Conversation
…approval After the browser approves the device, login saves the token to the system keyring. That can block on an unlock prompt, such as GNOME Keyring's password dialog, which may open on another screen. The spinner kept saying "Waiting for confirmation..." the whole time, so login looked stuck on the browser step even though access had been approved. Once the token arrives, the spinner now says access was approved and that credentials are being saved, and that the keyring may ask to be unlocked. See planetscale#1132. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The token endpoint can return the same generic error_description for every device-flow error, including expired_token: "The authorization server encountered an unexpected condition which prevented it from fulfilling the request." When a confirmation code expired before it was approved, login reported what read like a server failure. Describe RFC 8628's terminal device-flow errors from their error codes: an expired code tells the user to run `pscale auth login` again, and a denied request says it was denied. Other errors still use the server's description. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Two
pscale auth loginmessages make a working login look stuck or broken.1. "Waiting for confirmation..." stays up after access is approved
After the browser approves the device, login saves the token to the system keyring. On Linux that can block on an unlock prompt, such as GNOME Keyring's password dialog, which may open on another screen or behind other windows. The spinner keeps saying "Waiting for confirmation..." the whole time, so the user keeps looking at the browser step even though it already succeeded. This is the situation in #1132, which was closed when the reporter found the keyring popup, but the CLI output was never changed.
On a machine with a locked login keyring, the keyring's prompter process starts one poll interval after
auth loginstarts. Thepscaleprocess then has no connection open to the auth server, and it stays on "Waiting for confirmation..." well past the code's 5-minute expiry.Once the token arrives, the spinner now changes to:
It uses the existing
ProgressHandle.Update, the same waymetrics reportand the D1 import progress do. JSON mode is unchanged.2. An expired code is reported as a server failure
The token endpoint currently returns the same
error_descriptionfor every device-flow error, includingauthorization_pendingandexpired_token:ErrorResponse.Error()returns only the description, so when a confirmation code expires before it's approved, login reports what reads like a server crash. The terminal device-flow errors from RFC 8628 §3.5 are now described from their error codes:expired_token: "the confirmation code expired before it was approved; run 'pscale auth login' again"access_denied: "the login request was denied in the browser"Other errors still use the server's description. The server's generic
error_descriptionfor these codes may be worth fixing too.Testing
go build ./...,go vet,staticcheckon the changed packages, andgo test ./...all pass.TestGetAccessTokenForDeviceTerminalErrorscoversexpired_tokenandaccess_deniedarriving with the generic description.⠼ Waiting for confirmation...⠴ Access approved. Saving credentials to your system keyring; if it asks to be unlocked, enter your keyring password...Successfully logged in.once the save completes.🤖 Generated with Claude Code