google-auth-library: JWT with a JSON keyFile signs without iss since 10.6.1 (invalid_grant: account not found)
Los mantenedores suelen responder en 1 día
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 85/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- nodejs, typescript
- Área
- authentication
Línea de trabajo
Comienza en src/gtoken, en TokenHandler.processCredentials() y buildPayloadForJwsSign(), y después revisa los casos de keyFile en test/test.jwt.ts. Reproduce el claim iss ausente con una keyFile que omita email, añade cobertura de regresión para el valor client_email y ejecuta las pruebas de JWT para confirmar que el claim se ha restaurado.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Library Name
google-auth-library
Versions
Broken: 10.6.1 through 11.1.0 (latest). Works: 10.5.0 and earlier.
Node.js 22 and 24, Linux.
Description
A JWT client built from a JSON keyFile, with no email option, signs its token request with no iss claim. Google's token endpoint rejects it:
invalid_grant: Invalid grant: account not found
The same key works when email and key are passed explicitly, and it worked with the same keyFile code up to 10.5.0.
Reproduction
The transporter is stubbed and the key is a throwaway, so nothing is sent to Google:
// key.json: {"type":"service_account","client_email":"[email protected]","private_key":"<any RSA PEM>"}
const {JWT} = require('google-auth-library');
const client = new JWT({
keyFile: './key.json',
scopes: ['https://www.googleapis.com/auth/drive.readonly'],
});
client.transporter = {
request: async opts => {
const assertion = new URLSearchParams(opts.data).get('assertion');
const claims = JSON.parse(Buffer.from(assertion.split('.')[1], 'base64url'));
console.log(require('google-auth-library/package.json').version, 'iss =', claims.iss);
return {data: {access_token: 't', expires_in: 3600}};
},
};
client.getAccessToken();
10.5.0 iss = [email protected]
10.6.1 iss = undefined
11.1.0 iss = undefined
Cause
When gtoken was brought into this package (src/gtoken), the keyFile handling changed:
GoogleToken's constructor setsissfromemail. With only akeyFile,emailis still empty at that point.TokenHandler.processCredentials()reads the key file later and setstokenOptions.keyandtokenOptions.email, but nottokenOptions.iss.buildPayloadForJwsSign()signstokenOptions.iss, so the claim isundefined.
The standalone gtoken package did this.iss = creds.clientEmail || this.iss after reading the key file.
The existing tests don't catch it because every keyFile test in test/test.jwt.ts also passes email.
Expected behavior
The client_email from a JSON key file is used as iss, as before 10.6.1.
Workaround
Read the key file yourself and pass new JWT({email: key.client_email, key: key.private_key, scopes}).
I'll open a PR with a fix and tests.
- Lenguaje dominante
- TypeScript
- Estrellas
- 3.2k
- Forks
- 723
- Merge medio
- 3 d 2 h
- PR fusionados (30 d)
- 172
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de googleapis/google-cloud-node
-
api: spanner
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
googleapis/google-cloud-node#9513 ·
Los mantenedores suelen responder en 1 día
-
priority: p1 samples type: bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
googleapis/google-cloud-node#9367 ·
Los mantenedores suelen responder en 1 día
-
bug(gapic-node-processing): setOnlyDefaultSystemTests incorrectly matches substring on absolute pathPosiblemente ocupada @rootkiller6788 la tomó hace 3 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
googleapis/google-cloud-node#9342 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
TransferManager uploadFileInChunks does not error when abortedPosiblemente ocupada @Om-singhaI la tomó hace 46 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
googleapis/google-cloud-node#9193 ·
Los mantenedores suelen responder en 1 día
-
google-auth-library: getErrorFromOAuthErrorResponse() copies stack as non-writable, breaking error decoration in consumersPosiblemente ocupada @Om-singhaI la tomó hace 46 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
googleapis/google-cloud-node#9155 ·
Los mantenedores suelen responder en 1 día
Todos los issues de googleapis/google-cloud-node
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 1-3 horas Aptitud para principiantes 84/100
answerLoops/answerLoops#345 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 82/100
siyuan-note/siyuan#20313 ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
LanternOps/breeze#8254 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 1-3 horas Aptitud para principiantes 82/100
gofish-graphics/gofish-graphics#1084 ·
Los mantenedores suelen responder en 1 día