Skip to content

fix(jwt): include curve name in unsupported algorithm error message - #250

Open
forumevi wants to merge 1 commit into
agentcommercekit:mainfrom
forumevi:fix/signer-unsupported-algorithm-message
Open

forumevi wants to merge 1 commit into
agentcommercekit:mainfrom
forumevi:fix/signer-unsupported-algorithm-message

Conversation

@forumevi

@forumevi forumevi commented Oct 7, 2026

Copy link
Copy Markdown

Problem

In createJwtSigner(), the default branch throws:

throw new Error("Unsupported algorithm", keypair.curve)

Error's second parameter is ErrorOptions ({ cause?: unknown }), not a string. Passing keypair.curve (a plain string like "secp384r1") as the second argument is silently discarded by the runtime — TypeScript accepts it because string is assignable to ErrorOptions via structural typing, but the value is never used. The thrown error therefore only says "Unsupported algorithm", with no indication of which curve is unsupported.

Fix

Replace with a template literal:

throw new Error(`Unsupported algorithm: ${keypair.curve}`)

This makes the error self-describing (e.g. "Unsupported algorithm: secp384r1") and is consistent with the existing pattern in curveToJwtAlgorithm(), which already uses 'Unsupported curve: ${String(curve)}'.

Impact

  • One-line change, no behaviour change for supported curves.
  • No new dependencies.
  • The default branch has no test coverage today; this fix makes any future test trivially assertable against the message.

Error constructor's second parameter expects ErrorOptions ({ cause }),
not a plain string. Passing keypair.curve as a string was silently
ignored, making the thrown error only say "Unsupported algorithm"
with no indication of which curve triggered it.

Replace with a template literal so the message is self-describing:
  "Unsupported algorithm: secp384r1"

Consistent with the existing pattern in curveToJwtAlgorithm(), which
already uses this form.
@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 25 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 2 included reviews currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: c5e42941-c8b7-420b-b74a-00011af91f6f
📥 Commits

Reviewing files that changed from the base of the PR and between 3db94d6 and d579702.

📒 Files selected for processing (1)
  • packages/jwt/src/signer.ts
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant