refactor(v6): audit the public API surface and freeze the error taxonomy - #1634
refactor(v6): audit the public API surface and freeze the error taxonomy#1634NandanPrabhu wants to merge 2 commits into
Conversation
📝 WalkthroughWalkthroughThe SDK formalizes typed error codes, normalizes My Account errors, expands and validates public exports, and renames the DPoP parameter type while retaining a deprecated compatibility alias. Documentation and examples now use the updated error contracts. ChangesError taxonomy and normalization
Public API contract
DPoP parameter migration
Estimated code review effort: 4 (Complex) | ~45 minutes Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Prepares the v6 public contract so post-GA changes cannot break consumers accidentally (SDK-10043). Error taxonomy: - Add MyAccountErrorCodes, completing the set of six code objects. MyAccountError previously exposed a raw RFC 7807 type URI on `type`, unlike every sibling class; `type` is now a normalized code and the original URI is preserved on the new `typeUri` property. - Export a derived union per class (WebAuthErrorCode, ..., MyAccountErrorCode) computed from the constants object, so the runtime values and the type cannot drift, and narrow each class's `type` to its union. - Add Auth0ErrorCode as the umbrella union, and bring TimeoutError into the taxonomy with `type: 'TIMEOUT_ERROR'`. Surface cleanup (122 -> 136 exports): - Un-export four internal wire/config shapes: NativeAuth0Options, WebAuth0Options, NativeCredentialsResponse, SSOCredentialsResponse. - Export types that already appeared in public signatures but were unreachable from the entry point: IAuth0Client and its five sub-provider siblings, Auth0ContextInterface, AuthState, SafariViewControllerPresentationStyle. - Replace the blanket `export * from './types'` with explicit sectioned exports, and delete the dead, drifted src/exports/ barrel files. - Rename DPoPHeadersParams to DPoPHeadersParameters for consistency with the other `...Parameters` types, keeping a deprecated alias. Freeze mechanism: - publicApiSurface.spec.ts asserts the exact export list via the TypeScript compiler API, so type-only regressions are caught too. - errorTaxonomy.spec.ts asserts the structural invariants: every class carries a normalized `type`, falls back to a terminal unknown code, and keeps codes unique across classes except for three documented overlaps. Docs: document the taxonomy and the type/code/typeUri distinction as the stable contract, and fix two example blocks that referenced exports which never existed (MyAccountErrorCodes before this change, and AuthenticationException / AuthenticationErrorCodes, which do not exist at all). BREAKING CHANGE: MyAccountError.type is now a normalized MyAccountErrorCodes value rather than an RFC 7807 type URI; read `typeUri` for the raw URI. The internal types NativeAuth0Options, WebAuth0Options, NativeCredentialsResponse and SSOCredentialsResponse are no longer exported.
4c33400 to
5855652
Compare
There was a problem hiding this comment.
Actionable comments posted: 6
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@EXAMPLES.md`:
- Around line 1005-1023: Update the AuthError switch in the Custom Token
Exchange handler to use the documented emitted codes consistently: replace
unsupported_grant_type with unsupported_token_type and add unauthorized_client
with the corresponding documented disabled-client alert. Ensure the reference
documentation uses the same code set and preserves the existing access_denied
handling.
In `@README.md`:
- Around line 720-723: Update the My Account error examples to use the full
opaque A0E-<status>-<numeric> type format: in README.md lines
720-723, change the raw URI example to a value such as A0E-401-0001; in
EXAMPLES.md lines 1845-1859, update the typeUri output to use the same complete
format.
- Around line 673-680: Update the README error-handling guidance to restrict
`type`-based control flow to normalized error subclasses. Clarify that generic
`AuthError` flows, including Custom Token Exchange, should inspect `code` for
OAuth error values, while preserving `code` as the raw platform or wire
diagnostic for normalized errors.
- Around line 684-710: Update the README error-handling example and surrounding
description so it does not call the shown switch exhaustive while it contains a
default branch. Either describe WebAuthErrorCode as supporting exhaustive
handling, or handle every code explicitly and add a never guard; anchor the
change to the WebAuthErrorCode/WebAuthErrorCodes example.
In `@src/__tests__/publicApiSurface.spec.ts`:
- Around line 208-212: Update the test around “exposes the default export under
a named alias” to use the TypeScript checker to resolve the symbols for “Auth0”
and “default”, then assert that their aliased symbols are identical; retain the
existing surface-presence checks only if needed for setup.
In `@src/core/models/MyAccountError.ts`:
- Around line 158-166: Update the MyAccountError parsing logic to read the RFC
7807 parsed.status value before falling back to parsed.statusCode, while
retaining originalError.status as the final fallback for compatibility. Ensure
the resulting statusCode drives ERROR_CODE_MAP/fromStatusCode classification,
and add a regression test covering parsed status 401 with AuthError.status 0.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro Plus
Run ID: d34518ad-84ef-4e7b-ae2c-fa4bbf93375a
📒 Files selected for processing (31)
EXAMPLES.mdREADME.mdsrc/Auth0.tssrc/__tests__/publicApiSurface.spec.tssrc/core/interfaces/IAuth0Client.tssrc/core/models/CredentialsManagerError.tssrc/core/models/DPoPError.tssrc/core/models/MfaError.tssrc/core/models/MyAccountError.tssrc/core/models/PasskeyError.tssrc/core/models/WebAuthError.tssrc/core/models/__tests__/ErrorCodes.spec.tssrc/core/models/__tests__/MyAccountError.spec.tssrc/core/models/__tests__/errorTaxonomy.spec.tssrc/core/models/errorCodes.tssrc/core/models/index.tssrc/core/utils/fetchWithTimeout.tssrc/exports/classes.tssrc/exports/enums.tssrc/exports/hooks.tssrc/exports/index.tssrc/exports/interface.tssrc/hooks/Auth0Context.tssrc/hooks/Auth0Provider.tsxsrc/index.tssrc/platforms/native/adapters/NativeAuth0Client.tssrc/platforms/native/bridge/INativeBridge.tssrc/platforms/native/bridge/NativeBridgeManager.tssrc/platforms/web/adapters/WebAuth0Client.tssrc/platforms/web/adapters/__tests__/WebMyAccountClient.spec.tssrc/types/common.ts
💤 Files with no reviewable changes (5)
- src/exports/index.ts
- src/exports/hooks.ts
- src/exports/classes.ts
- src/exports/enums.ts
- src/exports/interface.ts
| if (e instanceof AuthError) { | ||
| // Custom Token Exchange surfaces the OAuth 2.0 error from the token | ||
| // endpoint on `code`. See the RFC 8693 error responses and your Action's | ||
| // own failure reasons. | ||
| switch (e.code) { | ||
| case 'invalid_request': | ||
| Alert.alert('Error', 'The external token or token type is invalid'); | ||
| break; | ||
| case AuthenticationErrorCodes.UNSUPPORTED_TOKEN_TYPE: | ||
| Alert.alert('Error', 'The token type is not supported'); | ||
| case 'invalid_grant': | ||
| Alert.alert('Error', 'The external token was rejected or expired'); | ||
| break; | ||
| case AuthenticationErrorCodes.TOKEN_EXCHANGE_NOT_CONFIGURED: | ||
| case 'unsupported_grant_type': | ||
| Alert.alert( | ||
| 'Error', | ||
| 'Custom Token Exchange is not configured for this tenant' | ||
| 'Custom Token Exchange is not enabled for this tenant' | ||
| ); | ||
| break; | ||
| case AuthenticationErrorCodes.TOKEN_VALIDATION_FAILED: | ||
| Alert.alert('Error', 'Token validation failed in Auth0 Action'); | ||
| break; | ||
| case AuthenticationErrorCodes.NETWORK_ERROR: | ||
| Alert.alert('Error', 'Network error. Please check your connection.'); | ||
| case 'access_denied': | ||
| Alert.alert('Error', 'Token validation failed in the Auth0 Action'); |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
Align the handler with the documented Custom Token Exchange codes.
This handler checks unsupported_grant_type. The reference at lines 1209-1226 lists unsupported_token_type and unauthorized_client instead. The documented alerts for unsupported token types and disabled clients will not run for the listed codes.
Align the handler and reference with the same emitted code set.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@EXAMPLES.md` around lines 1005 - 1023, Update the AuthError switch in the
Custom Token Exchange handler to use the documented emitted codes consistently:
replace unsupported_grant_type with unsupported_token_type and add
unauthorized_client with the corresponding documented disabled-client alert.
Ensure the reference documentation uses the same code set and preserves the
existing access_denied handling.
| Every error the SDK throws extends `AuthError` and carries a **normalized, platform-agnostic** | ||
| `type`. Switch on `type` — never on `code` — and your error handling behaves identically on iOS, | ||
| Android, and web. | ||
|
|
||
| | Property | Use it for | | ||
| | --------- | ---------------------------------------------------------------------------------------------------------- | | ||
| | `type` | **Control flow.** A normalized code, stable across platforms. Compare against the `…ErrorCodes` constants. | | ||
| | `code` | **Diagnostics.** The raw code from the underlying platform SDK or wire response. Varies by platform. | |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
Limit the type guidance to normalized error subclasses.
Custom Token Exchange throws AuthError and uses OAuth error values in code, as shown in EXAMPLES.md lines 1005-1023. The instruction to “never” switch on code conflicts with that supported flow.
State that consumers must use type for normalized error subclasses and use code for generic AuthError flows such as Custom Token Exchange.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@README.md` around lines 673 - 680, Update the README error-handling guidance
to restrict `type`-based control flow to normalized error subclasses. Clarify
that generic `AuthError` flows, including Custom Token Exchange, should inspect
`code` for OAuth error values, while preserving `code` as the raw platform or
wire diagnostic for normalized errors.
| Each error class ships a companion constants object and a matching TypeScript union, so a `switch` | ||
| on `type` is exhaustively checked at compile time: | ||
|
|
||
| | Error class | Constants | Type union | Thrown by | | ||
| | ------------------------- | ------------------------------ | ---------------------------------- | ----------------------------------------------- | | ||
| | `WebAuthError` | `WebAuthErrorCodes` | `WebAuthErrorCode` | `webAuth.authorize()`, `webAuth.clearSession()` | | ||
| | `CredentialsManagerError` | `CredentialsManagerErrorCodes` | `CredentialsManagerErrorCode` | `credentialsManager.*` | | ||
| | `MfaError` | `MfaErrorCodes` | `MfaErrorCode` | `mfa.*` | | ||
| | `PasskeyError` | `PasskeyErrorCodes` | `PasskeyErrorCode` | passkey signup/login and passkey enrollment | | ||
| | `MyAccountError` | `MyAccountErrorCodes` | `MyAccountErrorCode` | `myAccount.*` | | ||
| | `DPoPError` | `DPoPErrorCodes` | `DPoPErrorCode` | `getDPoPHeaders()` and DPoP key handling | | ||
| | `TimeoutError` | — | `type` is always `'TIMEOUT_ERROR'` | HTTP requests exceeding `timeout` | | ||
|
|
||
| ```typescript | ||
| import { WebAuthError, WebAuthErrorCodes } from 'react-native-auth0'; | ||
| import type { WebAuthErrorCode } from 'react-native-auth0'; | ||
|
|
||
| function describe(type: WebAuthErrorCode): string { | ||
| switch (type) { | ||
| case WebAuthErrorCodes.USER_CANCELLED: | ||
| return 'Cancelled'; | ||
| case WebAuthErrorCodes.NETWORK_ERROR: | ||
| return 'Offline'; | ||
| default: | ||
| return 'Login failed'; | ||
| } | ||
| } |
There was a problem hiding this comment.
📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
sed -n '675,715p' README.md
printf '\n--- related error-code definitions and examples ---\n'
rg -n -C 3 "WebAuthErrorCode|WebAuthErrorCodes|exhaustively|switch.*type" src README.md EXAMPLES.mdRepository: auth0/react-native-auth0
Length of output: 35642
🏁 Script executed:
command -v tsc || true
command -v npx || true
if command -v tsc >/dev/null 2>&1; then
tmpdir="$(mktemp -d)"
cat >"$tmpdir/exhaustiveness.ts" <<'TS'
type Code = 'USER_CANCELLED' | 'NETWORK_ERROR' | 'ACCESS_DENIED';
function withDefault(type: Code): string {
switch (type) {
case 'USER_CANCELLED':
return 'Cancelled';
default:
return 'Fallback';
}
}
function withNever(type: Code): string {
switch (type) {
case 'USER_CANCELLED':
return 'Cancelled';
case 'NETWORK_ERROR':
return 'Offline';
case 'ACCESS_DENIED':
return 'Denied';
default: {
const unreachable: never = type;
return unreachable;
}
}
}
TS
tsc --strict --noEmit "$tmpdir/exhaustiveness.ts"
rm -rf "$tmpdir"
fiRepository: auth0/react-native-auth0
Length of output: 342
🏁 Script executed:
tmpdir="$(mktemp -d)"
cat >"$tmpdir/exhaustiveness.ts" <<'TS'
type Code = 'USER_CANCELLED' | 'NETWORK_ERROR' | 'ACCESS_DENIED';
function withDefault(type: Code): string {
switch (type) {
case 'USER_CANCELLED':
return 'Cancelled';
default:
return 'Fallback';
}
}
function withNever(type: Code): string {
switch (type) {
case 'USER_CANCELLED':
return 'Cancelled';
case 'NETWORK_ERROR':
return 'Offline';
case 'ACCESS_DENIED':
return 'Denied';
default: {
const unreachable: never = type;
return unreachable;
}
}
}
TS
tsc --ignoreConfig --strict --noEmit "$tmpdir/exhaustiveness.ts"
rm -rf "$tmpdir"Repository: auth0/react-native-auth0
Length of output: 162
Do not describe this switch as exhaustive.
The default branch accepts omitted WebAuthErrorCode cases. State that the union supports exhaustive handling, or show a never guard with every code handled.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@README.md` around lines 684 - 710, Update the README error-handling example
and surrounding description so it does not call the shown switch exhaustive
while it contains a default branch. Either describe WebAuthErrorCode as
supporting exhaustive handling, or handle every code explicitly and add a never
guard; anchor the change to the WebAuthErrorCode/WebAuthErrorCodes example.
| `MyAccountError` is the one class with an extra property: the My Account API reports failures as | ||
| [RFC 7807](https://datatracker.ietf.org/doc/html/rfc7807) type URIs, so `type` holds the normalized | ||
| code while `typeUri` preserves the original URI (e.g. `https://auth0.com/api-errors/A0E-401`) for | ||
| logging and support tickets. |
There was a problem hiding this comment.
📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win
Use the full opaque My Account type value in both examples.
My Account API error types use the A0E-<status>-<numeric> format. A0E-401 omits the numeric component and can mislead users about the raw typeUri value.
README.md#L720-L723: change the raw URI example to include a numeric suffix, such asA0E-401-0001.EXAMPLES.md#L1845-L1859: change thetypeUrioutput example to include the same full opaque type format.
Based on learnings, web My Account errors use opaque A0E-<status>-<numeric> type values.
📍 Affects 2 files
README.md#L720-L723(this comment)EXAMPLES.md#L1845-L1859
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@README.md` around lines 720 - 723, Update the My Account error examples to
use the full opaque A0E-<status>-<numeric> type format: in README.md
lines 720-723, change the raw URI example to a value such as A0E-401-0001; in
EXAMPLES.md lines 1845-1859, update the typeUri output to use the same complete
format.
Source: Learnings
| it('exposes the default export under a named alias', () => { | ||
| // `default` alone is awkward for consumers doing `import { Auth0 }`. | ||
| expect(actual).toContain('default'); | ||
| expect(actual).toContain('Auth0'); | ||
| }); |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -eu
printf '%s\n' '--- target file outline ---'
ast-grep outline src/__tests__/publicApiSurface.spec.ts || true
printf '%s\n' '--- target test context ---'
sed -n '1,250p' src/__tests__/publicApiSurface.spec.ts
printf '%s\n' '--- Auth0 export declarations and related tests ---'
rg -n --glob '!lib/**' --glob '!docs/**' --glob '!coverage/**' \
"export .*Auth0|default as Auth0|class Auth0|const Auth0|interface .*Auth0|publicApiSurface|typeChecker|getAliasedSymbol" \
src package.json tsconfig*.jsonRepository: auth0/react-native-auth0
Length of output: 9982
🏁 Script executed:
#!/bin/bash
set -eu
printf '%s\n' '--- relevant source declarations ---'
sed -n '1,125p' src/index.ts
sed -n '1,55p' src/Auth0.ts
sed -n '205,225p' src/Auth0.ts
printf '%s\n' '--- TypeScript/test configuration ---'
cat package.json
printf '%s\n' '--- tsconfig ---'
cat tsconfig.json
printf '%s\n' '--- compiler API availability ---'
node - <<'JS'
try {
const ts = require('typescript');
console.log(JSON.stringify({ available: true, version: ts.version }));
} catch (error) {
console.log(JSON.stringify({ available: false, message: String(error) }));
}
JSRepository: auth0/react-native-auth0
Length of output: 11914
🏁 Script executed:
#!/bin/bash
set -eu
node - <<'JS'
const path = require('path');
const ts = require('typescript');
const projectRoot = process.cwd();
const configPath = path.join(projectRoot, 'tsconfig.json');
const entryPoint = path.join(projectRoot, 'src', 'index.ts');
const config = ts.getParsedCommandLineOfConfigFile(configPath, {}, {
...ts.sys,
onUnRecoverableConfigFileDiagnostic(diagnostic) {
throw new Error(ts.flattenDiagnosticMessageText(diagnostic.messageText, '\n'));
},
});
if (!config) throw new Error(`Unable to parse ${configPath}`);
const program = ts.createProgram([entryPoint], config.options);
const checker = program.getTypeChecker();
const sourceFile = program.getSourceFile(entryPoint);
if (!sourceFile) throw new Error(`Unable to load ${entryPoint}`);
const moduleSymbol = checker.getSymbolAtLocation(sourceFile);
if (!moduleSymbol) throw new Error('Entry point is not a module');
const exports = new Map(
checker.getExportsOfModule(moduleSymbol).map((symbol) => [symbol.getName(), symbol])
);
const defaultExport = exports.get('default');
const namedAuth0Export = exports.get('Auth0');
function describe(symbol) {
if (!symbol) return null;
const aliased = symbol.flags & ts.SymbolFlags.Alias
? checker.getAliasedSymbol(symbol)
: symbol;
return {
name: symbol.getName(),
flags: symbol.flags,
isAlias: Boolean(symbol.flags & ts.SymbolFlags.Alias),
aliasTargetName: aliased.getName(),
aliasTargetId: aliased.id,
declarations: (aliased.declarations ?? []).map((declaration) => ({
file: path.relative(projectRoot, declaration.getSourceFile().fileName),
kind: ts.SyntaxKind[declaration.kind],
text: declaration.getText(),
})),
};
}
console.log(JSON.stringify({
defaultExport: describe(defaultExport),
namedAuth0Export: describe(namedAuth0Export),
resolvedSymbolsIdentical:
defaultExport && namedAuth0Export &&
checker.getAliasedSymbol(defaultExport) === checker.getAliasedSymbol(namedAuth0Export),
}, null, 2));
JSRepository: auth0/react-native-auth0
Length of output: 12684
Assert that Auth0 resolves to the default export.
The current assertions only check that both names exist. Resolve both symbols with the TypeScript checker and compare their aliased symbols.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@src/__tests__/publicApiSurface.spec.ts` around lines 208 - 212, Update the
test around “exposes the default export under a named alias” to use the
TypeScript checker to resolve the symbols for “Auth0” and “default”, then assert
that their aliased symbols are identical; retain the existing surface-presence
checks only if needed for setup.
| this.typeUri = (parsed?.type as string) ?? originalError.code; | ||
| this.title = (parsed?.title as string) ?? ''; | ||
| this.detail = (parsed?.detail as string) ?? originalError.message; | ||
| this.statusCode = (parsed?.statusCode as number) ?? originalError.status; | ||
|
|
||
| this.type = | ||
| ERROR_CODE_MAP[originalError.code] ?? | ||
| fromStatusCode(this.statusCode) ?? | ||
| MyAccountErrorCodes.UNKNOWN_MY_ACCOUNT_ERROR; |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
# Inspect how My Account adapters populate AuthError status and problem details.
ast-grep outline src/core/models/MyAccountError.ts --view expanded
rg -n -C 5 --type ts \
'statusCode|\.status\b|new AuthError|MyAccountError' \
src/core/models src/platformsRepository: auth0/react-native-auth0
Length of output: 50383
🏁 Script executed:
#!/bin/bash
set -euo pipefail
printf '%s\n' '--- MyAccountError.ts ---'
cat -n src/core/models/MyAccountError.ts | sed -n '140,170p'
printf '%s\n' '--- My Account tests and payload fixtures ---'
rg -n -C 4 --type ts \
'MyAccountError|statusCode|status:|typeUri|json:' \
src --glob '*MyAccount*' --glob '*myAccount*'
printf '%s\n' '--- Adapter error construction ---'
rg -n -C 6 --type ts \
'AuthError\.fromResponse|new AuthError|response\.status|json' \
src/platforms/native/adapters/NativeMyAccountClient.ts \
src/platforms/web/adapters/WebMyAccountClient.ts
printf '%s\n' '--- Deterministic normalization probe ---'
python3 - <<'PY'
def from_status_code(status):
return {
400: 'INVALID_REQUEST',
401: 'UNAUTHORIZED',
403: 'UNAUTHORIZED',
404: 'NOT_FOUND',
409: 'CONFLICT',
429: 'TOO_MANY_REQUESTS',
}.get(status)
def normalize(original_code, original_status, parsed):
status_code = parsed.get('statusCode', original_status)
return from_status_code(status_code) or 'UNKNOWN_MY_ACCOUNT_ERROR'
cases = [
('A0E-401-0001', 0, {'status': 401}),
('A0E-401-0001', 0, {'statusCode': 401}),
('A0E-401-0001', 401, {'status': 401}),
]
for case in cases:
print(case, '=>', normalize(*case))
PYRepository: auth0/react-native-auth0
Length of output: 50382
🏁 Script executed:
#!/bin/bash
set -euo pipefail
printf '%s\n' '--- MyAccountError tests ---'
cat -n src/core/models/__tests__/MyAccountError.spec.ts | sed -n '1,180p'
printf '%s\n' '--- Web error mapping ---'
cat -n src/platforms/web/adapters/WebMyAccountClient.ts | sed -n '80,110p'
printf '%s\n' '--- Native error status sources ---'
rg -n -C 3 --type ts \
'statusCode|status:' \
src/platforms/native src/platforms/web/adapters/WebMyAccountClient.ts \
--glob '!**/__tests__/**'Repository: auth0/react-native-auth0
Length of output: 8013
Parse RFC 7807 status before statusCode.
When a problem document contains { "status": 401 } and AuthError.status is 0, the current code returns UNKNOWN_MY_ACCOUNT_ERROR. Preserve statusCode as a compatibility fallback and add a regression test.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@src/core/models/MyAccountError.ts` around lines 158 - 166, Update the
MyAccountError parsing logic to read the RFC 7807 parsed.status value before
falling back to parsed.statusCode, while retaining originalError.status as the
final fallback for compatibility. Ensure the resulting statusCode drives
ERROR_CODE_MAP/fromStatusCode classification, and add a regression test covering
parsed status 401 with AuthError.status 0.
Summary
Before v6 GA, freeze the public surface so post-GA additions can't happen by accident, and give consumers one predictable error contract across iOS, Android, and web.
MyAccountErrorCodes(previously referenced in docs but never implemented) and mappedMyAccountError.typeonto normalized codes instead of an RFC 7807 URI, preserving the URI on a newtypeUrifield. Exported six derived code unions (WebAuthErrorCode,CredentialsManagerErrorCode,DPoPErrorCode,MfaErrorCode,PasskeyErrorCode,MyAccountErrorCode) plus anAuth0ErrorCodeumbrella, and narrowed each error class'stypefield fromstringto its own union.TimeoutErrornow has atypeso it joins the taxonomy.NativeAuth0Options,WebAuth0Options,NativeCredentialsResponse,SSOCredentialsResponse), deleted the dead/driftedsrc/exports/barrel, and added 18 exports for types that already appeared in public method signatures but were unreachable fromsrc/index.ts(client interfaces,Auth0ContextInterface,AuthState, a namedAuth0export, etc.). Net: 122 → 136 exports.DPoPHeadersParams→DPoPHeadersParametersfor naming consistency, with a@deprecatedalias kept.MyAccountErrorCodesusage inEXAMPLES.mdand documented the frozen taxonomy inREADME.md.Breaking changes
MyAccountError.typeis now a normalized code instead of an RFC 7807 URI (the URI is preserved ontypeUri).typefield is narrowed fromstringto a specific union — breaks only for code that assigned arbitrary strings to.type, which isn't a supported use.Test plan
yarn test— 773 passed, 39 suitesyarn typecheck— clean