Repository navigation
feat(core): acquire license once per app sign-in [APPS-38002] - #799
lucarachiteanu wants to merge 25 commits into
Conversation
This PR changes the public API in a breaking wayExisting consumer code may stop compiling. If that is intended, it needs a release note and a major version bump — not a patch. If it is not, keep the old signature as a deprecated overload. What changed |
|
This comment has been minimized.
This comment has been minimized.
8d9c9f8 to
26c83c3
Compare
This comment has been minimized.
This comment has been minimized.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
0d15d6e to
282b5f3
Compare
This comment has been minimized.
This comment has been minimized.
…ield Co-Authored-By: Claude Opus 5.5 <[email protected]>
This comment has been minimized.
This comment has been minimized.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
…ded function Co-Authored-By: Claude Opus 5.5 <[email protected]>
This comment has been minimized.
This comment has been minimized.
1 similar comment
This comment has been minimized.
This comment has been minimized.
…globals Co-Authored-By: Claude Opus 5.5 <[email protected]>
Co-Authored-By: Claude Opus 5.5 <[email protected]>
This comment has been minimized.
This comment has been minimized.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
This comment has been minimized.
This comment has been minimized.
…s its absence Co-Authored-By: Claude Opus 5.5 <[email protected]>
…ure modes Co-Authored-By: Claude Opus 5.5 <[email protected]>
This comment has been minimized.
This comment has been minimized.
1 similar comment
This comment has been minimized.
This comment has been minimized.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
This comment has been minimized.
This comment has been minimized.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
…sion store is unavailable Co-Authored-By: Claude Opus 5.5 <[email protected]>
This comment has been minimized.
This comment has been minimized.
…s no storage Co-Authored-By: Claude Opus 5.5 <[email protected]>
This comment has been minimized.
This comment has been minimized.
1 similar comment
This comment has been minimized.
This comment has been minimized.
|
Co-Authored-By: Claude Opus 5.5 <[email protected]>
…l site Co-Authored-By: Claude Opus 5.5 <[email protected]>
This comment has been minimized.
This comment has been minimized.
…text Co-Authored-By: Claude Opus 5.5 <[email protected]>
Co-Authored-By: Claude Opus 5.5 <[email protected]>
This comment has been minimized.
This comment has been minimized.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
This comment has been minimized.
This comment has been minimized.
1 similar comment
This comment has been minimized.
This comment has been minimized.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
This comment has been minimized.
This comment has been minimized.
1 similar comment
This comment has been minimized.
This comment has been minimized.
…ed claim until sign-out Co-Authored-By: Claude Opus 5.5 <[email protected]>
This comment has been minimized.
This comment has been minimized.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Co-Authored-By: Claude Opus 5.5 <[email protected]>
This comment has been minimized.
This comment has been minimized.
1 similar comment
|
✅ No issues found. Checked for bugs and CLAUDE.md compliance. |
| new ApiClient(internalConfig, executionContext, tokenManager), | ||
| SessionStore.open() ?? new MemoryStore(), | ||
| ); | ||
| tokenManager.onTokenChange((tokenInfo) => license.onTokenChange(tokenInfo)); |
There was a problem hiding this comment.
Does this mean on every coded app sign in we will make an acquire license call? (at least once)
There was a problem hiding this comment.
Yes, but we try to do it at most once ( exclusing a very basic retry policy, with a timeout that accounts for p99)
There was a problem hiding this comment.
This ties coded apps and SW (coded functions) always. I dont think we should do that. Can we somehow intelligently do it only when Functions is called?
There was a problem hiding this comment.
There are many apps which are just meant to appear as dashboard. In such apps acquiring a license is unnecessary.
There was a problem hiding this comment.
That depends on where the coded app fetches the information from. The AcquireLicense call does reuse a SW endpoint, but its not scoped to it. Moreover, the issue surfaced from calling a trigger that reuses the caller identity. But the path that makes the user run into this issue is much more broad, e.g: any SDK call that starts a job as the signed-in user can hit 1230
I can make the call fire once a function invoke is done, but it should still be tied to a signed in user instance.


The Studio Web license is what provisions a user's personal robot, so it belongs to the user's login, not to one service. Today
Functions.invokeacquires it on every call and fails when it can't — tying licensing to one project type and running it even when the SDK is used inside a coded function.Licensing moves into core as part of the sign-in sequence, for interactive users only: the SDK acquires when it holds no credential of its own — a coded app signing its user in, or one whose host (Action Center, an embedding frame) supplies the user's token. A PAT, client credentials, the environment contract or a coded function's robot token never provision anyone's robot. The claim is written to the session store before the request starts and kept until sign-out, so it runs at most once per user, tenant and session across SDK instances and reloads. Completing the OAuth sign-in waits for it to settle, so an app redirecting right after sign-in cannot cut it short; it never fails sign-in, a failure is logged and not retried, and the server answers for a missing robot.
invokeno longer touches licensing, andFunctions.acquireLicenseand therefreshLicenseoption are removed — the Functions service is@experimental, so this is within its contract. Session storage now goes through oneSessionStorethat never throws; OAuth sign-in still stops before the redirect when it cannot store its PKCE state, as it did when storage threw.🤖 Generated with Claude Code