@origen-ui/http
v1.1.0
Published
Generic HTTP layer: ApiClient (dedup-cancel / trace-id / retry / 401 silent refresh) + TokenManager
Readme
@origen-ui/http
@origen-ui/http is an Axios-backed transport boundary for applications that need request cancellation, idempotent retries, trace IDs, response protocol adaptation, and refreshable authentication without embedding domain rules in the client.
import {
ApiClient,
createApiEnvelopeAdapter,
createBearerAuthStrategy,
responseDataAdapter,
TokenManager,
} from '@origen-ui/http'
const tokens = new TokenManager({
accessKey: 'admin-access-token',
accessStorage: window.localStorage,
})
const api = new ApiClient({
baseURL: '/api',
responseAdapter: createApiEnvelopeAdapter(),
auth: createBearerAuthStrategy({
tokenManager: tokens,
refresh: async ({ refreshToken, traceId }) => refreshSession({ refreshToken, traceId }),
shouldRefresh: (error) => error.kind === 'business' && error.code === 40101,
onExpired: () => navigateToLogin(),
}),
retry: 1,
})Successful requests resolve to data. Failures reject with ApiError; envelope failures specifically reject with ApiBusinessError and retain the backend code, data, HTTP status, trace ID, and request context.
const users = await api.get<User[]>('/users', {
params: { page: 1, pageSize: 20 },
})
const exportFile = await api.get<Blob>('/users/export', {
responseType: 'blob',
responseAdapter: responseDataAdapter,
})TokenManager defaults to memory. Pass storage explicitly when an application needs tokens to survive reloads. Feature repositories own DTO normalization, pagination parameter mapping, and user-facing business error translation; this package only owns reliable transport behavior. If an injected onError callback fails, ApiClient logs that callback failure and still rejects with the original ApiError.
Token and refresh boundary
ApiClient and TokenManager are application-owned instances; the package
does not install a singleton client or storage policy. Access and refresh
tokens are stored independently only when their corresponding storage options
are supplied. A refresh callback receives the current refresh token, a fresh
trace ID, and the optional CSRF token; it must return a new access token.
Refresh transport and cookie policy remain application concerns.
resolveHeaders resolves per-request defaults before explicit request headers
are applied, so a caller may inject locale or tenant headers without coupling
the client to application state. The HTTP package does not depend on Element
Plus and does not translate transport errors into UI messages.
