Skip to content

feat: SDK update for version 28.1.0 - #181

Merged
Meldiron merged 11 commits into
mainfrom
dev
Sep 25, 2026
Merged

Meldiron merged 11 commits into
mainfrom
dev

Conversation

@Meldiron

Copy link
Copy Markdown
Contributor

This PR contains updates to the SDK for version 28.1.0.

What's Changed

  • Added: Apps service to create and manage OAuth2 apps, their secrets, keys, and installations
  • Added: Oauth2 service for authorization, consent, device, PAR, and token flows
  • Added: App, AppSecret, AppKey, AppScope and Oauth2* response models

@greptile-apps

greptile-apps Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] SDK adds new service classes and updates dependencies.

The PR has no newly established blocking defect, though the two earlier non-blocking findings remain open.

Fix All in Claude CodeFindings

  1. P2 App-key usage is unclear ▶
  2. P2 Token flows lack behavior tests ▶
Fix with agent prompt
### Issue 1
src/services/apps.ts:undefined-1081
This method says callers can use an app key, but the request sends neither `X-Appwrite-Key` nor `X-Appwrite-App`, and `Client` has no setter for either. A caller following this API and its example cannot use the documented app-key path without directly modifying `client.headers`. Please document a supported way to supply those credentials, or direct callers to an appropriate server-side SDK.

### Issue 2
src/services/oauth-2.ts:1815-1820
The new token exchange supports authorization-code, refresh-token, and device-code flows, but none has a behavior test. Tests covering the requests and responses for each flow would catch credential or serialization regressions. Please test observable behavior rather than mirroring method bodies, configuration, or version strings.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

The PR updates the Web SDK to 28.1.0 and adds:

  • Apps and Oauth2 services for application management and OAuth2 flows.
  • Response models, usage examples, and release documentation for those APIs.

Reviews (2) · Last reviewed commit: "chore: merge main into dev for the 28.1...."

Comment thread src/services/apps.ts
}

/**
* Create a token for an installation of an application. Requires an app key sent in the `X-Appwrite-Key` header alongside the `X-Appwrite-App` header, or a caller with update access to the app. The returned token carries the scopes and authorization details granted to the installation, and can be used as an `Authorization: Bearer` header everywhere OAuth2 access tokens are accepted. Multiple tokens can be active for the same installation at once; each token stays valid until it expires or the installation is updated or deleted.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 App-key usage is unclear

This method says callers can use an app key, but the request sends neither X-Appwrite-Key nor X-Appwrite-App, and Client has no setter for either. A caller following this API and its example cannot use the documented app-key path without directly modifying client.headers. Please document a supported way to supply those credentials, or direct callers to an appropriate server-side SDK.

Prompt To Fix With AI
This is a comment left during a code review.
Path: src/services/apps.ts
Line: 1081

Comment:
**App-key usage is unclear**

This method says callers can use an app key, but the request sends neither `X-Appwrite-Key` nor `X-Appwrite-App`, and `Client` has no setter for either. A caller following this API and its example cannot use the documented app-key path without directly modifying `client.headers`. Please document a supported way to supply those credentials, or direct callers to an appropriate server-side SDK.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Claude Code Fix in Codex

Comment thread src/services/oauth-2.ts
Comment on lines +1815 to +1820
const apiHeaders: { [header: string]: string } = {
'content-type': 'application/json',
accept: 'application/json',
};

return this.client.call('post', uri, apiHeaders, payload);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Token flows lack behavior tests

The new token exchange supports authorization-code, refresh-token, and device-code flows, but none has a behavior test. Tests covering the requests and responses for each flow would catch credential or serialization regressions. Please test observable behavior rather than mirroring method bodies, configuration, or version strings.

Prompt To Fix With AI
This is a comment left during a code review.
Path: src/services/oauth-2.ts
Line: 1815-1820

Comment:
**Token flows lack behavior tests**

The new token exchange supports authorization-code, refresh-token, and device-code flows, but none has a behavior test. Tests covering the requests and responses for each flow would catch credential or serialization regressions. Please test observable behavior rather than mirroring method bodies, configuration, or version strings.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

Fix in Claude Code Fix in Codex

@Meldiron
Meldiron merged commit e0b6413 into main Sep 25, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants