Verify latest release
pnpm version
12.2.1
Which area(s) of pnpm are affected? (leave empty if unsure)
CLI
Link to the code that reproduces this issue or a replay of the bug
No response
Reproduction steps
- Create .npmrc:
@scope:registry=https://registry.example/
//registry.example/:_authToken="${TOKEN}"
- Add a private @scope/* dependency.
- Export a valid synthetic/test token:
- Run:
Describe the Bug
After bumping pnpm from v11.13.0 to v12.2.1, installs of private packages from our internal registry fail with ERR_PNPM_FETCH_401
Both of the versions are using the same global .npmrc file.
//registry.example/:_authToken="${TOKEN}"
With TOKEN=secret
- pnpm 11 parses the value as
secret
- pnpm 12 parses the values as
"secret"
It seems the quotes are becoming part of the value and are causing auth to fail with 401 Unauthorized.
To help repro I've used the unit tests beneath in both v11 and v12.
The TypeScript implementation passes this test at pnpm11/config/reader/test/index.ts:
test('user .npmrc expands a quoted auth token without retaining quotes', async () => {
prepare()
fs.mkdirSync('user-home')
const userconfig = path.resolve('user-home', '.npmrc')
fs.writeFileSync(
userconfig,
'//registry.example/:_authToken="${TOKEN}"\n',
'utf8'
)
const { config } = await getConfig({
cliOptions: { userconfig },
env: { ...env, TOKEN: 'secret' },
packageManager: {
name: 'pnpm',
version: '1.0.0',
},
})
expect(config.authConfig['//registry.example/:_authToken']).toBe('secret')
})
The equivalent Rust implementation fails at pnpm/crates/config/src/npmrc_auth/tests.rs:
#[test]
fn from_ini_expands_quoted_auth_env_placeholder_without_quotes() {
static_env!(Env, &[("TOKEN", "secret")]);
let auth = NpmrcAuth::from_ini::<Env>(
"//registry.example/:_authToken=\"${TOKEN}\"\n",
Path::new(""),
);
assert_eq!(
default_auth_token(&auth, "//registry.example/"),
Some(Some("secret")),
);
}
Expected Behavior
Expected: pnpm 12.2.1 removes the quotes the same as pnpm 11 and authenticates successfully.
Actual: pnpm 12.2.1 is keeping the quotes as part of the token, causing 401 Unauthorized
Which Node.js version are you using?
24.14.1
Which operating systems have you used?
If your OS is a Linux based, which one it is? (Include the version if relevant)
No response
Verify latest release
pnpm version
12.2.1
Which area(s) of pnpm are affected? (leave empty if unsure)
CLI
Link to the code that reproduces this issue or a replay of the bug
No response
Reproduction steps
Describe the Bug
After bumping pnpm from v11.13.0 to v12.2.1, installs of private packages from our internal registry fail with
ERR_PNPM_FETCH_401Both of the versions are using the same global
.npmrcfile.With
TOKEN=secretsecret"secret"It seems the quotes are becoming part of the value and are causing auth to fail with
401 Unauthorized.To help repro I've used the unit tests beneath in both v11 and v12.
The TypeScript implementation passes this test at
pnpm11/config/reader/test/index.ts:The equivalent Rust implementation fails at
pnpm/crates/config/src/npmrc_auth/tests.rs:Expected Behavior
Expected: pnpm 12.2.1 removes the quotes the same as pnpm 11 and authenticates successfully.
Actual: pnpm 12.2.1 is keeping the quotes as part of the token, causing
401 UnauthorizedWhich Node.js version are you using?
24.14.1
Which operating systems have you used?
If your OS is a Linux based, which one it is? (Include the version if relevant)
No response