Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Bearer authentication rejects every token: jwt-decode v4 has no default export

Đang mở Phù hợp với người mới
#499 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
86/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
javascript, node.js

Hướng nghiên cứu

Bắt đầu trong app/lib/authn-bearer.js tại phần import jwt-decode và lời gọi quanh các dòng 155-157, sau đó chạy npx mocha --exit app/tests/authn/challenge-apikey-service.spec.js. Được xem là hoàn tất khi yêu cầu session bằng token đã cấp thành công và các token không hợp lệ vẫn trả về 401, với cả 8 authentication spec đều pass. Xem lại package.json và app/tests/run-mocha-separate-jobs.sh nếu thêm coverage cho các lỗi authentication hiện đang bị che khuất.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

app/lib/authn-bearer.js:5 loads jwt-decode as const jwtDecoder = require('jwt-decode');, but package.json pins ^4.0.0 and v4 has no default export: require('jwt-decode') returns { InvalidTokenError, jwtDecode }. The call at :155 throws a TypeError, the catch at :156-157 passes it to done(null, false, err), and every Bearer request is rejected, including the token the API issues itself through the apikey challenge. Confirmed on main (6e6bf51); the same line and pin are on next (a69abef).

Run on main with Node 22, npx mocha --exit app/tests/authn/challenge-apikey-service.spec.js:

  • as shipped: 7 passing, 1 failing, GET /api/session returns the session: expected 200, got 401.
  • import changed to const { jwtDecode: jwtDecoder } = require('jwt-decode');: still 7/1, but now returns not authorized with an invalid token gets 500 instead of 401, because the catch forwards the InvalidTokenError object.
  • import change plus } catch { return done(null, false, { message: 'Invalid token' }); }: 8 passing.

OIDC client-credentials tokens go through the same call at :155 before the alg branch. I read that path; I did not run it, since I have no IdP here.

CI doesn't see this. npm test (package.json:29) does not include test:authn, and CI runs npm run coverage:cobertura (.github/workflows/ci.yml:74), which is c8 … npm test. npm run test:authn also exits 0 when specs fail: app/tests/run-mocha-separate-jobs.sh:3 uses find … -exec npx mocha {} \;, and find ignores the command's exit status (find . -maxdepth 0 -exec false \; exits 0; with {} + it exits 1). At HEAD it reported 6 failing specs and exited 0. Some of those need a local Keycloak, so running it in CI would need its own setup.

Happy to open the PR with the two-line fix against main, or next if you prefer. CONTRIBUTING points at develop, which I couldn't find.

Ngôn ngữ chính
JavaScript
Star
57
Fork
18
Merge trung bình
1 ngày 26 phút
Pull request đã merge (30 ngày)
7

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của mitre-attack/attack-workbench-rest-api

Tất cả issue của mitre-attack/attack-workbench-rest-api

Issue tương tự

Thêm issue về JavaScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.