Skip to content

Bearer authentication rejects every token: jwt-decode v4 has no default export #499

Description

@Santoshkumarpuppala

app/lib/authn-bearer.js:5 loads jwt-decode as const jwtDecoder = require('jwt-decode');, but package.json pins ^4.0.0 and v4 has no default export: require('jwt-decode') returns { InvalidTokenError, jwtDecode }. The call at :155 throws a TypeError, the catch at :156-157 passes it to done(null, false, err), and every Bearer request is rejected, including the token the API issues itself through the apikey challenge. Confirmed on main (6e6bf51); the same line and pin are on next (a69abef).

Run on main with Node 22, npx mocha --exit app/tests/authn/challenge-apikey-service.spec.js:

  • as shipped: 7 passing, 1 failing, GET /api/session returns the session: expected 200, got 401.
  • import changed to const { jwtDecode: jwtDecoder } = require('jwt-decode');: still 7/1, but now returns not authorized with an invalid token gets 500 instead of 401, because the catch forwards the InvalidTokenError object.
  • import change plus } catch { return done(null, false, { message: 'Invalid token' }); }: 8 passing.

OIDC client-credentials tokens go through the same call at :155 before the alg branch. I read that path; I did not run it, since I have no IdP here.

CI doesn't see this. npm test (package.json:29) does not include test:authn, and CI runs npm run coverage:cobertura (.github/workflows/ci.yml:74), which is c8 … npm test. npm run test:authn also exits 0 when specs fail: app/tests/run-mocha-separate-jobs.sh:3 uses find … -exec npx mocha {} \;, and find ignores the command's exit status (find . -maxdepth 0 -exec false \; exits 0; with {} + it exits 1). At HEAD it reported 6 failing specs and exited 0. Some of those need a local Keycloak, so running it in CI would need its own setup.

Happy to open the PR with the two-line fix against main, or next if you prefer. CONTRIBUTING points at develop, which I couldn't find.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions