Skip to content

Stop describing direct connections as deprecated - #2369

Merged
kmcginnes merged 1 commit into
mainfrom
undeprecate-direct-connections
Oct 6, 2026
Merged

kmcginnes merged 1 commit into
mainfrom
undeprecate-direct-connections

Conversation

@kmcginnes

@kmcginnes kmcginnes commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Description

  • Direct connections stay a supported option. They are the only route when the browser can reach a database that the server cannot, and for public endpoints that already allow cross-origin requests. The proxy remains the default because Amazon Neptune sends no CORS headers.
  • The form label and tooltip, the error messages, the docs, the glossary, and code comments no longer say the option is deprecated or will be removed.
  • The unify-docker-image decision is amended in place, because that change has not shipped. Its alternatives and consequences now describe keeping the direct route.
  • USING_PROXY_SERVER and PUBLIC_OR_PROXY_ENDPOINT keep working. Only the "will be removed" wording is dropped, and PUBLIC_OR_PROXY_ENDPOINT is documented as a legacy alias for the database URL of a direct default connection.

Validation

  • Test strings follow the updated label and error messages.
  • No behavior changes.
  • pnpm checks and pnpm test pass.

Merge Danger

Door: two-way

Blast Radius: docs, decision record, and user-facing wording

Related Issues

Related to #1622

Check List

  • I confirm that my contribution is made under the terms of the Apache 2.0 license.
  • I have verified pnpm checks passes with no errors.
  • I have verified pnpm test passes with no failures.
  • I have covered new added functionality with unit tests if necessary.
  • I have updated documentation if necessary.

@kmcginnes kmcginnes changed the title Choose the connection method with a radio group of choice cards Stop describing direct connections as deprecated Oct 6, 2026
@kmcginnes
kmcginnes added this pull request to stack #2370 October 6, 2026 01:07
@kmcginnes
kmcginnes force-pushed the undeprecate-direct-connections branch 2 times, most recently from f232214 to 1bfc410 Compare October 6, 2026 01:25

@kmcginnes kmcginnes left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@kmcginnes
kmcginnes marked this pull request as ready for review October 6, 2026 01:32
@kmcginnes
kmcginnes force-pushed the undeprecate-direct-connections branch from 1bfc410 to a518e53 Compare October 6, 2026 01:32
Base automatically changed from remove-direct-connection-marks to main October 6, 2026 01:34
Direct connections stay a supported option. They are the only route for a database that the browser can reach but the server cannot, and for public endpoints that already allow cross-origin requests. The form label and tooltip, the error messages, the docs, the glossary and the unify-docker-image decision no longer say the option is deprecated or will be removed.
@kmcginnes
kmcginnes force-pushed the undeprecate-direct-connections branch from a518e53 to faa0b7a Compare October 6, 2026 01:36
@kmcginnes
kmcginnes merged commit dbb5782 into main Oct 6, 2026
3 checks passed
@kmcginnes
kmcginnes deleted the undeprecate-direct-connections branch October 6, 2026 01:36
kmcginnes added a commit that referenced this pull request Oct 6, 2026
## Description

The connection method used to be a checkbox at the bottom of Advanced
options, so the most consequential choice in the form was also the
hardest to find, and the IAM fields appeared and vanished with nothing
on screen explaining why. Direct connections are supported again as of
#2369, so the form now presents both methods as a visible choice.

```diff
 <CreateConnection>
   Name
   Database URL
   Query Language
+  <ConnectionMethodField>                  "Connection method"
+    <MethodCard "Via proxy server">        selected by default
+      <IamSettings>                        Use AWS IAM authentication
+                                             AWS Region, Service Type
+    <MethodCard "Directly via browser">
   <Collapsible "Advanced options">
     Fetch Timeout
     Neighbor Expansion Limit
-    "Connect directly from the browser"    checkbox
```

- Each card carries one sentence on what that method supports and what
it gives up. The whole card is a click target.
- The IAM settings sit in the proxy card, because only the proxy server
can sign a request. Under "Directly via browser" they are hidden, and
their values stay in the form but are not saved.
- Checking IAM states that the Graph Explorer server signs requests with
its own AWS credentials, not yours.
- `RadioGroup` is a new primitive in `src/components`, wrapping the
Radix radio group the way the other shadcn-derived components do.
- The error messages, the Database URL validation message, the docs,
both decision records and the glossary follow the new wording.

## Validation

**Before:** the method was a checkbox labelled "Connect directly from
the browser" at the bottom of Advanced options, and the recovery
messages told the reader to uncheck it there.

**After:**

![Via proxy server selected by
default](https://github.com/user-attachments/assets/42f16416-0514-42e1-96c9-e5432324793c)

![AWS IAM authentication enabled inside the proxy
card](https://github.com/user-attachments/assets/9ef82a99-0705-4a4e-8a5a-58789c64b6c9)

![Directly via browser selected, with the IAM settings
hidden](https://github.com/user-attachments/assets/3b1dbc9b-efc3-46bd-b5a6-39af6a50efb8)

New tests cover the default method, arrow-key selection, selecting by
clicking a card, the signing notice, hiding and restoring the IAM
settings, saving each method, the URL validation on the browser method,
and editing a stored connection of either kind.

**Verified live:** exercised in Safari against a local dev server.
Clicking a card's title, description, padding or corners selects it,
arrow keys move between the cards, and the IAM controls inside the proxy
card stay usable without changing the selection. An empty region blocks
save, a relative URL on the browser method shows its validation message,
and editing a saved direct connection opens on "Directly via browser"
with Advanced options collapsed. The dialog logged no console errors.

## Merge Danger

**Door:** two-way

**Impact:** connection form layout

Stored and exported connections keep their shape, so reverting needs no
migration.

## Related Issues

- Follows #2369
- Related to #1622
- Related to #1327
- Related to #1625

### Check List

- [x] I confirm that my contribution is made under the terms of the
Apache 2.0 license.
- [x] I have verified `pnpm checks` passes with no errors.
- [x] I have verified `pnpm test` passes with no failures.
- [x] I have covered new added functionality with unit tests if
necessary.
- [x] I have updated documentation if necessary.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant