Skip to content

auth0: model user_metadata and app_metadata, expose them to rules - #379

Open
daaain wants to merge 1 commit into
thefrontside:mainfrom
daaain:feat/auth0-user-metadata
Open

daaain wants to merge 1 commit into
thefrontside:mainfrom
daaain:feat/auth0-user-metadata

Conversation

@daaain

@daaain daaain commented Sep 25, 2026 •

Copy link
Copy Markdown

Motivation

In Auth0, users have user_metadata and app_metadata, and rules often use them to add custom claims (for example, putting an organisation id from app_metadata into the access token).

The simulator's users only have id, name, email, password and picture. Metadata has nowhere to go, so a rule that reads user.app_metadata gets undefined. To test those rules today, you have to pass the values in some other way, such as an environment variable read inside the rule.

Approach

  • Users get two optional fields, user_metadata and app_metadata, which default to {}. You can set them in initialState like any other user field.
  • Rules receive both on the user argument, as in Auth0.
  • Neither is copied into the ID or access token by default. Like Auth0, a value only shows up in a token if a rule adds it as a claim.
  • Rules get a copy of the metadata, so a rule changing it doesn't change the stored user.

Tests cover seeding the fields, their defaults, reading them from a rule, and keeping them out of the tokens. The README has a short example.

Alternate Designs

The simplest option was to add metadata to the user data that already gets spread into the ID token. I didn't do that because the whole metadata object would then appear in every ID token, which real Auth0 doesn't do.

Possible Drawbacks or Risks

Nothing changes for existing users: both fields default to {}, and tokens look the same unless a rule uses the new fields.

TODOs and Open Questions

  • A follow-up PR adds Management API endpoints (PATCH /api/v2/users/:id and others) on top of this, so a metadata update can reach the next login.

Summary by CodeRabbit

  • New Features
    • Seeded users can now include user_metadata and app_metadata, which are available to rules through the user object.
    • Rules can copy metadata values into token claims. Metadata is not included in tokens by default.
    • Metadata fields omitted from seeded users default to empty objects.

Users seeded via initialState can carry user_metadata/app_metadata
(default {}), and rules receive both on the user argument as Auth0 Rules
do, so claims can be derived from metadata. Neither is copied into the
tokens unless a rule adds it as a claim.
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 3deb3d84-9b4e-4c7d-85bd-be03fc75eefd

📥 Commits

Reviewing files that changed from the base of the PR and between f5c06d3 and 879b0f4.

📒 Files selected for processing (9)
  • .changes/auth0-user-metadata.md
  • packages/auth0/README.md
  • packages/auth0/src/handlers/oauth-handlers.ts
  • packages/auth0/src/rules/types.ts
  • packages/auth0/src/store/entities.ts
  • packages/auth0/test/entities.test.ts
  • packages/auth0/test/fixtures/rules-metadata/metadata-claims.js
  • packages/auth0/test/fixtures/rules-metadata/metadata-claims.json
  • packages/auth0/test/rules.test.ts

Included review availability: Your plan provides up to 2 included reviews per hour; 1 remains after this review.


📝 Walkthrough

Walkthrough

The Auth0 simulator now stores seeded user_metadata and app_metadata, provides them to rules, and excludes the metadata objects from token claims unless a rule copies values into claims.

Changes

Auth0 user metadata

Layer / File(s) Summary
Metadata storage and rule input
packages/auth0/src/store/entities.ts, packages/auth0/src/rules/types.ts, packages/auth0/src/handlers/oauth-handlers.ts, packages/auth0/test/entities.test.ts, packages/auth0/README.md, .changes/auth0-user-metadata.md
The user schema defaults omitted metadata to empty objects. RuleUser includes optional metadata records. getIdToken supplies cloned metadata objects to rules. Tests cover parsing, store conversion, and defaults. The README example and changeset describe seeded metadata.
Rule claims and token output
packages/auth0/src/handlers/oauth-handlers.ts, packages/auth0/test/fixtures/rules-metadata/*, packages/auth0/test/rules.test.ts, packages/auth0/README.md
ID-token profile claims exclude metadata objects before merging rule-provided claims. The metadata rule fixture copies selected values into namespaced access-token and ID-token claims. Tests check the claims and confirm the metadata objects are not top-level token claims. The Rules documentation describes this behavior.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant OAuthHandler
  participant MetadataRule
  participant IDToken
  OAuthHandler->>MetadataRule: Supply cloned user_metadata and app_metadata on user
  MetadataRule->>IDToken: Add selected metadata values as claims
  OAuthHandler->>IDToken: Exclude metadata objects from profile claims and merge rule claims
Loading

Suggested reviewers: jbolda

Merge Risk: ⚪ Minimal · up to 879b0

No demonstrated issue blocks merging this metadata change after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 879b0

Metadata becomes available to configured rules, but is not placed in tokens by default. The reviewed flow keeps rule mutations separate from stored users, and no new metadata-update endpoint is shown. No PR-introduced security concern was established; broader security coverage remains unconfirmed.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — Exposure is bounded in the reviewed flow to metadata on the selected stored user and the configured rules processing that user. No new request-supplied metadata route was established.

Trust Boundaries and Controls

  • observed — Metadata crosses from stored user state into rule execution through structured clones. It crosses into signed token claims only if rule code writes corresponding context claims; the default ID-token projection excludes both metadata objects.

Resilience and Maintainability Implications

  • inferred — Refresh resolves the stored user again before following the same metadata-cloning and token-filtering path, rather than carrying rule-mutated metadata from a prior issuance.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: adding user_metadata and app_metadata to Auth0 users and exposing them to rules.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 6 files. (3 skipped: 3 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Sep 27, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@simulacrum/auth0-simulator@379

commit: 879b0f4

@frontsidejack

Copy link
Copy Markdown
Member

Package Changes Through 879b0f4

There are 1 changes which include @simulacrum/auth0-simulator with minor

Planned Package Versions

The following package releases are the planned based on the context of changes in this pull request.

package current next
@simulacrum/auth0-simulator 0.13.1 0.14.0

Add another change file through the GitHub UI by following this link.


Read about change files or the docs at github.com/jbolda/covector

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants