Skip to content

feat: SDK update for version 28.0.0 - #180

Merged
ChiragAgg5k merged 8 commits into
mainfrom
dev
Sep 24, 2026
Merged

ChiragAgg5k merged 8 commits into
mainfrom
dev

Conversation

@ChiragAgg5k

@ChiragAgg5k ChiragAgg5k commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

This PR contains updates to the SDK for version 28.0.0.

What's Changed

  • Breaking: removed Account.listLogs and the Log, LogList models
  • Breaking: removed Client.setDevKey
  • Breaking: SDK now targets Appwrite 2.3 (X-Appwrite-Response-Format: 2.3.0)
  • Added: Account.createIdTokenSession for native Apple and Google sign-in with IdTokenProvider enum
  • Added: Account.createRecoveryOTP and Account.updateRecoveryOTP for code-based password recovery
  • Added: Account.createEmailVerificationOTP and Account.updateEmailVerificationOTP
  • Added: Kakao and Tiktok values to OAuthProvider
  • Added: passwordPwned field on User and providerIdToken field on Identity
  • Fixed: empty-string required path parameters are rejected instead of sent to the API

@ChiragAgg5k ChiragAgg5k changed the title feat: Web SDK update for version 28.0.0 feat: SDK update for version 28.0.0 Sep 24, 2026
@greptile-apps

greptile-apps Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

The PR appears safe to merge, with non-blocking documentation, typing and behavioral-test improvements recommended.

Fix All in Claude CodeFindings

  1. P2 Apple nonce marked optional ▶
  2. P2 Nullable field excludes null ▶
  3. P2 New flows lack behavior tests ▶
Fix with agent prompt
### Issue 1
docs/examples/account/create-id-token-session.md:13
This example uses Apple but labels the nonce optional. The new method documentation says Apple requires a nonce and rejects tokens requested without one. A developer who follows the comment and omits it may be unable to create a session.

```suggestion
    nonce: '<NONCE>', // required for Apple
```

### Issue 2
src/models.ts:444
The field documentation says an unchecked password produces `null`, but `passwordPwned?: boolean` tells TypeScript callers to expect only a boolean or `undefined`. JSON responses are not normalized, so code relying on that type can mishandle an unchecked password.

```suggestion
        passwordPwned?: boolean | null;
```

### Issue 3
src/services/account.ts:2497
This release adds native sign-in and OTP flows and changes required-path validation across services, but adds no tests for the requests or the pre-fetch failures. Tests at the SDK boundary could catch incorrect methods, URLs, payloads and empty-path handling. Assertions that merely mirror source text, configuration or version pins would not cover that behavior.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

The SDK moves to version 28 and the Appwrite 2.3 response format.

  • Adds native ID-token sign-in, recovery and email-verification OTP methods, provider values and model fields.
  • Removes the documented legacy account-log and dev-key APIs and rejects empty required path parameters.
  • The Apple example, nullable model type and behavioral test coverage need attention.

Reviews (1) · Last reviewed commit: "chore: merge main into dev for the 28.0...."

const result = await account.createIdTokenSession({
provider: IdTokenProvider.Apple,
idToken: '<ID_TOKEN>',
nonce: '<NONCE>', // optional

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Apple nonce marked optional

This example uses Apple but labels the nonce optional. The new method documentation says Apple requires a nonce and rejects tokens requested without one. A developer who follows the comment and omits it may be unable to create a session.

Suggested change
nonce: '<NONCE>', // optional
nonce: '<NONCE>', // required for Apple
Prompt To Fix With AI
This is a comment left during a code review.
Path: docs/examples/account/create-id-token-session.md
Line: 13

Comment:
**Apple nonce marked optional**

This example uses Apple but labels the nonce optional. The new method documentation says Apple requires a nonce and rejects tokens requested without one. A developer who follows the comment and omits it may be unable to create a session.

```suggestion
    nonce: '<NONCE>', // required for Apple
```

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Claude Code Fix in Codex

Comment thread src/models.ts
/**
* Whether the password was found in a known data breach the last time it was checked. Null when the password has never been checked.
*/
passwordPwned?: boolean;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Nullable field excludes null

The field documentation says an unchecked password produces null, but passwordPwned?: boolean tells TypeScript callers to expect only a boolean or undefined. JSON responses are not normalized, so code relying on that type can mishandle an unchecked password.

Suggested change
passwordPwned?: boolean;
passwordPwned?: boolean | null;

Knowledge Base Used: API contracts and query construction

Prompt To Fix With AI
This is a comment left during a code review.
Path: src/models.ts
Line: 444

Comment:
**Nullable field excludes null**

The field documentation says an unchecked password produces `null`, but `passwordPwned?: boolean` tells TypeScript callers to expect only a boolean or `undefined`. JSON responses are not normalized, so code relying on that type can mishandle an unchecked password.

```suggestion
        passwordPwned?: boolean | null;
```

**Knowledge Base Used:** [API contracts and query construction](https://app.greptile.com/appwrite/-/custom-context/knowledge-base/appwrite/sdk-for-web/-/docs/api-contracts-and-querying.md)

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Claude Code Fix in Codex

Comment thread src/services/account.ts
* This flow does not return provider refresh tokens. You may pass an access token the provider handed your client, along with its lifetime, to store it on the session - but Appwrite cannot renew it once it expires. If your app needs long-lived access to provider APIs, use the browser-based OAuth2 flow instead.
*
* A user is limited to 10 active sessions at a time by default. [Learn more about session limits](https://appwrite.io/docs/authentication-security#limits).
*

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 New flows lack behavior tests

This release adds native sign-in and OTP flows and changes required-path validation across services, but adds no tests for the requests or the pre-fetch failures. Tests at the SDK boundary could catch incorrect methods, URLs, payloads and empty-path handling. Assertions that merely mirror source text, configuration or version pins would not cover that behavior.

Knowledge Base Used: Account authentication and sessions

Prompt To Fix With AI
This is a comment left during a code review.
Path: src/services/account.ts
Line: 2497

Comment:
**New flows lack behavior tests**

This release adds native sign-in and OTP flows and changes required-path validation across services, but adds no tests for the requests or the pre-fetch failures. Tests at the SDK boundary could catch incorrect methods, URLs, payloads and empty-path handling. Assertions that merely mirror source text, configuration or version pins would not cover that behavior.

**Knowledge Base Used:** [Account authentication and sessions](https://app.greptile.com/appwrite/-/custom-context/knowledge-base/appwrite/sdk-for-web/-/docs/account-authentication.md)

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

Fix in Claude Code Fix in Codex

@ChiragAgg5k
ChiragAgg5k merged commit 4f83d27 into main Sep 24, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants