mirror of
https://github.com/stack-auth/stack.git
synced 2026-06-13 21:01:21 +08:00
Some checks failed
all-good: Did all the other checks pass? / all-good (push) Has been cancelled
Ensure Prisma migrations are in sync with the schema / check_prisma_migrations (22.x) (push) Has been cancelled
DB migration compat / Check if migrations changed (push) Has been cancelled
Docker Server Build and Push / Docker Build and Push Server (push) Has been cancelled
Docker Server Build and Run / docker (push) Has been cancelled
Runs E2E API Tests (Local Emulator) / E2E Tests (Local Emulator, Node ${{ matrix.node-version }}) (22.x) (push) Has been cancelled
Runs E2E API Tests / E2E Tests (Node ${{ matrix.node-version }}, Freestyle ${{ matrix.freestyle-mode }}) (mock, 22.x) (push) Has been cancelled
Runs E2E API Tests / E2E Tests (Node ${{ matrix.node-version }}, Freestyle ${{ matrix.freestyle-mode }}) (prod, 22.x) (push) Has been cancelled
Runs E2E API Tests with custom port prefix / build (22.x) (push) Has been cancelled
Runs E2E Fallback Tests / E2E Fallback Tests (Node ${{ matrix.node-version }}) (22.x) (push) Has been cancelled
Lint & build / lint_and_build (24) (push) Has been cancelled
TOC Generator / TOC Generator (push) Has been cancelled
DB migration compat / Back-compat — Current branch migrations with ${{ needs.check-migrations-changed.outputs.base_branch }} branch code (push) Has been cancelled
DB migration compat / Forward-compat — Current branch code with ${{ needs.check-migrations-changed.outputs.base_branch }} branch migrations (push) Has been cancelled
DB migration compat / No migration changes (skipped) (push) Has been cancelled
## Summary **Stacked on [#1475](https://github.com/hexclave/stack-auth/pull/1475)** (`cl/hexclave-pr1`, the invisible compatibility layer). Diff vs that base = the actual PR 2 code. This is **PR 2 of the Stack Auth → Hexclave rebrand: the visible flip**. Old wire identifiers (cookies, request/response headers, Bearer prefix, JWT issuers, MCP tool name) keep working indefinitely via PR 1's dual-accept. This PR flips every user-visible surface — package names taught in docs, SDK class names in code examples, dashboard setup snippets, page titles, error messages, email content, CLI binary, default base URLs, GitHub repo slug, contributor guidance — to the Hexclave brand. See [`RENAME-TO-HEXCLAVE.md`](./RENAME-TO-HEXCLAVE.md) → *"PR 2: Rebrand to Hexclave (visible)"* for the full per-work-area spec. ## What's implemented (per the plan's PR 2 scope) - **SDK base URLs** flipped: `defaultBaseUrl` and `defaultAnalyticsBaseUrl` in [common.ts](packages/template/src/lib/stack-app/apps/implementations/common.ts:127) → `https://api.hexclave.com` / `https://r.hexclave.com`. PR 1's [`getHardcodedFallbackUrls`](packages/stack-shared/src/utils/urls.tsx:199) table now keys on the Hexclave domain. - **Domain inventory sweep** (16 subdomains from the plan): every `api/app/docs/discord/demo/mcp/skill/feedback/test/preview/r/api2/api.staging/idp-jwk-audience/built-with.stack-auth.com` reference in production code, docs-mintlify, examples, READMEs, and contributor guidance flipped to `*.hexclave.com`. Carve-outs: PR 1's intentional JWT issuer dual-accept table in [tokens.tsx](apps/backend/src/lib/tokens.tsx), the legacy `./docs/` folder, the `unified-docs-widget` allowlist (deliberately accepts both during DNS transition), and `url-targets.ts` hosted-component default (baked into existing customer deploys). - **`@deprecated` JSDoc** on every `Stack*` public export ([packages/template/src/lib/stack-app/index.ts](packages/template/src/lib/stack-app/index.ts) + [packages/template/src/index.ts](packages/template/src/index.ts)) — `StackClientApp`, `StackServerApp`, `StackAdminApp` + every constructor/options/JSON type, `StackHandler`, `StackProvider`, `StackTheme`, `useStackApp`, `defineStackConfig`, `StackConfig`. Hexclave\* aliases are now canonical. - **Runtime `console.warn`** ([packages/template/src/internal/deprecation-warning.ts](packages/template/src/internal/deprecation-warning.ts)) — once-per-process when the SDK is loaded from a `@stackframe/*` artifact. Detection uses the existing `STACK_COMPILE_TIME_CLIENT_PACKAGE_VERSION_SENTINEL` (rewritten at build time to e.g. `js @stackframe/stack@2.8.92` or `js @hexclave/next@1.0.0`); `@hexclave/*` mirror artifacts short-circuit the warning. - **Tier 3 data migration**: new idempotent SQL migration [`20260523000000_rename_internal_project_to_hexclave`](apps/backend/prisma/migrations/20260523000000_rename_internal_project_to_hexclave/migration.sql) — updates the internal Project `displayName` 'Stack Dashboard' → 'Hexclave Dashboard' and `description` only if both still hold the pre-rebrand defaults. Operator-renamed projects untouched, missing row no-ops, re-runs are no-ops. [`seed.ts`](apps/backend/prisma/seed.ts:87) default flipped. `getSharedEmailConfig("Stack Auth")` → `("Hexclave")`. - **Tier 4 brand strings** (mechanical sweep, ~340 files): - Page + OpenAPI titles (Hexclave API / Dashboard / REST API / Webhooks API / Documentation). OpenAPI `info.description` documents `X-Hexclave-*` headers as canonical with compat note on `X-Stack-*`. - `HexclaveAssertionError` message text ([errors.tsx:71](packages/stack-shared/src/utils/errors.tsx:71)) — "an error in Stack." → "an error in Hexclave." - Known-error message templates ([known-errors.tsx](packages/stack-shared/src/known-errors.tsx)) flipped to lead with `x-hexclave-*` + the new `docs.hexclave.com` URL; legacy `x-stack-*` mentioned as compat aliases. **25 e2e test files updated in lockstep**. - Email content: failed-emails-digest body, sendTestEmail recipient (now `sent-with-hexclave.com`), test-email-recipient default. - `CHANGELOG.md` title → "Hexclave Changelog". - `AGENTS.md` env var convention: new vars prefix `HEXCLAVE_` / `NEXT_PUBLIC_HEXCLAVE_` for Category A/B; legacy `STACK_*` explicitly noted as accepted via PR 1's dual-read. - **CLI / init wizard**: - Every dashboard setup snippet, init-stack template, and docs-mintlify page teaches `npx @hexclave/cli@latest init` (was `@stackframe/stack-cli`). [setup-page.tsx](apps/dashboard/src/app/(main)/(protected)/projects/[projectId]/(overview)/setup-page.tsx) + [link-existing-onboarding](apps/dashboard/src/app/(main)/(protected)/(outside-dashboard)/new-project/page-client-parts/link-existing-onboarding.tsx). - [init-stack](packages/init-stack/src/index.ts:634) `STACK_*_INSTALL_PACKAGE_NAME_OVERRIDE` defaults flipped to `@hexclave/*`. - Generated `stack/client.ts` / `stack/server.ts` import from `@hexclave/next` and reference `HexclaveClientApp` / `HexclaveServerApp`. - Internal `StackAuthKeys` dashboard component renamed to `HexclaveKeys`. - **docs-mintlify rewrite** (legacy `./docs/` intentionally untouched per scoping decision): - **78 MDX files swept**. `@stackframe/{react,stack,js,tanstack-start,...}` → `@hexclave/{react,stack,js,...}` in install snippets and code blocks; `Stack*` SDK class names → `Hexclave*` in all code examples; 'Stack Auth' brand phrase → 'Hexclave'. - `openapi/{server,admin,client,webhooks}.json` titles → 'Hexclave REST API' / 'Hexclave Webhooks API'. - **Generators flipped before regeneration**: - [`packages/stack-shared/src/helpers/init-prompt.ts`](packages/stack-shared/src/helpers/init-prompt.ts), [`/ai/prompts.ts`](packages/stack-shared/src/ai/prompts.ts), [`apps/backend/src/lib/ai/prompts.ts`](apps/backend/src/lib/ai/prompts.ts), [`apps/backend/src/lib/ai/tools/create-email-{template,draft}.ts`](apps/backend/src/lib/ai/tools/create-email-template.ts), [`apps/skills/src/app/route.ts`](apps/skills/src/app/route.ts) (taught MCP tool → `ask_hexclave` with compat note; CLI binary teach → `hexclave`), [`docs-mintlify/snippets/home-prompt-island.jsx`](docs-mintlify/snippets/home-prompt-island.jsx), [`packages/template/README.md`](packages/template/README.md) + integrations/convex/component/README.md. - `generate-sdks` propagated changes to `packages/{react,stack,js}`. - **OpenAPI dual-documentation**: [`apps/backend/src/app/api/latest/route.ts`](apps/backend/src/app/api/latest/route.ts) now lists `X-Hexclave-*` headers as primary documented schemas with `X-Stack-*` duplicates marked `.optional()` (both accepted at runtime by PR 1's normalize-at-proxy shim). - **`@stackframe/emails` virtual module**: dual-aliased to `@hexclave/emails` at the bundler boundary ([email-rendering.tsx:89](apps/backend/src/lib/email-rendering.tsx:89)). Stored email templates continue to import from either name; new AI-generated templates and the system prompt teach `@hexclave/emails`. - **Tier 2 mirror-publish wiring** (new this PR, lays the groundwork for `@hexclave/*` first publish): - [`scripts/rewrite-packages-to-hexclave.ts`](scripts/rewrite-packages-to-hexclave.ts) — rewrites 9 publishable `@stackframe/*` → `@hexclave/*` `package.json` files (reads `HEXCLAVE_VERSION` env or `--version=` flag), pins cross-deps to the shared `@hexclave` version, registers `hexclave` bin alongside `stack` for `@hexclave/cli`. - [`.github/workflows/npm-publish.yaml`](.github/workflows/npm-publish.yaml) appended with rewrite-then-republish step. `pnpm publish` skips already-on-npm versions so reruns are safe. - **Sender email domain**: `noreply@stackframe.co` → `noreply@sent-with-hexclave.com` (the dedicated transactional-sender domain split per the plan, to isolate bulk deliverability from `hexclave.com` reputation); `security@` / `team@stack-auth.com` inbound mailboxes → `@hexclave.com`. - **Self-host docs**: docker network / container names in the bash examples flipped from `stack-auth` to `hexclave` (`hexclave-postgres`, `hexclave-clickhouse`, `hexclave.env`). The docker image tag `stackauth/server:latest` stays per the plan's locked decision. - **GitHub repo slug**: `hexclave/stack-auth` → `hexclave/hexclave` in every `package.json` `repository` field, README link, CHANGELOG raw-asset URL. ## Carve-outs (deliberately untouched) - **[`apps/backend/src/lib/tokens.tsx`](apps/backend/src/lib/tokens.tsx)** JWT issuer dual-accept table — PR 1 intentional infrastructure, kept indefinitely. - **Legacy `./docs/` folder** — per scoping decision (only `docs-mintlify/` rewritten). - **`unified-docs-widget` hostname allowlist** — accepts both `.hexclave.com` (canonical) and `.stack-auth.com` (transition window) for DNS rollout. - **`url-targets.ts`** hosted-domain default `.built-with-stack-auth.com` — wire identifier baked into existing customer deploys; indefinite read-fallback. - **Binary visual assets** (logos, favicons, OG images, README screenshots) — out of scope for this PR. Need design work; tracked separately. ## Verification - **`pnpm typecheck`** on `packages/{template,stack-shared,react,stack,js}` + `apps/dashboard`: **all green**. The remaining backend / e-commerce-demo typecheck errors are pre-existing (Prisma codegen output + `./generated/api-versions.json` not present in fresh worktrees without `pnpm run codegen-prisma` + a live DB) and unrelated to this diff. - **`pnpm lint`** on the same 6 packages: all green. - **Final grep** for residual `Stack Auth` / `stack-auth.com` / `@stackframe/stack-cli@latest` references: zero outside the intentional carve-outs above. - **25 e2e test files updated in lockstep** with the known-error message changes (asserted strings flipped to match the new x-hexclave-* + compat-note messages). ## Deploy blockers (ops sequencing before this rebrand goes live) This PR is code-complete, but the rebrand's visible surfaces (SDK default URLs, dashboard links, npm READMEs, REST error messages, runtime deprecation warning) all point at `*.hexclave.com` / `@hexclave/*` resources that don't exist yet. None of these are fixable from a PR — they're ops/registrar/npm work that has to be sequenced before merging this to a release tag. Suggested ordering, hardest blockers first: ### Tier 1 — required before customer-facing deploy (everything below this line *will visibly break customers on day 1* if skipped) 1. **DNS + TLS for `api.hexclave.com` + `api1./api2.hexclave.com`** → must point at the same backend that serves `api.stack-auth.com` (or a backend that mirrors PR 1's dual-accept). The SDK's new `defaultBaseUrl` is `https://api.hexclave.com`; every customer that relied on the old default and upgrades to a post-PR2 SDK build sends API requests here. Until this resolves, every default-config customer's API call NXDOMAINs. 2. **DNS for `app.hexclave.com`** → the dashboard. Referenced in the SDK's default-error messages ("Please create a project on the Hexclave dashboard at https://app.hexclave.com"), the init-stack flow's `wizard-congrats` redirect, and the OAuth dashboard handoff. 3. **DNS for `docs.hexclave.com`** + Mintlify deploy → the SDK runtime deprecation warning (`https://docs.hexclave.com/migration`), every README, every "Learn more" link in the dashboard, and every REST API error body (`/api/overview#authentication`) points here. The MDX is in this PR; the docs build target needs DNS. 4. **DNS for `mcp.hexclave.com`** → the MCP server endpoint that every taught agent integration (`claude mcp add ...`, `cursor`, `codex`, `vscode`) registers. Until this resolves, every `npx @hexclave/cli@latest init` MCP-registration step fails. 5. **Reserve the `@hexclave` npm scope + set repo variable `HEXCLAVE_VERSION`** → the mirror-publish step in `.github/workflows/npm-publish.yaml` is gated on this variable. Without it, the entire taught onboarding command `npx @hexclave/cli@latest init` 404s from the npm registry, *and* every README that says "install `@hexclave/next`" leads to install failure. Pick the initial version intentionally (`1.0.0` or aligned to `@stackframe/stack`); don't accept a silent default. ### Tier 2 — required before announcing the rebrand publicly (lookalike or low-traffic surfaces, but visibly broken) 6. **DNS for `r.hexclave.com`** → the analytics beacon `defaultAnalyticsBaseUrl`. Silent failure if missing (analytics drops), but should land alongside Tier 1. 7. **Register `sent-with-hexclave.com` + full email auth (SPF / DKIM / DMARC)** → the new default sender domain for shared-sender transactional emails. Without it the dashboard "send test email" path emits bounces, and shared-sender flows (`getSharedEmailConfig("Hexclave")`) deliver to spam at best. 8. **MX + SPF / DMARC for `hexclave.com`** → `team@hexclave.com` and `security@hexclave.com` mailboxes. The security disclosure mailbox is referenced in [`.github/SECURITY.md`](.github/SECURITY.md); `team@hexclave.com` is the actual recipient of internal feedback emails sent at runtime by [`apps/backend/src/lib/internal-feedback-emails.tsx`](apps/backend/src/lib/internal-feedback-emails.tsx). Today, every runtime feedback email bounces. 9. **DNS for `skill.hexclave.com`** → the canonical AI-agent skill fetch URL (the agent bootstrap pivot). Without it, the entire "agent downloads `SKILL.md` from a known URL" flow taught in [`packages/stack-shared/src/helpers/init-prompt.ts`](packages/stack-shared/src/helpers/init-prompt.ts) fails. 10. **Create `github.com/hexclave/hexclave` as a public repo** (even as a redirect to `hexclave/stack-auth`) **OR** rewrite every `package.json` `"repository"` field + dashboard footer "view on GitHub" link to point at `hexclave/stack-auth` (which already exists). Currently every npm package page's "Repository" link is dead, and the dashboard's GitHub button + dev-tool repo link are dead. ### Tier 3 — broken but low-visibility / low-traffic 11. **DNS for `discord.hexclave.com`** → Discord invite redirect, used in every README's chip and the dashboard footer. 12. **DNS for `demo.hexclave.com`** → "✨ Demo" badge in every npm package README. Broken-image badge on the package page. 13. **DNS + TLS for `built-with-hexclave.com`** → optional hosted-handler domain (the default reverted to `.built-with-stack-auth.com` in this PR's carve-outs, so this only matters for projects that manually flip). ## Other follow-ups (not deploy-blocking) - **E2E snapshot regen across the full suite** for the dual-emitted `x-hexclave-*` response headers (PR 1 follow-up; `vitest -u` in CI absorbs). - **Binary visual assets** — logos, favicons, OG images, README screenshots; need design pass. - **Backend OpenAPI fumadocs regen** in CI flow — the JSON files in `docs-mintlify/openapi/` are committed but regen runs in CI. Verify the workflow that does this still works against the post-PR2 source. - **Backend typecheck infra debt** — needs `codegen-prisma` + `codegen-route-info` to clear; pre-existing, unaffected by this PR. ## Test plan - [ ] CI runs full e2e suite (with `vitest -u` to absorb residual snapshot deltas, then committed back). - [ ] Spot-check: new `@hexclave/cli init` (once published) generates `hexclave.config.ts` and works against a fresh project. - [ ] Spot-check: existing customer with `@stackframe/stack` import sees the once-per-process `console.warn` recommending `@hexclave/next` on SDK init. - [ ] Manual: dashboard setup page renders the `npx @hexclave/cli@latest init` snippet and the `x-hexclave-publishable-client-key` API header in the curl example. - [ ] Manual: a fresh `pnpm run prisma migrate` against a clean DB sets the internal project displayName to 'Hexclave Dashboard'. --------- Co-authored-by: Konstantin Wohlwend <n2d4xc@gmail.com>
503 lines
21 KiB
Swift
503 lines
21 KiB
Swift
import Foundation
|
|
#if canImport(FoundationNetworking)
|
|
import FoundationNetworking
|
|
#endif
|
|
|
|
/// Character set for form-urlencoded values.
|
|
/// Only unreserved characters (RFC 3986) are allowed; everything else must be percent-encoded.
|
|
/// This is stricter than urlQueryAllowed which incorrectly allows &, =, + etc.
|
|
private let formURLEncodedAllowedCharacters: CharacterSet = {
|
|
var allowed = CharacterSet.alphanumerics
|
|
allowed.insert(charactersIn: "-._~")
|
|
return allowed
|
|
}()
|
|
|
|
/// Percent-encode a string for use in application/x-www-form-urlencoded data
|
|
func formURLEncode(_ string: String) -> String {
|
|
return string.addingPercentEncoding(withAllowedCharacters: formURLEncodedAllowedCharacters) ?? string
|
|
}
|
|
|
|
// MARK: - JWT Payload
|
|
|
|
/// Decoded JWT payload for access tokens
|
|
struct JWTPayload {
|
|
let exp: TimeInterval? // Expiration time (Unix timestamp in seconds)
|
|
let iat: TimeInterval? // Issued at time (Unix timestamp in seconds)
|
|
|
|
/// Milliseconds until token expires (Int.max if no exp claim, 0 if expired)
|
|
var expiresInMillis: Int {
|
|
guard let exp = exp else { return Int.max }
|
|
let expiresIn = (exp * 1000) - (Date().timeIntervalSince1970 * 1000)
|
|
return max(0, Int(expiresIn))
|
|
}
|
|
|
|
/// Milliseconds since token was issued (0 if no iat claim)
|
|
var issuedMillisAgo: Int {
|
|
guard let iat = iat else { return 0 }
|
|
let issuedAgo = (Date().timeIntervalSince1970 * 1000) - (iat * 1000)
|
|
return max(0, Int(issuedAgo))
|
|
}
|
|
}
|
|
|
|
/// Decode a JWT token's payload (second segment)
|
|
func decodeJWTPayload(_ token: String) -> JWTPayload? {
|
|
let segments = token.split(separator: ".")
|
|
guard segments.count >= 2 else { return nil }
|
|
|
|
var base64 = String(segments[1])
|
|
// Convert base64url to base64
|
|
base64 = base64.replacingOccurrences(of: "-", with: "+")
|
|
base64 = base64.replacingOccurrences(of: "_", with: "/")
|
|
// Add padding if needed
|
|
let remainder = base64.count % 4
|
|
if remainder > 0 {
|
|
base64 += String(repeating: "=", count: 4 - remainder)
|
|
}
|
|
|
|
guard let data = Data(base64Encoded: base64),
|
|
let json = try? JSONSerialization.jsonObject(with: data) as? [String: Any] else {
|
|
return nil
|
|
}
|
|
|
|
let exp = json["exp"] as? TimeInterval
|
|
let iat = json["iat"] as? TimeInterval
|
|
return JWTPayload(exp: exp, iat: iat)
|
|
}
|
|
|
|
/// Check if a token is expired (expiresIn <= 0)
|
|
func isTokenExpired(_ accessToken: String?) -> Bool {
|
|
guard let token = accessToken,
|
|
let payload = decodeJWTPayload(token) else {
|
|
return true // Can't decode, treat as expired
|
|
}
|
|
return payload.expiresInMillis <= 0
|
|
}
|
|
|
|
/// Check if token should NOT be refreshed (is "fresh enough").
|
|
/// Returns TRUE if token expires in > 20 seconds AND was issued < 75 seconds ago.
|
|
func isTokenFreshEnough(_ accessToken: String?) -> Bool {
|
|
guard let token = accessToken,
|
|
let payload = decodeJWTPayload(token) else {
|
|
return false // Can't decode, should refresh
|
|
}
|
|
|
|
let expiresInMoreThan20s = payload.expiresInMillis > 20_000
|
|
let issuedLessThan75sAgo = payload.issuedMillisAgo < 75_000
|
|
|
|
return expiresInMoreThan20s && issuedLessThan75sAgo
|
|
}
|
|
|
|
// MARK: - Refresh Lock Manager
|
|
|
|
/// Manages per-token-store refresh locks to ensure only one refresh per store at a time.
|
|
/// Uses ObjectIdentifier to key locks since token stores no longer have an id property.
|
|
actor RefreshLockManager {
|
|
static let shared = RefreshLockManager()
|
|
|
|
private var activeLocks: [ObjectIdentifier: Bool] = [:]
|
|
private var waiters: [ObjectIdentifier: [CheckedContinuation<Void, Never>]] = [:]
|
|
|
|
func acquireLock(for store: any TokenStoreProtocol) async {
|
|
let key = ObjectIdentifier(store)
|
|
// Use WHILE loop to re-check condition after waking up.
|
|
// Multiple waiters may be resumed at once, but only one should acquire the lock.
|
|
while activeLocks[key] == true {
|
|
// Wait for existing refresh to complete
|
|
await withCheckedContinuation { continuation in
|
|
waiters[key, default: []].append(continuation)
|
|
}
|
|
}
|
|
activeLocks[key] = true
|
|
}
|
|
|
|
func releaseLock(for store: any TokenStoreProtocol) {
|
|
let key = ObjectIdentifier(store)
|
|
activeLocks[key] = false
|
|
if let storeWaiters = waiters[key] {
|
|
for waiter in storeWaiters {
|
|
waiter.resume()
|
|
}
|
|
waiters[key] = nil
|
|
}
|
|
}
|
|
}
|
|
|
|
/// Result of getOrFetchLikelyValidTokens
|
|
public struct TokenPair: Sendable {
|
|
public let refreshToken: String?
|
|
public let accessToken: String?
|
|
}
|
|
|
|
/// Internal API client for making HTTP requests to Hexclave
|
|
actor APIClient {
|
|
let baseUrl: String
|
|
let projectId: String
|
|
let publishableClientKey: String?
|
|
let secretServerKey: String?
|
|
private let tokenStore: any TokenStoreProtocol
|
|
|
|
private static let sdkVersion = "1.0.0"
|
|
|
|
init(
|
|
baseUrl: String,
|
|
projectId: String,
|
|
publishableClientKey: String?,
|
|
secretServerKey: String? = nil,
|
|
tokenStore: any TokenStoreProtocol
|
|
) {
|
|
self.baseUrl = baseUrl.hasSuffix("/") ? String(baseUrl.dropLast()) : baseUrl
|
|
self.projectId = projectId
|
|
self.publishableClientKey = publishableClientKey
|
|
self.secretServerKey = secretServerKey
|
|
self.tokenStore = tokenStore
|
|
}
|
|
|
|
func getOAuthClientSecret() -> String {
|
|
return publishableClientKey ?? publishableClientKeyNotNecessarySentinel
|
|
}
|
|
|
|
// MARK: - Request Methods
|
|
|
|
func sendRequest(
|
|
path: String,
|
|
method: String = "GET",
|
|
body: [String: Any]? = nil,
|
|
authenticated: Bool = false,
|
|
serverOnly: Bool = false,
|
|
tokenStoreOverride: (any TokenStoreProtocol)? = nil
|
|
) async throws -> (Data, HTTPURLResponse) {
|
|
let effectiveTokenStore = tokenStoreOverride ?? tokenStore
|
|
guard let url = URL(string: "\(baseUrl)/api/v1\(path)") else {
|
|
throw StackAuthError(code: "INVALID_URL", message: "Failed to construct request URL from base: \(baseUrl) and path: \(path)")
|
|
}
|
|
var request = URLRequest(url: url)
|
|
request.httpMethod = method
|
|
request.cachePolicy = .reloadIgnoringLocalCacheData
|
|
|
|
// Required headers
|
|
request.setValue(projectId, forHTTPHeaderField: "x-stack-project-id")
|
|
if let publishableClientKey = publishableClientKey {
|
|
request.setValue(publishableClientKey, forHTTPHeaderField: "x-stack-publishable-client-key")
|
|
}
|
|
request.setValue("swift@\(Self.sdkVersion)", forHTTPHeaderField: "x-stack-client-version")
|
|
request.setValue(serverOnly ? "server" : "client", forHTTPHeaderField: "x-stack-access-type")
|
|
request.setValue("true", forHTTPHeaderField: "x-stack-override-error-status")
|
|
request.setValue(UUID().uuidString, forHTTPHeaderField: "x-stack-random-nonce")
|
|
|
|
// Server key if required
|
|
if serverOnly {
|
|
guard let serverKey = secretServerKey else {
|
|
throw StackAuthError(code: "missing_server_key", message: "Server key required for this operation")
|
|
}
|
|
request.setValue(serverKey, forHTTPHeaderField: "x-stack-secret-server-key")
|
|
}
|
|
|
|
// Auth headers
|
|
if authenticated {
|
|
if let accessToken = await effectiveTokenStore.getStoredAccessToken() {
|
|
request.setValue(accessToken, forHTTPHeaderField: "x-stack-access-token")
|
|
}
|
|
if let refreshToken = await effectiveTokenStore.getStoredRefreshToken() {
|
|
request.setValue(refreshToken, forHTTPHeaderField: "x-stack-refresh-token")
|
|
}
|
|
}
|
|
|
|
// Body - always include for mutating methods
|
|
if let body = body {
|
|
request.setValue("application/json", forHTTPHeaderField: "Content-Type")
|
|
request.httpBody = try JSONSerialization.data(withJSONObject: body)
|
|
} else if method == "POST" || method == "PATCH" || method == "PUT" {
|
|
// POST/PATCH/PUT requests need a body even if empty
|
|
request.setValue("application/json", forHTTPHeaderField: "Content-Type")
|
|
request.httpBody = "{}".data(using: .utf8)
|
|
}
|
|
|
|
// Send request with retry logic
|
|
return try await sendWithRetry(request: request, authenticated: authenticated, tokenStore: effectiveTokenStore)
|
|
}
|
|
|
|
private func sendWithRetry(
|
|
request: URLRequest,
|
|
authenticated: Bool,
|
|
tokenStore: any TokenStoreProtocol,
|
|
attempt: Int = 0
|
|
) async throws -> (Data, HTTPURLResponse) {
|
|
do {
|
|
let (data, response) = try await URLSession.shared.data(for: request)
|
|
|
|
guard let httpResponse = response as? HTTPURLResponse else {
|
|
throw StackAuthError(code: "invalid_response", message: "Invalid HTTP response")
|
|
}
|
|
|
|
// Check for actual status code in header
|
|
let actualStatus: Int
|
|
if let statusHeader = httpResponse.value(forHTTPHeaderField: "x-stack-actual-status"),
|
|
let status = Int(statusHeader) {
|
|
actualStatus = status
|
|
} else {
|
|
actualStatus = httpResponse.statusCode
|
|
}
|
|
|
|
// Handle 401 with token refresh
|
|
if actualStatus == 401 && authenticated {
|
|
// Check if it's an invalid access token error
|
|
if let errorCode = httpResponse.value(forHTTPHeaderField: "x-stack-known-error"),
|
|
errorCode == "invalid_access_token" {
|
|
// Try to refresh token
|
|
let tokens = await fetchNewAccessToken(tokenStore: tokenStore)
|
|
if tokens.accessToken != nil {
|
|
// Retry with new token
|
|
var newRequest = request
|
|
newRequest.setValue(tokens.accessToken, forHTTPHeaderField: "x-stack-access-token")
|
|
return try await sendWithRetry(request: newRequest, authenticated: authenticated, tokenStore: tokenStore, attempt: 0)
|
|
}
|
|
}
|
|
}
|
|
|
|
// Handle rate limiting (max 5 retries)
|
|
if actualStatus == 429 && attempt < 5 {
|
|
if let retryAfter = httpResponse.value(forHTTPHeaderField: "Retry-After"),
|
|
let seconds = Double(retryAfter) {
|
|
// Use Retry-After header if provided
|
|
try await Task.sleep(nanoseconds: UInt64(seconds * 1_000_000_000))
|
|
} else {
|
|
// No Retry-After header: use exponential backoff (1s, 2s, 4s, 8s, 16s)
|
|
let delayMs = 1000.0 * pow(2.0, Double(attempt))
|
|
try await Task.sleep(nanoseconds: UInt64(delayMs * 1_000_000))
|
|
}
|
|
return try await sendWithRetry(request: request, authenticated: authenticated, tokenStore: tokenStore, attempt: attempt + 1)
|
|
}
|
|
|
|
// Rate limit exhausted after max retries
|
|
if actualStatus == 429 {
|
|
throw StackAuthError(code: "RATE_LIMITED", message: "Too many requests, please try again later")
|
|
}
|
|
|
|
// Check for known error
|
|
if let errorCode = httpResponse.value(forHTTPHeaderField: "x-stack-known-error") {
|
|
let errorData = try? JSONSerialization.jsonObject(with: data) as? [String: Any]
|
|
let message = errorData?["message"] as? String ?? "Unknown error"
|
|
let details = errorData?["details"] as? [String: Any]
|
|
throw StackAuthError.from(code: errorCode, message: message, details: details)
|
|
}
|
|
|
|
// Success
|
|
if actualStatus >= 200 && actualStatus < 300 {
|
|
return (data, httpResponse)
|
|
}
|
|
|
|
// Other error
|
|
throw StackAuthError(code: "http_error", message: "HTTP \(actualStatus)")
|
|
|
|
} catch let error as URLError {
|
|
// Network error - retry for idempotent requests
|
|
let idempotent = ["GET", "HEAD", "OPTIONS", "PUT", "DELETE"].contains(request.httpMethod ?? "")
|
|
if idempotent && attempt < 5 {
|
|
let delay = pow(2.0, Double(attempt)) * 1.0 // Exponential backoff
|
|
try await Task.sleep(nanoseconds: UInt64(delay * 1_000_000_000))
|
|
return try await sendWithRetry(request: request, authenticated: authenticated, tokenStore: tokenStore, attempt: attempt + 1)
|
|
}
|
|
throw StackAuthError(code: "network_error", message: error.localizedDescription)
|
|
}
|
|
}
|
|
|
|
// MARK: - Token Refresh
|
|
|
|
/// Performs the actual token refresh request.
|
|
/// Returns (wasValid, newAccessToken) where wasValid indicates if the refresh token was valid.
|
|
private func refresh(refreshToken: String) async -> (wasValid: Bool, accessToken: String?) {
|
|
let url = URL(string: "\(baseUrl)/api/v1/auth/oauth/token")!
|
|
var request = URLRequest(url: url)
|
|
request.httpMethod = "POST"
|
|
request.setValue("application/x-www-form-urlencoded", forHTTPHeaderField: "Content-Type")
|
|
request.setValue(projectId, forHTTPHeaderField: "x-stack-project-id")
|
|
if let publishableClientKey = publishableClientKey {
|
|
request.setValue(publishableClientKey, forHTTPHeaderField: "x-stack-publishable-client-key")
|
|
}
|
|
|
|
let oauthClientSecret = publishableClientKey ?? publishableClientKeyNotNecessarySentinel
|
|
let body = [
|
|
"grant_type=refresh_token",
|
|
"refresh_token=\(formURLEncode(refreshToken))",
|
|
"client_id=\(formURLEncode(projectId))",
|
|
"client_secret=\(formURLEncode(oauthClientSecret))"
|
|
].joined(separator: "&")
|
|
|
|
request.httpBody = body.data(using: .utf8)
|
|
|
|
do {
|
|
let (data, response) = try await URLSession.shared.data(for: request)
|
|
|
|
guard let httpResponse = response as? HTTPURLResponse,
|
|
httpResponse.statusCode == 200 else {
|
|
return (wasValid: false, accessToken: nil)
|
|
}
|
|
|
|
guard let json = try? JSONSerialization.jsonObject(with: data) as? [String: Any],
|
|
let newAccessToken = json["access_token"] as? String else {
|
|
return (wasValid: false, accessToken: nil)
|
|
}
|
|
|
|
return (wasValid: true, accessToken: newAccessToken)
|
|
} catch {
|
|
return (wasValid: false, accessToken: nil)
|
|
}
|
|
}
|
|
|
|
// MARK: - Token Management
|
|
|
|
func setTokens(accessToken: String?, refreshToken: String?) async {
|
|
await tokenStore.setTokens(accessToken: accessToken, refreshToken: refreshToken)
|
|
}
|
|
|
|
func setTokens(accessToken: String?, refreshToken: String?, tokenStoreOverride: any TokenStoreProtocol) async {
|
|
await tokenStoreOverride.setTokens(accessToken: accessToken, refreshToken: refreshToken)
|
|
}
|
|
|
|
func clearTokens() async {
|
|
await tokenStore.clearTokens()
|
|
}
|
|
|
|
func clearTokens(tokenStoreOverride: any TokenStoreProtocol) async {
|
|
await tokenStoreOverride.clearTokens()
|
|
}
|
|
|
|
/// Gets tokens, refreshing if needed. See spec for algorithm.
|
|
/// This is the main function to use for getting an access token.
|
|
func getOrFetchLikelyValidTokens() async -> TokenPair {
|
|
return await getOrFetchLikelyValidTokensFromStore(tokenStore)
|
|
}
|
|
|
|
func getOrFetchLikelyValidTokens(tokenStoreOverride: any TokenStoreProtocol) async -> TokenPair {
|
|
return await getOrFetchLikelyValidTokensFromStore(tokenStoreOverride)
|
|
}
|
|
|
|
/// Internal implementation of getOrFetchLikelyValidTokens algorithm.
|
|
private func getOrFetchLikelyValidTokensFromStore(_ ts: any TokenStoreProtocol) async -> TokenPair {
|
|
// Acquire lock to ensure only one refresh per token store
|
|
await RefreshLockManager.shared.acquireLock(for: ts)
|
|
|
|
let originalRefreshToken = await ts.getStoredRefreshToken()
|
|
let originalAccessToken = await ts.getStoredAccessToken()
|
|
|
|
let result: TokenPair
|
|
|
|
// Case 1: No refresh token
|
|
if originalRefreshToken == nil {
|
|
// If access token expires in > 0 seconds, return it
|
|
if let token = originalAccessToken, !isTokenExpired(token) {
|
|
result = TokenPair(refreshToken: nil, accessToken: token)
|
|
} else {
|
|
// Access token is expired or nil
|
|
result = TokenPair(refreshToken: nil, accessToken: nil)
|
|
}
|
|
} else {
|
|
// Case 2: Refresh token exists
|
|
let refreshToken = originalRefreshToken!
|
|
|
|
// Check if token is fresh enough (expires in > 20s AND issued < 75s ago)
|
|
if isTokenFreshEnough(originalAccessToken) {
|
|
result = TokenPair(refreshToken: refreshToken, accessToken: originalAccessToken)
|
|
} else {
|
|
// Need to refresh
|
|
let (wasValid, newAccessToken) = await refresh(refreshToken: refreshToken)
|
|
|
|
if wasValid, let newToken = newAccessToken {
|
|
// Refresh succeeded - update tokens atomically
|
|
await ts.compareAndSet(
|
|
compareRefreshToken: refreshToken,
|
|
newRefreshToken: refreshToken,
|
|
newAccessToken: newToken
|
|
)
|
|
result = TokenPair(refreshToken: refreshToken, accessToken: newToken)
|
|
} else {
|
|
// Refresh failed - clear tokens atomically
|
|
await ts.compareAndSet(
|
|
compareRefreshToken: refreshToken,
|
|
newRefreshToken: nil,
|
|
newAccessToken: nil
|
|
)
|
|
result = TokenPair(refreshToken: nil, accessToken: nil)
|
|
}
|
|
}
|
|
}
|
|
|
|
// Release lock synchronously before returning
|
|
await RefreshLockManager.shared.releaseLock(for: ts)
|
|
return result
|
|
}
|
|
|
|
/// Forcefully fetches a new access token from the server if possible.
|
|
func fetchNewAccessToken() async -> TokenPair {
|
|
return await fetchNewAccessToken(tokenStore: tokenStore)
|
|
}
|
|
|
|
func fetchNewAccessToken(tokenStoreOverride: any TokenStoreProtocol) async -> TokenPair {
|
|
return await fetchNewAccessToken(tokenStore: tokenStoreOverride)
|
|
}
|
|
|
|
private func fetchNewAccessToken(tokenStore ts: any TokenStoreProtocol) async -> TokenPair {
|
|
// Acquire lock to ensure only one refresh per token store
|
|
await RefreshLockManager.shared.acquireLock(for: ts)
|
|
|
|
let result: TokenPair
|
|
|
|
if let refreshToken = await ts.getStoredRefreshToken() {
|
|
let (wasValid, newAccessToken) = await refresh(refreshToken: refreshToken)
|
|
|
|
if wasValid, let newToken = newAccessToken {
|
|
await ts.compareAndSet(
|
|
compareRefreshToken: refreshToken,
|
|
newRefreshToken: refreshToken,
|
|
newAccessToken: newToken
|
|
)
|
|
result = TokenPair(refreshToken: refreshToken, accessToken: newToken)
|
|
} else {
|
|
await ts.compareAndSet(
|
|
compareRefreshToken: refreshToken,
|
|
newRefreshToken: nil,
|
|
newAccessToken: nil
|
|
)
|
|
result = TokenPair(refreshToken: nil, accessToken: nil)
|
|
}
|
|
} else {
|
|
result = TokenPair(refreshToken: nil, accessToken: nil)
|
|
}
|
|
|
|
// Release lock synchronously before returning
|
|
await RefreshLockManager.shared.releaseLock(for: ts)
|
|
return result
|
|
}
|
|
|
|
/// Get access token, refreshing if needed. Convenience wrapper around getOrFetchLikelyValidTokens.
|
|
func getAccessToken() async -> String? {
|
|
let tokens = await getOrFetchLikelyValidTokens()
|
|
return tokens.accessToken
|
|
}
|
|
|
|
func getAccessToken(tokenStoreOverride: any TokenStoreProtocol) async -> String? {
|
|
let tokens = await getOrFetchLikelyValidTokens(tokenStoreOverride: tokenStoreOverride)
|
|
return tokens.accessToken
|
|
}
|
|
|
|
/// Get refresh token (simple getter from store).
|
|
func getRefreshToken() async -> String? {
|
|
return await tokenStore.getStoredRefreshToken()
|
|
}
|
|
|
|
func getRefreshToken(tokenStoreOverride: any TokenStoreProtocol) async -> String? {
|
|
return await tokenStoreOverride.getStoredRefreshToken()
|
|
}
|
|
}
|
|
|
|
// MARK: - JSON Parsing Helpers
|
|
|
|
extension APIClient {
|
|
func parseJSON<T>(_ data: Data) throws -> T {
|
|
guard let json = try? JSONSerialization.jsonObject(with: data) as? T else {
|
|
throw StackAuthError(code: "parse_error", message: "Failed to parse response")
|
|
}
|
|
return json
|
|
}
|
|
}
|