Commit Graph

167 Commits

Author SHA1 Message Date
github-actions[bot] 1ac83900c8 Version Packages (#357)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-04-03 14:32:42 +03:00
Dominik Ferber c08f3e5614 [flags/next] perf improvements (#356)
* [flags] avoid re-imports

Avoid re-importing next/headers since it adds unnecessary microtask queue overhead

* [flags] avoid iife microtask queue overhead

* [flags] skip awaits where possible

* add undefined to headersModulePromise type
2026-04-03 11:24:31 +00:00
Dominik Ferber 9142790975 only build publishable packages during release process (#348)
* clean up

* fix release process
2026-03-21 21:17:04 +02:00
github-actions[bot] 14ef3fa940 Version Packages (#346)
* Version Packages

* blank commit

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Swarnava Sengupta <swarnava.sengupta@vercel.com>
2026-03-21 23:38:24 +05:30
Swarnava Sengupta b755ffecdf fix: SDK key detection to avoid false positives with third-party identifiers (#345)
The SDK key validation now uses a regex (/^vf_(?:server|client)_/) to require
the format vf_server_* or vf_client_* instead of accepting any string starting
with vf_. This prevents false positives with third-party service identifiers
that happen to start with vf_ (e.g., Stripe identity flow IDs like
vf_1PyHgVLpWuMxVFx...).

Adds isValidSdkKey() helper function and updates parseSdkKeyFromFlagsConnectionString()
to use the stricter validation. Updates all tests to use valid SDK key formats.
2026-03-21 17:39:00 +00:00
github-actions[bot] 471e0048b6 Version Packages (#342)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-20 21:19:04 +02:00
Dominik Ferber 44460570d4 [vercel/flags-core] allow json flags (#335)
* rm unused import

* [vercel-flags] allow json flags

* add flags-playground

* wip

* clean up type

* reword changeset

* rm examples/flags-playground
2026-03-20 14:03:53 +02:00
github-actions[bot] a3b536b504 Version Packages (#340)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-19 16:21:12 +02:00
Dominik Ferber b81963dc14 fix (#339) 2026-03-19 16:18:59 +02:00
github-actions[bot] b199f2083c Version Packages (#333)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-18 15:50:13 +02:00
Dominik Ferber 64619d7c66 @vercel/flags-core: allow specifying entities type when creating clients (#334)
* changeset

* adapt
2026-03-13 11:09:21 +02:00
Dominik Ferber 4a5f56a8c7 skip sending config reads (#330)
* skip sending config read for dev and custom envs

* add changeset

* clean up

* wip
2026-03-13 08:16:47 +01:00
github-actions[bot] 0af37593bd Version Packages (#331)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-12 21:53:04 +02:00
Dominik Ferber c9934fda03 [@vercel/flags-core] drop dependency on flags pkg (#332) 2026-03-12 21:24:11 +02:00
nadav dd1396e461 Guard missing Vercel Flags runtime helpers (#326)
* Guard request-context flag reporting

* Preserve request-context hook binding

* Guard core request-context reporting

* Guard missing bundled flag definitions

---------

Co-authored-by: Dominik Ferber <dominik.ferber@gmail.com>
2026-03-12 16:38:18 +02:00
github-actions[bot] e44eedf0cf Version Packages (#315)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-09 19:08:17 +02:00
Dominik Ferber df427e0e7a use catalog for react & react-dom (#318)
* use catalog for react & react-dom

this guarantees the same version for all packages and thus avoids type errors

* update lockfile
2026-03-09 19:01:30 +02:00
Dominik Ferber e5f3e34428 [docs] depend on workspace version of flags (#314)
* fix dep

* add packageManager

* move devDeps to top-level
2026-03-09 18:26:11 +02:00
Dominik Ferber 77727aaade use __no_flags__ to handle precompute with empty flags (#300)
* use __no_flags__ to handle precompute with empty flags

* handle __no_flags__ in serialize

* add __no_flags__ handling to sveltekit

* avoid returning undefined when defaultValue is set

This could only happen on precomputed flags in case of bad usage.

* add error messages

* test console logs

* update changeset
2026-03-09 15:10:47 +00:00
Dominik Ferber 2db1530275 Upgrade dependencies (#313)
* upgrade

* update biome

* upgrade more
2026-03-09 12:24:42 +00:00
github-actions[bot] 783b9efdda Version Packages (#312)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-09 12:29:55 +01:00
Luis Meyer 10c10b6aa4 Return meaningful result from prepareFlagsDefinitions (#311)
* Return meaningful result from prepareFlagsDefinitions

- Add PrepareFlagsDefinitionsResult discriminated union type that indicates whether definitions were created
- Change prepareFlagsDefinitions return type from Promise<void> to Promise<PrepareFlagsDefinitionsResult>
- Return { created: false, reason: 'no-sdk-keys' } when no SDK keys are found
- Return { created: true, sdkKeysCount: N } when definitions are successfully created
- Add tests for both return paths to verify the function communicates its result properly

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Add changeset for prepareFlagsDefinitions result type

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>
2026-03-09 12:25:55 +01:00
Dominik Ferber 05a5ebfda1 Add userAgentSuffix to prepare-flags-definitions (#306)
* Replace version param with userAgentSuffix in prepare-flags-definitions

Changed the API to use a cleaner approach:
- Removed `version?: string` option in favor of `userAgentSuffix?: string`
- Now imports package version directly from package.json
- Constructs user-agent as: `@vercel/prepare-flags-definitions/{pkgVersion} {suffix}`
- Allows consumers (e.g., vercel-cli, vercel-api) to add context to the header

Added tests verifying both default and suffixed user-agent headers.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* add changeset

---------

Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>
2026-03-09 11:18:51 +00:00
Dominik Ferber e8539cd52a make version dynamic in tests (#304) 2026-03-06 12:02:03 +00:00
github-actions[bot] c1fbe2f19d Version Packages (#284)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-06 13:57:18 +02:00
Dominik Ferber 3f3ec2bbe2 Revert "fix main export (#302)" (#303)
This reverts commit 62afa7f64e.
2026-03-06 10:13:44 +00:00
Dominik Ferber 62afa7f64e fix main export (#302) 2026-03-06 09:42:16 +00:00
Luis Meyer 96ba1226c8 Extract @vercel/prepare-flags-definitions package (#301)
* Extract @vercel/prepare-flags-definitions package

Extract the core flag definitions preparation logic from the Vercel CLI into a standalone, reusable package. This includes:
- prepareFlagsDefinitions() function that collects SDK keys from env, fetches definitions, and writes to node_modules
- hashSdkKey() helper for SHA-256 hashing
- generateDefinitionsModule() for JS module generation with deduplication and lazy parsing

Follows repo conventions: pnpm workspaces, tsup, vitest, ES modules with CJS fallback.

* Add JSDoc comments from original CLI source

* Add inline comments from original CLI source

* Add optional output parameter with debug logging

* Add output.time for datafile fetching

* Add changeset for @vercel/prepare-flags-definitions
2026-03-06 10:10:01 +01:00
Dominik Ferber b70c2ea466 Control (#278)
* refactor

* remove retries

* simplify

* simplify options

* before

* rename DataSource to Controller

* refactor and better tests

* avoid double polling

* rename

* fix

* simplify test setup

* wip

* unify

* wip

* only track 1 read per build

* make BundledSource lazy

* clean up fallback behavior

* add mode

* mutually exclusive streaming & polling

* rely more on black box testing

* simplify

* Update CLAUDE.md

* various fixes

* add tests

* more fixes

* Update CLAUDE.md

* more fixes

* resolve more issues

* unite black box tests

* tests

* progress

* adjust

* don't report on 401s; use Response.json

* enforce min polling interval

* progress

* types

* capture all logs

* throw with prefix

* added a minimum gap of `BASE_DELAY_MS` (1 second) between connection
 attempts

* step

* progress

* use request context in tests

* add separate tests depending on context

* tests

* rm unused option

* add state machine chart

* rm sources

* use fake timers for more tests

* swap remaining tests from msw to mocked fetch

* update comments

* Update CLAUDE.md

* update comment

* fix comment

* fix types

* rm peek

* adds ping checks and sending x-revision header  (#282)

* abort on missed pings

* use revision from bundled definitions

* tests

* simplify

* send x-revsion on reconnects too

* simplify StreamSource

* rename

* rename in test

* wait for stream

* replace startBackgroundUpdates with explicit call

* Update CLAUDE.md

* restore stronger tests

* Update CLAUDE.md

* convert

* simplify tests

* fix test

* fixes

* rm state machine

* await first poll before resoliving init

* rm outdated comment

* avoid leaking _origin

* changeset

* avoid log on reconnect due to missed pings

* don't warn on missed pings

* Update event reporting for control rewrite (#289)

* Update event reporting for control rewrite

* Log ingest response

* Use string for revision

* Add retries when ingesting events

* adapt changeset

* adjust test

---------

Co-authored-by: Luis Meyer <luis.meyer@vercel.com>
Co-authored-by: Andy <AndyBitz@users.noreply.github.com>
Co-authored-by: Andy Bitz <artzbitz@gmail.com>
2026-03-06 10:05:01 +02:00
Vincent Derks 722b0d054e Added new comparators: (not_)contains and case-insensitive versions (#288)
* Added new comparators: (not_)contains and case-insensitive versions

* Switched to "ci" option instead of creating new condition for every ci-case

* Cleanup

* More cleanup

* Some more cleanup & finetuning

Made-with: Cursor

* Changeset

* Switch options key to just "i" and also allow for passing "i" as string instead of options object

* Apply suggestions from code review

* Update packages/vercel-flags-core/src/evaluate.ts

Co-authored-by: Dominik Ferber <dominik.ferber@gmail.com>

* naming

* Renaming

---------

Co-authored-by: Dominik Ferber <dominik.ferber@gmail.com>
2026-03-06 07:52:32 +02:00
Vincent Derks 689b1575f6 Flags core as normal dep (#298)
* Changed @vercel/flags-core to dependency from peerDependency

* Updated docs and skills

* More explanation

* Updated skill with singleton explanation and example

* update README

* FLAGS_SDK_KEY → FLAGS

* update skill

* update changeset

---------

Co-authored-by: Dominik Ferber <dominik.ferber@gmail.com>
2026-03-05 12:53:04 +01:00
Vincent Derks a924044282 Fixed bug with inverted NOT_ONE_OF segment comparator (#296)
* Fixed bug with inverted NOT_ONE_OF segment comparator

* Feedback

* Changeset

* Updated unit-test
2026-03-05 10:52:50 +01:00
Luis Meyer 823bf786c1 Add CJS support for @vercel/flags-core (#283)
* Add CJS support for @vercel/flags-core

Update tsup config to build both ESM and CJS formats, and update package.json exports to use import/require conditions with separate entry points for CommonJS consumers.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* changeset

---------

Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>
2026-02-24 17:13:52 +01:00
github-actions[bot] fa58c6900d Version Packages (#275)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-02-13 15:19:35 +02:00
Dominik Ferber 7d7719a255 [@vercel/flags-core] deduplicate concurrent initialize() calls (#274)
* add shop

* wip

* fix parallel init initialize

* avoid double polling

* add tests

* rm shirt-shop-vercel

* ignore

* refactor

* rm unnecessary fix

* minimal

* changeset

* fix tests
2026-02-13 14:34:46 +02:00
Hayden Bleasel cf9ccd0076 Open Source Docs (#272)
* Scaffold Geistdocs instance

* Update biome.json

* Replace content

* Re-path docs

* Update docs package name

* Misc fixes

* Update geistdocs.tsx

* Move content to correct folder

* Start migrating custom components

* Finish migrating custom components

* Migrate existing redirects

* Remove #next suffixes from code blocks

* Migrate homepage and flags

* Remove duplicate lockfiles

* Start fixing homepage

* Replace Geist components

* Fix colors

* Improve layout

* Fix code blocks

* Fix hero

* Fix illustrations

* Fix redirect

* Fix nav links

* Patch in FrameworkSwitcher

* Bump Next.js in docs

* Delete turbo.json

* Misc fixes

* More logo fixes
2026-02-13 09:06:03 +02:00
github-actions[bot] 47806d4f89 Version Packages (#260)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-02-11 15:55:44 +02:00
Dominik Ferber 2bfaada64c Revert "add primed stream message support (#263)" (#270)
This reverts commit 8ae9101ba9.
2026-02-11 15:40:45 +02:00
Dominik Ferber c71729b37f add READMEs and changesets (#265)
* add READMEs

* add changesets
2026-02-11 15:23:22 +02:00
Dominik Ferber f14aea8e73 respect hashed keys (#267)
* respect hashed keys

* use cache for pending promises

* refactor

* add try/catch

* typo
2026-02-11 15:22:07 +02:00
Luis Meyer 8ae9101ba9 add primed stream message support (#263)
* add primed stream message support

Implements client-side support for version-based caching. When the client
already has the current datafile (indicated by revision), the server can
send a lightweight primed message instead of the full datafile, reducing
bandwidth. Tracks revision from datafile and sends X-Revision header on
reconnections.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* use getRevision getter for single source of truth and fix type errors

Refactors StreamConfig.revision to a getRevision getter function so
connectStream always reads the latest revision from client state instead
of tracking a separate copy. Fixes CI type-check errors in tests.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>
2026-02-11 12:51:54 +01:00
Andy 84714c3b91 [vercel-flags-core] Forward configUpdatedAt timestamp correctly (#266) 2026-02-11 12:50:07 +01:00
Luis Meyer 5e2d095863 Suppress stream abort error on intentional shutdown (#264)
When shutdown() is called on a client using FlagNetworkDataSource, the stream abort error is expected and should not be logged. The break statement still exits the loop properly.

Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>
2026-02-11 12:45:42 +01:00
Dominik Ferber d44a9229e3 pass default openfeature client (#261) 2026-02-11 12:52:29 +02:00
Luis Meyer be1a323486 Add custom fetch option to flags client (#262)
* Add custom fetch option to flags client

Allow passing a custom fetch function to createClient() for testing purposes (e.g. resolving to a different IP). Threads fetch through FlagNetworkDataSource, fetchDatafile(), and connectStream().

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* changeset

---------

Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>
2026-02-10 09:50:40 +01:00
Dominik Ferber 795dfd46a1 throw on declaration if flag is missing decide function (#259) 2026-02-09 13:28:41 +02:00
Dominik Ferber d8c366c484 avoid replacing datafiles with older ones (#257)
* avoid replacing datafiles with older ones

* fix types

* fix types

* fix test
2026-02-09 12:39:42 +02:00
Dominik Ferber 19d6ad394a export FallbackEntryNotFoundError and FallbackNotFoundError (#256) 2026-02-09 11:48:11 +02:00
Dominik Ferber 53149f5e81 add client (#255)
* prepare

* origin

* prepare script

* step

* redo peer deps

* wip

* continue

* every 5 secs

* connect flag network

* add shirt-shop-vercel

* upgrade

* push

* update endpoint

* add vercel getProviderData

* fix importts

* Add retries to flag network datasource (#237)

* Fix React Server Components CVE vulnerabilities (#235)

Updated dependencies to fix Next.js and React CVE vulnerabilities.

The fix-react2shell-next tool automatically updated the following packages to their secure versions:
- next
- react-server-dom-webpack
- react-server-dom-parcel  
- react-server-dom-turbopack

All package.json files have been scanned and vulnerable versions have been patched to the correct fixed versions based on the official React advisory.

Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>

* Add retries to flag network datasource when stream closes

Implements automatic retry logic with exponential backoff when the flag network
stream unexpectedly closes. The stream will retry with delays increasing from
1s to a maximum of 30s, allowing the datasource to recover from temporary
network issues while falling back to bundled definitions if initial connection
fails.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* Revert package.json and pnpm-lock changes

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

---------

Co-authored-by: vercel[bot] <35613825+vercel[bot]@users.noreply.github.com>
Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>
Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>

* use ndjson (#238)

* try

* try

* use debugLog

* replace testkey

* never retry on 4xx

* Track FLAG_CONFIG_READ events

* update @biomejs/biome

* send user-agent, rm terminate handling, fix tests

* extract usage-tracker and add tests

* rm EdgeConfigDataSource

* export EvaluationParams and EvaluationResult

* drop edge-config dep

* drop edge config from @flags-sdk/vercel

* adapt @flags-sdk/vercel

* fix integration tests

* wip

* assert ingest requests

* race initial connection, retry in background, abort on shutdown

* rm store

* make readBundledDefinitions async

* read from @vercel/flags-definitions/definitions.json

* add ensureFallback fn

* getDefaultFlagsClient() → flagsClient

* rm process.pid

* rm webpackIgnore: true

* require fallbacks at build time on vercel only

* test in layout

* vercel-flags prepare --verbose

* rm prebuild script

* ensure fallback from instrumentation.ts

* rm last process.pid

* print warning

* Track duration and cache status for config reads

* add tests

* await stream in initialize method

* consumeStream → runStreamLoop

* replace subscribe with doInitialize

* add webpackIgnore

* make @vercel/flags-core a peer dep

* fresh start

* debug

* step

* next-connection

* avoid opening stream during builds

* undo next specific exports

* handle abort

* fake

* poc

* clean up imports

* next-js exports

* upgrade next

* move "use cache" up

* move "use cache" handling to client

* split index.default.ts and index.next-js.ts

* separate

* jsdoc

* use scoped map instead of passing ref

* move jsdoc

* rename

* keep dataSource private, clean clientMap

* reset retryCount on connection; abort on 401

* break after 10 retries

* add backoff with jitter + limit

* add usage tracking and read fallback

* refactor

* extract stream-connection, update tests

* add tests

* reduce test amount

* add perf metadata

* add BaseEvaluationResult

* getData → read

* rm shirt-shop-vercel

* drop next-connection

* update pnpm-lock

* getMetadata → getInfo

* add getDatafile

* DataSourceData → Datafile

* merge metrics into datafile

* simplify metrics

* use embed for getDatafile

* add comment

* comment

* bring shirt-shop-vercel back

* try setCacheLife

* support cache components in OpenFeature import

* use new format

* rm cli

* fix origin

* use bundler

* simplify

* ensure warning is highlighted in build logs

* warn only once

* ensureFallback → getFallbackDatafile

* improve perf

* avoid creating new objects

* fix type issues

* stop exposing createRawClient

* fix: mark stream reconnection loop as intentional fire-and-forget

Add void operator before async IIFE to explicitly indicate the floating
promise is intentional, preventing linter warnings and making the code
intent clearer to future maintainers.

* fix: handle malformed JSON in stream messages gracefully

Wrap JSON.parse in try/catch to prevent crashes from malformed server
responses. Logs a warning and skips the invalid message instead of
crashing the stream connection handler.

* fix: add bounds checking for variant index access

Add getVariant() helper that throws a descriptive error if the variant
index is out of bounds. This prevents silent undefined returns when
variant indices are invalid, making issues easier to debug in production.

* fix: prevent concurrent initialization race condition

Add initializingPromise to coordinate concurrent initialize() calls.
The fast boolean check is preserved for the hot path, while concurrent
calls during initialization now await the same promise instead of
triggering multiple initializations.

* fix: add timeout and retry logic to fetchDatafile

- Add 10-second timeout using AbortController to prevent indefinite hangs
- Add exponential backoff retry (up to 3 attempts) for transient failures
- Skip retries for 4xx client errors (except 429 rate limiting)
- Improves resilience against network issues in production

* fix: prevent race condition in ensureStream

Use local variable for abortController and store streamPromise
immediately after creation. This prevents concurrent calls from
creating multiple streams or overwriting the abort controller
before the promise is stored.

* fix: prevent race condition in read() by capturing data reference

Capture this.data reference at the start of read() to ensure consistent
state throughout the method. The onMessage callback from the stream can
update this.data during async operations, which could cause inconsistent
behavior if the reference changes mid-operation.

* comments

* add streaming connectionState

* update usage

* fix init

* try to avoid hanging promise

* update attw, add types

* get rid of unnecessary async/await

* avoid printing the warning

* distinct warnings

* don't export cachedFns

* add CLAUDE.md

* jsdoc

* clear timeout

* export Datafile

* avoid exposing data sources

* simplify

* types

* avoid dangling timeout

* more options

* tests

* allow options in createClient

* DatafileInput

* better options

* Update event tracking to use streams

* Revert "Update event tracking to use streams"

This reverts commit cff740a18c.

* fix datafile input type

* type

* handle shutdown and re-init

* defensive

* retry stream for up to 15 minutes

* Update event reporting to use ndjson for more events

* Revert "Update event reporting to use ndjson for more events"

This reverts commit f70a7bfc59.

* Add debug logs to the usage tracker

* [adapter-vercel] fix getProviderData

* [adapter-vercel] only return vercel flags from getProviderData

* fix

* rm getInfo

* rm tgz

* rm example

* rm next/connection from gitignore

* rm unused deps

* use DatafileInput type

* fix tests

* ensure pollCount > 0

* fix type issues

* fix retry logic

* upgrade @sveltejs/kit

* resolve ci issues

---------

Co-authored-by: Luis Meyer <luis.meyer@vercel.com>
Co-authored-by: vercel[bot] <35613825+vercel[bot]@users.noreply.github.com>
Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>
Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>
Co-authored-by: Andy Bitz <artzbitz@gmail.com>
2026-02-09 11:45:00 +02:00
Vincent Derks 170364de7e Updated rimraf to 6.1.2 (#252) 2026-02-06 11:20:48 +01:00