@or-sdk/base
v0.45.2
Published
Shared HTTP client for OneReach SDK packages
Readme
@or-sdk/base
Shared HTTP transport for OneReach SDK packages. It has no SERVICE_KEY; subclasses provide the service key and API methods.
When to use
- Extend
Basewhen building an@or-sdk/*client for a OneReach service.
When not to use
- For application calls to an existing service, use that service's dedicated SDK instead of extending
Base.
Installation
npm install @or-sdk/baseUsage
Provide a token string or getter and a direct service URL when known. Use a discovery URL only when the service URL must be resolved.
import { Base } from '@or-sdk/base';
class ExampleClient extends Base {
constructor(token: string, serviceUrl: string) {
super({ token, serviceUrl, serviceKey: 'example' });
}
getItems() {
return this.callApiV2({ route: '/items', method: 'GET' });
}
}
const client = new ExampleClient(token, 'https://example.onereach.ai');
await client.getItems();Alternatively, pass discoveryUrl in place of serviceUrl to resolve the service on first request.
Critical pitfalls
- In Node.js, redirects are followed only to HTTPS on the exact same hostname, with a limit of five hops. HTTP-to-HTTPS upgrades and same-host HTTPS redirects work; HTTP targets, other hostnames, and URLs containing credentials are rejected. A rejected redirect fails the request. Resolve the correct service URL rather than relying on cross-host redirects.
- An HTTP starting URL still sends the first request, including its Authorization header, over plaintext before the upgrade. Use an HTTPS starting URL for token-bearing requests.
- This transport rule applies to requests made through
Base. A subclass that uses another HTTP client must enforce its own redirect policy.
Method map
| Method | Purpose |
|--------|---------|
| init() | Resolve and prepare the service URL. |
| callApiV2(params) | Send an authenticated request from a subclass. |
| callApi(params) | Legacy authenticated request method; deprecated. |
See src/Base.ts and src/types.ts for the complete protected API and configuration types.
Auth
token is a string or getter returning the Authorization header value. Treat service URLs and discovery responses as security-sensitive because the SDK sends this token to the resolved destination.
