Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

google-auth-library: JWT with a JSON keyFile signs without iss since 10.6.1 (invalid_grant: account not found)

Aperta Adatta ai principianti
#9,469 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@Marinski ci sta già lavorando.

Dal 29/9/2026.

  • #9470 di @Marinski — aperta

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
85/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
nodejs, typescript

Direzione di ricerca

Inizia in src/gtoken da TokenHandler.processCredentials() e buildPayloadForJwsSign(), quindi leggi i casi di keyFile in test/test.jwt.ts. Riproduci il claim iss mancante con una keyFile che omette email, aggiungi la copertura di regressione per il valore client_email ed esegui i test JWT per confermare che il claim sia stato ripristinato.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Library Name

google-auth-library

Versions

Broken: 10.6.1 through 11.1.0 (latest). Works: 10.5.0 and earlier.
Node.js 22 and 24, Linux.

Description

A JWT client built from a JSON keyFile, with no email option, signs its token request with no iss claim. Google's token endpoint rejects it:

invalid_grant: Invalid grant: account not found

The same key works when email and key are passed explicitly, and it worked with the same keyFile code up to 10.5.0.

Reproduction

The transporter is stubbed and the key is a throwaway, so nothing is sent to Google:

// key.json: {"type":"service_account","client_email":"[email protected]","private_key":"<any RSA PEM>"}
const {JWT} = require('google-auth-library');

const client = new JWT({
  keyFile: './key.json',
  scopes: ['https://www.googleapis.com/auth/drive.readonly'],
});
client.transporter = {
  request: async opts => {
    const assertion = new URLSearchParams(opts.data).get('assertion');
    const claims = JSON.parse(Buffer.from(assertion.split('.')[1], 'base64url'));
    console.log(require('google-auth-library/package.json').version, 'iss =', claims.iss);
    return {data: {access_token: 't', expires_in: 3600}};
  },
};
client.getAccessToken();
10.5.0 iss = [email protected]
10.6.1 iss = undefined
11.1.0 iss = undefined
Cause

When gtoken was brought into this package (src/gtoken), the keyFile handling changed:

  • GoogleToken's constructor sets iss from email. With only a keyFile, email is still empty at that point.
  • TokenHandler.processCredentials() reads the key file later and sets tokenOptions.key and tokenOptions.email, but not tokenOptions.iss.
  • buildPayloadForJwsSign() signs tokenOptions.iss, so the claim is undefined.

The standalone gtoken package did this.iss = creds.clientEmail || this.iss after reading the key file.

The existing tests don't catch it because every keyFile test in test/test.jwt.ts also passes email.

Expected behavior

The client_email from a JSON key file is used as iss, as before 10.6.1.

Workaround

Read the key file yourself and pass new JWT({email: key.client_email, key: key.private_key, scopes}).

I'll open a PR with a fix and tests.

Lingua principale
TypeScript
Stelle
3.2k
Fork
721
Merge medio
3g 7h
PR unite (30g)
149

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di googleapis/google-cloud-node

Tutte le issue di googleapis/google-cloud-node

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.