Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[sdk/local-evaluation] Duplicate identity override entries silently drop feature overrides

Open
#267 5 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
68/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Quiet
Tech stack
nodejs, typescript
Domain
backend

Research direction

Start at the local-evaluation path used by getIdentityFlags and trace how duplicate identity_overrides entries are represented for one identifier. Reproduce the payload with separate some_feature and mv_feature entries, then verify both overrides and enabled states are returned instead of falling back to the environment default.

Written by the indexing model from the issue text.

Description

Problem

When an environment document returned by the Flagsmith API contains more than one entry in identity_overrides sharing the same identifier, the SDK keeps only the last entry for that identifier during local evaluation. Any identity_features defined on the earlier entries are discarded, so the corresponding flags fall back to the environment default instead of the configured override.

For example, given an environment payload like:

{
  "identity_overrides": [
    {
      "identifier": "multi-override-id",
      "identity_features": [
        {
          "feature": { "name": "some_feature" },
          "feature_state_value": "override-from-first-entry",
          "enabled": false
        }
      ]
    },
    {
      "identifier": "multi-override-id",
      "identity_features": [
        {
          "feature": { "name": "mv_feature" },
          "feature_state_value": "override-from-second-entry",
          "enabled": true
        }
      ]
    }
  ]
}

Calling getIdentityFlags('multi-override-id') with local evaluation enabled returns the override for mv_feature only. some_feature resolves to its environment default, as if the first entry never existed.

Impact

Any identifier whose overrides arrive split across multiple identity_overrides entries gets the wrong flag values during server-side local evaluation. The breakage is silent (no warning, no error) and deterministic for a given payload, so affected identifiers stay broken on every request until the environment payload changes shape.

Reproduction

  1. Use an environment whose identity_overrides array contains two entries with the same identifier, each carrying a different feature in identity_features (e.g. entry A overrides some_feature, entry B overrides mv_feature).
  2. Initialise the SDK with enableLocalEvaluation: true and call getIdentityFlags('<that-identifier>').
  3. Observed: only the features from the last entry are applied. some_feature resolves to its environment default instead of "override-from-first-entry".
  4. Expected: both some_feature and mv_feature resolve to their respective override values and enabled states.
Dominant language
TypeScript
Stars
30
Forks
27
Avg merge
20h 52m
Merged PRs (30d)
6

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from Flagsmith/flagsmith-nodejs-client

All issues in Flagsmith/flagsmith-nodejs-client

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.