SIGN IN SIGN UP

[@vercel/blob] Read OIDC token via @vercel/oidc instead of inlined copy (#1072)

* [@vercel/blob] Read OIDC token via @vercel/oidc instead of inlined copy

Blob shipped its own inlined copy of the Vercel request-context reader, so
its OIDC support wasn't discoverable from the package's dependencies — an
agent had to read the bundled source to learn it used OIDC at all.

Depend on @vercel/oidc and use its `getContext` primitive. Behavior is
unchanged: Blob keeps its own resolution policy (trim tokens, ignore a blank
`x-vercel-oidc-token` header in favor of `VERCEL_OIDC_TOKEN`), since
@vercel/oidc's own token readers neither trim nor fall back on blank headers.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* [@vercel/blob] Pin jose to CJS in jest to fix jsdom/edge test envs

Depending on @vercel/oidc transitively pulls in jose (via verifyVercelOidcToken,
which Blob never calls). jose's browser/edge entry is ESM-only, so the jsdom and
edge-runtime jest environments resolved it and failed to parse it ("Unexpected
token 'export'") since jest doesn't transform node_modules. The node env was
unaffected because jose resolves to CJS there.

Move the jest config to jest.config.cjs and map `jose` to its CJS build in all
test environments. Blob doesn't use jose directly, so this only affects test
module resolution. Node/edge/browser suites all pass.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* [@vercel/blob] Use getVercelOidcTokenSync from @vercel/oidc

Switch the OIDC reader from @vercel/oidc's low-level `getContext` to its
`getVercelOidcTokenSync`, matching how every other consumer uses the package.
The wrapper converts the lib's "missing token" throw to undefined (so callers
fall through to BLOB_READ_WRITE_TOKEN) and treats a blank token as absent.

Behavior change (edge case): a blank `x-vercel-oidc-token` header now resolves
to no token instead of falling back to VERCEL_OIDC_TOKEN, since the library
selects the header whenever its key is present. Test updated accordingly.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
A
Agustin Falco committed
b7027de4bb60d1f6bdf3e41b8f3f61377738cbfc
Parent: 312d176
Committed by GitHub <noreply@github.com> on 6/15/2026, 8:32:55 PM