September 10, 2026
One Auth Path, Not Two
Deleted device pairing outright so desktop and browser run the exact same auth path, fixed a scoring model that had been silently guessing for weeks, and made the installer stop refusing hosts over a python version.
Killed a feature I built myself back in June: device pairing. QR code, bearer token, the whole link-a-mobile-client-to-your-desktop flow. Gone. Every client now logs in the same way — a session cookie, same origin, no exceptions.
Pairing existed because the desktop app and the browser used to be different beasts under the hood: one had a native host adapter, one didn’t, and bridging them meant a QR handshake and a bearer token riding over a websocket. That’s two authentication paths for one product, and two paths mean two sets of edge cases, two things that can silently drift apart, two places a bug hides. I’d already been trimming this down for months — collapsing login onto one path back in July was the same instinct. Today I finished the job: ripped the pairing pages, the master-username endpoint, and the websocket bearer handshake out of the backend, then pulled the QR flow, the vault-unlock overlay, and the native host adapter out of both frontends. The on-device speech branch the native adapter fed went with it — the mic button now always records through the browser and the server transcriber. Desktop and browser build from one identical bundle now. Not “mostly the same.” Identical.
Second thing, uglier: the model I use to decide how hard Chalie should think about a given turn had been broken for an unknown stretch of time. Silently. A tokenizer library got swapped out at some point, and the classifier started throwing on every single call — caught, logged as a warning, and treated as “no answer,” which meant every turn defaulted to the lowest thinking level whether it needed it or not. No crash, no alert, just a system quietly doing less than it was supposed to and reporting nothing. Found it, fixed it by giving the classifier its own tokenizer pinned to the exact 256-token window its model was trained on, instead of sharing one with the embedding path whose truncation window turned out to be mutable state two different callers were fighting over. That’s the actual bug: not the swap itself, but a shared object with hidden state that two unrelated features both thought they owned. Confirmed the token ids match the old path exactly before calling it fixed.
Also patched the installer, which has been quietly hostile to two entire Linux distributions. Ubuntu 22.04 and AlmaLinux 9 both ship a python3 older than what Chalie needs, and the installer used to just stop and hand you a manual instruction. Now it pulls a properly managed CPython 3.12 and builds the virtualenv off that — resolved only from the tool’s own known-good builds, never a stray system or pyenv python that happens to be sitting on the machine, because “happens to be on PATH” is exactly the kind of thing that works on my laptop and nowhere else. A download that fails, or an interpreter that can’t be provided, now says so loudly instead of limping into a half-built environment.
Three unrelated fixes, one habit: stop tolerating a system that quietly does less than it claims. Auth had a redundant path. The thinking-level model had a failure nobody could see. The installer had a requirement that didn’t need to exist. The one I actually want to watch is the classifier — it’s been under-thinking on an unknown number of turns for an unknown stretch of time, and I have no clean way to measure how much that cost until I watch what changes now that it’s actually scoring.
-
Removed device pairing entirely — QR link-device flow, bearer-token transport, vault-unlock overlay, and the native host adapter are gone from both web apps
-
Desktop and browser now run one identical frontend bundle, authenticated by session cookie only
-
Fixed the deliberation-scoring classifier, which had been silently failing and defaulting every turn to the lowest thinking level since a tokenizer library swap
-
Installer now provisions a managed Python 3.12 when the host’s python3 is too old, instead of refusing to install on Ubuntu 22.04 and AlmaLinux 9
-
Installer now fails loudly on a bad download or missing interpreter instead of continuing into a broken environment