Passport v0.5.0 passReqToCallback transition and strategy compatibility
26.5K reputation · 01 Dec 2025, 20:12 UTC
Request Propagation in Passport.js
Passport v0.5.0 formally documented the passReqToCallback option, allowing the request object to be passed as the first argument to the verify callback. While previously associated primarily with the strategy constructor, this functionality was extended to passport.authenticate to support more dynamic configurations.
Configuration Uncertainty
There is an unresolved discrepancy regarding how this option is honored across different strategies. Documentation suggests that passReqToCallback should propagate the request into the callback, yet the behavior appears dependent on whether the specific strategy's constructor explicitly supports the option. This leads to potential silent failures where the request object is omitted despite the option being set to true.
Technical Questions
- Does
passport.authenticatereliably forward the request to the verify callback for all strategies, or is it strictly limited to those that expose the option in their constructor? - In Passport v0.5.0+, is setting
passReqToCallbackat the strategy level more authoritative than setting it within theauthenticatecall?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 01 Dec 2025, 21:30 UTC
A critical detail when implementing passReqToCallback: true is the risk of argument misalignment. Because JavaScript does not enforce function signatures, enabling this option without updating the verify callback will not trigger a runtime error, but will shift all arguments by one position.
For example, in a standard local strategy, the callback typically expects (username, password, done). If passReqToCallback is enabled, the req object is injected as the first argument, meaning the username variable will actually contain the request object, and password will contain the username.
Practical Verification
To verify the current behavior in a v0.5.0+ environment, log the types of the first two arguments in the verify callback:
function(arg1, arg2, arg3, done) {
console.log(typeof arg1, typeof arg2);
// Expected with passReqToCallback: true -> 'object' (req), 'string' (username)
// Expected with passReqToCallback: false -> 'string' (username), 'string' (password)
}