Skip to content

[@vercel/flags-core] Support flags:projectId= connection strings - #517

Merged
vincent-derks merged 8 commits into
mainfrom
vincentderks/exp-3489-flags-sdk-support-for-flagsprojectid-connection-strings-oidc
Sep 28, 2026
Merged

vincent-derks merged 8 commits into
mainfrom
vincentderks/exp-3489-flags-sdk-support-for-flagsprojectid-connection-strings-oidc

Conversation

@vincent-derks

@vincent-derks vincent-derks commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Why

A deployment can read another Vercel project's flags with its own OIDC token instead of a copied SDK key. The connection string flags:projectId=<id> names that project. This is the client half; nothing changes for SDK keys or for createVercelAdapter() without arguments.

  • flags:projectId=<id> → OIDC bearer plus X-Vercel-Flags-Project-Id on datafile, stream, and ingest. Bundled definitions are looked up by that id.
  • Strings with both sdkKey and projectId, or a malformed projectId, throw.
  • 401s name the project; usage tracking pauses on a 401 and resumes on the next successful read.
  • Ingest for these clients goes over HTTP, batched, so both identities reach the service: the token (caller) and the header (project whose flags were evaluated). The runtime transport carries only the caller. Which project usage counts against is decided server-side, not here.
  • origin.projectId is set so getProviderData reports the right project.
  • prepare-flags-definitions embeds definitions for flags:projectId= env values, fetched with VERCEL_OIDC_TOKEN and the header.

Validation

Tests cover the header sets per request type, the parser rules, the 401 messages on every read path, tracking pause/resume, one batched ingest call with the runtime hook installed, and the prepare cases (fetch, no-token skip, own-project dedupe, both-keys skip).

Checked against the live service with a real OIDC token: flags:projectId=<own project> → 200 through the new path; <another project> → 401 naming it. The cross-project success path needs the backend to grant access and cannot be observed live yet; it was exercised against a local stand-in.

Try it

In any Vercel project with OIDC enabled, install the snapshot build and add:

createVercelAdapter(`flags:projectId=${process.env.VERCEL_PROJECT_ID}`); // 200, own flags via the new path
createVercelAdapter('flags:projectId=prj_someOtherProject');            // 401 naming that project

@vercel

vercel Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
flags-playground Ready Ready Preview, v0 Sep 28, 2026 11:47am UTC
flags-sdk-dev Ready Ready Preview, v0 Sep 28, 2026 11:47am UTC
flags-sdk-snippets Ready Ready Preview, v0 Sep 28, 2026 11:47am UTC
flags-sdk-sveltekit-snippets Ready Ready Preview, v0 Sep 28, 2026 11:47am UTC
shirt-shop Ready Ready Preview, v0 Sep 28, 2026 11:47am UTC
shirt-shop-api Ready Ready Preview, v0 Sep 28, 2026 11:47am UTC

…-flags-sdk-support-for-flagsprojectid-connection-strings-oidc

# Conflicts:
#	packages/vercel-flags-core/src/controller/fetch-datafile.ts
@vincent-derks
vincent-derks enabled auto-merge (squash) September 28, 2026 11:44
…-flags-sdk-support-for-flagsprojectid-connection-strings-oidc

This branch was successfully deployed

6 active deployments
Preview – flags-sdk-dev — 5e44ee29 Deployed Sep 28, 2026 by vercel[bot]
Preview – flags-sdk-sveltekit-snippets — 5e44ee29 Deployed Sep 28, 2026 by vercel[bot]
Preview – flags-playground — 5e44ee29 Deployed Sep 28, 2026 by vercel[bot]
Preview – flags-sdk-snippets — 5e44ee29 Deployed Sep 28, 2026 by vercel[bot]
Preview – shirt-shop — 5e44ee29 Deployed Sep 28, 2026 by vercel[bot]
Preview – shirt-shop-api — 5e44ee29 Deployed Sep 28, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants