Improve PIN pairing window - #130
Merged
Merged
Conversation
maximmaxim345
approved these changes
Aug 5, 2026
maximmaxim345
left a comment
Member
There was a problem hiding this comment.
Nice, changes look good to me.
Really nice to not have a lockout anymore!
maximmaxim345
added a commit
to Sendspin/aiosendspin
that referenced
this pull request
Aug 10, 2026
Improve PIN pairing window. Implements Sendspin/spec#130. ## Breaking changes This PR implements breaking changes made to protocol. However, those only touch encryption/pairing related parts of the Spec. Legacy clients will still keep working as before. Client SDK: `pin_display` and `pairing_window` on `SendspinClient` become a single `pairing_support=PairingSupport(...)`, and the SDK now owns the window lifetime, opened via `open_pairing_window()` instead of a caller-supplied awaitable. `ClientPairingStore`'s failure-counter methods drop their `method` argument and `is_pin_locked_out()` becomes `is_pin_escalated()`. The persisted `pin_failures` mapping becomes an integer, migrated on load. Server SDK: pairing timeouts now raise `PairingTimeoutError` rather than a bare `TimeoutError`.
maximmaxim345
added a commit
to Sendspin/sendspin-js
that referenced
this pull request
Aug 11, 2026
Aligns the client with the new pairing spec changes and moves the E2E dependency to aiosendspin 9.0.0. On the Spec side, this PR implements: - Sendspin/spec#129 - Sendspin/spec#130 - Sendspin/spec#131 - Sendspin/spec#132. ## Pairing `server/activate` now carries a `pairing` object (`method`, `pin_length`, `languages`) in place of `selected_pair_method`, and `pin_length` moved out of `server/pair-init` so the client validates it before an attempt starts. Terminal lockout is gone: a single dynamic-PIN failure counter escalates the method to gesture-gating at ten failures and de-escalates on the next verified round, so repeated wrong PINs can no longer leave a device permanently unpairable. A gesture-gated attempt signals `client/pair-pending` and waits for `openPairingWindow()` rather than closing the connection after five minutes, and a window opened before the server asks now survives a reconnect instead of being silently discarded. Clients can advertise where the operator finds each static secret through `locations`, and which channels convey the dynamic PIN through `out_channels`. A server's spoken-PIN language preference reaches the app as a second argument to `onPairingPin`; the sample player uses it to read the PIN aloud in the operator's language. ## Breaking changes `isPairingLockedOut()` and `clearPairingLockout()` are removed in favour of `isDynamicPinEscalated()`, since escalation has no operator exit other than a successful round. `onPairing` gained a `pending` event and `onPairingPin` a second `languages` argument. New optional config: `pinOutChannels`, `staticPinLocations` and `pairingPskLocations`, all omitted from `client/hello` when unset.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Improve PIN pairing window.
Unifies PIN-pairing consent around the pairing window and replaces terminal lockout with escalation.
static_pinattempt, anddynamic_pinattempts when the method is escalated or the session's PIN is shorter than 6 digits.dynamic_pin-only) no longer ends in terminal lockout: at 10 failures the method is escalated — every attempt becomes gesture-gated until a successful round resets it. Thelocked_outfield (descriptor & config) and abort reason are gone;get-pairing-configreportsescalatedinstead. Static PIN needs no counter: each attempt already costs a window.client/pair-pending. Signals that an attempt is gesture-gated and awaiting a window, without starting the attempt; index-gated likeclient/pair-init.management/open-pairing-window. Lets a paired server open the window in place of the operator gesture.server/activateshape.selected_pair_methodbecomes apairingobject;pin_lengthmoves fromserver/pair-initinto the activation so the client can validate it and decide gating before anything starts.supported_pair_methodsis clarified to list only currently-offered (enabled) methods. Out-channel devices SHOULD shipstatic_pintoo — disabled, with no PIN provisioned; enabling it without a configured (or simultaneously supplied) PIN is rejected.