|
| 1 | +--- |
| 2 | +'@objectstack/client': patch |
| 3 | +--- |
| 4 | + |
| 5 | +`organizations.getActiveMember`'s own prose says what an anonymous caller gets TODAY: `401 UNAUTHENTICATED` on request ONE — not `200 null` and then a `401 UNAUTHORIZED` from `list-members` |
| 6 | + |
| 7 | +objectstack#17881 (`374d9d3afa`) landed `plugin-auth`'s |
| 8 | +`refuseAnonymousSession`, which converts better-auth's `200` + the literal JSON |
| 9 | +`null` on `GET /api/v1/auth/get-session` into the declared ADR-0112 refusal |
| 10 | +envelope — HTTP `401`, `code: UNAUTHENTICATED` — before it leaves the process. |
| 11 | +`@objectstack/client` reaches the server over the wire, so that is what it |
| 12 | +sees. Three present-tense statements in and around `getActiveMember` still |
| 13 | +described the retired shape, and they were wrong on two axes at once: the CODE |
| 14 | +(`UNAUTHORIZED` vs `UNAUTHENTICATED`) and the REQUEST the refusal arrives on |
| 15 | +(the second one, `list-members`, vs the first, `/get-session` itself). |
| 16 | + |
| 17 | +**FROM → TO for a caller.** `getActiveMember` makes two requests for a |
| 18 | +signed-in caller. For an anonymous one it now makes ONE, and rejects: |
| 19 | + |
| 20 | +| you wrote | write instead | |
| 21 | +|:--|:--| |
| 22 | +| `try { await c.organizations.getActiveMember(id) } catch (e) { if (e.code === 'UNAUTHORIZED') … }` | `… catch (e) { if (e.code === 'UNAUTHENTICATED') … }` | |
| 23 | + |
| 24 | +The behaviour is objectstack#17881's and shipped then; what moves here is only |
| 25 | +the SDK's description of it. A reader coding against the old prose caught the |
| 26 | +wrong code, and expected the refusal on a request that is never put on the |
| 27 | +wire. |
| 28 | + |
| 29 | +**What changed** |
| 30 | + |
| 31 | +- Step 1 of the two-request list no longer says `/get-session` serves "the |
| 32 | + literal `null` for an anonymous one". The signed-in arm keeps its |
| 33 | + `(measured)` tag, which is still the 2026-09-09 drive's; the anonymous |
| 34 | + answer is stated separately and anchored to the producer, including that |
| 35 | + step 2 never reaches the wire. |
| 36 | +- The anonymous bullet of that drive's delta list no longer says an anonymous |
| 37 | + caller "still gets `401 UNAUTHORIZED`, thrown from the `list-members` |
| 38 | + request". It is RE-ANCHORED rather than restamped — the drive's own row is |
| 39 | + kept in the past tense and today's answer is stated from the producer, the |
| 40 | + same disposition objectstack#18642 used on this family's sibling statements. |
| 41 | +- The inline comment on the `userId` read no longer says `Anonymous → null`. |
| 42 | + It says an anonymous caller never reaches that line, and says why the |
| 43 | + `| null` annotation and the `?? ''` fallback stay as the defensive branch |
| 44 | + they always were. |
| 45 | + |
| 46 | +⛔ No behaviour changes. `packages/client/src/index.ts` changes COMMENTS ONLY — |
| 47 | +verified mechanically: of every line the diff touches in that file, zero are |
| 48 | +outside a comment. |
| 49 | + |
| 50 | +**This is shipped, which is why it carries a changeset rather than |
| 51 | +`skip-changeset`.** `@objectstack/client`'s published `files[]` is |
| 52 | +`["dist","README.md","CHANGELOG.md"]` and `getActiveMember` is a member of the |
| 53 | +exported `ObjectStackClient`, so its TSDoc is emitted into the shipped |
| 54 | +artifacts. Measured on the built `dist` at `13e09a5e3c`: the corrected sentence |
| 55 | +is present exactly once in `dist/index.d.ts`, `dist/index.d.mts`, |
| 56 | +`dist/index.js` and `dist/index.mjs`; the retired sentence is absent from all |
| 57 | +four; and `getActiveMember` was carried as the lit control, found in every one |
| 58 | +of them. ⚠️ This package emits no `.d.cts` and no `.cjs` — its CJS pair is |
| 59 | +`index.js` + `index.d.ts` and its ESM pair is `index.mjs` + `index.d.mts`, so |
| 60 | +a `*.d.cts` check here would have measured an absent file. |
| 61 | + |
| 62 | +Clause-②: no — no schema key moves, no closed set gains or loses a member, no |
| 63 | +published export changes and no registry row is touched. `UNAUTHENTICATED` is |
| 64 | +an existing `StandardErrorCode` that objectstack#17881 already derives through |
| 65 | +`standardErrorCodeForHttpStatus(401)`; nothing is minted here. The direction is |
| 66 | +a pull-back: the runtime has answered `401` since objectstack#17881 and the |
| 67 | +SDK's self-description was lagging. |
0 commit comments