Skip to content

Fix: TypeError in matchConnection and findADConnectionWithoutDomain for enterprise connections with null/undefined domains (#2749) - #2758

Merged
ankita10119 merged 3 commits into
masterfrom
SDK-8497
Apr 1, 2026
Merged

ankita10119 merged 3 commits into
masterfrom
SDK-8497

Conversation

@ankita10119

Copy link
Copy Markdown
Contributor

Changes

Problem

When a user types an email address into the Lock widget and an enterprise connection (e.g. samlp, oidc, ad) has no domains configured, the following error is thrown, crashing the widget:

Uncaught TypeError: Cannot read properties of undefined (reading 'contains')

This was reported in #2733 (v14.2.4) and further investigated in #2749 (v14.2.5).

Root Cause

The Auth0 API does not return the domains field consistently across tenants when no domains are configured. Some tenants omit the field entirely, others return it explicitly as null. These two cases behave differently in Immutable.js:

Specifically, Immutable's get(key, defaultValue) only uses defaultValue when the key is completely absent. If the key is present but its value is null or undefined, Immutable returns that value directly, bypassing the default entirely.

Changes

src/connection/enterprise.js - matchConnection

// Before
return x.get('domains', List()).contains(target);

// After
return (x.get('domains') || List()).contains(target);

src/connection/enterprise.js - findADConnectionWithoutDomain

The same pattern was identified in a second function that handles AD/LDAP connections:

// Before
return x.get('domains').isEmpty() && (!name || x.get('name') === name);

// After
return (x.get('domains') || List()).isEmpty() && (!name || x.get('name') === name);

Using || ensures all falsy values (null, undefined, absent key) are handled uniformly before calling .contains() or .isEmpty()

References

Closes #2749 | Related to #2733

Testing

Three test cases added to matchConnection.test.js:

Scenario Coverage
domains key absent Tenant omits the field
[Cell](domains: null) Tenant returns explicit null
Valid domains list Correct match still works

Checklist

…or enterprise connections with null/undefined domains (#2749)
@ankita10119
ankita10119 requested a review from a team as a code owner March 31, 2026 09:26
@ankita10119
ankita10119 merged commit 6393ffe into master Apr 1, 2026
5 checks passed
@ankita10119
ankita10119 deleted the SDK-8497 branch April 1, 2026 08:53
@ankita10119 ankita10119 mentioned this pull request Apr 6, 2026
ankita10119 added a commit that referenced this pull request Apr 6, 2026
**Added**
- feat(types): ship TypeScript definitions directly from the lock repo
[\#2763](#2763)
([ankita10119](https://github.com/ankita10119))

**Changed**
- chore(deps): upgrade webpack-dev-server to v5, auth0-password-policies
to 3.1.0, and fix dev setup
[\#2771](#2771)
([ankita10119](https://github.com/ankita10119))

**Deprecated**
- chore: remove deprecated yammer, renren, miicard strategies
[\#2747](#2747)
([omarquazi-okta](https://github.com/omarquazi-okta))

**Fixed**
- Fix: TypeError in matchConnection and findADConnectionWithoutDomain
for enterprise connections with null/undefined domains (#2749)
[\#2758](#2758)
([ankita10119](https://github.com/ankita10119))
@ankita10119 ankita10119 mentioned this pull request Apr 6, 2026
ankita10119 added a commit that referenced this pull request Apr 6, 2026
**Added**
- feat(types): ship TypeScript definitions directly from the lock repo
[\#2763](#2763)
([ankita10119](https://github.com/ankita10119))

**Changed**
- chore(deps): upgrade webpack-dev-server to v5, auth0-password-policies
to 3.1.0, and fix dev setup
[\#2771](#2771)
([ankita10119](https://github.com/ankita10119))

**Deprecated**
- chore: remove deprecated yammer, renren, miicard strategies
[\#2747](#2747)
([omarquazi-okta](https://github.com/omarquazi-okta))

**Fixed**
- Fix: TypeError in matchConnection and findADConnectionWithoutDomain
for enterprise connections with null/undefined domains (#2749)
[\#2758](#2758)
([ankita10119](https://github.com/ankita10119))
ankita10119 added a commit that referenced this pull request Aug 17, 2026
…D screen (#2841)

### Changes

`connection/enterprise.js`
- `matchConnection`: added null guard on x.get('domains') before calling
`.contains()` - prevents a crash when a connection has no domains
configured
- `findADConnectionWithoutDomain`: same null guard before calling
`.isEmpty()`

 ` connection/enterprise/hrd_screen.jsx`
- Changed `domain !== null `to `domain` && `domain.trim()` - empty or
whitespace-only domain strings now fall back to the generic login
instructions instead of interpolating a blank value into the enterprise
instructions string

### References

- #2736 - "Fix: TypeError in matchConnection for enterprise connections
with no domains" (merged Mar 17, 2026, closes #2733)
- #2758 - "Fix: TypeError in matchConnection and
findADConnectionWithoutDomain for null/undefined domains" (merged Apr 1,
2026, closes #2749)

### Testing

* [ ] This change adds unit test coverage
* [ ] This change adds integration test coverage
* [ ] This change has been tested on the latest version of the
platform/language

New test file `matchConnection.test.js` covers:
  - Matching a connection by email domain
  - No match when domain differs
  - No throw when a connection has null domains
  - Returns false for an email with no domain part

`hrd_screen.test.js` adds two new cases:
  - Empty string domain falls back to generic instructions
  - Whitespace-only domain falls back to generic instructions

  All 407 tests pass.

### Checklist

* [ ] I have read the [Auth0 general contribution
guidelines](https://github.com/auth0/open-source-template/blob/master/GENERAL-CONTRIBUTING.md)
* [ ] I have read the [Auth0 Code of
Conduct](https://github.com/auth0/open-source-template/blob/master/CODE-OF-CONDUCT.md)
* [ ] All code quality tools/guidelines have been run/followed
* [ ] All relevant assets have been compiled
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Error thrown for enterprise connection with no domains configured

2 participants