Skip to content

feat(react): optimistic auth gate, token identity guard, optimisticUpdate passthrough, deterministic server construction - #473

Merged
zbeyens merged 8 commits into
udecode:mainfrom
EfficiencyCorp:feat/optimistic-auth-gate
Sep 30, 2026
Merged

zbeyens merged 8 commits into
udecode:mainfrom
EfficiencyCorp:feat/optimistic-auth-gate

Conversation

@EfficiencyCorp

@EfficiencyCorp EfficiencyCorp commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor
  • Auto release

🐛 Fixes ➖ N/A

🧭 Task plan: docs/plans/473-optimistic-auth-gate.md

🟢 95-100% confidence

Phase 🧪 Tests 🌐 Browser
Reproduced 🔴 Mock contamination, callback cleanup, stale getter admission, and host-dependent fixture drift ➖ N/A
Verified 🟢 97 focused package tests, 14 fixture tests, package typecheck/build, and complete bun check ➖ N/A

✅ Outcome

  • Opt-in optimistic auth and identity admission guard Convex and HTTP token reuse.
  • Convex owns optimistic mutation updates; server clients preserve request isolation without random construction.
  • Fixture snapshots exclude host-dependent Expo settings and match current donor output.

⚠️ Caveat

  • Merge requires passing final-head GitHub CI and post-push code-owner approval. No protection bypass or fixture waiver applies.

🏗️ Design

  • Live identity getters are read at admission. The client closes before mismatch callbacks run.
  • Retry-test doubles use file-scoped spies instead of process-global module mocks.
  • Snapshot generation and both comparison scopes share the existing donor-aware normalizer. Product scaffold output is unchanged.

🧪 Verified

  • Focused package suite passes 97 tests/293 assertions; fixture regression passes 14 tests/57 assertions.
  • Package typecheck/build and all eight canonically regenerated fixture checks pass.
  • bun check passes 1,475 Bun tests, 1,053 Vitest tests (14 skipped), 124 CLI tests, Concave smoke, kitcn verify, and runtime scenarios.
  • Docs and published skill guidance match the API. Direct review, agent-native audit, autoreview, and secret scan are clean.

…date passthrough, deterministic server construction
@vercel

vercel Bot commented Sep 27, 2026

Copy link
Copy Markdown

@EfficiencyCorp is attempting to deploy a commit to the udecode Team on Vercel.

A member of the Team first needs to authorize it.

@changeset-bot

changeset-bot Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: a2a007d

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
Name Type
kitcn Patch
@kitcn/resend Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

…ocument

ConvexAuthProvider gets tokenIdentityBaseline?: string | null. The token
identity guard starts from it instead of from initialToken or the first
token obtained, so an app that mounts the provider more than once per
document (for example per route group over a shared Convex client) keeps
refusing another user's or session's token on a remount without a token.
Without it, behaviour is unchanged.
tokenIdentityBaseline also accepts a getter, () => string | null, read at
every admission (cached tokens included): a token must match both the
document's current identity and the one the guard already admitted, so a
provider kept mounted but hidden (React <Activity>) cannot resume under an
identity the document has moved away from.

onTokenIdentityAdmitted?: (token) => void is called with every token the
guard admits as it is handed out, cached ones included and refused ones
never, so the document can claim the identity at that moment. Both the
callback and the getter are read from refs, so new props do not re-run
effects or hand Convex a new fetcher.
@zbeyens zbeyens closed this Sep 29, 2026
@zbeyens zbeyens reopened this Sep 29, 2026
@zbeyens

zbeyens commented Sep 30, 2026

Copy link
Copy Markdown
Member

PASS. Independent verification of PR #473 in an isolated worktree. I did not author the implementation.

Verified head a2a007d5f789f262dd73d92225d9052f33b92823 against base 3250fb9cae19342dce587520cd9850abc8cad08b on udecode/kitcn:main. Stable base-to-head patch-id is cbea15be2c8d281b6154665652aab7f4fa0dba36.

The five matching package suites pass at the base with 71 tests and at the head with 97 tests and 293 assertions. The fixture suite passes with 12 tests at the base and 14 tests and 57 assertions at the head.

Head commands passed:

  • bun test ./packages/kitcn/src/auth-client/convex-auth-provider.test.tsx ./packages/kitcn/src/auth-start/index.retry.test.ts ./packages/kitcn/src/react/context.test.tsx ./packages/kitcn/src/react/use-query-options.test.tsx ./packages/kitcn/src/react/client.test.ts
  • bun test ./tooling/fixtures.test.ts
  • bun --cwd packages/kitcn typecheck
  • bun --cwd packages/kitcn build
  • bun tooling/fixtures.ts check expo --backend concave

The canonical Expo check generated, installed, code-generated, and typechecked a fresh app before comparison. The isolated worktree required bun --cwd packages/resend build first because its generated dist directory was absent. No tracked files changed during verification.

Source review found no actionable blocker in the auth gate, identity admission, HTTP headers, optimistic mutation integration, or fixture normalization. The fixture tests cover both Expo variants, both comparison scopes, repeated normalization, and retention of other Claude files and non-Expo settings.

This verdict does not replace required CI or human code-owner and last-push approval. No merge, automatic merge, or queue request was armed.

@zbeyens

zbeyens commented Sep 30, 2026

Copy link
Copy Markdown
Member

Verified head a2a007d5f789f262dd73d92225d9052f33b92823 for udecode/kitcn#473.
Destination main at 3250fb9cae19342dce587520cd9850abc8cad08b.
Stable base-to-head patch-id cbea15be2c8d281b6154665652aab7f4fa0dba36.

Local, fetched PR ref, and live GitHub head match. The exact-head task plan exists and the body has one matching task-plan line. No branch mutation is planned after this receipt.

Proof replay after the final push passes 97 package tests/293 assertions and 14 fixture tests/57 assertions. Independent head proof also passes package typecheck/build and a fresh Expo scaffold, codegen, typecheck, and comparison. Complete bun check passes all eight fixture comparisons, 1,475 Bun tests, 1,053 Vitest tests (14 skipped), 124 CLI tests, Concave smoke, verify, and runtime scenarios. Source review, incremental autoreview, agent-native audit, and secret scan have no accepted findings.

Feedback inventory has zero inline threads (resolved or unresolved), zero review bodies, and zero actionable P0-P3 items. Before this receipt, helper counts are 0 threads/2 comments/0 review bodies; raw counts are 3 top-level comments/0 reviews/0 threads. The P1 ledger is empty; no feedback proof remains unreplayed. No P2/P3 deferrals.

Non-actionable items are explicitly accounted for:

No automatic merge or queue request is armed. Required GitHub CI and post-push code-owner approval remain mandatory. No protection bypass or local fixture waiver applies.

@zbeyens
zbeyens merged commit 16e0bb4 into udecode:main Sep 30, 2026
4 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants