Repository navigation
feat: SDK update for version 28.0.0 - #136
Conversation
|
| "<ID_TOKEN>", // idToken | ||
| "<NONCE>", // nonce (optional) | ||
| "<ACCESS_TOKEN>", // accessToken (optional) | ||
| 0, // accessTokenExpiry (optional) |
There was a problem hiding this comment.
Broken native sign-in example The Java sample passes
0 for accessTokenExpiry, but the method expects a boxed Long, so the sample does not compile. Changing it to 0L alone would make the example’s access token immediately expired; the Kotlin sample also supplies zero seconds. Omit the optional expiry or use the provider-reported lifetime.
Prompt To Fix With AI
This is a comment left during a code review.
Path: docs/examples/java/account/create-id-token-session.md
Line: 20
Comment:
**Broken native sign-in example** The Java sample passes `0` for `accessTokenExpiry`, but the method expects a boxed `Long`, so the sample does not compile. Changing it to `0L` alone would make the example’s access token immediately expired; the Kotlin sample also supplies zero seconds. Omit the optional expiry or use the provider-reported lifetime.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| return; | ||
| } | ||
|
|
||
| Log.d("Appwrite", result.toString()); |
There was a problem hiding this comment.
Session credentials logged If a developer supplies the access token shown in this example, logging the full returned
Session can write that credential to Android logs. Log a non-sensitive field such as the session ID instead.
How this was verified: The method accepts an access token to store on the session, and Session.toString() includes its providerAccessToken field before this example passes it to Log.d.
| Log.d("Appwrite", result.toString()); | |
| Log.d("Appwrite", result.getId()); |
Prompt To Fix With AI
This is a comment left during a code review.
Path: docs/examples/java/account/create-id-token-session.md
Line: 28
Comment:
**Session credentials logged** If a developer supplies the access token shown in this example, logging the full returned `Session` can write that credential to Android logs. Log a non-sensitive field such as the session ID instead.
**How this was verified:** The method accepts an access token to store on the session, and `Session.toString()` includes its `providerAccessToken` field before this example passes it to `Log.d`.
```suggestion
Log.d("Appwrite", result.getId());
```
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| "provider" to provider, | ||
| "idToken" to idToken, | ||
| "nonce" to nonce, | ||
| "accessToken" to accessToken, | ||
| "accessTokenExpiry" to accessTokenExpiry, | ||
| "name" to name, |
There was a problem hiding this comment.
Untested authentication flows The new native sign-in and OTP methods have no behavioral HTTP tests. Existing tests cover JSON encoding and Java client setters, but do not exercise these methods’ requests or decoded responses, so authentication regressions could go unnoticed. Add tests of observable requests and results rather than assertions that mirror generated source or version strings.
Prompt To Fix With AI
This is a comment left during a code review.
Path: library/src/main/java/io/appwrite/services/Account.kt
Line: 1693-1698
Comment:
**Untested authentication flows** The new native sign-in and OTP methods have no behavioral HTTP tests. Existing tests cover JSON encoding and Java client setters, but do not exercise these methods’ requests or decoded responses, so authentication regressions could go unnoticed. Add tests of observable requests and results rather than assertions that mirror generated source or version strings.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
This PR contains updates to the SDK for version 28.0.0.
What's Changed
Account.listLogsand theLog,LogListmodelsClient.setDevKeyx-appwrite-response-format: 2.3.0)Account.createIdTokenSessionfor native Apple and Google sign-in withIdTokenProviderenumAccount.createRecoveryOTPandAccount.updateRecoveryOTPfor code-based password recoveryAccount.createEmailVerificationOTPandAccount.updateEmailVerificationOTPKAKAOandTIKTOKvalues toOAuthProviderpasswordPwnedfield onUserandproviderIdTokenfield onIdentity