Skip to main content

#Package Manager2 debatiendo

   

Subject: Link Namespace fails: invalid_request "missing required code challenge" 

    

   Dev Hub org ID: <xyz>. Namespace org ID: <abc>. Namespace: Nativesign. 

   Namespace Registries > Link Namespace popup returns error=invalid_request&error_description=missing required code challenge. 

   The connected app "SalesforceDX Namespace Registry" has PKCE checked and locked ("contact Support"). Org-level PKCE is OFF. How can I link my namespace? 

 

#Package Manager  #Appexchage Apps  #Generation Managed Package  #Installed Packages

1 respuesta
  1. 21 sept, 13:54

    This looks like a mismatch created by Salesforce's own PKCE enforcement rollout rather than something wrong in your org's configuration. The SalesforceDX Namespace Registry connected app is a Salesforce-owned system connected app used by the Namespace Registries Link Namespace flow, and its PKCE requirement is locked because Salesforce has been moving connected apps and External Client Apps toward mandatory PKCE, with no admin opt-out on system apps like this one. Your org-level Require PKCE toggle being off is not relevant here, since that setting only affects apps that inherit the org default, and this one has its own requirement baked in. 

     

    The "invalid_request / missing required code challenge" error means the client side of this OAuth exchange, the Link Namespace popup itself, is not sending a code_challenge parameter even though the connected app now demands one. Since that popup is Salesforce's own UI and not something you control from Setup, you cannot fix this from your Dev Hub or Namespace org settings. Other admins have hit the same "missing required code challenge" wall on various Salesforce-owned OAuth flows since PKCE enforcement tightened, so this is worth logging as a Salesforce Support case, quoting the exact error and the Dev Hub and Namespace org IDs, so they can confirm whether it is a tracked regression tied to the PKCE rollout on that specific connected app. 

     

    Background on PKCE enforcement:

    https://help.salesforce.com/s/articleView?id=005316703&language=en_US&type=1

     

     

    Assumption: I cannot reproduce your Dev Hub, so I cannot fully confirm this is a Salesforce-side defect versus something specific to your org's Namespace Registry setup. This is inferred from the well-documented PKCE enforcement pattern and other reports of the same error on Salesforce-managed connected apps once PKCE became mandatory without an opt-out.

0/9000

Hey Team,

 

I want to create a managed package and want to upload it on AppExchange. But the issue I am facing is that I cannot create a managed package even though I am trying it on Enterprise Edition.

 

Can anyone help regarding this? #Package Manager #AppExchange

1 comentario
  1. 27 may 2023, 11:10

    Hi there, 

     

    I believe you already have explored this area. If not and for anybody having same question, this answer might help: 

     

    To create managed packages and to be able to upload them on AppExchange, you need to be a Salesforce Partner. Please refer to ISVForce Guide - https://developer.salesforce.com/docs/atlas.en-us.packagingGuide.meta/packagingGuide/packaging_intro.htm. It contains step-by-step details that will help you to qualify to be a Salesforce partner. 

     

    It is recommended to develop Second Generation Managed Packages (2GP) for AppExchange Listing. 2GPs are only created via SFDX CLI. Here's the guide: https://developer.salesforce.com/docs/atlas.en-us.sfdx_dev.meta/sfdx_dev/sfdx_dev_dev2gp.htm

     

    It is important to note that releasing a package is a process, which undergoes salesforce security review before it is published on AppExchange. Make sure the package you develop is in alignment with that: https://developer.salesforce.com/docs/atlas.en-us.packagingGuide.meta/packagingGuide/security_review_guidelines.htm

     

    Hope it helps!

0/9000

Hi everyone!

 

Not sure if this is the best place to ask this question, but:

I'm trying to create a package with Custom Metadata Types(mdt), through the Package Manager in Salesforce.

I can add the mdt to the package but not it's records and I don't know how.

On this page, https://help.salesforce.com/articleView?id=custommetadatatypes_package_install.htm&type=5,  it says it is possible, so I was wondering if anyone has done it.

 

Thank you in advance!

5 comentarios
0/9000

There is a KI that talks about not being able to add components via Package Manager (under setup) when in Lightning - https://success.salesforce.com/issues_view?id=a1p3A0000003cx4QAA 

 

It shows 'No Fix' as the status. If there are no plans to fix bugs in Lightning, how can we fully migrate to Lightning?

0/9000

On the subject of "Dreaming what Salesforce DX could be" I'm thinking a package manager would be super handy. In a recent post, I outlined how we're using packages and namespaces with DX. Since then we've progressed along nicely and we're really starting to see the enterprise in this. So, with packages comes more packages, and with that we're starting to get into dependency management hell.

 

I recently had a talk with Dileep and others around the limits of DX, and right now there is no limit to the number of packages we can install, so why not push this to the limit right?

 

So what I'd like to see in the future is a package manager, with some of the following features in mind:

  • A dev hub can register a "names" which can be used for package grouping. We currently have a number of SF namespaces, however it would be nice to just have one big one - e.g. guidion
  • Package can be given a developer friendly name which can be used to install the package from the "name" as above. For example sfdx force:manager:install --dependency guidion/string --package my-package. This would install the package "String" under the name "Guidion" as a dependency into the my-package in the sfdx-project.json. Think of this as npm install @babel/cli
  • When doing sfdx:force:org:create a new option for --install-dependencies would parse the sfdx-project.json file and install all packages listed. For now i'm okay with the installs queuing, however it would be nice if the org is snapshotted and just all dependencies installed to make it quicker to boot up
  • A package could be public or private
    • Public: anyone can sfdx force:manager:install the package (guidion/string). Can also be searched by users
    • Private: When you install/search for packages, it checks the hub org for private packages with friendly names to install
  • As above point, you can search for packages using sfdx:manager:search for example. It would be good to have some sort of site similar to how NPM does this too so we don't have to go browsing to find out how to implement it.

 

Does anyone else have thoughts, opinions on how this could work? The more we ask for, the more new things we can get!

3 comentarios
0/9000