fix(init): scaffold bare clerkMiddleware instead of deprecated createRouteMatcher - #387

Merged
rafa-thayto merged 1 commit into
mainfrom
rafa-thayto/init-remove-create-route-matcher
Jul 21, 2026
Merged

fix(init): scaffold bare clerkMiddleware instead of deprecated createRouteMatcher#387
rafa-thayto merged 1 commit into
mainfrom
rafa-thayto/init-remove-create-route-matcher

Conversation

@rafa-thayto

@rafa-thaytorafa-thayto commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Summary

clerk init was scaffolding Next.js middleware with createRouteMatcher-based route protection, which Clerk has deprecated in favor of protecting each server-side resource individually with await auth.protect().

  • clerk init for Next.js (App Router and Pages Router) now generates bare export default clerkMiddleware() with the standard config matcher — no isPublicRoute / createRouteMatcher / auth.protect() block
  • i18n composition (next-intl et al.) and existing-middleware composition still wrap the user's middleware inside clerkMiddleware(); they just no longer inject the route matcher
  • The keyless "permissive middleware" variant collapsed into the default (both are now identical), so the ctx.keyless scaffold plumbing was removed
  • New post-init instruction tells users routes are public by default and how to protect resources (auth.protect() for App Router, getAuth() for Pages Router)
  • clerk webhooks listen 401 diagnostic no longer recommends createRouteMatcher(['/api/webhooks(.*)']); it now says to remove auth.protect() for the webhook route
  • Changeset included (clerk: patch)

Test plan

  • bun run format / lint / typecheck pass
  • Full unit/integration suite: 1903 pass, 0 fail
  • Ran real clerk init --keyless -y against 8 sandboxed projects: fresh App Router (next 15 → middleware.ts), Next 16 (→ proxy.ts), Pages Router, fresh next-intl project, existing next-intl expression middleware with own config, user-composed i18n function middleware, i18n middleware with taken varName, and existing plain custom middleware — zero createRouteMatcher occurrences in any generated file, compositions correct
  • Generated bare and i18n-composed middleware typecheck against the real published @clerk/nextjs
  • Idempotency: re-running init on a scaffolded project reports "No files to scaffold" and leaves middleware unchanged

…RouteMatcher
Clerk deprecated middleware-level route protection via createRouteMatcher
in favor of protecting each server-side resource individually with
`await auth.protect()`. `clerk init` for Next.js now generates
`export default clerkMiddleware()` (i18n and existing-middleware
compositions keep wrapping, minus the route matcher), prints a
post-init instruction pointing to resource-level protection, and the
`webhooks listen` 401 hint no longer recommends createRouteMatcher.
Removes the now-collapsed keyless middleware variant plumbing.
https://clerk.com/docs/guides/development/upgrading/upgrade-guides/migrate-from-create-route-matcher
@changeset-bot

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4465797

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 322b8793-1778-4bb2-aea9-5dcfe0f2ec52

📥 Commits

Reviewing files that changed from the base of the PR and between 19c0b58 and 4465797.

📒 Files selected for processing (12)
  • .changeset/init-remove-create-route-matcher.md
  • packages/cli-core/src/commands/init/README.md
  • packages/cli-core/src/commands/init/frameworks/helpers.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-app.test.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-app.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-pages.test.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-pages.ts
  • packages/cli-core/src/commands/init/frameworks/types.ts
  • packages/cli-core/src/commands/init/index.test.ts
  • packages/cli-core/src/commands/init/index.ts
  • packages/cli-core/src/commands/webhooks/render.test.ts
  • packages/cli-core/src/commands/webhooks/render.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
💤 Files with no reviewable changes (2)
  • packages/cli-core/src/commands/init/index.ts
  • packages/cli-core/src/commands/init/frameworks/types.ts

📝 Walkthrough

Walkthrough

Next.js initialization now generates bare clerkMiddleware() without createRouteMatcher route protection. App Router and Pages Router scaffolds add instructions to protect pages, API routes, route handlers, and server actions individually with auth.protect() or getAuth(). Middleware context and composition APIs were updated accordingly, tests and documentation reflect the new output, and webhook diagnostics now reference resource-level protection.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: scaffolding bare clerkMiddleware instead of deprecated createRouteMatcher logic.
Description check✅ PassedThe description is directly about the Next.js init scaffolding, middleware composition, guidance, and webhook diagnostic changes.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

@rafa-thayto
rafa-thayto merged commit c2577ab into mainJul 21, 2026
10 checks passed
@rafa-thayto
rafa-thayto deleted the rafa-thayto/init-remove-create-route-matcher branch July 21, 2026 20:20
@github-actionsgithub-actionsBot mentioned this pull request Jul 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@rafa-thayto@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(init): scaffold bare clerkMiddleware instead of deprecated createRouteMatcher - #387

Merged
rafa-thayto merged 1 commit into
mainfrom
rafa-thayto/init-remove-create-route-matcher
Jul 21, 2026
Merged

fix(init): scaffold bare clerkMiddleware instead of deprecated createRouteMatcher#387
rafa-thayto merged 1 commit into
mainfrom
rafa-thayto/init-remove-create-route-matcher

Conversation

@rafa-thayto

@rafa-thaytorafa-thayto commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Summary

clerk init was scaffolding Next.js middleware with createRouteMatcher-based route protection, which Clerk has deprecated in favor of protecting each server-side resource individually with await auth.protect().

  • clerk init for Next.js (App Router and Pages Router) now generates bare export default clerkMiddleware() with the standard config matcher — no isPublicRoute / createRouteMatcher / auth.protect() block
  • i18n composition (next-intl et al.) and existing-middleware composition still wrap the user's middleware inside clerkMiddleware(); they just no longer inject the route matcher
  • The keyless "permissive middleware" variant collapsed into the default (both are now identical), so the ctx.keyless scaffold plumbing was removed
  • New post-init instruction tells users routes are public by default and how to protect resources (auth.protect() for App Router, getAuth() for Pages Router)
  • clerk webhooks listen 401 diagnostic no longer recommends createRouteMatcher(['/api/webhooks(.*)']); it now says to remove auth.protect() for the webhook route
  • Changeset included (clerk: patch)

Test plan

  • bun run format / lint / typecheck pass
  • Full unit/integration suite: 1903 pass, 0 fail
  • Ran real clerk init --keyless -y against 8 sandboxed projects: fresh App Router (next 15 → middleware.ts), Next 16 (→ proxy.ts), Pages Router, fresh next-intl project, existing next-intl expression middleware with own config, user-composed i18n function middleware, i18n middleware with taken varName, and existing plain custom middleware — zero createRouteMatcher occurrences in any generated file, compositions correct
  • Generated bare and i18n-composed middleware typecheck against the real published @clerk/nextjs
  • Idempotency: re-running init on a scaffolded project reports "No files to scaffold" and leaves middleware unchanged

…RouteMatcher
Clerk deprecated middleware-level route protection via createRouteMatcher
in favor of protecting each server-side resource individually with
`await auth.protect()`. `clerk init` for Next.js now generates
`export default clerkMiddleware()` (i18n and existing-middleware
compositions keep wrapping, minus the route matcher), prints a
post-init instruction pointing to resource-level protection, and the
`webhooks listen` 401 hint no longer recommends createRouteMatcher.
Removes the now-collapsed keyless middleware variant plumbing.
https://clerk.com/docs/guides/development/upgrading/upgrade-guides/migrate-from-create-route-matcher
@changeset-bot

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4465797

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 322b8793-1778-4bb2-aea9-5dcfe0f2ec52

📥 Commits

Reviewing files that changed from the base of the PR and between 19c0b58 and 4465797.

📒 Files selected for processing (12)
  • .changeset/init-remove-create-route-matcher.md
  • packages/cli-core/src/commands/init/README.md
  • packages/cli-core/src/commands/init/frameworks/helpers.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-app.test.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-app.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-pages.test.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-pages.ts
  • packages/cli-core/src/commands/init/frameworks/types.ts
  • packages/cli-core/src/commands/init/index.test.ts
  • packages/cli-core/src/commands/init/index.ts
  • packages/cli-core/src/commands/webhooks/render.test.ts
  • packages/cli-core/src/commands/webhooks/render.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
💤 Files with no reviewable changes (2)
  • packages/cli-core/src/commands/init/index.ts
  • packages/cli-core/src/commands/init/frameworks/types.ts

📝 Walkthrough

Walkthrough

Next.js initialization now generates bare clerkMiddleware() without createRouteMatcher route protection. App Router and Pages Router scaffolds add instructions to protect pages, API routes, route handlers, and server actions individually with auth.protect() or getAuth(). Middleware context and composition APIs were updated accordingly, tests and documentation reflect the new output, and webhook diagnostics now reference resource-level protection.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: scaffolding bare clerkMiddleware instead of deprecated createRouteMatcher logic.
Description check✅ PassedThe description is directly about the Next.js init scaffolding, middleware composition, guidance, and webhook diagnostic changes.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

@rafa-thayto
rafa-thayto merged commit c2577ab into mainJul 21, 2026
10 checks passed
@rafa-thayto
rafa-thayto deleted the rafa-thayto/init-remove-create-route-matcher branch July 21, 2026 20:20
@github-actionsgithub-actionsBot mentioned this pull request Jul 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@rafa-thayto@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(init): scaffold bare clerkMiddleware instead of deprecated createRouteMatcher - #387

Merged
rafa-thayto merged 1 commit into
mainfrom
rafa-thayto/init-remove-create-route-matcher
Jul 21, 2026
Merged

fix(init): scaffold bare clerkMiddleware instead of deprecated createRouteMatcher#387
rafa-thayto merged 1 commit into
mainfrom
rafa-thayto/init-remove-create-route-matcher

Conversation

@rafa-thayto

@rafa-thaytorafa-thayto commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Summary

clerk init was scaffolding Next.js middleware with createRouteMatcher-based route protection, which Clerk has deprecated in favor of protecting each server-side resource individually with await auth.protect().

  • clerk init for Next.js (App Router and Pages Router) now generates bare export default clerkMiddleware() with the standard config matcher — no isPublicRoute / createRouteMatcher / auth.protect() block
  • i18n composition (next-intl et al.) and existing-middleware composition still wrap the user's middleware inside clerkMiddleware(); they just no longer inject the route matcher
  • The keyless "permissive middleware" variant collapsed into the default (both are now identical), so the ctx.keyless scaffold plumbing was removed
  • New post-init instruction tells users routes are public by default and how to protect resources (auth.protect() for App Router, getAuth() for Pages Router)
  • clerk webhooks listen 401 diagnostic no longer recommends createRouteMatcher(['/api/webhooks(.*)']); it now says to remove auth.protect() for the webhook route
  • Changeset included (clerk: patch)

Test plan

  • bun run format / lint / typecheck pass
  • Full unit/integration suite: 1903 pass, 0 fail
  • Ran real clerk init --keyless -y against 8 sandboxed projects: fresh App Router (next 15 → middleware.ts), Next 16 (→ proxy.ts), Pages Router, fresh next-intl project, existing next-intl expression middleware with own config, user-composed i18n function middleware, i18n middleware with taken varName, and existing plain custom middleware — zero createRouteMatcher occurrences in any generated file, compositions correct
  • Generated bare and i18n-composed middleware typecheck against the real published @clerk/nextjs
  • Idempotency: re-running init on a scaffolded project reports "No files to scaffold" and leaves middleware unchanged

…RouteMatcher
Clerk deprecated middleware-level route protection via createRouteMatcher
in favor of protecting each server-side resource individually with
`await auth.protect()`. `clerk init` for Next.js now generates
`export default clerkMiddleware()` (i18n and existing-middleware
compositions keep wrapping, minus the route matcher), prints a
post-init instruction pointing to resource-level protection, and the
`webhooks listen` 401 hint no longer recommends createRouteMatcher.
Removes the now-collapsed keyless middleware variant plumbing.
https://clerk.com/docs/guides/development/upgrading/upgrade-guides/migrate-from-create-route-matcher
@changeset-bot

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4465797

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 322b8793-1778-4bb2-aea9-5dcfe0f2ec52

📥 Commits

Reviewing files that changed from the base of the PR and between 19c0b58 and 4465797.

📒 Files selected for processing (12)
  • .changeset/init-remove-create-route-matcher.md
  • packages/cli-core/src/commands/init/README.md
  • packages/cli-core/src/commands/init/frameworks/helpers.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-app.test.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-app.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-pages.test.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-pages.ts
  • packages/cli-core/src/commands/init/frameworks/types.ts
  • packages/cli-core/src/commands/init/index.test.ts
  • packages/cli-core/src/commands/init/index.ts
  • packages/cli-core/src/commands/webhooks/render.test.ts
  • packages/cli-core/src/commands/webhooks/render.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
💤 Files with no reviewable changes (2)
  • packages/cli-core/src/commands/init/index.ts
  • packages/cli-core/src/commands/init/frameworks/types.ts

📝 Walkthrough

Walkthrough

Next.js initialization now generates bare clerkMiddleware() without createRouteMatcher route protection. App Router and Pages Router scaffolds add instructions to protect pages, API routes, route handlers, and server actions individually with auth.protect() or getAuth(). Middleware context and composition APIs were updated accordingly, tests and documentation reflect the new output, and webhook diagnostics now reference resource-level protection.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: scaffolding bare clerkMiddleware instead of deprecated createRouteMatcher logic.
Description check✅ PassedThe description is directly about the Next.js init scaffolding, middleware composition, guidance, and webhook diagnostic changes.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

@rafa-thayto
rafa-thayto merged commit c2577ab into mainJul 21, 2026
10 checks passed
@rafa-thayto
rafa-thayto deleted the rafa-thayto/init-remove-create-route-matcher branch July 21, 2026 20:20
@github-actionsgithub-actionsBot mentioned this pull request Jul 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@rafa-thayto@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(init): scaffold bare clerkMiddleware instead of deprecated createRouteMatcher - #387

Merged
rafa-thayto merged 1 commit into
mainfrom
rafa-thayto/init-remove-create-route-matcher
Jul 21, 2026
Merged

fix(init): scaffold bare clerkMiddleware instead of deprecated createRouteMatcher#387
rafa-thayto merged 1 commit into
mainfrom
rafa-thayto/init-remove-create-route-matcher

Conversation

@rafa-thayto

@rafa-thaytorafa-thayto commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Summary

clerk init was scaffolding Next.js middleware with createRouteMatcher-based route protection, which Clerk has deprecated in favor of protecting each server-side resource individually with await auth.protect().

  • clerk init for Next.js (App Router and Pages Router) now generates bare export default clerkMiddleware() with the standard config matcher — no isPublicRoute / createRouteMatcher / auth.protect() block
  • i18n composition (next-intl et al.) and existing-middleware composition still wrap the user's middleware inside clerkMiddleware(); they just no longer inject the route matcher
  • The keyless "permissive middleware" variant collapsed into the default (both are now identical), so the ctx.keyless scaffold plumbing was removed
  • New post-init instruction tells users routes are public by default and how to protect resources (auth.protect() for App Router, getAuth() for Pages Router)
  • clerk webhooks listen 401 diagnostic no longer recommends createRouteMatcher(['/api/webhooks(.*)']); it now says to remove auth.protect() for the webhook route
  • Changeset included (clerk: patch)

Test plan

  • bun run format / lint / typecheck pass
  • Full unit/integration suite: 1903 pass, 0 fail
  • Ran real clerk init --keyless -y against 8 sandboxed projects: fresh App Router (next 15 → middleware.ts), Next 16 (→ proxy.ts), Pages Router, fresh next-intl project, existing next-intl expression middleware with own config, user-composed i18n function middleware, i18n middleware with taken varName, and existing plain custom middleware — zero createRouteMatcher occurrences in any generated file, compositions correct
  • Generated bare and i18n-composed middleware typecheck against the real published @clerk/nextjs
  • Idempotency: re-running init on a scaffolded project reports "No files to scaffold" and leaves middleware unchanged

…RouteMatcher
Clerk deprecated middleware-level route protection via createRouteMatcher
in favor of protecting each server-side resource individually with
`await auth.protect()`. `clerk init` for Next.js now generates
`export default clerkMiddleware()` (i18n and existing-middleware
compositions keep wrapping, minus the route matcher), prints a
post-init instruction pointing to resource-level protection, and the
`webhooks listen` 401 hint no longer recommends createRouteMatcher.
Removes the now-collapsed keyless middleware variant plumbing.
https://clerk.com/docs/guides/development/upgrading/upgrade-guides/migrate-from-create-route-matcher
@changeset-bot

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4465797

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 322b8793-1778-4bb2-aea9-5dcfe0f2ec52

📥 Commits

Reviewing files that changed from the base of the PR and between 19c0b58 and 4465797.

📒 Files selected for processing (12)
  • .changeset/init-remove-create-route-matcher.md
  • packages/cli-core/src/commands/init/README.md
  • packages/cli-core/src/commands/init/frameworks/helpers.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-app.test.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-app.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-pages.test.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-pages.ts
  • packages/cli-core/src/commands/init/frameworks/types.ts
  • packages/cli-core/src/commands/init/index.test.ts
  • packages/cli-core/src/commands/init/index.ts
  • packages/cli-core/src/commands/webhooks/render.test.ts
  • packages/cli-core/src/commands/webhooks/render.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
💤 Files with no reviewable changes (2)
  • packages/cli-core/src/commands/init/index.ts
  • packages/cli-core/src/commands/init/frameworks/types.ts

📝 Walkthrough

Walkthrough

Next.js initialization now generates bare clerkMiddleware() without createRouteMatcher route protection. App Router and Pages Router scaffolds add instructions to protect pages, API routes, route handlers, and server actions individually with auth.protect() or getAuth(). Middleware context and composition APIs were updated accordingly, tests and documentation reflect the new output, and webhook diagnostics now reference resource-level protection.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: scaffolding bare clerkMiddleware instead of deprecated createRouteMatcher logic.
Description check✅ PassedThe description is directly about the Next.js init scaffolding, middleware composition, guidance, and webhook diagnostic changes.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

@rafa-thayto
rafa-thayto merged commit c2577ab into mainJul 21, 2026
10 checks passed
@rafa-thayto
rafa-thayto deleted the rafa-thayto/init-remove-create-route-matcher branch July 21, 2026 20:20
@github-actionsgithub-actionsBot mentioned this pull request Jul 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@rafa-thayto@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(init): scaffold bare clerkMiddleware instead of deprecated createRouteMatcher - #387

Merged
rafa-thayto merged 1 commit into
mainfrom
rafa-thayto/init-remove-create-route-matcher
Jul 21, 2026
Merged

fix(init): scaffold bare clerkMiddleware instead of deprecated createRouteMatcher#387
rafa-thayto merged 1 commit into
mainfrom
rafa-thayto/init-remove-create-route-matcher

Conversation

@rafa-thayto

@rafa-thaytorafa-thayto commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Summary

clerk init was scaffolding Next.js middleware with createRouteMatcher-based route protection, which Clerk has deprecated in favor of protecting each server-side resource individually with await auth.protect().

  • clerk init for Next.js (App Router and Pages Router) now generates bare export default clerkMiddleware() with the standard config matcher — no isPublicRoute / createRouteMatcher / auth.protect() block
  • i18n composition (next-intl et al.) and existing-middleware composition still wrap the user's middleware inside clerkMiddleware(); they just no longer inject the route matcher
  • The keyless "permissive middleware" variant collapsed into the default (both are now identical), so the ctx.keyless scaffold plumbing was removed
  • New post-init instruction tells users routes are public by default and how to protect resources (auth.protect() for App Router, getAuth() for Pages Router)
  • clerk webhooks listen 401 diagnostic no longer recommends createRouteMatcher(['/api/webhooks(.*)']); it now says to remove auth.protect() for the webhook route
  • Changeset included (clerk: patch)

Test plan

  • bun run format / lint / typecheck pass
  • Full unit/integration suite: 1903 pass, 0 fail
  • Ran real clerk init --keyless -y against 8 sandboxed projects: fresh App Router (next 15 → middleware.ts), Next 16 (→ proxy.ts), Pages Router, fresh next-intl project, existing next-intl expression middleware with own config, user-composed i18n function middleware, i18n middleware with taken varName, and existing plain custom middleware — zero createRouteMatcher occurrences in any generated file, compositions correct
  • Generated bare and i18n-composed middleware typecheck against the real published @clerk/nextjs
  • Idempotency: re-running init on a scaffolded project reports "No files to scaffold" and leaves middleware unchanged

…RouteMatcher
Clerk deprecated middleware-level route protection via createRouteMatcher
in favor of protecting each server-side resource individually with
`await auth.protect()`. `clerk init` for Next.js now generates
`export default clerkMiddleware()` (i18n and existing-middleware
compositions keep wrapping, minus the route matcher), prints a
post-init instruction pointing to resource-level protection, and the
`webhooks listen` 401 hint no longer recommends createRouteMatcher.
Removes the now-collapsed keyless middleware variant plumbing.
https://clerk.com/docs/guides/development/upgrading/upgrade-guides/migrate-from-create-route-matcher
@changeset-bot

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4465797

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 322b8793-1778-4bb2-aea9-5dcfe0f2ec52

📥 Commits

Reviewing files that changed from the base of the PR and between 19c0b58 and 4465797.

📒 Files selected for processing (12)
  • .changeset/init-remove-create-route-matcher.md
  • packages/cli-core/src/commands/init/README.md
  • packages/cli-core/src/commands/init/frameworks/helpers.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-app.test.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-app.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-pages.test.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-pages.ts
  • packages/cli-core/src/commands/init/frameworks/types.ts
  • packages/cli-core/src/commands/init/index.test.ts
  • packages/cli-core/src/commands/init/index.ts
  • packages/cli-core/src/commands/webhooks/render.test.ts
  • packages/cli-core/src/commands/webhooks/render.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
💤 Files with no reviewable changes (2)
  • packages/cli-core/src/commands/init/index.ts
  • packages/cli-core/src/commands/init/frameworks/types.ts

📝 Walkthrough

Walkthrough

Next.js initialization now generates bare clerkMiddleware() without createRouteMatcher route protection. App Router and Pages Router scaffolds add instructions to protect pages, API routes, route handlers, and server actions individually with auth.protect() or getAuth(). Middleware context and composition APIs were updated accordingly, tests and documentation reflect the new output, and webhook diagnostics now reference resource-level protection.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: scaffolding bare clerkMiddleware instead of deprecated createRouteMatcher logic.
Description check✅ PassedThe description is directly about the Next.js init scaffolding, middleware composition, guidance, and webhook diagnostic changes.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

@rafa-thayto
rafa-thayto merged commit c2577ab into mainJul 21, 2026
10 checks passed
@rafa-thayto
rafa-thayto deleted the rafa-thayto/init-remove-create-route-matcher branch July 21, 2026 20:20
@github-actionsgithub-actionsBot mentioned this pull request Jul 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@rafa-thayto@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(init): scaffold bare clerkMiddleware instead of deprecated createRouteMatcher - #387

Merged
rafa-thayto merged 1 commit into
mainfrom
rafa-thayto/init-remove-create-route-matcher
Jul 21, 2026
Merged

fix(init): scaffold bare clerkMiddleware instead of deprecated createRouteMatcher#387
rafa-thayto merged 1 commit into
mainfrom
rafa-thayto/init-remove-create-route-matcher

Conversation

@rafa-thayto

@rafa-thaytorafa-thayto commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Summary

clerk init was scaffolding Next.js middleware with createRouteMatcher-based route protection, which Clerk has deprecated in favor of protecting each server-side resource individually with await auth.protect().

  • clerk init for Next.js (App Router and Pages Router) now generates bare export default clerkMiddleware() with the standard config matcher — no isPublicRoute / createRouteMatcher / auth.protect() block
  • i18n composition (next-intl et al.) and existing-middleware composition still wrap the user's middleware inside clerkMiddleware(); they just no longer inject the route matcher
  • The keyless "permissive middleware" variant collapsed into the default (both are now identical), so the ctx.keyless scaffold plumbing was removed
  • New post-init instruction tells users routes are public by default and how to protect resources (auth.protect() for App Router, getAuth() for Pages Router)
  • clerk webhooks listen 401 diagnostic no longer recommends createRouteMatcher(['/api/webhooks(.*)']); it now says to remove auth.protect() for the webhook route
  • Changeset included (clerk: patch)

Test plan

  • bun run format / lint / typecheck pass
  • Full unit/integration suite: 1903 pass, 0 fail
  • Ran real clerk init --keyless -y against 8 sandboxed projects: fresh App Router (next 15 → middleware.ts), Next 16 (→ proxy.ts), Pages Router, fresh next-intl project, existing next-intl expression middleware with own config, user-composed i18n function middleware, i18n middleware with taken varName, and existing plain custom middleware — zero createRouteMatcher occurrences in any generated file, compositions correct
  • Generated bare and i18n-composed middleware typecheck against the real published @clerk/nextjs
  • Idempotency: re-running init on a scaffolded project reports "No files to scaffold" and leaves middleware unchanged

…RouteMatcher
Clerk deprecated middleware-level route protection via createRouteMatcher
in favor of protecting each server-side resource individually with
`await auth.protect()`. `clerk init` for Next.js now generates
`export default clerkMiddleware()` (i18n and existing-middleware
compositions keep wrapping, minus the route matcher), prints a
post-init instruction pointing to resource-level protection, and the
`webhooks listen` 401 hint no longer recommends createRouteMatcher.
Removes the now-collapsed keyless middleware variant plumbing.
https://clerk.com/docs/guides/development/upgrading/upgrade-guides/migrate-from-create-route-matcher
@changeset-bot

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4465797

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 322b8793-1778-4bb2-aea9-5dcfe0f2ec52

📥 Commits

Reviewing files that changed from the base of the PR and between 19c0b58 and 4465797.

📒 Files selected for processing (12)
  • .changeset/init-remove-create-route-matcher.md
  • packages/cli-core/src/commands/init/README.md
  • packages/cli-core/src/commands/init/frameworks/helpers.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-app.test.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-app.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-pages.test.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-pages.ts
  • packages/cli-core/src/commands/init/frameworks/types.ts
  • packages/cli-core/src/commands/init/index.test.ts
  • packages/cli-core/src/commands/init/index.ts
  • packages/cli-core/src/commands/webhooks/render.test.ts
  • packages/cli-core/src/commands/webhooks/render.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
💤 Files with no reviewable changes (2)
  • packages/cli-core/src/commands/init/index.ts
  • packages/cli-core/src/commands/init/frameworks/types.ts

📝 Walkthrough

Walkthrough

Next.js initialization now generates bare clerkMiddleware() without createRouteMatcher route protection. App Router and Pages Router scaffolds add instructions to protect pages, API routes, route handlers, and server actions individually with auth.protect() or getAuth(). Middleware context and composition APIs were updated accordingly, tests and documentation reflect the new output, and webhook diagnostics now reference resource-level protection.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: scaffolding bare clerkMiddleware instead of deprecated createRouteMatcher logic.
Description check✅ PassedThe description is directly about the Next.js init scaffolding, middleware composition, guidance, and webhook diagnostic changes.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

@rafa-thayto
rafa-thayto merged commit c2577ab into mainJul 21, 2026
10 checks passed
@rafa-thayto
rafa-thayto deleted the rafa-thayto/init-remove-create-route-matcher branch July 21, 2026 20:20
@github-actionsgithub-actionsBot mentioned this pull request Jul 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@rafa-thayto@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(init): scaffold bare clerkMiddleware instead of deprecated createRouteMatcher - #387

Merged
rafa-thayto merged 1 commit into
mainfrom
rafa-thayto/init-remove-create-route-matcher
Jul 21, 2026
Merged

fix(init): scaffold bare clerkMiddleware instead of deprecated createRouteMatcher#387
rafa-thayto merged 1 commit into
mainfrom
rafa-thayto/init-remove-create-route-matcher

Conversation

@rafa-thayto

@rafa-thaytorafa-thayto commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Summary

clerk init was scaffolding Next.js middleware with createRouteMatcher-based route protection, which Clerk has deprecated in favor of protecting each server-side resource individually with await auth.protect().

  • clerk init for Next.js (App Router and Pages Router) now generates bare export default clerkMiddleware() with the standard config matcher — no isPublicRoute / createRouteMatcher / auth.protect() block
  • i18n composition (next-intl et al.) and existing-middleware composition still wrap the user's middleware inside clerkMiddleware(); they just no longer inject the route matcher
  • The keyless "permissive middleware" variant collapsed into the default (both are now identical), so the ctx.keyless scaffold plumbing was removed
  • New post-init instruction tells users routes are public by default and how to protect resources (auth.protect() for App Router, getAuth() for Pages Router)
  • clerk webhooks listen 401 diagnostic no longer recommends createRouteMatcher(['/api/webhooks(.*)']); it now says to remove auth.protect() for the webhook route
  • Changeset included (clerk: patch)

Test plan

  • bun run format / lint / typecheck pass
  • Full unit/integration suite: 1903 pass, 0 fail
  • Ran real clerk init --keyless -y against 8 sandboxed projects: fresh App Router (next 15 → middleware.ts), Next 16 (→ proxy.ts), Pages Router, fresh next-intl project, existing next-intl expression middleware with own config, user-composed i18n function middleware, i18n middleware with taken varName, and existing plain custom middleware — zero createRouteMatcher occurrences in any generated file, compositions correct
  • Generated bare and i18n-composed middleware typecheck against the real published @clerk/nextjs
  • Idempotency: re-running init on a scaffolded project reports "No files to scaffold" and leaves middleware unchanged

…RouteMatcher
Clerk deprecated middleware-level route protection via createRouteMatcher
in favor of protecting each server-side resource individually with
`await auth.protect()`. `clerk init` for Next.js now generates
`export default clerkMiddleware()` (i18n and existing-middleware
compositions keep wrapping, minus the route matcher), prints a
post-init instruction pointing to resource-level protection, and the
`webhooks listen` 401 hint no longer recommends createRouteMatcher.
Removes the now-collapsed keyless middleware variant plumbing.
https://clerk.com/docs/guides/development/upgrading/upgrade-guides/migrate-from-create-route-matcher
@changeset-bot

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4465797

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 322b8793-1778-4bb2-aea9-5dcfe0f2ec52

📥 Commits

Reviewing files that changed from the base of the PR and between 19c0b58 and 4465797.

📒 Files selected for processing (12)
  • .changeset/init-remove-create-route-matcher.md
  • packages/cli-core/src/commands/init/README.md
  • packages/cli-core/src/commands/init/frameworks/helpers.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-app.test.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-app.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-pages.test.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-pages.ts
  • packages/cli-core/src/commands/init/frameworks/types.ts
  • packages/cli-core/src/commands/init/index.test.ts
  • packages/cli-core/src/commands/init/index.ts
  • packages/cli-core/src/commands/webhooks/render.test.ts
  • packages/cli-core/src/commands/webhooks/render.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
💤 Files with no reviewable changes (2)
  • packages/cli-core/src/commands/init/index.ts
  • packages/cli-core/src/commands/init/frameworks/types.ts

📝 Walkthrough

Walkthrough

Next.js initialization now generates bare clerkMiddleware() without createRouteMatcher route protection. App Router and Pages Router scaffolds add instructions to protect pages, API routes, route handlers, and server actions individually with auth.protect() or getAuth(). Middleware context and composition APIs were updated accordingly, tests and documentation reflect the new output, and webhook diagnostics now reference resource-level protection.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: scaffolding bare clerkMiddleware instead of deprecated createRouteMatcher logic.
Description check✅ PassedThe description is directly about the Next.js init scaffolding, middleware composition, guidance, and webhook diagnostic changes.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

@rafa-thayto
rafa-thayto merged commit c2577ab into mainJul 21, 2026
10 checks passed
@rafa-thayto
rafa-thayto deleted the rafa-thayto/init-remove-create-route-matcher branch July 21, 2026 20:20
@github-actionsgithub-actionsBot mentioned this pull request Jul 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@rafa-thayto@wyattjoh
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(init): scaffold bare clerkMiddleware instead of deprecated createRouteMatcher - #387

Merged
rafa-thayto merged 1 commit into
mainfrom
rafa-thayto/init-remove-create-route-matcher
Jul 21, 2026
Merged

fix(init): scaffold bare clerkMiddleware instead of deprecated createRouteMatcher#387
rafa-thayto merged 1 commit into
mainfrom
rafa-thayto/init-remove-create-route-matcher

Conversation

@rafa-thayto

@rafa-thaytorafa-thayto commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Summary

clerk init was scaffolding Next.js middleware with createRouteMatcher-based route protection, which Clerk has deprecated in favor of protecting each server-side resource individually with await auth.protect().

  • clerk init for Next.js (App Router and Pages Router) now generates bare export default clerkMiddleware() with the standard config matcher — no isPublicRoute / createRouteMatcher / auth.protect() block
  • i18n composition (next-intl et al.) and existing-middleware composition still wrap the user's middleware inside clerkMiddleware(); they just no longer inject the route matcher
  • The keyless "permissive middleware" variant collapsed into the default (both are now identical), so the ctx.keyless scaffold plumbing was removed
  • New post-init instruction tells users routes are public by default and how to protect resources (auth.protect() for App Router, getAuth() for Pages Router)
  • clerk webhooks listen 401 diagnostic no longer recommends createRouteMatcher(['/api/webhooks(.*)']); it now says to remove auth.protect() for the webhook route
  • Changeset included (clerk: patch)

Test plan

  • bun run format / lint / typecheck pass
  • Full unit/integration suite: 1903 pass, 0 fail
  • Ran real clerk init --keyless -y against 8 sandboxed projects: fresh App Router (next 15 → middleware.ts), Next 16 (→ proxy.ts), Pages Router, fresh next-intl project, existing next-intl expression middleware with own config, user-composed i18n function middleware, i18n middleware with taken varName, and existing plain custom middleware — zero createRouteMatcher occurrences in any generated file, compositions correct
  • Generated bare and i18n-composed middleware typecheck against the real published @clerk/nextjs
  • Idempotency: re-running init on a scaffolded project reports "No files to scaffold" and leaves middleware unchanged

…RouteMatcher
Clerk deprecated middleware-level route protection via createRouteMatcher
in favor of protecting each server-side resource individually with
`await auth.protect()`. `clerk init` for Next.js now generates
`export default clerkMiddleware()` (i18n and existing-middleware
compositions keep wrapping, minus the route matcher), prints a
post-init instruction pointing to resource-level protection, and the
`webhooks listen` 401 hint no longer recommends createRouteMatcher.
Removes the now-collapsed keyless middleware variant plumbing.
https://clerk.com/docs/guides/development/upgrading/upgrade-guides/migrate-from-create-route-matcher
@changeset-bot

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4465797

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
clerkPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 322b8793-1778-4bb2-aea9-5dcfe0f2ec52

📥 Commits

Reviewing files that changed from the base of the PR and between 19c0b58 and 4465797.

📒 Files selected for processing (12)
  • .changeset/init-remove-create-route-matcher.md
  • packages/cli-core/src/commands/init/README.md
  • packages/cli-core/src/commands/init/frameworks/helpers.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-app.test.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-app.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-pages.test.ts
  • packages/cli-core/src/commands/init/frameworks/nextjs-pages.ts
  • packages/cli-core/src/commands/init/frameworks/types.ts
  • packages/cli-core/src/commands/init/index.test.ts
  • packages/cli-core/src/commands/init/index.ts
  • packages/cli-core/src/commands/webhooks/render.test.ts
  • packages/cli-core/src/commands/webhooks/render.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
💤 Files with no reviewable changes (2)
  • packages/cli-core/src/commands/init/index.ts
  • packages/cli-core/src/commands/init/frameworks/types.ts

📝 Walkthrough

Walkthrough

Next.js initialization now generates bare clerkMiddleware() without createRouteMatcher route protection. App Router and Pages Router scaffolds add instructions to protect pages, API routes, route handlers, and server actions individually with auth.protect() or getAuth(). Middleware context and composition APIs were updated accordingly, tests and documentation reflect the new output, and webhook diagnostics now reference resource-level protection.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: scaffolding bare clerkMiddleware instead of deprecated createRouteMatcher logic.
Description check✅ PassedThe description is directly about the Next.js init scaffolding, middleware composition, guidance, and webhook diagnostic changes.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

@rafa-thayto
rafa-thayto merged commit c2577ab into mainJul 21, 2026
10 checks passed
@rafa-thayto
rafa-thayto deleted the rafa-thayto/init-remove-create-route-matcher branch July 21, 2026 20:20
@github-actionsgithub-actionsBot mentioned this pull request Jul 21, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@rafa-thayto@wyattjoh