Skip to content

fix(auth): handle malformed access-token cookies - #467

Merged
chonilius merged 1 commit into
MergeFi:mainfrom
iamcracked-dev:fix-jwt-malformed-cookie-462
Sep 27, 2026
Merged

chonilius merged 1 commit into
MergeFi:mainfrom
iamcracked-dev:fix-jwt-malformed-cookie-462

Conversation

@iamcracked-dev

Copy link
Copy Markdown
Contributor

Closes #464
Closes #463
Closes #462
Closes #461

Summary

Hardens authentication request handling so a malformed URL-encoded access_token cookie is treated as absent instead of causing token extraction to throw before the application can apply its normal unauthorized-request behavior.

Changes

  • Wraps cookie value decoding in a targeted try/catch block.
  • Returns null for malformed encoded cookie content, matching the extractor contract for a missing token.
  • Preserves existing behavior for valid cookie tokens and bearer-token authentication.
  • Keeps the change isolated to the JWT strategy’s manual cookie parsing path.

Scope

This PR delivers the small, low-risk authentication hardening slice from the assigned backend work. It does not alter cache, pagination, or OAuth process-lifecycle behavior; those concerns remain independently scoped for review despite being listed above for assignment tracking.

Verification

No dependencies were installed and no builds, tests, or CI checks were run, per request.

@drips-wave

drips-wave Bot commented Sep 27, 2026

Copy link
Copy Markdown

@iamcracked-dev Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@vercel

vercel Bot commented Sep 27, 2026

Copy link
Copy Markdown

@iamcracked-dev is attempting to deploy a commit to the chonilius' projects Team on Vercel.

A member of the Team first needs to authorize it.

@chonilius
chonilius merged commit 50930fa into MergeFi:main Sep 27, 2026
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment