Skip to content

[1966] bypass for json userInfoResponse - #592

Merged
anushasunkada merged 2 commits into
mosip:developfrom
Infosys:task/1996_1
Jun 16, 2026
Merged

[1966] bypass for json userInfoResponse#592
anushasunkada merged 2 commits into
mosip:developfrom
Infosys:task/1996_1

Conversation

@zesu22

@zesu22 zesu22 commented Jun 16, 2026

Copy link
Copy Markdown
Contributor
  • handle userinfo response flow when JSON response comes up instead of JWS or JWE

Summary by CodeRabbit

  • Bug Fixes
    • Improved user info response handling by detecting when the payload is already in JSON/object form and using it directly.
    • This prevents unnecessary decoding attempts and ensures the application correctly parses and consumes user data regardless of whether it arrives as an already-decoded object or an encoded token.

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>
@coderabbitai

coderabbitai Bot commented Jun 16, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 6b2b302a-367c-4e66-8638-be3f534956a6

📥 Commits

Reviewing files that changed from the base of the PR and between 3da6709 and c8e470d.

📒 Files selected for processing (1)
  • mock-relying-party-service/utils.js

Walkthrough

Updates decodeUserInfoResponse in mock-relying-party-service/utils.js to short-circuit when the input is already a non-null object: it logs that the payload is already an object and returns it directly, bypassing the existing JWE/JWT decoding logic.

Changes

Object Short-Circuit for userinfo Decoding

Layer / File(s) Summary
decodeUserInfoResponse object early-return
mock-relying-party-service/utils.js
Inserts a guard at the start of decodeUserInfoResponse that detects non-null object inputs, logs the condition, and returns the payload directly instead of proceeding to JWE/JWT decoding.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Poem

A bunny found the payload so neat,
Already an object, what a treat!
"No decode needed," the function cried,
Returns it straight, with rabbity pride,
🐇 Fast and simple, nothing to hide!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly references the main change: a bypass mechanism for handling JSON userInfoResponse instead of JWE/JWT tokens in the mock-relying-party-service.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@mock-relying-party-service/utils.js`:
- Around line 98-106: The condition at lines 98-106 in
mock-relying-party-service/utils.js uses
isJson(JSON.stringify(userInfoResponse)) which always evaluates to true since
JSON.stringify() produces valid JSON for any input, preventing the JWE/JWT
decoding logic below from executing. Replace this condition with a direct type
check to detect whether axios has already parsed userInfoResponse into a
JavaScript object (rather than leaving it as a string). After making this
type-check fix, remove the now-unused isJson helper function that appears at
lines 80-89.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 2cbe9998-4a1d-40bf-a698-17b251137963

📥 Commits

Reviewing files that changed from the base of the PR and between 3fc8da6 and 3da6709.

⛔ Files ignored due to path filters (1)
  • mock-relying-party-service/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • mock-relying-party-service/utils.js

Comment thread mock-relying-party-service/utils.js Outdated
Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>
@anushasunkada
anushasunkada merged commit e8fc0f1 into mosip:develop Jun 16, 2026
18 checks passed
sacrana0 added a commit that referenced this pull request Aug 27, 2026
* Added PKCE implementation

Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com>

* fixed coderabbit comment

Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com>

* Corrected the logic to full dynamic identity schema

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

* Fixed review comments

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

* added proxy pass for par and dpop (#554)

Signed-off-by: Harsh Kashiwal <harsh.kashiwal@infosys.com>

* resolved comments

Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com>

* resolved review comment

Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com>

* resolve review comments

Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com>

* set active_profile_env to "default" in deployment (#558) (#560)

Signed-off-by: Sachin Rana <sacrana324@gmail.com>

* docs: fix typos, remove duplicate overview, and improve README formatting (#561) (#563)

Signed-off-by: Nandhukumar <nandhukumare@gmail.com>

* Added endpoint to fetch identity schema (#564)

* Added endpoint to fetch identity schema

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

* Added endpoint to fetch identity schema

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

* Fixed testcase

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

---------

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

* Fixed the required field validation error (#565)

* Added endpoint to fetch identity schema

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

* Added endpoint to fetch identity schema

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

* Fixed required fields validation error

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

---------

Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>

* Snapshot updates 0.13.0 -> 0.13.1

Signed-off-by: Harsh Kashiwal <kashiwalharsh1234@gmail.com>

* [ES-2962] Added error messages for login_required and request_not_supported error.

Signed-off-by: GurukiranP <talk2gurukiran@gmail.com>

* [ES-1616] Added new error message.

Signed-off-by: GurukiranP <talk2gurukiran@gmail.com>

* [MOSIP-37808] Updated DB attributes of MOSIP esignet-mock

Signed-off-by: Abhi <abhishek.shankarcs@gmail.com>

* [MOSIP-37808] Updated DB attributes of MOSIP esignet-mock (#579)

Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com>

* Updating sign-in-with-esignet, removing optional parameter from config (#590)

* [MODIFIED] used npm library for sign-in-with-esignet

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [MODIFIED] ignore optional parameter in sign-in-with-esignet

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [MODIFIED] readme file

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [MODIFIED] coderabbit comment resolved

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [MODIFIED] review comment addressed

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [MODIFIED] readme updated

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

---------

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [1996] added configurable token and userinfo endpoint (#591)

* [1996] added configurable token and userinfo endpoint

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [1996] add kid only, if private key has it

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [1996] default value of token & userinfo endpoint

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

---------

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [1966] bypass for json userInfoResponse (#592)

* [1966] bypass for json userInfoResponse

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [1966] bypass for json userInfoResponse

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

---------

Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>

* [mosip/mosip-infra#1890] Added domainConfig support in helm charts (#589)

* [mosip/mosip-infra#1890] Removed esignet-global, added domainConfig support in helm charts

Signed-off-by: bhumi46 <thisisbn46@gmail.com>

* [mosip/mosip-infra#1890] Set chart versions to 0.0.1-develop

Signed-off-by: bhumi46 <thisisbn46@gmail.com>

* migrate to domainConfig helm values
 #1890

Signed-off-by: bhumi46 <thisisbn46@gmail.com>

---------

Signed-off-by: bhumi46 <thisisbn46@gmail.com>
Co-authored-by: bhumi46 <bhumi11111a@gmail.com>

* Gpg update Test  (#596)

* ci: point kattu maven workflows at @develop to test kattu#353

Repoints maven-build / maven-publish-to-nexus / maven-sonar-analysis(-new)
reusable-workflow references to mosip/kattu@develop so the GPG-key-import
migration (mosip/kattu#353) is exercised by this repo's CI once it merges.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Mahesh.Binayak <mahesh.binayak@technoforte.co.in>

* ci: pass GPG_PRIVATE_KEY secret from caller workflows (kattu#353)

kattu#353 imports the signing key from the GPG_PRIVATE_KEY secret (now
required: true in maven-build / maven-publish-to-nexus workflow_call), so
the caller must forward it. Added GPG_PRIVATE_KEY to the maven-build and
maven-publish-to-nexus caller jobs only (sonar workflows don't declare it).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Mahesh.Binayak <mahesh.binayak@technoforte.co.in>

* ci: point maven workflows at Mahesh-Binayak/kattu@gpgupdate-masterj21

gpgupdate-masterj21 = master-java21 + the GPG-secret-import / key-age /
simplify4u-pgpverify changes, keeping master-java21's interface intact.
Repoints maven-build / maven-publish-to-nexus / maven-sonar-analysis to it,
restores MAVEN_NON_EXEC_ARTIFACTS, and forwards GPG_PRIVATE_KEY to the
build/publish jobs. Other workflows (docker-build, npm-*, sonar-new@develop)
and commented refs are left unchanged.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Mahesh.Binayak <mahesh.binayak@technoforte.co.in>

* ci: point maven workflows at mosip/kattu@gpgupdate-masterj21

The gpgupdate-masterj21 branch now lives on mosip/kattu; reference it
there instead of the fork. Interface unchanged; GPG_PRIVATE_KEY forwarded.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Mahesh.Binayak <mahesh.binayak@technoforte.co.in>

---------

Signed-off-by: Mahesh.Binayak <mahesh.binayak@technoforte.co.in>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* [issue:1963] Updated helm for thunder deployment (#593)

Signed-off-by: Prafulrakhade <prafulrakhade02@gmail.com>

* [issue:597] Add PKCS12 keystore support to mock-identity-system as an alternative to SoftHSM (#599)

install.sh now prompts to opt into a PKCS12 mounted-volume keystore instead
of SoftHSM; SoftHSM provisioning only runs when PKCS12 isn't selected. The
chart gained a PersistentVolumeClaim template, a fixed volume-permissions
init container (was a literal unfilled placeholder), persistence volume
wiring in the deployment, and additive extraEnvVarsAdditional support.

Signed-off-by: Swapnil <swapnil.mohanty@technoforte.co.in>

* Fix default prompt value (#600)

Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com>
Co-authored-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com>

* #10670: Add AGENTS.md tree for AI coding assistant guidance

Adds a root AGENTS.md hub covering the repository as a whole, plus
per-module AGENTS.md guides for mock-identity-system,
mock-relying-party-service, mock-relying-party-ui,
mock-relying-party-ui-esim, and partner-onboarder — the independently
buildable modules in this repo. Each guide documents purpose, layout,
how to run/build/test, configuration, and explicit agent do/do-not
rules, verified against the actual READMEs, pom.xml/package.json
files, and GitHub Actions workflows in this repo.

Addresses mosip/mosip-config#10670

Signed-off-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com>

* #10670: Address CodeRabbit review feedback on AGENTS.md

- Stop prescribing npm test for every Node/React module; point to
  each module's own AGENTS.md/README.md since scripts differ
  (mock-relying-party-service has no test script at all).
- Fix docker-compose path in mock-identity-system/AGENTS.md: from the
  repo root it's docker-compose/, not ../docker-compose/.
- Use MOCK_RELYING_PARTY_SERVER_URL in the mock-relying-party-ui-esim
  Docker example, matching the variable the Dockerfile/UI actually
  read (MOCK_RELYING_PARTY_BASE_URL has no effect).
- Note that partner-onboarder targets a non-production eSignet
  deployment only, per the root README's repo-wide scope.

Addresses review comments on #601

Signed-off-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com>

* fix: 602 convert extraEnvVars/extraEnvVarsAdditional to maps (#603)

* fix: 602 convert extraEnvVars/extraEnvVarsAdditional to maps

Helm merges map keys across values layers but replaces lists wholesale,
so any downstream override of extraEnvVars/extraEnvVarsAdditional had
to re-declare the whole list just to change one entry. Convert both to
maps keyed by env var name in mock-identity-system,
mock-relying-party-service, and mock-relying-party-ui, and render them
with a range loop that auto-detects plain scalars vs. valueFrom,
matching the existing domainConfig pattern already used in these
charts. Same fix already applied to mosip/esignet (issue #2380).

Signed-off-by: bhumi46 <thisisbn46@gmail.com>

* fix: 602 update mock-identity-system installer for extraEnvVarsAdditional map contract

deploy/mock-identity-system/install.sh generated extraEnvVarsAdditional
as a list in two places (PKCS12 and softhsm branches), which produced
broken index-keyed env entries against the chart's map-shaped default
introduced in this PR. Convert both to the map contract (KEY: value /
KEY: {valueFrom: ...}), matching the fix already applied to esignet's
legacy installer scripts.

Signed-off-by: bhumi46 <thisisbn46@gmail.com>

---------

Signed-off-by: bhumi46 <thisisbn46@gmail.com>

* Change image tag from release-0.10.x to develop

Signed-off-by: Praful Rakhade <prafulrakhade02@gmail.com>

* Change image tag from release-0.10.x to develop

Signed-off-by: Praful Rakhade <prafulrakhade02@gmail.com>

* Change image tag from release-0.10.x to develop

Signed-off-by: Praful Rakhade <prafulrakhade02@gmail.com>

* #2347 Update database host and clean up configuration (#610)

Updated the host to include the namespace and removed unused service configurations.

Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com>

* #2347 Update database username in postgres config (#611)

* #2347 Update database username in postgres config

Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com>

* #2347 Update database username in deploy.properties

Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com>

---------

Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com>

* updated version 0.13.0 to 0.14.0

Signed-off-by: Sachin Rana <sacrana324@gmail.com>

* updated helm chart version

Signed-off-by: Sachin Rana <sacrana324@gmail.com>

---------

Signed-off-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com>
Signed-off-by: ase-101 <sunkadaeanusha@gmail.com>
Signed-off-by: Harsh Kashiwal <harsh.kashiwal@infosys.com>
Signed-off-by: Sachin Rana <sacrana324@gmail.com>
Signed-off-by: Nandhukumar <nandhukumare@gmail.com>
Signed-off-by: Harsh Kashiwal <kashiwalharsh1234@gmail.com>
Signed-off-by: GurukiranP <talk2gurukiran@gmail.com>
Signed-off-by: Abhi <abhishek.shankarcs@gmail.com>
Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com>
Signed-off-by: Zeeshan Mehboob <zeeshan.mehboob@infosys.com>
Signed-off-by: bhumi46 <thisisbn46@gmail.com>
Signed-off-by: Mahesh.Binayak <mahesh.binayak@technoforte.co.in>
Signed-off-by: Prafulrakhade <prafulrakhade02@gmail.com>
Signed-off-by: Swapnil <swapnil.mohanty@technoforte.co.in>
Signed-off-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com>
Signed-off-by: Praful Rakhade <prafulrakhade02@gmail.com>
Co-authored-by: Sajid Mannikeri <sajid.mannikeri@ad.infosys.com>
Co-authored-by: ase-101 <sunkadaeanusha@gmail.com>
Co-authored-by: Zeeshan Mehboob <82993262+zesu22@users.noreply.github.com>
Co-authored-by: Harsh Kashiwal <77677724+KashiwalHarsh@users.noreply.github.com>
Co-authored-by: Nandhukumar <nandhukumare@gmail.com>
Co-authored-by: Harsh Kashiwal <kashiwalharsh1234@gmail.com>
Co-authored-by: GurukiranP <talk2gurukiran@gmail.com>
Co-authored-by: Abhi <abhishek.shankarcs@gmail.com>
Co-authored-by: Chandra Keshav Mishra <chandrakeshavmishra@gmail.com>
Co-authored-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com>
Co-authored-by: bhumi46 <111699703+bhumi46@users.noreply.github.com>
Co-authored-by: bhumi46 <bhumi11111a@gmail.com>
Co-authored-by: Mahesh-Binayak <76687012+Mahesh-Binayak@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Praful Rakhade <prafulrakhade02@gmail.com>
Co-authored-by: Swapnil <swapnil.mohanty@technoforte.co.in>
Co-authored-by: Sajid Mannikeri <sajid.mannikeri@infosys.com>
Co-authored-by: Chetan Kumar Hirematha <chetankumar.h.239@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Integrating thunder token exchange and user info endpoint with Mock relying party service

2 participants