You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
plugin-auth: phone-number send-otp with no SMS provider answers 500 with an empty body in production instead of a 4xx naming NOT_SUPPORTED #21793
Clause A4 of identity-auth.auth-method-matrix (rev 3) fails in the 17.7 pre-release run #21784 (subject 316be321e). An independent verifier (RUNNER rule 7) confirmed it from code and the measured 500 shape: CONFIRMED, P3. Predates 17.6.0.
Reproduction
Boot with NODE_ENV=production, the phone-number sign-in method enabled and no SMS provider configured.
POST /api/v1/auth/phone-number/send-otp {"phoneNumber":"+15550100"}.
Expected: a 4xx whose code names the missing capability (NOT_SUPPORTED), so the login page can say why.
Actual: 500 with a null body; the console shows a generic failure.
Mechanism
packages/plugins/plugin-auth/src/auth-manager.ts:5329-5336 throws a plain Error('NOT_SUPPORTED…'); better-call turns a non-API error into a bare 500 (the shape is described in service-sms/sms-service.ts:140-146).
QA-source: #21784 · identity-auth.auth-method-matrix · acceptance[3]
Clause A4 of
identity-auth.auth-method-matrix(rev 3) fails in the 17.7 pre-release run #21784 (subject316be321e). An independent verifier (RUNNER rule 7) confirmed it from code and the measured 500 shape: CONFIRMED, P3. Predates 17.6.0.Reproduction
NODE_ENV=production, the phone-number sign-in method enabled and no SMS provider configured.POST /api/v1/auth/phone-number/send-otp {"phoneNumber":"+15550100"}.NOT_SUPPORTED), so the login page can say why.500with a null body; the console shows a generic failure.Mechanism
packages/plugins/plugin-auth/src/auth-manager.ts:5329-5336throws a plainError('NOT_SUPPORTED…'); better-call turns a non-API error into a bare 500 (the shape is described inservice-sms/sms-service.ts:140-146).:5386) with a typed error; the no-provider branch was left on the plainError.Done when
The no-provider branch throws the same typed API error as the quota branch, and a test pins the status and code.
Generated by Claude Code