Skip to content

Empty AuthToken Causes Cryptic JWT Parse Error - #552

Open
aniket866 wants to merge 1 commit into
microcks:masterfrom
aniket866:fix/check-empty-token
Open

aniket866 wants to merge 1 commit into
microcks:masterfrom
aniket866:fix/check-empty-token

Conversation

@aniket866

@aniket866 aniket866 commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Describe the bug

Description

refreshAuthToken in pkg/connectors/microcks_client.go calls
jwt.ParseUnverified(configCtx.User.AuthToken, &claims) without first checking
whether AuthToken is empty. After a fresh install, after logout --token-only,
or whenever the config exists but contains no token, AuthToken is "". The JWT
parser returns an error for the empty string, which propagates all the way up to
NewClient and then to the user as a low-level JWT error rather than a
human-readable "please run microcks login" message.

// microcks_client.go (refreshAuthToken)
if c.RefreshToken == "" {
    return nil  // ← correctly handles empty refresh token
}
// ... but AuthToken="" is never guarded:
_, _, err = parser.ParseUnverified(configCtx.User.AuthToken, &claims)
if err != nil {
    return err  // ← surfaces as "token is malformed: ..." to the user
}

Ai Disclosure: No ai is used to code these lines,

Closes #551

Signed-off-by: aniket866 <iamaniketkumarmaner@gmail.com>
@naitk2

naitk2 commented Sep 28, 2026

Copy link
Copy Markdown

check code if err != nil {
return err // ← surfaces as "token is malformed: ..." to the user

This branch was successfully deployed

1 active deployment
Build — 7f42f603 Deployed Sep 28, 2026 by aniket866 via build-verify-package #743
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Empty AuthToken Causes Cryptic JWT Parse Error

2 participants