Repository navigation
feat: SDK update for version 18.0.0 - #114
Conversation
main received 15.7.0 as a squash merge (#108), so the same change exists under a different commit on each branch. main's tree is identical to dev's 15.7.0 commit, so dev's generated 15.8.0 tree is kept as-is.
main carries only the squashed 16.0.0 release commit, whose tree the generator has since superseded — the doc text in `account.ts`, the formatting of `rollup.config.mjs` and the two `dist/*/package.json` files all differ from what `sdks` now emits. Keeping the generated tree verbatim means the next generation produces no spurious diff.
|
| if (typeof attributes !== 'undefined') { | ||
| payload['attributes'] = attributes; |
There was a problem hiding this comment.
Conversation attributes are corrupted When
createConversation receives an attributes object, the multipart encoder turns it into the string "[object Object]". This happens with or without an attachment, so the API receives corrupted attributes instead of the values the caller supplied.
Knowledge Base Used: Client configuration and HTTP transport
Prompt To Fix With AI
This is a comment left during a code review.
Path: src/services/growth.ts
Line: 192-193
Comment:
**Conversation attributes are corrupted** When `createConversation` receives an `attributes` object, the multipart encoder turns it into the string `"[object Object]"`. This happens with or without an attachment, so the API receives corrupted attributes instead of the values the caller supplied.
**Knowledge Base Used:** [Client configuration and HTTP transport](https://app.greptile.com/appwrite/-/custom-context/knowledge-base/appwrite/sdk-for-console/-/docs/sdk-client-and-transport.md)
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| const clientId = | ||
| this.client.config.pushClientId || | ||
| (authMethod === 'appwrite-jwt' | ||
| ? userIdFromJwt(credential) | ||
| : userIdFromSession(credential)) || | ||
| this.fallbackClientId; |
There was a problem hiding this comment.
Push connections displace each other If the same user opens two tabs, both Push connections use the user ID as their MQTT client ID. The second connection takes over the first one's broker session, and automatic reconnection makes the tabs repeatedly disconnect each other instead of maintaining both subscriptions.
Knowledge Base Used: Networking, realtime, and security
Prompt To Fix With AI
This is a comment left during a code review.
Path: src/services/push.ts
Line: 508-513
Comment:
**Push connections displace each other** If the same user opens two tabs, both Push connections use the user ID as their MQTT client ID. The second connection takes over the first one's broker session, and automatic reconnection makes the tabs repeatedly disconnect each other instead of maintaining both subscriptions.
**Knowledge Base Used:** [Networking, realtime, and security](https://app.greptile.com/appwrite/-/custom-context/knowledge-base/appwrite/sdk-for-console/-/docs/networking-realtime-and-security.md)
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| const options: IClientOptions = { | ||
| clientId, | ||
| protocolVersion: 5, | ||
| clean: false, // always keep the session so the broker can replay QoS-1 topics | ||
| keepalive: KEEP_ALIVE_SECONDS, | ||
| reconnectPeriod: RECONNECT_PERIOD_MS, | ||
| manualConnect: true, | ||
| // Enhanced auth carried in CONNECT properties. | ||
| properties: { | ||
| authenticationMethod: authMethod, | ||
| authenticationData: Buffer.from(credential), | ||
| userProperties: { projectId: project }, | ||
| }, |
There was a problem hiding this comment.
Offline replay is not retained With MQTT 5,
clean: false alone does not keep a broker session after disconnection: the session-expiry interval defaults to zero. Because these connection options do not set one, QoS-1 messages missed during a reload or outage cannot be replayed as retry promises.
Knowledge Base Used: Integrations and communications
Prompt To Fix With AI
This is a comment left during a code review.
Path: src/services/push.ts
Line: 515-527
Comment:
**Offline replay is not retained** With MQTT 5, `clean: false` alone does not keep a broker session after disconnection: the session-expiry interval defaults to zero. Because these connection options do not set one, QoS-1 messages missed during a reload or outage cannot be replayed as `retry` promises.
**Knowledge Base Used:** [Integrations and communications](https://app.greptile.com/appwrite/-/custom-context/knowledge-base/appwrite/sdk-for-console/-/docs/integrations-and-communications.md)
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| if (this.client.config.jwt) { | ||
| authMethod = 'appwrite-jwt'; | ||
| credential = this.client.config.jwt; | ||
| } else if (this.client.config.session) { | ||
| authMethod = 'appwrite-session'; | ||
| credential = this.client.config.session; | ||
| } else { | ||
| throw new Error( | ||
| 'No credential set on the client; call Client.setJWT() or Client.setSession() first.', | ||
| ); | ||
| } | ||
|
|
||
| const project = this.client.config.project ?? ''; |
There was a problem hiding this comment.
Push keeps the previous identity If an application changes the client's JWT, session, or project after login or logout, Push reuses the MQTT connection created with the previous values. It can keep delivering subscriptions under the old identity, while new subscriptions do not connect under the newly configured identity or project until Push is closed.
Knowledge Base Used: Client configuration and HTTP transport
Prompt To Fix With AI
This is a comment left during a code review.
Path: src/services/push.ts
Line: 489-501
Comment:
**Push keeps the previous identity** If an application changes the client's JWT, session, or project after login or logout, Push reuses the MQTT connection created with the previous values. It can keep delivering subscriptions under the old identity, while new subscriptions do not connect under the newly configured identity or project until Push is closed.
**Knowledge Base Used:** [Client configuration and HTTP transport](https://app.greptile.com/appwrite/-/custom-context/knowledge-base/appwrite/sdk-for-console/-/docs/sdk-client-and-transport.md)
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| private connect(): Promise<MqttClient> { | ||
| if (this.mqtt) { | ||
| return Promise.resolve(this.mqtt); | ||
| } | ||
| if (!this.connecting) { | ||
| this.connecting = this.open(); |
There was a problem hiding this comment.
Concurrent subscriptions bypass connection If a second
subscribe() starts before the first connection receives CONNACK, this.mqtt is already set and the second call skips the in-flight connection promise. It can subscribe on a client that has not connected; if the first connection fails, its cleanup also clears the second call's subscription state.
Knowledge Base Used: Networking, realtime, and security
Prompt To Fix With AI
This is a comment left during a code review.
Path: src/services/push.ts
Line: 452-457
Comment:
**Concurrent subscriptions bypass connection** If a second `subscribe()` starts before the first connection receives CONNACK, `this.mqtt` is already set and the second call skips the in-flight connection promise. It can subscribe on a client that has not connected; if the first connection fails, its cleanup also clears the second call's subscription state.
**Knowledge Base Used:** [Networking, realtime, and security](https://app.greptile.com/appwrite/-/custom-context/knowledge-base/appwrite/sdk-for-console/-/docs/networking-realtime-and-security.md)
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| replyToEmail: rest[9] as string, | ||
| replyToName: rest[10] as string, | ||
| scheduledAt: rest[11] as string, | ||
| attachments: rest[12] as string[], |
There was a problem hiding this comment.
Positional email arguments shift An existing positional
updateEmail call that passes scheduledAt still type-checks, but this mapping now sends that string as replyToEmail and omits the scheduled time. The added arguments also break existing positional calls that pass draft to createEmail or enabled to the changed OAuth methods.
Prompt To Fix With AI
This is a comment left during a code review.
Path: src/services/messaging.ts
Line: 503-506
Comment:
**Positional email arguments shift** An existing positional `updateEmail` call that passes `scheduledAt` still type-checks, but this mapping now sends that string as `replyToEmail` and omits the scheduled time. The added arguments also break existing positional calls that pass `draft` to `createEmail` or `enabled` to the changed OAuth methods.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| if ( | ||
| !endpointPush.startsWith('ws://') && | ||
| !endpointPush.startsWith('wss://') | ||
| ) { | ||
| throw new AppwriteException( | ||
| 'Invalid push endpoint URL: ' + endpointPush, | ||
| ); | ||
| } |
There was a problem hiding this comment.
Push credentials use cleartext If a caller sets a
ws:// Push endpoint, or derives one from a supported http:// API endpoint, Push sends the full JWT or session secret in MQTT CONNECT authentication data over that unencrypted connection. This exposes the credential in transit.
How this was verified: The allowed cleartext endpoint reaches mqtt.connect with the raw credential in CONNECT authenticationData.
Knowledge Base Used: Client configuration and HTTP transport
Prompt To Fix With AI
This is a comment left during a code review.
Path: src/client.ts
Line: 500-507
Comment:
**Push credentials use cleartext** If a caller sets a `ws://` Push endpoint, or derives one from a supported `http://` API endpoint, Push sends the full JWT or session secret in MQTT CONNECT authentication data over that unencrypted connection. This exposes the credential in transit.
**How this was verified:** The allowed cleartext endpoint reaches `mqtt.connect` with the raw credential in CONNECT `authenticationData`.
**Knowledge Base Used:** [Client configuration and HTTP transport](https://app.greptile.com/appwrite/-/custom-context/knowledge-base/appwrite/sdk-for-console/-/docs/sdk-client-and-transport.md)
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| for (const sub of this.subscriptions.values()) { | ||
| if (matches(sub.topic, message.topic)) { | ||
| await sub.callback(message); |
There was a problem hiding this comment.
Overlapping filters duplicate callbacks When one
subscribe() call supplies overlapping filters such as users/123/# and users/123/alerts, each filter registers the same callback. A message matching both invokes it twice, which can duplicate notification handling or other side effects.
Knowledge Base Used: Networking, realtime, and security
Prompt To Fix With AI
This is a comment left during a code review.
Path: src/services/push.ts
Line: 639-641
Comment:
**Overlapping filters duplicate callbacks** When one `subscribe()` call supplies overlapping filters such as `users/123/#` and `users/123/alerts`, each filter registers the same callback. A message matching both invokes it twice, which can duplicate notification handling or other side effects.
**Knowledge Base Used:** [Networking, realtime, and security](https://app.greptile.com/appwrite/-/custom-context/knowledge-base/appwrite/sdk-for-console/-/docs/networking-realtime-and-security.md)
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.
This PR contains updates to the SDK for version 18.0.0.
What's Changed
X-Appwrite-Response-Format: 2.3.0)Organizations.getEstimationQuerySuggestionResource.AppwritePushLedgerrenamed toPushLedgerManager.updateOrganizationStatusto block and unblock an organizationPushservice over MQTT withTopic, plusClient.setPushEndpointandClient.setPushClientIdGrowthservice withcreateConversation,createInstallation,ConversationTypeenum andGrowthConversationmodelAccount.createRecoveryOTPandAccount.updateRecoveryOTPfor code-based password recoverypromptparameter onProject.updateOAuth2*for Auth0, Discord, GitHub, Kakao, Microsoft, Okta, Salesforce, Zohopromptfields and enums on theOAuth2*provider modelsreplyToNameandreplyToEmailonMessaging.createEmailandMessaging.updateEmailorganizationUrlon theInstallationmodelProjectEmailTemplateId.OtpRecoveryand Deno 1.21, 1.24, 1.35 inRuntimeandBuildRuntimeDatabases.getAttributereturn type now includes bigint, spatial, varchar and text attributesmqttandbufferdependencies and browser Node polyfills forPush