Skip to content

fix(core): check a silently refreshed token against authServerIssuer - #198

Merged
Bccorb merged 1 commit into
mainfrom
fix/ensure-cookies-tests
Oct 7, 2026
Merged

Bccorb merged 1 commit into
mainfrom
fix/ensure-cookies-tests

Conversation

@Bccorb

@Bccorb Bccorb commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Summary

main has failed the Release workflow since ca8fa4a: 2 tests in packages/core/tests/ensureCookies.test.js (run 37564480523). Two PRs merged minutes apart:

So, besides the stale test assertions, there was a real bug: the silent refresh checked iss against authServerUrl even when authServerIssuer was configured. An app that reaches the auth server at a different URL from its issuer (for example, the local Docker stack run from the host, seamless-cli#224) got a 401 on every silent refresh and was signed out. It failed closed, so it was not a security hole.

Fix

  • The JWKS verification of the refreshed token added in fix(core): verify the token a silent refresh returns before issuing cookies #193 is unchanged and still fails closed. The only change is passing the issuer through, the same way login, OTP, OAuth, and the other session flows already do.
  • core: EnsureCookiesOptions extends AuthServerIssuerOption and passes authServerIssuer to issueSessionCookies.
  • express (createEnsureCookiesMiddleware, createServer), fastify (ensureCookies hook), and nextjs (handler) pass their configured authServerIssuer. The new option is optional, so no existing caller breaks.
  • The ERR_JWS_SIGNATURE_VERIFICATION_FAILED line in the failing log comes from a passing negative test in verifySignedAuthResponse.test.js and also appears on green runs.

Tests

  • core: the two stale assertions expect the 4th argument. New "verifies against the configured auth server issuer".
  • express: a silent refresh with authServerIssuer is accepted, and one with an unexpected issuer gets 401.
  • fastify, nextjs (issuer.parity.test.js, kept as mirrors): the same two scenarios against each adapter and Express.
  • With the source change reverted, the new tests fail (core 1, express 1, fastify 2, nextjs 2).

Patch changeset for core, express, fastify, and nextjs. It ships with the unreleased #192 and #193 changesets.

Testing

On Node 24: pnpm install --frozen-lockfile, pnpm check:types-current, pnpm build, and pnpm test pass (core 342, express 203, nextjs 155, fastify 146). CI covers Node 22 and latest.

The Release workflow on main failed in packages/core: two tests in
ensureCookies.test.js expected verifySignedAuthResponse to be called with
three arguments and received a fourth, undefined.

#193 (silent refresh verification) and #192 (authServerIssuer) were
written in parallel and merged minutes apart. #192 gave
verifySignedAuthResponse and issueSessionCookies an issuer argument and
threaded it through every flow that issues a session; #193 routed the
silent refresh through issueSessionCookies without it. So the tests were
stale, and the silent refresh also ignored a configured authServerIssuer:
an app reaching the auth server at another URL (the local Docker stack
from the host) got a 401 on every silent refresh and was signed out.

Add authServerIssuer to EnsureCookiesOptions and the Express
createEnsureCookiesMiddleware options, pass it to issueSessionCookies,
and have the Express, Fastify and Next.js adapters pass their configured
value. The JWKS verification of the refreshed token is unchanged and
still fails closed. Update the core assertions for the issuer argument,
and cover the silent refresh with a configured issuer, and from an
unexpected one, in the Express middleware tests and the Fastify and
Next.js issuer parity suites.
@Bccorb
Bccorb merged commit 0314dfa into main Oct 7, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant