Merge branch 'main' into fix/ab/sh-380-completion-pdf-post-upload-error

This commit is contained in:
Alexandre Brandizzi 2026-09-18 19:21:18 -03:00 • committed by GitHub
commit 7eb7e4a730
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 12 additions and 2 deletions

View file

@ -216,10 +216,14 @@ export const workOrderBoardDocumentsApi = {
workOrderId: string | number, workOrderId: string | number,
mediaId: string | number, mediaId: string | number,
): Promise<Blob> => { ): Promise<Blob> => {
// No `credentials: "include"`: this endpoint authenticates with the bearer token the ky
// beforeRequest hook attaches, not cookies. In credentialed mode the browser rejects the
// API's `Access-Control-Allow-Origin: *` outright, so the fetch would throw and the document
// would never open.
const response = await apiRequestRaw( const response = await apiRequestRaw(
"get", "get",
API_PATHS.workOrder.mediaContent(workOrderId, mediaId), API_PATHS.workOrder.mediaContent(workOrderId, mediaId),
{ credentials: "include", throwHttpErrors: false }, { throwHttpErrors: false },
"workOrderBoardDocumentsApi.getMediaContent", "workOrderBoardDocumentsApi.getMediaContent",
); );

View file

@ -1022,8 +1022,14 @@ describe("workOrdersApi.getMediaContent", () => {
expect(result).toBe(blob); expect(result).toBe(blob);
expect(apiGetFn).toHaveBeenCalledWith( expect(apiGetFn).toHaveBeenCalledWith(
API_PATHS.workOrder.mediaContent(10, 12), API_PATHS.workOrder.mediaContent(10, 12),
expect.objectContaining({ credentials: "include", throwHttpErrors: false }), expect.objectContaining({ throwHttpErrors: false }),
); );
// Regression guard (SH-382): a credentialed cross-origin fetch is rejected by the browser
// against the API's `Access-Control-Allow-Origin: *`, so the content request must not opt
// into credentials mode — otherwise the document never opens. JSDOM cannot enforce CORS, so
// this asserts the request shape rather than reproducing the block.
const [, options] = apiGetFn.mock.calls[0] as [string, Record<string, unknown>];
expect(options).not.toHaveProperty("credentials");
}); });
it("throws ApiError on 404 without inventing a filename", async () => { it("throws ApiError on 404 without inventing a filename", async () => {