Skip to content

fix(example): skip browser auth callback when proxy is passed - #1416

Merged
gabrielseco merged 4 commits into
mainfrom
fix/example-proxied-demos-auth-none
Sep 29, 2026
Merged

gabrielseco merged 4 commits into
mainfrom
fix/example-proxied-demos-auth-none

Conversation

@gabrielseco

@gabrielseco gabrielseco commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Stops the demo app from repeatedly calling a token endpoint that always fails (403) on the deployed demo, on every page that already routes its API calls through the demo's own server.

Why

When a demo passes proxy, the demo app's server adds the access token to every request itself, so the browser never needs one. These demos still asked for a token through /api/fetch-refresh-token, which is blocked in production on purpose so the deployed demo never hands an access token to the browser. Every page load produced a stream of 403s that looked like real failures while debugging the deployed app.

Passing proxy should be enough on its own, so the fix is a default in the demo app's RemoteFlows wrapper rather than an extra prop on each demo.

What changed

Toggle details
  • example/src/RemoteFlows.tsx: when proxy is passed and neither authType nor isClientToken is set, the wrapper passes no auth callback. An explicit authType still wins.
  • This is only in the example app's wrapper, not the SDK. SDK consumers can legitimately pass proxy and auth together (a relay-only proxy that forwards the browser's token), so the SDK keeps calling auth whenever it's given.
  • Affected demos: Onboarding (Basic), Contract Amendment, Contract Document, Invoice Schedule, plus Termination, JSON Schema Playground, JSON Schema Comparison, Contractor Onboarding and Create Company, which drop their explicit authType='company-manager'. The proxy already overwrote the browser's Authorization header with its own token, so the company-manager token they fetched was never used, and /api/fetch-company-manager returns 403 on the deployed app anyway. The GP onboarding demos already passed authType='none'; that's now redundant but harmless, so I left it along with their comments.
  • Why it repeated: the 403 body has no access_token, so the SDK cached an undefined token with a NaN expiry, treated it as expired, and called the endpoint again before every request.
  • Removed the /api/fetch-refresh-token stub from example/e2e/invoice-schedule.spec.ts, since that route is no longer hit.
  • Local dev is unaffected: the local proxy adds tokens on the server the same way.
  • No SDK or public API changes.
  • Not changed: OnboardingWithCustomBenefits.tsx, OnboardingWithoutSelectCountryStep.tsx and CostCalculatorWithExportPdf.tsx don't use the proxy at all, so on the deployed app they get no token and likely fail outright. Left for a follow-up.

Screenshots

N/A

Related Resources

Testing

  • On the preview deploy, open Onboarding (Basic), Termination, JSON Schema Playground, JSON Schema Comparison, Contractor Onboarding and Create Company: no /api/fetch-refresh-token or /api/fetch-company-manager requests, and API calls return 200
  • Feature flag: N/A

🤖 Generated with Claude Code


Note

Low Risk
Example-app-only auth wiring and test stub cleanup; no SDK or production consumer API changes.

Overview
The example app’s RemoteFlows wrapper now skips the browser auth callback by default when proxy is set (unless authType or isClientToken is explicit), so deployed demos stop hammering blocked token routes like /api/fetch-refresh-token and /api/fetch-company-manager while the server proxy already attaches tokens.

Proxy-based demos (Contractor Onboarding, Create Company, Termination, JSON Schema demos, etc.) drop redundant authType='company-manager' props. Invoice schedule e2e removes the fetch-refresh-token route stub because that path is no longer used.

SDK / public API unchanged — behavior is limited to the example wrapper.

Reviewed by Cursor Bugbot for commit fded1c1. Bugbot is set up for automated code reviews on this repo. Configure here.

The Onboarding, Contract Amendment, Contract Document and Invoice Schedule
demos send every request through the example app's own proxy, which mints
the gateway token server-side and sets Authorization itself. They still
used the default refresh-token auth callback, which calls
/api/fetch-refresh-token - an endpoint that returns 403 in production so
the deployed demo never hands an access token to the browser. The failed
callback left no cached token, so the SDK retried it before every request,
flooding the deployed app's network log with 403s. Use authType='none',
as the GP onboarding demos already do, and drop the now-unreached token
stub from the invoice-schedule e2e spec.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Deploy preview for remote-flows ready!

Project:remote-flows
Status: ✅  Deploy successful!
Preview URL:https://remote-flows-nd6s0uyk8-remotecom.vercel.app
Latest Commit:fded1c1

Deployed with vercel-action

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Deploy preview for adp-cost-calculator ready!

Project:adp-cost-calculator
Status: ✅  Deploy successful!
Preview URL:https://adp-cost-calculator-gjjklox89-remotecom.vercel.app
Latest Commit:fded1c1

Deployed with vercel-action

Every proxy the example app uses is its own Express server, which mints
the gateway token itself, so passing proxy already implies the browser
never needs a token. Make that the RemoteFlows wrapper's default instead
of adding authType='none' to each proxied demo. An explicit authType still
wins, so Termination and JsonSchemaPlayground keep company-manager.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@gabrielseco gabrielseco changed the title fix(example): skip browser auth callback on proxied demos fix(example): skip browser auth callback when proxy is passed Sep 28, 2026
@github-actions

Copy link
Copy Markdown
Contributor

📊 Coverage Report

⚪ Coverage unchanged

Metric Current Previous Change Status
Lines 86.36% 86.36% 0% ⚪
Statements 85.93% 85.93% 0% ⚪
Functions 84.92% 84.92% 0% ⚪
Branches 77.79% 77.79% 0% ⚪

Detailed Breakdown

Lines Coverage
  • Covered: 4850 / 5616
  • Coverage: 86.36%
  • Change: 0% (0 lines)
Statements Coverage
  • Covered: 4934 / 5742
  • Coverage: 85.93%
  • Change: 0% (0 statements)
Functions Coverage
  • Covered: 1290 / 1519
  • Coverage: 84.92%
  • Change: 0% (0 functions)
Branches Coverage
  • Covered: 3002 / 3859
  • Coverage: 77.79%
  • Change: 0% (0 branches)

✅ Coverage check passed

gabrielseco and others added 2 commits September 28, 2026 15:31
Termination and JsonSchemaPlayground pass proxy, and the example proxy
overwrites the Authorization header with a token it mints server-side, so
the company-manager token the browser fetched was never used. On the
deployed app /api/fetch-company-manager returns 403, so it only added
failing requests. Let them fall back to the proxy default like the other
proxied demos.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…emos

JsonSchemaComparison, ContractorOnboarding and CreateCompany also pass
proxy with authType='company-manager'. Same as Termination and
JsonSchemaPlayground: the proxy overwrites Authorization with its own
token, so the browser-fetched one was never used and only produced 403s
on the deployed app.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@gabrielseco
gabrielseco merged commit 06f8ff5 into main Sep 29, 2026
13 checks passed
@gabrielseco
gabrielseco deleted the fix/example-proxied-demos-auth-none branch September 29, 2026 10:12
@gabrielseco gabrielseco mentioned this pull request Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants