feat(appkit): surface caller expiry and support local OBO - #597
Open
MarioCadenas wants to merge 2 commits into
Open
MarioCadenas wants to merge 2 commits into
MarioCadenas wants to merge 2 commits into
Conversation
MarioCadenas
requested review from
calvarjorge
and removed request for
a team
September 23, 2026 18:22
MarioCadenas
added this pull request to stack #602
September 24, 2026 08:14
Contributor
📦 Bundle size reportCompared against
|
| dist | raw | gzip |
|---|---|---|
| JS (runtime) | 1.2 MB (+16 KB) | 431 KB (+6.3 KB) |
| Type declarations | 450 KB (+6.3 KB) | 163 KB (+2.4 KB) |
| Source maps | 2.4 MB (+29 KB) | 809 KB (+11 KB) |
| Other | 11 KB | 3.7 KB |
| Total | 4.0 MB (+52 KB) | 1.4 MB (+20 KB) |
Per-entry composition (own code — deps external (as shipped))
| Entry | Initial (gz) | Lazy (gz) | Total (gz) | node_modules (min) | Own code (min) |
|---|---|---|---|---|---|
. |
97 KB (+1.7 KB) | 2.5 KB | 100 KB (+1.7 KB) | external | 319 KB (+5.2 KB) |
./beta |
94 KB (+1.4 KB) | 439 B (-18 B) | 95 KB (+1.4 KB) | external | 286 KB (+4.6 KB) |
./testing |
40 KB (+1.8 KB) | 30 KB (-18 B) | 71 KB (+1.8 KB) | external | 205 KB (+4.3 KB) |
./tsdown |
520 B | 0 B | 520 B | external | 813 B |
./type-generator |
23 KB | 0 B | 23 KB | external | 65 KB |
Chunks:
| Entry | Chunk | Load | Size (gz) |
|---|---|---|---|
. |
index.js |
initial | 93 KB |
. |
utils.js |
initial | 4.0 KB |
. |
remote-tunnel-manager.js |
lazy | 2.5 KB |
./beta |
beta.js |
initial | 78 KB |
./beta |
stream-manager.js |
initial | 5.9 KB |
./beta |
service-context.js |
initial | 4.1 KB |
./beta |
wide-event-emitter.js |
initial | 3.2 KB |
./beta |
databricks.js |
initial | 3.1 KB |
./beta |
client.js |
initial | 542 B |
./beta |
index.js |
initial | 20 B |
./beta |
supervisor-api.js |
lazy | 192 B |
./beta |
databricks.js |
lazy | 132 B |
./beta |
index.js |
lazy | 115 B |
./testing |
manifest.js |
initial | 27 KB |
./testing |
index.js |
initial | 10 KB |
./testing |
wide-event-emitter.js |
initial | 2.9 KB |
./testing |
index.js |
lazy | 26 KB |
./testing |
remote-tunnel-manager.js |
lazy | 2.5 KB |
./testing |
utils.js |
lazy | 1.2 KB |
./tsdown |
index.js |
initial | 520 B |
./type-generator |
index.js |
initial | 23 KB |
@databricks/appkit-ui
npm tarball (packed): 350 KB (-4 B) — gzipped download (dist + bin; excludes release-only docs/NOTICE).
| dist | raw | gzip |
|---|---|---|
| JS (runtime) | 395 KB | 132 KB |
| Type declarations | 229 KB | 84 KB (-1 B) |
| Source maps | 766 KB | 253 KB (+1 B) |
| CSS | 16 KB | 3.2 KB |
| Total | 1.4 MB | 472 KB |
Per-entry composition (consumer bundle — deps bundled, peerDeps external)
| Entry | Initial (gz) | Lazy (gz) | Total (gz) | node_modules (min) | Own code (min) |
|---|---|---|---|---|---|
./js |
5.3 KB | 49 KB | 55 KB | 208 KB | 14 KB |
./js/beta |
20 B | 0 B | 20 B | 0 B | 0 B |
./react |
432 KB | 49 KB | 481 KB | 1.3 MB | 177 KB |
./react/beta |
1.0 KB | 0 B | 1.0 KB | 0 B | 1.9 KB |
Chunks:
| Entry | Chunk | Load | Size (gz) |
|---|---|---|---|
./js |
index.js |
initial | 5.2 KB |
./js |
chunk |
initial | 120 B |
./js |
apache-arrow |
lazy | 49 KB |
./js/beta |
beta.js |
initial | 20 B |
./react |
index.js |
initial | 430 KB |
./react |
tslib |
initial | 2.1 KB |
./react |
apache-arrow |
lazy | 49 KB |
./react/beta |
beta.js |
initial | 1.0 KB |
Contributor
🤖 AppKit PR bot🔬 Run evalsStart an eval for this PR from the evals-monitor app: Go to Evals Monitor → 📦 Try this PR's app templateScaffolds a new app from this PR's SDK build. Run it in any folder (requires the GitHub CLI — gh run download 36113876176 -R databricks/appkit -n appkit-template-0.78.0-pr.c8e5928-execution-identity-lifecycle-597 -D appkit-pr-597 \
&& unzip -o "appkit-pr-597/appkit-template-0.78.0-pr.c8e5928-execution-identity-lifecycle-597.zip" -d "appkit-pr-597" \
&& databricks apps init --template "appkit-pr-597"The template pins |
MarioCadenas
force-pushed
the
execution-identity-lifecycle
branch
from
September 24, 2026 13:42
2790860 to
25ecd06
Compare
MarioCadenas
force-pushed
the
execution-identity-lifecycle
branch
from
September 24, 2026 16:26
25ecd06 to
45d2d28
Compare
Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Use plain punctuation in the inherited error comment so generated pages follow repository style. Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
MarioCadenas
force-pushed
the
execution-identity-lifecycle
branch
from
September 25, 2026 08:36
45d2d28 to
81ff9a7
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Long-running caller operations now expose credential rejection as
IdentityExpiredError(IDENTITY_EXPIRED) instead of opaque failures. HTTP and SSE agent responses carry the stable error code. The error retains only the existing token fingerprint, never the original credential-bearing upstream error.This is layer 4 of the stack, based on #595 (
execution-standalone-user). Design:design-docs/execution-identity-e2e.md, section 5.1.4. Cache partitioning landed in #594.appkit.execution.principal,appkit.execution.principal_id, and the initiating user'sappkit.execution.actor_idwhen present, including cache, tool, and connector spans. Tokens are not span attributes.appkit dev-obo --profile <chosen-user-profile> --target http://127.0.0.1:3000provides opt-in local user execution through a loopback proxy. It injects forwarded user headers, keeps credentials in memory, refreshes them, and fails closed on refresh failure. No profile is selected implicitly.DEV_OBO_FALLBACKremains when local user injection is not used.Behavior note
Caller-scope downstream 401s surface typed expiry information. Plugin
execute()preserves the existing failed-result envelope and adds an optional typederrorfield, so result-based consumers continue to work. Throwing and streaming APIs exposeIdentityExpiredError. Non-401 failures, local missing-token errors, and SP execution retain their existing behavior. Consumers can reauthenticate rather than retry expired credentials.Verification
pnpm -r typecheck