Repository navigation
feat(proxy): pass audit and coverage report routes through, with raw downloads - #191
Merged
Merged
Conversation
…downloads Adds passthroughs for the audit integrity check, the audit event export and the authentication coverage report. The export and the report answer with files, so proxied routes can now forward the upstream body and its content headers unparsed through a new raw mode in core and every adapter. Refs fells-code/seamless-auth-api#173, #174, #178.
This was referenced Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Passthroughs for three new auth API admin routes, all on the caller's access identity, with their queries forwarded:
GET /admin/auth-events/integrityGET /admin/auth-events/exportGET /admin/reports/authentication-coverageformat=csv/admin/reportsis added to theensureCookiesrequirement map./admin/auth-eventsalready covers the new sub-paths by prefix.Raw passthrough
proxyRequestalways parsed the upstream body as JSON. The tolerant parser turns a CSV or NDJSON body into{ message: "<text>" }, and the adapter then dropsContent-TypeandContent-Disposition, so a download would arrive as a JSON blob. This adds a raw mode:proxyRequest({ ..., raw: true })returnsraw: { headers, body }.bodyis the upstream stream, andheadersholds onlycontent-type,content-dispositionandcache-control.applyResulthands that to a new requiredResponseAdapter.sendRaw(status, raw). The adapter's own rejections (no session, for example) still go out as JSON.Readable.fromWeb(...).pipe(res). An upstream failure partway through destroys the connection, so the client sees a truncated file rather than a hang. The API's export ends every complete file with a manifest line, so truncation is detectable.replyso Fastify waits for it. Without that the body was empty, which the new test caught.new Response(raw.body, { headers }).rawflag on the route-table entries (fastify, nextjs) and a{ raw }option on express'sproxyWithIdentity. Only the two download routes set it.Breaking for custom adapters:
ResponseAdaptergains a requiredsendRaw. Every adapter in this repo implements it. The changeset bumps minor (all packages are pre-1.0).Also bumps
@seamless-auth/typesto^0.27.0in core and nextjs, whichcheck:types-currentrequires now that 0.27.0 is published.Tests
proxyRequestraw passthrough (body unparsed, headers filtered) and JSON unchanged withoutraw.applyResultroutes raw results tosendRawand keeps rejections as JSON.Response, since raw routes read its headers and body.pnpm buildandpnpm test(core 322, express 192, nextjs 128, fastify 114, all passing), pluspnpm check:types-current. The changed files are Prettier-clean.Merge order: this can go before or after the API PRs. Until the upstream routes are deployed, the passthroughs answer whatever the API answers, which is a 404.