Skip to content

[sup] ACM-mode transport adapter: cookie auth, JSON-body /query, per-format result unwrap, settings-into-SQL, fake-stream #353

Description

@BorisTyshkevich

Part of #352. Updated for the same-origin / cookie-auth model.

ACM-mode transport behind the injected ctx.fetch, so authedFetch/queryJson/runQuery/loadSchema stay untouched. Pure translation logic in src/core/ at 100%.

Scope

  • Cookie auth, no token. Requests go to /api/cluster/{id}/query with credentials:'same-origin' and no Authorization/X-Auth-Token header.
  • JSON body request: { node, query, ddl, user, password, timeout, swarm } (matches acm-ui's own cluster-explore/query). SQL/creds never in the URL.
  • Settings → in-SQL: rewrite otherwise-dropped query-string settings into an appended SETTINGS <k=v,…> clause; then FORMAT <fmt>. ⚠️ SQL-tail rewriter must handle existing FORMAT/SETTINGS, trailing ;, comments — its own pure module + tests.
  • Response unwrap: parse the per-node array → select the target node → on meta.error, synthesize a non-ok Response carrying the CH error text (so parseExceptionText works); else wrap result as raw text for the requested format (do NOT blindly JSON.parse — TSV/CSV/raw and empty effect-statement bodies must pass through).
  • Fake progress-stream: for Table/KPI/Filter, emit the buffered rows as synthetic progress lines so runQuery's reader loop + grids work unchanged.
  • Explicit node required on every query (LB nondeterminism verified).

Removed vs. original

  • Map AUTHENTICATION_FAILED → synthetic 401 to reuse refresh(). The ACM session is browser-managed (cookie); a real session expiry is a normal login redirect. Only the temp CH password is ours to re-mint (see [sup] ACM cookie-auth session: URL cluster/node context + temp-credential lifecycle #354) — via an explicit single-flight remint on a CH-auth error, not by sniffing error text into the shared authedFetch refresh path (which latches authConfirmed after first success anyway).

Acceptance

  • Injected fetch; no changes to authedFetch/queryJson/runQuery.
  • Cookie auth; nothing in the URL; JSON body.
  • Settings effective via in-SQL SETTINGS; SQL-tail rewriter unit-tested on FORMAT/SETTINGS/;/comment edge cases.
  • result wrapped per-format; empty bodies + error envelopes handled.
  • Grids render via the fake stream unchanged; explicit node targeting.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestsupAltinity support-team build variant (dist/sql-sup.html)

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions