Skip to content

[Bug]: Pairing fails with HTTP 500 since #10298 because the consume query binds a boolean #16797

Description

@BOTKooper

Before submitting

  • I searched existing issues and did not find a duplicate.
  • I included enough detail to reproduce or investigate the problem.

Area

apps/server

Steps to reproduce

  1. Run the server from main (e.g. vp run dev) on Node 24.
  2. Pair a client with any one-time pairing token stored in the database: the startup pairing URL, a token from node apps/server/src/bin.ts pair, or a link issued from Connections settings.

Or run the existing tests: vp test run src/auth/PairingGrantStore.test.ts in apps/server. Five tests fail, including "issues one-time bootstrap tokens that can only be consumed once".

Expected behavior

A valid token pairs the client. An unknown or used token is rejected as unknown.

Actual behavior

POST /api/auth/browser-session returns HTTP 500 with browser_session_issuance_failed, so the client cannot pair at all.

Cause: #10298 changed the consume query in apps/server/src/persistence/AuthPairingLinks.ts to bind ${requestedScopes === undefined}, a raw JavaScript boolean. node:sqlite rejects boolean parameters before Node 24.21.0 ("Provided value cannot be bound to SQLite parameter"), so the UPDATE ... RETURNING fails for every database-backed token. Boolean binding arrived in nodejs/node#62001, backported to 24.21.0. CI and the desktop app (Electron 44.4.2) both run Node 24.21.0, which is why the tests pass there, but engines allows ^24.13.1, so npx t3 and dev servers on Node 24.13.1–24.20.x hit this. The server's other boolean parameters are bound as 1/0 (? 1 : 0 or Schema.BooleanFromBit).

Impact

Major degradation or frequent failure

Version or commit

main @ cd41c4a

Environment

Arch Linux, Node 24.18.0, server started with vp run dev

Logs or stack traces

ERROR environment api operation failed
  reason: 'browser_session_issuance_failed'
  cause: {
    _tag: 'ServerAuthBootstrapCredentialValidationError',
    cause: { _tag: 'BootstrapCredentialConsumeAvailableError', cause: [Object] }
  }
POST /api/auth/browser-session -> 500

# node:sqlite directly:
Provided value cannot be bound to SQLite parameter 3.

Workaround

None for database-backed tokens. Binding 1/0 in the query fixes it.

Activity

  1. floklein commented on Oct 7, 2026

    @floklein

    Also reproduced on Windows 11, Node v24.18.0, fresh worktree dev server (vp run dev), so it is not platform-specific. Both the startup pairingUrl and a fresh token from node apps/server/src/bin.ts pair fail. The pairing page shows "Primary environment request failed during exchange-bootstrap-credential (HTTP 500)".

    Full cause chain from server.trace.ndjson:

    ServerAuthBootstrapCredentialValidationError
    → BootstrapCredentialConsumeAvailableError
    → PersistenceSqlError (operation: AuthPairingLinkRepository.consumeAvailable:query)
    → SqlError
    → TypeError [ERR_INVALID_ARG_TYPE]: Provided value cannot be bound to SQLite parameter 5.
    

    Changing the bind to ${requestedScopes === undefined ? 1 : 0} locally makes pairing work.

    Two more findings:

    • No other query binds a boolean. On main @ ba0ea3d, AuthPairingLinks.ts:175 is the only SQL template that binds a raw boolean.
    • Why CI is green: PairingGrantStore.test.ts already exercises the real node:sqlite driver and fails on Node 24.18. CI uses node-version-file: package.json, and ^24.13.1 resolves to the newest 24.x, which accepts booleans. So the engines floor (24.13.1–24.20.x) is never tested, and a regression test would not fail in CI either.

    Two open PRs make the same one-line fix: #16730 and #16799 (draft, which says Fixes #16797).

  2. BOTKooper commented on Oct 7, 2026

    @BOTKooper
    Author

    Closed my PR #16799 in favour of #16730, which was opened first and makes the same one-line fix.

  3. juliusmarminge commented on Oct 8, 2026

    @juliusmarminge
    Member

    Note

    Grok responding on behalf of Julius.

    Fixed by #16730 (merged in 4daec10), which now binds the scope-omission flag as 1/0 so pairing works on Node versions before 24.21.0. Closing as completed. Thanks for the detailed report!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions