Skip to content

Conversation

@arcoraven
Copy link
Contributor

@arcoraven arcoraven commented Jun 9, 2025

[Dashboard] Fix: Update Authorization in Analytics API

Notes for the reviewer

This PR updates the authorization mechanism in the analytics API by:

  1. Adding the Authorization Bearer token header to all analytics API requests
  2. Removing redundant Content-Type headers from individual API methods
  3. Removing commented-out debug code

How to test

Verify that analytics API requests are properly authorized and returning expected data.

Summary by CodeRabbit

  • Chores
    • Updated request headers to use Authorization tokens instead of explicit content-type for analytics data fetching.
    • Removed unused debug code related to query parameters.

@vercel
Copy link

vercel bot commented Jun 9, 2025

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
thirdweb-www ✅ Ready (Inspect) Visit Preview 💬 Add feedback Jun 9, 2025 9:55am
4 Skipped Deployments
Name Status Preview Comments Updated (UTC)
docs-v2 ⬜️ Skipped (Inspect) Jun 9, 2025 9:55am
login ⬜️ Skipped (Inspect) Jun 9, 2025 9:55am
thirdweb_playground ⬜️ Skipped (Inspect) Jun 9, 2025 9:55am
wallet-ui ⬜️ Skipped (Inspect) Jun 9, 2025 9:55am

@vercel vercel bot temporarily deployed to Preview – login June 9, 2025 09:48 Inactive
@vercel vercel bot temporarily deployed to Preview – wallet-ui June 9, 2025 09:48 Inactive
@vercel vercel bot temporarily deployed to Preview – thirdweb_playground June 9, 2025 09:48 Inactive
@vercel vercel bot temporarily deployed to Preview – docs-v2 June 9, 2025 09:48 Inactive
@changeset-bot
Copy link

changeset-bot bot commented Jun 9, 2025

⚠️ No Changeset found

Latest commit: d0b1695

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai
Copy link
Contributor

coderabbitai bot commented Jun 9, 2025

Walkthrough

The update removes explicit "Content-Type: application/json" headers from GET requests in analytics API functions and replaces the content-type header with an Authorization header using a bearer token in the shared fetch function. Debug code related to query parameters is also eliminated, with no changes to function signatures.

Changes

File(s) Change Summary
apps/dashboard/src/@/api/analytics.ts Removed explicit "Content-Type" headers from GET requests, added Authorization header, and deleted commented debug code.

Suggested labels

Dashboard

Warning

Review ran into problems

🔥 Problems

Errors were encountered while retrieving linked issues.

Errors (1)
  • TEAM-0000: Entity not found: Issue - Could not find referenced Issue.
✨ Finishing Touches
  • 📝 Generate Docstrings

🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Explain this complex logic.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query. Examples:
    • @coderabbitai explain this code block.
    • @coderabbitai modularize this function.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read src/utils.ts and explain its main purpose.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.
    • @coderabbitai help me debug CodeRabbit configuration file.

Support

Need help? Create a ticket on our support page for assistance with any issues or questions.

Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments.

CodeRabbit Commands (Invoked using PR comments)

  • @coderabbitai pause to pause the reviews on a PR.
  • @coderabbitai resume to resume the paused reviews.
  • @coderabbitai review to trigger an incremental review. This is useful when automatic reviews are disabled for the repository.
  • @coderabbitai full review to do a full review from scratch and review all the files again.
  • @coderabbitai summary to regenerate the summary of the PR.
  • @coderabbitai generate docstrings to generate docstrings for this PR.
  • @coderabbitai generate sequence diagram to generate a sequence diagram of the changes in this PR.
  • @coderabbitai resolve resolve all the CodeRabbit review comments.
  • @coderabbitai configuration to show the current CodeRabbit configuration for the repository.
  • @coderabbitai help to get help.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Documentation and Community

  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

@arcoraven arcoraven marked this pull request as ready for review June 9, 2025 09:48
@arcoraven arcoraven requested review from a team as code owners June 9, 2025 09:48
Copy link
Contributor Author


How to use the Graphite Merge Queue

Add either label to this PR to merge it via the merge queue:

  • merge-queue - adds this PR to the back of the merge queue
  • hotfix - for urgent hot fixes, skip the queue and merge this PR next

You must have a Graphite account in order to use the merge queue. Sign up using this link.

An organization admin has enabled the Graphite Merge Queue in this repository.

Please do not merge from GitHub as this will restart CI on PRs being processed by the merge queue.

This stack of pull requests is managed by Graphite. Learn more about stacking.

@github-actions github-actions bot added the Dashboard Involves changes to the Dashboard. label Jun 9, 2025
Copy link
Contributor

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (2)
apps/dashboard/src/@/api/analytics.ts (2)

29-49: Consider using URL constructor for more robust URL parsing.

The manual URL parsing logic could be simplified and made more robust by using the URL constructor directly.

-  const [pathname, searchParams] = input.toString().split("?");
-  if (!pathname) {
-    throw new Error("Invalid input, no pathname provided");
-  }
-
-  // create a new URL object for the analytics server
-  const analyticsServiceUrl = new URL(
-    ANALYTICS_SERVICE_URL || "https://analytics.thirdweb.com",
-  );
-
-  analyticsServiceUrl.pathname = pathname;
-  for (const param of searchParams?.split("&") || []) {
-    const [key, value] = param.split("=");
-    if (!key || !value) {
-      throw new Error("Invalid input, no key or value provided");
-    }
-    analyticsServiceUrl.searchParams.append(
-      decodeURIComponent(key),
-      decodeURIComponent(value),
-    );
-  }
+  const inputUrl = new URL(input.toString(), 'http://dummy.com');
+  const analyticsServiceUrl = new URL(
+    ANALYTICS_SERVICE_URL || "https://analytics.thirdweb.com",
+  );
+  
+  analyticsServiceUrl.pathname = inputUrl.pathname;
+  analyticsServiceUrl.search = inputUrl.search;

220-221: Improve error logging consistency.

Some functions include the response reason in error logs while others don't. Consider standardizing error logging across all analytics functions for better debugging.

-    console.error("Failed to fetch RPC method usage");
+    const reason = await res?.text();
+    console.error(
+      `Failed to fetch RPC method usage, ${res?.status} - ${res.statusText} - ${reason}`,
+    );
-    console.error("Failed to fetch Engine Cloud method usage");
+    const reason = await res?.text();
+    console.error(
+      `Failed to fetch Engine Cloud method usage, ${res?.status} - ${res.statusText} - ${reason}`,
+    );

Also applies to: 420-421

📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 6378f37 and d0b1695.

📒 Files selected for processing (1)
  • apps/dashboard/src/@/api/analytics.ts (1 hunks)
⏰ Context from checks skipped due to timeout of 90000ms (8)
  • GitHub Check: Unit Tests
  • GitHub Check: E2E Tests (pnpm, esbuild)
  • GitHub Check: E2E Tests (pnpm, webpack)
  • GitHub Check: Build Packages
  • GitHub Check: Size
  • GitHub Check: E2E Tests (pnpm, vite)
  • GitHub Check: Lint Packages
  • GitHub Check: Analyze (javascript)
🔇 Additional comments (2)
apps/dashboard/src/@/api/analytics.ts (2)

24-27: LGTM: Proper authentication validation.

The implementation correctly validates the auth token presence and throws a descriptive error when unauthorized. This prevents making requests without proper authentication.


54-54: LGTM: Correct Bearer token implementation.

The Authorization header is properly formatted using the Bearer token scheme, which aligns with the PR objective to pass authToken to analytics queries.

return fetch(analyticsServiceUrl, {
...init,
headers: {
"content-type": "application/json",
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Analytics-service only has GET queries. No content-type header is needed.

@codecov
Copy link

codecov bot commented Jun 9, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 55.57%. Comparing base (6378f37) to head (d0b1695).
Report is 1 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #7306   +/-   ##
=======================================
  Coverage   55.57%   55.57%           
=======================================
  Files         909      909           
  Lines       58673    58673           
  Branches     4158     4158           
=======================================
  Hits        32607    32607           
  Misses      25959    25959           
  Partials      107      107           
Flag Coverage Δ
packages 55.57% <ø> (ø)
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@arcoraven arcoraven added the merge-queue Adds the pull request to Graphite's merge queue. label Jun 9, 2025
@arcoraven arcoraven merged commit 2a4195b into main Jun 9, 2025
25 of 26 checks passed
@arcoraven arcoraven deleted the ph/06-09-chore_pass_authtoken_to_analytics_query branch June 9, 2025 09:51
Copy link
Contributor Author

Merge activity

  • Jun 9, 9:51 AM UTC: The merge label 'merge-queue' was detected. This PR will be added to the Graphite merge queue once it meets the requirements.

@github-actions
Copy link
Contributor

github-actions bot commented Jun 9, 2025

size-limit report 📦

Path Size Loading time (3g) Running time (snapdragon) Total time
thirdweb (esm) 62.57 KB (0%) 1.3 s (0%) 252 ms (+214.05% 🔺) 1.6 s
thirdweb (cjs) 345.55 KB (0%) 7 s (0%) 685 ms (+18.27% 🔺) 7.6 s
thirdweb (minimal + tree-shaking) 5.7 KB (0%) 114 ms (0%) 83 ms (+1494.95% 🔺) 197 ms
thirdweb/chains (tree-shaking) 531 B (0%) 11 ms (0%) 16 ms (+850.01% 🔺) 27 ms
thirdweb/react (minimal + tree-shaking) 19.56 KB (0%) 392 ms (0%) 52 ms (+305.7% 🔺) 443 ms

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Dashboard Involves changes to the Dashboard. merge-queue Adds the pull request to Graphite's merge queue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants