Skip to content

Commit 62960ff

Browse files
committed
Merge origin/main into claude/issue-21913-principal-less-producers-services
Claude-Session: https://claude.ai/code/session_011K3zqE8Pv1Evw5hc8tZCnN Co-authored-by: Claude <noreply@anthropic.com>
2 parents 10e77fe + 9dce635 commit 62960ff

3 files changed

Lines changed: 61 additions & 4 deletions

File tree

‎content/docs/data-modeling/drivers.mdx‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -154,7 +154,10 @@ Two things live **outside** `config`, because they are not driver-specific:
154154

155155
A plugin-contributed driver (`com.vendor.snowflake`) has no contract in this
156156
repo, so its `config` is left unvalidated rather than judged against a shape the
157-
platform does not have.
157+
platform does not have. The platform also does not guess which of its keys hold
158+
credentials: `config` is stored and served to administrators as written. Keeping
159+
secrets out of it is the plugin author's responsibility; put the credential in
160+
the bound secret (`external.credentialsRef`) instead.
158161

159162
<Callout type="info">
160163
The same schemas are projected to JSON Schema for

‎content/docs/permissions/sso.mdx‎

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -379,11 +379,16 @@ The Console `/login` and `/register` pages will now show a button for each enabl
379379
4. Provider redirects to `/api/v1/auth/callback/google`.
380380
5. better-auth creates a session and redirects to `callbackURL`.
381381

382-
**OIDC/enterprise providers**:
382+
**OIDC/enterprise providers** (`oidcProviders`): better-auth's generic-OAuth plugin
383+
registers each one as a social provider and adds no endpoints of its own, so the flow uses
384+
the same two routes as above.
383385
1. User clicks **Continue with Okta SSO**.
384-
2. Client calls `POST /api/v1/auth/sign-in/oauth2` with `{ providerId: "okta", callbackURL }`.
386+
2. Client calls `POST /api/v1/auth/sign-in/social` with `{ provider: "okta", callbackURL }`,
387+
where `provider` is the entry's `providerId`.
385388
3. Browser redirects to the provider's authorization endpoint.
386-
4. Provider redirects back; better-auth validates the OIDC token and creates a session.
389+
4. Provider redirects to `/api/v1/auth/callback/okta`. better-auth exchanges the code, reads
390+
the user's profile from the ID token or `userInfoUrl`, creates a session and redirects to
391+
`callbackURL`.
387392

388393
## Linking to an existing account
389394

‎packages/rest/src/meta-state-route-engine-outage.test.ts‎

Lines changed: 49 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -101,6 +101,39 @@
101101
* same 501 instead of escaping to the route's own `500 EMAIL_SEND_FAILED`.
102102
*/
103103

104+
// [#21920] Pay the state route's `@objectstack/objectql` load at MODULE LOAD,
105+
// never inside a clocked window.
106+
//
107+
// The route reaches `legalNextStates` through a dynamic
108+
// `await import('@objectstack/objectql')` in `rest-server.ts`, kept dynamic on
109+
// purpose (a devDependency there: a host without the data engine degrades to
110+
// 501 rather than failing to load). This package's tests resolve that specifier
111+
// through `dist/`, so the first request to reach that line pays the vite
112+
// transform and evaluation of objectql's whole module graph, inside whichever
113+
// `it()` first gets PAST the gate with a schema: §0's multi-kernel case. Measured
114+
// on a 4-vCPU container, this file run alone, before this import existed:
115+
//
116+
// * idle: that case cost 3574-3661 ms of the 5000 ms `testTimeout`. Phase-timed,
117+
// the handler call is all of it (2.7-2.8 s in a stripped probe); wiring and
118+
// boot are under 1 ms each, and the cold KERNEL branch answering a 404 before
119+
// the load costs 1.5 ms. So it is the load, not a multi-kernel first-request
120+
// cost: under plain Node the same cold import is ~0.6 s on top of the core
121+
// and spec this server already loads, and a host whose engine IS objectql
122+
// has it loaded before any request.
123+
// * confined to one core beside two busy loops: `Test timed out in 5000ms` on
124+
// 3 of 3 runs, and the load, still in flight, then landed on §3's served
125+
// CONTROL (3714-4330 ms), the next case to reach the same line.
126+
//
127+
// A module-top import is paid during COLLECTION, which vitest clocks against
128+
// nothing (AGENTS.md § Build & Test; `scripts/check-test-source-alias.mjs`
129+
// carries the runner measurement). ⛔ Not a `beforeAll` with a budget, and not a
130+
// raised timeout: either only moves the window around the cost, and
131+
// `dev-plugin-security-enforcement-warning.test.ts` (plugin-dev) records such a
132+
// hook budget being exhausted on a heavier shard. The dynamic call in
133+
// `rest-server.ts` stays where it is; this only decides where the first load is
134+
// paid. §0's multi-kernel case pins it with a budget on its own work.
135+
import '@objectstack/objectql';
136+
104137
import { describe, it, expect, vi } from 'vitest';
105138
import {
106139
AUTHZ_STORE_UNAVAILABLE_CODE,
@@ -299,9 +332,25 @@ describe('[#15405] §0 reachability of this consumer, measured', () => {
299332
// and the route's own engine line is what decides. This is the
300333
// precondition every case in §1–§4 depends on; without it they would
301334
// all be measuring the gate.
335+
const started = performance.now();
302336
const seen = await driveStateOnKernelHost(providerHealthy);
337+
const ownWorkMs = performance.now() - started;
303338
expect(seen.outcome).toBe('answered');
304339
expect(seen.status).toBe(200);
340+
// [#21920] PIN — this is the file's FIRST case to reach the route's
341+
// `import('@objectstack/objectql')`, so it is the one that pays that load
342+
// if it ever lands in a clocked window again (file head). Its own work,
343+
// measured on a 4-vCPU container: 3 ms idle, 12-16 ms with this file
344+
// confined to a third of one core, 3-23 ms confined to a fifth. The load
345+
// it must not carry: 3574-3661 ms with the file run alone, 893 and
346+
// 1723 ms in two whole-package runs (an earlier file had already cached
347+
// the transform). 500 ms sits about 20x above the first and below every
348+
// reading of the second, so the regression reads red on an IDLE box,
349+
// well before a loaded shard turns it into the 5000 ms timeout.
350+
expect(
351+
ownWorkMs,
352+
"this case paid a module load inside its clocked window: keep the module-top import of '@objectstack/objectql' at the file head",
353+
).toBeLessThan(500);
305354
});
306355
});
307356

0 commit comments

Comments
 (0)