Skip to content

Converge the identity of the server and the browser - #12

Merged
marcospassos merged 7 commits into
masterfrom
identity
Aug 26, 2026
Merged

marcospassos merged 7 commits into
masterfrom
identity

Conversation

@marcospassos

@marcospassos marcospassos commented Aug 26, 2026 •

Copy link
Copy Markdown
Member

Fix token and client ID persistence.

Requests issued while a page is rendered forward the cookies of the request
being rendered, which on a first visit carry no identity yet, so the
middleware issued a second client ID and user token for them. The page was
evaluated as a visitor the browser never receives, as only the identity of
the page response reaches it.

The issued cookies are now reflected on the request being handled, so every
request derived from it evaluates as the same visitor.
The cookies carrying the client ID, the user token and the preview token
were restricted to HTTP, so the SDK running in the browser could neither
read nor write them, and evaluated as a different visitor than the server.

They are now readable by the SDK, as in the other frameworks, which also
hands it the preview token back.
@pkg-pr-new

pkg-pr-new Bot commented Aug 26, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@croct/plug-nuxt@12

commit: 396a4ef

@marcospassos marcospassos added the bug Something isn't working label Aug 26, 2026
The identity was only asserted for evaluations, so fetches are now covered
on both sides, in application routes as well.

The preview cookie is managed by the SDK too, so exiting preview settles
asynchronously, which the assertion now waits for.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR aligns (“converges”) identity handling between server-side rendering and the browser SDK by making identity cookies readable in the browser and ensuring SSR-internal requests reuse the identity issued for the page request. It also updates preview-token validation to match the SDK and adds E2E coverage to prevent regressions around identity persistence.

Changes:

  • Make ct.user_token, ct.client_id, and preview token cookies readable by the browser SDK (removing HttpOnly where previously set).
  • Reflect newly issued identity cookies back onto the in-flight request cookie header to keep SSR-internal requests consistent.
  • Add/adjust runtime and E2E tests to validate identity persistence and preview token behavior.

Reviewed changes

Copilot reviewed 11 out of 11 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
test/runtime/server/utils/cookie.test.ts Updates expectations to ensure the SDK can read the user token cookie.
test/runtime/server/middleware/croct.test.ts Uses real SDK tokens for preview tests and adds coverage for request-cookie reflection + HttpOnly removal.
src/runtime/server/utils/cookie.ts Removes httpOnly from the user token cookie options.
src/runtime/server/middleware/croct.ts Removes httpOnly from cookies, adds request cookie reflection logic, and switches preview token validation to Token.parse(...).isValidNow().
e2e/specs/ssr/identity.spec.ts Adds E2E coverage ensuring SSR + browser SDK see the same identity across visits/navigation/routes.
e2e/specs/middleware.spec.ts Updates preview token generation to SDK-issued tokens and adds browser visibility + async “exit” settling test.
e2e/mock-server.ts Extends mock API to echo identity headers and modifies CORS behavior to allow credentialed requests.
e2e/constants.ts Adds constants for identity echo query/slot used by new specs.
e2e/app/server/api/identity.get.ts Adds API route to evaluate/fetch identity outside of page rendering.
e2e/app/pages/index.vue Adds navigation link to the new identity page in the E2E app.
e2e/app/pages/identity.vue Adds an E2E page that compares SSR identity vs browser SDK identity.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/runtime/server/utils/cookie.ts
Comment thread src/runtime/server/middleware/croct.ts Outdated
Comment thread e2e/mock-server.ts Outdated
Cookies named after object properties are no longer dropped from the
request, and the mock API only allows credentials for an explicit origin.
@marcospassos
marcospassos merged commit 785f414 into master Aug 26, 2026
8 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants