colab-client
v0.0.1
Published
Shared browser API client for co:lab UIs — fetch wrapper with JWT storage/expiry, auth-failure redirects, and colab-errors envelope decoding.
Downloads
167
Readme
colab-client
Shared browser API client for UIs. Has a fetch wrapper with JWT storage/expiry, auth-failure redirects, and colab-errors decoding.
How it ships
co:lab UIs serve src/ directly with no build step, so node_modules is never reachable from
a page. colab-client therefore ships as a single classic script (colab-client.js, global:
ColabClient) that consumers vendor into their own src/script/ with a copy step.
Setup
1. Install
npm install --save-dev colab-client2. Vendor the script
Add to the consumer's package.json scripts (postinstall keeps the vendored copy in sync
with the installed version):
"sync-client": "cp node_modules/colab-client/colab-client.js src/script/colab-client.js",
"postinstall": "npm run sync-client"Commit src/script/colab-client.js — local dev serves src/ as-is, so the file must exist
in the tree, and d8e minifies/hashes it on build like any other script.
3. Create the app's client
Load it before the app's own api.js, then build the per-app client there:
<script src="script/colab-client.js"></script>
<script src="script/api.js"></script>const ecvClient = ColabClient.createClient('ecv');Conventions: the API base URL comes from data-api-base on <body>, the JWT is stored
under "<appName>-token", and auth failures redirect to login.html. The methods read
these via this, so the extras object can override apiBase/tokenKey/loginPath in
the rare project that needs to deviate.
What the client owns
request(path, { method, body }) — JSON request with Authorization header, 204 handling,
and colab-errors envelope decoding ({ message } becomes the thrown Error's message).
401/403 responses sent with a token clear it and redirect to loginPath.
getToken() / setToken() / clearToken() / isTokenExpired() — JWT storage; expired
tokens are cleared on read so callers never see one.
fetchBinary(path) / download(path, fallbackFileName) / extractFileName(response) —
auth-aware binary fetching and Content-Disposition-named downloads. Note: reading
Content-Disposition cross-origin requires the API to expose it
(Access-Control-Expose-Headers: Content-Disposition — colab APIs' CORS config does).
App-specific state (session IDs and the like) belongs in the consumer's own api.js,
layered onto the client object — not in this library.
