[@vercel/flags-core] Support flags:projectId= connection strings - #517
Merged
vincent-derks merged 8 commits intoSep 28, 2026
Conversation
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
…-flags-sdk-support-for-flagsprojectid-connection-strings-oidc # Conflicts: # packages/vercel-flags-core/src/controller/fetch-datafile.ts
vincent-derks
marked this pull request as ready for review
September 25, 2026 15:14
dferber90
approved these changes
Sep 28, 2026
vincent-derks
enabled auto-merge (squash)
September 28, 2026 11:44
…-flags-sdk-support-for-flagsprojectid-connection-strings-oidc
vincent-derks
deleted the
vincentderks/exp-3489-flags-sdk-support-for-flagsprojectid-connection-strings-oidc
branch
September 28, 2026 11:47
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
A deployment can read another Vercel project's flags with its own OIDC token instead of a copied SDK key. The connection string
flags:projectId=<id>names that project. This is the client half; nothing changes for SDK keys or forcreateVercelAdapter()without arguments.flags:projectId=<id>→ OIDC bearer plusX-Vercel-Flags-Project-Idon datafile, stream, and ingest. Bundled definitions are looked up by that id.sdkKeyandprojectId, or a malformedprojectId, throw.origin.projectIdis set sogetProviderDatareports the right project.prepare-flags-definitionsembeds definitions forflags:projectId=env values, fetched withVERCEL_OIDC_TOKENand the header.Validation
Tests cover the header sets per request type, the parser rules, the 401 messages on every read path, tracking pause/resume, one batched ingest call with the runtime hook installed, and the prepare cases (fetch, no-token skip, own-project dedupe, both-keys skip).
Checked against the live service with a real OIDC token:
flags:projectId=<own project>→ 200 through the new path;<another project>→ 401 naming it. The cross-project success path needs the backend to grant access and cannot be observed live yet; it was exercised against a local stand-in.Try it
In any Vercel project with OIDC enabled, install the snapshot build and add: