feat(artifacts): prefer server-assembled bundle delivery for downloads - #93
Merged
Conversation
Artifact and HTML-report downloads now try a bundle-delivery path first: the
API returns a signed manifest plus a URL to a delivery service that streams
the ZIP straight from storage, so large downloads don't flow through the API.
The client relays the signed { manifest, sig } to that URL (no auth header —
the manifest is the signed token) and streams the result to disk.
Falls back to the existing inline download automatically when bundle delivery
isn't offered (501) or anything about the path doesn't pan out, so behaviour
is unchanged on older deployments. Applies to artifacts and the HTML report;
junit and allure keep using their existing endpoints.
Adds a shared tryBundleDownload helper in the API gateway and unit tests
covering the bundle path, the no-auth relay, the 501 fallback, and the HTML
report.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Code reviewNo issues found. Checked for bugs and CLAUDE.md compliance. |
streamResponseToFile threw past both tryBundleDownload call sites on a mid-stream failure or null body, escaping the inline fallback and leaving a partial file. Wrap it to return false like every other failure path. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
finalerock44
added a commit
that referenced
this pull request
Aug 7, 2026
Promote from dev to stable: * feat: client-side envelope encryption of app binaries, flow zips and env vars (#94, #101) — opt-in via `--encrypt` / `DCD_ENCRYPT_BINARIES=1` and off by default, so uploads stay byte-identical unless asked for. Per-upload DEK, chunked AES-256-GCM container, X25519 sealed-box DEK wrap; encrypted binaries dedup on the plaintext hash so re-uploads still hit the cache. * feat(artifacts): prefer server-assembled bundle delivery for downloads (#93) — falls back to the inline endpoint on 501, so it degrades cleanly against an API that has not shipped bundles. * feat(device): add Android API level 37 (Android 17) (#107) — the flag enum accepts 37, but the device/API-level pair is validated against the compatibility matrix the *target* API serves, and production still tops out at 36, so 37 is refused client-side until the platform gate flips. * refactor(cloud): remove the enterprise-only --mitmHost / --mitmPath flags (#102). The submitted config payload for runs that never passed them is byte-identical. * fix(deps) / deps: clear every outstanding pnpm audit advisory (#89, #92, #95, #100, #106), bump chalk 5 -> 6, and regenerate the schema types from the current API swagger (#105). No platform prerequisite this time: the envelope decrypt half (dcd api + simulators) is already on production with both env KEK public keys pinned, bundle delivery has a 501 fallback, and API 37 is gated server-side. Carries only the source delta — package.json version, CHANGELOG.md and the release-please manifests stay as release-please left them on production. Release-As: 5.3.0
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Artifact and HTML-report downloads now try a bundle-delivery path before the inline download:
GET /results/{uploadId}/artifacts-bundle?results=…or…/report-bundle).{ manifest, sig }to that URL — no auth header, since the manifest is itself the signed access token — and streams the ZIP to disk.Large downloads stream directly from storage instead of flowing through the API.
Compatibility
Fully backwards-compatible, no version negotiation:
501→ the CLI falls back to the existing inline download.How
tryBundleDownloadhelper in the API gateway;downloadArtifactsZipand the HTML branch ofdownloadReportGenericcall it first and fall back onfalse.Testing
pnpm typecheck+pnpm lintclean.pnpm test— 171 passing, including new coverage: streams from the bundle URL and skips the inline endpoint, sends no auth header to the (pre-signed) bundle URL, falls back to inline on501, and uses bundle delivery for the HTML report. Existing inline-download tests unchanged.🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.