Skip to content

fix: load jose lazily from commonjs entrypoints - #508

Open
nkgotcode wants to merge 1 commit into
auth0:masterfrom
nkgotcode:fix/jose-v6-commonjs-load-crash
Open

nkgotcode wants to merge 1 commit into
auth0:masterfrom
nkgotcode:fix/jose-v6-commonjs-load-crash

Conversation

@nkgotcode

Copy link
Copy Markdown

Fixes #507.

Summary:

  • Load jose lazily so CommonJS entrypoints can be required without synchronously loading an ES module.
  • Share the lazy loader from the utility and passport integration paths.
  • Add regression coverage for requiring the public CommonJS entrypoints with synchronous ESM loading disabled.

Testing:

  • node --no-experimental-require-module -e "require('./src'); console.log('loaded top-level')"
  • node --no-experimental-require-module -e "require('./src/utils'); console.log('loaded utils')"
  • npm run test:js -- --grep "CommonJS module loading|utils - retrieveSigningKeys|passportJwtSecret"
  • npm run lint
  • npm run test:js
  • npm test

@nkgotcode
nkgotcode requested a review from a team as a code owner June 17, 2026 20:24
amitsingh-007 added a commit to amitsingh-007/bypass-links that referenced this pull request Jul 11, 2026
firebase-admin 14 -> jwks-rsa@4 require()s ESM-only jose@6, which crashes
with ERR_REQUIRE_ESM in the Next/Turbopack serverless runtime on Vercel.
Pin jose under jwks-rsa to the dual CJS/ESM 4.15.9 (jwks-rsa only uses
importJWK/exportSPKI, API-identical across jose 4/5/6) — the workaround
endorsed in firebase/firebase-admin-node#3181.

The override is declared in BOTH pnpm-workspace.yaml (read by local pnpm 11,
which bakes it into the lockfile) and package.json#pnpm.overrides (read by
Vercel's pnpm 9); both must match or the frozen install fails with
ERR_PNPM_LOCKFILE_CONFIG_MISMATCH. Remove both once auth0/node-jwks-rsa#508
ships.

Verified on a Vercel preview: bookmarksGet/personsGet/getDownloadUrl return
200 and bookmarks are cached.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CommonJS require() fails with jose v6 (ESM-only) in jwks-rsa

1 participant