Repository navigation
feat!: add readSession and fake tenant org/account APIs - #46
Conversation
106e607 to
75cbdf0
Compare
|
feat!: add readSession and fake tenant org/account APIs (75cbdf0, rebased on 0.6.0) — review fixes. The fake now follows the real service's first-party session rules: a same-browser sign-in revokes the session's earlier credentials, and revoking a token (endpoint or refresh-token family replay) ends its session. FakeTenantClient.type "third-party" keeps a credential outside its session. The contract gains checks for those rules, plain-member and cross-organization refusals on revoke/withdraw/list invitations, and the merged metadata cap; all 70 pass against Udibo's identity service. TenantContractFixture now requires linkAccount and takes signIn(..., { sameBrowser }), so the commit is marked breaking with a migration note. The testing guide's refusal wording is corrected (an admin gets 403 on owner-only actions). |
75cbdf0 to
57aee91
Compare
HonoBff#readSession(c) lets a server that renders pages read who is
signed in without a round trip to GET /auth/session. It counts a session
exactly when the probe does, destroys one past sessionMaxAgeMs and clears
its cookie, needs no CSRF header, and never returns a token. It answers
the same SessionState BffClient.getSession() does, so it can seed the
React provider's initialState.
createFakeTenant now answers the tenant-host organization API
(/api/organizations: create, list, get, rename, delete, members,
member-roles, invitations, offers, accept, revoke a tier) and the
account API (/api/account metadata read and merge, login sessions with
revoke and revoke-others, linked accounts with the last-method guard).
Memberships are grants, so a pending offer confers nothing. Every
signInAs is a new browser whose first authorization starts a login
session. New seeding: FakeTenantUser userMetadata and hasPassword,
signInAs userAgent and ipAddress, linkAccount and defineOrganizationRole.
A first-party application's credentials belong to their login session,
as on a real tenant. A later sign-in in the same browser revokes the
credentials the session issued before, revoking a token at the
revocation endpoint or through refresh-token reuse ends the session,
and ending the session revokes its credentials. FakeTenantClient takes
type "third-party" for an application whose credentials only name the
session they came from and outlive it.
runTenantContractTests covers both new APIs, including those session
rules, a plain member refused every manager action, a manager kept to
the organization the path names, and the metadata cap applied to the
merged bucket. The same checks pass against the fake here and against
the identity service.
BREAKING CHANGE: TenantContractFixture asks more of a fixture.
linkAccount is now required and links an external account to a person.
addUser must honor its optional profile: give the person profile.email,
verify it unless emailVerified is false, and with password false leave
them no password while signIn can still sign them in. signIn takes a
third argument, and with { sameBrowser: true } it must sign the person
in from the browser their previous sign-in used. The fixture's client
must be first-party. createFakeTenant also changed: a second
authorization under one signInAs revokes a first-party application's
earlier credentials, so call signInAs before each sign-in that should
stay independent, or register the client with type "third-party". A
membership seeded without roles, or with [], now holds ["member"]
instead of none.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
57aee91 to
2c102c7
Compare
|
feat!: add readSession and fake tenant org/account APIs (2c102c7) — I moved the branch back onto 0.5.1, which supersedes 75cbdf0. A pointer at a 0.6.0 commit would take Udibo's starters ( |
# [0.8.0](0.7.0...0.8.0) (2026-09-26) * feat!: add readSession and fake tenant org/account APIs ([#46](#46)) ([17e28ab](17e28ab)) ### BREAKING CHANGES * TenantContractFixture asks more of a fixture. linkAccount is now required and links an external account to a person. addUser must honor its optional profile: give the person profile.email, verify it unless emailVerified is false, and with password false leave them no password while signIn can still sign them in. signIn takes a third argument, and with { sameBrowser: true } it must sign the person in from the browser their previous sign-in used. The fixture's client must be first-party. createFakeTenant also changed: a second authorization under one signInAs revokes a first-party application's earlier credentials, so call signInAs before each sign-in that should stay independent, or register the client with type "third-party". A membership seeded without roles, or with [], now holds ["member"] instead of none. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(testing): isolate concurrent session issuance
|
🎉 This PR is included in version 0.8.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
Summary
The BFF can now return token-free session state directly to server-rendered pages through
HonoBff.readSession(c). The fake tenant also supports the organization, account, device-session, and linked-account APIs needed for runnable starter demos. The expanded tenant contract exercises these APIs against a fixture.readSessionshares the session probe's live-session lookup and response projection. Own-session mode enforcessessionMaxAgeMs; shared mode leaves lifetime enforcement to the application/store. Callers must apply private/no-store caching to personalized pages.Fake tenant credentials now follow first-party session revocation rules, with an explicit third-party exception. Credential issuance is serialized per person so simultaneous exchanges from distinct browsers retain their own session binding; ending one browser session leaves the other active. Organization mutations enforce membership tiers, invitations respect ownership and expiry, and metadata validation applies its size limit to UTF-8 bytes after merging.
Breaking changes
TenantContractFixture.linkAccountis required;addUsermust honor the profile fields for email, verification and password, andsignInaccepts{ sameBrowser }.FakeTenantClient.typeselects first-party (default) or third-party behavior.The branch is refreshed onto package main at 0.7.0. The automatic release determines the next version; adopting it in the starters remains a separate change.
Validation
deno task check,deno task test --parallel --reporter=dot(231 tests, 2,753 steps), anddeno task test:allpassed on native Windows.Closes
Nothing. Refs udibo/udibo#1505 and udibo/udibo#1508.
🤖 Generated with Codex