Commit d27bb98
committed
fix(client): allow custom claims to override reserved JWT claims in createPrivateKeyJwtAuth
Remove redundant jose setter calls (.setIssuer, .setSubject, .setAudience,
.setIssuedAt, .setExpirationTime, .setJti) that silently overwrote values from
options.claims after they had been merged into the claims object. The six
reserved claims are already present in the merged object via baseClaims, so the
setter calls were redundant for the default case and harmful when users provided
overrides -- contradicting the documented "custom claims taking precedence"
contract.
Fixes #19141 parent b8886e7 commit d27bb98
3 files changed
Lines changed: 44 additions & 6 deletions
File tree
- .changeset
- packages/client
- src/client
- test/client
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
79 | 79 | | |
80 | 80 | | |
81 | 81 | | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
82 | 87 | | |
83 | 88 | | |
84 | | - | |
85 | | - | |
86 | | - | |
87 | | - | |
88 | | - | |
89 | | - | |
90 | 89 | | |
91 | 90 | | |
92 | 91 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
448 | 448 | | |
449 | 449 | | |
450 | 450 | | |
| 451 | + | |
| 452 | + | |
| 453 | + | |
| 454 | + | |
| 455 | + | |
| 456 | + | |
| 457 | + | |
| 458 | + | |
| 459 | + | |
| 460 | + | |
| 461 | + | |
| 462 | + | |
| 463 | + | |
| 464 | + | |
| 465 | + | |
| 466 | + | |
| 467 | + | |
| 468 | + | |
| 469 | + | |
| 470 | + | |
| 471 | + | |
| 472 | + | |
| 473 | + | |
| 474 | + | |
| 475 | + | |
| 476 | + | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
451 | 480 | | |
452 | 481 | | |
453 | 482 | | |
| |||
0 commit comments