Repository navigation
fix(example): skip browser auth callback when proxy is passed - #1416
Merged
Merged
Conversation
The Onboarding, Contract Amendment, Contract Document and Invoice Schedule demos send every request through the example app's own proxy, which mints the gateway token server-side and sets Authorization itself. They still used the default refresh-token auth callback, which calls /api/fetch-refresh-token - an endpoint that returns 403 in production so the deployed demo never hands an access token to the browser. The failed callback left no cached token, so the SDK retried it before every request, flooding the deployed app's network log with 403s. Use authType='none', as the GP onboarding demos already do, and drop the now-unreached token stub from the invoice-schedule e2e spec. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
|
Deploy preview for remote-flows ready!
Deployed with vercel-action |
Contributor
|
Deploy preview for adp-cost-calculator ready!
Deployed with vercel-action |
Every proxy the example app uses is its own Express server, which mints the gateway token itself, so passing proxy already implies the browser never needs a token. Make that the RemoteFlows wrapper's default instead of adding authType='none' to each proxied demo. An explicit authType still wins, so Termination and JsonSchemaPlayground keep company-manager. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
📊 Coverage Report⚪ Coverage unchanged
Detailed BreakdownLines Coverage
Statements Coverage
Functions Coverage
Branches Coverage
✅ Coverage check passed |
Termination and JsonSchemaPlayground pass proxy, and the example proxy overwrites the Authorization header with a token it mints server-side, so the company-manager token the browser fetched was never used. On the deployed app /api/fetch-company-manager returns 403, so it only added failing requests. Let them fall back to the proxy default like the other proxied demos. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…emos JsonSchemaComparison, ContractorOnboarding and CreateCompany also pass proxy with authType='company-manager'. Same as Termination and JsonSchemaPlayground: the proxy overwrites Authorization with its own token, so the browser-fetched one was never used and only produced 403s on the deployed app. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
jordividaller
approved these changes
Sep 29, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Stops the demo app from repeatedly calling a token endpoint that always fails (403) on the deployed demo, on every page that already routes its API calls through the demo's own server.
Why
When a demo passes
proxy, the demo app's server adds the access token to every request itself, so the browser never needs one. These demos still asked for a token through/api/fetch-refresh-token, which is blocked in production on purpose so the deployed demo never hands an access token to the browser. Every page load produced a stream of 403s that looked like real failures while debugging the deployed app.Passing
proxyshould be enough on its own, so the fix is a default in the demo app'sRemoteFlowswrapper rather than an extra prop on each demo.What changed
Toggle details
example/src/RemoteFlows.tsx: whenproxyis passed and neitherauthTypenorisClientTokenis set, the wrapper passes noauthcallback. An explicitauthTypestill wins.proxyandauthtogether (a relay-only proxy that forwards the browser's token), so the SDK keeps callingauthwhenever it's given.authType='company-manager'. The proxy already overwrote the browser'sAuthorizationheader with its own token, so the company-manager token they fetched was never used, and/api/fetch-company-managerreturns 403 on the deployed app anyway. The GP onboarding demos already passedauthType='none'; that's now redundant but harmless, so I left it along with their comments.access_token, so the SDK cached an undefined token with aNaNexpiry, treated it as expired, and called the endpoint again before every request./api/fetch-refresh-tokenstub fromexample/e2e/invoice-schedule.spec.ts, since that route is no longer hit.OnboardingWithCustomBenefits.tsx,OnboardingWithoutSelectCountryStep.tsxandCostCalculatorWithExportPdf.tsxdon't use the proxy at all, so on the deployed app they get no token and likely fail outright. Left for a follow-up.Screenshots
N/A
Related Resources
Testing
/api/fetch-refresh-tokenor/api/fetch-company-managerrequests, and API calls return 200🤖 Generated with Claude Code
Note
Low Risk
Example-app-only auth wiring and test stub cleanup; no SDK or production consumer API changes.
Overview
The example app’s
RemoteFlowswrapper now skips the browser auth callback by default whenproxyis set (unlessauthTypeorisClientTokenis explicit), so deployed demos stop hammering blocked token routes like/api/fetch-refresh-tokenand/api/fetch-company-managerwhile the server proxy already attaches tokens.Proxy-based demos (Contractor Onboarding, Create Company, Termination, JSON Schema demos, etc.) drop redundant
authType='company-manager'props. Invoice schedule e2e removes thefetch-refresh-tokenroute stub because that path is no longer used.SDK / public API unchanged — behavior is limited to the example wrapper.
Reviewed by Cursor Bugbot for commit fded1c1. Bugbot is set up for automated code reviews on this repo. Configure here.