Repository navigation
Conversation
pb-login checks the session by POSTing to /api/login without credentials, which auth:login answers from the session's cookie. On pb-components' next line (3.0.0-next-4.21, 4.22) it does so through pb-fetch, and on window focus sends a null body with no Content-Type; base10 declared the body required, so the request was refused (400) and pb-login took the user for logged out. The released 3.6.8 (iron-ajax) sends a Content-Type, so apps on it are not affected yet. The schemas were already "nullable", and jinks' own modules/api.json declares the same route's body optional; base10 now agrees with both. Needs eeditiones/roaster's fix for optional bodies sent without one: until then roaster rejects a request with no Content-Type whether or not the body is required. Tested together on a base10 app loading pb-components 3.0.0-next-4.21: the empty session check returns the logged-in user (200) only with both changes; with either alone it is still 400. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
[This PR was prompted by Joe, drafted by Claude Code, and reviewed by Joe.]
The problem
pb-loginchecks the session by POSTing to/api/loginwith no credentials, andauth:loginanswers such a request from the session's cookie. On pb-components'nextline (3.0.0-next-4.21 and 4.22),pb-loginmakes that request throughpb-fetch: when the window regains focus, it sends a null body with noContent-Type. base10'smodules/lib/api.tpl.jsondeclares the login body required, so the request is refused before the handler runs, andpb-loginshows a logged-in user as logged out:Apps on the released pb-components 3.6.8, base10's default, are not affected today:
iron-ajaxsendsapplication/x-www-form-urlencodedeven for an empty body. They will be oncepb-loginmoves topb-fetch.The fix
"required": falseon/api/login's request body. The schemas were already"nullable": true, and jinks' ownmodules/api.jsondeclares the same route's body optional; base10 now agrees with both. A login with user and password is unchanged.Depends on eeditiones/roaster#151
roaster rejects a request with no
Content-Typewhether or not the body is required, so this change alone does not fix the session check. Tested together on a base10 app (TEI Publisher 11, eXist 6) that loads pb-components 3.0.0-next-4.21:/api/loginbodyIn the browser (Chrome), after logging in through
pb-loginand dispatching a windowblurandfocus: with both changes the check returns 200 with the user andpb-loginstays logged in; with the generated spec it returns 400 andpb-loginlogs out.A note for the tests
The Cypress support file base10 gives generated apps (
test/cypress/support/e2e.js) stubs every login probe with{ user: null, authenticated: false }, so tests built on it cannot see this; the browser check above ran without it.