Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 41 additions & 0 deletions .changeset/unlucky-frogs-tap.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
---
'@clerk/backend': major
'@clerk/nextjs': major
---

Replace return the value of the following jwt helpers to match the format of backend API client return values (for consistency).

```diff
import { signJwt } from '@clerk/backend/jwt';

- const { data, error } = await signJwt(...);
+ const { data, errors: [error] = [] } = await signJwt(...);
```

```diff
import { verifyJwt } from '@clerk/backend/jwt';

- const { data, error } = await verifyJwt(...);
+ const { data, errors: [error] = [] } = await verifyJwt(...);
```

```diff
import { hasValidSignature } from '@clerk/backend/jwt';

- const { data, error } = await hasValidSignature(...);
+ const { data, errors: [error] = [] } = await hasValidSignature(...);
```

```diff
import { decodeJwt } from '@clerk/backend/jwt';

- const { data, error } = await decodeJwt(...);
+ const { data, errors: [error] = [] } = await decodeJwt(...);
```

```diff
import { verifyToken } from '@clerk/backend';

- const { data, error } = await verifyToken(...);
+ const { data, errors: [error] = [] } = await verifyToken(...);
```
12 changes: 6 additions & 6 deletions packages/backend/src/jwt/__tests__/verifyJwt.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -56,27 +56,27 @@ export default (QUnit: QUnit) => {
});

test('returns an error if null is given as jwt', assert => {
const { error } = decodeJwt('null');
const { errors: [error] = [] } = decodeJwt('null');
assert.propContains(error, invalidTokenError);
});

test('returns an error if undefined is given as jwt', assert => {
const { error } = decodeJwt('undefined');
const { errors: [error] = [] } = decodeJwt('undefined');
assert.propContains(error, invalidTokenError);
});

test('returns an error if empty string is given as jwt', assert => {
const { error } = decodeJwt('');
const { errors: [error] = [] } = decodeJwt('');
assert.propContains(error, invalidTokenError);
});

test('throws an error if invalid string is given as jwt', assert => {
const { error } = decodeJwt('whatever');
const { errors: [error] = [] } = decodeJwt('whatever');
assert.propContains(error, invalidTokenError);
});

test('throws an error if number is given as jwt', assert => {
const { error } = decodeJwt('42');
const { errors: [error] = [] } = decodeJwt('42');
assert.propContains(error, invalidTokenError);
});
});
Expand DownExpand Up@@ -127,7 +127,7 @@ export default (QUnit: QUnit) => {
issuer: mockJwtPayload.iss,
authorizedParties: ['', 'https://accounts.inspired.puma-74.lcl.dev'],
};
const { error } = await verifyJwt('invalid-jwt', inputVerifyJwtOptions);
const { errors: [error] = [] } = await verifyJwt('invalid-jwt', inputVerifyJwtOptions);
assert.propContains(error, invalidTokenError);
});
});
Expand Down
2 changes: 1 addition & 1 deletion packages/backend/src/jwt/signJwt.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -60,6 +60,6 @@ export async function signJwt(
const encodedSignature = `${firstPart}.${base64url.stringify(new Uint8Array(signature), { pad: false })}`;
return { data: encodedSignature };
} catch (error) {
return { error: new SignJWTError((error as Error)?.message) };
return { errors: [new SignJWTError((error as Error)?.message)] };
}
}
4 changes: 2 additions & 2 deletions packages/backend/src/jwt/types.ts
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
export type JwtReturnType<R, E extends Error> =
| {
data: R;
error?: undefined;
errors?: undefined;
}
| {
data?: undefined;
error: E;
errors: [E];

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

with this type we make it explicit that the errors in this case will have a maximum of 1 item.

};
54 changes: 31 additions & 23 deletions packages/backend/src/jwt/verifyJwt.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -34,10 +34,12 @@ export async function hasValidSignature(jwt: Jwt, key: JsonWebKey | string): Pro
return { data: verified };
} catch (error) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: (error as Error)?.message,
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: (error as Error)?.message,
}),
],
};
}
}
Expand All@@ -46,10 +48,12 @@ export function decodeJwt(token: string): JwtReturnType<Jwt, TokenVerificationEr
const tokenParts = (token || '').toString().split('.');
if (tokenParts.length !== 3) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalid,
message: `Invalid JWT form. A JWT consists of three parts separated by dots.`,
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalid,
message: `Invalid JWT form. A JWT consists of three parts separated by dots.`,
}),
],
};
}

Expand DownExpand Up@@ -105,9 +109,9 @@ export async function verifyJwt(
const { audience, authorizedParties, clockSkewInMs, key } = options;
const clockSkew = clockSkewInMs || DEFAULT_CLOCK_SKEW_IN_SECONDS;

const { data: decoded, error } = decodeJwt(token);
if (error) {
return { error };
const { data: decoded, errors } = decodeJwt(token);
if (errors) {
return { errors };
}

const { header, payload } = decoded;
Expand All@@ -128,26 +132,30 @@ export async function verifyJwt(
assertActivationClaim(nbf, clockSkew);
assertIssuedAtClaim(iat, clockSkew);
} catch (err) {
return { error: err as TokenVerificationError };
return { errors: [err as TokenVerificationError] };
}

const { data: signatureValid, error: signatureError } = await hasValidSignature(decoded, key);
if (signatureError) {
const { data: signatureValid, errors: signatureErrors } = await hasValidSignature(decoded, key);
if (signatureErrors) {
return {
error: new TokenVerificationError({
action: TokenVerificationErrorAction.EnsureClerkJWT,
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying JWT signature. ${signatureError}`,
}),
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.EnsureClerkJWT,
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying JWT signature. ${signatureErrors[0]}`,
}),
],
};
}

if (!signatureValid) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: 'JWT signature is invalid.',
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: 'JWT signature is invalid.',
}),
],
};
}

Expand Down
18 changes: 9 additions & 9 deletions packages/backend/src/tokens/handshake.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,9 +6,9 @@ import { loadClerkJWKFromLocal, loadClerkJWKFromRemote } from './keys';
import type { VerifyTokenOptions } from './verify';

async function verifyHandshakeJwt(token: string, { key }: VerifyJwtOptions): Promise<{ handshake: string[] }> {
const { data: decoded, error } = decodeJwt(token);
if (error) {
throw error;
const { data: decoded, errors } = decodeJwt(token);
if (errors) {
throw errors[0];
}

const { header, payload } = decoded;
Expand All@@ -19,11 +19,11 @@ async function verifyHandshakeJwt(token: string, { key }: VerifyJwtOptions): Pro
assertHeaderType(typ);
assertHeaderAlgorithm(alg);

const { data: signatureValid, error: signatureError } = await hasValidSignature(decoded, key);
if (signatureError) {
const { data: signatureValid, errors: signatureErrors } = await hasValidSignature(decoded, key);
if (signatureErrors) {
throw new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying handshake token. ${signatureError}`,
message: `Error verifying handshake token. ${signatureErrors[0]}`,
});
}

Expand All@@ -46,9 +46,9 @@ export async function verifyHandshakeToken(
): Promise<{ handshake: string[] }> {
const { secretKey, apiUrl, apiVersion, jwksCacheTtlInMs, jwtKey, skipJwksCache } = options;

const { data, error } = decodeJwt(token);
if (error) {
throw error;
const { data, errors } = decodeJwt(token);
if (errors) {
throw errors[0];
}

const { kid } = data.header;
Expand Down
22 changes: 11 additions & 11 deletions packages/backend/src/tokens/request.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -117,7 +117,7 @@ export async function authenticateRequest(
return signedOut(authenticateContext, AuthErrorReason.SessionTokenMissing, '', headers);
}

const { data, error } = await verifyToken(sessionToken, authenticateContext);
const { data, errors: [error] = [] } = await verifyToken(sessionToken, authenticateContext);
if (data) {
return signedIn(authenticateContext, data, headers, sessionToken);
}
Expand All@@ -140,7 +140,7 @@ ${error.getFullMessage()}`,
);

// Retry with a generous clock skew allowance (1 day)
const { data: retryResult, error: retryError } = await verifyToken(sessionToken, {
const { data: retryResult, errors: [retryError] = [] } = await verifyToken(sessionToken, {
...authenticateContext,
clockSkewInMs: 86_400_000,
});
Expand DownExpand Up@@ -180,9 +180,9 @@ ${error.getFullMessage()}`,
const { sessionTokenInHeader } = authenticateContext;

try {
const { data, error } = await verifyToken(sessionTokenInHeader!, authenticateContext);
if (error) {
throw error;
const { data, errors } = await verifyToken(sessionTokenInHeader!, authenticateContext);
if (errors) {
throw errors[0];
}
// use `await` to force this try/catch handle the signedIn invocation
return await signedIn(authenticateContext, data, undefined, sessionTokenInHeader!);
Expand DownExpand Up@@ -286,19 +286,19 @@ ${error.getFullMessage()}`,
return handleMaybeHandshakeStatus(authenticateContext, AuthErrorReason.ClientUATWithoutSessionToken, '');
}

const { data: decodeResult, error: decodedError } = decodeJwt(authenticateContext.sessionTokenInCookie!);
if (decodedError) {
return handleError(decodedError, 'cookie');
const { data: decodeResult, errors: decodedErrors } = decodeJwt(authenticateContext.sessionTokenInCookie!);
if (decodedErrors) {
return handleError(decodedErrors[0], 'cookie');
}

if (decodeResult.payload.iat < authenticateContext.clientUat) {
return handleMaybeHandshakeStatus(authenticateContext, AuthErrorReason.SessionTokenOutdated, '');
}

try {
const { data, error } = await verifyToken(authenticateContext.sessionTokenInCookie!, authenticateContext);
if (error) {
throw error;
const { data, errors } = await verifyToken(authenticateContext.sessionTokenInCookie!, authenticateContext);
if (errors) {
throw errors[0];
}
// use `await` to force this try/catch handle the signedIn invocation
return await signedIn(authenticateContext, data, undefined, authenticateContext.sessionTokenInCookie!);
Expand Down
20 changes: 11 additions & 9 deletions packages/backend/src/tokens/verify.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,9 @@ export async function verifyToken(
token: string,
options: VerifyTokenOptions,
): Promise<JwtReturnType<JwtPayload, TokenVerificationError>> {
const { data: decodedResult, error: decodedError } = decodeJwt(token);
if (decodedError) {
return { error: decodedError };
const { data: decodedResult, errors } = decodeJwt(token);
if (errors) {
return { errors };
}

const { header } = decodedResult;
Expand All@@ -32,16 +32,18 @@ export async function verifyToken(
key = await loadClerkJWKFromRemote({ ...options, kid });
} else {
return {
error: new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkJWTKey,
message: 'Failed to resolve JWK during verification.',
reason: TokenVerificationErrorReason.JWKFailedToResolve,
}),
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkJWTKey,
message: 'Failed to resolve JWK during verification.',
reason: TokenVerificationErrorReason.JWKFailedToResolve,
}),
],
};
}

return await verifyJwt(token, { ...options, key });
} catch (error) {
return { error: error as TokenVerificationError };
return { errors: [error as TokenVerificationError] };
}
}
12 changes: 6 additions & 6 deletions packages/nextjs/src/server/createGetAuth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -46,9 +46,9 @@ export const createGetAuth = ({
logger.debug('Options debug', options);

if (authStatus === AuthStatus.SignedIn) {
const { data: jwt, error } = decodeJwt(authToken as string);
if (error) {
throw error;
const { data: jwt, errors } = decodeJwt(authToken as string);
if (errors) {
throw errors[0];
}

logger.debug('JWT debug', jwt.raw.text);
Expand All@@ -68,10 +68,10 @@ export const getAuth = createGetAuth({
export const parseJwt = (req: RequestLike) => {
const cookieToken = getCookie(req, constants.Cookies.Session);
const headerToken = getHeader(req, 'authorization')?.replace('Bearer ', '');
const { data, error } = decodeJwt(cookieToken || headerToken || '');
const { data, errors } = decodeJwt(cookieToken || headerToken || '');

if (error) {
throw error;
if (errors) {
throw errors[0];
}

return data;
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 41 additions & 0 deletions .changeset/unlucky-frogs-tap.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
---
'@clerk/backend': major
'@clerk/nextjs': major
---

Replace return the value of the following jwt helpers to match the format of backend API client return values (for consistency).

```diff
import { signJwt } from '@clerk/backend/jwt';

- const { data, error } = await signJwt(...);
+ const { data, errors: [error] = [] } = await signJwt(...);
```

```diff
import { verifyJwt } from '@clerk/backend/jwt';

- const { data, error } = await verifyJwt(...);
+ const { data, errors: [error] = [] } = await verifyJwt(...);
```

```diff
import { hasValidSignature } from '@clerk/backend/jwt';

- const { data, error } = await hasValidSignature(...);
+ const { data, errors: [error] = [] } = await hasValidSignature(...);
```

```diff
import { decodeJwt } from '@clerk/backend/jwt';

- const { data, error } = await decodeJwt(...);
+ const { data, errors: [error] = [] } = await decodeJwt(...);
```

```diff
import { verifyToken } from '@clerk/backend';

- const { data, error } = await verifyToken(...);
+ const { data, errors: [error] = [] } = await verifyToken(...);
```
12 changes: 6 additions & 6 deletions packages/backend/src/jwt/__tests__/verifyJwt.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -56,27 +56,27 @@ export default (QUnit: QUnit) => {
});

test('returns an error if null is given as jwt', assert => {
const { error } = decodeJwt('null');
const { errors: [error] = [] } = decodeJwt('null');
assert.propContains(error, invalidTokenError);
});

test('returns an error if undefined is given as jwt', assert => {
const { error } = decodeJwt('undefined');
const { errors: [error] = [] } = decodeJwt('undefined');
assert.propContains(error, invalidTokenError);
});

test('returns an error if empty string is given as jwt', assert => {
const { error } = decodeJwt('');
const { errors: [error] = [] } = decodeJwt('');
assert.propContains(error, invalidTokenError);
});

test('throws an error if invalid string is given as jwt', assert => {
const { error } = decodeJwt('whatever');
const { errors: [error] = [] } = decodeJwt('whatever');
assert.propContains(error, invalidTokenError);
});

test('throws an error if number is given as jwt', assert => {
const { error } = decodeJwt('42');
const { errors: [error] = [] } = decodeJwt('42');
assert.propContains(error, invalidTokenError);
});
});
Expand DownExpand Up@@ -127,7 +127,7 @@ export default (QUnit: QUnit) => {
issuer: mockJwtPayload.iss,
authorizedParties: ['', 'https://accounts.inspired.puma-74.lcl.dev'],
};
const { error } = await verifyJwt('invalid-jwt', inputVerifyJwtOptions);
const { errors: [error] = [] } = await verifyJwt('invalid-jwt', inputVerifyJwtOptions);
assert.propContains(error, invalidTokenError);
});
});
Expand Down
2 changes: 1 addition & 1 deletion packages/backend/src/jwt/signJwt.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -60,6 +60,6 @@ export async function signJwt(
const encodedSignature = `${firstPart}.${base64url.stringify(new Uint8Array(signature), { pad: false })}`;
return { data: encodedSignature };
} catch (error) {
return { error: new SignJWTError((error as Error)?.message) };
return { errors: [new SignJWTError((error as Error)?.message)] };
}
}
4 changes: 2 additions & 2 deletions packages/backend/src/jwt/types.ts
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
export type JwtReturnType<R, E extends Error> =
| {
data: R;
error?: undefined;
errors?: undefined;
}
| {
data?: undefined;
error: E;
errors: [E];

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

with this type we make it explicit that the errors in this case will have a maximum of 1 item.

};
54 changes: 31 additions & 23 deletions packages/backend/src/jwt/verifyJwt.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -34,10 +34,12 @@ export async function hasValidSignature(jwt: Jwt, key: JsonWebKey | string): Pro
return { data: verified };
} catch (error) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: (error as Error)?.message,
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: (error as Error)?.message,
}),
],
};
}
}
Expand All@@ -46,10 +48,12 @@ export function decodeJwt(token: string): JwtReturnType<Jwt, TokenVerificationEr
const tokenParts = (token || '').toString().split('.');
if (tokenParts.length !== 3) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalid,
message: `Invalid JWT form. A JWT consists of three parts separated by dots.`,
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalid,
message: `Invalid JWT form. A JWT consists of three parts separated by dots.`,
}),
],
};
}

Expand DownExpand Up@@ -105,9 +109,9 @@ export async function verifyJwt(
const { audience, authorizedParties, clockSkewInMs, key } = options;
const clockSkew = clockSkewInMs || DEFAULT_CLOCK_SKEW_IN_SECONDS;

const { data: decoded, error } = decodeJwt(token);
if (error) {
return { error };
const { data: decoded, errors } = decodeJwt(token);
if (errors) {
return { errors };
}

const { header, payload } = decoded;
Expand All@@ -128,26 +132,30 @@ export async function verifyJwt(
assertActivationClaim(nbf, clockSkew);
assertIssuedAtClaim(iat, clockSkew);
} catch (err) {
return { error: err as TokenVerificationError };
return { errors: [err as TokenVerificationError] };
}

const { data: signatureValid, error: signatureError } = await hasValidSignature(decoded, key);
if (signatureError) {
const { data: signatureValid, errors: signatureErrors } = await hasValidSignature(decoded, key);
if (signatureErrors) {
return {
error: new TokenVerificationError({
action: TokenVerificationErrorAction.EnsureClerkJWT,
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying JWT signature. ${signatureError}`,
}),
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.EnsureClerkJWT,
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying JWT signature. ${signatureErrors[0]}`,
}),
],
};
}

if (!signatureValid) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: 'JWT signature is invalid.',
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: 'JWT signature is invalid.',
}),
],
};
}

Expand Down
18 changes: 9 additions & 9 deletions packages/backend/src/tokens/handshake.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,9 +6,9 @@ import { loadClerkJWKFromLocal, loadClerkJWKFromRemote } from './keys';
import type { VerifyTokenOptions } from './verify';

async function verifyHandshakeJwt(token: string, { key }: VerifyJwtOptions): Promise<{ handshake: string[] }> {
const { data: decoded, error } = decodeJwt(token);
if (error) {
throw error;
const { data: decoded, errors } = decodeJwt(token);
if (errors) {
throw errors[0];
}

const { header, payload } = decoded;
Expand All@@ -19,11 +19,11 @@ async function verifyHandshakeJwt(token: string, { key }: VerifyJwtOptions): Pro
assertHeaderType(typ);
assertHeaderAlgorithm(alg);

const { data: signatureValid, error: signatureError } = await hasValidSignature(decoded, key);
if (signatureError) {
const { data: signatureValid, errors: signatureErrors } = await hasValidSignature(decoded, key);
if (signatureErrors) {
throw new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying handshake token. ${signatureError}`,
message: `Error verifying handshake token. ${signatureErrors[0]}`,
});
}

Expand All@@ -46,9 +46,9 @@ export async function verifyHandshakeToken(
): Promise<{ handshake: string[] }> {
const { secretKey, apiUrl, apiVersion, jwksCacheTtlInMs, jwtKey, skipJwksCache } = options;

const { data, error } = decodeJwt(token);
if (error) {
throw error;
const { data, errors } = decodeJwt(token);
if (errors) {
throw errors[0];
}

const { kid } = data.header;
Expand Down
22 changes: 11 additions & 11 deletions packages/backend/src/tokens/request.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -117,7 +117,7 @@ export async function authenticateRequest(
return signedOut(authenticateContext, AuthErrorReason.SessionTokenMissing, '', headers);
}

const { data, error } = await verifyToken(sessionToken, authenticateContext);
const { data, errors: [error] = [] } = await verifyToken(sessionToken, authenticateContext);
if (data) {
return signedIn(authenticateContext, data, headers, sessionToken);
}
Expand All@@ -140,7 +140,7 @@ ${error.getFullMessage()}`,
);

// Retry with a generous clock skew allowance (1 day)
const { data: retryResult, error: retryError } = await verifyToken(sessionToken, {
const { data: retryResult, errors: [retryError] = [] } = await verifyToken(sessionToken, {
...authenticateContext,
clockSkewInMs: 86_400_000,
});
Expand DownExpand Up@@ -180,9 +180,9 @@ ${error.getFullMessage()}`,
const { sessionTokenInHeader } = authenticateContext;

try {
const { data, error } = await verifyToken(sessionTokenInHeader!, authenticateContext);
if (error) {
throw error;
const { data, errors } = await verifyToken(sessionTokenInHeader!, authenticateContext);
if (errors) {
throw errors[0];
}
// use `await` to force this try/catch handle the signedIn invocation
return await signedIn(authenticateContext, data, undefined, sessionTokenInHeader!);
Expand DownExpand Up@@ -286,19 +286,19 @@ ${error.getFullMessage()}`,
return handleMaybeHandshakeStatus(authenticateContext, AuthErrorReason.ClientUATWithoutSessionToken, '');
}

const { data: decodeResult, error: decodedError } = decodeJwt(authenticateContext.sessionTokenInCookie!);
if (decodedError) {
return handleError(decodedError, 'cookie');
const { data: decodeResult, errors: decodedErrors } = decodeJwt(authenticateContext.sessionTokenInCookie!);
if (decodedErrors) {
return handleError(decodedErrors[0], 'cookie');
}

if (decodeResult.payload.iat < authenticateContext.clientUat) {
return handleMaybeHandshakeStatus(authenticateContext, AuthErrorReason.SessionTokenOutdated, '');
}

try {
const { data, error } = await verifyToken(authenticateContext.sessionTokenInCookie!, authenticateContext);
if (error) {
throw error;
const { data, errors } = await verifyToken(authenticateContext.sessionTokenInCookie!, authenticateContext);
if (errors) {
throw errors[0];
}
// use `await` to force this try/catch handle the signedIn invocation
return await signedIn(authenticateContext, data, undefined, authenticateContext.sessionTokenInCookie!);
Expand Down
20 changes: 11 additions & 9 deletions packages/backend/src/tokens/verify.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,9 @@ export async function verifyToken(
token: string,
options: VerifyTokenOptions,
): Promise<JwtReturnType<JwtPayload, TokenVerificationError>> {
const { data: decodedResult, error: decodedError } = decodeJwt(token);
if (decodedError) {
return { error: decodedError };
const { data: decodedResult, errors } = decodeJwt(token);
if (errors) {
return { errors };
}

const { header } = decodedResult;
Expand All@@ -32,16 +32,18 @@ export async function verifyToken(
key = await loadClerkJWKFromRemote({ ...options, kid });
} else {
return {
error: new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkJWTKey,
message: 'Failed to resolve JWK during verification.',
reason: TokenVerificationErrorReason.JWKFailedToResolve,
}),
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkJWTKey,
message: 'Failed to resolve JWK during verification.',
reason: TokenVerificationErrorReason.JWKFailedToResolve,
}),
],
};
}

return await verifyJwt(token, { ...options, key });
} catch (error) {
return { error: error as TokenVerificationError };
return { errors: [error as TokenVerificationError] };
}
}
12 changes: 6 additions & 6 deletions packages/nextjs/src/server/createGetAuth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -46,9 +46,9 @@ export const createGetAuth = ({
logger.debug('Options debug', options);

if (authStatus === AuthStatus.SignedIn) {
const { data: jwt, error } = decodeJwt(authToken as string);
if (error) {
throw error;
const { data: jwt, errors } = decodeJwt(authToken as string);
if (errors) {
throw errors[0];
}

logger.debug('JWT debug', jwt.raw.text);
Expand All@@ -68,10 +68,10 @@ export const getAuth = createGetAuth({
export const parseJwt = (req: RequestLike) => {
const cookieToken = getCookie(req, constants.Cookies.Session);
const headerToken = getHeader(req, 'authorization')?.replace('Bearer ', '');
const { data, error } = decodeJwt(cookieToken || headerToken || '');
const { data, errors } = decodeJwt(cookieToken || headerToken || '');

if (error) {
throw error;
if (errors) {
throw errors[0];
}

return data;
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 41 additions & 0 deletions .changeset/unlucky-frogs-tap.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
---
'@clerk/backend': major
'@clerk/nextjs': major
---

Replace return the value of the following jwt helpers to match the format of backend API client return values (for consistency).

```diff
import { signJwt } from '@clerk/backend/jwt';

- const { data, error } = await signJwt(...);
+ const { data, errors: [error] = [] } = await signJwt(...);
```

```diff
import { verifyJwt } from '@clerk/backend/jwt';

- const { data, error } = await verifyJwt(...);
+ const { data, errors: [error] = [] } = await verifyJwt(...);
```

```diff
import { hasValidSignature } from '@clerk/backend/jwt';

- const { data, error } = await hasValidSignature(...);
+ const { data, errors: [error] = [] } = await hasValidSignature(...);
```

```diff
import { decodeJwt } from '@clerk/backend/jwt';

- const { data, error } = await decodeJwt(...);
+ const { data, errors: [error] = [] } = await decodeJwt(...);
```

```diff
import { verifyToken } from '@clerk/backend';

- const { data, error } = await verifyToken(...);
+ const { data, errors: [error] = [] } = await verifyToken(...);
```
12 changes: 6 additions & 6 deletions packages/backend/src/jwt/__tests__/verifyJwt.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -56,27 +56,27 @@ export default (QUnit: QUnit) => {
});

test('returns an error if null is given as jwt', assert => {
const { error } = decodeJwt('null');
const { errors: [error] = [] } = decodeJwt('null');
assert.propContains(error, invalidTokenError);
});

test('returns an error if undefined is given as jwt', assert => {
const { error } = decodeJwt('undefined');
const { errors: [error] = [] } = decodeJwt('undefined');
assert.propContains(error, invalidTokenError);
});

test('returns an error if empty string is given as jwt', assert => {
const { error } = decodeJwt('');
const { errors: [error] = [] } = decodeJwt('');
assert.propContains(error, invalidTokenError);
});

test('throws an error if invalid string is given as jwt', assert => {
const { error } = decodeJwt('whatever');
const { errors: [error] = [] } = decodeJwt('whatever');
assert.propContains(error, invalidTokenError);
});

test('throws an error if number is given as jwt', assert => {
const { error } = decodeJwt('42');
const { errors: [error] = [] } = decodeJwt('42');
assert.propContains(error, invalidTokenError);
});
});
Expand DownExpand Up@@ -127,7 +127,7 @@ export default (QUnit: QUnit) => {
issuer: mockJwtPayload.iss,
authorizedParties: ['', 'https://accounts.inspired.puma-74.lcl.dev'],
};
const { error } = await verifyJwt('invalid-jwt', inputVerifyJwtOptions);
const { errors: [error] = [] } = await verifyJwt('invalid-jwt', inputVerifyJwtOptions);
assert.propContains(error, invalidTokenError);
});
});
Expand Down
2 changes: 1 addition & 1 deletion packages/backend/src/jwt/signJwt.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -60,6 +60,6 @@ export async function signJwt(
const encodedSignature = `${firstPart}.${base64url.stringify(new Uint8Array(signature), { pad: false })}`;
return { data: encodedSignature };
} catch (error) {
return { error: new SignJWTError((error as Error)?.message) };
return { errors: [new SignJWTError((error as Error)?.message)] };
}
}
4 changes: 2 additions & 2 deletions packages/backend/src/jwt/types.ts
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
export type JwtReturnType<R, E extends Error> =
| {
data: R;
error?: undefined;
errors?: undefined;
}
| {
data?: undefined;
error: E;
errors: [E];

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

with this type we make it explicit that the errors in this case will have a maximum of 1 item.

};
54 changes: 31 additions & 23 deletions packages/backend/src/jwt/verifyJwt.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -34,10 +34,12 @@ export async function hasValidSignature(jwt: Jwt, key: JsonWebKey | string): Pro
return { data: verified };
} catch (error) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: (error as Error)?.message,
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: (error as Error)?.message,
}),
],
};
}
}
Expand All@@ -46,10 +48,12 @@ export function decodeJwt(token: string): JwtReturnType<Jwt, TokenVerificationEr
const tokenParts = (token || '').toString().split('.');
if (tokenParts.length !== 3) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalid,
message: `Invalid JWT form. A JWT consists of three parts separated by dots.`,
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalid,
message: `Invalid JWT form. A JWT consists of three parts separated by dots.`,
}),
],
};
}

Expand DownExpand Up@@ -105,9 +109,9 @@ export async function verifyJwt(
const { audience, authorizedParties, clockSkewInMs, key } = options;
const clockSkew = clockSkewInMs || DEFAULT_CLOCK_SKEW_IN_SECONDS;

const { data: decoded, error } = decodeJwt(token);
if (error) {
return { error };
const { data: decoded, errors } = decodeJwt(token);
if (errors) {
return { errors };
}

const { header, payload } = decoded;
Expand All@@ -128,26 +132,30 @@ export async function verifyJwt(
assertActivationClaim(nbf, clockSkew);
assertIssuedAtClaim(iat, clockSkew);
} catch (err) {
return { error: err as TokenVerificationError };
return { errors: [err as TokenVerificationError] };
}

const { data: signatureValid, error: signatureError } = await hasValidSignature(decoded, key);
if (signatureError) {
const { data: signatureValid, errors: signatureErrors } = await hasValidSignature(decoded, key);
if (signatureErrors) {
return {
error: new TokenVerificationError({
action: TokenVerificationErrorAction.EnsureClerkJWT,
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying JWT signature. ${signatureError}`,
}),
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.EnsureClerkJWT,
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying JWT signature. ${signatureErrors[0]}`,
}),
],
};
}

if (!signatureValid) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: 'JWT signature is invalid.',
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: 'JWT signature is invalid.',
}),
],
};
}

Expand Down
18 changes: 9 additions & 9 deletions packages/backend/src/tokens/handshake.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,9 +6,9 @@ import { loadClerkJWKFromLocal, loadClerkJWKFromRemote } from './keys';
import type { VerifyTokenOptions } from './verify';

async function verifyHandshakeJwt(token: string, { key }: VerifyJwtOptions): Promise<{ handshake: string[] }> {
const { data: decoded, error } = decodeJwt(token);
if (error) {
throw error;
const { data: decoded, errors } = decodeJwt(token);
if (errors) {
throw errors[0];
}

const { header, payload } = decoded;
Expand All@@ -19,11 +19,11 @@ async function verifyHandshakeJwt(token: string, { key }: VerifyJwtOptions): Pro
assertHeaderType(typ);
assertHeaderAlgorithm(alg);

const { data: signatureValid, error: signatureError } = await hasValidSignature(decoded, key);
if (signatureError) {
const { data: signatureValid, errors: signatureErrors } = await hasValidSignature(decoded, key);
if (signatureErrors) {
throw new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying handshake token. ${signatureError}`,
message: `Error verifying handshake token. ${signatureErrors[0]}`,
});
}

Expand All@@ -46,9 +46,9 @@ export async function verifyHandshakeToken(
): Promise<{ handshake: string[] }> {
const { secretKey, apiUrl, apiVersion, jwksCacheTtlInMs, jwtKey, skipJwksCache } = options;

const { data, error } = decodeJwt(token);
if (error) {
throw error;
const { data, errors } = decodeJwt(token);
if (errors) {
throw errors[0];
}

const { kid } = data.header;
Expand Down
22 changes: 11 additions & 11 deletions packages/backend/src/tokens/request.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -117,7 +117,7 @@ export async function authenticateRequest(
return signedOut(authenticateContext, AuthErrorReason.SessionTokenMissing, '', headers);
}

const { data, error } = await verifyToken(sessionToken, authenticateContext);
const { data, errors: [error] = [] } = await verifyToken(sessionToken, authenticateContext);
if (data) {
return signedIn(authenticateContext, data, headers, sessionToken);
}
Expand All@@ -140,7 +140,7 @@ ${error.getFullMessage()}`,
);

// Retry with a generous clock skew allowance (1 day)
const { data: retryResult, error: retryError } = await verifyToken(sessionToken, {
const { data: retryResult, errors: [retryError] = [] } = await verifyToken(sessionToken, {
...authenticateContext,
clockSkewInMs: 86_400_000,
});
Expand DownExpand Up@@ -180,9 +180,9 @@ ${error.getFullMessage()}`,
const { sessionTokenInHeader } = authenticateContext;

try {
const { data, error } = await verifyToken(sessionTokenInHeader!, authenticateContext);
if (error) {
throw error;
const { data, errors } = await verifyToken(sessionTokenInHeader!, authenticateContext);
if (errors) {
throw errors[0];
}
// use `await` to force this try/catch handle the signedIn invocation
return await signedIn(authenticateContext, data, undefined, sessionTokenInHeader!);
Expand DownExpand Up@@ -286,19 +286,19 @@ ${error.getFullMessage()}`,
return handleMaybeHandshakeStatus(authenticateContext, AuthErrorReason.ClientUATWithoutSessionToken, '');
}

const { data: decodeResult, error: decodedError } = decodeJwt(authenticateContext.sessionTokenInCookie!);
if (decodedError) {
return handleError(decodedError, 'cookie');
const { data: decodeResult, errors: decodedErrors } = decodeJwt(authenticateContext.sessionTokenInCookie!);
if (decodedErrors) {
return handleError(decodedErrors[0], 'cookie');
}

if (decodeResult.payload.iat < authenticateContext.clientUat) {
return handleMaybeHandshakeStatus(authenticateContext, AuthErrorReason.SessionTokenOutdated, '');
}

try {
const { data, error } = await verifyToken(authenticateContext.sessionTokenInCookie!, authenticateContext);
if (error) {
throw error;
const { data, errors } = await verifyToken(authenticateContext.sessionTokenInCookie!, authenticateContext);
if (errors) {
throw errors[0];
}
// use `await` to force this try/catch handle the signedIn invocation
return await signedIn(authenticateContext, data, undefined, authenticateContext.sessionTokenInCookie!);
Expand Down
20 changes: 11 additions & 9 deletions packages/backend/src/tokens/verify.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,9 @@ export async function verifyToken(
token: string,
options: VerifyTokenOptions,
): Promise<JwtReturnType<JwtPayload, TokenVerificationError>> {
const { data: decodedResult, error: decodedError } = decodeJwt(token);
if (decodedError) {
return { error: decodedError };
const { data: decodedResult, errors } = decodeJwt(token);
if (errors) {
return { errors };
}

const { header } = decodedResult;
Expand All@@ -32,16 +32,18 @@ export async function verifyToken(
key = await loadClerkJWKFromRemote({ ...options, kid });
} else {
return {
error: new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkJWTKey,
message: 'Failed to resolve JWK during verification.',
reason: TokenVerificationErrorReason.JWKFailedToResolve,
}),
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkJWTKey,
message: 'Failed to resolve JWK during verification.',
reason: TokenVerificationErrorReason.JWKFailedToResolve,
}),
],
};
}

return await verifyJwt(token, { ...options, key });
} catch (error) {
return { error: error as TokenVerificationError };
return { errors: [error as TokenVerificationError] };
}
}
12 changes: 6 additions & 6 deletions packages/nextjs/src/server/createGetAuth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -46,9 +46,9 @@ export const createGetAuth = ({
logger.debug('Options debug', options);

if (authStatus === AuthStatus.SignedIn) {
const { data: jwt, error } = decodeJwt(authToken as string);
if (error) {
throw error;
const { data: jwt, errors } = decodeJwt(authToken as string);
if (errors) {
throw errors[0];
}

logger.debug('JWT debug', jwt.raw.text);
Expand All@@ -68,10 +68,10 @@ export const getAuth = createGetAuth({
export const parseJwt = (req: RequestLike) => {
const cookieToken = getCookie(req, constants.Cookies.Session);
const headerToken = getHeader(req, 'authorization')?.replace('Bearer ', '');
const { data, error } = decodeJwt(cookieToken || headerToken || '');
const { data, errors } = decodeJwt(cookieToken || headerToken || '');

if (error) {
throw error;
if (errors) {
throw errors[0];
}

return data;
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 41 additions & 0 deletions .changeset/unlucky-frogs-tap.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
---
'@clerk/backend': major
'@clerk/nextjs': major
---

Replace return the value of the following jwt helpers to match the format of backend API client return values (for consistency).

```diff
import { signJwt } from '@clerk/backend/jwt';

- const { data, error } = await signJwt(...);
+ const { data, errors: [error] = [] } = await signJwt(...);
```

```diff
import { verifyJwt } from '@clerk/backend/jwt';

- const { data, error } = await verifyJwt(...);
+ const { data, errors: [error] = [] } = await verifyJwt(...);
```

```diff
import { hasValidSignature } from '@clerk/backend/jwt';

- const { data, error } = await hasValidSignature(...);
+ const { data, errors: [error] = [] } = await hasValidSignature(...);
```

```diff
import { decodeJwt } from '@clerk/backend/jwt';

- const { data, error } = await decodeJwt(...);
+ const { data, errors: [error] = [] } = await decodeJwt(...);
```

```diff
import { verifyToken } from '@clerk/backend';

- const { data, error } = await verifyToken(...);
+ const { data, errors: [error] = [] } = await verifyToken(...);
```
12 changes: 6 additions & 6 deletions packages/backend/src/jwt/__tests__/verifyJwt.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -56,27 +56,27 @@ export default (QUnit: QUnit) => {
});

test('returns an error if null is given as jwt', assert => {
const { error } = decodeJwt('null');
const { errors: [error] = [] } = decodeJwt('null');
assert.propContains(error, invalidTokenError);
});

test('returns an error if undefined is given as jwt', assert => {
const { error } = decodeJwt('undefined');
const { errors: [error] = [] } = decodeJwt('undefined');
assert.propContains(error, invalidTokenError);
});

test('returns an error if empty string is given as jwt', assert => {
const { error } = decodeJwt('');
const { errors: [error] = [] } = decodeJwt('');
assert.propContains(error, invalidTokenError);
});

test('throws an error if invalid string is given as jwt', assert => {
const { error } = decodeJwt('whatever');
const { errors: [error] = [] } = decodeJwt('whatever');
assert.propContains(error, invalidTokenError);
});

test('throws an error if number is given as jwt', assert => {
const { error } = decodeJwt('42');
const { errors: [error] = [] } = decodeJwt('42');
assert.propContains(error, invalidTokenError);
});
});
Expand DownExpand Up@@ -127,7 +127,7 @@ export default (QUnit: QUnit) => {
issuer: mockJwtPayload.iss,
authorizedParties: ['', 'https://accounts.inspired.puma-74.lcl.dev'],
};
const { error } = await verifyJwt('invalid-jwt', inputVerifyJwtOptions);
const { errors: [error] = [] } = await verifyJwt('invalid-jwt', inputVerifyJwtOptions);
assert.propContains(error, invalidTokenError);
});
});
Expand Down
2 changes: 1 addition & 1 deletion packages/backend/src/jwt/signJwt.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -60,6 +60,6 @@ export async function signJwt(
const encodedSignature = `${firstPart}.${base64url.stringify(new Uint8Array(signature), { pad: false })}`;
return { data: encodedSignature };
} catch (error) {
return { error: new SignJWTError((error as Error)?.message) };
return { errors: [new SignJWTError((error as Error)?.message)] };
}
}
4 changes: 2 additions & 2 deletions packages/backend/src/jwt/types.ts
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
export type JwtReturnType<R, E extends Error> =
| {
data: R;
error?: undefined;
errors?: undefined;
}
| {
data?: undefined;
error: E;
errors: [E];

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

with this type we make it explicit that the errors in this case will have a maximum of 1 item.

};
54 changes: 31 additions & 23 deletions packages/backend/src/jwt/verifyJwt.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -34,10 +34,12 @@ export async function hasValidSignature(jwt: Jwt, key: JsonWebKey | string): Pro
return { data: verified };
} catch (error) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: (error as Error)?.message,
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: (error as Error)?.message,
}),
],
};
}
}
Expand All@@ -46,10 +48,12 @@ export function decodeJwt(token: string): JwtReturnType<Jwt, TokenVerificationEr
const tokenParts = (token || '').toString().split('.');
if (tokenParts.length !== 3) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalid,
message: `Invalid JWT form. A JWT consists of three parts separated by dots.`,
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalid,
message: `Invalid JWT form. A JWT consists of three parts separated by dots.`,
}),
],
};
}

Expand DownExpand Up@@ -105,9 +109,9 @@ export async function verifyJwt(
const { audience, authorizedParties, clockSkewInMs, key } = options;
const clockSkew = clockSkewInMs || DEFAULT_CLOCK_SKEW_IN_SECONDS;

const { data: decoded, error } = decodeJwt(token);
if (error) {
return { error };
const { data: decoded, errors } = decodeJwt(token);
if (errors) {
return { errors };
}

const { header, payload } = decoded;
Expand All@@ -128,26 +132,30 @@ export async function verifyJwt(
assertActivationClaim(nbf, clockSkew);
assertIssuedAtClaim(iat, clockSkew);
} catch (err) {
return { error: err as TokenVerificationError };
return { errors: [err as TokenVerificationError] };
}

const { data: signatureValid, error: signatureError } = await hasValidSignature(decoded, key);
if (signatureError) {
const { data: signatureValid, errors: signatureErrors } = await hasValidSignature(decoded, key);
if (signatureErrors) {
return {
error: new TokenVerificationError({
action: TokenVerificationErrorAction.EnsureClerkJWT,
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying JWT signature. ${signatureError}`,
}),
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.EnsureClerkJWT,
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying JWT signature. ${signatureErrors[0]}`,
}),
],
};
}

if (!signatureValid) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: 'JWT signature is invalid.',
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: 'JWT signature is invalid.',
}),
],
};
}

Expand Down
18 changes: 9 additions & 9 deletions packages/backend/src/tokens/handshake.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,9 +6,9 @@ import { loadClerkJWKFromLocal, loadClerkJWKFromRemote } from './keys';
import type { VerifyTokenOptions } from './verify';

async function verifyHandshakeJwt(token: string, { key }: VerifyJwtOptions): Promise<{ handshake: string[] }> {
const { data: decoded, error } = decodeJwt(token);
if (error) {
throw error;
const { data: decoded, errors } = decodeJwt(token);
if (errors) {
throw errors[0];
}

const { header, payload } = decoded;
Expand All@@ -19,11 +19,11 @@ async function verifyHandshakeJwt(token: string, { key }: VerifyJwtOptions): Pro
assertHeaderType(typ);
assertHeaderAlgorithm(alg);

const { data: signatureValid, error: signatureError } = await hasValidSignature(decoded, key);
if (signatureError) {
const { data: signatureValid, errors: signatureErrors } = await hasValidSignature(decoded, key);
if (signatureErrors) {
throw new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying handshake token. ${signatureError}`,
message: `Error verifying handshake token. ${signatureErrors[0]}`,
});
}

Expand All@@ -46,9 +46,9 @@ export async function verifyHandshakeToken(
): Promise<{ handshake: string[] }> {
const { secretKey, apiUrl, apiVersion, jwksCacheTtlInMs, jwtKey, skipJwksCache } = options;

const { data, error } = decodeJwt(token);
if (error) {
throw error;
const { data, errors } = decodeJwt(token);
if (errors) {
throw errors[0];
}

const { kid } = data.header;
Expand Down
22 changes: 11 additions & 11 deletions packages/backend/src/tokens/request.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -117,7 +117,7 @@ export async function authenticateRequest(
return signedOut(authenticateContext, AuthErrorReason.SessionTokenMissing, '', headers);
}

const { data, error } = await verifyToken(sessionToken, authenticateContext);
const { data, errors: [error] = [] } = await verifyToken(sessionToken, authenticateContext);
if (data) {
return signedIn(authenticateContext, data, headers, sessionToken);
}
Expand All@@ -140,7 +140,7 @@ ${error.getFullMessage()}`,
);

// Retry with a generous clock skew allowance (1 day)
const { data: retryResult, error: retryError } = await verifyToken(sessionToken, {
const { data: retryResult, errors: [retryError] = [] } = await verifyToken(sessionToken, {
...authenticateContext,
clockSkewInMs: 86_400_000,
});
Expand DownExpand Up@@ -180,9 +180,9 @@ ${error.getFullMessage()}`,
const { sessionTokenInHeader } = authenticateContext;

try {
const { data, error } = await verifyToken(sessionTokenInHeader!, authenticateContext);
if (error) {
throw error;
const { data, errors } = await verifyToken(sessionTokenInHeader!, authenticateContext);
if (errors) {
throw errors[0];
}
// use `await` to force this try/catch handle the signedIn invocation
return await signedIn(authenticateContext, data, undefined, sessionTokenInHeader!);
Expand DownExpand Up@@ -286,19 +286,19 @@ ${error.getFullMessage()}`,
return handleMaybeHandshakeStatus(authenticateContext, AuthErrorReason.ClientUATWithoutSessionToken, '');
}

const { data: decodeResult, error: decodedError } = decodeJwt(authenticateContext.sessionTokenInCookie!);
if (decodedError) {
return handleError(decodedError, 'cookie');
const { data: decodeResult, errors: decodedErrors } = decodeJwt(authenticateContext.sessionTokenInCookie!);
if (decodedErrors) {
return handleError(decodedErrors[0], 'cookie');
}

if (decodeResult.payload.iat < authenticateContext.clientUat) {
return handleMaybeHandshakeStatus(authenticateContext, AuthErrorReason.SessionTokenOutdated, '');
}

try {
const { data, error } = await verifyToken(authenticateContext.sessionTokenInCookie!, authenticateContext);
if (error) {
throw error;
const { data, errors } = await verifyToken(authenticateContext.sessionTokenInCookie!, authenticateContext);
if (errors) {
throw errors[0];
}
// use `await` to force this try/catch handle the signedIn invocation
return await signedIn(authenticateContext, data, undefined, authenticateContext.sessionTokenInCookie!);
Expand Down
20 changes: 11 additions & 9 deletions packages/backend/src/tokens/verify.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,9 @@ export async function verifyToken(
token: string,
options: VerifyTokenOptions,
): Promise<JwtReturnType<JwtPayload, TokenVerificationError>> {
const { data: decodedResult, error: decodedError } = decodeJwt(token);
if (decodedError) {
return { error: decodedError };
const { data: decodedResult, errors } = decodeJwt(token);
if (errors) {
return { errors };
}

const { header } = decodedResult;
Expand All@@ -32,16 +32,18 @@ export async function verifyToken(
key = await loadClerkJWKFromRemote({ ...options, kid });
} else {
return {
error: new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkJWTKey,
message: 'Failed to resolve JWK during verification.',
reason: TokenVerificationErrorReason.JWKFailedToResolve,
}),
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkJWTKey,
message: 'Failed to resolve JWK during verification.',
reason: TokenVerificationErrorReason.JWKFailedToResolve,
}),
],
};
}

return await verifyJwt(token, { ...options, key });
} catch (error) {
return { error: error as TokenVerificationError };
return { errors: [error as TokenVerificationError] };
}
}
12 changes: 6 additions & 6 deletions packages/nextjs/src/server/createGetAuth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -46,9 +46,9 @@ export const createGetAuth = ({
logger.debug('Options debug', options);

if (authStatus === AuthStatus.SignedIn) {
const { data: jwt, error } = decodeJwt(authToken as string);
if (error) {
throw error;
const { data: jwt, errors } = decodeJwt(authToken as string);
if (errors) {
throw errors[0];
}

logger.debug('JWT debug', jwt.raw.text);
Expand All@@ -68,10 +68,10 @@ export const getAuth = createGetAuth({
export const parseJwt = (req: RequestLike) => {
const cookieToken = getCookie(req, constants.Cookies.Session);
const headerToken = getHeader(req, 'authorization')?.replace('Bearer ', '');
const { data, error } = decodeJwt(cookieToken || headerToken || '');
const { data, errors } = decodeJwt(cookieToken || headerToken || '');

if (error) {
throw error;
if (errors) {
throw errors[0];
}

return data;
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 41 additions & 0 deletions .changeset/unlucky-frogs-tap.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
---
'@clerk/backend': major
'@clerk/nextjs': major
---

Replace return the value of the following jwt helpers to match the format of backend API client return values (for consistency).

```diff
import { signJwt } from '@clerk/backend/jwt';

- const { data, error } = await signJwt(...);
+ const { data, errors: [error] = [] } = await signJwt(...);
```

```diff
import { verifyJwt } from '@clerk/backend/jwt';

- const { data, error } = await verifyJwt(...);
+ const { data, errors: [error] = [] } = await verifyJwt(...);
```

```diff
import { hasValidSignature } from '@clerk/backend/jwt';

- const { data, error } = await hasValidSignature(...);
+ const { data, errors: [error] = [] } = await hasValidSignature(...);
```

```diff
import { decodeJwt } from '@clerk/backend/jwt';

- const { data, error } = await decodeJwt(...);
+ const { data, errors: [error] = [] } = await decodeJwt(...);
```

```diff
import { verifyToken } from '@clerk/backend';

- const { data, error } = await verifyToken(...);
+ const { data, errors: [error] = [] } = await verifyToken(...);
```
12 changes: 6 additions & 6 deletions packages/backend/src/jwt/__tests__/verifyJwt.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -56,27 +56,27 @@ export default (QUnit: QUnit) => {
});

test('returns an error if null is given as jwt', assert => {
const { error } = decodeJwt('null');
const { errors: [error] = [] } = decodeJwt('null');
assert.propContains(error, invalidTokenError);
});

test('returns an error if undefined is given as jwt', assert => {
const { error } = decodeJwt('undefined');
const { errors: [error] = [] } = decodeJwt('undefined');
assert.propContains(error, invalidTokenError);
});

test('returns an error if empty string is given as jwt', assert => {
const { error } = decodeJwt('');
const { errors: [error] = [] } = decodeJwt('');
assert.propContains(error, invalidTokenError);
});

test('throws an error if invalid string is given as jwt', assert => {
const { error } = decodeJwt('whatever');
const { errors: [error] = [] } = decodeJwt('whatever');
assert.propContains(error, invalidTokenError);
});

test('throws an error if number is given as jwt', assert => {
const { error } = decodeJwt('42');
const { errors: [error] = [] } = decodeJwt('42');
assert.propContains(error, invalidTokenError);
});
});
Expand DownExpand Up@@ -127,7 +127,7 @@ export default (QUnit: QUnit) => {
issuer: mockJwtPayload.iss,
authorizedParties: ['', 'https://accounts.inspired.puma-74.lcl.dev'],
};
const { error } = await verifyJwt('invalid-jwt', inputVerifyJwtOptions);
const { errors: [error] = [] } = await verifyJwt('invalid-jwt', inputVerifyJwtOptions);
assert.propContains(error, invalidTokenError);
});
});
Expand Down
2 changes: 1 addition & 1 deletion packages/backend/src/jwt/signJwt.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -60,6 +60,6 @@ export async function signJwt(
const encodedSignature = `${firstPart}.${base64url.stringify(new Uint8Array(signature), { pad: false })}`;
return { data: encodedSignature };
} catch (error) {
return { error: new SignJWTError((error as Error)?.message) };
return { errors: [new SignJWTError((error as Error)?.message)] };
}
}
4 changes: 2 additions & 2 deletions packages/backend/src/jwt/types.ts
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
export type JwtReturnType<R, E extends Error> =
| {
data: R;
error?: undefined;
errors?: undefined;
}
| {
data?: undefined;
error: E;
errors: [E];

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

with this type we make it explicit that the errors in this case will have a maximum of 1 item.

};
54 changes: 31 additions & 23 deletions packages/backend/src/jwt/verifyJwt.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -34,10 +34,12 @@ export async function hasValidSignature(jwt: Jwt, key: JsonWebKey | string): Pro
return { data: verified };
} catch (error) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: (error as Error)?.message,
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: (error as Error)?.message,
}),
],
};
}
}
Expand All@@ -46,10 +48,12 @@ export function decodeJwt(token: string): JwtReturnType<Jwt, TokenVerificationEr
const tokenParts = (token || '').toString().split('.');
if (tokenParts.length !== 3) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalid,
message: `Invalid JWT form. A JWT consists of three parts separated by dots.`,
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalid,
message: `Invalid JWT form. A JWT consists of three parts separated by dots.`,
}),
],
};
}

Expand DownExpand Up@@ -105,9 +109,9 @@ export async function verifyJwt(
const { audience, authorizedParties, clockSkewInMs, key } = options;
const clockSkew = clockSkewInMs || DEFAULT_CLOCK_SKEW_IN_SECONDS;

const { data: decoded, error } = decodeJwt(token);
if (error) {
return { error };
const { data: decoded, errors } = decodeJwt(token);
if (errors) {
return { errors };
}

const { header, payload } = decoded;
Expand All@@ -128,26 +132,30 @@ export async function verifyJwt(
assertActivationClaim(nbf, clockSkew);
assertIssuedAtClaim(iat, clockSkew);
} catch (err) {
return { error: err as TokenVerificationError };
return { errors: [err as TokenVerificationError] };
}

const { data: signatureValid, error: signatureError } = await hasValidSignature(decoded, key);
if (signatureError) {
const { data: signatureValid, errors: signatureErrors } = await hasValidSignature(decoded, key);
if (signatureErrors) {
return {
error: new TokenVerificationError({
action: TokenVerificationErrorAction.EnsureClerkJWT,
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying JWT signature. ${signatureError}`,
}),
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.EnsureClerkJWT,
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying JWT signature. ${signatureErrors[0]}`,
}),
],
};
}

if (!signatureValid) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: 'JWT signature is invalid.',
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: 'JWT signature is invalid.',
}),
],
};
}

Expand Down
18 changes: 9 additions & 9 deletions packages/backend/src/tokens/handshake.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,9 +6,9 @@ import { loadClerkJWKFromLocal, loadClerkJWKFromRemote } from './keys';
import type { VerifyTokenOptions } from './verify';

async function verifyHandshakeJwt(token: string, { key }: VerifyJwtOptions): Promise<{ handshake: string[] }> {
const { data: decoded, error } = decodeJwt(token);
if (error) {
throw error;
const { data: decoded, errors } = decodeJwt(token);
if (errors) {
throw errors[0];
}

const { header, payload } = decoded;
Expand All@@ -19,11 +19,11 @@ async function verifyHandshakeJwt(token: string, { key }: VerifyJwtOptions): Pro
assertHeaderType(typ);
assertHeaderAlgorithm(alg);

const { data: signatureValid, error: signatureError } = await hasValidSignature(decoded, key);
if (signatureError) {
const { data: signatureValid, errors: signatureErrors } = await hasValidSignature(decoded, key);
if (signatureErrors) {
throw new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying handshake token. ${signatureError}`,
message: `Error verifying handshake token. ${signatureErrors[0]}`,
});
}

Expand All@@ -46,9 +46,9 @@ export async function verifyHandshakeToken(
): Promise<{ handshake: string[] }> {
const { secretKey, apiUrl, apiVersion, jwksCacheTtlInMs, jwtKey, skipJwksCache } = options;

const { data, error } = decodeJwt(token);
if (error) {
throw error;
const { data, errors } = decodeJwt(token);
if (errors) {
throw errors[0];
}

const { kid } = data.header;
Expand Down
22 changes: 11 additions & 11 deletions packages/backend/src/tokens/request.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -117,7 +117,7 @@ export async function authenticateRequest(
return signedOut(authenticateContext, AuthErrorReason.SessionTokenMissing, '', headers);
}

const { data, error } = await verifyToken(sessionToken, authenticateContext);
const { data, errors: [error] = [] } = await verifyToken(sessionToken, authenticateContext);
if (data) {
return signedIn(authenticateContext, data, headers, sessionToken);
}
Expand All@@ -140,7 +140,7 @@ ${error.getFullMessage()}`,
);

// Retry with a generous clock skew allowance (1 day)
const { data: retryResult, error: retryError } = await verifyToken(sessionToken, {
const { data: retryResult, errors: [retryError] = [] } = await verifyToken(sessionToken, {
...authenticateContext,
clockSkewInMs: 86_400_000,
});
Expand DownExpand Up@@ -180,9 +180,9 @@ ${error.getFullMessage()}`,
const { sessionTokenInHeader } = authenticateContext;

try {
const { data, error } = await verifyToken(sessionTokenInHeader!, authenticateContext);
if (error) {
throw error;
const { data, errors } = await verifyToken(sessionTokenInHeader!, authenticateContext);
if (errors) {
throw errors[0];
}
// use `await` to force this try/catch handle the signedIn invocation
return await signedIn(authenticateContext, data, undefined, sessionTokenInHeader!);
Expand DownExpand Up@@ -286,19 +286,19 @@ ${error.getFullMessage()}`,
return handleMaybeHandshakeStatus(authenticateContext, AuthErrorReason.ClientUATWithoutSessionToken, '');
}

const { data: decodeResult, error: decodedError } = decodeJwt(authenticateContext.sessionTokenInCookie!);
if (decodedError) {
return handleError(decodedError, 'cookie');
const { data: decodeResult, errors: decodedErrors } = decodeJwt(authenticateContext.sessionTokenInCookie!);
if (decodedErrors) {
return handleError(decodedErrors[0], 'cookie');
}

if (decodeResult.payload.iat < authenticateContext.clientUat) {
return handleMaybeHandshakeStatus(authenticateContext, AuthErrorReason.SessionTokenOutdated, '');
}

try {
const { data, error } = await verifyToken(authenticateContext.sessionTokenInCookie!, authenticateContext);
if (error) {
throw error;
const { data, errors } = await verifyToken(authenticateContext.sessionTokenInCookie!, authenticateContext);
if (errors) {
throw errors[0];
}
// use `await` to force this try/catch handle the signedIn invocation
return await signedIn(authenticateContext, data, undefined, authenticateContext.sessionTokenInCookie!);
Expand Down
20 changes: 11 additions & 9 deletions packages/backend/src/tokens/verify.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,9 @@ export async function verifyToken(
token: string,
options: VerifyTokenOptions,
): Promise<JwtReturnType<JwtPayload, TokenVerificationError>> {
const { data: decodedResult, error: decodedError } = decodeJwt(token);
if (decodedError) {
return { error: decodedError };
const { data: decodedResult, errors } = decodeJwt(token);
if (errors) {
return { errors };
}

const { header } = decodedResult;
Expand All@@ -32,16 +32,18 @@ export async function verifyToken(
key = await loadClerkJWKFromRemote({ ...options, kid });
} else {
return {
error: new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkJWTKey,
message: 'Failed to resolve JWK during verification.',
reason: TokenVerificationErrorReason.JWKFailedToResolve,
}),
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkJWTKey,
message: 'Failed to resolve JWK during verification.',
reason: TokenVerificationErrorReason.JWKFailedToResolve,
}),
],
};
}

return await verifyJwt(token, { ...options, key });
} catch (error) {
return { error: error as TokenVerificationError };
return { errors: [error as TokenVerificationError] };
}
}
12 changes: 6 additions & 6 deletions packages/nextjs/src/server/createGetAuth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -46,9 +46,9 @@ export const createGetAuth = ({
logger.debug('Options debug', options);

if (authStatus === AuthStatus.SignedIn) {
const { data: jwt, error } = decodeJwt(authToken as string);
if (error) {
throw error;
const { data: jwt, errors } = decodeJwt(authToken as string);
if (errors) {
throw errors[0];
}

logger.debug('JWT debug', jwt.raw.text);
Expand All@@ -68,10 +68,10 @@ export const getAuth = createGetAuth({
export const parseJwt = (req: RequestLike) => {
const cookieToken = getCookie(req, constants.Cookies.Session);
const headerToken = getHeader(req, 'authorization')?.replace('Bearer ', '');
const { data, error } = decodeJwt(cookieToken || headerToken || '');
const { data, errors } = decodeJwt(cookieToken || headerToken || '');

if (error) {
throw error;
if (errors) {
throw errors[0];
}

return data;
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 41 additions & 0 deletions .changeset/unlucky-frogs-tap.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
---
'@clerk/backend': major
'@clerk/nextjs': major
---

Replace return the value of the following jwt helpers to match the format of backend API client return values (for consistency).

```diff
import { signJwt } from '@clerk/backend/jwt';

- const { data, error } = await signJwt(...);
+ const { data, errors: [error] = [] } = await signJwt(...);
```

```diff
import { verifyJwt } from '@clerk/backend/jwt';

- const { data, error } = await verifyJwt(...);
+ const { data, errors: [error] = [] } = await verifyJwt(...);
```

```diff
import { hasValidSignature } from '@clerk/backend/jwt';

- const { data, error } = await hasValidSignature(...);
+ const { data, errors: [error] = [] } = await hasValidSignature(...);
```

```diff
import { decodeJwt } from '@clerk/backend/jwt';

- const { data, error } = await decodeJwt(...);
+ const { data, errors: [error] = [] } = await decodeJwt(...);
```

```diff
import { verifyToken } from '@clerk/backend';

- const { data, error } = await verifyToken(...);
+ const { data, errors: [error] = [] } = await verifyToken(...);
```
12 changes: 6 additions & 6 deletions packages/backend/src/jwt/__tests__/verifyJwt.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -56,27 +56,27 @@ export default (QUnit: QUnit) => {
});

test('returns an error if null is given as jwt', assert => {
const { error } = decodeJwt('null');
const { errors: [error] = [] } = decodeJwt('null');
assert.propContains(error, invalidTokenError);
});

test('returns an error if undefined is given as jwt', assert => {
const { error } = decodeJwt('undefined');
const { errors: [error] = [] } = decodeJwt('undefined');
assert.propContains(error, invalidTokenError);
});

test('returns an error if empty string is given as jwt', assert => {
const { error } = decodeJwt('');
const { errors: [error] = [] } = decodeJwt('');
assert.propContains(error, invalidTokenError);
});

test('throws an error if invalid string is given as jwt', assert => {
const { error } = decodeJwt('whatever');
const { errors: [error] = [] } = decodeJwt('whatever');
assert.propContains(error, invalidTokenError);
});

test('throws an error if number is given as jwt', assert => {
const { error } = decodeJwt('42');
const { errors: [error] = [] } = decodeJwt('42');
assert.propContains(error, invalidTokenError);
});
});
Expand DownExpand Up@@ -127,7 +127,7 @@ export default (QUnit: QUnit) => {
issuer: mockJwtPayload.iss,
authorizedParties: ['', 'https://accounts.inspired.puma-74.lcl.dev'],
};
const { error } = await verifyJwt('invalid-jwt', inputVerifyJwtOptions);
const { errors: [error] = [] } = await verifyJwt('invalid-jwt', inputVerifyJwtOptions);
assert.propContains(error, invalidTokenError);
});
});
Expand Down
2 changes: 1 addition & 1 deletion packages/backend/src/jwt/signJwt.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -60,6 +60,6 @@ export async function signJwt(
const encodedSignature = `${firstPart}.${base64url.stringify(new Uint8Array(signature), { pad: false })}`;
return { data: encodedSignature };
} catch (error) {
return { error: new SignJWTError((error as Error)?.message) };
return { errors: [new SignJWTError((error as Error)?.message)] };
}
}
4 changes: 2 additions & 2 deletions packages/backend/src/jwt/types.ts
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
export type JwtReturnType<R, E extends Error> =
| {
data: R;
error?: undefined;
errors?: undefined;
}
| {
data?: undefined;
error: E;
errors: [E];

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

with this type we make it explicit that the errors in this case will have a maximum of 1 item.

};
54 changes: 31 additions & 23 deletions packages/backend/src/jwt/verifyJwt.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -34,10 +34,12 @@ export async function hasValidSignature(jwt: Jwt, key: JsonWebKey | string): Pro
return { data: verified };
} catch (error) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: (error as Error)?.message,
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: (error as Error)?.message,
}),
],
};
}
}
Expand All@@ -46,10 +48,12 @@ export function decodeJwt(token: string): JwtReturnType<Jwt, TokenVerificationEr
const tokenParts = (token || '').toString().split('.');
if (tokenParts.length !== 3) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalid,
message: `Invalid JWT form. A JWT consists of three parts separated by dots.`,
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalid,
message: `Invalid JWT form. A JWT consists of three parts separated by dots.`,
}),
],
};
}

Expand DownExpand Up@@ -105,9 +109,9 @@ export async function verifyJwt(
const { audience, authorizedParties, clockSkewInMs, key } = options;
const clockSkew = clockSkewInMs || DEFAULT_CLOCK_SKEW_IN_SECONDS;

const { data: decoded, error } = decodeJwt(token);
if (error) {
return { error };
const { data: decoded, errors } = decodeJwt(token);
if (errors) {
return { errors };
}

const { header, payload } = decoded;
Expand All@@ -128,26 +132,30 @@ export async function verifyJwt(
assertActivationClaim(nbf, clockSkew);
assertIssuedAtClaim(iat, clockSkew);
} catch (err) {
return { error: err as TokenVerificationError };
return { errors: [err as TokenVerificationError] };
}

const { data: signatureValid, error: signatureError } = await hasValidSignature(decoded, key);
if (signatureError) {
const { data: signatureValid, errors: signatureErrors } = await hasValidSignature(decoded, key);
if (signatureErrors) {
return {
error: new TokenVerificationError({
action: TokenVerificationErrorAction.EnsureClerkJWT,
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying JWT signature. ${signatureError}`,
}),
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.EnsureClerkJWT,
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying JWT signature. ${signatureErrors[0]}`,
}),
],
};
}

if (!signatureValid) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: 'JWT signature is invalid.',
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: 'JWT signature is invalid.',
}),
],
};
}

Expand Down
18 changes: 9 additions & 9 deletions packages/backend/src/tokens/handshake.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,9 +6,9 @@ import { loadClerkJWKFromLocal, loadClerkJWKFromRemote } from './keys';
import type { VerifyTokenOptions } from './verify';

async function verifyHandshakeJwt(token: string, { key }: VerifyJwtOptions): Promise<{ handshake: string[] }> {
const { data: decoded, error } = decodeJwt(token);
if (error) {
throw error;
const { data: decoded, errors } = decodeJwt(token);
if (errors) {
throw errors[0];
}

const { header, payload } = decoded;
Expand All@@ -19,11 +19,11 @@ async function verifyHandshakeJwt(token: string, { key }: VerifyJwtOptions): Pro
assertHeaderType(typ);
assertHeaderAlgorithm(alg);

const { data: signatureValid, error: signatureError } = await hasValidSignature(decoded, key);
if (signatureError) {
const { data: signatureValid, errors: signatureErrors } = await hasValidSignature(decoded, key);
if (signatureErrors) {
throw new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying handshake token. ${signatureError}`,
message: `Error verifying handshake token. ${signatureErrors[0]}`,
});
}

Expand All@@ -46,9 +46,9 @@ export async function verifyHandshakeToken(
): Promise<{ handshake: string[] }> {
const { secretKey, apiUrl, apiVersion, jwksCacheTtlInMs, jwtKey, skipJwksCache } = options;

const { data, error } = decodeJwt(token);
if (error) {
throw error;
const { data, errors } = decodeJwt(token);
if (errors) {
throw errors[0];
}

const { kid } = data.header;
Expand Down
22 changes: 11 additions & 11 deletions packages/backend/src/tokens/request.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -117,7 +117,7 @@ export async function authenticateRequest(
return signedOut(authenticateContext, AuthErrorReason.SessionTokenMissing, '', headers);
}

const { data, error } = await verifyToken(sessionToken, authenticateContext);
const { data, errors: [error] = [] } = await verifyToken(sessionToken, authenticateContext);
if (data) {
return signedIn(authenticateContext, data, headers, sessionToken);
}
Expand All@@ -140,7 +140,7 @@ ${error.getFullMessage()}`,
);

// Retry with a generous clock skew allowance (1 day)
const { data: retryResult, error: retryError } = await verifyToken(sessionToken, {
const { data: retryResult, errors: [retryError] = [] } = await verifyToken(sessionToken, {
...authenticateContext,
clockSkewInMs: 86_400_000,
});
Expand DownExpand Up@@ -180,9 +180,9 @@ ${error.getFullMessage()}`,
const { sessionTokenInHeader } = authenticateContext;

try {
const { data, error } = await verifyToken(sessionTokenInHeader!, authenticateContext);
if (error) {
throw error;
const { data, errors } = await verifyToken(sessionTokenInHeader!, authenticateContext);
if (errors) {
throw errors[0];
}
// use `await` to force this try/catch handle the signedIn invocation
return await signedIn(authenticateContext, data, undefined, sessionTokenInHeader!);
Expand DownExpand Up@@ -286,19 +286,19 @@ ${error.getFullMessage()}`,
return handleMaybeHandshakeStatus(authenticateContext, AuthErrorReason.ClientUATWithoutSessionToken, '');
}

const { data: decodeResult, error: decodedError } = decodeJwt(authenticateContext.sessionTokenInCookie!);
if (decodedError) {
return handleError(decodedError, 'cookie');
const { data: decodeResult, errors: decodedErrors } = decodeJwt(authenticateContext.sessionTokenInCookie!);
if (decodedErrors) {
return handleError(decodedErrors[0], 'cookie');
}

if (decodeResult.payload.iat < authenticateContext.clientUat) {
return handleMaybeHandshakeStatus(authenticateContext, AuthErrorReason.SessionTokenOutdated, '');
}

try {
const { data, error } = await verifyToken(authenticateContext.sessionTokenInCookie!, authenticateContext);
if (error) {
throw error;
const { data, errors } = await verifyToken(authenticateContext.sessionTokenInCookie!, authenticateContext);
if (errors) {
throw errors[0];
}
// use `await` to force this try/catch handle the signedIn invocation
return await signedIn(authenticateContext, data, undefined, authenticateContext.sessionTokenInCookie!);
Expand Down
20 changes: 11 additions & 9 deletions packages/backend/src/tokens/verify.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,9 @@ export async function verifyToken(
token: string,
options: VerifyTokenOptions,
): Promise<JwtReturnType<JwtPayload, TokenVerificationError>> {
const { data: decodedResult, error: decodedError } = decodeJwt(token);
if (decodedError) {
return { error: decodedError };
const { data: decodedResult, errors } = decodeJwt(token);
if (errors) {
return { errors };
}

const { header } = decodedResult;
Expand All@@ -32,16 +32,18 @@ export async function verifyToken(
key = await loadClerkJWKFromRemote({ ...options, kid });
} else {
return {
error: new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkJWTKey,
message: 'Failed to resolve JWK during verification.',
reason: TokenVerificationErrorReason.JWKFailedToResolve,
}),
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkJWTKey,
message: 'Failed to resolve JWK during verification.',
reason: TokenVerificationErrorReason.JWKFailedToResolve,
}),
],
};
}

return await verifyJwt(token, { ...options, key });
} catch (error) {
return { error: error as TokenVerificationError };
return { errors: [error as TokenVerificationError] };
}
}
12 changes: 6 additions & 6 deletions packages/nextjs/src/server/createGetAuth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -46,9 +46,9 @@ export const createGetAuth = ({
logger.debug('Options debug', options);

if (authStatus === AuthStatus.SignedIn) {
const { data: jwt, error } = decodeJwt(authToken as string);
if (error) {
throw error;
const { data: jwt, errors } = decodeJwt(authToken as string);
if (errors) {
throw errors[0];
}

logger.debug('JWT debug', jwt.raw.text);
Expand All@@ -68,10 +68,10 @@ export const getAuth = createGetAuth({
export const parseJwt = (req: RequestLike) => {
const cookieToken = getCookie(req, constants.Cookies.Session);
const headerToken = getHeader(req, 'authorization')?.replace('Bearer ', '');
const { data, error } = decodeJwt(cookieToken || headerToken || '');
const { data, errors } = decodeJwt(cookieToken || headerToken || '');

if (error) {
throw error;
if (errors) {
throw errors[0];
}

return data;
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 41 additions & 0 deletions .changeset/unlucky-frogs-tap.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
---
'@clerk/backend': major
'@clerk/nextjs': major
---

Replace return the value of the following jwt helpers to match the format of backend API client return values (for consistency).

```diff
import { signJwt } from '@clerk/backend/jwt';

- const { data, error } = await signJwt(...);
+ const { data, errors: [error] = [] } = await signJwt(...);
```

```diff
import { verifyJwt } from '@clerk/backend/jwt';

- const { data, error } = await verifyJwt(...);
+ const { data, errors: [error] = [] } = await verifyJwt(...);
```

```diff
import { hasValidSignature } from '@clerk/backend/jwt';

- const { data, error } = await hasValidSignature(...);
+ const { data, errors: [error] = [] } = await hasValidSignature(...);
```

```diff
import { decodeJwt } from '@clerk/backend/jwt';

- const { data, error } = await decodeJwt(...);
+ const { data, errors: [error] = [] } = await decodeJwt(...);
```

```diff
import { verifyToken } from '@clerk/backend';

- const { data, error } = await verifyToken(...);
+ const { data, errors: [error] = [] } = await verifyToken(...);
```
12 changes: 6 additions & 6 deletions packages/backend/src/jwt/__tests__/verifyJwt.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -56,27 +56,27 @@ export default (QUnit: QUnit) => {
});

test('returns an error if null is given as jwt', assert => {
const { error } = decodeJwt('null');
const { errors: [error] = [] } = decodeJwt('null');
assert.propContains(error, invalidTokenError);
});

test('returns an error if undefined is given as jwt', assert => {
const { error } = decodeJwt('undefined');
const { errors: [error] = [] } = decodeJwt('undefined');
assert.propContains(error, invalidTokenError);
});

test('returns an error if empty string is given as jwt', assert => {
const { error } = decodeJwt('');
const { errors: [error] = [] } = decodeJwt('');
assert.propContains(error, invalidTokenError);
});

test('throws an error if invalid string is given as jwt', assert => {
const { error } = decodeJwt('whatever');
const { errors: [error] = [] } = decodeJwt('whatever');
assert.propContains(error, invalidTokenError);
});

test('throws an error if number is given as jwt', assert => {
const { error } = decodeJwt('42');
const { errors: [error] = [] } = decodeJwt('42');
assert.propContains(error, invalidTokenError);
});
});
Expand DownExpand Up@@ -127,7 +127,7 @@ export default (QUnit: QUnit) => {
issuer: mockJwtPayload.iss,
authorizedParties: ['', 'https://accounts.inspired.puma-74.lcl.dev'],
};
const { error } = await verifyJwt('invalid-jwt', inputVerifyJwtOptions);
const { errors: [error] = [] } = await verifyJwt('invalid-jwt', inputVerifyJwtOptions);
assert.propContains(error, invalidTokenError);
});
});
Expand Down
2 changes: 1 addition & 1 deletion packages/backend/src/jwt/signJwt.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -60,6 +60,6 @@ export async function signJwt(
const encodedSignature = `${firstPart}.${base64url.stringify(new Uint8Array(signature), { pad: false })}`;
return { data: encodedSignature };
} catch (error) {
return { error: new SignJWTError((error as Error)?.message) };
return { errors: [new SignJWTError((error as Error)?.message)] };
}
}
4 changes: 2 additions & 2 deletions packages/backend/src/jwt/types.ts
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
export type JwtReturnType<R, E extends Error> =
| {
data: R;
error?: undefined;
errors?: undefined;
}
| {
data?: undefined;
error: E;
errors: [E];

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

with this type we make it explicit that the errors in this case will have a maximum of 1 item.

};
54 changes: 31 additions & 23 deletions packages/backend/src/jwt/verifyJwt.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -34,10 +34,12 @@ export async function hasValidSignature(jwt: Jwt, key: JsonWebKey | string): Pro
return { data: verified };
} catch (error) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: (error as Error)?.message,
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: (error as Error)?.message,
}),
],
};
}
}
Expand All@@ -46,10 +48,12 @@ export function decodeJwt(token: string): JwtReturnType<Jwt, TokenVerificationEr
const tokenParts = (token || '').toString().split('.');
if (tokenParts.length !== 3) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalid,
message: `Invalid JWT form. A JWT consists of three parts separated by dots.`,
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalid,
message: `Invalid JWT form. A JWT consists of three parts separated by dots.`,
}),
],
};
}

Expand DownExpand Up@@ -105,9 +109,9 @@ export async function verifyJwt(
const { audience, authorizedParties, clockSkewInMs, key } = options;
const clockSkew = clockSkewInMs || DEFAULT_CLOCK_SKEW_IN_SECONDS;

const { data: decoded, error } = decodeJwt(token);
if (error) {
return { error };
const { data: decoded, errors } = decodeJwt(token);
if (errors) {
return { errors };
}

const { header, payload } = decoded;
Expand All@@ -128,26 +132,30 @@ export async function verifyJwt(
assertActivationClaim(nbf, clockSkew);
assertIssuedAtClaim(iat, clockSkew);
} catch (err) {
return { error: err as TokenVerificationError };
return { errors: [err as TokenVerificationError] };
}

const { data: signatureValid, error: signatureError } = await hasValidSignature(decoded, key);
if (signatureError) {
const { data: signatureValid, errors: signatureErrors } = await hasValidSignature(decoded, key);
if (signatureErrors) {
return {
error: new TokenVerificationError({
action: TokenVerificationErrorAction.EnsureClerkJWT,
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying JWT signature. ${signatureError}`,
}),
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.EnsureClerkJWT,
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying JWT signature. ${signatureErrors[0]}`,
}),
],
};
}

if (!signatureValid) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: 'JWT signature is invalid.',
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: 'JWT signature is invalid.',
}),
],
};
}

Expand Down
18 changes: 9 additions & 9 deletions packages/backend/src/tokens/handshake.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,9 +6,9 @@ import { loadClerkJWKFromLocal, loadClerkJWKFromRemote } from './keys';
import type { VerifyTokenOptions } from './verify';

async function verifyHandshakeJwt(token: string, { key }: VerifyJwtOptions): Promise<{ handshake: string[] }> {
const { data: decoded, error } = decodeJwt(token);
if (error) {
throw error;
const { data: decoded, errors } = decodeJwt(token);
if (errors) {
throw errors[0];
}

const { header, payload } = decoded;
Expand All@@ -19,11 +19,11 @@ async function verifyHandshakeJwt(token: string, { key }: VerifyJwtOptions): Pro
assertHeaderType(typ);
assertHeaderAlgorithm(alg);

const { data: signatureValid, error: signatureError } = await hasValidSignature(decoded, key);
if (signatureError) {
const { data: signatureValid, errors: signatureErrors } = await hasValidSignature(decoded, key);
if (signatureErrors) {
throw new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying handshake token. ${signatureError}`,
message: `Error verifying handshake token. ${signatureErrors[0]}`,
});
}

Expand All@@ -46,9 +46,9 @@ export async function verifyHandshakeToken(
): Promise<{ handshake: string[] }> {
const { secretKey, apiUrl, apiVersion, jwksCacheTtlInMs, jwtKey, skipJwksCache } = options;

const { data, error } = decodeJwt(token);
if (error) {
throw error;
const { data, errors } = decodeJwt(token);
if (errors) {
throw errors[0];
}

const { kid } = data.header;
Expand Down
22 changes: 11 additions & 11 deletions packages/backend/src/tokens/request.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -117,7 +117,7 @@ export async function authenticateRequest(
return signedOut(authenticateContext, AuthErrorReason.SessionTokenMissing, '', headers);
}

const { data, error } = await verifyToken(sessionToken, authenticateContext);
const { data, errors: [error] = [] } = await verifyToken(sessionToken, authenticateContext);
if (data) {
return signedIn(authenticateContext, data, headers, sessionToken);
}
Expand All@@ -140,7 +140,7 @@ ${error.getFullMessage()}`,
);

// Retry with a generous clock skew allowance (1 day)
const { data: retryResult, error: retryError } = await verifyToken(sessionToken, {
const { data: retryResult, errors: [retryError] = [] } = await verifyToken(sessionToken, {
...authenticateContext,
clockSkewInMs: 86_400_000,
});
Expand DownExpand Up@@ -180,9 +180,9 @@ ${error.getFullMessage()}`,
const { sessionTokenInHeader } = authenticateContext;

try {
const { data, error } = await verifyToken(sessionTokenInHeader!, authenticateContext);
if (error) {
throw error;
const { data, errors } = await verifyToken(sessionTokenInHeader!, authenticateContext);
if (errors) {
throw errors[0];
}
// use `await` to force this try/catch handle the signedIn invocation
return await signedIn(authenticateContext, data, undefined, sessionTokenInHeader!);
Expand DownExpand Up@@ -286,19 +286,19 @@ ${error.getFullMessage()}`,
return handleMaybeHandshakeStatus(authenticateContext, AuthErrorReason.ClientUATWithoutSessionToken, '');
}

const { data: decodeResult, error: decodedError } = decodeJwt(authenticateContext.sessionTokenInCookie!);
if (decodedError) {
return handleError(decodedError, 'cookie');
const { data: decodeResult, errors: decodedErrors } = decodeJwt(authenticateContext.sessionTokenInCookie!);
if (decodedErrors) {
return handleError(decodedErrors[0], 'cookie');
}

if (decodeResult.payload.iat < authenticateContext.clientUat) {
return handleMaybeHandshakeStatus(authenticateContext, AuthErrorReason.SessionTokenOutdated, '');
}

try {
const { data, error } = await verifyToken(authenticateContext.sessionTokenInCookie!, authenticateContext);
if (error) {
throw error;
const { data, errors } = await verifyToken(authenticateContext.sessionTokenInCookie!, authenticateContext);
if (errors) {
throw errors[0];
}
// use `await` to force this try/catch handle the signedIn invocation
return await signedIn(authenticateContext, data, undefined, authenticateContext.sessionTokenInCookie!);
Expand Down
20 changes: 11 additions & 9 deletions packages/backend/src/tokens/verify.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,9 @@ export async function verifyToken(
token: string,
options: VerifyTokenOptions,
): Promise<JwtReturnType<JwtPayload, TokenVerificationError>> {
const { data: decodedResult, error: decodedError } = decodeJwt(token);
if (decodedError) {
return { error: decodedError };
const { data: decodedResult, errors } = decodeJwt(token);
if (errors) {
return { errors };
}

const { header } = decodedResult;
Expand All@@ -32,16 +32,18 @@ export async function verifyToken(
key = await loadClerkJWKFromRemote({ ...options, kid });
} else {
return {
error: new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkJWTKey,
message: 'Failed to resolve JWK during verification.',
reason: TokenVerificationErrorReason.JWKFailedToResolve,
}),
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkJWTKey,
message: 'Failed to resolve JWK during verification.',
reason: TokenVerificationErrorReason.JWKFailedToResolve,
}),
],
};
}

return await verifyJwt(token, { ...options, key });
} catch (error) {
return { error: error as TokenVerificationError };
return { errors: [error as TokenVerificationError] };
}
}
12 changes: 6 additions & 6 deletions packages/nextjs/src/server/createGetAuth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -46,9 +46,9 @@ export const createGetAuth = ({
logger.debug('Options debug', options);

if (authStatus === AuthStatus.SignedIn) {
const { data: jwt, error } = decodeJwt(authToken as string);
if (error) {
throw error;
const { data: jwt, errors } = decodeJwt(authToken as string);
if (errors) {
throw errors[0];
}

logger.debug('JWT debug', jwt.raw.text);
Expand All@@ -68,10 +68,10 @@ export const getAuth = createGetAuth({
export const parseJwt = (req: RequestLike) => {
const cookieToken = getCookie(req, constants.Cookies.Session);
const headerToken = getHeader(req, 'authorization')?.replace('Bearer ', '');
const { data, error } = decodeJwt(cookieToken || headerToken || '');
const { data, errors } = decodeJwt(cookieToken || headerToken || '');

if (error) {
throw error;
if (errors) {
throw errors[0];
}

return data;
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 41 additions & 0 deletions .changeset/unlucky-frogs-tap.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
---
'@clerk/backend': major
'@clerk/nextjs': major
---

Replace return the value of the following jwt helpers to match the format of backend API client return values (for consistency).

```diff
import { signJwt } from '@clerk/backend/jwt';

- const { data, error } = await signJwt(...);
+ const { data, errors: [error] = [] } = await signJwt(...);
```

```diff
import { verifyJwt } from '@clerk/backend/jwt';

- const { data, error } = await verifyJwt(...);
+ const { data, errors: [error] = [] } = await verifyJwt(...);
```

```diff
import { hasValidSignature } from '@clerk/backend/jwt';

- const { data, error } = await hasValidSignature(...);
+ const { data, errors: [error] = [] } = await hasValidSignature(...);
```

```diff
import { decodeJwt } from '@clerk/backend/jwt';

- const { data, error } = await decodeJwt(...);
+ const { data, errors: [error] = [] } = await decodeJwt(...);
```

```diff
import { verifyToken } from '@clerk/backend';

- const { data, error } = await verifyToken(...);
+ const { data, errors: [error] = [] } = await verifyToken(...);
```
12 changes: 6 additions & 6 deletions packages/backend/src/jwt/__tests__/verifyJwt.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -56,27 +56,27 @@ export default (QUnit: QUnit) => {
});

test('returns an error if null is given as jwt', assert => {
const { error } = decodeJwt('null');
const { errors: [error] = [] } = decodeJwt('null');
assert.propContains(error, invalidTokenError);
});

test('returns an error if undefined is given as jwt', assert => {
const { error } = decodeJwt('undefined');
const { errors: [error] = [] } = decodeJwt('undefined');
assert.propContains(error, invalidTokenError);
});

test('returns an error if empty string is given as jwt', assert => {
const { error } = decodeJwt('');
const { errors: [error] = [] } = decodeJwt('');
assert.propContains(error, invalidTokenError);
});

test('throws an error if invalid string is given as jwt', assert => {
const { error } = decodeJwt('whatever');
const { errors: [error] = [] } = decodeJwt('whatever');
assert.propContains(error, invalidTokenError);
});

test('throws an error if number is given as jwt', assert => {
const { error } = decodeJwt('42');
const { errors: [error] = [] } = decodeJwt('42');
assert.propContains(error, invalidTokenError);
});
});
Expand DownExpand Up@@ -127,7 +127,7 @@ export default (QUnit: QUnit) => {
issuer: mockJwtPayload.iss,
authorizedParties: ['', 'https://accounts.inspired.puma-74.lcl.dev'],
};
const { error } = await verifyJwt('invalid-jwt', inputVerifyJwtOptions);
const { errors: [error] = [] } = await verifyJwt('invalid-jwt', inputVerifyJwtOptions);
assert.propContains(error, invalidTokenError);
});
});
Expand Down
2 changes: 1 addition & 1 deletion packages/backend/src/jwt/signJwt.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -60,6 +60,6 @@ export async function signJwt(
const encodedSignature = `${firstPart}.${base64url.stringify(new Uint8Array(signature), { pad: false })}`;
return { data: encodedSignature };
} catch (error) {
return { error: new SignJWTError((error as Error)?.message) };
return { errors: [new SignJWTError((error as Error)?.message)] };
}
}
4 changes: 2 additions & 2 deletions packages/backend/src/jwt/types.ts
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
export type JwtReturnType<R, E extends Error> =
| {
data: R;
error?: undefined;
errors?: undefined;
}
| {
data?: undefined;
error: E;
errors: [E];

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

with this type we make it explicit that the errors in this case will have a maximum of 1 item.

};
54 changes: 31 additions & 23 deletions packages/backend/src/jwt/verifyJwt.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -34,10 +34,12 @@ export async function hasValidSignature(jwt: Jwt, key: JsonWebKey | string): Pro
return { data: verified };
} catch (error) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: (error as Error)?.message,
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: (error as Error)?.message,
}),
],
};
}
}
Expand All@@ -46,10 +48,12 @@ export function decodeJwt(token: string): JwtReturnType<Jwt, TokenVerificationEr
const tokenParts = (token || '').toString().split('.');
if (tokenParts.length !== 3) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalid,
message: `Invalid JWT form. A JWT consists of three parts separated by dots.`,
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalid,
message: `Invalid JWT form. A JWT consists of three parts separated by dots.`,
}),
],
};
}

Expand DownExpand Up@@ -105,9 +109,9 @@ export async function verifyJwt(
const { audience, authorizedParties, clockSkewInMs, key } = options;
const clockSkew = clockSkewInMs || DEFAULT_CLOCK_SKEW_IN_SECONDS;

const { data: decoded, error } = decodeJwt(token);
if (error) {
return { error };
const { data: decoded, errors } = decodeJwt(token);
if (errors) {
return { errors };
}

const { header, payload } = decoded;
Expand All@@ -128,26 +132,30 @@ export async function verifyJwt(
assertActivationClaim(nbf, clockSkew);
assertIssuedAtClaim(iat, clockSkew);
} catch (err) {
return { error: err as TokenVerificationError };
return { errors: [err as TokenVerificationError] };
}

const { data: signatureValid, error: signatureError } = await hasValidSignature(decoded, key);
if (signatureError) {
const { data: signatureValid, errors: signatureErrors } = await hasValidSignature(decoded, key);
if (signatureErrors) {
return {
error: new TokenVerificationError({
action: TokenVerificationErrorAction.EnsureClerkJWT,
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying JWT signature. ${signatureError}`,
}),
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.EnsureClerkJWT,
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying JWT signature. ${signatureErrors[0]}`,
}),
],
};
}

if (!signatureValid) {
return {
error: new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: 'JWT signature is invalid.',
}),
errors: [
new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenInvalidSignature,
message: 'JWT signature is invalid.',
}),
],
};
}

Expand Down
18 changes: 9 additions & 9 deletions packages/backend/src/tokens/handshake.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,9 +6,9 @@ import { loadClerkJWKFromLocal, loadClerkJWKFromRemote } from './keys';
import type { VerifyTokenOptions } from './verify';

async function verifyHandshakeJwt(token: string, { key }: VerifyJwtOptions): Promise<{ handshake: string[] }> {
const { data: decoded, error } = decodeJwt(token);
if (error) {
throw error;
const { data: decoded, errors } = decodeJwt(token);
if (errors) {
throw errors[0];
}

const { header, payload } = decoded;
Expand All@@ -19,11 +19,11 @@ async function verifyHandshakeJwt(token: string, { key }: VerifyJwtOptions): Pro
assertHeaderType(typ);
assertHeaderAlgorithm(alg);

const { data: signatureValid, error: signatureError } = await hasValidSignature(decoded, key);
if (signatureError) {
const { data: signatureValid, errors: signatureErrors } = await hasValidSignature(decoded, key);
if (signatureErrors) {
throw new TokenVerificationError({
reason: TokenVerificationErrorReason.TokenVerificationFailed,
message: `Error verifying handshake token. ${signatureError}`,
message: `Error verifying handshake token. ${signatureErrors[0]}`,
});
}

Expand All@@ -46,9 +46,9 @@ export async function verifyHandshakeToken(
): Promise<{ handshake: string[] }> {
const { secretKey, apiUrl, apiVersion, jwksCacheTtlInMs, jwtKey, skipJwksCache } = options;

const { data, error } = decodeJwt(token);
if (error) {
throw error;
const { data, errors } = decodeJwt(token);
if (errors) {
throw errors[0];
}

const { kid } = data.header;
Expand Down
22 changes: 11 additions & 11 deletions packages/backend/src/tokens/request.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -117,7 +117,7 @@ export async function authenticateRequest(
return signedOut(authenticateContext, AuthErrorReason.SessionTokenMissing, '', headers);
}

const { data, error } = await verifyToken(sessionToken, authenticateContext);
const { data, errors: [error] = [] } = await verifyToken(sessionToken, authenticateContext);
if (data) {
return signedIn(authenticateContext, data, headers, sessionToken);
}
Expand All@@ -140,7 +140,7 @@ ${error.getFullMessage()}`,
);

// Retry with a generous clock skew allowance (1 day)
const { data: retryResult, error: retryError } = await verifyToken(sessionToken, {
const { data: retryResult, errors: [retryError] = [] } = await verifyToken(sessionToken, {
...authenticateContext,
clockSkewInMs: 86_400_000,
});
Expand DownExpand Up@@ -180,9 +180,9 @@ ${error.getFullMessage()}`,
const { sessionTokenInHeader } = authenticateContext;

try {
const { data, error } = await verifyToken(sessionTokenInHeader!, authenticateContext);
if (error) {
throw error;
const { data, errors } = await verifyToken(sessionTokenInHeader!, authenticateContext);
if (errors) {
throw errors[0];
}
// use `await` to force this try/catch handle the signedIn invocation
return await signedIn(authenticateContext, data, undefined, sessionTokenInHeader!);
Expand DownExpand Up@@ -286,19 +286,19 @@ ${error.getFullMessage()}`,
return handleMaybeHandshakeStatus(authenticateContext, AuthErrorReason.ClientUATWithoutSessionToken, '');
}

const { data: decodeResult, error: decodedError } = decodeJwt(authenticateContext.sessionTokenInCookie!);
if (decodedError) {
return handleError(decodedError, 'cookie');
const { data: decodeResult, errors: decodedErrors } = decodeJwt(authenticateContext.sessionTokenInCookie!);
if (decodedErrors) {
return handleError(decodedErrors[0], 'cookie');
}

if (decodeResult.payload.iat < authenticateContext.clientUat) {
return handleMaybeHandshakeStatus(authenticateContext, AuthErrorReason.SessionTokenOutdated, '');
}

try {
const { data, error } = await verifyToken(authenticateContext.sessionTokenInCookie!, authenticateContext);
if (error) {
throw error;
const { data, errors } = await verifyToken(authenticateContext.sessionTokenInCookie!, authenticateContext);
if (errors) {
throw errors[0];
}
// use `await` to force this try/catch handle the signedIn invocation
return await signedIn(authenticateContext, data, undefined, authenticateContext.sessionTokenInCookie!);
Expand Down
20 changes: 11 additions & 9 deletions packages/backend/src/tokens/verify.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -14,9 +14,9 @@ export async function verifyToken(
token: string,
options: VerifyTokenOptions,
): Promise<JwtReturnType<JwtPayload, TokenVerificationError>> {
const { data: decodedResult, error: decodedError } = decodeJwt(token);
if (decodedError) {
return { error: decodedError };
const { data: decodedResult, errors } = decodeJwt(token);
if (errors) {
return { errors };
}

const { header } = decodedResult;
Expand All@@ -32,16 +32,18 @@ export async function verifyToken(
key = await loadClerkJWKFromRemote({ ...options, kid });
} else {
return {
error: new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkJWTKey,
message: 'Failed to resolve JWK during verification.',
reason: TokenVerificationErrorReason.JWKFailedToResolve,
}),
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkJWTKey,
message: 'Failed to resolve JWK during verification.',
reason: TokenVerificationErrorReason.JWKFailedToResolve,
}),
],
};
}

return await verifyJwt(token, { ...options, key });
} catch (error) {
return { error: error as TokenVerificationError };
return { errors: [error as TokenVerificationError] };
}
}
12 changes: 6 additions & 6 deletions packages/nextjs/src/server/createGetAuth.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -46,9 +46,9 @@ export const createGetAuth = ({
logger.debug('Options debug', options);

if (authStatus === AuthStatus.SignedIn) {
const { data: jwt, error } = decodeJwt(authToken as string);
if (error) {
throw error;
const { data: jwt, errors } = decodeJwt(authToken as string);
if (errors) {
throw errors[0];
}

logger.debug('JWT debug', jwt.raw.text);
Expand All@@ -68,10 +68,10 @@ export const getAuth = createGetAuth({
export const parseJwt = (req: RequestLike) => {
const cookieToken = getCookie(req, constants.Cookies.Session);
const headerToken = getHeader(req, 'authorization')?.replace('Bearer ', '');
const { data, error } = decodeJwt(cookieToken || headerToken || '');
const { data, errors } = decodeJwt(cookieToken || headerToken || '');

if (error) {
throw error;
if (errors) {
throw errors[0];
}

return data;
Expand Down