From 97271dae38a8ca3011cac310a93bf719550fa28f Mon Sep 17 00:00:00 2001 From: scanash00 Date: Fri, 12 Jun 2026 11:16:04 -0800 Subject: [PATCH] Stop sending service-auth through the batch proxy (caused 400s) Slingshot's hydrateQueryResponse batch proxy rejects requests that include an authorization field - it returns 400 whenever the field is present, regardless of whether the token is valid (verified live: identical request 400s with the field, succeeds without it). The earlier service-auth wiring therefore made every logged-in custom-feed batch fetch 400, which collapsed buildCustomFeed to an empty page on re-fetch. Revert to the logged-out-only batch path: logged-in users use the AppView, which forwards viewer auth correctly for personalized feeds. The batch path keeps its speed win for logged-out browsing. --- src/lib/api/feed/custom.ts | 26 ++++++-------------------- 1 file changed, 6 insertions(+), 20 deletions(-) diff --git a/src/lib/api/feed/custom.ts b/src/lib/api/feed/custom.ts index 6f3f690..5ff27f7 100644 --- a/src/lib/api/feed/custom.ts +++ b/src/lib/api/feed/custom.ts @@ -52,30 +52,16 @@ export class CustomFeedAPI implements FeedAPI { cursor: string | undefined limit: number }): Promise { - // Microcosm batch path: Slingshot proxies the feed generator's skeleton and - // fetches all post records in one request. For personalized feeds we forward - // a service-auth token (aud = the feed generator's DID) so the generator can - // identify the viewer — same as the AppView would. - if (MICROCOSM_ENABLED) { + // Microcosm batch path: Slingshot proxies the feed generator's PUBLIC + // skeleton and fetches all post records in one request. Slingshot's batch + // proxy rejects a forwarded auth token (returns 400), so we only use this + // path logged out. Logged-in users go through the AppView below, which + // forwards the viewer's auth correctly (needed for personalized feeds). + if (MICROCOSM_ENABLED && !this.agent.did) { try { const page = await buildCustomFeed(this.params.feed, { - viewerDid: this.agent.did, limit, cursor, - getAuthorization: this.agent.did - ? async (feedGenDid: string) => { - try { - const {data} = - await this.agent.com.atproto.server.getServiceAuth({ - aud: feedGenDid, - lxm: 'app.bsky.feed.getFeedSkeleton', - }) - return data.token - } catch { - return undefined - } - } - : undefined, }) if (page.feed.length) { return {cursor: page.cursor, feed: page.feed} -- 2.51.2