buildProviderConfig lets an undefined option overwrite the preset (e.g. scope from onResolveProvider)
Maintainers usually reply within 5 days
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 86/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- typescript
- Domain
- authentication
Research direction
Start at buildProviderConfig in src/lib/config.ts, then compare its behavior with the built output in dist/lib/config.js and the scope handling noted in dist/lib/OAuthProvider.js. Add the requested unit test for a Google config resolved with scope: undefined and verify that the preset retains 'openid profile email' while explicit null or empty-string values remain distinguishable.
Written by the indexing model from the issue text.
Description
What happens
buildProviderConfig (src/lib/config.ts) copies every key of the caller's provider options into expandedOptions, including keys whose value is undefined, then builds the config as { ...pluginDefaults, ...providerPreset, ...expandedOptions, redirectUri }. An option present with value undefined therefore overwrites the preset's value.
The common trigger is a dynamic provider from onResolveProvider: a hook that returns a config object built from a database row naturally writes scope: row.scope, which is undefined when the row has no custom scope. For the Google preset that replaces 'openid profile email' with undefined, OAuthProvider then sends scope: this.config.scope || '', and Google rejects the authorization request (an empty scope). The same shape can clear any preset default (usernameClaim, issuer, jwksUri, …) that a hook passes through unset.
Verified by reading the 2.7.0 build (dist/lib/config.js ~L205-L262, dist/lib/OAuthProvider.js ~L59); found through a consumer whose resolver returns scope: config.scope for every org provider.
Expected
An option whose value is undefined means "not specified" and must not override the plugin default or the preset. Skip undefined values when building expandedOptions (keep null/'' as explicit values if that's the intended contract, and document it), with a unit test: a Google config resolved with scope: undefined ends up with 'openid profile email'.
- Dominant language
- JavaScript
- Stars
- 1
- Forks
- 2
- Avg merge
- 3d 8h
- Merged PRs (30d)
- 11
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from HarperFast/oauth
-
Difficulty 1/5 Under an hour Newbie friendliness 82/100
HarperFast/oauth#207 ·
Maintainers usually reply within 5 days
-
Provider-type check in the 2.7.0 evidence path is case-sensitive while preset resolution is notOpen
Difficulty 3/5 1-2 days Newbie friendliness 76/100
HarperFast/oauth#242 ·
Maintainers usually reply within 5 days
-
Difficulty 3/5 1-2 days Newbie friendliness 68/100
HarperFast/oauth#240 ·
Maintainers usually reply within 5 days
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
HarperFast/oauth#231 · 1 comment ·
Maintainers usually reply within 5 days
-
enhancement
Difficulty 4/5 3-5 days Newbie friendliness 68/100
HarperFast/oauth#230 · 1 comment ·
Maintainers usually reply within 5 days
All issues in HarperFast/oauth
Similar issues
-
refactor
Difficulty 2/5 Half a day Newbie friendliness 84/100
Maintainers usually reply within 5 days
-
translation
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
ciderapp/translations#87 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 67/100
Maintainers usually reply within 1 day
-
component: split-view platform: windows
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
zen-browser/desktop#15616 · 1 reaction ·
Maintainers usually reply within 1 day