Skip to content

fix: add 'too_many_attempts' to error codes in logInError function - #2718

Merged
ankita10119 merged 1 commit into
masterfrom
SDK-7525
Jan 20, 2026
Merged

ankita10119 merged 1 commit into
masterfrom
SDK-7525

Conversation

@ankita10119

@ankita10119 ankita10119 commented Jan 16, 2026 •

Copy link
Copy Markdown
Contributor

Changes

Fixes issue #2589 where the authorization_error event was not being emitted when users trigger rate limiting by attempting too many failed logins.

Problem

When Auth0's brute force protection triggers and returns a too_many_attempts error (HTTP 429), Lock was not emitting the authorization_error event. This prevented applications from handling rate limiting errors gracefully through the event listener.

The error code too_many_attempts was missing from the whitelist array that determines which error codes should trigger the authorization_error event.

Solution

Added 'too_many_attempts' to the errorCodesThatEmitAuthorizationErrorEvent array in src/core/actions.js

This ensures that when rate limiting is triggered, applications can now handle it properly:

lock.on('authorization_error', function(error) {
  if (error.error === 'too_many_attempts') {
    // Show custom message to user
  }
});

References

Closes #2589

Testing

  • This change adds unit test coverage
  • This change adds integration test coverage
  • This change has been tested on the latest version of the platform/language

Checklist

@ankita10119
ankita10119 requested a review from a team as a code owner January 16, 2026 16:44
@ankita10119

ankita10119 commented Jan 16, 2026 •

Copy link
Copy Markdown
Contributor Author

Before

Screen.Recording.2026-01-16.at.9.49.42.PM.mov

After

Screen.Recording.2026-01-16.at.9.52.29.PM.mov

@ankita10119
ankita10119 merged commit 0a6071c into master Jan 20, 2026
5 checks passed
@ankita10119
ankita10119 deleted the SDK-7525 branch January 20, 2026 12:22
ankita10119 added a commit that referenced this pull request Jan 21, 2026
**Fixed**
- fix: update className and InputWrap name in SelectInput component
(#2534) [\#2719](#2719)
([ankita10119](https://github.com/ankita10119))
- fix: handle undefined and empty domain values in HRD screen (#2526)
[\#2720](#2720)
([ankita10119](https://github.com/ankita10119))
- fix: add 'too_many_attempts' to error codes in logInError function
[\#2718](#2718)
([ankita10119](https://github.com/ankita10119))
ankita10119 added a commit that referenced this pull request Sep 3, 2026
…ugin instantiation, fix SelectInput name prop (#2842)

### Changes

`core/actions.js`
- Added `too_many_attempts` to
`errorCodesThatEmitAuthorizationErrorEvent` - the `authorization_error`
event is now emitted when a user's account is blocked after consecutive
failed logins, consistent with other blocking error codes

  `core/web_api/p2_api.js`
- Wrapped new `CordovaAuth0Plugin()` in a typeof `CordovaAuth0Plugin ===
'function'` guard - prevents a runtime crash in non-Cordova environments
where the module may not export a valid constructor

 ` ui/input/select_input.jsx`
- Fixed InputWrap receiving the hardcoded string "location" as its name
prop, now correctly passes the dynamic name prop, fixing broken CSS
scoping, aria attributes, and id generation for any select input that
isn't a location picker

### References

- #2718 - "fix: add 'too_many_attempts' to error codes in logInError
function"
- #2742 - "Fix: TypeError when CordovaAuth0Plugin is not a constructor
(auth0-js 9.30.1+)"
- #2719 - "fix: update className and InputWrap name in SelectInput
component"

### Testing

* [x] This change adds unit test coverage
* [x] This change adds integration test coverage
* [x] This change has been tested on the latest version of the
platform/language

All 401 existing tests pass. The `too_many_attempts` event change and
the SelectInput fix are best verified with a running Lock instance. The
Cordova guard can be confirmed by initialising Lock in a non-Cordova
browser environment and verifying no constructor error is thrown.

### Checklist

* [x] I have read the [Auth0 general contribution
guidelines](https://github.com/auth0/open-source-template/blob/master/GENERAL-CONTRIBUTING.md)
* [x] I have read the [Auth0 Code of
Conduct](https://github.com/auth0/open-source-template/blob/master/CODE-OF-CONDUCT.md)
* [x] All code quality tools/guidelines have been run/followed
* [ ] All relevant assets have been compiled
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

"authorization_error" event is not triggering the "too_many_attempts" error

2 participants