Skip to content

fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough - #335

Merged
Railly merged 4 commits into
mainfrom
fix/deploy-oauth-redirect-fapi
Jun 17, 2026
Merged

fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough#335
Railly merged 4 commits into
mainfrom
fix/deploy-oauth-redirect-fapi

Conversation

@Railly

@RaillyRailly commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Problem

The OAuth walkthrough in clerk deploy prints https://accounts.{domain}/v1/oauth_callback as the redirect URI. That endpoint lives on the Frontend API (clerk.{domain}), not the Account Portal, so pasting the printed value into a provider console causes redirect_uri_mismatch. Affects every provider walkthrough since #260.

Fix

PLAPI already returns the correct value as frontend_api_url on the domain object; it was being dropped. Thread it through deploy state (new-deploy and resume paths) into showOAuthWalkthrough, with a https://clerk.{domain} fallback since TS types do not validate runtime JSON.

Tests

  • New walkthrough test with a distinctive API-provided frontend_api_url proves the value is threaded, not string-built from the domain
  • Reconcile-path walkthrough test now asserts the FAPI URI and the absence of the accounts. one
  • bun test, typecheck, lint, format:check pass

@changeset-bot

changeset-botBot commented Jun 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5e62655

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

The OAuth walkthrough printed https://accounts.{domain}/v1/oauth_callback,
but /v1/oauth_callback is served by the Frontend API (clerk.{domain}), not
the Account Portal. Users pasting the printed value into their provider
console hit redirect_uri_mismatch.
Thread frontend_api_url from the PLAPI domain response through
DeployOperationState and LiveDeploySnapshot into showOAuthWalkthrough,
falling back to https://clerk.{domain} if absent.
@Railly
Raillyforce-pushed the fix/deploy-oauth-redirect-fapi branch from 61640b5 to 31baaf9CompareJune 12, 2026 23:52
@coderabbitai

coderabbitaiBot commented Jun 12, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: e65e23ab-e2a2-4d5b-919e-f2a4f7e68628

📥 Commits

Reviewing files that changed from the base of the PR and between 1df3c49 and 5e62655.

📒 Files selected for processing (2)
  • packages/cli-core/src/commands/deploy/copy.ts
  • packages/cli-core/src/commands/deploy/providers.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/cli-core/src/commands/deploy/providers.ts

📝 Walkthrough

Walkthrough

This PR updates the clerk deploy command's OAuth credential setup flow to use the Frontend API URL for OAuth redirect URIs instead of the Accounts Portal URL. The change threads frontendApiUrl from the production domain through the deploy operation state into the OAuth walkthrough renderer, where it constructs and displays the correct callback URI. A new clerkSubdomains helper extracts subdomain computation logic for reuse. Supporting updates include extending the DeployOperationState type, including the URL in the live deployment snapshot, refactoring test helpers to support dynamic Frontend API URL injection, and documenting the new behavior.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~14 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 23.08% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly describes the main change: using the Frontend API URL for OAuth redirect URI in the walkthrough, which matches the primary fix across all modified files.
Description check✅ PassedThe description is well-related to the changeset, explaining the problem, the solution, and the testing approach that matches the actual code changes.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@Railly
Raillyforce-pushed the fix/deploy-oauth-redirect-fapi branch from c1135f5 to 5eac92dCompareJune 12, 2026 23:55
@Railly
Railly requested review from rafa-thayto and wyattjoh and removed request for rafa-thaytoJune 16, 2026 17:46
Comment threadpackages/cli-core/src/commands/deploy/providers.ts Outdated
@wyattjoh

Copy link
Copy Markdown
Contributor

I was more sort of thinking these domain subdomains:

consthosts=[`clerk.${domain}`,`accounts.${domain}`,`clkmail.${domain}`];

That way other code can just reference it properly instead of hardcoding accounts. which can too easily drift.

@Railly
Railly requested a review from wyattjohJune 17, 2026 14:49
Centralizes the clerk./accounts./clkmail. subdomain derivations so they
can't drift independently across copy.ts and providers.ts.
@Railly
Railly merged commit ea8da27 into mainJun 17, 2026
10 checks passed
@Railly
Railly deleted the fix/deploy-oauth-redirect-fapi branch June 17, 2026 18:21
@github-actionsgithub-actionsBot mentioned this pull request Jun 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Railly@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough by Railly · Pull Request #335 · clerk/cli · GitHub
Skip to content

fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough - #335

Merged
Railly merged 4 commits into
mainfrom
fix/deploy-oauth-redirect-fapi
Jun 17, 2026
Merged

fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough#335
Railly merged 4 commits into
mainfrom
fix/deploy-oauth-redirect-fapi

Conversation

@Railly

@RaillyRailly commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Problem

The OAuth walkthrough in clerk deploy prints https://accounts.{domain}/v1/oauth_callback as the redirect URI. That endpoint lives on the Frontend API (clerk.{domain}), not the Account Portal, so pasting the printed value into a provider console causes redirect_uri_mismatch. Affects every provider walkthrough since #260.

Fix

PLAPI already returns the correct value as frontend_api_url on the domain object; it was being dropped. Thread it through deploy state (new-deploy and resume paths) into showOAuthWalkthrough, with a https://clerk.{domain} fallback since TS types do not validate runtime JSON.

Tests

  • New walkthrough test with a distinctive API-provided frontend_api_url proves the value is threaded, not string-built from the domain
  • Reconcile-path walkthrough test now asserts the FAPI URI and the absence of the accounts. one
  • bun test, typecheck, lint, format:check pass

@changeset-bot

changeset-botBot commented Jun 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5e62655

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

The OAuth walkthrough printed https://accounts.{domain}/v1/oauth_callback,
but /v1/oauth_callback is served by the Frontend API (clerk.{domain}), not
the Account Portal. Users pasting the printed value into their provider
console hit redirect_uri_mismatch.
Thread frontend_api_url from the PLAPI domain response through
DeployOperationState and LiveDeploySnapshot into showOAuthWalkthrough,
falling back to https://clerk.{domain} if absent.
@Railly
Raillyforce-pushed the fix/deploy-oauth-redirect-fapi branch from 61640b5 to 31baaf9CompareJune 12, 2026 23:52
@coderabbitai

coderabbitaiBot commented Jun 12, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: e65e23ab-e2a2-4d5b-919e-f2a4f7e68628

📥 Commits

Reviewing files that changed from the base of the PR and between 1df3c49 and 5e62655.

📒 Files selected for processing (2)
  • packages/cli-core/src/commands/deploy/copy.ts
  • packages/cli-core/src/commands/deploy/providers.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/cli-core/src/commands/deploy/providers.ts

📝 Walkthrough

Walkthrough

This PR updates the clerk deploy command's OAuth credential setup flow to use the Frontend API URL for OAuth redirect URIs instead of the Accounts Portal URL. The change threads frontendApiUrl from the production domain through the deploy operation state into the OAuth walkthrough renderer, where it constructs and displays the correct callback URI. A new clerkSubdomains helper extracts subdomain computation logic for reuse. Supporting updates include extending the DeployOperationState type, including the URL in the live deployment snapshot, refactoring test helpers to support dynamic Frontend API URL injection, and documenting the new behavior.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~14 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 23.08% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly describes the main change: using the Frontend API URL for OAuth redirect URI in the walkthrough, which matches the primary fix across all modified files.
Description check✅ PassedThe description is well-related to the changeset, explaining the problem, the solution, and the testing approach that matches the actual code changes.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@Railly
Raillyforce-pushed the fix/deploy-oauth-redirect-fapi branch from c1135f5 to 5eac92dCompareJune 12, 2026 23:55
@Railly
Railly requested review from rafa-thayto and wyattjoh and removed request for rafa-thaytoJune 16, 2026 17:46
Comment threadpackages/cli-core/src/commands/deploy/providers.ts Outdated
@wyattjoh

Copy link
Copy Markdown
Contributor

I was more sort of thinking these domain subdomains:

consthosts=[`clerk.${domain}`,`accounts.${domain}`,`clkmail.${domain}`];

That way other code can just reference it properly instead of hardcoding accounts. which can too easily drift.

@Railly
Railly requested a review from wyattjohJune 17, 2026 14:49
Centralizes the clerk./accounts./clkmail. subdomain derivations so they
can't drift independently across copy.ts and providers.ts.
@Railly
Railly merged commit ea8da27 into mainJun 17, 2026
10 checks passed
@Railly
Railly deleted the fix/deploy-oauth-redirect-fapi branch June 17, 2026 18:21
@github-actionsgithub-actionsBot mentioned this pull request Jun 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Railly@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough by Railly · Pull Request #335 · clerk/cli · GitHub
Skip to content

fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough - #335

Merged
Railly merged 4 commits into
mainfrom
fix/deploy-oauth-redirect-fapi
Jun 17, 2026
Merged

fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough#335
Railly merged 4 commits into
mainfrom
fix/deploy-oauth-redirect-fapi

Conversation

@Railly

@RaillyRailly commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Problem

The OAuth walkthrough in clerk deploy prints https://accounts.{domain}/v1/oauth_callback as the redirect URI. That endpoint lives on the Frontend API (clerk.{domain}), not the Account Portal, so pasting the printed value into a provider console causes redirect_uri_mismatch. Affects every provider walkthrough since #260.

Fix

PLAPI already returns the correct value as frontend_api_url on the domain object; it was being dropped. Thread it through deploy state (new-deploy and resume paths) into showOAuthWalkthrough, with a https://clerk.{domain} fallback since TS types do not validate runtime JSON.

Tests

  • New walkthrough test with a distinctive API-provided frontend_api_url proves the value is threaded, not string-built from the domain
  • Reconcile-path walkthrough test now asserts the FAPI URI and the absence of the accounts. one
  • bun test, typecheck, lint, format:check pass

@changeset-bot

changeset-botBot commented Jun 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5e62655

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

The OAuth walkthrough printed https://accounts.{domain}/v1/oauth_callback,
but /v1/oauth_callback is served by the Frontend API (clerk.{domain}), not
the Account Portal. Users pasting the printed value into their provider
console hit redirect_uri_mismatch.
Thread frontend_api_url from the PLAPI domain response through
DeployOperationState and LiveDeploySnapshot into showOAuthWalkthrough,
falling back to https://clerk.{domain} if absent.
@Railly
Raillyforce-pushed the fix/deploy-oauth-redirect-fapi branch from 61640b5 to 31baaf9CompareJune 12, 2026 23:52
@coderabbitai

coderabbitaiBot commented Jun 12, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: e65e23ab-e2a2-4d5b-919e-f2a4f7e68628

📥 Commits

Reviewing files that changed from the base of the PR and between 1df3c49 and 5e62655.

📒 Files selected for processing (2)
  • packages/cli-core/src/commands/deploy/copy.ts
  • packages/cli-core/src/commands/deploy/providers.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/cli-core/src/commands/deploy/providers.ts

📝 Walkthrough

Walkthrough

This PR updates the clerk deploy command's OAuth credential setup flow to use the Frontend API URL for OAuth redirect URIs instead of the Accounts Portal URL. The change threads frontendApiUrl from the production domain through the deploy operation state into the OAuth walkthrough renderer, where it constructs and displays the correct callback URI. A new clerkSubdomains helper extracts subdomain computation logic for reuse. Supporting updates include extending the DeployOperationState type, including the URL in the live deployment snapshot, refactoring test helpers to support dynamic Frontend API URL injection, and documenting the new behavior.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~14 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 23.08% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly describes the main change: using the Frontend API URL for OAuth redirect URI in the walkthrough, which matches the primary fix across all modified files.
Description check✅ PassedThe description is well-related to the changeset, explaining the problem, the solution, and the testing approach that matches the actual code changes.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@Railly
Raillyforce-pushed the fix/deploy-oauth-redirect-fapi branch from c1135f5 to 5eac92dCompareJune 12, 2026 23:55
@Railly
Railly requested review from rafa-thayto and wyattjoh and removed request for rafa-thaytoJune 16, 2026 17:46
Comment threadpackages/cli-core/src/commands/deploy/providers.ts Outdated
@wyattjoh

Copy link
Copy Markdown
Contributor

I was more sort of thinking these domain subdomains:

consthosts=[`clerk.${domain}`,`accounts.${domain}`,`clkmail.${domain}`];

That way other code can just reference it properly instead of hardcoding accounts. which can too easily drift.

@Railly
Railly requested a review from wyattjohJune 17, 2026 14:49
Centralizes the clerk./accounts./clkmail. subdomain derivations so they
can't drift independently across copy.ts and providers.ts.
@Railly
Railly merged commit ea8da27 into mainJun 17, 2026
10 checks passed
@Railly
Railly deleted the fix/deploy-oauth-redirect-fapi branch June 17, 2026 18:21
@github-actionsgithub-actionsBot mentioned this pull request Jun 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Railly@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough by Railly · Pull Request #335 · clerk/cli · GitHub
Skip to content

fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough - #335

Merged
Railly merged 4 commits into
mainfrom
fix/deploy-oauth-redirect-fapi
Jun 17, 2026
Merged

fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough#335
Railly merged 4 commits into
mainfrom
fix/deploy-oauth-redirect-fapi

Conversation

@Railly

@RaillyRailly commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Problem

The OAuth walkthrough in clerk deploy prints https://accounts.{domain}/v1/oauth_callback as the redirect URI. That endpoint lives on the Frontend API (clerk.{domain}), not the Account Portal, so pasting the printed value into a provider console causes redirect_uri_mismatch. Affects every provider walkthrough since #260.

Fix

PLAPI already returns the correct value as frontend_api_url on the domain object; it was being dropped. Thread it through deploy state (new-deploy and resume paths) into showOAuthWalkthrough, with a https://clerk.{domain} fallback since TS types do not validate runtime JSON.

Tests

  • New walkthrough test with a distinctive API-provided frontend_api_url proves the value is threaded, not string-built from the domain
  • Reconcile-path walkthrough test now asserts the FAPI URI and the absence of the accounts. one
  • bun test, typecheck, lint, format:check pass

@changeset-bot

changeset-botBot commented Jun 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5e62655

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

The OAuth walkthrough printed https://accounts.{domain}/v1/oauth_callback,
but /v1/oauth_callback is served by the Frontend API (clerk.{domain}), not
the Account Portal. Users pasting the printed value into their provider
console hit redirect_uri_mismatch.
Thread frontend_api_url from the PLAPI domain response through
DeployOperationState and LiveDeploySnapshot into showOAuthWalkthrough,
falling back to https://clerk.{domain} if absent.
@Railly
Raillyforce-pushed the fix/deploy-oauth-redirect-fapi branch from 61640b5 to 31baaf9CompareJune 12, 2026 23:52
@coderabbitai

coderabbitaiBot commented Jun 12, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: e65e23ab-e2a2-4d5b-919e-f2a4f7e68628

📥 Commits

Reviewing files that changed from the base of the PR and between 1df3c49 and 5e62655.

📒 Files selected for processing (2)
  • packages/cli-core/src/commands/deploy/copy.ts
  • packages/cli-core/src/commands/deploy/providers.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/cli-core/src/commands/deploy/providers.ts

📝 Walkthrough

Walkthrough

This PR updates the clerk deploy command's OAuth credential setup flow to use the Frontend API URL for OAuth redirect URIs instead of the Accounts Portal URL. The change threads frontendApiUrl from the production domain through the deploy operation state into the OAuth walkthrough renderer, where it constructs and displays the correct callback URI. A new clerkSubdomains helper extracts subdomain computation logic for reuse. Supporting updates include extending the DeployOperationState type, including the URL in the live deployment snapshot, refactoring test helpers to support dynamic Frontend API URL injection, and documenting the new behavior.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~14 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 23.08% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly describes the main change: using the Frontend API URL for OAuth redirect URI in the walkthrough, which matches the primary fix across all modified files.
Description check✅ PassedThe description is well-related to the changeset, explaining the problem, the solution, and the testing approach that matches the actual code changes.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@Railly
Raillyforce-pushed the fix/deploy-oauth-redirect-fapi branch from c1135f5 to 5eac92dCompareJune 12, 2026 23:55
@Railly
Railly requested review from rafa-thayto and wyattjoh and removed request for rafa-thaytoJune 16, 2026 17:46
Comment threadpackages/cli-core/src/commands/deploy/providers.ts Outdated
@wyattjoh

Copy link
Copy Markdown
Contributor

I was more sort of thinking these domain subdomains:

consthosts=[`clerk.${domain}`,`accounts.${domain}`,`clkmail.${domain}`];

That way other code can just reference it properly instead of hardcoding accounts. which can too easily drift.

@Railly
Railly requested a review from wyattjohJune 17, 2026 14:49
Centralizes the clerk./accounts./clkmail. subdomain derivations so they
can't drift independently across copy.ts and providers.ts.
@Railly
Railly merged commit ea8da27 into mainJun 17, 2026
10 checks passed
@Railly
Railly deleted the fix/deploy-oauth-redirect-fapi branch June 17, 2026 18:21
@github-actionsgithub-actionsBot mentioned this pull request Jun 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Railly@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough by Railly · Pull Request #335 · clerk/cli · GitHub
Skip to content

fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough - #335

Merged
Railly merged 4 commits into
mainfrom
fix/deploy-oauth-redirect-fapi
Jun 17, 2026
Merged

fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough#335
Railly merged 4 commits into
mainfrom
fix/deploy-oauth-redirect-fapi

Conversation

@Railly

@RaillyRailly commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Problem

The OAuth walkthrough in clerk deploy prints https://accounts.{domain}/v1/oauth_callback as the redirect URI. That endpoint lives on the Frontend API (clerk.{domain}), not the Account Portal, so pasting the printed value into a provider console causes redirect_uri_mismatch. Affects every provider walkthrough since #260.

Fix

PLAPI already returns the correct value as frontend_api_url on the domain object; it was being dropped. Thread it through deploy state (new-deploy and resume paths) into showOAuthWalkthrough, with a https://clerk.{domain} fallback since TS types do not validate runtime JSON.

Tests

  • New walkthrough test with a distinctive API-provided frontend_api_url proves the value is threaded, not string-built from the domain
  • Reconcile-path walkthrough test now asserts the FAPI URI and the absence of the accounts. one
  • bun test, typecheck, lint, format:check pass

@changeset-bot

changeset-botBot commented Jun 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5e62655

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

The OAuth walkthrough printed https://accounts.{domain}/v1/oauth_callback,
but /v1/oauth_callback is served by the Frontend API (clerk.{domain}), not
the Account Portal. Users pasting the printed value into their provider
console hit redirect_uri_mismatch.
Thread frontend_api_url from the PLAPI domain response through
DeployOperationState and LiveDeploySnapshot into showOAuthWalkthrough,
falling back to https://clerk.{domain} if absent.
@Railly
Raillyforce-pushed the fix/deploy-oauth-redirect-fapi branch from 61640b5 to 31baaf9CompareJune 12, 2026 23:52
@coderabbitai

coderabbitaiBot commented Jun 12, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: e65e23ab-e2a2-4d5b-919e-f2a4f7e68628

📥 Commits

Reviewing files that changed from the base of the PR and between 1df3c49 and 5e62655.

📒 Files selected for processing (2)
  • packages/cli-core/src/commands/deploy/copy.ts
  • packages/cli-core/src/commands/deploy/providers.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/cli-core/src/commands/deploy/providers.ts

📝 Walkthrough

Walkthrough

This PR updates the clerk deploy command's OAuth credential setup flow to use the Frontend API URL for OAuth redirect URIs instead of the Accounts Portal URL. The change threads frontendApiUrl from the production domain through the deploy operation state into the OAuth walkthrough renderer, where it constructs and displays the correct callback URI. A new clerkSubdomains helper extracts subdomain computation logic for reuse. Supporting updates include extending the DeployOperationState type, including the URL in the live deployment snapshot, refactoring test helpers to support dynamic Frontend API URL injection, and documenting the new behavior.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~14 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 23.08% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly describes the main change: using the Frontend API URL for OAuth redirect URI in the walkthrough, which matches the primary fix across all modified files.
Description check✅ PassedThe description is well-related to the changeset, explaining the problem, the solution, and the testing approach that matches the actual code changes.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@Railly
Raillyforce-pushed the fix/deploy-oauth-redirect-fapi branch from c1135f5 to 5eac92dCompareJune 12, 2026 23:55
@Railly
Railly requested review from rafa-thayto and wyattjoh and removed request for rafa-thaytoJune 16, 2026 17:46
Comment threadpackages/cli-core/src/commands/deploy/providers.ts Outdated
@wyattjoh

Copy link
Copy Markdown
Contributor

I was more sort of thinking these domain subdomains:

consthosts=[`clerk.${domain}`,`accounts.${domain}`,`clkmail.${domain}`];

That way other code can just reference it properly instead of hardcoding accounts. which can too easily drift.

@Railly
Railly requested a review from wyattjohJune 17, 2026 14:49
Centralizes the clerk./accounts./clkmail. subdomain derivations so they
can't drift independently across copy.ts and providers.ts.
@Railly
Railly merged commit ea8da27 into mainJun 17, 2026
10 checks passed
@Railly
Railly deleted the fix/deploy-oauth-redirect-fapi branch June 17, 2026 18:21
@github-actionsgithub-actionsBot mentioned this pull request Jun 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Railly@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough by Railly · Pull Request #335 · clerk/cli · GitHub
Skip to content

fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough - #335

Merged
Railly merged 4 commits into
mainfrom
fix/deploy-oauth-redirect-fapi
Jun 17, 2026
Merged

fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough#335
Railly merged 4 commits into
mainfrom
fix/deploy-oauth-redirect-fapi

Conversation

@Railly

@RaillyRailly commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Problem

The OAuth walkthrough in clerk deploy prints https://accounts.{domain}/v1/oauth_callback as the redirect URI. That endpoint lives on the Frontend API (clerk.{domain}), not the Account Portal, so pasting the printed value into a provider console causes redirect_uri_mismatch. Affects every provider walkthrough since #260.

Fix

PLAPI already returns the correct value as frontend_api_url on the domain object; it was being dropped. Thread it through deploy state (new-deploy and resume paths) into showOAuthWalkthrough, with a https://clerk.{domain} fallback since TS types do not validate runtime JSON.

Tests

  • New walkthrough test with a distinctive API-provided frontend_api_url proves the value is threaded, not string-built from the domain
  • Reconcile-path walkthrough test now asserts the FAPI URI and the absence of the accounts. one
  • bun test, typecheck, lint, format:check pass

@changeset-bot

changeset-botBot commented Jun 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5e62655

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

The OAuth walkthrough printed https://accounts.{domain}/v1/oauth_callback,
but /v1/oauth_callback is served by the Frontend API (clerk.{domain}), not
the Account Portal. Users pasting the printed value into their provider
console hit redirect_uri_mismatch.
Thread frontend_api_url from the PLAPI domain response through
DeployOperationState and LiveDeploySnapshot into showOAuthWalkthrough,
falling back to https://clerk.{domain} if absent.
@Railly
Raillyforce-pushed the fix/deploy-oauth-redirect-fapi branch from 61640b5 to 31baaf9CompareJune 12, 2026 23:52
@coderabbitai

coderabbitaiBot commented Jun 12, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: e65e23ab-e2a2-4d5b-919e-f2a4f7e68628

📥 Commits

Reviewing files that changed from the base of the PR and between 1df3c49 and 5e62655.

📒 Files selected for processing (2)
  • packages/cli-core/src/commands/deploy/copy.ts
  • packages/cli-core/src/commands/deploy/providers.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/cli-core/src/commands/deploy/providers.ts

📝 Walkthrough

Walkthrough

This PR updates the clerk deploy command's OAuth credential setup flow to use the Frontend API URL for OAuth redirect URIs instead of the Accounts Portal URL. The change threads frontendApiUrl from the production domain through the deploy operation state into the OAuth walkthrough renderer, where it constructs and displays the correct callback URI. A new clerkSubdomains helper extracts subdomain computation logic for reuse. Supporting updates include extending the DeployOperationState type, including the URL in the live deployment snapshot, refactoring test helpers to support dynamic Frontend API URL injection, and documenting the new behavior.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~14 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 23.08% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly describes the main change: using the Frontend API URL for OAuth redirect URI in the walkthrough, which matches the primary fix across all modified files.
Description check✅ PassedThe description is well-related to the changeset, explaining the problem, the solution, and the testing approach that matches the actual code changes.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@Railly
Raillyforce-pushed the fix/deploy-oauth-redirect-fapi branch from c1135f5 to 5eac92dCompareJune 12, 2026 23:55
@Railly
Railly requested review from rafa-thayto and wyattjoh and removed request for rafa-thaytoJune 16, 2026 17:46
Comment threadpackages/cli-core/src/commands/deploy/providers.ts Outdated
@wyattjoh

Copy link
Copy Markdown
Contributor

I was more sort of thinking these domain subdomains:

consthosts=[`clerk.${domain}`,`accounts.${domain}`,`clkmail.${domain}`];

That way other code can just reference it properly instead of hardcoding accounts. which can too easily drift.

@Railly
Railly requested a review from wyattjohJune 17, 2026 14:49
Centralizes the clerk./accounts./clkmail. subdomain derivations so they
can't drift independently across copy.ts and providers.ts.
@Railly
Railly merged commit ea8da27 into mainJun 17, 2026
10 checks passed
@Railly
Railly deleted the fix/deploy-oauth-redirect-fapi branch June 17, 2026 18:21
@github-actionsgithub-actionsBot mentioned this pull request Jun 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Railly@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough by Railly · Pull Request #335 · clerk/cli · GitHub
Skip to content

fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough - #335

Merged
Railly merged 4 commits into
mainfrom
fix/deploy-oauth-redirect-fapi
Jun 17, 2026
Merged

fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough#335
Railly merged 4 commits into
mainfrom
fix/deploy-oauth-redirect-fapi

Conversation

@Railly

@RaillyRailly commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Problem

The OAuth walkthrough in clerk deploy prints https://accounts.{domain}/v1/oauth_callback as the redirect URI. That endpoint lives on the Frontend API (clerk.{domain}), not the Account Portal, so pasting the printed value into a provider console causes redirect_uri_mismatch. Affects every provider walkthrough since #260.

Fix

PLAPI already returns the correct value as frontend_api_url on the domain object; it was being dropped. Thread it through deploy state (new-deploy and resume paths) into showOAuthWalkthrough, with a https://clerk.{domain} fallback since TS types do not validate runtime JSON.

Tests

  • New walkthrough test with a distinctive API-provided frontend_api_url proves the value is threaded, not string-built from the domain
  • Reconcile-path walkthrough test now asserts the FAPI URI and the absence of the accounts. one
  • bun test, typecheck, lint, format:check pass

@changeset-bot

changeset-botBot commented Jun 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5e62655

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

The OAuth walkthrough printed https://accounts.{domain}/v1/oauth_callback,
but /v1/oauth_callback is served by the Frontend API (clerk.{domain}), not
the Account Portal. Users pasting the printed value into their provider
console hit redirect_uri_mismatch.
Thread frontend_api_url from the PLAPI domain response through
DeployOperationState and LiveDeploySnapshot into showOAuthWalkthrough,
falling back to https://clerk.{domain} if absent.
@Railly
Raillyforce-pushed the fix/deploy-oauth-redirect-fapi branch from 61640b5 to 31baaf9CompareJune 12, 2026 23:52
@coderabbitai

coderabbitaiBot commented Jun 12, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: e65e23ab-e2a2-4d5b-919e-f2a4f7e68628

📥 Commits

Reviewing files that changed from the base of the PR and between 1df3c49 and 5e62655.

📒 Files selected for processing (2)
  • packages/cli-core/src/commands/deploy/copy.ts
  • packages/cli-core/src/commands/deploy/providers.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/cli-core/src/commands/deploy/providers.ts

📝 Walkthrough

Walkthrough

This PR updates the clerk deploy command's OAuth credential setup flow to use the Frontend API URL for OAuth redirect URIs instead of the Accounts Portal URL. The change threads frontendApiUrl from the production domain through the deploy operation state into the OAuth walkthrough renderer, where it constructs and displays the correct callback URI. A new clerkSubdomains helper extracts subdomain computation logic for reuse. Supporting updates include extending the DeployOperationState type, including the URL in the live deployment snapshot, refactoring test helpers to support dynamic Frontend API URL injection, and documenting the new behavior.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~14 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 23.08% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly describes the main change: using the Frontend API URL for OAuth redirect URI in the walkthrough, which matches the primary fix across all modified files.
Description check✅ PassedThe description is well-related to the changeset, explaining the problem, the solution, and the testing approach that matches the actual code changes.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@Railly
Raillyforce-pushed the fix/deploy-oauth-redirect-fapi branch from c1135f5 to 5eac92dCompareJune 12, 2026 23:55
@Railly
Railly requested review from rafa-thayto and wyattjoh and removed request for rafa-thaytoJune 16, 2026 17:46
Comment threadpackages/cli-core/src/commands/deploy/providers.ts Outdated
@wyattjoh

Copy link
Copy Markdown
Contributor

I was more sort of thinking these domain subdomains:

consthosts=[`clerk.${domain}`,`accounts.${domain}`,`clkmail.${domain}`];

That way other code can just reference it properly instead of hardcoding accounts. which can too easily drift.

@Railly
Railly requested a review from wyattjohJune 17, 2026 14:49
Centralizes the clerk./accounts./clkmail. subdomain derivations so they
can't drift independently across copy.ts and providers.ts.
@Railly
Railly merged commit ea8da27 into mainJun 17, 2026
10 checks passed
@Railly
Railly deleted the fix/deploy-oauth-redirect-fapi branch June 17, 2026 18:21
@github-actionsgithub-actionsBot mentioned this pull request Jun 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Railly@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough by Railly · Pull Request #335 · clerk/cli · GitHub
Skip to content

fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough - #335

Merged
Railly merged 4 commits into
mainfrom
fix/deploy-oauth-redirect-fapi
Jun 17, 2026
Merged

fix(deploy): use Frontend API URL for OAuth redirect URI in walkthrough#335
Railly merged 4 commits into
mainfrom
fix/deploy-oauth-redirect-fapi

Conversation

@Railly

@RaillyRailly commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Problem

The OAuth walkthrough in clerk deploy prints https://accounts.{domain}/v1/oauth_callback as the redirect URI. That endpoint lives on the Frontend API (clerk.{domain}), not the Account Portal, so pasting the printed value into a provider console causes redirect_uri_mismatch. Affects every provider walkthrough since #260.

Fix

PLAPI already returns the correct value as frontend_api_url on the domain object; it was being dropped. Thread it through deploy state (new-deploy and resume paths) into showOAuthWalkthrough, with a https://clerk.{domain} fallback since TS types do not validate runtime JSON.

Tests

  • New walkthrough test with a distinctive API-provided frontend_api_url proves the value is threaded, not string-built from the domain
  • Reconcile-path walkthrough test now asserts the FAPI URI and the absence of the accounts. one
  • bun test, typecheck, lint, format:check pass

@changeset-bot

changeset-botBot commented Jun 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5e62655

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

The OAuth walkthrough printed https://accounts.{domain}/v1/oauth_callback,
but /v1/oauth_callback is served by the Frontend API (clerk.{domain}), not
the Account Portal. Users pasting the printed value into their provider
console hit redirect_uri_mismatch.
Thread frontend_api_url from the PLAPI domain response through
DeployOperationState and LiveDeploySnapshot into showOAuthWalkthrough,
falling back to https://clerk.{domain} if absent.
@Railly
Raillyforce-pushed the fix/deploy-oauth-redirect-fapi branch from 61640b5 to 31baaf9CompareJune 12, 2026 23:52
@coderabbitai

coderabbitaiBot commented Jun 12, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: e65e23ab-e2a2-4d5b-919e-f2a4f7e68628

📥 Commits

Reviewing files that changed from the base of the PR and between 1df3c49 and 5e62655.

📒 Files selected for processing (2)
  • packages/cli-core/src/commands/deploy/copy.ts
  • packages/cli-core/src/commands/deploy/providers.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/cli-core/src/commands/deploy/providers.ts

📝 Walkthrough

Walkthrough

This PR updates the clerk deploy command's OAuth credential setup flow to use the Frontend API URL for OAuth redirect URIs instead of the Accounts Portal URL. The change threads frontendApiUrl from the production domain through the deploy operation state into the OAuth walkthrough renderer, where it constructs and displays the correct callback URI. A new clerkSubdomains helper extracts subdomain computation logic for reuse. Supporting updates include extending the DeployOperationState type, including the URL in the live deployment snapshot, refactoring test helpers to support dynamic Frontend API URL injection, and documenting the new behavior.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~14 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 23.08% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly describes the main change: using the Frontend API URL for OAuth redirect URI in the walkthrough, which matches the primary fix across all modified files.
Description check✅ PassedThe description is well-related to the changeset, explaining the problem, the solution, and the testing approach that matches the actual code changes.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@Railly
Raillyforce-pushed the fix/deploy-oauth-redirect-fapi branch from c1135f5 to 5eac92dCompareJune 12, 2026 23:55
@Railly
Railly requested review from rafa-thayto and wyattjoh and removed request for rafa-thaytoJune 16, 2026 17:46
Comment threadpackages/cli-core/src/commands/deploy/providers.ts Outdated
@wyattjoh

Copy link
Copy Markdown
Contributor

I was more sort of thinking these domain subdomains:

consthosts=[`clerk.${domain}`,`accounts.${domain}`,`clkmail.${domain}`];

That way other code can just reference it properly instead of hardcoding accounts. which can too easily drift.

@Railly
Railly requested a review from wyattjohJune 17, 2026 14:49
Centralizes the clerk./accounts./clkmail. subdomain derivations so they
can't drift independently across copy.ts and providers.ts.
@Railly
Railly merged commit ea8da27 into mainJun 17, 2026
10 checks passed
@Railly
Railly deleted the fix/deploy-oauth-redirect-fapi branch June 17, 2026 18:21
@github-actionsgithub-actionsBot mentioned this pull request Jun 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Railly@wyattjoh