Repository navigation
Don't default NPM_AUTH_TOKEN to support NPM OIDC #1440
Copy link
Copy link
Closed
Labels
feature requestNew feature or request to improve the current logicNew feature or request to improve the current logic
Description
Activity
- addedfeature requestNew feature or request to improve the current logicNew feature or request to improve the current logic
on Nov 24, 2025 As a workaround, we can do this for now...
- uses: actions/setup-node@v5 with: node-version: 24 registry-url: "https://registry.npmjs.org" - run: | NODE_AUTH_TOKEN="" npm publish
Overwriting the
NODE_AUTH_TOKENenv when running the command works like a charm.Reacted by 小弟调调, Mohd Hamza Shaikh and zhzhangReacted by Mohd Hamza Shaikh and Johannes LindgrenFYI for those following along, specifically this part of the code:
Lines 54 to 58 in 633bb92
// Export empty node_auth_token if didn't exist so npm doesn't complain about not being able to find it core.exportVariable( 'NODE_AUTH_TOKEN', process.env.NODE_AUTH_TOKEN || 'XXXXX-XXXXX-XXXXX-XXXXX' ); ^ Although do note, that there is a comment about it prior to the line around issues of the variable not being set. Maybe worth evaulating whether if that is still indeed the case?
Hello @mannycarrera4,
Thank you for this feature request. We will investigate it and get back to you as soon as we have some feedback.Reacted by Mikkel ALMONTE--RINGAUD感謝建議 — 我已整理並補強成具體的變更提案,包含相容性與測試安排,供大家討論與實作參考:
建議變更總覽
- 預設行為:移除自動將 NODE_AUTH_TOKEN 設為預設假值的做法。只有在使用者明確提供 NODE_AUTH_TOKEN 時才會匯出該環境變數。
- 測試:新增單元測試與 CI 測試場景,覆蓋「未設定 NODE_AUTH_TOKEN」以及 NPM OIDC 發佈的情境。
- 備援說明:在 README / CHANGELOG 中新增升級指南,說明使用者若仍需舊流程,應如何在工作流程中顯式清空或提供 NODE_AUTH_TOKEN。
- 可選開關:提供向後相容選項,如 with: respect-node-auth-token: true/false,或在程式中特別檢測 NODE_AUTH_TOKEN === '',讓使用者能明確控制行為。
實作細節建議
- 核心行為變更
- 將目前在 export NODE_AUTH_TOKEN 時的預設假值移除,改為:
- 若 process.env.NODE_AUTH_TOKEN 存在(非 undefined),則匯出該值(包含空字串 '',以便使用者刻意清空)。
- 若不存在,則不匯出該環境變數,避免向註冊表傳遞假 token。
- 範例程式邏輯:
- if (Object.prototype.hasOwnProperty.call(process.env, 'NODE_AUTH_TOKEN')) { export NODE_AUTH_TOKEN = process.env.NODE_AUTH_TOKEN } else { 不匯出 }
- 向後相容與開關
- 新增輸入參數,例如 with: respect-node-auth-token: true/false(預設 false 表示採用新安全行為),或相反視專案偏好。
- 另外支援透過明確空字串來表達「刻意清空」的情境(NODE_AUTH_TOKEN === ''),此情況應被視為有效輸入而導出空字串,以符合現有 CI workaround(如 NODE_AUTH_TOKEN="" npm publish)。
- 測試計畫
- 單元測試:覆蓋以下情況
- process.env.NODE_AUTH_TOKEN 未定義 → 不匯出變數
- process.env.NODE_AUTH_TOKEN === '' → 匯出空字串
- process.env.NODE_AUTH_TOKEN 有值 → 匯出該值
- respect-node-auth-token 選項在 true/false 時的行為
- 整合/CI 測試:建立模擬 NPM OIDC 發佈流程的 CI scenario(可在專門的 CI matrix 或模擬測試中執行),確保在不匯出預設 token 的情況下,OIDC 發佈可正常運作,且舊流程仍可透過選項或顯式環境變數達成。
- 文件與升級指南
- README / CHANGELOG 更新要點:
- 說明此行為變更的原因(支援 NPM OIDC,避免假 token 干擾)。
- 提供範例轉換說明:
- 若依賴舊行為,請在 workflow 中明確設定 NODE_AUTH_TOKEN(或透過 with 選項開啟相容模式)。
- 若要刻意清空 token(workaround),請在 publish 步驟前設定 NODE_AUTH_TOKEN=""。
- 範例片段與常見 FAQ(例如:「為什麼需要清空?」、「如何在 OIDC 環境下發佈?」)。
需求與注意事項
- 變更需小心以免破壞現有使用者的 pipeline,因此建議先以選項方式提供,並在下一個 major/minor 版本再改預設(視 repo 發行政策)。
- 請保留原始註解與 commit 跟蹤(例如你引用的那段 authutil.ts 註解),並在 commit message 中說明原因與風險評估。
如果你同意這個方向,我可以:
- 開一個 PR 草案,包含程式碼變更、單元測試、README/CHANGELOG 更新範本與 CI 測試範例。
- 或先提交一個較小的 PR 只做行為改動與單元測試,再用後續 PR 加上選項與文件說明。
請告訴你偏好的步驟(直接 PR 草案或分階段提交),我就開始準備。
Reacted by Mikkel ALMONTE--RINGAUD, Sukka, bezze, Kyle Shores and Chad Wilson- added 2 commits that reference this issue
on Nov 27, 2025 - added 2 commits that reference this issue
on Dec 5, 2025 - added a commit that references this issue
on Dec 6, 2025 114 remaining items
- added a commit that references this issue
on Aug 21, 2026 - added a commit that references this issue
on Aug 23, 2026 - added a commit that references this issue
on Aug 26, 2026 - added a commit that references this issue
on Aug 27, 2026 - added a commit that references this issue
on Sep 2, 2026 - added a commit that references this issue
on Sep 13, 2026 - added a commit that references this issue
on Sep 17, 2026 - added a commit that references this issue
on Sep 28, 2026 - added a commit that references this issue
on Sep 28, 2026 - added a commit that references this issue
on Oct 2, 2026 - added a commit that references this issue
on Oct 8, 2026
Metadata
Metadata
Assignees
Labels
feature requestNew feature or request to improve the current logicNew feature or request to improve the current logic
Description:
A lot of packages are switching to OIDC to validate packages when publishing. It took a lot of debugging, but we had to reset the auth token to empty string intentionally in our CI, but it wasn't clear what was setting it.
Any chance we can the default setting to support NPM OIDC?