[1966] bypass for json userInfoResponse - #592
Conversation
Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
WalkthroughUpdates ChangesObject Short-Circuit for userinfo Decoding
Estimated code review effort🎯 2 (Simple) | ⏱️ ~8 minutes Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@mock-relying-party-service/utils.js`:
- Around line 98-106: The condition at lines 98-106 in
mock-relying-party-service/utils.js uses
isJson(JSON.stringify(userInfoResponse)) which always evaluates to true since
JSON.stringify() produces valid JSON for any input, preventing the JWE/JWT
decoding logic below from executing. Replace this condition with a direct type
check to detect whether axios has already parsed userInfoResponse into a
JavaScript object (rather than leaving it as a string). After making this
type-check fix, remove the now-unused isJson helper function that appears at
lines 80-89.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI
Review profile: CHILL
Plan: Pro
Run ID: 2cbe9998-4a1d-40bf-a698-17b251137963
⛔ Files ignored due to path filters (1)
mock-relying-party-service/package-lock.jsonis excluded by!**/package-lock.json
📒 Files selected for processing (1)
mock-relying-party-service/utils.js
Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>
* Added PKCE implementation Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com> * fixed coderabbit comment Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com> * Corrected the logic to full dynamic identity schema Signed-off-by: ase-101 <sunkadaeanusha@gmail.com> * Fixed review comments Signed-off-by: ase-101 <sunkadaeanusha@gmail.com> * added proxy pass for par and dpop (#554) Signed-off-by: Harsh Kashiwal <harsh.kashiwal@infosys.com> * resolved comments Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com> * resolved review comment Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com> * resolve review comments Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com> * set active_profile_env to "default" in deployment (#558) (#560) Signed-off-by: Sachin Rana <sacrana324@gmail.com> * docs: fix typos, remove duplicate overview, and improve README formatting (#561) (#563) Signed-off-by: Nandhukumar <nandhukumare@gmail.com> * Added endpoint to fetch identity schema (#564) * Added endpoint to fetch identity schema Signed-off-by: ase-101 <sunkadaeanusha@gmail.com> * Added endpoint to fetch identity schema Signed-off-by: ase-101 <sunkadaeanusha@gmail.com> * Fixed testcase Signed-off-by: ase-101 <sunkadaeanusha@gmail.com> --------- Signed-off-by: ase-101 <sunkadaeanusha@gmail.com> * Fixed the required field validation error (#565) * Added endpoint to fetch identity schema Signed-off-by: ase-101 <sunkadaeanusha@gmail.com> * Added endpoint to fetch identity schema Signed-off-by: ase-101 <sunkadaeanusha@gmail.com> * Fixed required fields validation error Signed-off-by: ase-101 <sunkadaeanusha@gmail.com> --------- Signed-off-by: ase-101 <sunkadaeanusha@gmail.com> * Snapshot updates 0.13.0 -> 0.13.1 Signed-off-by: Harsh Kashiwal <kashiwalharsh1234@gmail.com> * [ES-2962] Added error messages for login_required and request_not_supported error. Signed-off-by: GurukiranP <talk2gurukiran@gmail.com> * [ES-1616] Added new error message. Signed-off-by: GurukiranP <talk2gurukiran@gmail.com> * [MOSIP-37808] Updated DB attributes of MOSIP esignet-mock Signed-off-by: Abhi <abhishek.shankarcs@gmail.com> * [MOSIP-37808] Updated DB attributes of MOSIP esignet-mock (#579) Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com> * Updating sign-in-with-esignet, removing optional parameter from config (#590) * [MODIFIED] used npm library for sign-in-with-esignet Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com> * [MODIFIED] ignore optional parameter in sign-in-with-esignet Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com> * [MODIFIED] readme file Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com> * [MODIFIED] coderabbit comment resolved Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com> * [MODIFIED] review comment addressed Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com> * [MODIFIED] readme updated Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com> --------- Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com> * [1996] added configurable token and userinfo endpoint (#591) * [1996] added configurable token and userinfo endpoint Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com> * [1996] add kid only, if private key has it Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com> * [1996] default value of token & userinfo endpoint Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com> --------- Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com> * [1966] bypass for json userInfoResponse (#592) * [1966] bypass for json userInfoResponse Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com> * [1966] bypass for json userInfoResponse Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com> --------- Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com> * [mosip/mosip-infra#1890] Added domainConfig support in helm charts (#589) * [mosip/mosip-infra#1890] Removed esignet-global, added domainConfig support in helm charts Signed-off-by: bhumi46 <thisisbn46@gmail.com> * [mosip/mosip-infra#1890] Set chart versions to 0.0.1-develop Signed-off-by: bhumi46 <thisisbn46@gmail.com> * migrate to domainConfig helm values #1890 Signed-off-by: bhumi46 <thisisbn46@gmail.com> --------- Signed-off-by: bhumi46 <thisisbn46@gmail.com> Co-authored-by: bhumi46 <bhumi11111a@gmail.com> * Gpg update Test (#596) * ci: point kattu maven workflows at @develop to test kattu#353 Repoints maven-build / maven-publish-to-nexus / maven-sonar-analysis(-new) reusable-workflow references to mosip/kattu@develop so the GPG-key-import migration (mosip/kattu#353) is exercised by this repo's CI once it merges. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Signed-off-by: Mahesh.Binayak <mahesh.binayak@technoforte.co.in> * ci: pass GPG_PRIVATE_KEY secret from caller workflows (kattu#353) kattu#353 imports the signing key from the GPG_PRIVATE_KEY secret (now required: true in maven-build / maven-publish-to-nexus workflow_call), so the caller must forward it. Added GPG_PRIVATE_KEY to the maven-build and maven-publish-to-nexus caller jobs only (sonar workflows don't declare it). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Signed-off-by: Mahesh.Binayak <mahesh.binayak@technoforte.co.in> * ci: point maven workflows at Mahesh-Binayak/kattu@gpgupdate-masterj21 gpgupdate-masterj21 = master-java21 + the GPG-secret-import / key-age / simplify4u-pgpverify changes, keeping master-java21's interface intact. Repoints maven-build / maven-publish-to-nexus / maven-sonar-analysis to it, restores MAVEN_NON_EXEC_ARTIFACTS, and forwards GPG_PRIVATE_KEY to the build/publish jobs. Other workflows (docker-build, npm-*, sonar-new@develop) and commented refs are left unchanged. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Signed-off-by: Mahesh.Binayak <mahesh.binayak@technoforte.co.in> * ci: point maven workflows at mosip/kattu@gpgupdate-masterj21 The gpgupdate-masterj21 branch now lives on mosip/kattu; reference it there instead of the fork. Interface unchanged; GPG_PRIVATE_KEY forwarded. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Signed-off-by: Mahesh.Binayak <mahesh.binayak@technoforte.co.in> --------- Signed-off-by: Mahesh.Binayak <mahesh.binayak@technoforte.co.in> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> * [issue:1963] Updated helm for thunder deployment (#593) Signed-off-by: Prafulrakhade <prafulrakhade02@gmail.com> * [issue:597] Add PKCS12 keystore support to mock-identity-system as an alternative to SoftHSM (#599) install.sh now prompts to opt into a PKCS12 mounted-volume keystore instead of SoftHSM; SoftHSM provisioning only runs when PKCS12 isn't selected. The chart gained a PersistentVolumeClaim template, a fixed volume-permissions init container (was a literal unfilled placeholder), persistence volume wiring in the deployment, and additive extraEnvVarsAdditional support. Signed-off-by: Swapnil <swapnil.mohanty@technoforte.co.in> * Fix default prompt value (#600) Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com> Co-authored-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com> * #10670: Add AGENTS.md tree for AI coding assistant guidance Adds a root AGENTS.md hub covering the repository as a whole, plus per-module AGENTS.md guides for mock-identity-system, mock-relying-party-service, mock-relying-party-ui, mock-relying-party-ui-esim, and partner-onboarder — the independently buildable modules in this repo. Each guide documents purpose, layout, how to run/build/test, configuration, and explicit agent do/do-not rules, verified against the actual READMEs, pom.xml/package.json files, and GitHub Actions workflows in this repo. Addresses mosip/mosip-config#10670 Signed-off-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com> * #10670: Address CodeRabbit review feedback on AGENTS.md - Stop prescribing npm test for every Node/React module; point to each module's own AGENTS.md/README.md since scripts differ (mock-relying-party-service has no test script at all). - Fix docker-compose path in mock-identity-system/AGENTS.md: from the repo root it's docker-compose/, not ../docker-compose/. - Use MOCK_RELYING_PARTY_SERVER_URL in the mock-relying-party-ui-esim Docker example, matching the variable the Dockerfile/UI actually read (MOCK_RELYING_PARTY_BASE_URL has no effect). - Note that partner-onboarder targets a non-production eSignet deployment only, per the root README's repo-wide scope. Addresses review comments on #601 Signed-off-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com> * fix: 602 convert extraEnvVars/extraEnvVarsAdditional to maps (#603) * fix: 602 convert extraEnvVars/extraEnvVarsAdditional to maps Helm merges map keys across values layers but replaces lists wholesale, so any downstream override of extraEnvVars/extraEnvVarsAdditional had to re-declare the whole list just to change one entry. Convert both to maps keyed by env var name in mock-identity-system, mock-relying-party-service, and mock-relying-party-ui, and render them with a range loop that auto-detects plain scalars vs. valueFrom, matching the existing domainConfig pattern already used in these charts. Same fix already applied to mosip/esignet (issue #2380). Signed-off-by: bhumi46 <thisisbn46@gmail.com> * fix: 602 update mock-identity-system installer for extraEnvVarsAdditional map contract deploy/mock-identity-system/install.sh generated extraEnvVarsAdditional as a list in two places (PKCS12 and softhsm branches), which produced broken index-keyed env entries against the chart's map-shaped default introduced in this PR. Convert both to the map contract (KEY: value / KEY: {valueFrom: ...}), matching the fix already applied to esignet's legacy installer scripts. Signed-off-by: bhumi46 <thisisbn46@gmail.com> --------- Signed-off-by: bhumi46 <thisisbn46@gmail.com> * Change image tag from release-0.10.x to develop Signed-off-by: Praful Rakhade <prafulrakhade02@gmail.com> * Change image tag from release-0.10.x to develop Signed-off-by: Praful Rakhade <prafulrakhade02@gmail.com> * Change image tag from release-0.10.x to develop Signed-off-by: Praful Rakhade <prafulrakhade02@gmail.com> * #2347 Update database host and clean up configuration (#610) Updated the host to include the namespace and removed unused service configurations. Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com> * #2347 Update database username in postgres config (#611) * #2347 Update database username in postgres config Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com> * #2347 Update database username in deploy.properties Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com> --------- Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com> * updated version 0.13.0 to 0.14.0 Signed-off-by: Sachin Rana <sacrana324@gmail.com> * updated helm chart version Signed-off-by: Sachin Rana <sacrana324@gmail.com> --------- Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com> Signed-off-by: ase-101 <sunkadaeanusha@gmail.com> Signed-off-by: Harsh Kashiwal <harsh.kashiwal@infosys.com> Signed-off-by: Sachin Rana <sacrana324@gmail.com> Signed-off-by: Nandhukumar <nandhukumare@gmail.com> Signed-off-by: Harsh Kashiwal <kashiwalharsh1234@gmail.com> Signed-off-by: GurukiranP <talk2gurukiran@gmail.com> Signed-off-by: Abhi <abhishek.shankarcs@gmail.com> Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com> Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com> Signed-off-by: bhumi46 <thisisbn46@gmail.com> Signed-off-by: Mahesh.Binayak <mahesh.binayak@technoforte.co.in> Signed-off-by: Prafulrakhade <prafulrakhade02@gmail.com> Signed-off-by: Swapnil <swapnil.mohanty@technoforte.co.in> Signed-off-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com> Signed-off-by: Praful Rakhade <prafulrakhade02@gmail.com> Co-authored-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com> Co-authored-by: ase-101 <sunkadaeanusha@gmail.com> Co-authored-by: Zeeshan Mehboob <82993262+zesu22@users.noreply.github.com> Co-authored-by: Harsh Kashiwal <77677724+KashiwalHarsh@users.noreply.github.com> Co-authored-by: Nandhukumar <nandhukumare@gmail.com> Co-authored-by: Harsh Kashiwal <kashiwalharsh1234@gmail.com> Co-authored-by: GurukiranP <talk2gurukiran@gmail.com> Co-authored-by: Abhi <abhishek.shankarcs@gmail.com> Co-authored-by: Chandra Keshav Mishra <chandrakeshavmishra@gmail.com> Co-authored-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com> Co-authored-by: bhumi46 <111699703+bhumi46@users.noreply.github.com> Co-authored-by: bhumi46 <bhumi11111a@gmail.com> Co-authored-by: Mahesh-Binayak <76687012+Mahesh-Binayak@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: Praful Rakhade <prafulrakhade02@gmail.com> Co-authored-by: Swapnil <swapnil.mohanty@technoforte.co.in> Co-authored-by: Sajid Mannikeri <sajid.mannikeri@infosys.com> Co-authored-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com>
Summary by CodeRabbit