒 Files selected for processing (21)
  • .agents/skills/test-t3-app/SKILL.md
  • .agents/skills/test-t3-mobile/SKILL.md
  • .plans/21-agent-dev-auth.html
  • apps/mobile/src/features/connection/ConnectionsNewRouteScreen.tsx
  • apps/server/src/auth/EnvironmentAuthPolicy.test.ts
  • apps/server/src/auth/EnvironmentAuthPolicy.ts
  • apps/server/src/auth/PairingGrantStore.test.ts
  • apps/server/src/auth/PairingGrantStore.ts
  • apps/server/src/auth/SessionStore.ts
  • apps/server/src/auth/utils.ts
  • apps/server/src/bin.test.ts
  • apps/server/src/cli/config.test.ts
  • apps/server/src/cli/config.ts
  • apps/server/src/config.ts
  • apps/server/src/environment/ServerEnvironment.test.ts
  • apps/server/src/server.test.ts
  • apps/server/src/startupAccess.ts
  • packages/shared/package.json
  • packages/shared/src/networkHost.ts
  • scripts/dev-runner.test.ts
  • scripts/dev-runner.ts

Comment threadpackages/shared/src/networkHost.ts Outdated
@t3dotgg

Copy link
Copy Markdown
MemberAuthor

Closing because reusable loopback admin credentials have been overtaken by isolated dev state, safe sharing, and recoverable one-time pairing in #4555/#4556/#4955. The explicit pairing model is simpler and matches the current testing workflow.

@t3dotggt3dotgg closed this Jul 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL500-999 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add reusable loopback development auth - #4360

Closed
t3dotgg wants to merge 3 commits into
mainfrom
t3code/53440ffe
Closed

Add reusable loopback development auth#4360
t3dotgg wants to merge 3 commits into
mainfrom
t3code/53440ffe

Conversation

@t3dotgg

@t3dotggt3dotgg commented Jul 23, 2026

Copy link
Copy Markdown
Member

Summary

  • derive a stable public development key from the canonical worktree path and print reusable web/iOS/Android pairing URLs from the dev runner
  • seed that key as a process-lifetime administrative bootstrap grant only when explicitly enabled on a loopback bind
  • namespace dev browser cookies by backend port and auto-submit mobile pairing deep links through the existing onboarding flow
  • update the web/mobile agent testing skills and include the reviewed implementation plan

The development key intentionally assumes a single-user development machine. It is not a production secret, and server config rejects it on wildcard, LAN, Tailnet, or other non-loopback binds. Real pairing remains unchanged.

Verification

  • vp test run scripts/dev-runner.test.ts apps/server/src/cli/config.test.ts apps/server/src/auth/PairingGrantStore.test.ts apps/server/src/auth/EnvironmentAuthPolicy.test.ts apps/server/src/startupAccess.test.ts apps/mobile/src/features/connection/pairing.test.ts (66 tests)
  • affected package typechecks: shared, server, mobile, scripts
  • targeted lint, formatting, and git diff --check
  • web: reused the same printed pairing URL in two fresh browser tabs; both reached the authenticated home
  • iOS Simulator: rebuilt the dev client, opened the printed iOS pairing URL, and confirmed the app connected to the isolated backend
  • Fable review via Claude Code; addressed lifetime, shared loopback predicate, and repeated deep-link findings

Note

Add reusable loopback development auth for simulators and emulators

  • Introduces a dev auth system where T3CODE_DEV_AUTH=1 and a stable T3CODE_DEV_AUTH_KEY (SHA-256 of the worktree root) are injected by the dev runner when binding to the loopback host, enabling reusable pairing without one-time tokens.
  • The server seeds a reusable administrative desktop-bootstrap grant under devAuthKey at startup with unbounded uses and a far-future expiration, so simulators/emulators can reconnect via a stable deep link.
  • Adds isLoopbackAddress, isLoopbackHost, isWildcardHost, and formatHostForUrl utilities to @t3tools/shared/networkHost, and migrates startupAccess.ts to use them; renames the preview-scoped isLoopbackHost to isPreviewLocalHost to avoid collision.
  • Session cookie names are port-namespaced when devAuthKey is configured, isolating dev sessions by port.
  • Risk: the reusable credential is refused on non-loopback hosts and when Tailscale Serve is enabled; physical devices must still use real one-time pairing.

Macroscope summarized 7c9a298.


Note

High Risk
Introduces a reusable administrative bootstrap grant and dev-only auth wiring; risk is mitigated by explicit env flags, loopback-only binding checks, and Tailscale Serve rejection, but misconfiguration could still widen local privilege.

Overview
Adds worktree-scoped reusable dev authentication so agents and local tooling can pair web and simulators without burning one-time tokens.

The dev runner derives a stable key from the canonical worktree path (sha256("t3-dev:" + root)), sets T3CODE_DEV_AUTH / T3CODE_DEV_AUTH_KEY only for dev / dev:server bound to 127.0.0.1, and logs reusable web, iOS, and Android pairing URLs. Non-127.0.0.1 hosts skip dev auth (physical LAN still uses real pairing).

The server reads devAuthKey from config, seeds an unlimited administrative bootstrap grant in PairingGrantStore (same exchange path as desktop bootstrap), and suffixes session cookies by port when dev auth is on so parallel backends do not clobber cookies. Startup rejects dev auth without a key, on non-loopback binds, or with Tailscale Serve.

Mobileconnections/new accepts a pairingUrl param and auto-runs the existing connect flow once per URL. Agent skills and a new implementation plan document describe reusable URLs vs one-time recovery.

Shared adds @t3tools/shared/networkHost with a strict isLoopbackAddress for dev-auth policy; preview code renames loopback checks to isPreviewLocalHost so preview behavior stays separate.

Reviewed by Cursor Bugbot for commit 7c9a298. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added reusable development authentication for loopback web servers.
    • Dev tools now display reusable web, iOS, and Android connection URLs.
    • Mobile simulators and emulators can automatically connect using pairing URLs.
    • Physical-device pairing continues to support fresh, one-time credentials.
    • Added safeguards requiring development authentication to use loopback hosts.
  • Bug Fixes

    • Prevented repeated automatic pairing attempts in the mobile connection flow.
  • Documentation

    • Updated web and mobile testing guidance, troubleshooting steps, and authentication security recommendations.
    • Added an implementation plan for development authentication.

@coderabbitai

coderabbitaiBot commented Jul 23, 2026

Copy link
Copy Markdown
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Title check✅ PassedThe title is concise and accurately summarizes the main change: reusable loopback development auth.
Description check✅ PassedIt explains what changed, why, and how it was verified, though it doesn't follow the exact template headings.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch t3code/53440ffe

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Jul 23, 2026
Comment threadscripts/dev-runner.ts
Comment threadpackages/shared/src/networkHost.ts Outdated
@t3dotgg
t3dotgg marked this pull request as ready for review July 23, 2026 11:10

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 6ddeaf0. Configure here.

Comment threadpackages/shared/src/networkHost.ts
Comment threadpackages/shared/src/networkHost.ts
@macroscopeapp

macroscopeappBot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

This PR modifies authentication logic in apps/server/src/auth/, adding a new reusable development authentication mechanism. Changes to auth directories are treated as sensitive and warrant human review regardless of the guardrails in place.

You can customize Macroscope's approvability policy. Learn more.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
apps/server/src/auth/PairingGrantStore.test.ts (1)

201-221: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Assert the reusable grant’s full shape on the second consume.

The test checks only second.subject; a regression could return the wrong method or reduced scopes after reuse while still passing.

Suggested assertions
 expect(second.subject).toBe("development-bootstrap");
+ expect(second.method).toBe("desktop-bootstrap");+ expect(second.scopes).toEqual(first.scopes);
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@apps/server/src/auth/PairingGrantStore.test.ts` around lines 201 - 221,
Expand the assertions for the second consume in the “seeds the development
credential” test to verify its full grant shape, including method, subject, and
complete scopes. Match the existing first-grant expectations so reuse is
confirmed to preserve all grant fields.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/shared/src/networkHost.ts`:
- Around line 1-13: Update packages/shared/src/networkHost.ts at lines 1-13 so
isLoopbackHost accepts only validated loopback address literals, returning false
for omitted hosts and rejecting hostname-like values such as
127.attacker.example; update apps/server/src/cli/config.ts at lines 362-368 to
require an explicit validated loopback bind before enabling dev auth; update
scripts/dev-runner.ts at lines 326-334 to provision dev auth only with an
explicit 127.0.0.1 bind, otherwise leave it disabled; add regression coverage
for an omitted host and 127.attacker.example.
---
Nitpick comments:
In `@apps/server/src/auth/PairingGrantStore.test.ts`:
- Around line 201-221: Expand the assertions for the second consume in the
“seeds the development credential” test to verify its full grant shape,
including method, subject, and complete scopes. Match the existing first-grant
expectations so reuse is confirmed to preserve all grant fields.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: e6601f36-61f6-4463-aa10-624815e2af0c

📥 Commits

Reviewing files that changed from the base of the PR and between 1c9a6de and 6ddeaf0.

📒 Files selected for processing (21)
  • .agents/skills/test-t3-app/SKILL.md
  • .agents/skills/test-t3-mobile/SKILL.md
  • .plans/21-agent-dev-auth.html
  • apps/mobile/src/features/connection/ConnectionsNewRouteScreen.tsx
  • apps/server/src/auth/EnvironmentAuthPolicy.test.ts
  • apps/server/src/auth/EnvironmentAuthPolicy.ts
  • apps/server/src/auth/PairingGrantStore.test.ts
  • apps/server/src/auth/PairingGrantStore.ts
  • apps/server/src/auth/SessionStore.ts
  • apps/server/src/auth/utils.ts
  • apps/server/src/bin.test.ts
  • apps/server/src/cli/config.test.ts
  • apps/server/src/cli/config.ts
  • apps/server/src/config.ts
  • apps/server/src/environment/ServerEnvironment.test.ts
  • apps/server/src/server.test.ts
  • apps/server/src/startupAccess.ts
  • packages/shared/package.json
  • packages/shared/src/networkHost.ts
  • scripts/dev-runner.test.ts
  • scripts/dev-runner.ts

Comment threadpackages/shared/src/networkHost.ts Outdated
@t3dotgg

Copy link
Copy Markdown
MemberAuthor

Closing because reusable loopback admin credentials have been overtaken by isolated dev state, safe sharing, and recoverable one-time pairing in #4555/#4556/#4955. The explicit pairing model is simpler and matches the current testing workflow.

@t3dotggt3dotgg closed this Jul 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL500-999 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Add reusable loopback development auth - #4360

Closed
t3dotgg wants to merge 3 commits into
mainfrom
t3code/53440ffe
Closed

Add reusable loopback development auth#4360
t3dotgg wants to merge 3 commits into
mainfrom
t3code/53440ffe

Conversation

@t3dotgg

@t3dotggt3dotgg commented Jul 23, 2026

Copy link
Copy Markdown
Member

Summary

  • derive a stable public development key from the canonical worktree path and print reusable web/iOS/Android pairing URLs from the dev runner
  • seed that key as a process-lifetime administrative bootstrap grant only when explicitly enabled on a loopback bind
  • namespace dev browser cookies by backend port and auto-submit mobile pairing deep links through the existing onboarding flow
  • update the web/mobile agent testing skills and include the reviewed implementation plan

The development key intentionally assumes a single-user development machine. It is not a production secret, and server config rejects it on wildcard, LAN, Tailnet, or other non-loopback binds. Real pairing remains unchanged.

Verification

  • vp test run scripts/dev-runner.test.ts apps/server/src/cli/config.test.ts apps/server/src/auth/PairingGrantStore.test.ts apps/server/src/auth/EnvironmentAuthPolicy.test.ts apps/server/src/startupAccess.test.ts apps/mobile/src/features/connection/pairing.test.ts (66 tests)
  • affected package typechecks: shared, server, mobile, scripts
  • targeted lint, formatting, and git diff --check
  • web: reused the same printed pairing URL in two fresh browser tabs; both reached the authenticated home
  • iOS Simulator: rebuilt the dev client, opened the printed iOS pairing URL, and confirmed the app connected to the isolated backend
  • Fable review via Claude Code; addressed lifetime, shared loopback predicate, and repeated deep-link findings

Note

Add reusable loopback development auth for simulators and emulators

  • Introduces a dev auth system where T3CODE_DEV_AUTH=1 and a stable T3CODE_DEV_AUTH_KEY (SHA-256 of the worktree root) are injected by the dev runner when binding to the loopback host, enabling reusable pairing without one-time tokens.
  • The server seeds a reusable administrative desktop-bootstrap grant under devAuthKey at startup with unbounded uses and a far-future expiration, so simulators/emulators can reconnect via a stable deep link.
  • Adds isLoopbackAddress, isLoopbackHost, isWildcardHost, and formatHostForUrl utilities to @t3tools/shared/networkHost, and migrates startupAccess.ts to use them; renames the preview-scoped isLoopbackHost to isPreviewLocalHost to avoid collision.
  • Session cookie names are port-namespaced when devAuthKey is configured, isolating dev sessions by port.
  • Risk: the reusable credential is refused on non-loopback hosts and when Tailscale Serve is enabled; physical devices must still use real one-time pairing.

Macroscope summarized 7c9a298.


Note

High Risk
Introduces a reusable administrative bootstrap grant and dev-only auth wiring; risk is mitigated by explicit env flags, loopback-only binding checks, and Tailscale Serve rejection, but misconfiguration could still widen local privilege.

Overview
Adds worktree-scoped reusable dev authentication so agents and local tooling can pair web and simulators without burning one-time tokens.

The dev runner derives a stable key from the canonical worktree path (sha256("t3-dev:" + root)), sets T3CODE_DEV_AUTH / T3CODE_DEV_AUTH_KEY only for dev / dev:server bound to 127.0.0.1, and logs reusable web, iOS, and Android pairing URLs. Non-127.0.0.1 hosts skip dev auth (physical LAN still uses real pairing).

The server reads devAuthKey from config, seeds an unlimited administrative bootstrap grant in PairingGrantStore (same exchange path as desktop bootstrap), and suffixes session cookies by port when dev auth is on so parallel backends do not clobber cookies. Startup rejects dev auth without a key, on non-loopback binds, or with Tailscale Serve.

Mobileconnections/new accepts a pairingUrl param and auto-runs the existing connect flow once per URL. Agent skills and a new implementation plan document describe reusable URLs vs one-time recovery.

Shared adds @t3tools/shared/networkHost with a strict isLoopbackAddress for dev-auth policy; preview code renames loopback checks to isPreviewLocalHost so preview behavior stays separate.

Reviewed by Cursor Bugbot for commit 7c9a298. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added reusable development authentication for loopback web servers.
    • Dev tools now display reusable web, iOS, and Android connection URLs.
    • Mobile simulators and emulators can automatically connect using pairing URLs.
    • Physical-device pairing continues to support fresh, one-time credentials.
    • Added safeguards requiring development authentication to use loopback hosts.
  • Bug Fixes

    • Prevented repeated automatic pairing attempts in the mobile connection flow.
  • Documentation

    • Updated web and mobile testing guidance, troubleshooting steps, and authentication security recommendations.
    • Added an implementation plan for development authentication.

@coderabbitai

coderabbitaiBot commented Jul 23, 2026

Copy link
Copy Markdown
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Title check✅ PassedThe title is concise and accurately summarizes the main change: reusable loopback development auth.
Description check✅ PassedIt explains what changed, why, and how it was verified, though it doesn't follow the exact template headings.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch t3code/53440ffe

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Jul 23, 2026
Comment threadscripts/dev-runner.ts
Comment threadpackages/shared/src/networkHost.ts Outdated
@t3dotgg
t3dotgg marked this pull request as ready for review July 23, 2026 11:10

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 6ddeaf0. Configure here.

Comment threadpackages/shared/src/networkHost.ts
Comment threadpackages/shared/src/networkHost.ts
@macroscopeapp

macroscopeappBot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

This PR modifies authentication logic in apps/server/src/auth/, adding a new reusable development authentication mechanism. Changes to auth directories are treated as sensitive and warrant human review regardless of the guardrails in place.

You can customize Macroscope's approvability policy. Learn more.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
apps/server/src/auth/PairingGrantStore.test.ts (1)

201-221: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Assert the reusable grant’s full shape on the second consume.

The test checks only second.subject; a regression could return the wrong method or reduced scopes after reuse while still passing.

Suggested assertions
 expect(second.subject).toBe("development-bootstrap");
+ expect(second.method).toBe("desktop-bootstrap");+ expect(second.scopes).toEqual(first.scopes);
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@apps/server/src/auth/PairingGrantStore.test.ts` around lines 201 - 221,
Expand the assertions for the second consume in the “seeds the development
credential” test to verify its full grant shape, including method, subject, and
complete scopes. Match the existing first-grant expectations so reuse is
confirmed to preserve all grant fields.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/shared/src/networkHost.ts`:
- Around line 1-13: Update packages/shared/src/networkHost.ts at lines 1-13 so
isLoopbackHost accepts only validated loopback address literals, returning false
for omitted hosts and rejecting hostname-like values such as
127.attacker.example; update apps/server/src/cli/config.ts at lines 362-368 to
require an explicit validated loopback bind before enabling dev auth; update
scripts/dev-runner.ts at lines 326-334 to provision dev auth only with an
explicit 127.0.0.1 bind, otherwise leave it disabled; add regression coverage
for an omitted host and 127.attacker.example.
---
Nitpick comments:
In `@apps/server/src/auth/PairingGrantStore.test.ts`:
- Around line 201-221: Expand the assertions for the second consume in the
“seeds the development credential” test to verify its full grant shape,
including method, subject, and complete scopes. Match the existing first-grant
expectations so reuse is confirmed to preserve all grant fields.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: e6601f36-61f6-4463-aa10-624815e2af0c

📥 Commits

Reviewing files that changed from the base of the PR and between 1c9a6de and 6ddeaf0.

📒 Files selected for processing (21)
  • .agents/skills/test-t3-app/SKILL.md
  • .agents/skills/test-t3-mobile/SKILL.md
  • .plans/21-agent-dev-auth.html
  • apps/mobile/src/features/connection/ConnectionsNewRouteScreen.tsx
  • apps/server/src/auth/EnvironmentAuthPolicy.test.ts
  • apps/server/src/auth/EnvironmentAuthPolicy.ts
  • apps/server/src/auth/PairingGrantStore.test.ts
  • apps/server/src/auth/PairingGrantStore.ts
  • apps/server/src/auth/SessionStore.ts
  • apps/server/src/auth/utils.ts
  • apps/server/src/bin.test.ts
  • apps/server/src/cli/config.test.ts
  • apps/server/src/cli/config.ts
  • apps/server/src/config.ts
  • apps/server/src/environment/ServerEnvironment.test.ts
  • apps/server/src/server.test.ts
  • apps/server/src/startupAccess.ts
  • packages/shared/package.json
  • packages/shared/src/networkHost.ts
  • scripts/dev-runner.test.ts
  • scripts/dev-runner.ts

Comment threadpackages/shared/src/networkHost.ts Outdated
@t3dotgg

Copy link
Copy Markdown
MemberAuthor

Closing because reusable loopback admin credentials have been overtaken by isolated dev state, safe sharing, and recoverable one-time pairing in #4555/#4556/#4955. The explicit pairing model is simpler and matches the current testing workflow.

@t3dotggt3dotgg closed this Jul 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL500-999 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add reusable loopback development auth - #4360

Closed
t3dotgg wants to merge 3 commits into
mainfrom
t3code/53440ffe
Closed

Add reusable loopback development auth#4360
t3dotgg wants to merge 3 commits into
mainfrom
t3code/53440ffe

Conversation

@t3dotgg

@t3dotggt3dotgg commented Jul 23, 2026

Copy link
Copy Markdown
Member

Summary

  • derive a stable public development key from the canonical worktree path and print reusable web/iOS/Android pairing URLs from the dev runner
  • seed that key as a process-lifetime administrative bootstrap grant only when explicitly enabled on a loopback bind
  • namespace dev browser cookies by backend port and auto-submit mobile pairing deep links through the existing onboarding flow
  • update the web/mobile agent testing skills and include the reviewed implementation plan

The development key intentionally assumes a single-user development machine. It is not a production secret, and server config rejects it on wildcard, LAN, Tailnet, or other non-loopback binds. Real pairing remains unchanged.

Verification

  • vp test run scripts/dev-runner.test.ts apps/server/src/cli/config.test.ts apps/server/src/auth/PairingGrantStore.test.ts apps/server/src/auth/EnvironmentAuthPolicy.test.ts apps/server/src/startupAccess.test.ts apps/mobile/src/features/connection/pairing.test.ts (66 tests)
  • affected package typechecks: shared, server, mobile, scripts
  • targeted lint, formatting, and git diff --check
  • web: reused the same printed pairing URL in two fresh browser tabs; both reached the authenticated home
  • iOS Simulator: rebuilt the dev client, opened the printed iOS pairing URL, and confirmed the app connected to the isolated backend
  • Fable review via Claude Code; addressed lifetime, shared loopback predicate, and repeated deep-link findings

Note

Add reusable loopback development auth for simulators and emulators

  • Introduces a dev auth system where T3CODE_DEV_AUTH=1 and a stable T3CODE_DEV_AUTH_KEY (SHA-256 of the worktree root) are injected by the dev runner when binding to the loopback host, enabling reusable pairing without one-time tokens.
  • The server seeds a reusable administrative desktop-bootstrap grant under devAuthKey at startup with unbounded uses and a far-future expiration, so simulators/emulators can reconnect via a stable deep link.
  • Adds isLoopbackAddress, isLoopbackHost, isWildcardHost, and formatHostForUrl utilities to @t3tools/shared/networkHost, and migrates startupAccess.ts to use them; renames the preview-scoped isLoopbackHost to isPreviewLocalHost to avoid collision.
  • Session cookie names are port-namespaced when devAuthKey is configured, isolating dev sessions by port.
  • Risk: the reusable credential is refused on non-loopback hosts and when Tailscale Serve is enabled; physical devices must still use real one-time pairing.

Macroscope summarized 7c9a298.


Note

High Risk
Introduces a reusable administrative bootstrap grant and dev-only auth wiring; risk is mitigated by explicit env flags, loopback-only binding checks, and Tailscale Serve rejection, but misconfiguration could still widen local privilege.

Overview
Adds worktree-scoped reusable dev authentication so agents and local tooling can pair web and simulators without burning one-time tokens.

The dev runner derives a stable key from the canonical worktree path (sha256("t3-dev:" + root)), sets T3CODE_DEV_AUTH / T3CODE_DEV_AUTH_KEY only for dev / dev:server bound to 127.0.0.1, and logs reusable web, iOS, and Android pairing URLs. Non-127.0.0.1 hosts skip dev auth (physical LAN still uses real pairing).

The server reads devAuthKey from config, seeds an unlimited administrative bootstrap grant in PairingGrantStore (same exchange path as desktop bootstrap), and suffixes session cookies by port when dev auth is on so parallel backends do not clobber cookies. Startup rejects dev auth without a key, on non-loopback binds, or with Tailscale Serve.

Mobileconnections/new accepts a pairingUrl param and auto-runs the existing connect flow once per URL. Agent skills and a new implementation plan document describe reusable URLs vs one-time recovery.

Shared adds @t3tools/shared/networkHost with a strict isLoopbackAddress for dev-auth policy; preview code renames loopback checks to isPreviewLocalHost so preview behavior stays separate.

Reviewed by Cursor Bugbot for commit 7c9a298. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added reusable development authentication for loopback web servers.
    • Dev tools now display reusable web, iOS, and Android connection URLs.
    • Mobile simulators and emulators can automatically connect using pairing URLs.
    • Physical-device pairing continues to support fresh, one-time credentials.
    • Added safeguards requiring development authentication to use loopback hosts.
  • Bug Fixes

    • Prevented repeated automatic pairing attempts in the mobile connection flow.
  • Documentation

    • Updated web and mobile testing guidance, troubleshooting steps, and authentication security recommendations.
    • Added an implementation plan for development authentication.

@coderabbitai

coderabbitaiBot commented Jul 23, 2026

Copy link
Copy Markdown
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Title check✅ PassedThe title is concise and accurately summarizes the main change: reusable loopback development auth.
Description check✅ PassedIt explains what changed, why, and how it was verified, though it doesn't follow the exact template headings.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch t3code/53440ffe

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Jul 23, 2026
Comment threadscripts/dev-runner.ts
Comment threadpackages/shared/src/networkHost.ts Outdated
@t3dotgg
t3dotgg marked this pull request as ready for review July 23, 2026 11:10

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 6ddeaf0. Configure here.

Comment threadpackages/shared/src/networkHost.ts
Comment threadpackages/shared/src/networkHost.ts
@macroscopeapp

macroscopeappBot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

This PR modifies authentication logic in apps/server/src/auth/, adding a new reusable development authentication mechanism. Changes to auth directories are treated as sensitive and warrant human review regardless of the guardrails in place.

You can customize Macroscope's approvability policy. Learn more.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
apps/server/src/auth/PairingGrantStore.test.ts (1)

201-221: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Assert the reusable grant’s full shape on the second consume.

The test checks only second.subject; a regression could return the wrong method or reduced scopes after reuse while still passing.

Suggested assertions
 expect(second.subject).toBe("development-bootstrap");
+ expect(second.method).toBe("desktop-bootstrap");+ expect(second.scopes).toEqual(first.scopes);
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@apps/server/src/auth/PairingGrantStore.test.ts` around lines 201 - 221,
Expand the assertions for the second consume in the “seeds the development
credential” test to verify its full grant shape, including method, subject, and
complete scopes. Match the existing first-grant expectations so reuse is
confirmed to preserve all grant fields.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/shared/src/networkHost.ts`:
- Around line 1-13: Update packages/shared/src/networkHost.ts at lines 1-13 so
isLoopbackHost accepts only validated loopback address literals, returning false
for omitted hosts and rejecting hostname-like values such as
127.attacker.example; update apps/server/src/cli/config.ts at lines 362-368 to
require an explicit validated loopback bind before enabling dev auth; update
scripts/dev-runner.ts at lines 326-334 to provision dev auth only with an
explicit 127.0.0.1 bind, otherwise leave it disabled; add regression coverage
for an omitted host and 127.attacker.example.
---
Nitpick comments:
In `@apps/server/src/auth/PairingGrantStore.test.ts`:
- Around line 201-221: Expand the assertions for the second consume in the
“seeds the development credential” test to verify its full grant shape,
including method, subject, and complete scopes. Match the existing first-grant
expectations so reuse is confirmed to preserve all grant fields.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: e6601f36-61f6-4463-aa10-624815e2af0c

📥 Commits

Reviewing files that changed from the base of the PR and between 1c9a6de and 6ddeaf0.

📒 Files selected for processing (21)
  • .agents/skills/test-t3-app/SKILL.md
  • .agents/skills/test-t3-mobile/SKILL.md
  • .plans/21-agent-dev-auth.html
  • apps/mobile/src/features/connection/ConnectionsNewRouteScreen.tsx
  • apps/server/src/auth/EnvironmentAuthPolicy.test.ts
  • apps/server/src/auth/EnvironmentAuthPolicy.ts
  • apps/server/src/auth/PairingGrantStore.test.ts
  • apps/server/src/auth/PairingGrantStore.ts
  • apps/server/src/auth/SessionStore.ts
  • apps/server/src/auth/utils.ts
  • apps/server/src/bin.test.ts
  • apps/server/src/cli/config.test.ts
  • apps/server/src/cli/config.ts
  • apps/server/src/config.ts
  • apps/server/src/environment/ServerEnvironment.test.ts
  • apps/server/src/server.test.ts
  • apps/server/src/startupAccess.ts
  • packages/shared/package.json
  • packages/shared/src/networkHost.ts
  • scripts/dev-runner.test.ts
  • scripts/dev-runner.ts

Comment threadpackages/shared/src/networkHost.ts Outdated
@t3dotgg

Copy link
Copy Markdown
MemberAuthor

Closing because reusable loopback admin credentials have been overtaken by isolated dev state, safe sharing, and recoverable one-time pairing in #4555/#4556/#4955. The explicit pairing model is simpler and matches the current testing workflow.

@t3dotggt3dotgg closed this Jul 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL500-999 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add reusable loopback development auth - #4360

Closed
t3dotgg wants to merge 3 commits into
mainfrom
t3code/53440ffe
Closed

Add reusable loopback development auth#4360
t3dotgg wants to merge 3 commits into
mainfrom
t3code/53440ffe

Conversation

@t3dotgg

@t3dotggt3dotgg commented Jul 23, 2026

Copy link
Copy Markdown
Member

Summary

  • derive a stable public development key from the canonical worktree path and print reusable web/iOS/Android pairing URLs from the dev runner
  • seed that key as a process-lifetime administrative bootstrap grant only when explicitly enabled on a loopback bind
  • namespace dev browser cookies by backend port and auto-submit mobile pairing deep links through the existing onboarding flow
  • update the web/mobile agent testing skills and include the reviewed implementation plan

The development key intentionally assumes a single-user development machine. It is not a production secret, and server config rejects it on wildcard, LAN, Tailnet, or other non-loopback binds. Real pairing remains unchanged.

Verification

  • vp test run scripts/dev-runner.test.ts apps/server/src/cli/config.test.ts apps/server/src/auth/PairingGrantStore.test.ts apps/server/src/auth/EnvironmentAuthPolicy.test.ts apps/server/src/startupAccess.test.ts apps/mobile/src/features/connection/pairing.test.ts (66 tests)
  • affected package typechecks: shared, server, mobile, scripts
  • targeted lint, formatting, and git diff --check
  • web: reused the same printed pairing URL in two fresh browser tabs; both reached the authenticated home
  • iOS Simulator: rebuilt the dev client, opened the printed iOS pairing URL, and confirmed the app connected to the isolated backend
  • Fable review via Claude Code; addressed lifetime, shared loopback predicate, and repeated deep-link findings

Note

Add reusable loopback development auth for simulators and emulators

  • Introduces a dev auth system where T3CODE_DEV_AUTH=1 and a stable T3CODE_DEV_AUTH_KEY (SHA-256 of the worktree root) are injected by the dev runner when binding to the loopback host, enabling reusable pairing without one-time tokens.
  • The server seeds a reusable administrative desktop-bootstrap grant under devAuthKey at startup with unbounded uses and a far-future expiration, so simulators/emulators can reconnect via a stable deep link.
  • Adds isLoopbackAddress, isLoopbackHost, isWildcardHost, and formatHostForUrl utilities to @t3tools/shared/networkHost, and migrates startupAccess.ts to use them; renames the preview-scoped isLoopbackHost to isPreviewLocalHost to avoid collision.
  • Session cookie names are port-namespaced when devAuthKey is configured, isolating dev sessions by port.
  • Risk: the reusable credential is refused on non-loopback hosts and when Tailscale Serve is enabled; physical devices must still use real one-time pairing.

Macroscope summarized 7c9a298.


Note

High Risk
Introduces a reusable administrative bootstrap grant and dev-only auth wiring; risk is mitigated by explicit env flags, loopback-only binding checks, and Tailscale Serve rejection, but misconfiguration could still widen local privilege.

Overview
Adds worktree-scoped reusable dev authentication so agents and local tooling can pair web and simulators without burning one-time tokens.

The dev runner derives a stable key from the canonical worktree path (sha256("t3-dev:" + root)), sets T3CODE_DEV_AUTH / T3CODE_DEV_AUTH_KEY only for dev / dev:server bound to 127.0.0.1, and logs reusable web, iOS, and Android pairing URLs. Non-127.0.0.1 hosts skip dev auth (physical LAN still uses real pairing).

The server reads devAuthKey from config, seeds an unlimited administrative bootstrap grant in PairingGrantStore (same exchange path as desktop bootstrap), and suffixes session cookies by port when dev auth is on so parallel backends do not clobber cookies. Startup rejects dev auth without a key, on non-loopback binds, or with Tailscale Serve.

Mobileconnections/new accepts a pairingUrl param and auto-runs the existing connect flow once per URL. Agent skills and a new implementation plan document describe reusable URLs vs one-time recovery.

Shared adds @t3tools/shared/networkHost with a strict isLoopbackAddress for dev-auth policy; preview code renames loopback checks to isPreviewLocalHost so preview behavior stays separate.

Reviewed by Cursor Bugbot for commit 7c9a298. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added reusable development authentication for loopback web servers.
    • Dev tools now display reusable web, iOS, and Android connection URLs.
    • Mobile simulators and emulators can automatically connect using pairing URLs.
    • Physical-device pairing continues to support fresh, one-time credentials.
    • Added safeguards requiring development authentication to use loopback hosts.
  • Bug Fixes

    • Prevented repeated automatic pairing attempts in the mobile connection flow.
  • Documentation

    • Updated web and mobile testing guidance, troubleshooting steps, and authentication security recommendations.
    • Added an implementation plan for development authentication.

@coderabbitai

coderabbitaiBot commented Jul 23, 2026

Copy link
Copy Markdown
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Title check✅ PassedThe title is concise and accurately summarizes the main change: reusable loopback development auth.
Description check✅ PassedIt explains what changed, why, and how it was verified, though it doesn't follow the exact template headings.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch t3code/53440ffe

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Jul 23, 2026
Comment threadscripts/dev-runner.ts
Comment threadpackages/shared/src/networkHost.ts Outdated
@t3dotgg
t3dotgg marked this pull request as ready for review July 23, 2026 11:10

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 6ddeaf0. Configure here.

Comment threadpackages/shared/src/networkHost.ts
Comment threadpackages/shared/src/networkHost.ts
@macroscopeapp

macroscopeappBot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

This PR modifies authentication logic in apps/server/src/auth/, adding a new reusable development authentication mechanism. Changes to auth directories are treated as sensitive and warrant human review regardless of the guardrails in place.

You can customize Macroscope's approvability policy. Learn more.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
apps/server/src/auth/PairingGrantStore.test.ts (1)

201-221: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Assert the reusable grant’s full shape on the second consume.

The test checks only second.subject; a regression could return the wrong method or reduced scopes after reuse while still passing.

Suggested assertions
 expect(second.subject).toBe("development-bootstrap");
+ expect(second.method).toBe("desktop-bootstrap");+ expect(second.scopes).toEqual(first.scopes);
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@apps/server/src/auth/PairingGrantStore.test.ts` around lines 201 - 221,
Expand the assertions for the second consume in the “seeds the development
credential” test to verify its full grant shape, including method, subject, and
complete scopes. Match the existing first-grant expectations so reuse is
confirmed to preserve all grant fields.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/shared/src/networkHost.ts`:
- Around line 1-13: Update packages/shared/src/networkHost.ts at lines 1-13 so
isLoopbackHost accepts only validated loopback address literals, returning false
for omitted hosts and rejecting hostname-like values such as
127.attacker.example; update apps/server/src/cli/config.ts at lines 362-368 to
require an explicit validated loopback bind before enabling dev auth; update
scripts/dev-runner.ts at lines 326-334 to provision dev auth only with an
explicit 127.0.0.1 bind, otherwise leave it disabled; add regression coverage
for an omitted host and 127.attacker.example.
---
Nitpick comments:
In `@apps/server/src/auth/PairingGrantStore.test.ts`:
- Around line 201-221: Expand the assertions for the second consume in the
“seeds the development credential” test to verify its full grant shape,
including method, subject, and complete scopes. Match the existing first-grant
expectations so reuse is confirmed to preserve all grant fields.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: e6601f36-61f6-4463-aa10-624815e2af0c

📥 Commits

Reviewing files that changed from the base of the PR and between 1c9a6de and 6ddeaf0.

📒 Files selected for processing (21)
  • .agents/skills/test-t3-app/SKILL.md
  • .agents/skills/test-t3-mobile/SKILL.md
  • .plans/21-agent-dev-auth.html
  • apps/mobile/src/features/connection/ConnectionsNewRouteScreen.tsx
  • apps/server/src/auth/EnvironmentAuthPolicy.test.ts
  • apps/server/src/auth/EnvironmentAuthPolicy.ts
  • apps/server/src/auth/PairingGrantStore.test.ts
  • apps/server/src/auth/PairingGrantStore.ts
  • apps/server/src/auth/SessionStore.ts
  • apps/server/src/auth/utils.ts
  • apps/server/src/bin.test.ts
  • apps/server/src/cli/config.test.ts
  • apps/server/src/cli/config.ts
  • apps/server/src/config.ts
  • apps/server/src/environment/ServerEnvironment.test.ts
  • apps/server/src/server.test.ts
  • apps/server/src/startupAccess.ts
  • packages/shared/package.json
  • packages/shared/src/networkHost.ts
  • scripts/dev-runner.test.ts
  • scripts/dev-runner.ts

Comment threadpackages/shared/src/networkHost.ts Outdated
@t3dotgg

Copy link
Copy Markdown
MemberAuthor

Closing because reusable loopback admin credentials have been overtaken by isolated dev state, safe sharing, and recoverable one-time pairing in #4555/#4556/#4955. The explicit pairing model is simpler and matches the current testing workflow.

@t3dotggt3dotgg closed this Jul 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL500-999 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Add reusable loopback development auth - #4360

Closed
t3dotgg wants to merge 3 commits into
mainfrom
t3code/53440ffe
Closed

Add reusable loopback development auth#4360
t3dotgg wants to merge 3 commits into
mainfrom
t3code/53440ffe

Conversation

@t3dotgg

@t3dotggt3dotgg commented Jul 23, 2026

Copy link
Copy Markdown
Member

Summary

  • derive a stable public development key from the canonical worktree path and print reusable web/iOS/Android pairing URLs from the dev runner
  • seed that key as a process-lifetime administrative bootstrap grant only when explicitly enabled on a loopback bind
  • namespace dev browser cookies by backend port and auto-submit mobile pairing deep links through the existing onboarding flow
  • update the web/mobile agent testing skills and include the reviewed implementation plan

The development key intentionally assumes a single-user development machine. It is not a production secret, and server config rejects it on wildcard, LAN, Tailnet, or other non-loopback binds. Real pairing remains unchanged.

Verification

  • vp test run scripts/dev-runner.test.ts apps/server/src/cli/config.test.ts apps/server/src/auth/PairingGrantStore.test.ts apps/server/src/auth/EnvironmentAuthPolicy.test.ts apps/server/src/startupAccess.test.ts apps/mobile/src/features/connection/pairing.test.ts (66 tests)
  • affected package typechecks: shared, server, mobile, scripts
  • targeted lint, formatting, and git diff --check
  • web: reused the same printed pairing URL in two fresh browser tabs; both reached the authenticated home
  • iOS Simulator: rebuilt the dev client, opened the printed iOS pairing URL, and confirmed the app connected to the isolated backend
  • Fable review via Claude Code; addressed lifetime, shared loopback predicate, and repeated deep-link findings

Note

Add reusable loopback development auth for simulators and emulators

  • Introduces a dev auth system where T3CODE_DEV_AUTH=1 and a stable T3CODE_DEV_AUTH_KEY (SHA-256 of the worktree root) are injected by the dev runner when binding to the loopback host, enabling reusable pairing without one-time tokens.
  • The server seeds a reusable administrative desktop-bootstrap grant under devAuthKey at startup with unbounded uses and a far-future expiration, so simulators/emulators can reconnect via a stable deep link.
  • Adds isLoopbackAddress, isLoopbackHost, isWildcardHost, and formatHostForUrl utilities to @t3tools/shared/networkHost, and migrates startupAccess.ts to use them; renames the preview-scoped isLoopbackHost to isPreviewLocalHost to avoid collision.
  • Session cookie names are port-namespaced when devAuthKey is configured, isolating dev sessions by port.
  • Risk: the reusable credential is refused on non-loopback hosts and when Tailscale Serve is enabled; physical devices must still use real one-time pairing.

Macroscope summarized 7c9a298.


Note

High Risk
Introduces a reusable administrative bootstrap grant and dev-only auth wiring; risk is mitigated by explicit env flags, loopback-only binding checks, and Tailscale Serve rejection, but misconfiguration could still widen local privilege.

Overview
Adds worktree-scoped reusable dev authentication so agents and local tooling can pair web and simulators without burning one-time tokens.

The dev runner derives a stable key from the canonical worktree path (sha256("t3-dev:" + root)), sets T3CODE_DEV_AUTH / T3CODE_DEV_AUTH_KEY only for dev / dev:server bound to 127.0.0.1, and logs reusable web, iOS, and Android pairing URLs. Non-127.0.0.1 hosts skip dev auth (physical LAN still uses real pairing).

The server reads devAuthKey from config, seeds an unlimited administrative bootstrap grant in PairingGrantStore (same exchange path as desktop bootstrap), and suffixes session cookies by port when dev auth is on so parallel backends do not clobber cookies. Startup rejects dev auth without a key, on non-loopback binds, or with Tailscale Serve.

Mobileconnections/new accepts a pairingUrl param and auto-runs the existing connect flow once per URL. Agent skills and a new implementation plan document describe reusable URLs vs one-time recovery.

Shared adds @t3tools/shared/networkHost with a strict isLoopbackAddress for dev-auth policy; preview code renames loopback checks to isPreviewLocalHost so preview behavior stays separate.

Reviewed by Cursor Bugbot for commit 7c9a298. Bugbot is set up for automated code reviews on this repo. Configure here.

Summary by CodeRabbit

  • New Features

    • Added reusable development authentication for loopback web servers.
    • Dev tools now display reusable web, iOS, and Android connection URLs.
    • Mobile simulators and emulators can automatically connect using pairing URLs.
    • Physical-device pairing continues to support fresh, one-time credentials.
    • Added safeguards requiring development authentication to use loopback hosts.
  • Bug Fixes

    • Prevented repeated automatic pairing attempts in the mobile connection flow.
  • Documentation

    • Updated web and mobile testing guidance, troubleshooting steps, and authentication security recommendations.
    • Added an implementation plan for development authentication.

@coderabbitai

coderabbitaiBot commented Jul 23, 2026

Copy link
Copy Markdown
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Title check✅ PassedThe title is concise and accurately summarizes the main change: reusable loopback development auth.
Description check✅ PassedIt explains what changed, why, and how it was verified, though it doesn't follow the exact template headings.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch t3code/53440ffe

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XL 500-999 changed lines (additions + deletions). labels Jul 23, 2026
Comment threadscripts/dev-runner.ts
Comment threadpackages/shared/src/networkHost.ts Outdated
@t3dotgg
t3dotgg marked this pull request as ready for review July 23, 2026 11:10

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 6ddeaf0. Configure here.

Comment threadpackages/shared/src/networkHost.ts
Comment threadpackages/shared/src/networkHost.ts
@macroscopeapp

macroscopeappBot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

This PR modifies authentication logic in apps/server/src/auth/, adding a new reusable development authentication mechanism. Changes to auth directories are treated as sensitive and warrant human review regardless of the guardrails in place.

You can customize Macroscope's approvability policy. Learn more.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
apps/server/src/auth/PairingGrantStore.test.ts (1)

201-221: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Assert the reusable grant’s full shape on the second consume.

The test checks only second.subject; a regression could return the wrong method or reduced scopes after reuse while still passing.

Suggested assertions
 expect(second.subject).toBe("development-bootstrap");
+ expect(second.method).toBe("desktop-bootstrap");+ expect(second.scopes).toEqual(first.scopes);
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@apps/server/src/auth/PairingGrantStore.test.ts` around lines 201 - 221,
Expand the assertions for the second consume in the “seeds the development
credential” test to verify its full grant shape, including method, subject, and
complete scopes. Match the existing first-grant expectations so reuse is
confirmed to preserve all grant fields.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/shared/src/networkHost.ts`:
- Around line 1-13: Update packages/shared/src/networkHost.ts at lines 1-13 so
isLoopbackHost accepts only validated loopback address literals, returning false
for omitted hosts and rejecting hostname-like values such as
127.attacker.example; update apps/server/src/cli/config.ts at lines 362-368 to
require an explicit validated loopback bind before enabling dev auth; update
scripts/dev-runner.ts at lines 326-334 to provision dev auth only with an
explicit 127.0.0.1 bind, otherwise leave it disabled; add regression coverage
for an omitted host and 127.attacker.example.
---
Nitpick comments:
In `@apps/server/src/auth/PairingGrantStore.test.ts`:
- Around line 201-221: Expand the assertions for the second consume in the
“seeds the development credential” test to verify its full grant shape,
including method, subject, and complete scopes. Match the existing first-grant
expectations so reuse is confirmed to preserve all grant fields.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: e6601f36-61f6-4463-aa10-624815e2af0c

📥 Commits

Reviewing files that changed from the base of the PR and between 1c9a6de and 6ddeaf0.

📒 Files selected for processing (21)
  • .agents/skills/test-t3-app/SKILL.md
  • .agents/skills/test-t3-mobile/SKILL.md
  • .plans/21-agent-dev-auth.html
  • apps/mobile/src/features/connection/ConnectionsNewRouteScreen.tsx
  • apps/server/src/auth/EnvironmentAuthPolicy.test.ts
  • apps/server/src/auth/EnvironmentAuthPolicy.ts
  • apps/server/src/auth/PairingGrantStore.test.ts
  • apps/server/src/auth/PairingGrantStore.ts
  • apps/server/src/auth/SessionStore.ts
  • apps/server/src/auth/utils.ts
  • apps/server/src/bin.test.ts
  • apps/server/src/cli/config.test.ts
  • apps/server/src/cli/config.ts
  • apps/server/src/config.ts
  • apps/server/src/environment/ServerEnvironment.test.ts
  • apps/server/src/server.test.ts
  • apps/server/src/startupAccess.ts
  • packages/shared/package.json
  • packages/shared/src/networkHost.ts
  • scripts/dev-runner.test.ts
  • scripts/dev-runner.ts

Comment threadpackages/shared/src/networkHost.ts Outdated
@t3dotgg

Copy link
Copy Markdown
MemberAuthor

Closing because reusable loopback admin credentials have been overtaken by isolated dev state, safe sharing, and recoverable one-time pairing in #4555/#4556/#4955. The explicit pairing model is simpler and matches the current testing workflow.

@t3dotggt3dotgg closed this Jul 30, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL500-999 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg