Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

buildProviderConfig lets an undefined option overwrite the preset (e.g. scope from onResolveProvider)

Open Beginner friendly
#243 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 5 days

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
86/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
typescript

Research direction

Start at buildProviderConfig in src/lib/config.ts, then compare its behavior with the built output in dist/lib/config.js and the scope handling noted in dist/lib/OAuthProvider.js. Add the requested unit test for a Google config resolved with scope: undefined and verify that the preset retains 'openid profile email' while explicit null or empty-string values remain distinguishable.

Written by the indexing model from the issue text.

Description

What happens

buildProviderConfig (src/lib/config.ts) copies every key of the caller's provider options into expandedOptions, including keys whose value is undefined, then builds the config as { ...pluginDefaults, ...providerPreset, ...expandedOptions, redirectUri }. An option present with value undefined therefore overwrites the preset's value.

The common trigger is a dynamic provider from onResolveProvider: a hook that returns a config object built from a database row naturally writes scope: row.scope, which is undefined when the row has no custom scope. For the Google preset that replaces 'openid profile email' with undefined, OAuthProvider then sends scope: this.config.scope || '', and Google rejects the authorization request (an empty scope). The same shape can clear any preset default (usernameClaim, issuer, jwksUri, …) that a hook passes through unset.

Verified by reading the 2.7.0 build (dist/lib/config.js ~L205-L262, dist/lib/OAuthProvider.js ~L59); found through a consumer whose resolver returns scope: config.scope for every org provider.

Expected

An option whose value is undefined means "not specified" and must not override the plugin default or the preset. Skip undefined values when building expandedOptions (keep null/'' as explicit values if that's the intended contract, and document it), with a unit test: a Google config resolved with scope: undefined ends up with 'openid profile email'.

Dominant language
JavaScript
Stars
1
Forks
2
Avg merge
3d 8h
Merged PRs (30d)
11

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from HarperFast/oauth

All issues in HarperFast/oauth

Similar issues

More JavaScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.