app/lib/authn-bearer.js:5 loads jwt-decode as const jwtDecoder = require('jwt-decode');, but package.json pins ^4.0.0 and v4 has no default export: require('jwt-decode') returns { InvalidTokenError, jwtDecode }. The call at :155 throws a TypeError, the catch at :156-157 passes it to done(null, false, err), and every Bearer request is rejected, including the token the API issues itself through the apikey challenge. Confirmed on main (6e6bf51); the same line and pin are on next (a69abef).
Run on main with Node 22, npx mocha --exit app/tests/authn/challenge-apikey-service.spec.js:
- as shipped: 7 passing, 1 failing,
GET /api/session returns the session: expected 200, got 401.
- import changed to
const { jwtDecode: jwtDecoder } = require('jwt-decode');: still 7/1, but now returns not authorized with an invalid token gets 500 instead of 401, because the catch forwards the InvalidTokenError object.
- import change plus
} catch { return done(null, false, { message: 'Invalid token' }); }: 8 passing.
OIDC client-credentials tokens go through the same call at :155 before the alg branch. I read that path; I did not run it, since I have no IdP here.
CI doesn't see this. npm test (package.json:29) does not include test:authn, and CI runs npm run coverage:cobertura (.github/workflows/ci.yml:74), which is c8 … npm test. npm run test:authn also exits 0 when specs fail: app/tests/run-mocha-separate-jobs.sh:3 uses find … -exec npx mocha {} \;, and find ignores the command's exit status (find . -maxdepth 0 -exec false \; exits 0; with {} + it exits 1). At HEAD it reported 6 failing specs and exited 0. Some of those need a local Keycloak, so running it in CI would need its own setup.
Happy to open the PR with the two-line fix against main, or next if you prefer. CONTRIBUTING points at develop, which I couldn't find.
app/lib/authn-bearer.js:5loads jwt-decode asconst jwtDecoder = require('jwt-decode');, butpackage.jsonpins^4.0.0and v4 has no default export:require('jwt-decode')returns{ InvalidTokenError, jwtDecode }. The call at:155throws aTypeError, the catch at:156-157passes it todone(null, false, err), and every Bearer request is rejected, including the token the API issues itself through the apikey challenge. Confirmed onmain(6e6bf51); the same line and pin are onnext(a69abef).Run on
mainwith Node 22,npx mocha --exit app/tests/authn/challenge-apikey-service.spec.js:GET /api/session returns the session: expected 200, got 401.const { jwtDecode: jwtDecoder } = require('jwt-decode');: still 7/1, but nowreturns not authorized with an invalid tokengets 500 instead of 401, because the catch forwards theInvalidTokenErrorobject.} catch { return done(null, false, { message: 'Invalid token' }); }: 8 passing.OIDC client-credentials tokens go through the same call at
:155before thealgbranch. I read that path; I did not run it, since I have no IdP here.CI doesn't see this.
npm test(package.json:29) does not includetest:authn, and CI runsnpm run coverage:cobertura(.github/workflows/ci.yml:74), which isc8 … npm test.npm run test:authnalso exits 0 when specs fail:app/tests/run-mocha-separate-jobs.sh:3usesfind … -exec npx mocha {} \;, andfindignores the command's exit status (find . -maxdepth 0 -exec false \;exits 0; with{} +it exits 1). At HEAD it reported 6 failing specs and exited 0. Some of those need a local Keycloak, so running it in CI would need its own setup.Happy to open the PR with the two-line fix against
main, ornextif you prefer. CONTRIBUTING points atdevelop, which I couldn't find.