Skip to content

feat: SDK update for version 1.1.0 - #118

Merged
ChiragAgg5k merged 12 commits into
mainfrom
dev
Sep 24, 2026
Merged

ChiragAgg5k merged 12 commits into
mainfrom
dev

Conversation

@ChiragAgg5k

@ChiragAgg5k ChiragAgg5k commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

This PR contains updates to the SDK for version 1.1.0.

What's Changed

  • Added: Account.createRecoveryOTP and Account.updateRecoveryOTP for code-based password recovery
  • Updated: SDK now targets Appwrite 2.3 (X-Appwrite-Response-Format: 2.3.0)
  • Updated: requests always send credentials now that dev keys are no longer supported

@ChiragAgg5k ChiragAgg5k changed the title feat: React Native SDK update for version 1.1.0 feat: SDK update for version 1.1.0 Sep 24, 2026
@greptile-apps

greptile-apps Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

The PR appears safe to merge, with non-blocking test coverage needed for the new recovery flow.

Fix All in Claude CodeFindings

  1. P1 Uploads depend on atob ▶
  2. P2 Recovery flow lacks tests ▶
  3. P2 Apple nonce marked optional ▶
  4. P2 Upload behavior lacks coverage ▶
Fix with agent prompt
### Issue 1
src/service.ts:undefined-43
If a React Native runtime does not provide a global `atob`, Expo fetch's call to the new file part's `bytes()` method throws here before the request is sent. This affects both small files and chunked uploads. Decode the base64 data without relying on that browser global.

### Issue 2
src/services/account.ts:2418-2439
The new OTP initiation and completion requests have no observable-behavior tests. A regression in either step could go unnoticed until a user cannot reset their password. Please test successful recovery and rejected or expired codes through the SDK, rather than asserting that source code, headers, or version strings match fixed values.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

### Issue 3
docs/examples/account/create-id-token-session.md:undefined-13
This example selects Apple, but the new API documentation says Apple sign-in requires a raw nonce. A developer who follows the optional label and omits it will have the ID token rejected.

```suggestion
    nonce: '<NONCE>',
```

### Issue 4
src/services/storage.ts:290-299
The new file-part path changes how both small files and upload chunks reach fetch, but there is no observable upload regression coverage. Add behavior-level checks for a small file and a multi-chunk file through the supported fetch paths. Tests that only mirror `FilePart` or its configuration would not show whether the correct bytes reach the request.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

The PR updates the SDK’s declared Appwrite compatibility to 2.3, adds password-recovery OTP methods and examples, and removes the obsolete dev-key exception to credentialed requests.

  • The new recovery flow would benefit from observable-behavior coverage.

Reviews (1) · Last reviewed commit: "chore: merge main into dev for the 1.1.0..."

Comment thread src/service.ts
}

static decodeBase64(data: string): Uint8Array {
const binary = atob(data);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Uploads depend on atob If a React Native runtime does not provide a global atob, Expo fetch's call to the new file part's bytes() method throws here before the request is sent. This affects both small files and chunked uploads. Decode the base64 data without relying on that browser global.

Prompt To Fix With AI
This is a comment left during a code review.
Path: src/service.ts
Line: 43

Comment:
**Uploads depend on atob** If a React Native runtime does not provide a global `atob`, Expo fetch's call to the new file part's `bytes()` method throws here before the request is sent. This affects both small files and chunked uploads. Decode the base64 data without relying on that browser global.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Claude Code Fix in Codex

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not introduced here: src/service.ts is not in this PR's diff. decodeBase64 and its atob call shipped in 1.0.0 (#117); this comment was made against a commit from before main was merged into dev. Hermes has provided a global atob since React Native 0.74, and this package requires react-native >=0.76.7, where Hermes is the default engine.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You’re right on both points: src/service.ts is not part of PR #118, so this is an inherited issue from #117 rather than a regression introduced here. Given this package’s react-native >=0.76.7 peer requirement and Hermes providing atob in the supported runtime, the concern is not actionable for this PR. I’ll withdraw the comment.

const result = await account.createIdTokenSession({
provider: IdTokenProvider.Apple,
idToken: '<ID_TOKEN>',
nonce: '<NONCE>', // optional

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Apple nonce marked optional This example selects Apple, but the new API documentation says Apple sign-in requires a raw nonce. A developer who follows the optional label and omits it will have the ID token rejected.

Suggested change
nonce: '<NONCE>', // optional
nonce: '<NONCE>',
Prompt To Fix With AI
This is a comment left during a code review.
Path: docs/examples/account/create-id-token-session.md
Line: 13

Comment:
**Apple nonce marked optional** This example selects Apple, but the new API documentation says Apple sign-in requires a raw nonce. A developer who follows the optional label and omits it will have the ID token rejected.

```suggestion
    nonce: '<NONCE>',
```

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Claude Code Fix in Codex

Comment thread src/services/storage.ts
Comment on lines 290 to +299
if (size <= Service.CHUNK_SIZE) {
payload['file'] = Service.filePart(
file.uri,
file.name,
file.type,
() =>
FileSystem.readAsStringAsync(file.uri, {
encoding: FileSystem.EncodingType.Base64,
}),
);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Upload behavior lacks coverage The new file-part path changes how both small files and upload chunks reach fetch, but there is no observable upload regression coverage. Add behavior-level checks for a small file and a multi-chunk file through the supported fetch paths. Tests that only mirror FilePart or its configuration would not show whether the correct bytes reach the request.

Prompt To Fix With AI
This is a comment left during a code review.
Path: src/services/storage.ts
Line: 290-299

Comment:
**Upload behavior lacks coverage** The new file-part path changes how both small files and upload chunks reach fetch, but there is no observable upload regression coverage. Add behavior-level checks for a small file and a multi-chunk file through the supported fetch paths. Tests that only mirror `FilePart` or its configuration would not show whether the correct bytes reach the request.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

Fix in Claude Code Fix in Codex

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not in this release: src/services/storage.ts is not in this PR's diff. The file-part upload path shipped in 1.0.0 (#117); this comment was made against a commit from before main was merged into dev.

Comment thread src/services/account.ts
Comment on lines +2418 to +2439
const apiPath = '/account/recovery/otp';
const payload: Payload = {};

if (typeof email !== 'undefined') {
payload['email'] = email;
}

if (typeof phrase !== 'undefined') {
payload['phrase'] = phrase;
}

const uri = new URL(this.client.config.endpoint + apiPath);
return this.client.call(
'post',
uri,
{
'X-Appwrite-Project': this.client.config.project,
'content-type': 'application/json',
accept: 'application/json',
},
payload,
);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Recovery flow lacks tests

The new OTP initiation and completion requests have no observable-behavior tests. A regression in either step could go unnoticed until a user cannot reset their password. Please test successful recovery and rejected or expired codes through the SDK, rather than asserting that source code, headers, or version strings match fixed values.

Prompt To Fix With AI
This is a comment left during a code review.
Path: src/services/account.ts
Line: 2418-2439

Comment:
**Recovery flow lacks tests**

The new OTP initiation and completion requests have no observable-behavior tests. A regression in either step could go unnoticed until a user cannot reset their password. Please test successful recovery and rejected or expired codes through the SDK, rather than asserting that source code, headers, or version strings match fixed values.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

Fix in Claude Code Fix in Codex

@ChiragAgg5k
ChiragAgg5k merged commit bda9bc1 into main Sep 24, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants