Hey team ! I’m posting this here because I think it’s for the galaxy’s crew
cc @hschmaiske @anderson
Hi,
Thanks for giving us visibility into this. I will ask our development team to take a look at it
Yeah, I cannot login into Atmosphere and push package updates
Thanks @hschmaiske and the Galaxy team, the Meteor Developer OAuth flow works again ![]()
I checked it end to end today: registered a redirect URI in Galaxy, configured a fresh Meteor 3.5.2 app with the Client ID and Secret, and signed in with my Meteor account. The authorize dialog, the token exchange and the identity endpoint on www.meteor.com all respond correctly ![]()
For anyone setting it up, the page lives at my.galaxycloud.app → Settings → API & Integrations → Authorized Domains. The docs and the accounts-ui configuration dialog still pointed to the old path, so I opened docs(meteor-developer): update OAuth setup steps for the current Galaxy UI by dupontbertrand · Pull Request #14816 · meteor/meteor · GitHub to update both.
@dr.dimitru, @theosp published tap:i18n with the CLI on Oct 4, so package publishing is back too. Worth retrying on your side ![]()
(Small one for the Galaxy team: the “Add domain” modal says “Metor” twice and “indentify” in the App Name description)
@hschmaiske @dupontbertrand Publishing is still failing for me today (5 October), so I don’t think this is fully fixed yet.
I maintain vlasky:galvanized-iron-router and see three failures with the same Meteor account:
meteor publishfails withError from package server: No matching login attempt found [145546287]. Same result with the 3.4.1, 3.5.1 and 3.5.2 tools.meteor whoamireports my account correctly.- Signing in at https://packages.meteor.com ends with
Invalid redirect URI [400]. The redirect URI in the popup ishttps://packages-meteor-com.us.galaxycloud.app/_oauth/meteor-developer?close, i.e. the Galaxy hostname and notpackages.meteor.com. - Signing in at Galaxy 2.0 gives “User account configuration error”. I don’t recall ever using Galaxy with this account.
My guess is that the publish that worked on 4 October used a package-server token that was already saved, which skips the OAuth step. My session has none, so the CLI has to go through the OAuth flow, and the package server’s side of it fails.
I’ve put the details, including a step-by-step replay of the CLI handshake, in Package server login fails: redirect URI points at packages-meteor-com.us.galaxycloud.app, meteor publish cannot authenticate · Issue #14817 · meteor/meteor · GitHub .
Two questions for the Galaxy team:
- Can the package server’s redirect URI be pointed back at
packages.meteor.com, or the Galaxy hostname be authorised? - Do existing Meteor developer accounts now need to be activated on Galaxy before they can publish packages? If so, how?
My last successful publish was on 29 August.
It was working again 5-6 hours later after my post. So, all good as of now. I wander what was it?
Claude code analysis
@vlasky you’re right, and my “publishing is back” was too broad: it only holds for sessions that already have a package-server token
Confirmed from outside: packages.meteor.com serves ROOT_URL=https://packages-meteor-com.us.galaxycloud.app, while atmospherejs.com and www.meteor.com serve their own hostnames. The CLI authorizes with https://packages.meteor.com/_oauth/meteor-developer?close, then the package server exchanges the code with a redirect URI built on the Galaxy hostname. The two never match, so the login ends as “No matching login attempt found”
@hschmaiske the fix is a config change on the Galaxy app behind packages.meteor.com: set ROOT_URL=https://packages.meteor.com and restart it. Registering the Galaxy hostname on the accounts side would not help, since every released meteor tool hardcodes packages.meteor.com. Details in Package server login fails: redirect URI points at packages-meteor-com.us.galaxycloud.app, meteor publish cannot authenticate · Issue #14817 · meteor/meteor · GitHub
@dr.dimitru on Sep 30, the auth dialog on www.meteor.com was blank and the token and identity endpoints returned the website HTML instead of JSON. Both answer correctly now
Hi everyone,
Thanks for the detailed reports, especially @vlasky for the step-by-step in issue #14817.
We found the cause and pushed a fix on the package server: its OAuth redirect URI was being built from the Galaxy hostname instead of packages.meteor.com, so the login handshake never completed and meteor publish failed with No matching login attempt found.
I just tested with a fresh session and a new package, and publishing works again.
If you were affected, please try again with a clean login:
meteor logout
meteor login
meteor publish
Signing in at https://packages.meteor.com should also work now. If you still see any error, reply here with the full message and we’ll take a look.
Thanks for your patience!