Skip to content

feat(shared): add a modular auth + raw-request seam to the workspace client - #644

Draft
MarioCadenas wants to merge 1 commit into
analytics-migration-sdkfrom
feat/modular-auth-seam
Draft

MarioCadenas wants to merge 1 commit into
analytics-migration-sdkfrom
feat/modular-auth-seam

Conversation

@MarioCadenas

Copy link
Copy Markdown
Collaborator

Part of the migration off @databricks/sdk-experimental onto the modular @databricks/sdk-* SDK (see #562). Base: analytics-migration-sdk.

Changes

feat(shared): add a modular auth + raw-request seam to the workspace client

Add getHost(), authenticate(headers) and request(req) to the WorkspaceClient
facade, built only from mapToClientOptions and resolved the same way the
modular SDK's resolveClientConfig does (profile resolve + defaultCredentials).
request() sends through the modular transport, so it carries the AppKit
User-Agent, returns the raw Response, and throws the wrapper ApiError on
non-2xx.

Migrate the drop-in callers off the legacy config/apiClient: SCIM workspace
id probe, dev warehouse discovery (still skip_cannot_use=true), internal
telemetry, files upload, mlflow eval auth, and agents hosted-tool auth.

Also cache env-M2M OAuth tokens until 40s before expiry. sdk-auth 0.51.0's
newM2mCredentials mints a new token per request, unlike the legacy SDK; this
affected the already-migrated warehouses/statementExecution clients too.

Draft: implemented by an agent; needs review and a deployed SP + OBO check before it's marked ready.

This pull request and its description were written by Isaac.

…client

Add getHost(), authenticate(headers) and request(req) to the WorkspaceClient
facade, built only from mapToClientOptions and resolved the same way the
modular SDK's resolveClientConfig does (profile resolve + defaultCredentials).
request() sends through the modular transport, so it carries the AppKit
User-Agent, returns the raw Response, and throws the wrapper ApiError on
non-2xx.

Migrate the drop-in callers off the legacy config/apiClient: SCIM workspace
id probe, dev warehouse discovery (still skip_cannot_use=true), internal
telemetry, files upload, mlflow eval auth, and agents hosted-tool auth.

Also cache env-M2M OAuth tokens until 40s before expiry. sdk-auth 0.51.0's
newM2mCredentials mints a new token per request, unlike the legacy SDK; this
affected the already-migrated warehouses/statementExecution clients too.

Co-authored-by: Isaac <no-reply@databricks.com>
Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
@MarioCadenas
MarioCadenas force-pushed the feat/modular-auth-seam branch from cb1617a to f90c6b8 Compare October 8, 2026 14:37
@MarioCadenas
MarioCadenas added this pull request to stack #636 October 8, 2026 14:38
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

📦 Bundle size report

Compared against bundle-size-baseline.json (main).

@databricks/appkit

npm tarball (packed): 1.2 MB (+12 KB) — gzipped download (dist + bin; excludes release-only docs/NOTICE).

dist raw gzip
JS (runtime) 1.2 MB (+11 KB) 451 KB (+4.4 KB)
Type declarations 459 KB (+3.2 KB) 167 KB (+1.3 KB)
Source maps 2.5 MB (+22 KB) 845 KB (+8.0 KB)
Other 11 KB 3.7 KB
Total 4.2 MB (+36 KB) 1.4 MB (+14 KB)
Per-entry composition (own code — deps external (as shipped))
Entry Initial (gz) Lazy (gz) Total (gz) node_modules (min) Own code (min)
. 103 KB (+1.0 KB) 2.5 KB (+1 B) 106 KB (+1.0 KB) external 334 KB (+2.6 KB)
./beta 99 KB (+988 B) 484 B 100 KB (+988 B) external 300 KB (+2.5 KB)
./testing 43 KB (+1.1 KB) 32 KB (+1 B) 75 KB (+1.1 KB) external 218 KB (+3.0 KB)
./tsdown 520 B 0 B 520 B external 813 B
./type-generator 24 KB (+1.0 KB) 0 B 24 KB (+1.0 KB) external 69 KB (+2.8 KB)

Chunks:

Entry Chunk Load Size (gz)
. index.js initial 98 KB
. utils.js initial 4.6 KB
. remote-tunnel-manager.js lazy 2.5 KB
./beta beta.js initial 81 KB
./beta stream-manager.js initial 5.9 KB
./beta modular.js initial 4.3 KB
./beta service-context.js initial 4.2 KB
./beta databricks.js initial 3.3 KB
./beta client.js initial 593 B
./beta index.js initial 20 B
./beta supervisor-api.js lazy 193 B
./beta databricks.js lazy 176 B
./beta index.js lazy 115 B
./testing manifest.js initial 30 KB
./testing index.js initial 10 KB
./testing wide-event-emitter.js initial 2.9 KB
./testing index.js lazy 28 KB
./testing remote-tunnel-manager.js lazy 2.5 KB
./testing utils.js lazy 1.8 KB
./tsdown index.js initial 520 B
./type-generator index.js initial 24 KB

@databricks/appkit-ui

npm tarball (packed): 397 KB (+102 B) — gzipped download (dist + bin; excludes release-only docs/NOTICE).

dist raw gzip
JS (runtime) 428 KB 146 KB
Type declarations 266 KB (+191 B) 98 KB (+123 B)
Source maps 852 KB 285 KB
CSS 16 KB 3.2 KB
Total 1.5 MB (+191 B) 533 KB (+123 B)
Per-entry composition (consumer bundle — deps bundled, peerDeps external)
Entry Initial (gz) Lazy (gz) Total (gz) node_modules (min) Own code (min)
./js 5.3 KB 49 KB 55 KB 208 KB 14 KB
./js/beta 2.1 KB 0 B 2.1 KB 0 B 5.0 KB
./react 433 KB 49 KB 481 KB 1.3 MB 177 KB
./react/beta 4.9 KB 0 B 4.9 KB 0 B 12 KB

Chunks:

Entry Chunk Load Size (gz)
./js index.js initial 5.2 KB
./js chunk initial 120 B
./js apache-arrow lazy 49 KB
./js/beta beta.js initial 2.1 KB
./react index.js initial 431 KB
./react tslib initial 2.1 KB
./react apache-arrow lazy 49 KB
./react/beta beta.js initial 4.9 KB

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

🤖 AppKit PR bot

🔬 Run evals

Start an eval for this PR from the evals-monitor app: Go to Evals Monitor →

📦 Try this PR's app template

Scaffolds a new app from this PR's SDK build. Run it in any folder (requires the GitHub CLI — gh auth login — and the Databricks CLI):

gh run download 37794004346 -R databricks/appkit -n appkit-template-0.87.0-pr.a8e9b83-feat-modular-auth-seam-644 -D appkit-pr-644 \
  && unzip -o "appkit-pr-644/appkit-template-0.87.0-pr.a8e9b83-feat-modular-auth-seam-644.zip" -d "appkit-pr-644" \
  && databricks apps init --template "appkit-pr-644"

The template pins @databricks/appkit and @databricks/appkit-ui to tarballs built from this branch, so the scaffolded app runs against this PR's code.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant