Repository navigation
Conversation
…achine clerk auth login now races the loopback callback against a paste prompt in interactive terminals. Signing in on another device leaves the browser on a failed 127.0.0.1 redirect; pasting that URL completes the login. The pasted URL passes the same state check as the loopback redirect, and the code is still bound to the PKCE verifier held by the CLI.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (9)
🔗 Linked repositories identifiedCodeRabbit considers these linked repositories for cross-repo context during reviews:
Included review availability: This review used your included allowance. 9 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 10 reviews per hour. 📝 WalkthroughWalkthroughInteractive TTY login now accepts a pasted redirect URL or the loopback callback. Pasted URLs use shared state and authorization-code validation. Login aborts the outstanding prompt and stops the authentication server when either path completes. Non-TTY and agent runs continue to use the loopback callback. The changes also update callback handling, tests, and login documentation. Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Suggested reviewers: Merge Risk: ⚪ Minimal · up to The paste-back login flow is mergeable after normal checks; the investigated validation and prompt-cancellation paths do not show a blocking issue. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Comment |
🦋 Changeset detectedLatest commit: 913a1c3 The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
|
!snapshot |
Snapshot failedView the workflow run for details. |
What
clerk auth logincan now finish on a machine without a browser. In an interactive terminal it shows a paste prompt next to the usual wait, so you can sign in on another device and paste back the URL your browser lands on.Why
Login is an OAuth redirect to a local callback server on
127.0.0.1. Over SSH, or on any box without a GUI, you can open the printed URL on your laptop, but the final redirect then goes to the laptop's127.0.0.1, fails to load, and the CLI waits until it times out. SSH port forwarding is the only workaround, and it's awkward because the callback port is random on every run.How
statecheck refuses a URL from someone else's sign-in, so nobody can trick you into finishing their login and signing into their account (RFC 6749 §10.12). A wrong or stale URL re-prompts. A denied consent (error=) ends the login, as it does on the loopback path.redirect_uri, which Clerk already accepts on any port (RFC 8252 §7.3), and the code is useless without the PKCE verifier that never leaves the process (RFC 7636 §4.6). The pasted URL is never logged.stop()on the callback server now rejects the pending wait. Login carries on in the same process when the paste wins, and an open wait would have pinned the human-wait counter, making every later Ctrl-C exit 0..claude/rules/interrupts.mdis updated to match.