Repository navigation
Evaluate in the context of the originating page - #11
Merged
Merged
Conversation
Content and queries were evaluated in the context of the request being handled, which is the internal API route rather than the page that originated the fetch, so every evaluation reported `/api/_croct/*` as the page. The composables and the components now report the page they run on: the page being rendered on the server, or the page open in the browser, including its title and time zone. The server composables give the reported context precedence over the one derived from the request, which remains the fallback for direct calls. As a result, the `attributes` of the components now reach the API as part of the context, instead of being dropped as an unknown option.
commit: |
The evaluation context is small enough to be assembled where it is used, so the helpers give way to the object literals they wrapped, leaving a single module for the context reported by the composables. The URI and the referrer of the request are now sanitized as configured, which requires exposing the client options to the server bundle.
The SDK captures the page it runs on and assembles the context, so the module only decides where the page comes from: the request being rendered on the server, or the tab in the browser. The sanitizer moves back out of the middleware, as the context is now sanitized where it is built, keeping the request context untouched.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
evaluate()andfetchContent()builtcontext.pagefrom the URL of the request being handled. For calls coming fromuseContent,useEvaluation,SlotandPersonalization, that request is the internal API route, so every evaluation was contextualized as/api/_croct/*instead of the page. The referrer was wrong in the browser too, as the fetch sends the page itself asReferer.Solution
The page is provided by whoever knows it, and the SDK assembles the context with
EvaluationContext.createPageContext(croct-tech/sdk-js#527, released in@croct/sdk@0.22.3):urlSanitizer.Requests still go through the internal routes with the API key, the server-issued token, the preview token and per-tenant credentials, so nothing changes for applications.
Also fixed
evaluate()discarded acontextprovided by the caller, andfetchContent()dropped the page of the request when the caller provided a partial one.attributesprop ofSlotandPersonalizationwas sent as a top-level option, which the server API ignores, so it never reached the evaluation. It now travels ascontext.attributes.fetchContent()andevaluate()calls in application routes now report a sanitized page.Testing
Unit tests cover the context resolution, the composables and the components. The e2e run against a mock API that echoes the received context, covering server rendering, client navigation, refetching in the browser, and direct calls in application routes.
Mutation testing over the changed code killed all 17 mutants, including spread precedence, environment detection, referrer source, sanitizer and page fallback.
109 unit tests, 60 e2e, 3 prerendering.