Composition: Handle 401 responses with loginUrl from Chromatic#33705
Merged
Conversation
Chromatic is changing their endpoints to return 401 instead of 200 when authentication is required. This change adds support for extracting loginUrl from 401 response bodies in addition to the existing 200 handling.
|
View your CI Pipeline Execution ↗ for commit d29589d
☁️ Nx Cloud last updated this comment at |
Contributor
📝 WalkthroughWalkthroughThe PR adds authentication error handling for Storybook references. It exports the previously internal Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes ✨ Finishing touches
Comment |
JReinhold
approved these changes
Jan 29, 2026
Merged
10 tasks
valentinpalkovic
pushed a commit
that referenced
this pull request
Jan 30, 2026
Composition: Handle 401 responses with loginUrl from Chromatic (cherry picked from commit afdf02a)
24 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #
What I did
Chromatic is changing their endpoints to return HTTP 401 instead of 200 when authentication is required for private Storybooks. Previously, they returned
200 OKwith{ loginUrl: "..." }in the response body. After this change, they will return401 Unauthorizedwith the same{ loginUrl: "..." }body.This PR updates the refs/composition feature to handle both scenarios:
refs.ts): ExtractloginUrlfrom 401 response bodies inhandleRequest()get-storybook-refs.ts): Already returnsfalsefor 401 (no change needed), exportedcheckReffor testingNote for Chromatic
Chromatic can only roll out this change (returning 401 instead of 200) after deprecating Storybook < 10.2. Until then, the following endpoints must continue returning
200 OKwith{ loginUrl: "..." }for backwards compatibility:GET /index.jsonGET /stories.jsonGET /metadata.jsonNote:
/iframe.htmldoes not need to be in this list - both 200 withloginUrland 401 result in the same behavior: the build-time check marks the ref astype: 'unknown', which triggers the runtime fetch with credentials.Checklist for Contributors
Testing
The changes in this PR are covered in the following automated tests:
Manual testing
Caution
This section is mandatory for all contributions. If you believe no manual test is necessary, please state so explicitly. Thanks!
Manual testing was performed with the following steps:
Added a private Chromatic ref to
code/.storybook/main.ts:Ran
yarn nx run-many -t compileandyarn storybook:uiCreated a Playwright test that intercepts requests and returns 401 with
loginUrl:Verified that clicking the "Private (auth test)" ref in the sidebar shows "Sign in to browse this Storybook" with a login button
Documentation
MIGRATION.MD
Checklist for Maintainers
When this PR is ready for testing, make sure to add
ci:normal,ci:mergedorci:dailyGH label to it to run a specific set of sandboxes. The particular set of sandboxes can be found incode/lib/cli-storybook/src/sandbox-templates.tsMake sure this PR contains one of the labels below:
Available labels
bug: Internal changes that fixes incorrect behavior.maintenance: User-facing maintenance tasks.dependencies: Upgrading (sometimes downgrading) dependencies.build: Internal-facing build tooling & test updates. Will not show up in release changelog.cleanup: Minor cleanup style change. Will not show up in release changelog.documentation: Documentation only changes. Will not show up in release changelog.feature request: Introducing a new feature.BREAKING CHANGE: Changes that break compatibility in some way with current major version.other: Changes that don't fit in the above categories.🦋 Canary release
This PR does not have a canary release associated. You can request a canary release of this pull request by mentioning the
@storybookjs/coreteam here.core team members can create a canary release here or locally with
gh workflow run --repo storybookjs/storybook publish.yml --field pr=<PR_NUMBER>