Skip to content

fix(publish) Support split npmrc auth for publish - #26178

Closed
gavinhailey wants to merge 3 commits into
oven-sh:mainfrom
gavinhailey:fix-publish-npmrc-split-auth
Closed

gavinhailey wants to merge 3 commits into
oven-sh:mainfrom
gavinhailey:fix-publish-npmrc-split-auth

Conversation

@gavinhailey

@gavinhailey gavinhailey commented Jan 17, 2026 •

Copy link
Copy Markdown

What does this PR do?

Fixes bun publish failing with "error: missing authentication" despite valid .npmrc credentials, while bun install and npm publish both work fine with the same configuration. Updates the auth check to accept the registry.auth and registry.user combination that gets set.

This specifically affects split username/password authentication like:

//registry.example.com/:username=myuser
//registry.example.com/:_password=base64encodedpass

Related Issues

How did you verify your code works?

New auth tests in test/cli/install/bun-publish.test.ts, four new tests verify different .npmrc authentication formats:

  • Split username/password with default registry (fails on current release)
  • Split username/password with scoped registry (fails on current release)
  • Split _authToken with default registry (already worked, but expanded coverage)
  • Split _authToken with scoped registry (already worked, but expanded coverage)

Manual testing with debug release:

Tested publishing to a private JFrog Artifactory registry using split username/password in .npmrc:

@scope:registry=https://registry.example.com/npm/
//registry.example.com/npm/:username=myuser
//registry.example.com/npm/:_password=mysecurebase64encodedpass

Before fix: ❌ error: missing authentication
After fix: ✅ + @scope/abcefg@0.1.0-rc.0

@gavinhailey gavinhailey changed the title fix split auth for publish fix(publish) Support split npmrc auth for publish Jan 17, 2026
@coderabbitai

coderabbitai Bot commented Jan 17, 2026 •

Copy link
Copy Markdown
Contributor

Walkthrough

Broadened the authentication condition in PublishCommand.publish to require missing token, auth, and user (plus incomplete URL-embedded credentials). Added tests covering split npmrc authentication formats (username/password and _authToken) for scoped and unscoped registries against Verdaccio.

Changes

Cohort / File(s) Summary
Publish command logic
src/cli/publish_command.zig
Adjusted authentication-check logic: NeedAuth now triggers only when token, auth, and user are all absent and URL-embedded credentials are incomplete (+2/-1).
Publish tests (split npmrc auth)
test/cli/install/bun-publish.test.ts
Added test suite validating four split npmrc authentication formats (username/password and _authToken, each with scoped and unscoped registry cases) against a Verdaccio registry (+89/-0).

Possibly related PRs

Suggested reviewers

  • dylan-conway
🚥 Pre-merge checks | ✅ 2
✅ Passed checks (2 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: fixing bun publish to support split npmrc authentication, which directly matches the core objective of the PR.
Description check ✅ Passed The pull request description follows the required template with both sections completed: 'What does this PR do?' and 'How did you verify your code works?' are present with detailed, substantive information.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Tip

Try Coding Plans. Let us write the prompt for your AI agent so you can ship faster (with fewer bugs).
Share your feedback on Discord.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Fix all issues with AI agents
In `@src/cli/publish_command.zig`:
- Around line 537-539: The auth gate in publish_command.zig incorrectly requires
both registry.auth and registry.user to be set, causing false NeedAuth errors
when legacy _auth populates only registry.auth; update the condition so it
accepts any of: registry.token non-empty, registry.auth non-empty OR
registry.user non-empty, or URL-embedded credentials
(registry.url.username/registry.url.password), i.e., check registry.auth.len > 0
|| registry.user.len > 0 rather than requiring both; ensure this logic aligns
with constructPublishHeaders which already uses registry.auth.

In `@test/cli/install/bun-publish.test.ts`:
- Around line 1014-1018: Reorder the assertions in the test so stdout/stderr
expectations run before checking the process exit code: move the
expect(out).toContain(`+ ${format.packageName}@1.0.0`) and
expect(err).not.toContain("missing authentication") to precede
expect(exitCode).toBe(0) in the test that calls publish(env, packageDir)
(variables: out, err, exitCode, and helper publish).

Comment thread src/cli/publish_command.zig
Comment thread test/cli/install/bun-publish.test.ts
@Ristovski

Copy link
Copy Markdown

Are there any other blockers preventing this from being merged? This has been a very annoying issue for a very long time...

@gavinhailey
gavinhailey force-pushed the fix-publish-npmrc-split-auth branch from 8c95bf0 to 2f8f31a Compare March 30, 2026 20:12
@gavinhailey
gavinhailey force-pushed the fix-publish-npmrc-split-auth branch from 2f8f31a to a2aba29 Compare March 30, 2026 20:13
@robobun

robobun commented Jun 26, 2026

Copy link
Copy Markdown
Collaborator

Closing as stale: this PR predates the Rust rewrite. Every src/ file it modifies has since been removed or relocated on main (Zig sources deleted; src/bun.js/ reorganized into src/jsc/), so it can no longer merge.

If the underlying change is still wanted, it will need to be redone against the current Rust/C++ tree. Apologies for the churn, and thank you for the contribution.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants