Repository navigation
fix(tweet): send cookies when fetching the X shell for the transaction ID - #21
Merged
Merged
Conversation
…n ID x-client-transaction-id resolves the ondemand.s chunk URL from the webpack chunk map, which X now only serves on the authenticated shell: anonymous requests get the new Rolldown/Vite build, so ClientTransaction.create() throws OnDemandFileUrlResolutionError before the request is sent. The shell fetch only sent config.headers, so it was always anonymous even with an API key configured (a regression from the same fix in Rettiwt #885). Add buildXShellHeaders() to attach the decoded cookie, and keep the candidate routes (/home first) as a guest fallback. Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
Add docs/features/tweet/transaction-id.md with the measurements (cookie vs anonymous shell, indices rotating per build), update postmortem 013 with the corrected root cause, and refresh the dev log and CHANGELOG. Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Owner
Author
AI Code Review范围:单文件 结论:✅ 可以合并(CI 全绿:typecheck / lint / verify / build / build-storybook)。 核对项
残留 / 后续(不阻塞)
|
Add AC-TWEET-011 plus a behavioral test that mocks axios.get and runs the real `_fetchTransactionDocument`, asserting the shell request actually carries the decoded cookie (and stays anonymous without an API key). The pure-function unit tests cannot catch the regression shape -- the caller dropping the cookie -- which is exactly how upstream #885's fix was lost in #888. Falsifiability checked: reverting `_fetchXHomePage` to `this.config.headers` turns the case red (`expected undefined to be 'auth_token=...'`). - test/acceptance/ac-tweet.spec.ts: AC-TWEET-011 (2 cases) - verify/acceptance-criteria/AC-tweet.md: v1.2, AC-TWEET-011 + summary row - verify/README.md: AC-TWEET-001~011, suite 0.3.2 Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
- docs/development-log/2026-09-25.md: AC close-out section -- motivation (the pure-function tests cannot see the caller dropping the cookie), placement, falsifiability check and scope (verification only, runtime semantics unchanged) - docs/development-log/README.md: add AC-TWEET-011 to the 2026-09-25 timeline row - CHANGELOG.md: AC-TWEET-011 regression guard entry Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
背景
GET /api/tweet/get等全部 X 数据接口报OnDemandFileUrlResolutionError,在请求发出前(ClientTransaction.create())即失败。根因
x-client-transaction-id从外壳 HTML 的 webpack chunk map 解析ondemand.s的 URL。X 现在只对登录态返回仍含该 chunk map 的旧外壳,匿名请求拿到的是新版 Rolldown/Vite 外壳——而_handleXMigration()只发送config.headers,从不附带 cookie,因此外壳请求永远匿名,即便配置了TWEET_KEYS。同一 URL
x.com/home实测(仅切换Cookie):ondemand.s/home/home这是回归:上游 Rettiwt #885 曾以「抓外壳时附 cookie」修好同一错误,被 #888 合并时丢失。
改动
buildXShellHeaders(headers, apiKey):存在 API Key 时附带AuthService.decodeCookie(apiKey)_fetchXHomePage改为使用它;候选列表改名X_SHELL_URLS并把/home提到首位,legacy 路由降级为无 Key(guest)时的兜底验证
bun run typecheck/bun run lint/bun run test(451 passed)/bun run verify/index.ts --exit-on-fail(459 passed / 7 skipped)全绿;pre-push 的build与build-storybook亦通过TweetDetail与TweetLikers(#908 的复现接口)均成功返回test/acceptance/ac-tweet.spec.ts):mockaxios.get后跑真实_fetchTransactionDocument,断言实际发出的外壳请求头带解码后 cookie、无 Key 时保持匿名。纯函数单测覆盖不到「调用点丢掉 cookie」这一回归形态——正是 #885→#888 的丢失方式。Falsifiability 复核:回退_fetchXHomePage为this.config.headers后该用例变红文档
docs/features/tweet/transaction-id.md:调研(含ondemand.sindices 每构建随机、不可 pin 的实测)verify/acceptance-criteria/AC-tweet.mdv1.2(AC-TWEET-011)+verify/README.mdAC 计数同步