Compare commits

...
1 Commits
Author SHA1 Message Date
Jeroen SchweitzerandClaude Opus 4.5 672f497733 fix(auth): enable cookie credentials for web API requests
Build and Push / release (push) Successful in 3s
Build and Push / build (push) Successful in 2m56s
Configure Dio with BrowserHttpClientAdapter and withCredentials: true
for web platform, allowing session cookies to be sent with XHR requests.
This fixes NPM forward auth not working for API calls.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-03 22:56:56 +01:00
5 changed files with 50 additions and 21 deletions
+7
View File
@@ -7,6 +7,13 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
## [Unreleased] ## [Unreleased]
## [1.0.1] - 2026-01-03
### Fixed
- Web authentication now works correctly with NPM forward auth
- Dio client sends cookies with requests via `withCredentials: true`
- Added platform-specific adapters (native vs web) for proper cookie handling
## [1.0.0] - 2026-01-03 ## [1.0.0] - 2026-01-03
### Added ### Added
+23 -20
View File
@@ -3,23 +3,26 @@ import 'package:riverpod_annotation/riverpod_annotation.dart';
import 'package:tatlock_ui/core/api/api_interceptors.dart'; import 'package:tatlock_ui/core/api/api_interceptors.dart';
import 'package:tatlock_ui/core/config/app_config.dart'; import 'package:tatlock_ui/core/config/app_config.dart';
import 'api_client_native.dart' if (dart.library.html) 'api_client_web.dart'
as platform;
part 'api_client.g.dart'; part 'api_client.g.dart';
/// Provides the Dio instance for Core API. /// Provides the Dio instance for Core API.
@riverpod @riverpod
Dio coreApiClient(Ref ref) { Dio coreApiClient(Ref ref) {
final dio = Dio( final options = BaseOptions(
BaseOptions( baseUrl: AppConfig.coreApiUrl,
baseUrl: AppConfig.coreApiUrl, connectTimeout: const Duration(seconds: 10),
connectTimeout: const Duration(seconds: 10), receiveTimeout: const Duration(seconds: 30),
receiveTimeout: const Duration(seconds: 30), headers: {
headers: { 'Content-Type': 'application/json',
'Content-Type': 'application/json', 'Accept': 'application/json',
'Accept': 'application/json', },
},
),
); );
final dio = platform.createDio(options);
dio.interceptors.addAll([ dio.interceptors.addAll([
AuthInterceptor(ref), AuthInterceptor(ref),
LoggingInterceptor(), LoggingInterceptor(),
@@ -32,18 +35,18 @@ Dio coreApiClient(Ref ref) {
/// Provides the Dio instance for Tatlock API. /// Provides the Dio instance for Tatlock API.
@riverpod @riverpod
Dio tatlockApiClient(Ref ref) { Dio tatlockApiClient(Ref ref) {
final dio = Dio( final options = BaseOptions(
BaseOptions( baseUrl: AppConfig.tatlockApiUrl,
baseUrl: AppConfig.tatlockApiUrl, connectTimeout: const Duration(seconds: 10),
connectTimeout: const Duration(seconds: 10), receiveTimeout: const Duration(minutes: 5), // Longer for LLM responses
receiveTimeout: const Duration(minutes: 5), // Longer for LLM responses headers: {
headers: { 'Content-Type': 'application/json',
'Content-Type': 'application/json', 'Accept': 'application/json',
'Accept': 'application/json', },
},
),
); );
final dio = platform.createDio(options);
dio.interceptors.addAll([ dio.interceptors.addAll([
AuthInterceptor(ref), AuthInterceptor(ref),
LoggingInterceptor(), LoggingInterceptor(),
+6
View File
@@ -0,0 +1,6 @@
import 'package:dio/dio.dart';
/// Create a Dio instance for native platforms (mobile, desktop).
Dio createDio(BaseOptions options) {
return Dio(options);
}
+12
View File
@@ -0,0 +1,12 @@
import 'package:dio/dio.dart';
import 'package:dio_web_adapter/dio_web_adapter.dart';
/// Create a Dio instance for web platform with credentials support.
///
/// Enables `withCredentials` to send cookies with requests, which is
/// required for NPM forward auth to work correctly.
Dio createDio(BaseOptions options) {
final dio = Dio(options);
dio.httpClientAdapter = BrowserHttpClientAdapter(withCredentials: true);
return dio;
}
+2 -1
View File
@@ -16,7 +16,7 @@ publish_to: 'none' # Remove this line if you wish to publish to pub.dev
# https://developer.apple.com/library/archive/documentation/General/Reference/InfoPlistKeyReference/Articles/CoreFoundationKeys.html # https://developer.apple.com/library/archive/documentation/General/Reference/InfoPlistKeyReference/Articles/CoreFoundationKeys.html
# In Windows, build-name is used as the major, minor, and patch parts # In Windows, build-name is used as the major, minor, and patch parts
# of the product and file versions while build-number is used as the build suffix. # of the product and file versions while build-number is used as the build suffix.
version: 1.0.0+1 version: 1.0.1+1
environment: environment:
sdk: ^3.10.4 sdk: ^3.10.4
@@ -67,6 +67,7 @@ dependencies:
url_launcher: ^6.3.1 url_launcher: ^6.3.1
flutter_code_editor: ^0.3.5 flutter_code_editor: ^0.3.5
highlight: ^0.7.0 highlight: ^0.7.0
dio_web_adapter: ^2.1.1
dev_dependencies: dev_dependencies:
flutter_test: flutter_test: