Skip to content

feat(data): thread the host's authenticated fetch into provider:'api' data sources (#2725) - #2732

Merged
os-zhuang merged 1 commit into
mainfrom
claude/github-issue-2725-a70ef3
Jul 20, 2026
Merged

feat(data): thread the host's authenticated fetch into provider:'api' data sources (#2725)#2732
os-zhuang merged 1 commit into
mainfrom
claude/github-issue-2725-a70ef3

Conversation

@baozhoutao

Copy link
Copy Markdown
Contributor

Fixes#2725

Problem

provider: 'api' view data sources went through a bare globalThis.fetch, so custom endpoints (gantt composite trees, report aggregates) carried only same-origin cookies while every native /api/v1/* request carried Authorization: Bearer. The moment cookie HMAC verification failed (dev restart rotating the fallback auth secret, cookie expiry/rotation in prod), those views 401'd while the rest of the app kept working.

The injection points existed from day one (ApiDataSource accepts fetch/defaultHeaders, resolveDataSource passes them through) but no caller ever wired them — see the root-cause confirmation on the issue.

Changes

  • @object-ui/reactSchemaRendererProvider accepts an optional apiFetch; nested providers inherit it from their parent, so re-wrapped subtrees (react pages, studio preview surfaces) keep the host's authentication. useViewData defaults the api-provider adapter's fetch to the context apiFetch (explicit adapterOptions.fetch still wins).
  • @object-ui/authcreateAuthenticatedFetch gains a sameOriginOnly option: cross-origin URLs pass through to the bare fetch with no Authorization / X-Tenant-ID / Accept-Language, so metadata-supplied third-party URLs never see the platform token.
  • @object-ui/app-shell — the console wires withSettleSignal(createAuthenticatedFetch({ sameOriginOnly: true })) as apiFetch on the root SchemaRendererProvider, so api-provider requests carry the same credentials as the native adapter channel and stay visible to the ADR-0054 C5 idle probe.
  • @object-ui/plugin-ganttObjectGantt resolves its api-provider DataSource with the context apiFetch, covering reads AND write-backs.

Backward compatible: hosts that don't provide apiFetch keep the current behaviour (bare fetch + cookies).

Tests

  • auth: sameOriginOnly attaches on same-origin, strips all credential headers cross-origin, legacy no-option behaviour unchanged (3 new).
  • react: useViewData routes api-provider requests through the context apiFetch / explicit override wins (2 new); provider nesting inheritance (3 new).
  • plugin-gantt: ObjectGantt reads through SchemaRendererContext.apiFetch instead of the bare global fetch, and still falls back without one (2 new).
  • Full suites green: auth 89, react 89, plugin-gantt 340; turbo run build --filter=@object-ui/app-shell (29 packages) passes.

Docs updated (react/auth READMEs, plugin-gantt.mdx) + changeset.

🤖 Generated with Claude Code

@vercel

vercelBot commented Jul 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredJul 20, 2026 5:06am

Request Review

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation package: react plugin tests labels Jul 20, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)28.0 KB350 KB
Entry fileindex-BjypM0fO.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)8.19KB2.96KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)21.70KB4.21KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.12KB3.41KB
auth (LoginForm.js)17.86KB5.29KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.43KB2.09KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)33.74KB8.53KB
auth (createAuthenticatedFetch.js)4.37KB1.69KB
auth (index.js)1.83KB0.79KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.86KB0.85KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)18.38KB4.49KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)3.65KB1.42KB
collaboration (PresenceProvider.js)2.42KB0.96KB
collaboration (index.js)1.25KB0.53KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)450.04KB97.85KB
core (index.js)1.86KB0.63KB
create-plugin (index.js)9.28KB2.98KB
data-objectstack (index.js)120.81KB30.10KB
fields (index.js)210.89KB51.70KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.46KB0.96KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)5.37KB1.72KB
i18n (useObjectLabel.js)21.22KB4.69KB
i18n (useSafeTranslation.js)2.87KB1.28KB
layout (index.js)38.45KB10.67KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)4.42KB1.27KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)1.77KB0.77KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)5.90KB2.15KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.46KB1.03KB
permissions (evaluator.js)4.00KB1.23KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.50KB0.70KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.37KB12.48KB
plugin-charts (index.js)46.81KB13.24KB
plugin-chatbot (index.js)179.58KB42.81KB
plugin-dashboard (index.js)108.58KB27.98KB
plugin-designer (index.js)210.92KB42.69KB
plugin-detail (index.js)214.92KB52.44KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)102.94KB24.95KB
plugin-gantt (index.js)162.34KB39.54KB
plugin-grid (index.js)174.50KB46.00KB
plugin-kanban (index.js)47.47KB12.99KB
plugin-list (index.js)98.22KB23.21KB
plugin-map (index.js)16.80KB5.24KB
plugin-markdown (index.js)13.65KB4.67KB
plugin-report (index.js)37.81KB9.98KB
plugin-timeline (index.js)25.37KB7.20KB
plugin-tree (index.js)8.36KB2.81KB
plugin-view (index.js)85.74KB20.86KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.55KB0.67KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)3.19KB1.38KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)18.70KB6.09KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.00KB0.55KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)2.16KB0.94KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)0.77KB0.41KB
types (disclosure.js)0.20KB0.18KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (index.js)2.02KB0.95KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.17KB0.17KB
types (mobile.js)0.20KB0.18KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.26KB1.96KB
types (system-fields.js)2.39KB1.17KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)0.75KB0.46KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

… data sources (#2725)
provider:'api' view data sources used a bare globalThis.fetch, so custom
endpoints carried only same-origin cookies while native requests carried
Authorization: Bearer — cookie HMAC rotation (dev restart, prod expiry)
401'd those views while the rest of the app kept working.
- react: SchemaRendererProvider gains optional apiFetch (inherited by
nested providers); useViewData defaults the api adapter's fetch to it.
- auth: createAuthenticatedFetch({ sameOriginOnly }) passes cross-origin
URLs through untouched so metadata-supplied third-party URLs never see
the platform token.
- app-shell: console wires a settle-signal-wrapped, same-origin-only
authenticated fetch as apiFetch on the root provider.
- plugin-gantt: ObjectGantt resolves its api-provider DataSource with the
context apiFetch (reads and write-backs).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@os-zhuang
os-zhuang merged commit 803558e into mainJul 20, 2026
14 checks passed
@os-zhuang
os-zhuang deleted the claude/github-issue-2725-a70ef3 branch July 20, 2026 07:47
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationpackage: reactplugintests

Projects

None yet

2 participants

@baozhoutao@os-zhuang