{"record":{"id":"59415446773364d9","repo":"thedotmack/claude-mem","slug":"origin-device-id-does-not-match-authenticated-x-de","errorCode":null,"errorMessage":"origin_device_id does not match authenticated X-Device-Id","messagePattern":"origin_device_id does not match authenticated X-Device-Id","errorType":"validation","errorClass":"Error","httpStatus":400,"severity":"error","filePath":"workers/sync-hub/src/do/SyncHub.ts","lineNumber":382,"sourceCode":"\t\t} catch (error) {\n\t\t\tconsole.error(\"sync-hub fan-out failed (advisory; push unaffected):\", error);\n\t\t}\n\t}\n\n\t// ---------------------------------------------------------------------\n\t// Canonical append path and client cursor reads.\n\t// ---------------------------------------------------------------------\n\n\tasync pushOps(deviceId: string, ops: PushOp[], deviceName: string | null = null): Promise<PushOutcome> {\n\t\tlet rows: ValidatedOp[];\n\t\ttry {\n\t\t\tif (typeof deviceId !== \"string\" || deviceId.length === 0) throw invalid(\"deviceId must be non-empty\");\n\t\t\tif (!Array.isArray(ops)) throw invalid(\"ops must be an array\");\n\t\t\trows = await Promise.all(ops.map(async (op, index) => {\n\t\t\t\ttry {\n\t\t\t\t\tconst parsed = await parseCanonicalOperation(op);\n\t\t\t\t\tif (parsed.body.origin_device_id !== deviceId) {\n\t\t\t\t\t\tthrow new Error(\"origin_device_id does not match authenticated X-Device-Id\");\n\t\t\t\t\t}\n\t\t\t\t\treturn parsed;\n\t\t\t\t} catch (error) {\n\t\t\t\t\tthrow invalid(`ops[${index}] ${error instanceof Error ? error.message : String(error)}`);\n\t\t\t\t}\n\t\t\t}));\n\t\t} catch (error) {\n\t\t\tif (error instanceof Error && error.message.startsWith(INVALID_OPS_PREFIX)) {\n\t\t\t\treturn { refused: true, error: error.message };\n\t\t\t}\n\t\t\tif (isDeviceLimitError(error)) return { refused: true, error: DEVICE_LIMIT_ERROR };\n\t\t\tthrow error;\n\t\t}\n\n\t\tconst sql = this.ctx.storage.sql;\n\t\tconst now = Date.now();\n\t\tconst nowDecimal = String(now);\n\t\tconst headBefore = this.headSeq();","sourceCodeStart":364,"sourceCodeEnd":400,"githubUrl":"https://github.com/thedotmack/claude-mem/blob/d8bc9755e74915e5c3b999181e10a67c889bce2a/workers/sync-hub/src/do/SyncHub.ts#L364-L400","documentation":"In SyncHubDO.pushOps, each incoming op body is checked against the deviceId authenticated via the X-Device-Id header. This error fires when an op's payload origin_device_id differs from that authenticated device — i.e. a client is attempting to append operations that claim to originate from another device. It is an authorization guard against cross-device spoofing; the throw is caught by the per-op wrapper and rethrown with the invalid(...)/INVALID_OPS_PREFIX sentinel, causing the whole push to be refused.","triggerScenarios":"Thrown at workers/sync-hub/src/do/SyncHub.ts:382 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Ensure the client sets each op body's origin_device_id to the same device id it authenticates with in the X-Device-Id header","Re-authenticate with the header of the device that actually produced the ops if pushing another device's local queue","Inspect and correct device provisioning so ops are stamped with their true originating device id","Drop or re-originate stale ops that were authored on a device whose id has changed"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"d8bc9755e74915e5c3b999181e10a67c889bce2a","analyzedAt":"2026-09-17T16:40:26.182Z","contentChangedAt":"2026-09-17T16:40:26.182Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}