Repository navigation
Fix: TypeError in matchConnection and findADConnectionWithoutDomain for enterprise connections with null/undefined domains (#2749) - #2758
Merged
Merged
Conversation
…or enterprise connections with null/undefined domains (#2749)
Piyush-85
approved these changes
Mar 31, 2026
4 tasks done
Merged
ankita10119
added a commit
that referenced
this pull request
Apr 6, 2026
**Added** - feat(types): ship TypeScript definitions directly from the lock repo [\#2763](#2763) ([ankita10119](https://github.com/ankita10119)) **Changed** - chore(deps): upgrade webpack-dev-server to v5, auth0-password-policies to 3.1.0, and fix dev setup [\#2771](#2771) ([ankita10119](https://github.com/ankita10119)) **Deprecated** - chore: remove deprecated yammer, renren, miicard strategies [\#2747](#2747) ([omarquazi-okta](https://github.com/omarquazi-okta)) **Fixed** - Fix: TypeError in matchConnection and findADConnectionWithoutDomain for enterprise connections with null/undefined domains (#2749) [\#2758](#2758) ([ankita10119](https://github.com/ankita10119))
Merged
ankita10119
added a commit
that referenced
this pull request
Apr 6, 2026
**Added** - feat(types): ship TypeScript definitions directly from the lock repo [\#2763](#2763) ([ankita10119](https://github.com/ankita10119)) **Changed** - chore(deps): upgrade webpack-dev-server to v5, auth0-password-policies to 3.1.0, and fix dev setup [\#2771](#2771) ([ankita10119](https://github.com/ankita10119)) **Deprecated** - chore: remove deprecated yammer, renren, miicard strategies [\#2747](#2747) ([omarquazi-okta](https://github.com/omarquazi-okta)) **Fixed** - Fix: TypeError in matchConnection and findADConnectionWithoutDomain for enterprise connections with null/undefined domains (#2749) [\#2758](#2758) ([ankita10119](https://github.com/ankita10119))
7 tasks
7 tasks
ankita10119
added a commit
that referenced
this pull request
Aug 17, 2026
…D screen (#2841) ### Changes `connection/enterprise.js` - `matchConnection`: added null guard on x.get('domains') before calling `.contains()` - prevents a crash when a connection has no domains configured - `findADConnectionWithoutDomain`: same null guard before calling `.isEmpty()` ` connection/enterprise/hrd_screen.jsx` - Changed `domain !== null `to `domain` && `domain.trim()` - empty or whitespace-only domain strings now fall back to the generic login instructions instead of interpolating a blank value into the enterprise instructions string ### References - #2736 - "Fix: TypeError in matchConnection for enterprise connections with no domains" (merged Mar 17, 2026, closes #2733) - #2758 - "Fix: TypeError in matchConnection and findADConnectionWithoutDomain for null/undefined domains" (merged Apr 1, 2026, closes #2749) ### Testing * [ ] This change adds unit test coverage * [ ] This change adds integration test coverage * [ ] This change has been tested on the latest version of the platform/language New test file `matchConnection.test.js` covers: - Matching a connection by email domain - No match when domain differs - No throw when a connection has null domains - Returns false for an email with no domain part `hrd_screen.test.js` adds two new cases: - Empty string domain falls back to generic instructions - Whitespace-only domain falls back to generic instructions All 407 tests pass. ### Checklist * [ ] I have read the [Auth0 general contribution guidelines](https://github.com/auth0/open-source-template/blob/master/GENERAL-CONTRIBUTING.md) * [ ] I have read the [Auth0 Code of Conduct](https://github.com/auth0/open-source-template/blob/master/CODE-OF-CONDUCT.md) * [ ] All code quality tools/guidelines have been run/followed * [ ] All relevant assets have been compiled
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
Problem
When a user types an email address into the Lock widget and an enterprise connection (e.g. samlp, oidc, ad) has no domains configured, the following error is thrown, crashing the widget:
Uncaught TypeError: Cannot read properties of undefined (reading 'contains')This was reported in #2733 (v14.2.4) and further investigated in #2749 (v14.2.5).
Root Cause
The Auth0 API does not return the domains field consistently across tenants when no domains are configured. Some tenants omit the field entirely, others return it explicitly as null. These two cases behave differently in
Immutable.js:Specifically, Immutable's
get(key, defaultValue)only uses defaultValue when the key is completely absent. If the key is present but its value is null or undefined, Immutable returns that value directly, bypassing the default entirely.Changes
src/connection/enterprise.js - matchConnection// Before
return x.get('domains', List()).contains(target);// After
return (x.get('domains') || List()).contains(target);src/connection/enterprise.js - findADConnectionWithoutDomainThe same pattern was identified in a second function that handles AD/LDAP connections:
// Before
return x.get('domains').isEmpty() && (!name || x.get('name') === name);// After
return (x.get('domains') || List()).isEmpty() && (!name || x.get('name') === name);Using || ensures all falsy values
(null, undefined, absent key)are handled uniformly before calling.contains()or.isEmpty()References
Closes #2749 | Related to #2733
Testing
Three test cases added to
matchConnection.test.js:domainskey absent[Cell](domains: null)domainslistChecklist