Skip to content

pnpm 12 preserves quotes around interpolated .npmrc auth tokens #14427

Description

@tjamesmac

Verify latest release

  • I verified that the issue exists in the latest pnpm release

pnpm version

12.2.1

Which area(s) of pnpm are affected? (leave empty if unsure)

CLI

Link to the code that reproduces this issue or a replay of the bug

No response

Reproduction steps

  1. Create .npmrc:
@scope:registry=https://registry.example/
//registry.example/:_authToken="${TOKEN}"
  1. Add a private @scope/* dependency.
  2. Export a valid synthetic/test token:
export TOKEN=...
  1. Run:
pnpm install

Describe the Bug

After bumping pnpm from v11.13.0 to v12.2.1, installs of private packages from our internal registry fail with ERR_PNPM_FETCH_401

Both of the versions are using the same global .npmrc file.

//registry.example/:_authToken="${TOKEN}"

With TOKEN=secret

  • pnpm 11 parses the value as secret
  • pnpm 12 parses the values as "secret"

It seems the quotes are becoming part of the value and are causing auth to fail with 401 Unauthorized.

To help repro I've used the unit tests beneath in both v11 and v12.

The TypeScript implementation passes this test at pnpm11/config/reader/test/index.ts:

test('user .npmrc expands a quoted auth token without retaining quotes', async () => {
  prepare()

  fs.mkdirSync('user-home')
  const userconfig = path.resolve('user-home', '.npmrc')
  fs.writeFileSync(
    userconfig,
    '//registry.example/:_authToken="${TOKEN}"\n',
    'utf8'
  )

  const { config } = await getConfig({
    cliOptions: { userconfig },
    env: { ...env, TOKEN: 'secret' },
    packageManager: {
      name: 'pnpm',
      version: '1.0.0',
    },
  })

  expect(config.authConfig['//registry.example/:_authToken']).toBe('secret')
})

The equivalent Rust implementation fails at pnpm/crates/config/src/npmrc_auth/tests.rs:

#[test]
fn from_ini_expands_quoted_auth_env_placeholder_without_quotes() {
    static_env!(Env, &[("TOKEN", "secret")]);

    let auth = NpmrcAuth::from_ini::<Env>(
        "//registry.example/:_authToken=\"${TOKEN}\"\n",
        Path::new(""),
    );

    assert_eq!(
        default_auth_token(&auth, "//registry.example/"),
        Some(Some("secret")),
    );
}

Expected Behavior

Expected: pnpm 12.2.1 removes the quotes the same as pnpm 11 and authenticates successfully.
Actual: pnpm 12.2.1 is keeping the quotes as part of the token, causing 401 Unauthorized

Which Node.js version are you using?

24.14.1

Which operating systems have you used?

  • macOS
  • Windows
  • Linux

If your OS is a Linux based, which one it is? (Include the version if relevant)

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

state: acceptedThe required changes are defined. There is consensus on the change. Development can be startedtype: bug

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions