Skip to content

Commit b085676

Browse files
committed
refactor(client): name connection discovery options and explain isolation
1 parent 6d66d7e commit b085676

3 files changed

Lines changed: 33 additions & 14 deletions

File tree

‎packages/devframe/src/client/connection.ts‎

Lines changed: 22 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -23,18 +23,33 @@ export interface DevframeConnection {
2323
metaBaseUrl: string
2424
/** Previously issued bearer token, when the connection is already trusted. */
2525
authToken?: string
26-
/** Skip shared browser caches and authentication broadcasts. Retained when reconnecting. */
26+
/**
27+
* Skip shared browser caches and authentication broadcasts. Retained when reconnecting.
28+
* The origin-wide `devframe-auth` channel carries no backend identity, so a token
29+
* from another connection could otherwise overwrite this connection's credentials.
30+
* Authentication still uses this connection's own RPC transport.
31+
*/
32+
isolated?: boolean
33+
}
34+
35+
/**
36+
* Configure discovery before metadata and its source URL have been resolved.
37+
* Shared behavior is the default. Set `isolated: true` when connecting to independent
38+
* backends from one viewer. Browser credential caches are not scoped per backend, and
39+
* `devframe-auth` broadcasts carry no backend identity, so they can mix credentials.
40+
* An isolated connection still authenticates through its own RPC transport.
41+
*/
42+
export interface DevframeConnectionDiscoveryOptions {
43+
/** Use connection-local credentials; see {@link DevframeConnection.isolated}. Defaults to shared behavior. */
2744
isolated?: boolean
45+
connectionMeta?: never
46+
metaBaseUrl?: never
47+
authToken?: never
2848
}
2949

3050
export interface SetupDevframeConnectionOptions {
3151
/** Reuse a prepared connection, or configure isolation before resolving its metadata. */
32-
connection?: DevframeConnection | {
33-
isolated?: boolean
34-
connectionMeta?: never
35-
metaBaseUrl?: never
36-
authToken?: never
37-
}
52+
connection?: DevframeConnection | DevframeConnectionDiscoveryOptions
3853
/** Use a pre-known descriptor while deriving its source URL from `baseURL`. */
3954
connectionMeta?: ConnectionMeta
4055
/** Base URL, or fallback list, used to locate `__connection.json`. */

‎packages/devframe/src/client/rpc.ts‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -425,7 +425,10 @@ export async function getDevframeRpcClient(
425425
wsOptions: options.wsOptions,
426426
})
427427

428-
/** Channel name kept for cross-tab interop with the Vite DevTools auth page. */
428+
/**
429+
* Shared with the Vite DevTools auth page; messages carry no backend identity,
430+
* so isolated connections must neither publish nor consume credentials here.
431+
*/
429432
let authChannel: BroadcastChannel | undefined
430433
if (!connection.isolated) {
431434
try {

‎tests/__snapshots__/tsnapi/devframe/client.snapshot.d.ts‎

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,12 @@ export interface DevframeConnection {
88
authToken?: string;
99
isolated?: boolean;
1010
}
11+
export interface DevframeConnectionDiscoveryOptions {
12+
isolated?: boolean;
13+
connectionMeta?: never;
14+
metaBaseUrl?: never;
15+
authToken?: never;
16+
}
1117
export interface DevframeRpcClient {
1218
events: EventEmitter<RpcClientEvents>;
1319
readonly isTrusted: boolean | null;
@@ -126,12 +132,7 @@ export interface RpcStreamingClientHost {
126132
upload: <T = unknown>(_: string, _: string) => StreamSink<T>;
127133
}
128134
export interface SetupDevframeConnectionOptions {
129-
connection?: DevframeConnection | {
130-
isolated?: boolean;
131-
connectionMeta?: never;
132-
metaBaseUrl?: never;
133-
authToken?: never;
134-
};
135+
connection?: DevframeConnection | DevframeConnectionDiscoveryOptions;
135136
connectionMeta?: ConnectionMeta;
136137
baseURL?: string | string[];
137138
authToken?: string;

0 commit comments

Comments
 (0)