feat: add actor token support for Custom Token Exchange impersonation & delegation#1595
feat: add actor token support for Custom Token Exchange impersonation & delegation#1595subhankarmaiti wants to merge 8 commits into
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughCustom token exchange now supports paired actor-token parameters across web, JavaScript, Android, and iOS paths. Validation prevents incomplete pairs, native requests construct actor tokens, user profiles expose ChangesActor token custom exchange
Estimated code review effort: 3 (Moderate) | ~25 minutes Sequence Diagram(s)sequenceDiagram
participant App
participant Auth0Client
participant WebOrNativeBridge
participant Auth0
App->>Auth0Client: customTokenExchange(actorToken, actorTokenType)
Auth0Client->>Auth0Client: validate paired parameters
Auth0Client->>WebOrNativeBridge: forward actor-token parameters
WebOrNativeBridge->>Auth0: exchange subject and actor tokens
Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 3
🧹 Nitpick comments (1)
src/core/utils/__tests__/validation.spec.ts (1)
24-33: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low valueUse Jest's built-in error matching.
The manual
try/catch/throwpattern can be simplified into a single concise assertion using Jest's.toThrow()combined withexpect.objectContaining().♻️ Proposed fix
- it('should throw with the invalid_actor_token_parameters code', () => { - try { - validateActorTokenParameters(undefined, 'urn:token-type'); - throw new Error('Expected validateActorTokenParameters to throw'); - } catch (e) { - expect(e).toBeInstanceOf(AuthError); - expect((e as AuthError).code).toBe('invalid_actor_token_parameters'); - } - }); + it('should throw with the invalid_actor_token_parameters code', () => { + expect(() => validateActorTokenParameters(undefined, 'urn:token-type')).toThrow( + expect.objectContaining({ code: 'invalid_actor_token_parameters' }) + ); + });🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@src/core/utils/__tests__/validation.spec.ts` around lines 24 - 33, Replace the manual try/catch and fallback throw in the validation test with Jest’s built-in error assertion around validateActorTokenParameters, using toThrow with expect.objectContaining to verify the AuthError instance and invalid_actor_token_parameters code.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/platforms/native/adapters/__tests__/NativeAuth0Client.spec.ts`:
- Around line 281-283: Remove the any casts from both customTokenExchange
assertions in src/platforms/native/adapters/__tests__/NativeAuth0Client.spec.ts
at lines 281-283 and 306-308, using the typed mock function directly or
jest.mocked(mockBridgeInstance.customTokenExchange). In
src/platforms/native/bridge/__tests__/NativeBridgeManager.spec.ts at lines
442-444, replace the any cast with an unknown-to-specific-type cast such as
Credentials, using the correct return type for the test.
In `@src/platforms/web/adapters/WebAuth0Client.ts`:
- Around line 265-266: Update the conditional property spreads in the
WebAuth0Client request payload to check actorToken and actorTokenType against
undefined rather than truthiness, ensuring empty-string values are included
consistently with validateActorTokenParameters and the paired fields are sent
together.
In `@src/types/common.ts`:
- Line 156: Update the act property in the relevant type definition to use
Record<string, unknown> instead of Record<string, any>, preserving its optional
nested actor-claim structure.
---
Nitpick comments:
In `@src/core/utils/__tests__/validation.spec.ts`:
- Around line 24-33: Replace the manual try/catch and fallback throw in the
validation test with Jest’s built-in error assertion around
validateActorTokenParameters, using toThrow with expect.objectContaining to
verify the AuthError instance and invalid_actor_token_parameters code.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 5e711f4b-b1ab-4117-804c-e1a9302fbd32
📒 Files selected for processing (16)
EXAMPLES.mdandroid/src/main/java/com/auth0/react/A0Auth0Module.ktios/NativeBridge.swiftsrc/core/models/__tests__/Auth0User.spec.tssrc/core/utils/__tests__/validation.spec.tssrc/core/utils/validation.tssrc/platforms/native/adapters/NativeAuth0Client.tssrc/platforms/native/adapters/__tests__/NativeAuth0Client.spec.tssrc/platforms/native/bridge/INativeBridge.tssrc/platforms/native/bridge/NativeBridgeManager.tssrc/platforms/native/bridge/__tests__/NativeBridgeManager.spec.tssrc/platforms/web/adapters/WebAuth0Client.tssrc/platforms/web/adapters/__tests__/WebAuth0Client.spec.tssrc/specs/NativeA0Auth0.tssrc/types/common.tssrc/types/parameters.ts
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@example/src/screens/class-based/ClassApiTests.tsx`:
- Around line 238-253: Update the custom token exchange button’s disabled
condition in the actor-enabled test to also require actorTokenType, alongside
subjectToken, subjectTokenType, and actorToken. Keep the existing runTest and
customTokenExchange behavior unchanged.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 4a615615-4f7a-496a-bdba-9e1eae0ec5cb
📒 Files selected for processing (9)
example/src/navigation/ClassDemoNavigator.tsxexample/src/screens/class-based/ClassApiTests.tsxexample/src/screens/class-based/ClassProfile.tsxios/A0Auth0.mmios/NativeBridge.swiftsrc/platforms/native/adapters/__tests__/NativeAuth0Client.spec.tssrc/platforms/native/bridge/__tests__/NativeBridgeManager.spec.tssrc/platforms/web/adapters/WebAuth0Client.tssrc/types/common.ts
🚧 Files skipped from review as they are similar to previous changes (4)
- src/platforms/web/adapters/WebAuth0Client.ts
- src/types/common.ts
- src/platforms/native/adapters/tests/NativeAuth0Client.spec.ts
- src/platforms/native/bridge/tests/NativeBridgeManager.spec.ts
| actorTokenType | ||
| ); | ||
| return new CredentialsModel(credential); | ||
| } catch (e) { |
There was a problem hiding this comment.
The catch here always sets code to custom_token_exchange_failed in the details, even when the error coming out of a0_call is already an AuthError carrying the real Auth0 code (for example invalid_request when the tenant flag is off, or the actor-token JWT errors). The name keeps the original code but code gets flattened to the generic string, so error.name and error.code end up disagreeing, and a developer branching on code loses the actual reason.
We need to surface actor-token failures cleanly, shall we pass the original code through when the error is already an AuthError, and only fall back to the generic one for truly unknown errors?
| actorToken?: string, | ||
| actorTokenType?: string | ||
| ): void { | ||
| const hasToken = actorToken !== undefined && actorToken !== null; |
There was a problem hiding this comment.
The presence check treats an empty string as provided, so actorToken: '' with a real actorTokenType passes the pairing check and gets forwarded, and the empty value only fails later at the server. The web adapter then spreads it through as actor_token: '' too.
Can we treat empty (and maybe whitespace-only) strings as not provided here, so the guard catches this case client-side like it does for the missing one?
| * @param actorTokenType The actor token type URI, if provided. | ||
| * @throws {AuthError} If exactly one of the two parameters is provided. | ||
| */ | ||
| export function validateActorTokenParameters( |
There was a problem hiding this comment.
This validates the pairing but not that actorTokenType is a valid URI. The product spec calls for a client-side URI check that throws before the network call, the same way subjectTokenType is meant to be validated, so a bad type is rejected locally with a clear error rather than bouncing off the server.
Shall we add the URI check here for actorTokenType (and confirm subjectTokenType gets the same treatment, since I couldn't find a client-side check for it either)?
| ); | ||
| }); | ||
|
|
||
| it('should not include actor token keys when not provided', async () => { |
There was a problem hiding this comment.
The refresh-token suppression behavior is documented but nothing pins it in a test. When an actor token is used the server returns no refresh token, and we want to be sure the SDK handles a missing refresh_token without breaking.
Could we add a case that runs the exchange with an actor token, has the mock return no refresh_token, and asserts credentials.refreshToken comes back undefined?
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/core/utils/validation.ts`:
- Around line 82-85: Normalize actor values to undefined when they are empty or
whitespace-only before the exchange boundary, rather than forwarding the
original truthy strings. Update validateActorTokenParameters and the
WebAuth0Client.customTokenExchange/native forwarding paths to reuse the
normalized values, and add an adapter-level regression test covering
whitespace-only inputs.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 5231cf93-a909-486c-8537-51867f1c92d7
📒 Files selected for processing (7)
src/core/utils/__tests__/validation.spec.tssrc/core/utils/validation.tssrc/platforms/native/adapters/NativeAuth0Client.tssrc/platforms/native/bridge/NativeBridgeManager.tssrc/platforms/native/bridge/__tests__/NativeBridgeManager.spec.tssrc/platforms/web/adapters/WebAuth0Client.tssrc/platforms/web/adapters/__tests__/WebAuth0Client.spec.ts
🚧 Files skipped from review as they are similar to previous changes (6)
- src/platforms/native/adapters/NativeAuth0Client.ts
- src/platforms/web/adapters/tests/WebAuth0Client.spec.ts
- src/platforms/web/adapters/WebAuth0Client.ts
- src/platforms/native/bridge/NativeBridgeManager.ts
- src/platforms/native/bridge/tests/NativeBridgeManager.spec.ts
- src/core/utils/tests/validation.spec.ts
This PR adds support for delegation and impersonation in Custom Token Exchange flows, following RFC 8693 OAuth 2.0 Token Exchange.
You can now pass an
actorToken(and itsactorTokenType) tocustomTokenExchangeto indicate the acting party in a delegation or impersonation scenario. When present, the issued tokens carry theactclaim, which is now exposed on the user profile.Supported on web, iOS, and Android.
Summary by CodeRabbit
actorToken/actorTokenTypeacross web, iOS, and Android.actclaim (including nested delegation).actpreservation and actor-token validation/forwarding.