Skip to content

fix(base10): the login request body is optional - #388

Open
joewiz wants to merge 1 commit into
eeditiones:mainfrom
joewiz:fix/login-optional-body
Open

joewiz wants to merge 1 commit into
eeditiones:mainfrom
joewiz:fix/login-optional-body

Conversation

@joewiz

@joewiz joewiz commented Oct 9, 2026

Copy link
Copy Markdown
Member

[This PR was prompted by Joe, drafted by Claude Code, and reviewed by Joe.]

The problem

pb-login checks the session by POSTing to /api/login with no credentials, and auth:login answers such a request from the session's cookie. On pb-components' next line (3.0.0-next-4.21 and 4.22), pb-login makes that request through pb-fetch: when the window regains focus, it sends a null body with no Content-Type. base10's modules/lib/api.tpl.json declares the login body required, so the request is refused before the handler runs, and pb-login shows a logged-in user as logged out:

400 errors:BODY_CONTENT_TYPE  Body with media-type '' is not allowed

Apps on the released pb-components 3.6.8, base10's default, are not affected today: iron-ajax sends application/x-www-form-urlencoded even for an empty body. They will be once pb-login moves to pb-fetch.

The fix

"required": false on /api/login's request body. The schemas were already "nullable": true, and jinks' own modules/api.json declares the same route's body optional; base10 now agrees with both. A login with user and password is unchanged.

Depends on eeditiones/roaster#151

roaster rejects a request with no Content-Type whether or not the body is required, so this change alone does not fix the session check. Tested together on a base10 app (TEI Publisher 11, eXist 6) that loads pb-components 3.0.0-next-4.21:

roaster /api/login body session check, logged in logged out
1.12.1 required (as generated) 400 400
1.12.1 optional (this PR) 400 400
eeditiones/roaster#151 required (as generated) 400 400
eeditiones/roaster#151 optional (this PR) 200, the user 200, no user

In the browser (Chrome), after logging in through pb-login and dispatching a window blur and focus: with both changes the check returns 200 with the user and pb-login stays logged in; with the generated spec it returns 400 and pb-login logs out.

A note for the tests

The Cypress support file base10 gives generated apps (test/cypress/support/e2e.js) stubs every login probe with { user: null, authenticated: false }, so tests built on it cannot see this; the browser check above ran without it.

pb-login checks the session by POSTing to /api/login without credentials,
which auth:login answers from the session's cookie. On pb-components' next
line (3.0.0-next-4.21, 4.22) it does so through pb-fetch, and on window focus
sends a null body with no Content-Type; base10 declared the body required, so
the request was refused (400) and pb-login took the user for logged out. The
released 3.6.8 (iron-ajax) sends a Content-Type, so apps on it are not
affected yet.

The schemas were already "nullable", and jinks' own modules/api.json declares
the same route's body optional; base10 now agrees with both.

Needs eeditiones/roaster's fix for optional bodies sent without one: until
then roaster rejects a request with no Content-Type whether or not the body is
required. Tested together on a base10 app loading pb-components
3.0.0-next-4.21: the empty session check returns the logged-in user (200) only
with both changes; with either alone it is still 400.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant