From 53ab03dc4d408cde53035acf551c7d2f019f0ff5 Mon Sep 17 00:00:00 2001 From: Ben Barclay Date: Mon, 24 Aug 2026 16:58:51 +1000 Subject: [PATCH] fix(auth): thread use_https into the native password-login PKCE clear MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Merging main brought in the RFC 8252 native sign-in path for password providers (#75808), added while this PR was open. Its loopback-code branch calls clear_pkce_cookie() without use_https, which is now a required keyword-only argument — so /auth/native/password-login raised TypeError on the success path. This is the same call-site class the PR already fixed at the other three sites: the deletion must mirror the shape the setter emitted for the active origin, or the browser keeps the stale PKCE cookie. Caught by CI running the merge commit against main's newer test_dashboard_auth_native_flow.py suite, which does not exist on the branch. Three tests failed there and pass with this change. --- hermes_cli/dashboard_auth/routes.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/hermes_cli/dashboard_auth/routes.py b/hermes_cli/dashboard_auth/routes.py index 04832b35b7..d42165f867 100644 --- a/hermes_cli/dashboard_auth/routes.py +++ b/hermes_cli/dashboard_auth/routes.py @@ -854,7 +854,7 @@ async def auth_password_login(request: Request, body: _PasswordLoginBody): # this window" page. No session cookies: the desktop is not a # browser session (mirrors the /auth/callback native branch). resp = JSONResponse({"ok": True, "next": loopback}) - clear_pkce_cookie(resp, prefix=_prefix(request)) + clear_pkce_cookie(resp, use_https=detect_https(request), prefix=_prefix(request)) return resp expires_in = max(60, session.expires_at - int(time.time()))