Skip to content

feat(proxy): pass audit and coverage report routes through, with raw downloads - #191

Merged
Bccorb merged 1 commit into
mainfrom
feat/audit-and-coverage-passthroughs
Oct 7, 2026
Merged

Bccorb merged 1 commit into
mainfrom
feat/audit-and-coverage-passthroughs

Conversation

@Bccorb

@Bccorb Bccorb commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Passthroughs for three new auth API admin routes, all on the caller's access identity, with their queries forwarded:

Route API PR Body
GET /admin/auth-events/integrity fells-code/seamless-auth-api#356 (merged) JSON
GET /admin/auth-events/export fells-code/seamless-auth-api#358 NDJSON download
GET /admin/reports/authentication-coverage fells-code/seamless-auth-api#357 JSON, or CSV with format=csv

/admin/reports is added to the ensureCookies requirement map. /admin/auth-events already covers the new sub-paths by prefix.

Raw passthrough

proxyRequest always parsed the upstream body as JSON. The tolerant parser turns a CSV or NDJSON body into { message: "<text>" }, and the adapter then drops Content-Type and Content-Disposition, so a download would arrive as a JSON blob. This adds a raw mode:

  • core: proxyRequest({ ..., raw: true }) returns raw: { headers, body }. body is the upstream stream, and headers holds only content-type, content-disposition and cache-control. applyResult hands that to a new required ResponseAdapter.sendRaw(status, raw). The adapter's own rejections (no session, for example) still go out as JSON.
  • express: streams with Readable.fromWeb(...).pipe(res). An upstream failure partway through destroys the connection, so the client sees a truncated file rather than a hang. The API's export ends every complete file with a manifest line, so truncation is detectable.
  • fastify: sends the Node stream, and the proxy handler now returns reply so Fastify waits for it. Without that the body was empty, which the new test caught.
  • nextjs: returns new Response(raw.body, { headers }).
  • A raw flag on the route-table entries (fastify, nextjs) and a { raw } option on express's proxyWithIdentity. Only the two download routes set it.

Breaking for custom adapters: ResponseAdapter gains a required sendRaw. Every adapter in this repo implements it. The changeset bumps minor (all packages are pre-1.0).

Also bumps @seamless-auth/types to ^0.27.0 in core and nextjs, which check:types-current requires now that 0.27.0 is published.

Tests

  • core: proxyRequest raw passthrough (body unparsed, headers filtered) and JSON unchanged without raw. applyResult routes raw results to sendRaw and keeps rejections as JSON.
  • Parity (fastify vs express, nextjs vs express): the integrity route in the JSON tables. A new raw suite checks that NDJSON, CSV and a JSON 403 from a download route arrive byte for byte, with matching content type, status and disposition across adapters.
  • Query forwarding (express, fastify): both download routes. The mocks now return a real Response, since raw routes read its headers and body.

pnpm build and pnpm test (core 322, express 192, nextjs 128, fastify 114, all passing), plus pnpm check:types-current. The changed files are Prettier-clean.

Merge order: this can go before or after the API PRs. Until the upstream routes are deployed, the passthroughs answer whatever the API answers, which is a 404.

…downloads

Adds passthroughs for the audit integrity check, the audit event export and
the authentication coverage report. The export and the report answer with
files, so proxied routes can now forward the upstream body and its content
headers unparsed through a new raw mode in core and every adapter.

Refs fells-code/seamless-auth-api#173, #174, #178.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant