Repository navigation
feat(routes): declare adapter behaviour in defineRoute and publish an adapter manifest - #380
Merged
Merged
Conversation
… adapter manifest Server adapters hard-code which token each route takes and which tokens a response issues or clears. Routes now declare that with an `adapter` option, and the API publishes it at GET /.well-known/seamless-adapter.json (also committed as adapter-manifest.json by `npm run generate:api`), so adapters in any language can follow data instead of a hand-maintained route list. Registration fails when a public route does not say whether adapters expose it, when an ephemeral route does not name the token it takes, or when a route that always returns a token does not say what it issues. The four OTP send routes and the magic-link request now also accept POST. They send a message, and a GET can be triggered cross-site without a CORS preflight. The GET forms still work and are deprecated. Part of #371. Closes #372.
This was referenced Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #371. Closes #372.
Why
Server adapters hard-code per-route knowledge: which token a route takes, and which tokens a response issues or clears. In
seamless-auth-serverthat is seven files per new route, the Express and Fastify adapters have drifted before, and a Go, Rust or Python adapter would have to copy all of it. This makes the API the source of that knowledge so adapters follow data instead.What changes
adapteroption ondefineRoute. Access routes default to an exposed passthrough that sends the access token, so most routes need nothing. The routes that differ declarecredential,issues,clears,body.pick(adapter cookie transport only) anddelivery. The API itself stays bearer and JSON only.adapter: falseor an object)preAuthorregistrationGET /.well-known/seamless-adapter.jsonserves the manifest (schemaVersion: 1).npm run generate:apialso writes it toadapter-manifest.json, and a test keeps the committed copy in step. Health, JWKS, the manifest itself and the conformance routes areadapter: false.POSTfor the four OTP send routes and the magic-link request. They send a message, and the SDK already calls them with POST so a cross-site page cannot trigger them without a CORS preflight. A generic adapter following the manifest would otherwise have exposedGET. TheGETforms keep working, are marked deprecated, and are not in the manifest./loginkeeps its narrowed body (message,identifierType,loginMethods).Contract impact
Additive: one new endpoint, five new
POSTroutes, fiveGETroutes deprecated. No existing route changes shape. Consumers:ensureCookiesmap with a proxy driven by this manifest.Found while mapping the adapter
These are for fells-code/seamless-auth-server#201 and are not changed here:
POST /totp/verify-login(TOTP sign-in) has no adapter passthrough, so TOTP sign-in does not work through an adapter today. It is in the manifest.POST /users/update, which does not exist on the API.tokenfrom the OTP send routes to the browser.Checks
npm run typecheck,npm run lintandnpm run format:checkare clean.npm run test:run: 135 files, 1795 passed.npm run buildpasses.adapteris metadata only, that thePOSTvariants carry the same auth, decoy and limiter middleware, and that the manifest exposes nothing sensitive.