acai-demo-sdk
v0.4.1
Published
Shared Try Demo feature package — session-end redirect claim, expiry polling, persona switching against auth-sso-server's /demo/* endpoints, and the DemoModeBar UI itself. Each consuming app supplies its own cookie adapter and post-switch navigation inste
Readme
acai-demo-sdk
Shared Try Demo feature package: session-end redirect claim, expiry polling,
persona switching against auth-sso-server's /demo/* endpoints, and the
DemoModeBar UI. Each consuming app supplies its own cookie adapter and
post-switch navigation.
Also carries the backend clone/teardown contract types
(acai-demo-sdk/contracts) — type-only, no React dependency, safe to import
from a NestJS backend.
0.3.0 (breaking for 0.x consumers)
- The demo JWT now lives in its own cookie,
demo_accessToken(DEMO_ACCESS_TOKEN_COOKIE), never the real-loginaccessToken. Write/clear it only through this package (writeDemoCookie,clearDemoState,endDemoSessionRedirect); read the token an API client should send withgetActiveAccessToken()(demo first, then real). Proxies/middleware usepickAccessToken()fromacai-demo-sdk/middleware-token. POST /demo/startreturns apollToken; everyGET /demo/status/:idsends it asx-demo-poll-token. It lives in sessionStorage only and reaches/demo-entryin the URL fragment (consumeDemoEntryFragment()).useDemoSessionkeeps callbacks in refs, applies a server-time offset, re-confirms expiry against/status(the server is the authority), backs off on 429/5xx (reconnecting), and exposesisSwitching/reconnecting/error.DemoModeBartakesswitching/reconnecting.acai-demo-sdk/env:assertProductionUrl()fornext.configso a production build never ships a localhost SSO URL.
