fix(desktop): recognize the LAN-bound local server when tagging client tokens
The client-create gate added in 1.13.9 rejects client tokens without the desktop-local kind, but the kind was only attached when the runtime origin exactly matched the injected local origin — an empty (same-origin) api base, loopback aliases, and the embedded server addressed via a LAN interface (0.0.0.0 binds) all minted untagged tokens, which then hit 403 and surfaced as "Local — Auth required" plus the unreachable-server screen. The renderer now treats same-origin and loopback targets as local, the Electron main additionally matches any of the machine's own interface addresses on the local server's port, and a deduped kind-tagged mint migrates away legacy same-label tokens that predate client kinds. The client-create gate itself is unchanged.
This commit is contained in:
@@ -135,6 +135,14 @@ export const createRemoteClientAuthRuntime = ({ fsPromises, path, crypto, storeP
|
||||
};
|
||||
if (normalizedDedupeKey) {
|
||||
store.clients = store.clients.filter((entry) => entry.dedupeKey !== normalizedDedupeKey);
|
||||
// Migrate pre-clientKind desktop tokens: a deduped, kind-tagged mint
|
||||
// supersedes legacy records with the same label that carry neither a
|
||||
// kind nor a dedupe key — those tokens can no longer pass the
|
||||
// desktop-local client-create gate and would otherwise linger forever.
|
||||
if (client.clientKind) {
|
||||
store.clients = store.clients.filter((entry) =>
|
||||
!(entry.label === client.label && !entry.clientKind && !entry.dedupeKey));
|
||||
}
|
||||
}
|
||||
store.clients.push(client);
|
||||
await writeStore(store);
|
||||
|
||||
Reference in New Issue
Block a user