Repository navigation
fix(examples): use Direct consent in the Next.js starter - #92
Conversation
|
Independent verification: PASS+NOTES Verifier: Codex shipping lane Verified patch:
Both revisions produced successful production builds. Fresh Chromium profiles exercised the built parent at Parent observation: the real starter generated Head observations:
Notes / proof limits: these runs prove the built starter and SDK path against fake transport services. They do not prove hosted owner consent, real provider delivery, native mobile/Desktop launch, or production Account rendering. The mobile continuation destination was intercepted locally. SDK acknowledgement remains best effort; the starter's documented enclave-only limitation remains. No real account, provider or payment operation ran. Local evidence: |
|
🎉 This PR is included in version 0.41.1 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
The shipped Next.js starter sends users to Account with a legacy Session Relay URL. Current Account rejects that URL with
client_id: Required, so the advertised browser integration cannot reach approval or data.This migrates the starter to the existing SDK 4.3.1 Direct controller and React hook: create a signed request, open approval from the click, poll through the app backend, then read the configured ChatGPT scope automatically. App keys, scope selection and Personal Server resolution stay server-side. Failed reads can reuse the approved request; active flows cannot be reset into the SDK's stale-response race. Every HTTP 402 stops before payment signing, including explicit retries.
Standalone PR, base
vana-com/vana-cli:main. No prerequisite PRs or stack. It does not depend on Unity Surfaces PRs or modify Account/Desktop. Legacy public exports, signed manifest and webhook stub remain compatible; the documentation identifies their limits and directs new browser integrations to Direct.Review
examples/nextjs-starter/src/config.ts,src/app/api/{connect,status,data}/route.ts, andsrc/components/ConnectFlow.tsx.Validation
pnpm validate: 61 files, 816 tests pass; TypeScript, ESLint and formatting pass.pnpm --filter nextjs-starter build: production build passes. No server app key appears in browser assets.http://127.0.0.1:4317/, real SDK, fresh Chromium, isolated local transport fixtures: approval/data, denial/expiry with no reads, failed-read retry with one consent request, retry status failure without an unhandled rejection, blocked-popup recovery and mobile continuation pass. Signed app requests are independently verified by the fixture.X-PAYMENT, no payment or acknowledgement effect. Explicit retry remains unpaid.The browser evidence uses local consent and Personal Server fixtures. It does not claim hosted owner approval, real provider delivery or a native mobile/Desktop launch. SDK acknowledgement is best effort; enclave-only delivery is not supported by this controller. Live use requires a registered app identity and an owner's available Personal Server data.