Repository navigation
feat: SDK update for version 28.0.0 - #180
Conversation
|
| const result = await account.createIdTokenSession({ | ||
| provider: IdTokenProvider.Apple, | ||
| idToken: '<ID_TOKEN>', | ||
| nonce: '<NONCE>', // optional |
There was a problem hiding this comment.
This example uses Apple but labels the nonce optional. The new method documentation says Apple requires a nonce and rejects tokens requested without one. A developer who follows the comment and omits it may be unable to create a session.
| nonce: '<NONCE>', // optional | |
| nonce: '<NONCE>', // required for Apple |
Prompt To Fix With AI
This is a comment left during a code review.
Path: docs/examples/account/create-id-token-session.md
Line: 13
Comment:
**Apple nonce marked optional**
This example uses Apple but labels the nonce optional. The new method documentation says Apple requires a nonce and rejects tokens requested without one. A developer who follows the comment and omits it may be unable to create a session.
```suggestion
nonce: '<NONCE>', // required for Apple
```
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| /** | ||
| * Whether the password was found in a known data breach the last time it was checked. Null when the password has never been checked. | ||
| */ | ||
| passwordPwned?: boolean; |
There was a problem hiding this comment.
The field documentation says an unchecked password produces null, but passwordPwned?: boolean tells TypeScript callers to expect only a boolean or undefined. JSON responses are not normalized, so code relying on that type can mishandle an unchecked password.
| passwordPwned?: boolean; | |
| passwordPwned?: boolean | null; |
Knowledge Base Used: API contracts and query construction
Prompt To Fix With AI
This is a comment left during a code review.
Path: src/models.ts
Line: 444
Comment:
**Nullable field excludes null**
The field documentation says an unchecked password produces `null`, but `passwordPwned?: boolean` tells TypeScript callers to expect only a boolean or `undefined`. JSON responses are not normalized, so code relying on that type can mishandle an unchecked password.
```suggestion
passwordPwned?: boolean | null;
```
**Knowledge Base Used:** [API contracts and query construction](https://app.greptile.com/appwrite/-/custom-context/knowledge-base/appwrite/sdk-for-web/-/docs/api-contracts-and-querying.md)
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| * This flow does not return provider refresh tokens. You may pass an access token the provider handed your client, along with its lifetime, to store it on the session - but Appwrite cannot renew it once it expires. If your app needs long-lived access to provider APIs, use the browser-based OAuth2 flow instead. | ||
| * | ||
| * A user is limited to 10 active sessions at a time by default. [Learn more about session limits](https://appwrite.io/docs/authentication-security#limits). | ||
| * |
There was a problem hiding this comment.
This release adds native sign-in and OTP flows and changes required-path validation across services, but adds no tests for the requests or the pre-fetch failures. Tests at the SDK boundary could catch incorrect methods, URLs, payloads and empty-path handling. Assertions that merely mirror source text, configuration or version pins would not cover that behavior.
Knowledge Base Used: Account authentication and sessions
Prompt To Fix With AI
This is a comment left during a code review.
Path: src/services/account.ts
Line: 2497
Comment:
**New flows lack behavior tests**
This release adds native sign-in and OTP flows and changes required-path validation across services, but adds no tests for the requests or the pre-fetch failures. Tests at the SDK boundary could catch incorrect methods, URLs, payloads and empty-path handling. Assertions that merely mirror source text, configuration or version pins would not cover that behavior.
**Knowledge Base Used:** [Account authentication and sessions](https://app.greptile.com/appwrite/-/custom-context/knowledge-base/appwrite/sdk-for-web/-/docs/account-authentication.md)
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
This PR contains updates to the SDK for version 28.0.0.
What's Changed
Account.listLogsand theLog,LogListmodelsClient.setDevKeyX-Appwrite-Response-Format: 2.3.0)Account.createIdTokenSessionfor native Apple and Google sign-in withIdTokenProviderenumAccount.createRecoveryOTPandAccount.updateRecoveryOTPfor code-based password recoveryAccount.createEmailVerificationOTPandAccount.updateEmailVerificationOTPKakaoandTiktokvalues toOAuthProviderpasswordPwnedfield onUserandproviderIdTokenfield onIdentity