Converge the identity of the server and the browser - #12
Merged
Merged
Conversation
Requests issued while a page is rendered forward the cookies of the request being rendered, which on a first visit carry no identity yet, so the middleware issued a second client ID and user token for them. The page was evaluated as a visitor the browser never receives, as only the identity of the page response reaches it. The issued cookies are now reflected on the request being handled, so every request derived from it evaluates as the same visitor.
The cookies carrying the client ID, the user token and the preview token were restricted to HTTP, so the SDK running in the browser could neither read nor write them, and evaluated as a different visitor than the server. They are now readable by the SDK, as in the other frameworks, which also hands it the preview token back.
commit: |
The identity was only asserted for evaluations, so fetches are now covered on both sides, in application routes as well. The preview cookie is managed by the SDK too, so exiting preview settles asynchronously, which the assertion now waits for.
There was a problem hiding this comment.
Pull request overview
This PR aligns (“converges”) identity handling between server-side rendering and the browser SDK by making identity cookies readable in the browser and ensuring SSR-internal requests reuse the identity issued for the page request. It also updates preview-token validation to match the SDK and adds E2E coverage to prevent regressions around identity persistence.
Changes:
- Make
ct.user_token,ct.client_id, and preview token cookies readable by the browser SDK (removingHttpOnlywhere previously set). - Reflect newly issued identity cookies back onto the in-flight request cookie header to keep SSR-internal requests consistent.
- Add/adjust runtime and E2E tests to validate identity persistence and preview token behavior.
Reviewed changes
Copilot reviewed 11 out of 11 changed files in this pull request and generated 3 comments.
Show a summary per file
| File | Description |
|---|---|
| test/runtime/server/utils/cookie.test.ts | Updates expectations to ensure the SDK can read the user token cookie. |
| test/runtime/server/middleware/croct.test.ts | Uses real SDK tokens for preview tests and adds coverage for request-cookie reflection + HttpOnly removal. |
| src/runtime/server/utils/cookie.ts | Removes httpOnly from the user token cookie options. |
| src/runtime/server/middleware/croct.ts | Removes httpOnly from cookies, adds request cookie reflection logic, and switches preview token validation to Token.parse(...).isValidNow(). |
| e2e/specs/ssr/identity.spec.ts | Adds E2E coverage ensuring SSR + browser SDK see the same identity across visits/navigation/routes. |
| e2e/specs/middleware.spec.ts | Updates preview token generation to SDK-issued tokens and adds browser visibility + async “exit” settling test. |
| e2e/mock-server.ts | Extends mock API to echo identity headers and modifies CORS behavior to allow credentialed requests. |
| e2e/constants.ts | Adds constants for identity echo query/slot used by new specs. |
| e2e/app/server/api/identity.get.ts | Adds API route to evaluate/fetch identity outside of page rendering. |
| e2e/app/pages/index.vue | Adds navigation link to the new identity page in the E2E app. |
| e2e/app/pages/identity.vue | Adds an E2E page that compares SSR identity vs browser SDK identity. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Fryuni
approved these changes
Aug 26, 2026
Cookies named after object properties are no longer dropped from the request, and the mock API only allows credentials for an explicit origin.
renan628
approved these changes
Aug 26, 2026
Fryuni
approved these changes
Aug 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fix token and client ID persistence.