Skip to content

feat(react-native-kratos)!: add native authentication lifecycle - #3

Merged
TorinAsakura merged 37 commits into
masterfrom
feat/kratos-auth-lifecycle
Oct 6, 2026
Merged

TorinAsakura merged 37 commits into
masterfrom
feat/kratos-auth-lifecycle

Conversation

@TorinAsakura

@TorinAsakura TorinAsakura commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Task

  • Close [Package] Kratos React Native #1
  • Breaking release: adopt Expo 56 / React Native 0.85 / React 19 and the new public native authentication lifecycle. The package has an explicit Yarn major decision.

How to test

Main scenario

  1. During restoration, hold toSession after SecureStore has returned a token. Log out, fail the first remote revocation, retry it, then release the late validation response. The known token must be revoked, local auth and storage cleared, and the late response must not authenticate it.
  2. Validate a legacy user_session value while accepting a newer account. Migration must wait for validation; an older 401 must not delete the newer credential.
  3. Register and log in through the public native flow wrappers on Android against the existing non-production Kratos stand. Check persistence, restart/restoration, synchronization, logout, local clear, temporary unavailability and recovery, inactive-session cleanup, account switching and failed-logout retry without exposing token values.

Additional scenario

  1. Confirm a session, overlap replacements, fail a later persistence write and synchronize during acceptance. The last committed credential remains authoritative; temporary server failure retains the previously confirmed public auth state. Account switching does not automatically revoke another account's session.
  2. Run CI=true yarn install --immutable, yarn check --verify and yarn workspace @atls/react-native-kratos build. Verify the package's ESM output and declarations against the current Expo 56 / React Native 0.85 / React 19 consumer dependency graph. Package compatibility does not imply adoption by the product.
  3. Confirm .github/workflows/publish-image.yml is absent from this branch and .github/workflows/publish-npm.yaml remains unchanged here. Merging must not start image publication; the Terraform-managed npm caller on master now uses the shared workspace release workflow.
  4. Hold the new session in storage.write, then call logout before the write finishes. Both the prior and incoming server sessions must be revoked, local storage cleared, and a failed incoming revocation reported and retried.
  5. Run yarn version check, yarn release version infer --dry-run and yarn version apply --all --dry-run. The explicit major decision must remain authoritative and produce @atls/react-native-kratos@1.0.0 without changing the version in this PR.

Proof

  • Current head: 32cc924b09d20201a1e4e99d1338a72c5d2169ac; the branch forked from master at b1c497fcc24b71922abfa4e4ca24f41c18c3bfc7. The image-workflow removal, Raijin update, pending-logout fix and explicit major decision are separate ordinary commits; no published history was rewritten.
  • The repository now uses released @atls/raijin@1.1.0 and Yarn 4.18.0. The checked-in Yarn runtime matches the GitHub release asset's SHA-256 70cc9cd3583ffa73a2533911d6412517d7f52b3fd2bac860ea9b868d0319d89a; lock/PnP files were regenerated. The root package declares ESM and the redundant .yarn/releases/package.json remains absent. The Raijin update did not change adapter source or packages/react-native-kratos/package.json; the following fix changes the session store and its tests.
  • The updater first hit Yarn's 24-hour quarantine for the new first-party release, then declined to migrate legacy hook files without final newlines. A one-command age-gate override and HUSKY=0 completed the verified package/runtime update; no hook or repository policy file changed. A normal immutable install and normal commit hooks passed afterward.
  • Removed the unused root @atls/code-runtime dependency, its one-line ambient type reference and the unreferenced legacy yarn-remote.mjs bundle. The root TypeScript include list now names only packages/**/*; regenerated lock/PnP files no longer contain code-runtime. The active Yarn runtime remains .yarn/releases/yarn.js.
  • Removed the unused .github/workflows/publish-image.yml from this PR. The Terraform-owned checks workflow and the npm-publishing caller were not changed. The shared npm release workflow was repaired separately by Infrastructure #1594.
  • Removed all 14 tracked .idea/ files and the obsolete linterIgnorePatterns and TypeScript exclusion. .idea/ remains ignored so local IDE state cannot re-enter Git. On this head, CI=true yarn install --immutable --inline-builds, yarn check --verify (format, lint, typecheck, 27 unit cases and integration), yarn workspace @atls/react-native-kratos build and yarn version check passed locally.
  • After the Raijin update, CI=true yarn install --immutable --inline-builds, yarn check --verify (format, lint, typecheck, 27 unit cases, integration) and yarn workspace @atls/react-native-kratos build passed. Normal commit hooks passed. Before the explicit decision, inference suggested minor; the committed .yarn/versions/d2aee7e8.yml now records major. yarn release version infer --dry-run reports no missing decisions, yarn version check passes, and yarn version apply --all --dry-run shows @atls/react-native-kratos@1.0.0. Yarn selects this workspace from the PR base. git diff --check passes for the manifest, lockfile and PnP loader; it reports 12 trailing whitespace lines inside the byte-verified published yarn.js asset, which was kept intact. The GitHub Checks run passed before the release-decision commit; current-head checks are tracked on the PR.
  • The prior Raijin 1.0.2 migration introduced the checked-in Yarn runtime and explicit lint-staged configuration. Its exact-head GitHub Checks run passed; that result is historical and is not assigned to this head.
  • The Terraform-owned .github/workflows/checks.yaml is unchanged. Its prior one-line direct override was removed in b379600. The shared check workflow's yarn check --verify default remains supported. Infrastructure #1594 delivered the new release workflow to atls/shared; Infrastructure #1599 delivered the caller switch: the OpenTofu apply succeeded, and atls/react-native master contains the exact shared caller blob 9c3c4adf. This PR does not edit CI or provider permissions.
  • Scope reduction removed browser exchange/callback, web fallback, unused peers and their tests. Test cleanup removed two duplicate store scenarios. Public provider cases still cover local clear versus explicit logout, and pending restoration followed by logout, retry and a late response. The separate 403 AAL decision was not changed.
  • AI finding 4140068644 mixed two claims: automatic revocation on account switching conflicts with issue [Package] Kratos React Native #1 and was not added; explicit logout missing a token already read during restoration was valid and was fixed in eb692b0. Store and mounted-provider tests reach the pending SDK operation, cover revocation/retry and reject its late result. The AI thread was resolved with native readback; the user's review 5359924081 remains untouched.
  • Before the latest toolchain and session-store updates, the candidate package passed strict TypeScript and clean-cache Metro exports in isolated Expo 56 fixtures using public registry dependencies, including the current Caily auth-runtime versions. The only file: dependency was the candidate archive. That is packaging compatibility, not consumer adoption; this new head has not been reinstalled into those fixtures.
  • Android acceptance was performed on the existing Expo Go 56.0.4 / Android 16 arm64 emulator against the existing non-production Yggdrasil Kratos stand, which reported server 1.3.0; the client SDK was 26.2.0. Registration, login, persistence, force-stop/reopen restoration, synchronization, explicit logout, local clear, temporary server failure/recovery, inactive-session cleanup, account switching and retry after failed remote logout behaved as recorded in the earlier PR history. Controlled test sessions were disabled afterward, while identities/database were retained and the stand was restored. The device run belongs to an earlier package candidate; the pending-logout store fix has unit coverage but has not been rerun on the emulator at this head. The package manifest remains unchanged. No local Docker stand, backend copy, server upgrade or production-data change was made.
  • An earlier independent read-only technical review is historical. Review finding 4170808109 about logout during a pending credential write was reproduced, fixed in baacd7f, and covered by two store tests; the fixing reply was published and the exact review thread was resolved. The user's earlier review remains preserved. iOS device verification is deferred. Package publication, product adoption, native app deployment and this PR's merge are not claimed.

@TorinAsakura TorinAsakura changed the title feat(kratos): add native auth lifecycle feat(react-native-kratos): add native authentication lifecycle Sep 29, 2026
@TorinAsakura
TorinAsakura marked this pull request as ready for review September 29, 2026 23:59
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T00:02:32.091057Z 1ee43bb New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bda7075118

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/react-native-kratos/src/providers/session-token.storage.ts Outdated
Comment thread packages/react-native-kratos/src/providers/auth-session.store.ts

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: caf9b05c4b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/react-native-kratos/src/providers/auth-session.store.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4206181883

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/react-native-kratos/src/providers/auth-session.store.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6fb25e3d92

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/react-native-kratos/src/providers/auth.provider.tsx Outdated
Comment thread packages/react-native-kratos/src/index.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5300c0bf08

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/react-native-kratos/src/providers/session-token.storage.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4dcfa088e4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/react-native-kratos/src/providers/auth-session.store.ts
Comment thread packages/react-native-kratos/src/providers/auth-session.store.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e6efcc3808

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/react-native-kratos/src/providers/auth-session.store.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 05a84d16a1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/react-native-kratos/src/providers/auth-session.store.ts
Comment thread packages/react-native-kratos/src/providers/auth-session.store.ts Outdated
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1ee43bbca0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/react-native-kratos/src/providers/auth-session.store.ts Outdated
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@TorinAsakura TorinAsakura changed the title feat(react-native-kratos): add native authentication lifecycle feat(react-native-kratos)!: add native authentication lifecycle Oct 6, 2026
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@TorinAsakura
TorinAsakura merged commit a2a18b8 into master Oct 6, 2026
2 checks passed
@TorinAsakura
TorinAsakura deleted the feat/kratos-auth-lifecycle branch October 6, 2026 00:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Package] Kratos React Native

1 participant