[BREAKING] feat!: remove Authentication layer - #1390
Conversation
…uth-js BREAKING CHANGE: removes AuthenticationClient and UserInfoClient from the auth0 package. Management API token acquisition now delegates to @auth0/auth0-auth-js AuthClient.getTokenByClientCredentials. mTLS now requires an explicit fetch option. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…p any cast
Match published TelemetryConfig ({enabled:false} | {enabled?:true,name,version});
drop unsupported env field; type options as AuthClientOptions.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ent token tests - Delete obsolete tests/auth/**, tests/userinfo/**, tests/lib/runtime.test.ts - Rewrite token-provider test to mock @auth0/auth0-auth-js AuthClient (8 cases: both credential modes, cache hit, leeway refresh with expiresAt*1000 boundary, in-flight dedup, error propagation, error-not-cached, expiry) - Add export-surface test asserting AuthenticationClient/UserInfoClient removed - jest: map @auth0/auth0-auth-js to CJS stub for unit/wire (avoids ESM openid-client under Jest CJS runtime); allow openid-client/oauth4webapi transform in root-tests ESM project Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- README: replace AuthenticationClient/UserInfoClient sections with pointers to @auth0/auth0-auth-js; add 'Migrating from v6 to v7' with method-mapping table and mTLS note; preserve auth0/legacy docs - CHANGELOG: v7.0.0 breaking-change entry - token-provider: doc comment on @auth0/auth0-auth-js delegation + expiresAt seconds-to-ms conversion Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…dd TC-2.9/2.10 Throw at construction when useMTLS=true and no fetch is provided, preventing silent 401s at request time. Replace (options as any).fetch with a typed intersection narrowing. Add comments documenting the telemetry env-field delta and node-auth0 identity intent. Add TC-2.9 and TC-2.10 covering both paths. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…t credentials grant Replace the auth0-auth-js AuthClient delegation with a self-contained raw fetch + jose implementation. The dep added openid-client and oauth4webapi as transitive dependencies for what amounts to a single POST to /oauth/token. Key changes: - Inline fetchToken(): URLSearchParams body, Content-Type header, response parsing - Client-assertion path: importPKCS8 + SignJWT via jose (already a dep) - mTLS: forward caller-supplied fetch; guard against useMTLS + clientAssertion combination (mutually exclusive auth methods) - Domain validation: reject domains containing slashes or query strings - Telemetry header: use jose base64url.encode instead of Buffer (portability) - expiresAt computed as Date.now() + expires_in * 1000 (relative, same as pre-v7) - Add TC-2.11 (domain validation) and TC-2.12 (mTLS+assertion guard); 13/13 pass Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Delete tests/lib/utils.test.ts — tests resolveValueToPromise which was removed from src/utils.ts as auth-only dead code - Add fetch mock to mTLS test in management-client-custom-domain.test.ts — TokenProvider now throws at construction when useMTLS=true and no fetch is provided (fail-fast guard added in previous commit) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## master #1390 +/- ##
==========================================
- Coverage 89.73% 89.40% -0.33%
==========================================
Files 441 429 -12
Lines 20799 20380 -419
Branches 10146 9723 -423
==========================================
- Hits 18663 18221 -442
- Misses 2136 2159 +23
Flags with carried forward coverage won't be shown. Click here to find out more.
🚀 New features to boost your workflow:
|
…erated mTLS token acquisition reads options.fetch which is defined on BaseClientOptions in the Fern-generated BaseClient.ts. Add a comment at the usage site so the dependency survives future regenerations. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…th-js mock artifacts - Forward plain-string options.headers to POST /oauth/token, matching the behavior fixed in v6 via PR #1392. Supplier-function headers are skipped (require async resolution, not supported on the token endpoint path). SDK-controlled headers (Content-Type, Auth0-Client) always take precedence. - Delete src/management/tests/__mocks__/auth0-auth-js.cjs — leftover CJS stub from when TokenProvider delegated to @auth0/auth0-auth-js; no longer needed. - Remove three moduleNameMapper entries for @auth0/auth0-auth-js from jest.config.mjs. - Add TC-2.13 covering plain-string forwarding, supplier filtering, and override precedence. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
… error
- Token endpoint uses `mtls.{domain}` when useMTLS is set
- Normalize all user-supplied header keys to lowercase before SDK headers override
- Wrap fetch in AbortSignal.timeout(10_000); timeout throws ManagementError(408)
- Non-2xx response parses JSON body first, falls back to text, throws ManagementError
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
useMTLS + clientAssertionSigningKey throws at construction — they are mutually exclusive auth methods. Removing useMTLS from WithClientAssertion prevents the type from advertising an impossible configuration. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- makeErrorResponse upgraded to 3-param with JSON body (errorCode, description)
- TC-2.6, TC-2.7: assert ManagementError instance + statusCode instead of regex
- TC-2.9: assert mTLS-prefixed token URL (mtls.{domain})
- TC-2.13: update header key assertions to lowercase (matches normalization)
- TC-2.14: header case normalization — user lowercase key overridden by SDK
- TC-2.15: ManagementError carries statusCode and parsed OAuth error body
- TC-2.16: AbortSignal timeout throws ManagementError(408)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Two entries were accidentally merged into one line `*.lcov.forge/` which matched neither pattern correctly. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Fix 4 broken links: auth0/node-auth0/tree/.../auth0-auth-js -> auth0/auth0-auth-js/tree/...
- Fix method mapping table: database.signUp/changePassword use nested namespace
- Fix passwordless login* methods: split into challenge + getTokenByPasswordlessDbConnection
- Fix sendSMS -> sendSms (correct camelCase)
- Remove non-existent getUserInfo: no such method in auth0-auth-js; document workarounds
- Add AuthApiError -> ManagementError migration section with before/after examples
- Add mTLS breaking changes block: explicit fetch required, mtls.{domain} automatic, mutually
exclusive with clientAssertionSigningKey
- Update User Profile Information section to reflect actual available APIs
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This package was removed from package.json in 53d0879 but its yarn.lock entry remained. Removing the unreferenced entry. Three other packages (jose, oauth4webapi, openid-client) still resolve to the internal Artifactory registry — these will be cleaned up in a separate PR once yarn can reach the public registry in CI. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
getUserInfo shipped in auth0-auth-js db2435c. Update the User Profile
Information section and migration table to point at
authClient.getUserInfo({ accessToken }) with correct MRRT audience guidance.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
The auth-separation commit introduced yarn.lock entries resolving to the internal a0us.jfrog.io Artifactory, which returns 401 for external contributors on this public repo. jose@^6, oauth4webapi, and openid-client were transitive dependencies of @auth0/auth0-auth-js, which was reverted out of package.json. Remove the three now-unreferenced blocks so no entry points at a host external contributors cannot reach. The runtime jose dependency resolves via jose@^5 from the public registry. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
Related PRs:
|
TokenProvider error handling: - Read the error response body exactly once. Calling response.json() then response.text() throws 'Body has already been read', which swallowed non-JSON error payloads (e.g. proxy/WAF 502s). Read text first, then attempt to parse it as JSON. - Map AbortError to a 408 in addition to TimeoutError. Built-in fetch aborts with TimeoutError, but node-fetch (used on the mTLS path via a custom fetch) aborts with AbortError; without this the mTLS timeout surfaced a raw abort error instead of a 408. - Attach a 'token request failed' message so a 401 from the token endpoint is distinguishable from a Management API 401. README: - Import from 'auth0' (the published package name), not '@auth0/node-auth0', in the error-handling examples. - Map passwordless loginWithEmail/loginWithSMS one-to-one to getTokenByPasswordlessEmail/getTokenByPasswordlessSms, matching the migration guide and auth0-auth-js. Tests: add AbortError timeout case and a non-JSON error-body case. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Combining useMTLS with clientAssertionSigningKey previously threw at construction. That was an undeclared breaking change: v6 added the mtls. endpoint alias from useMTLS alone, with no check on the auth method, so private_key_jwt with a TLS client certificate worked and yielded a certificate-bound token. mTLS (RFC 8705) is a transport-layer concern that is independent of the client authentication method. The TLS client certificate produces a certificate-bound access token regardless of whether the client authenticates with client_secret or client_assertion. Rejecting the stronger credential (private_key_jwt) while allowing the weaker one (client_secret) was also inconsistent. - Add useMTLS to ManagementClientOptionsWithClientAssertion so it is on both members of the credentials union. - Remove the mutual-exclusivity throw and read useMTLS off the union directly instead of casting to the client-secret type. - TC-2.12 now asserts the combination is allowed and hits the mtls alias with a client_assertion body. - README: document that useMTLS works with both auth methods. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Deferred items and follow-up planConsolidating the remaining review threads here so there is a single place to track them, and resolving those threads against this list. Most of these are fallout from the auth-separation work itself: it orphaned some now-dead code and exposed the Follow-up cleanup PR (pre-v7-GA):
Separate PR (not auth-separation cleanup):
Still owed in this PR (not deferred): expanding the migration section with the full list of removed public exports ( |
What this does
Removes the Authentication layer from
node-auth0, making it a Management-API-only SDK.ManagementClientcontinues to work — internal token acquisition is handled directly via the client credentials grant.Changes
src/auth/(9 files),src/userinfo/—AuthenticationClient+UserInfoClientgone from main entrypointmtls.{domain}automatically. Timeout (10s) throwsManagementError(408). Non-2xx throwsManagementErrorwith parsed OAuth error body.src/lib/runtime.ts, auth-onlysrc/utils.tshelpers (mtlsPrefix,resolveValueToPromise). KeptgenerateClientInfofor telemetryuuidBreaking changes
AuthenticationClientandUserInfoClientremoved fromauth0main entrypoint. Theauth0/legacyentrypoint (auth0-legacy v4) still ships them.UserInfoClientis removed. UseauthClient.getUserInfo({ accessToken })from@auth0/auth0-auth-js(shipped in #228). For ID token claims, useTokenResponse.claimsdirectly.useMTLS: truemust supply an explicitfetchoption. Throws at construction if absent — prevents silent 401s at request time. Token endpoint usesmtls.{domain}automatically.useMTLSremoved fromManagementClientOptionsWithClientAssertiontype.domainmust be a bare hostname. Slashes or query strings throw at construction.ManagementError(notError). CarriesstatusCodeand parsedbody.Implementation notes
TokenProviderPOSTs tohttps://{domain}/oauth/token(orhttps://mtls.{domain}/oauth/tokenwhenuseMTLS) withapplication/x-www-form-urlencoded.expires_in(seconds) →Date.now() + expires_in * 1000for cache expiry.jose(importPKCS8+SignJWT), already a project dependency.Content-Type/content-typecausing 400s.node-auth0identity in theAuth0-Clientheader.envfield (runtime fingerprint) intentionally absent — documented in code.Tests
token-provider.test.ts: TC-2.1–2.16. Covers credential modes, cache hit, leeway refresh, in-flight de-dup, error propagation, error-not-cached retry, expiry, mTLS customFetch forwarding, mTLS throw-on-no-fetch, domain validation, mTLS+assertion guard, header normalization, typed error body, timeout error.export-surface.test.ts: assertsAuthenticationClient/UserInfoClientabsent from main entrypoint.tests/auth/**,tests/userinfo/**,tests/lib/runtime.test.ts.Validation
Known issues
yarn.lockcontains 3 entries (jose,oauth4webapi,openid-client) that resolve to the internal Artifactory registry (a0us.jfrog.io). These predate this PR and will cause 401s for external contributors runningyarn install. The 3 will be cleaned up in a separate lockfile-regen PR.🤖 Generated with Claude Code
Related PRs