Compare commits

...
19 Commits
Author SHA1 Message Date
semantic-release-bot 3d0cdc85cd chore(release): 4.17.2 [skip ci]
## [4.17.2](https://github.com/sasjs/adapter/compare/v4.17.1...v4.17.2) (2026-07-21)

### Bug Fixes

* **deps:** resolve npm audit vulnerabilities ([0ad18be](https://github.com/sasjs/adapter/commit/0ad18be38f005bb0dfecb313f8cff4598460318c))
* route all traffic trough connected VPN ([ff6e67e](https://github.com/sasjs/adapter/commit/ff6e67e902529a4211f5847dd59c19038298852f))
2026-07-21 11:49:39 +00:00
Allan BoweandGitHub 425d6eb993 Merge pull request #893 from sasjs/dep-vulnerabilities
fix(deps): resolve npm audit vulnerabilities
2026-07-21 12:48:39 +01:00
M 47c6e45024 chore: cleanup package-lock 2026-07-21 13:42:29 +02:00
M ff6e67e902 fix: route all traffic trough connected VPN 2026-07-21 13:39:28 +02:00
YuryShkoda 22667baea1 chore: cleanup 2026-07-21 13:06:12 +03:00
YuryShkoda b50afbec41 ci: add VPN diagnostics and curl retry to server-tests workflow
The "Fetch SASJS server" step was timing out after 130s+ despite the
VPN reporting "Connected", with no way to tell whether routes hadn't
propagated yet or the firewall was silently dropping packets from the
runner's IP. Log VPN session/route/DNS state right after connecting,
and retry the curl with a shorter per-attempt timeout so a routing
race resolves itself instead of hanging the whole job.
2026-07-21 12:55:01 +03:00
YuryShkoda 0ad18be38f fix(deps): resolve npm audit vulnerabilities
Bump axios (prod) plus express, webpack, terser-webpack-plugin,
node-polyfill-webpack-plugin, and semantic-release (dev) to patch
73 known vulnerabilities down to 6 low-severity, upstream-unfixed
ones in node-polyfill-webpack-plugin's own dependency chain.
2026-07-21 11:24:33 +03:00
Allan BoweandGitHub df43c921b9 Merge pull request #892 from sasjs/gha
chore: ensuring latest npm
2026-06-18 20:44:52 +01:00
Allan Bowe e20555ac82 chore: ensuring latest npm 2026-06-18 19:44:03 +00:00
semantic-release-bot 5c5967fa10 chore(release): 4.17.1 [skip ci]
## [4.17.1](https://github.com/sasjs/adapter/compare/v4.17.0...v4.17.1) (2026-06-18)

### Bug Fixes

* session expiry ([#886](https://github.com/sasjs/adapter/issues/886)) ([b3921f7](https://github.com/sasjs/adapter/commit/b3921f7d058693ec125d0ae6ddafdb4095b0771e))
2026-06-18 19:19:00 +00:00
Allan BoweandGitHub a641a2fbdf Merge pull request #891 from sasjs/gha
chore: using github app to bypass branch protection
2026-06-18 20:17:59 +01:00
Allan Bowe 5f1d2fa1c9 chore: using github app to bypass branch protection 2026-06-18 19:16:26 +00:00
Allan BoweandGitHub b7b56ecde1 Merge pull request #889 from sasjs/chorebranch
chore: more pipeline fixings
2026-06-18 15:19:52 +01:00
Allan Bowe 39e5386346 chore: more pipeline fixings 2026-06-18 14:17:48 +00:00
Trevor MoodyandGitHub 33e28483c5 Merge pull request #888 from sasjs/chorebranch
chore: pipeline for oidc
2026-06-18 15:02:51 +01:00
Allan Bowe fa67b5b447 chore: pipeline for oidc 2026-06-18 13:55:06 +00:00
Allan BoweandGitHub 6f42f40f07 Merge pull request #887 from sasjs/chorebranch
chore: publish using oidc
2026-06-18 14:27:35 +01:00
Allan Bowe c0289583d5 chore: publish using oidc 2026-06-18 13:00:26 +00:00
Sead MulahasanovićandGitHub b3921f7d05 fix: session expiry (#886)
* fix: handle session inactivity expiry

* fix: clear all cookies on session expiry and throw LoginRequiredError

* chore: add diagnostic logging to session recovery flow

* fix: re-establish session on ERR_NETWORK before retrying

* chore: remove diagnostic logging

Partially reverts 706fd8e470

* fix(deps): bump form-data
2026-06-18 13:17:28 +02:00
9 changed files with 6533 additions and 4208 deletions
+5
View File
@@ -14,6 +14,11 @@ script-security 2
keepalive 10 120
remote-cert-tls server
# Route ALL traffic through the VPN (full tunnel)
redirect-gateway def1
# Send DNS through the tunnel so it doesn't leak to your local ISP
dhcp-option DNS 1.1.1.1
# Keys
ca ca.crt
cert user.crt
+34 -7
View File
@@ -11,21 +11,45 @@ on:
jobs:
build:
runs-on: ubuntu-latest
permissions:
contents: write
id-token: write # required for npm provenance (trusted publisher)
issues: write # optional: lets @semantic-release/github comment on issues
pull-requests: write # optional: lets @semantic-release/github comment on PRs
strategy:
matrix:
node-version: [22]
steps:
- uses: actions/checkout@v2
# Mint a short-lived GitHub App token (bypass-capable)
- name: Generate token
id: app-token
uses: actions/create-github-app-token@v1
with:
app-id: ${{ secrets.APP_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}
# Checkout using the app token so the release commit can be pushed
- uses: actions/checkout@v4
with:
token: ${{ steps.app-token.outputs.token }}
persist-credentials: true
fetch-depth: 0 # semantic-release needs full history + tags
- name: Use Node.js ${{ matrix.node-version }}
uses: actions/setup-node@v2
uses: actions/setup-node@v4
with:
node-version: ${{ matrix.node-version }}
registry-url: https://registry.npmjs.org
# 2. Restore npm cache manually
# Node 22 ships npm 10.x — OIDC trusted publishing needs npm >= 11.5.1
- name: Update npm
run: npm install -g npm@latest
# Restore npm cache manually
- name: Restore npm cache
uses: actions/cache@v3
uses: actions/cache@v4
id: npm-cache
with:
path: ~/.npm
@@ -46,10 +70,13 @@ jobs:
run: npm run publishInit
- name: Semantic Release
uses: cycjimmy/semantic-release-action@v3
run: npx semantic-release
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
GITHUB_TOKEN: ${{ steps.app-token.outputs.token }} # <-- app token, not secrets.GITHUB_TOKEN
- name: Publish to npm with trusted publisher
if: success()
run: npm publish --access public
- name: Send Matrix message
run: curl -XPOST -d "{\"msgtype\":\"m.text\", \"body\":\"New version of @sasjs/adapter has been released! \n Please deploy and run 'dctests' with new adapter to make sure everything is still in place.\"}" https://matrix.4gl.io/_matrix/client/r0/rooms/!jRebyiGmHZlpfDwYXN:4gl.io/send/m.room.message?access_token=${{ secrets.MATRIX_TOKEN }}
+23 -1
View File
@@ -86,8 +86,30 @@ jobs:
- name: install pm2
run: npm i -g pm2
- name: Diagnose VPN connectivity
run: |
echo "--- openvpn3 sessions-list ---"
openvpn3 sessions-list
echo "--- openvpn3 session-stats ---"
openvpn3 session-stats --config .github/vpn/config.ovpn
echo "--- ip addr (tun interface) ---"
ip addr show tun0 || echo "no tun0 interface found"
echo "--- ip route ---"
ip route
echo "--- DNS resolution check for target host (host/IP not printed) ---"
TARGET_HOST="$(echo '${{ secrets.SASJS_SERVER_URL }}' | sed -E 's#^[a-z]+://##; s#[:/].*##')"
if getent hosts "$TARGET_HOST" > /dev/null; then
echo "DNS resolution: OK"
else
echo "DNS resolution: FAILED"
fi
shell: bash
- name: Fetch SASJS server
run: curl ${{ secrets.SASJS_SERVER_URL }}/SASjsApi/info
run: |
curl -sS --retry 5 --retry-delay 5 --retry-all-errors --connect-timeout 15 --max-time 30 \
-o /dev/null -w "HTTP status: %{http_code}\n" \
"${{ secrets.SASJS_SERVER_URL }}/SASjsApi/info"
- name: Deploy sasjs-tests
run: |
+6332 -4184
View File
File diff suppressed because it is too large Load Diff
+31 -14
View File
@@ -23,10 +23,24 @@
},
"release": {
"plugins": [
"@semantic-release/npm",
{
"pkgRoot": "/build"
}
"@semantic-release/commit-analyzer",
"@semantic-release/release-notes-generator",
[
"@semantic-release/exec",
{
"prepareCmd": "npm version ${nextRelease.version} --no-git-tag-version"
}
],
[
"@semantic-release/git",
{
"assets": [
"package.json",
"package-lock.json"
]
}
],
"@semantic-release/github"
]
},
"keywords": [
@@ -34,14 +48,16 @@
"viya",
"sasjs"
],
"author": "Allan Bowe <support@macropeople.com>",
"author": "support@4gl.io",
"repository": {
"type": "git",
"url": "https://github.com/sasjs/adapter"
"url": "git+https://github.com/sasjs/adapter.git"
},
"license": "ISC",
"devDependencies": {
"@cypress/webpack-preprocessor": "5.9.1",
"@semantic-release/exec": "6.0.3",
"@semantic-release/git": "10.0.1",
"@types/cors": "^2.8.17",
"@types/express": "4.17.13",
"@types/jest": "29.5.14",
@@ -53,17 +69,17 @@
"cp": "0.2.0",
"cypress": "^15.7.1",
"dotenv": "16.0.0",
"express": "4.17.3",
"express": "4.22.2",
"jest": "29.7.0",
"jest-environment-jsdom": "^29.7.0",
"jest-extended": "4.0.2",
"node-polyfill-webpack-plugin": "1.1.4",
"node-polyfill-webpack-plugin": "4.1.0",
"path": "0.12.7",
"pem": "1.14.5",
"prettier": "3.8.2",
"process": "0.11.10",
"semantic-release": "19.0.3",
"terser-webpack-plugin": "5.3.6",
"semantic-release": "25.0.8",
"terser-webpack-plugin": "5.6.1",
"ts-jest": "29.2.6",
"ts-loader": "9.4.0",
"tslint": "6.1.3",
@@ -71,16 +87,17 @@
"typedoc": "0.23.24",
"typedoc-plugin-rename-defaults": "0.6.4",
"typescript": "4.9.5",
"webpack": "5.76.2",
"webpack": "5.108.4",
"webpack-cli": "4.9.2"
},
"main": "index.js",
"dependencies": {
"@sasjs/utils": "^3.5.6",
"axios": "1.16.0",
"axios": "1.18.1",
"axios-cookiejar-support": "5.0.5",
"form-data": "4.0.4",
"form-data": "4.0.6",
"https": "1.0.0",
"tough-cookie": "4.1.3"
}
},
"version": "4.17.2"
}
+1 -1
View File
@@ -375,7 +375,7 @@ export class AuthManager {
*
*/
public async logOut() {
this.requestClient.clearCsrfTokens()
this.requestClient.resetInMemoryAuthState()
return this.requestClient.get(this.logoutUrl, undefined).then(() => true)
}
+64 -1
View File
@@ -28,6 +28,9 @@ import {
import { InvalidSASjsCsrfError } from '../types/errors/InvalidSASjsCsrfError'
import { inspect } from 'util'
const getLogger = () =>
(typeof process !== 'undefined' && process.logger) || console
export class RequestClient implements HttpClient {
private requests: SASjsRequest[] = []
private requestsLimit: number = 10
@@ -37,6 +40,7 @@ export class RequestClient implements HttpClient {
protected csrfToken: CsrfToken = { headerName: '', value: '' }
protected fileUploadCsrfToken: CsrfToken | undefined
protected httpClient!: AxiosInstance
private isRecoveringFromNetworkError = false
constructor(
protected baseUrl: string,
@@ -77,6 +81,25 @@ export class RequestClient implements HttpClient {
localStorage.setItem('refreshToken', '')
}
public resetInMemoryAuthState() {
this.clearCsrfTokens()
if (typeof localStorage !== 'undefined') {
this.clearLocalStorageTokens()
}
if (typeof document !== 'undefined') {
this.clearAllCookies()
}
}
private clearAllCookies() {
const cookies = document.cookie.split(';')
for (const cookie of cookies) {
const name = cookie.split('=')[0].trim()
if (!name) continue
document.cookie = `${name}=; Max-Age=0; Path=/;`
}
}
public getBaseUrl() {
return this.httpClient.defaults.baseURL || ''
}
@@ -354,6 +377,7 @@ export class RequestClient implements HttpClient {
const csrfTokenKey = Object.keys(params).find((k) =>
k?.toLowerCase().includes('csrf')
)
if (csrfTokenKey) {
this.csrfToken.value = params[csrfTokenKey]
this.csrfToken.headerName = this.csrfToken.headerName || 'x-csrf-token'
@@ -378,7 +402,7 @@ export class RequestClient implements HttpClient {
})
.then((res) => res.data)
.catch((error) => {
const logger = process.logger || console
const logger = getLogger()
logger.error(error)
})
}
@@ -687,6 +711,45 @@ ${resHeaders}${parsedResBody ? `\n\n${parsedResBody}` : ''}
throw new CertificateError(e.message)
}
if (
e.isAxiosError &&
!response &&
e.code === 'ERR_NETWORK' &&
!this.isRecoveringFromNetworkError
) {
// Opaque ERR_NETWORK usually means the server rejected stale credentials.
// Wipe in-memory auth state, re-establish session via GET /,
// then retry the original request.
this.resetInMemoryAuthState()
this.isRecoveringFromNetworkError = true
try {
// Re-establish session and CSRF cookie
const rootResponse = await this.httpClient
.get('/', { withXSRFToken: true })
.catch((err) => err.response)
if (rootResponse?.data) {
const cookie =
/<script>document.cookie = '(XSRF-TOKEN=.*; Max-Age=86400; SameSite=Strict; Path=\/;)'<\/script>/.exec(
rootResponse.data
)?.[1]
if (cookie && typeof document !== 'undefined') {
document.cookie = cookie
}
this.parseAndSetCsrfToken(rootResponse)
}
return await callback()
} catch {
// Session could not be recovered — surface LoginRequiredError
throw new LoginRequiredError()
} finally {
this.isRecoveringFromNetworkError = false
}
}
if (e.message) throw e
else throw prefixMessage(e, 'Error while handling error. ')
}
+7
View File
@@ -23,6 +23,13 @@ export class Sas9RequestClient extends RequestClient {
}
}
public resetInMemoryAuthState() {
super.resetInMemoryAuthState()
if (this.httpClient.defaults.jar) {
;(this.httpClient.defaults.jar as tough.CookieJar).removeAllCookiesSync()
}
}
public async login(username: string, password: string, jobsPath: string) {
const codeInjectorPath = `/User Folders/${username}/My Folder/sasjs/runner`
if (this.httpClient.defaults.jar) {
+36
View File
@@ -589,6 +589,42 @@ ${resHeaders[0]}: ${resHeaders[1]}${
requestClient['handleError'](error, () => {}, false)
).resolves.toEqual(undefined)
})
it('should clear CSRF and retry once on opaque ERR_NETWORK', async () => {
const networkError = {
isAxiosError: true,
code: 'ERR_NETWORK',
message: 'Network Error'
}
requestClient['csrfToken'] = { headerName: 'h', value: 'v' }
const callback = jest.fn().mockResolvedValue('ok')
await expect(
requestClient['handleError'](networkError, callback)
).resolves.toEqual('ok')
expect(callback).toHaveBeenCalledTimes(1)
expect(requestClient['csrfToken']).toEqual({ headerName: '', value: '' })
})
it('should throw LoginRequiredError if retry also fails with ERR_NETWORK', async () => {
const networkError = {
isAxiosError: true,
code: 'ERR_NETWORK',
message: 'Network Error'
}
const innerHandle = jest.fn(() =>
requestClient['handleError'](networkError, () =>
Promise.reject(networkError)
)
)
await expect(
requestClient['handleError'](networkError, innerHandle)
).rejects.toThrow(LoginRequiredError)
expect(innerHandle).toHaveBeenCalledTimes(1)
})
})
})