From a4c82c480ce8fda30444c500ef206ec9702798d7 Mon Sep 17 00:00:00 2001 From: Kevin Rajan <7121943+kvnloo@users.noreply.github.com> Date: Sat, 3 Oct 2026 16:14:08 -0500 Subject: [PATCH 1/2] fix(app): encode server credentials as UTF-8 --- packages/app/src/utils/server.ts | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/packages/app/src/utils/server.ts b/packages/app/src/utils/server.ts index 1c8292ca9d95..3f5d2f7a1c3a 100644 --- a/packages/app/src/utils/server.ts +++ b/packages/app/src/utils/server.ts @@ -4,7 +4,8 @@ import type { ServerConnection } from "@/context/server" import { decode64 } from "@/utils/base64" export function authTokenFromCredentials(input: { username?: string; password: string }) { - return btoa(`${input.username ?? "opencode"}:${input.password}`) + const bytes = new TextEncoder().encode(`${input.username ?? "opencode"}:${input.password}`) + return btoa(Array.from(bytes, (byte) => String.fromCharCode(byte)).join("")) } export function authFromToken(token: string | null) { From ccb981699b4c763a9404d19a6d15c32fe5118033 Mon Sep 17 00:00:00 2001 From: Kevin Rajan <7121943+kvnloo@users.noreply.github.com> Date: Sat, 3 Oct 2026 16:14:10 -0500 Subject: [PATCH 2/2] test(app): cover unicode server credentials --- packages/app/src/utils/server.test.ts | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/packages/app/src/utils/server.test.ts b/packages/app/src/utils/server.test.ts index 4666b7d6d03c..106bd605cf14 100644 --- a/packages/app/src/utils/server.test.ts +++ b/packages/app/src/utils/server.test.ts @@ -20,4 +20,15 @@ describe("authTokenFromCredentials", () => { test("encodes credentials with the default username", () => { expect(authTokenFromCredentials({ password: "secret" })).toBe(btoa("opencode:secret")) }) + + test("encodes unicode credentials as UTF-8", () => { + expect(authTokenFromCredentials({ password: "päss" })).toBe( + Buffer.from("opencode:päss", "utf8").toString("base64"), + ) + }) + + test("round trips multibyte credentials", () => { + const token = authTokenFromCredentials({ username: "用户", password: "秘密🔐" }) + expect(authFromToken(token)).toEqual({ username: "用户", password: "秘密🔐" }) + }) })