fix(clerk-js): Pass dev_browser to AP via query param, fix AP origin … - #1567

Merged
yourtallness merged 1 commit into
mainfrom
yourtallness/dev_browser_query_params_for_ap
Aug 14, 2023
Merged

fix(clerk-js): Pass dev_browser to AP via query param, fix AP origin …#1567
yourtallness merged 1 commit into
mainfrom
yourtallness/dev_browser_query_params_for_ap

Conversation

@yourtallness

@yourtallnessyourtallness commented Aug 9, 2023

Copy link
Copy Markdown
Contributor

…detection util

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Packages affected

  • @clerk/clerk-js
  • @clerk/clerk-react
  • @clerk/nextjs
  • @clerk/remix
  • @clerk/types
  • @clerk/themes
  • @clerk/localizations
  • @clerk/clerk-expo
  • @clerk/backend
  • @clerk/clerk-sdk-node
  • @clerk/shared
  • @clerk/fastify
  • @clerk/chrome-extension
  • gatsby-plugin-clerk
  • build/tooling/chore

Description

To make the dev_browser JWT available to the SSR context on Account Portal, we need to pass the JWT via the query, not the hash.

The current PR detects whether the URL we are navigating to is an AP URL & passes the db JWT as a query param.

Also fixed the AP origin detection util, which did not cover kima instances (ported logic from our backend).

Adding @chanioxaris to help verify if the AP origin detection logic is accurate.

@changeset-bot

changeset-botBot commented Aug 9, 2023

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 9d54fe7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from 0144a11 to b9aa85dCompareAugust 9, 2023 12:25

@jit-cijit-ciBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Great news! Jit hasn't found any security issues in your PR. Good Job! 🏆

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from b9aa85d to e313934CompareAugust 9, 2023 15:02

@panteliselefpanteliselef left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me 💯 but maybe wait for Haris as requested

return res;
}

// Returns true for hosts such as:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe we should be a bit more strict with our checks here. For example we will return true for hostname accounts.foo.13.bar-1.lcl.dev which is wrong

});
}

// Returns true for hosts such as:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same here we can be more strict with our checks. For example we will return true for hostname foo.bar.13.whatever.accounts.dev which is wrong. Maybe use a regex instead?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking of a regex, but preferred to use the same logic as the BE has for this.

Note that this regex would also require that .clerk is not contained be contained and I'm a bit worried about using a negative lookahead (?!).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chanioxaris do you have any planned changes in mind that could break this check? I totally agree that we could make this stricter to be on the safe side... the example domain you provided is unlikely to be used by someone though - could we be missing any cases here?

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch 2 times, most recently from ba28b18 to 4f92750CompareAugust 11, 2023 14:18
Comment threadpackages/clerk-js/src/utils/url.ts Outdated

export const LEGACY_DEV_SUFFIXES = ['.lcl.dev', '.lclstage.dev', '.lclclerk.com'];

export const KIMA_DEV_SUFFIXES = ['.accounts.dev', '.accountstage.dev', '.accounts.lclclerk.com'];

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
exportconstKIMA_DEV_SUFFIXES=['.accounts.dev','.accountstage.dev','.accounts.lclclerk.com'];
exportconstDEV_SUFFIXES=['.accounts.dev','.accountstage.dev','.accounts.lclclerk.com'];

Kima was an internal project naming that shouldn't leak in the code.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will rename

Comment threadpackages/clerk-js/src/utils/url.ts Outdated
// * foo-bar-13.accounts.lclclerk.com
// But false for:
// * foo-bar-13.clerk.accounts.lclclerk.com
function isKimaDevAccountPortalOrigin(host: string): boolean {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ditto about Kima

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renamed

const hasQueryParam = (url || '').includes('?');
return `${url}${hasQueryParam ? '&' : '?'}${DEV_BROWSER_SSO_JWT_PARAMETER}=${(jwt || '').trim()}`;
// extract & strip existing jwt from hash
const jwtFromHash = extractDevBrowserJWTFromHash(resultURL.hash);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ Since this is the setDevBrowserJWTInURL method are we using extractDevBrowserJWTFromHash to make sure it's only set once?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, but it might be in the hash & we need to move it to search or vice versa.

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from 4f92750 to 9d54fe7CompareAugust 14, 2023 16:25
@yourtallness
yourtallness merged commit 854aa38 into mainAug 14, 2023
@yourtallness
yourtallness deleted the yourtallness/dev_browser_query_params_for_ap branch August 14, 2023 16:53
@clerk-cookieclerk-cookie mentioned this pull request Aug 14, 2023
'accounts.dev',
];

export const LEGACY_DEV_SUFFIXES = ['.lcl.dev', '.lclstage.dev', '.lclclerk.com'];

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Adding a comment for posterity/ future reference mostly, this change needs to be made to all similar helpers until we revamp clerk/shared.

@clerk-cookie

Copy link
Copy Markdown
Collaborator

This PR has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@clerkclerk locked as resolved and limited conversation to collaborators Aug 24, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@yourtallness@clerk-cookie@SokratisVidros@nikosdouvlis@panteliselef@chanioxaris
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(clerk-js): Pass dev_browser to AP via query param, fix AP origin … - #1567

Merged
yourtallness merged 1 commit into
mainfrom
yourtallness/dev_browser_query_params_for_ap
Aug 14, 2023
Merged

fix(clerk-js): Pass dev_browser to AP via query param, fix AP origin …#1567
yourtallness merged 1 commit into
mainfrom
yourtallness/dev_browser_query_params_for_ap

Conversation

@yourtallness

@yourtallnessyourtallness commented Aug 9, 2023

Copy link
Copy Markdown
Contributor

…detection util

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Packages affected

  • @clerk/clerk-js
  • @clerk/clerk-react
  • @clerk/nextjs
  • @clerk/remix
  • @clerk/types
  • @clerk/themes
  • @clerk/localizations
  • @clerk/clerk-expo
  • @clerk/backend
  • @clerk/clerk-sdk-node
  • @clerk/shared
  • @clerk/fastify
  • @clerk/chrome-extension
  • gatsby-plugin-clerk
  • build/tooling/chore

Description

To make the dev_browser JWT available to the SSR context on Account Portal, we need to pass the JWT via the query, not the hash.

The current PR detects whether the URL we are navigating to is an AP URL & passes the db JWT as a query param.

Also fixed the AP origin detection util, which did not cover kima instances (ported logic from our backend).

Adding @chanioxaris to help verify if the AP origin detection logic is accurate.

@changeset-bot

changeset-botBot commented Aug 9, 2023

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 9d54fe7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from 0144a11 to b9aa85dCompareAugust 9, 2023 12:25

@jit-cijit-ciBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Great news! Jit hasn't found any security issues in your PR. Good Job! 🏆

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from b9aa85d to e313934CompareAugust 9, 2023 15:02

@panteliselefpanteliselef left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me 💯 but maybe wait for Haris as requested

return res;
}

// Returns true for hosts such as:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe we should be a bit more strict with our checks here. For example we will return true for hostname accounts.foo.13.bar-1.lcl.dev which is wrong

});
}

// Returns true for hosts such as:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same here we can be more strict with our checks. For example we will return true for hostname foo.bar.13.whatever.accounts.dev which is wrong. Maybe use a regex instead?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking of a regex, but preferred to use the same logic as the BE has for this.

Note that this regex would also require that .clerk is not contained be contained and I'm a bit worried about using a negative lookahead (?!).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chanioxaris do you have any planned changes in mind that could break this check? I totally agree that we could make this stricter to be on the safe side... the example domain you provided is unlikely to be used by someone though - could we be missing any cases here?

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch 2 times, most recently from ba28b18 to 4f92750CompareAugust 11, 2023 14:18
Comment threadpackages/clerk-js/src/utils/url.ts Outdated

export const LEGACY_DEV_SUFFIXES = ['.lcl.dev', '.lclstage.dev', '.lclclerk.com'];

export const KIMA_DEV_SUFFIXES = ['.accounts.dev', '.accountstage.dev', '.accounts.lclclerk.com'];

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
exportconstKIMA_DEV_SUFFIXES=['.accounts.dev','.accountstage.dev','.accounts.lclclerk.com'];
exportconstDEV_SUFFIXES=['.accounts.dev','.accountstage.dev','.accounts.lclclerk.com'];

Kima was an internal project naming that shouldn't leak in the code.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will rename

Comment threadpackages/clerk-js/src/utils/url.ts Outdated
// * foo-bar-13.accounts.lclclerk.com
// But false for:
// * foo-bar-13.clerk.accounts.lclclerk.com
function isKimaDevAccountPortalOrigin(host: string): boolean {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ditto about Kima

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renamed

const hasQueryParam = (url || '').includes('?');
return `${url}${hasQueryParam ? '&' : '?'}${DEV_BROWSER_SSO_JWT_PARAMETER}=${(jwt || '').trim()}`;
// extract & strip existing jwt from hash
const jwtFromHash = extractDevBrowserJWTFromHash(resultURL.hash);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ Since this is the setDevBrowserJWTInURL method are we using extractDevBrowserJWTFromHash to make sure it's only set once?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, but it might be in the hash & we need to move it to search or vice versa.

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from 4f92750 to 9d54fe7CompareAugust 14, 2023 16:25
@yourtallness
yourtallness merged commit 854aa38 into mainAug 14, 2023
@yourtallness
yourtallness deleted the yourtallness/dev_browser_query_params_for_ap branch August 14, 2023 16:53
@clerk-cookieclerk-cookie mentioned this pull request Aug 14, 2023
'accounts.dev',
];

export const LEGACY_DEV_SUFFIXES = ['.lcl.dev', '.lclstage.dev', '.lclclerk.com'];

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Adding a comment for posterity/ future reference mostly, this change needs to be made to all similar helpers until we revamp clerk/shared.

@clerk-cookie

Copy link
Copy Markdown
Collaborator

This PR has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@clerkclerk locked as resolved and limited conversation to collaborators Aug 24, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@yourtallness@clerk-cookie@SokratisVidros@nikosdouvlis@panteliselef@chanioxaris
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-js): Pass dev_browser to AP via query param, fix AP origin … - #1567

Merged
yourtallness merged 1 commit into
mainfrom
yourtallness/dev_browser_query_params_for_ap
Aug 14, 2023
Merged

fix(clerk-js): Pass dev_browser to AP via query param, fix AP origin …#1567
yourtallness merged 1 commit into
mainfrom
yourtallness/dev_browser_query_params_for_ap

Conversation

@yourtallness

@yourtallnessyourtallness commented Aug 9, 2023

Copy link
Copy Markdown
Contributor

…detection util

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Packages affected

  • @clerk/clerk-js
  • @clerk/clerk-react
  • @clerk/nextjs
  • @clerk/remix
  • @clerk/types
  • @clerk/themes
  • @clerk/localizations
  • @clerk/clerk-expo
  • @clerk/backend
  • @clerk/clerk-sdk-node
  • @clerk/shared
  • @clerk/fastify
  • @clerk/chrome-extension
  • gatsby-plugin-clerk
  • build/tooling/chore

Description

To make the dev_browser JWT available to the SSR context on Account Portal, we need to pass the JWT via the query, not the hash.

The current PR detects whether the URL we are navigating to is an AP URL & passes the db JWT as a query param.

Also fixed the AP origin detection util, which did not cover kima instances (ported logic from our backend).

Adding @chanioxaris to help verify if the AP origin detection logic is accurate.

@changeset-bot

changeset-botBot commented Aug 9, 2023

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 9d54fe7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from 0144a11 to b9aa85dCompareAugust 9, 2023 12:25

@jit-cijit-ciBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Great news! Jit hasn't found any security issues in your PR. Good Job! 🏆

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from b9aa85d to e313934CompareAugust 9, 2023 15:02

@panteliselefpanteliselef left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me 💯 but maybe wait for Haris as requested

return res;
}

// Returns true for hosts such as:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe we should be a bit more strict with our checks here. For example we will return true for hostname accounts.foo.13.bar-1.lcl.dev which is wrong

});
}

// Returns true for hosts such as:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same here we can be more strict with our checks. For example we will return true for hostname foo.bar.13.whatever.accounts.dev which is wrong. Maybe use a regex instead?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking of a regex, but preferred to use the same logic as the BE has for this.

Note that this regex would also require that .clerk is not contained be contained and I'm a bit worried about using a negative lookahead (?!).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chanioxaris do you have any planned changes in mind that could break this check? I totally agree that we could make this stricter to be on the safe side... the example domain you provided is unlikely to be used by someone though - could we be missing any cases here?

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch 2 times, most recently from ba28b18 to 4f92750CompareAugust 11, 2023 14:18
Comment threadpackages/clerk-js/src/utils/url.ts Outdated

export const LEGACY_DEV_SUFFIXES = ['.lcl.dev', '.lclstage.dev', '.lclclerk.com'];

export const KIMA_DEV_SUFFIXES = ['.accounts.dev', '.accountstage.dev', '.accounts.lclclerk.com'];

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
exportconstKIMA_DEV_SUFFIXES=['.accounts.dev','.accountstage.dev','.accounts.lclclerk.com'];
exportconstDEV_SUFFIXES=['.accounts.dev','.accountstage.dev','.accounts.lclclerk.com'];

Kima was an internal project naming that shouldn't leak in the code.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will rename

Comment threadpackages/clerk-js/src/utils/url.ts Outdated
// * foo-bar-13.accounts.lclclerk.com
// But false for:
// * foo-bar-13.clerk.accounts.lclclerk.com
function isKimaDevAccountPortalOrigin(host: string): boolean {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ditto about Kima

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renamed

const hasQueryParam = (url || '').includes('?');
return `${url}${hasQueryParam ? '&' : '?'}${DEV_BROWSER_SSO_JWT_PARAMETER}=${(jwt || '').trim()}`;
// extract & strip existing jwt from hash
const jwtFromHash = extractDevBrowserJWTFromHash(resultURL.hash);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ Since this is the setDevBrowserJWTInURL method are we using extractDevBrowserJWTFromHash to make sure it's only set once?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, but it might be in the hash & we need to move it to search or vice versa.

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from 4f92750 to 9d54fe7CompareAugust 14, 2023 16:25
@yourtallness
yourtallness merged commit 854aa38 into mainAug 14, 2023
@yourtallness
yourtallness deleted the yourtallness/dev_browser_query_params_for_ap branch August 14, 2023 16:53
@clerk-cookieclerk-cookie mentioned this pull request Aug 14, 2023
'accounts.dev',
];

export const LEGACY_DEV_SUFFIXES = ['.lcl.dev', '.lclstage.dev', '.lclclerk.com'];

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Adding a comment for posterity/ future reference mostly, this change needs to be made to all similar helpers until we revamp clerk/shared.

@clerk-cookie

Copy link
Copy Markdown
Collaborator

This PR has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@clerkclerk locked as resolved and limited conversation to collaborators Aug 24, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@yourtallness@clerk-cookie@SokratisVidros@nikosdouvlis@panteliselef@chanioxaris
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-js): Pass dev_browser to AP via query param, fix AP origin … - #1567

Merged
yourtallness merged 1 commit into
mainfrom
yourtallness/dev_browser_query_params_for_ap
Aug 14, 2023
Merged

fix(clerk-js): Pass dev_browser to AP via query param, fix AP origin …#1567
yourtallness merged 1 commit into
mainfrom
yourtallness/dev_browser_query_params_for_ap

Conversation

@yourtallness

@yourtallnessyourtallness commented Aug 9, 2023

Copy link
Copy Markdown
Contributor

…detection util

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Packages affected

  • @clerk/clerk-js
  • @clerk/clerk-react
  • @clerk/nextjs
  • @clerk/remix
  • @clerk/types
  • @clerk/themes
  • @clerk/localizations
  • @clerk/clerk-expo
  • @clerk/backend
  • @clerk/clerk-sdk-node
  • @clerk/shared
  • @clerk/fastify
  • @clerk/chrome-extension
  • gatsby-plugin-clerk
  • build/tooling/chore

Description

To make the dev_browser JWT available to the SSR context on Account Portal, we need to pass the JWT via the query, not the hash.

The current PR detects whether the URL we are navigating to is an AP URL & passes the db JWT as a query param.

Also fixed the AP origin detection util, which did not cover kima instances (ported logic from our backend).

Adding @chanioxaris to help verify if the AP origin detection logic is accurate.

@changeset-bot

changeset-botBot commented Aug 9, 2023

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 9d54fe7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from 0144a11 to b9aa85dCompareAugust 9, 2023 12:25

@jit-cijit-ciBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Great news! Jit hasn't found any security issues in your PR. Good Job! 🏆

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from b9aa85d to e313934CompareAugust 9, 2023 15:02

@panteliselefpanteliselef left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me 💯 but maybe wait for Haris as requested

return res;
}

// Returns true for hosts such as:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe we should be a bit more strict with our checks here. For example we will return true for hostname accounts.foo.13.bar-1.lcl.dev which is wrong

});
}

// Returns true for hosts such as:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same here we can be more strict with our checks. For example we will return true for hostname foo.bar.13.whatever.accounts.dev which is wrong. Maybe use a regex instead?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking of a regex, but preferred to use the same logic as the BE has for this.

Note that this regex would also require that .clerk is not contained be contained and I'm a bit worried about using a negative lookahead (?!).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chanioxaris do you have any planned changes in mind that could break this check? I totally agree that we could make this stricter to be on the safe side... the example domain you provided is unlikely to be used by someone though - could we be missing any cases here?

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch 2 times, most recently from ba28b18 to 4f92750CompareAugust 11, 2023 14:18
Comment threadpackages/clerk-js/src/utils/url.ts Outdated

export const LEGACY_DEV_SUFFIXES = ['.lcl.dev', '.lclstage.dev', '.lclclerk.com'];

export const KIMA_DEV_SUFFIXES = ['.accounts.dev', '.accountstage.dev', '.accounts.lclclerk.com'];

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
exportconstKIMA_DEV_SUFFIXES=['.accounts.dev','.accountstage.dev','.accounts.lclclerk.com'];
exportconstDEV_SUFFIXES=['.accounts.dev','.accountstage.dev','.accounts.lclclerk.com'];

Kima was an internal project naming that shouldn't leak in the code.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will rename

Comment threadpackages/clerk-js/src/utils/url.ts Outdated
// * foo-bar-13.accounts.lclclerk.com
// But false for:
// * foo-bar-13.clerk.accounts.lclclerk.com
function isKimaDevAccountPortalOrigin(host: string): boolean {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ditto about Kima

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renamed

const hasQueryParam = (url || '').includes('?');
return `${url}${hasQueryParam ? '&' : '?'}${DEV_BROWSER_SSO_JWT_PARAMETER}=${(jwt || '').trim()}`;
// extract & strip existing jwt from hash
const jwtFromHash = extractDevBrowserJWTFromHash(resultURL.hash);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ Since this is the setDevBrowserJWTInURL method are we using extractDevBrowserJWTFromHash to make sure it's only set once?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, but it might be in the hash & we need to move it to search or vice versa.

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from 4f92750 to 9d54fe7CompareAugust 14, 2023 16:25
@yourtallness
yourtallness merged commit 854aa38 into mainAug 14, 2023
@yourtallness
yourtallness deleted the yourtallness/dev_browser_query_params_for_ap branch August 14, 2023 16:53
@clerk-cookieclerk-cookie mentioned this pull request Aug 14, 2023
'accounts.dev',
];

export const LEGACY_DEV_SUFFIXES = ['.lcl.dev', '.lclstage.dev', '.lclclerk.com'];

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Adding a comment for posterity/ future reference mostly, this change needs to be made to all similar helpers until we revamp clerk/shared.

@clerk-cookie

Copy link
Copy Markdown
Collaborator

This PR has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@clerkclerk locked as resolved and limited conversation to collaborators Aug 24, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@yourtallness@clerk-cookie@SokratisVidros@nikosdouvlis@panteliselef@chanioxaris
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(clerk-js): Pass dev_browser to AP via query param, fix AP origin … - #1567

Merged
yourtallness merged 1 commit into
mainfrom
yourtallness/dev_browser_query_params_for_ap
Aug 14, 2023
Merged

fix(clerk-js): Pass dev_browser to AP via query param, fix AP origin …#1567
yourtallness merged 1 commit into
mainfrom
yourtallness/dev_browser_query_params_for_ap

Conversation

@yourtallness

@yourtallnessyourtallness commented Aug 9, 2023

Copy link
Copy Markdown
Contributor

…detection util

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Packages affected

  • @clerk/clerk-js
  • @clerk/clerk-react
  • @clerk/nextjs
  • @clerk/remix
  • @clerk/types
  • @clerk/themes
  • @clerk/localizations
  • @clerk/clerk-expo
  • @clerk/backend
  • @clerk/clerk-sdk-node
  • @clerk/shared
  • @clerk/fastify
  • @clerk/chrome-extension
  • gatsby-plugin-clerk
  • build/tooling/chore

Description

To make the dev_browser JWT available to the SSR context on Account Portal, we need to pass the JWT via the query, not the hash.

The current PR detects whether the URL we are navigating to is an AP URL & passes the db JWT as a query param.

Also fixed the AP origin detection util, which did not cover kima instances (ported logic from our backend).

Adding @chanioxaris to help verify if the AP origin detection logic is accurate.

@changeset-bot

changeset-botBot commented Aug 9, 2023

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 9d54fe7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from 0144a11 to b9aa85dCompareAugust 9, 2023 12:25

@jit-cijit-ciBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Great news! Jit hasn't found any security issues in your PR. Good Job! 🏆

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from b9aa85d to e313934CompareAugust 9, 2023 15:02

@panteliselefpanteliselef left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me 💯 but maybe wait for Haris as requested

return res;
}

// Returns true for hosts such as:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe we should be a bit more strict with our checks here. For example we will return true for hostname accounts.foo.13.bar-1.lcl.dev which is wrong

});
}

// Returns true for hosts such as:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same here we can be more strict with our checks. For example we will return true for hostname foo.bar.13.whatever.accounts.dev which is wrong. Maybe use a regex instead?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking of a regex, but preferred to use the same logic as the BE has for this.

Note that this regex would also require that .clerk is not contained be contained and I'm a bit worried about using a negative lookahead (?!).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chanioxaris do you have any planned changes in mind that could break this check? I totally agree that we could make this stricter to be on the safe side... the example domain you provided is unlikely to be used by someone though - could we be missing any cases here?

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch 2 times, most recently from ba28b18 to 4f92750CompareAugust 11, 2023 14:18
Comment threadpackages/clerk-js/src/utils/url.ts Outdated

export const LEGACY_DEV_SUFFIXES = ['.lcl.dev', '.lclstage.dev', '.lclclerk.com'];

export const KIMA_DEV_SUFFIXES = ['.accounts.dev', '.accountstage.dev', '.accounts.lclclerk.com'];

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
exportconstKIMA_DEV_SUFFIXES=['.accounts.dev','.accountstage.dev','.accounts.lclclerk.com'];
exportconstDEV_SUFFIXES=['.accounts.dev','.accountstage.dev','.accounts.lclclerk.com'];

Kima was an internal project naming that shouldn't leak in the code.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will rename

Comment threadpackages/clerk-js/src/utils/url.ts Outdated
// * foo-bar-13.accounts.lclclerk.com
// But false for:
// * foo-bar-13.clerk.accounts.lclclerk.com
function isKimaDevAccountPortalOrigin(host: string): boolean {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ditto about Kima

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renamed

const hasQueryParam = (url || '').includes('?');
return `${url}${hasQueryParam ? '&' : '?'}${DEV_BROWSER_SSO_JWT_PARAMETER}=${(jwt || '').trim()}`;
// extract & strip existing jwt from hash
const jwtFromHash = extractDevBrowserJWTFromHash(resultURL.hash);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ Since this is the setDevBrowserJWTInURL method are we using extractDevBrowserJWTFromHash to make sure it's only set once?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, but it might be in the hash & we need to move it to search or vice versa.

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from 4f92750 to 9d54fe7CompareAugust 14, 2023 16:25
@yourtallness
yourtallness merged commit 854aa38 into mainAug 14, 2023
@yourtallness
yourtallness deleted the yourtallness/dev_browser_query_params_for_ap branch August 14, 2023 16:53
@clerk-cookieclerk-cookie mentioned this pull request Aug 14, 2023
'accounts.dev',
];

export const LEGACY_DEV_SUFFIXES = ['.lcl.dev', '.lclstage.dev', '.lclclerk.com'];

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Adding a comment for posterity/ future reference mostly, this change needs to be made to all similar helpers until we revamp clerk/shared.

@clerk-cookie

Copy link
Copy Markdown
Collaborator

This PR has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@clerkclerk locked as resolved and limited conversation to collaborators Aug 24, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@yourtallness@clerk-cookie@SokratisVidros@nikosdouvlis@panteliselef@chanioxaris
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-js): Pass dev_browser to AP via query param, fix AP origin … - #1567

Merged
yourtallness merged 1 commit into
mainfrom
yourtallness/dev_browser_query_params_for_ap
Aug 14, 2023
Merged

fix(clerk-js): Pass dev_browser to AP via query param, fix AP origin …#1567
yourtallness merged 1 commit into
mainfrom
yourtallness/dev_browser_query_params_for_ap

Conversation

@yourtallness

@yourtallnessyourtallness commented Aug 9, 2023

Copy link
Copy Markdown
Contributor

…detection util

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Packages affected

  • @clerk/clerk-js
  • @clerk/clerk-react
  • @clerk/nextjs
  • @clerk/remix
  • @clerk/types
  • @clerk/themes
  • @clerk/localizations
  • @clerk/clerk-expo
  • @clerk/backend
  • @clerk/clerk-sdk-node
  • @clerk/shared
  • @clerk/fastify
  • @clerk/chrome-extension
  • gatsby-plugin-clerk
  • build/tooling/chore

Description

To make the dev_browser JWT available to the SSR context on Account Portal, we need to pass the JWT via the query, not the hash.

The current PR detects whether the URL we are navigating to is an AP URL & passes the db JWT as a query param.

Also fixed the AP origin detection util, which did not cover kima instances (ported logic from our backend).

Adding @chanioxaris to help verify if the AP origin detection logic is accurate.

@changeset-bot

changeset-botBot commented Aug 9, 2023

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 9d54fe7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from 0144a11 to b9aa85dCompareAugust 9, 2023 12:25

@jit-cijit-ciBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Great news! Jit hasn't found any security issues in your PR. Good Job! 🏆

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from b9aa85d to e313934CompareAugust 9, 2023 15:02

@panteliselefpanteliselef left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me 💯 but maybe wait for Haris as requested

return res;
}

// Returns true for hosts such as:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe we should be a bit more strict with our checks here. For example we will return true for hostname accounts.foo.13.bar-1.lcl.dev which is wrong

});
}

// Returns true for hosts such as:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same here we can be more strict with our checks. For example we will return true for hostname foo.bar.13.whatever.accounts.dev which is wrong. Maybe use a regex instead?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking of a regex, but preferred to use the same logic as the BE has for this.

Note that this regex would also require that .clerk is not contained be contained and I'm a bit worried about using a negative lookahead (?!).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chanioxaris do you have any planned changes in mind that could break this check? I totally agree that we could make this stricter to be on the safe side... the example domain you provided is unlikely to be used by someone though - could we be missing any cases here?

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch 2 times, most recently from ba28b18 to 4f92750CompareAugust 11, 2023 14:18
Comment threadpackages/clerk-js/src/utils/url.ts Outdated

export const LEGACY_DEV_SUFFIXES = ['.lcl.dev', '.lclstage.dev', '.lclclerk.com'];

export const KIMA_DEV_SUFFIXES = ['.accounts.dev', '.accountstage.dev', '.accounts.lclclerk.com'];

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
exportconstKIMA_DEV_SUFFIXES=['.accounts.dev','.accountstage.dev','.accounts.lclclerk.com'];
exportconstDEV_SUFFIXES=['.accounts.dev','.accountstage.dev','.accounts.lclclerk.com'];

Kima was an internal project naming that shouldn't leak in the code.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will rename

Comment threadpackages/clerk-js/src/utils/url.ts Outdated
// * foo-bar-13.accounts.lclclerk.com
// But false for:
// * foo-bar-13.clerk.accounts.lclclerk.com
function isKimaDevAccountPortalOrigin(host: string): boolean {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ditto about Kima

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renamed

const hasQueryParam = (url || '').includes('?');
return `${url}${hasQueryParam ? '&' : '?'}${DEV_BROWSER_SSO_JWT_PARAMETER}=${(jwt || '').trim()}`;
// extract & strip existing jwt from hash
const jwtFromHash = extractDevBrowserJWTFromHash(resultURL.hash);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ Since this is the setDevBrowserJWTInURL method are we using extractDevBrowserJWTFromHash to make sure it's only set once?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, but it might be in the hash & we need to move it to search or vice versa.

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from 4f92750 to 9d54fe7CompareAugust 14, 2023 16:25
@yourtallness
yourtallness merged commit 854aa38 into mainAug 14, 2023
@yourtallness
yourtallness deleted the yourtallness/dev_browser_query_params_for_ap branch August 14, 2023 16:53
@clerk-cookieclerk-cookie mentioned this pull request Aug 14, 2023
'accounts.dev',
];

export const LEGACY_DEV_SUFFIXES = ['.lcl.dev', '.lclstage.dev', '.lclclerk.com'];

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Adding a comment for posterity/ future reference mostly, this change needs to be made to all similar helpers until we revamp clerk/shared.

@clerk-cookie

Copy link
Copy Markdown
Collaborator

This PR has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@clerkclerk locked as resolved and limited conversation to collaborators Aug 24, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@yourtallness@clerk-cookie@SokratisVidros@nikosdouvlis@panteliselef@chanioxaris
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-js): Pass dev_browser to AP via query param, fix AP origin … - #1567

Merged
yourtallness merged 1 commit into
mainfrom
yourtallness/dev_browser_query_params_for_ap
Aug 14, 2023
Merged

fix(clerk-js): Pass dev_browser to AP via query param, fix AP origin …#1567
yourtallness merged 1 commit into
mainfrom
yourtallness/dev_browser_query_params_for_ap

Conversation

@yourtallness

@yourtallnessyourtallness commented Aug 9, 2023

Copy link
Copy Markdown
Contributor

…detection util

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Packages affected

  • @clerk/clerk-js
  • @clerk/clerk-react
  • @clerk/nextjs
  • @clerk/remix
  • @clerk/types
  • @clerk/themes
  • @clerk/localizations
  • @clerk/clerk-expo
  • @clerk/backend
  • @clerk/clerk-sdk-node
  • @clerk/shared
  • @clerk/fastify
  • @clerk/chrome-extension
  • gatsby-plugin-clerk
  • build/tooling/chore

Description

To make the dev_browser JWT available to the SSR context on Account Portal, we need to pass the JWT via the query, not the hash.

The current PR detects whether the URL we are navigating to is an AP URL & passes the db JWT as a query param.

Also fixed the AP origin detection util, which did not cover kima instances (ported logic from our backend).

Adding @chanioxaris to help verify if the AP origin detection logic is accurate.

@changeset-bot

changeset-botBot commented Aug 9, 2023

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 9d54fe7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from 0144a11 to b9aa85dCompareAugust 9, 2023 12:25

@jit-cijit-ciBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Great news! Jit hasn't found any security issues in your PR. Good Job! 🏆

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from b9aa85d to e313934CompareAugust 9, 2023 15:02

@panteliselefpanteliselef left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me 💯 but maybe wait for Haris as requested

return res;
}

// Returns true for hosts such as:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe we should be a bit more strict with our checks here. For example we will return true for hostname accounts.foo.13.bar-1.lcl.dev which is wrong

});
}

// Returns true for hosts such as:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same here we can be more strict with our checks. For example we will return true for hostname foo.bar.13.whatever.accounts.dev which is wrong. Maybe use a regex instead?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking of a regex, but preferred to use the same logic as the BE has for this.

Note that this regex would also require that .clerk is not contained be contained and I'm a bit worried about using a negative lookahead (?!).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chanioxaris do you have any planned changes in mind that could break this check? I totally agree that we could make this stricter to be on the safe side... the example domain you provided is unlikely to be used by someone though - could we be missing any cases here?

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch 2 times, most recently from ba28b18 to 4f92750CompareAugust 11, 2023 14:18
Comment threadpackages/clerk-js/src/utils/url.ts Outdated

export const LEGACY_DEV_SUFFIXES = ['.lcl.dev', '.lclstage.dev', '.lclclerk.com'];

export const KIMA_DEV_SUFFIXES = ['.accounts.dev', '.accountstage.dev', '.accounts.lclclerk.com'];

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
exportconstKIMA_DEV_SUFFIXES=['.accounts.dev','.accountstage.dev','.accounts.lclclerk.com'];
exportconstDEV_SUFFIXES=['.accounts.dev','.accountstage.dev','.accounts.lclclerk.com'];

Kima was an internal project naming that shouldn't leak in the code.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will rename

Comment threadpackages/clerk-js/src/utils/url.ts Outdated
// * foo-bar-13.accounts.lclclerk.com
// But false for:
// * foo-bar-13.clerk.accounts.lclclerk.com
function isKimaDevAccountPortalOrigin(host: string): boolean {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ditto about Kima

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renamed

const hasQueryParam = (url || '').includes('?');
return `${url}${hasQueryParam ? '&' : '?'}${DEV_BROWSER_SSO_JWT_PARAMETER}=${(jwt || '').trim()}`;
// extract & strip existing jwt from hash
const jwtFromHash = extractDevBrowserJWTFromHash(resultURL.hash);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ Since this is the setDevBrowserJWTInURL method are we using extractDevBrowserJWTFromHash to make sure it's only set once?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, but it might be in the hash & we need to move it to search or vice versa.

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from 4f92750 to 9d54fe7CompareAugust 14, 2023 16:25
@yourtallness
yourtallness merged commit 854aa38 into mainAug 14, 2023
@yourtallness
yourtallness deleted the yourtallness/dev_browser_query_params_for_ap branch August 14, 2023 16:53
@clerk-cookieclerk-cookie mentioned this pull request Aug 14, 2023
'accounts.dev',
];

export const LEGACY_DEV_SUFFIXES = ['.lcl.dev', '.lclstage.dev', '.lclclerk.com'];

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Adding a comment for posterity/ future reference mostly, this change needs to be made to all similar helpers until we revamp clerk/shared.

@clerk-cookie

Copy link
Copy Markdown
Collaborator

This PR has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@clerkclerk locked as resolved and limited conversation to collaborators Aug 24, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@yourtallness@clerk-cookie@SokratisVidros@nikosdouvlis@panteliselef@chanioxaris
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(clerk-js): Pass dev_browser to AP via query param, fix AP origin … - #1567

Merged
yourtallness merged 1 commit into
mainfrom
yourtallness/dev_browser_query_params_for_ap
Aug 14, 2023
Merged

fix(clerk-js): Pass dev_browser to AP via query param, fix AP origin …#1567
yourtallness merged 1 commit into
mainfrom
yourtallness/dev_browser_query_params_for_ap

Conversation

@yourtallness

@yourtallnessyourtallness commented Aug 9, 2023

Copy link
Copy Markdown
Contributor

…detection util

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Packages affected

  • @clerk/clerk-js
  • @clerk/clerk-react
  • @clerk/nextjs
  • @clerk/remix
  • @clerk/types
  • @clerk/themes
  • @clerk/localizations
  • @clerk/clerk-expo
  • @clerk/backend
  • @clerk/clerk-sdk-node
  • @clerk/shared
  • @clerk/fastify
  • @clerk/chrome-extension
  • gatsby-plugin-clerk
  • build/tooling/chore

Description

To make the dev_browser JWT available to the SSR context on Account Portal, we need to pass the JWT via the query, not the hash.

The current PR detects whether the URL we are navigating to is an AP URL & passes the db JWT as a query param.

Also fixed the AP origin detection util, which did not cover kima instances (ported logic from our backend).

Adding @chanioxaris to help verify if the AP origin detection logic is accurate.

@changeset-bot

changeset-botBot commented Aug 9, 2023

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 9d54fe7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from 0144a11 to b9aa85dCompareAugust 9, 2023 12:25

@jit-cijit-ciBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Great news! Jit hasn't found any security issues in your PR. Good Job! 🏆

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from b9aa85d to e313934CompareAugust 9, 2023 15:02

@panteliselefpanteliselef left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me 💯 but maybe wait for Haris as requested

return res;
}

// Returns true for hosts such as:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe we should be a bit more strict with our checks here. For example we will return true for hostname accounts.foo.13.bar-1.lcl.dev which is wrong

});
}

// Returns true for hosts such as:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same here we can be more strict with our checks. For example we will return true for hostname foo.bar.13.whatever.accounts.dev which is wrong. Maybe use a regex instead?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking of a regex, but preferred to use the same logic as the BE has for this.

Note that this regex would also require that .clerk is not contained be contained and I'm a bit worried about using a negative lookahead (?!).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chanioxaris do you have any planned changes in mind that could break this check? I totally agree that we could make this stricter to be on the safe side... the example domain you provided is unlikely to be used by someone though - could we be missing any cases here?

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch 2 times, most recently from ba28b18 to 4f92750CompareAugust 11, 2023 14:18
Comment threadpackages/clerk-js/src/utils/url.ts Outdated

export const LEGACY_DEV_SUFFIXES = ['.lcl.dev', '.lclstage.dev', '.lclclerk.com'];

export const KIMA_DEV_SUFFIXES = ['.accounts.dev', '.accountstage.dev', '.accounts.lclclerk.com'];

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
exportconstKIMA_DEV_SUFFIXES=['.accounts.dev','.accountstage.dev','.accounts.lclclerk.com'];
exportconstDEV_SUFFIXES=['.accounts.dev','.accountstage.dev','.accounts.lclclerk.com'];

Kima was an internal project naming that shouldn't leak in the code.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will rename

Comment threadpackages/clerk-js/src/utils/url.ts Outdated
// * foo-bar-13.accounts.lclclerk.com
// But false for:
// * foo-bar-13.clerk.accounts.lclclerk.com
function isKimaDevAccountPortalOrigin(host: string): boolean {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ditto about Kima

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renamed

const hasQueryParam = (url || '').includes('?');
return `${url}${hasQueryParam ? '&' : '?'}${DEV_BROWSER_SSO_JWT_PARAMETER}=${(jwt || '').trim()}`;
// extract & strip existing jwt from hash
const jwtFromHash = extractDevBrowserJWTFromHash(resultURL.hash);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ Since this is the setDevBrowserJWTInURL method are we using extractDevBrowserJWTFromHash to make sure it's only set once?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, but it might be in the hash & we need to move it to search or vice versa.

@yourtallness
yourtallnessforce-pushed the yourtallness/dev_browser_query_params_for_ap branch from 4f92750 to 9d54fe7CompareAugust 14, 2023 16:25
@yourtallness
yourtallness merged commit 854aa38 into mainAug 14, 2023
@yourtallness
yourtallness deleted the yourtallness/dev_browser_query_params_for_ap branch August 14, 2023 16:53
@clerk-cookieclerk-cookie mentioned this pull request Aug 14, 2023
'accounts.dev',
];

export const LEGACY_DEV_SUFFIXES = ['.lcl.dev', '.lclstage.dev', '.lclclerk.com'];

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Adding a comment for posterity/ future reference mostly, this change needs to be made to all similar helpers until we revamp clerk/shared.

@clerk-cookie

Copy link
Copy Markdown
Collaborator

This PR has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@clerkclerk locked as resolved and limited conversation to collaborators Aug 24, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@yourtallness@clerk-cookie@SokratisVidros@nikosdouvlis@panteliselef@chanioxaris