Skip to content

feat(rn): [P2] Scan desktop QR to authorize desktop login #14

Description

@liuyidi

Summary

After the user is already logged in on the mobile app, allow them to scan a QR code shown on desktop and one-tap approve so the desktop (WebUI / minibot desktop) gets a session — without re-entering email OTP / OAuth on the computer.

This is not:

  • WeChat / phone IdP login
  • IM channel QR (Feishu / Weixin pairing)
  • Expo Go Metro QR

Priority

P2 / deferred. Desktop already has browser OAuth + handoff. RN still has open P0/P1 work; this is a convenience path and should wait until mobile login + Gateway chat are stable.

Proposed shape

Layer Role
mini-auth Own the challenge / approve / token issuance (prefer extending existing Device Flow)
minibot Desktop / WebUI Show QR, poll until ready, materialize local session (reuse handoff pattern)
minibot-react-native Scan (or open deep link) → if already logged in, confirm → call approve API

Happy path:

  1. Desktop: “用手机扫码登录” → start device / login challenge
  2. QR encodes verification_uri_complete (or app deep link)
  3. RN: scan → one-tap approve with existing session
  4. Desktop: poll → install session (e.g. existing /auth/desktop/session-style handoff)

Avoid a minibot-only private “mobile token → desktop cookie” protocol long-term; identity confirmation belongs at the IdP.

RN scope (this repo)

  • Camera / QR scan entry (or handle universal / deep link from QR)
  • “Confirm desktop login” screen when already authenticated
  • Call mini-auth approve API; clear error if logged out / expired challenge
  • Do not block Chat MVP or P0 settings work on this

Related

  • mini-auth: Device Authorization Grant already exists for CLI; needs mobile-friendly approve UX
  • minibot: desktop browser login + /auth/desktop/handoff already ships; QR path would be additive
  • Cross-device login discussion: phone-as-authenticator for desktop (Codex / Discord style)

Out of scope (for now)

  • Using RN to log in a brand-new account via QR alone
  • Replacing primary email OTP / Google / GitHub on RN

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions