Skip to content

feat!: run on Node 22 and stop logging tokens - #6

Merged
howardfuntek merged 1 commit into
masterfrom
feat/modernize-node22
Sep 25, 2026
Merged

howardfuntek merged 1 commit into
masterfrom
feat/modernize-node22

Conversation

@howardfuntek

Copy link
Copy Markdown
Contributor

Summary

  • Upgrade to Node 22, express 5.2.1, jsonwebtoken 9.0.3; remove unused dependencies (jade, serve-favicon, cookie-parser, body-parser, debug).
  • Stop logging credentials: /sign no longer prints each issued token and /verify no longer prints decoded claims. The request log keeps method, path, status and timing.
  • No built-in default secret: the service exits at startup when JWT_SECRET is not set. Previously it fell back to the value in package.json, which is public in this repository.
  • /verify accepts only HS256 (the algorithm /sign has always used).
  • Container runs as the non-root node user; .dockerignore added.
  • Tests (node --test) and CI: test on every PR; on master, publish ghcr.io/imkit/imkit-auth-server:{sha,master}.

Compatibility

  • API contract unchanged: GET /, POST /verify (claims or 401), POST /sign ({token, expirationDate}, one-year exp).
  • Tokens are interchangeable with 1.x when both use the same JWT_SECRET:
    • unit test signs/verifies across jsonwebtoken 8.5.1 and 9.0.3;
    • manual check against the published 1.x image (5698e38e): new-signed → old /verify 200, old-signed → new /verify 200.

Breaking change

Deployments that relied on the default secret must set JWT_SECRET before upgrading, or the service will not start. Rotating to a new secret invalidates existing tokens.

Test plan

  • npm test: 6 passing
  • Each test fails when its behaviour is reverted (token logging, algorithm pinning, default secret)
  • docker build and run: runs as node, no token in logs, exits 1 without JWT_SECRET

🤖 Generated with Claude Code

- Upgrade to Node 22, express 5, jsonwebtoken 9; drop unused dependencies.
- Never log issued tokens or decoded claims; keep method/path/status logs.
- Require JWT_SECRET at startup instead of falling back to a built-in default.
- Accept only HS256 on /verify; /sign keeps HS256 and the one-year exp.
- Run the container as the non-root node user; add tests and CI that
  publishes ghcr.io/imkit/imkit-auth-server.

Tokens stay compatible with 1.x: a test signs and verifies across
jsonwebtoken 8 and 9 with the same secret.

BREAKING CHANGE: the service exits if JWT_SECRET is not set.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@howardfuntek
howardfuntek merged commit f835e55 into master Sep 25, 2026
2 checks passed
@howardfuntek
howardfuntek deleted the feat/modernize-node22 branch September 25, 2026 13:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants