Skip to content

plugin-auth: phone-number send-otp with no SMS provider answers 500 with an empty body in production instead of a 4xx naming NOT_SUPPORTED #21793

Description

@objectstack-fleet

QA-source: #21784 · identity-auth.auth-method-matrix · acceptance[3]

Clause A4 of identity-auth.auth-method-matrix (rev 3) fails in the 17.7 pre-release run #21784 (subject 316be321e). An independent verifier (RUNNER rule 7) confirmed it from code and the measured 500 shape: CONFIRMED, P3. Predates 17.6.0.

Reproduction

  1. Boot with NODE_ENV=production, the phone-number sign-in method enabled and no SMS provider configured.
  2. POST /api/v1/auth/phone-number/send-otp {"phoneNumber":"+15550100"}.
  • Expected: a 4xx whose code names the missing capability (NOT_SUPPORTED), so the login page can say why.
  • Actual: 500 with a null body; the console shows a generic failure.

Mechanism

Done when

The no-provider branch throws the same typed API error as the quota branch, and a test pins the status and code.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:identityLogin and identity — sign-up, sessions, organization membership, SSObugSomething isn't workingdomain:servicespriority:p3

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions