Skip to content

fix: name the claim when JWT aud, iss, or nbf validation fails - #171

Merged
mandarini merged 3 commits into
mainfrom
fix/name-aud-iss-claim-failures
Sep 18, 2026
Merged

mandarini merged 3 commits into
mainfrom
fix/name-aud-iss-claim-failures

Conversation

@mandarini

@mandarini mandarini commented Sep 18, 2026 •

Copy link
Copy Markdown
Collaborator

A JWT that fails a claim check used to reject with the generic "a registered claim failed validation" and a hint about the server clock. The claim-validation branch now reads the claim and reason jose reports: a claim with the wrong type is reported as malformed whatever its name, a mismatched or missing aud / iss names the claim and the hint points at the audience / issuer option, since #160 made those the first checks driven by server configuration, a future nbf keeps its clock hint, and any other claim is named with a generic hint. An empty audience or issuer array now hits the same empty-option guard as an empty string instead of surfacing as a mismatch. The status stays 401 and the failure kind stays token, because the same jose error covers a mistyped option and a token from another project. Nine tests cover the new branches, and the reason table in docs/error-handling.md lists every message the code emits.

@mandarini
mandarini requested review from a team as code owners September 18, 2026 12:34
@pkg-pr-new

pkg-pr-new Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@supabase/server@171

commit: 2a7fcf0

@mandarini
mandarini merged commit a94e5e2 into main Sep 18, 2026
10 checks passed
@mandarini
mandarini deleted the fix/name-aud-iss-claim-failures branch September 18, 2026 14:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants