Repository navigation
feat(react): optimistic auth gate, token identity guard, optimisticUpdate passthrough, deterministic server construction - #473
Conversation
…date passthrough, deterministic server construction
|
@EfficiencyCorp is attempting to deploy a commit to the udecode Team on Vercel. A member of the Team first needs to authorize it. |
🦋 Changeset detectedLatest commit: a2a007d The changes in this PR will be included in the next version bump. This PR includes changesets to release 2 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
…ocument ConvexAuthProvider gets tokenIdentityBaseline?: string | null. The token identity guard starts from it instead of from initialToken or the first token obtained, so an app that mounts the provider more than once per document (for example per route group over a shared Convex client) keeps refusing another user's or session's token on a remount without a token. Without it, behaviour is unchanged.
tokenIdentityBaseline also accepts a getter, () => string | null, read at every admission (cached tokens included): a token must match both the document's current identity and the one the guard already admitted, so a provider kept mounted but hidden (React <Activity>) cannot resume under an identity the document has moved away from. onTokenIdentityAdmitted?: (token) => void is called with every token the guard admits as it is handed out, cached ones included and refused ones never, so the document can claim the identity at that moment. Both the callback and the getter are read from refs, so new props do not re-run effects or hand Convex a new fetcher.
|
PASS. Independent verification of PR #473 in an isolated worktree. I did not author the implementation. Verified head The five matching package suites pass at the base with 71 tests and at the head with 97 tests and 293 assertions. The fixture suite passes with 12 tests at the base and 14 tests and 57 assertions at the head. Head commands passed:
The canonical Expo check generated, installed, code-generated, and typechecked a fresh app before comparison. The isolated worktree required Source review found no actionable blocker in the auth gate, identity admission, HTTP headers, optimistic mutation integration, or fixture normalization. The fixture tests cover both Expo variants, both comparison scopes, repeated normalization, and retention of other Claude files and non-Expo settings. This verdict does not replace required CI or human code-owner and last-push approval. No merge, automatic merge, or queue request was armed. |
|
Verified head Local, fetched PR ref, and live GitHub head match. The exact-head task plan exists and the body has one matching task-plan line. No branch mutation is planned after this receipt. Proof replay after the final push passes 97 package tests/293 assertions and 14 fixture tests/57 assertions. Independent head proof also passes package typecheck/build and a fresh Expo scaffold, codegen, typecheck, and comparison. Complete Feedback inventory has zero inline threads (resolved or unresolved), zero review bodies, and zero actionable P0-P3 items. Before this receipt, helper counts are 0 threads/2 comments/0 review bodies; raw counts are 3 top-level comments/0 reviews/0 threads. The P1 ledger is empty; no feedback proof remains unreplayed. No P2/P3 deferrals. Non-actionable items are explicitly accounted for:
No automatic merge or queue request is armed. Required GitHub CI and post-push code-owner approval remain mandatory. No protection bypass or local fixture waiver applies. |
🐛 Fixes ➖ N/A
🧭 Task plan: docs/plans/473-optimistic-auth-gate.md
🟢 95-100% confidence
✅ Outcome
🏗️ Design
🧪 Verified
bun checkpasses 1,475 Bun tests, 1,053 Vitest tests (14 skipped), 124 CLI tests, Concave smoke,kitcn verify, and runtime scenarios.