Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

google-auth-library: JWT with a JSON keyFile signs without iss since 10.6.1 (invalid_grant: account not found)

Abierto Apto para principiantes
#9,469 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

@Marinski ya está trabajando en esto.

Desde el 29/9/2026.

  • #9470 de @Marinski — abierto

Evaluación

Dificultad
2/5
Tiempo estimado
1-3 horas
Aptitud para principiantes
85/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
nodejs, typescript

Línea de trabajo

Comienza en src/gtoken, en TokenHandler.processCredentials() y buildPayloadForJwsSign(), y después revisa los casos de keyFile en test/test.jwt.ts. Reproduce el claim iss ausente con una keyFile que omita email, añade cobertura de regresión para el valor client_email y ejecuta las pruebas de JWT para confirmar que el claim se ha restaurado.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Library Name

google-auth-library

Versions

Broken: 10.6.1 through 11.1.0 (latest). Works: 10.5.0 and earlier.
Node.js 22 and 24, Linux.

Description

A JWT client built from a JSON keyFile, with no email option, signs its token request with no iss claim. Google's token endpoint rejects it:

invalid_grant: Invalid grant: account not found

The same key works when email and key are passed explicitly, and it worked with the same keyFile code up to 10.5.0.

Reproduction

The transporter is stubbed and the key is a throwaway, so nothing is sent to Google:

// key.json: {"type":"service_account","client_email":"[email protected]","private_key":"<any RSA PEM>"}
const {JWT} = require('google-auth-library');

const client = new JWT({
  keyFile: './key.json',
  scopes: ['https://www.googleapis.com/auth/drive.readonly'],
});
client.transporter = {
  request: async opts => {
    const assertion = new URLSearchParams(opts.data).get('assertion');
    const claims = JSON.parse(Buffer.from(assertion.split('.')[1], 'base64url'));
    console.log(require('google-auth-library/package.json').version, 'iss =', claims.iss);
    return {data: {access_token: 't', expires_in: 3600}};
  },
};
client.getAccessToken();
10.5.0 iss = [email protected]
10.6.1 iss = undefined
11.1.0 iss = undefined
Cause

When gtoken was brought into this package (src/gtoken), the keyFile handling changed:

  • GoogleToken's constructor sets iss from email. With only a keyFile, email is still empty at that point.
  • TokenHandler.processCredentials() reads the key file later and sets tokenOptions.key and tokenOptions.email, but not tokenOptions.iss.
  • buildPayloadForJwsSign() signs tokenOptions.iss, so the claim is undefined.

The standalone gtoken package did this.iss = creds.clientEmail || this.iss after reading the key file.

The existing tests don't catch it because every keyFile test in test/test.jwt.ts also passes email.

Expected behavior

The client_email from a JSON key file is used as iss, as before 10.6.1.

Workaround

Read the key file yourself and pass new JWT({email: key.client_email, key: key.private_key, scopes}).

I'll open a PR with a fix and tests.

Lenguaje dominante
TypeScript
Estrellas
3.2k
Forks
723
Merge medio
3 d 2 h
PR fusionados (30 d)
172

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de googleapis/google-cloud-node

Todos los issues de googleapis/google-cloud-node

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.