feat: browser experiments with auth-safe exposure tracking - #280
Open
LiorMazig wants to merge 5 commits into
Open
feat: browser experiments with auth-safe exposure tracking#280LiorMazig wants to merge 5 commits into
LiorMazig wants to merge 5 commits into
Conversation
🚀 Package Preview Available!Install this PR's preview build with npm: npm i @base44-preview/sdk@0.8.48-pr.280.7eec9baPrefer not to change any import paths? Install using npm alias so your code still imports npm i "@base44/sdk@npm:@base44-preview/sdk@0.8.48-pr.280.7eec9ba"Or add it to your {
"dependencies": {
"@base44/sdk": "npm:@base44-preview/sdk@0.8.48-pr.280.7eec9ba"
}
}
Preview published to npm registry — try new features instantly! |
Author
|
CI verification update:
Stable |
LiorMazig
marked this pull request as ready for review
September 10, 2026 04:50
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
base44.experimentsfor browser feature-flag reads, auth-aware readiness/subscriptions, and experiment exposure tracking. Draft pending platform integration and complete validation; no stable package release or dependency changes.Intent (for reviewers & PR Autofix)
What this PR does
Adds SDK-owned local experiment evaluation for browsers/request-scoped Workers, common-auth reactivity, hydration snapshots and acknowledged exposure delivery. Live QA follow-ups preserve occurrence-time preview intent on goals and isolate server Analytics clients.
Key decisions & why
What NOT to touch
Package version, dependencies and lockfiles are unchanged intentionally. The context header is not authentication: app ingress must strip/rebuild it. Preserve existing void/best-effort Analytics tracking rather than claiming durable delivery or adding a new public API.
Tradeoffs / follow-ups
Ten added regression cases cover preview capture and concurrent public Worker clients, including separate apps/users, cleanup/token-reset isolation and fallback identities. Focused local runs pass (59 experiment/auth tests; 22 analytics/client tests, overlapping). Local Vitest/dependency aliases differ from the lockfile; expanded collection/type checking remains dependency-blocked, so current-head locked CI is required.
The preceding head passed 355 locked unit/type tests and preview publishing; that is not new-head evidence. Matching platform preview-goal filtering and rebuilt SDK adoption must ship together. Stable release, live Worker/auth QA and delayed finalization remain rollout gates. Retries are memory-bound, not offline-durable or exactly-once.
Testing
git diff --checkpassed.npm ciis blocked by local registry/security access; offline cache is incomplete. Full unit/type tests, build, lint, and generated documentation remain unverified locally and require CI or restored dependency access.