Skip to content

PLT 155 - Introduce jwt signing js backend - #1786

Merged
Nikpolik merged 2 commits into
mainfrom
introduce-jwt-signing-js-backend
Oct 12, 2023
Merged

PLT 155 - Introduce jwt signing js backend#1786
Nikpolik merged 2 commits into
mainfrom
introduce-jwt-signing-js-backend

Conversation

@Nikpolik

@NikpolikNikpolik commented Sep 27, 2023

Copy link
Copy Markdown
Contributor

Description

Added a new signJwt(payload, secret, options) function to allow us to sign tokens.

Updated the hasValidSignature(jwt, secret) method to be able to verify tokens using PEM formatted keys.

The process for signing JWT was heavily inspired from another library cloudflare-worker-jwt and its sign method.

Quick overview of process for signing JWT

  1. JSON.stringify header and payload
  2. URL encode the two strings
  3. Create the first part of the token headerEncoded.payloadEncoded
  4. Import key
  5. Signing using the algorithm provided in the options and encode signature
  6. Return the final JWT headerEncoded.payloadEncoded.signature

Changes implemented

  1. Extract isomorphicAtob to separate file to reuse for key importing.
  2. Extract jwk to crypto algorithm mapping to separate file. This is will be shared between verify and sign.
  3. Create shared importKey function that handles multiple key formats.
  4. Use new importKey function inside hasValidSignature and verifyJWT also added tests for hasValidSignature.
  5. Implement signing procedure described above.
  6. Export new function.
  7. Added tests and updated docs.

Notes

  1. Since we only use RSASSA-PKCS1-v1_5 currently only added support for importing keys formatted jwk,pkcs8,spki and not raw.
  2. ~~signJwt was prefixed with unstable since its goal is to be used internally. ~~ marked with JSDocs that will be used internally
  3. Isomorphic atob could be imported from @clerk/shared (fix(shared, nextjs): Support importing @clerk/shared in @clerk/backend #1769)Done
  4. In the cloudflare-worker-jwt implementation of the sign method, the IAT (Issued at) field in the payload is updated. I am not sure if this is something that should be handled in the signing process or when we create the payload 🤔Changed to update IAT.
  5. verifyJWT method was not updated since it has its own implementation of hasValidSignature maybe it should use the updated one? This will allow us to use it PEM pem keys also.Fixed and removed duplicate (unused hasValidSignature)

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Packages affected

  • @clerk/clerk-js
  • @clerk/clerk-react
  • @clerk/nextjs
  • @clerk/remix
  • @clerk/types
  • @clerk/themes
  • @clerk/localizations
  • @clerk/clerk-expo
  • @clerk/backend
  • @clerk/clerk-sdk-node
  • @clerk/shared
  • @clerk/fastify
  • @clerk/chrome-extension
  • gatsby-plugin-clerk
  • build/tooling/chore

@NikpolikNikpolik self-assigned this Sep 27, 2023
@changeset-bot

changeset-botBot commented Sep 27, 2023

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: f47a6ba

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
NameType
@clerk/backendPatch
@clerk/fastifyPatch
gatsby-plugin-clerkPatch
@clerk/nextjsPatch
@clerk/remixPatch
@clerk/clerk-sdk-nodePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@SokratisVidrosSokratisVidros left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Nikpolik excellent PR description!

Can you please elaborate on the comment about iat? Is this about updating the iat of the token when we compute the signature?

Comment threadpackages/backend/src/shared/isomorphicAtob.ts Outdated
@Nikpolik

Nikpolik commented Sep 29, 2023

Copy link
Copy Markdown
ContributorAuthor

@Nikpolik excellent PR description!

Can you please elaborate on the comment about iat? Is this about updating the iat of the token when we compute the signature?

Basically overwrite the iat payload.iat = Math.floor(Date.now() / 1000) to make sure that the signed token always has the correct timestamp of when it was signed. After thinking about it more clearly I need to add.

@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch from 5f9a83c to 2016926CompareOctober 3, 2023 08:37
@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch 2 times, most recently from 51b07ba to 7e4189cCompareOctober 6, 2023 10:02
@Nikpolik
Nikpolik marked this pull request as ready for review October 6, 2023 10:05
@Nikpolik
Nikpolik requested a review from a team as a code ownerOctober 6, 2023 10:05
Comment threadpackages/backend/src/tokens/jwt/signJwt.test.ts Outdated

@georgepsarakisgeorgepsarakis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👏 Nice work! Overall seems fine to me, just not approving since I'm not so well-versed in JS/TS and there might be some subtle issue with crypto I'm missing.

Comment threadpackages/backend/src/tokens/fixtures.ts Outdated
export { __unstable__signJwt } from './signJwt';

export type { VerifyJwtOptions } from './verifyJwt';
export type { SignJwtOptions } from './signJwt';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ Does it make sense to prefix these options as unstable? Unlikely to be used, but only for semantics purposes.

Comment threadpackages/backend/src/tokens/jwt/signJwt.test.ts Outdated
Comment thread.changeset/cold-bags-watch.md Outdated
Comment threadpackages/backend/src/tokens/jwt/assertions.test.ts
Comment threadpackages/backend/src/tokens/jwt/signJwt.ts Outdated
Comment threadpackages/backend/src/tokens/jwt/signJwt.ts Outdated
Comment threadpackages/backend/src/tokens/jwt/algorithms.ts Outdated
@dimkl

Copy link
Copy Markdown
Contributor

Really nice work! 🚀

@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch 3 times, most recently from b5b367e to c251845CompareOctober 12, 2023 10:24
Nikos Polykandriotis added 2 commits October 12, 2023 14:28
Also extracted some functionality to scr/tokens/jwt/algorithms so it can
be reused in the future and added some spec. Removed constants and tests
for ES256, ES384, ES512
This method is marked as internal since it will be only used on other
clerk packages for now.
@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch from c251845 to f47a6baCompareOctober 12, 2023 11:31
@Nikpolik
Nikpolik added this pull request to the merge queue Oct 12, 2023
Merged via the queue into main with commit 13e9dfbOct 12, 2023
@Nikpolik
Nikpolik deleted the introduce-jwt-signing-js-backend branch October 12, 2023 12:14
@clerk-cookieclerk-cookie mentioned this pull request Oct 12, 2023
@clerk-cookie

Copy link
Copy Markdown
Collaborator

This PR has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@clerkclerk locked as resolved and limited conversation to collaborators Oct 12, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@Nikpolik@dimkl@clerk-cookie@georgepsarakis@SokratisVidros@nikosdouvlis
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
PLT 155 - Introduce jwt signing js backend by Nikpolik · Pull Request #1786 · clerk/javascript · GitHub
Skip to content

PLT 155 - Introduce jwt signing js backend - #1786

Merged
Nikpolik merged 2 commits into
mainfrom
introduce-jwt-signing-js-backend
Oct 12, 2023
Merged

PLT 155 - Introduce jwt signing js backend#1786
Nikpolik merged 2 commits into
mainfrom
introduce-jwt-signing-js-backend

Conversation

@Nikpolik

@NikpolikNikpolik commented Sep 27, 2023

Copy link
Copy Markdown
Contributor

Description

Added a new signJwt(payload, secret, options) function to allow us to sign tokens.

Updated the hasValidSignature(jwt, secret) method to be able to verify tokens using PEM formatted keys.

The process for signing JWT was heavily inspired from another library cloudflare-worker-jwt and its sign method.

Quick overview of process for signing JWT

  1. JSON.stringify header and payload
  2. URL encode the two strings
  3. Create the first part of the token headerEncoded.payloadEncoded
  4. Import key
  5. Signing using the algorithm provided in the options and encode signature
  6. Return the final JWT headerEncoded.payloadEncoded.signature

Changes implemented

  1. Extract isomorphicAtob to separate file to reuse for key importing.
  2. Extract jwk to crypto algorithm mapping to separate file. This is will be shared between verify and sign.
  3. Create shared importKey function that handles multiple key formats.
  4. Use new importKey function inside hasValidSignature and verifyJWT also added tests for hasValidSignature.
  5. Implement signing procedure described above.
  6. Export new function.
  7. Added tests and updated docs.

Notes

  1. Since we only use RSASSA-PKCS1-v1_5 currently only added support for importing keys formatted jwk,pkcs8,spki and not raw.
  2. ~~signJwt was prefixed with unstable since its goal is to be used internally. ~~ marked with JSDocs that will be used internally
  3. Isomorphic atob could be imported from @clerk/shared (fix(shared, nextjs): Support importing @clerk/shared in @clerk/backend #1769)Done
  4. In the cloudflare-worker-jwt implementation of the sign method, the IAT (Issued at) field in the payload is updated. I am not sure if this is something that should be handled in the signing process or when we create the payload 🤔Changed to update IAT.
  5. verifyJWT method was not updated since it has its own implementation of hasValidSignature maybe it should use the updated one? This will allow us to use it PEM pem keys also.Fixed and removed duplicate (unused hasValidSignature)

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Packages affected

  • @clerk/clerk-js
  • @clerk/clerk-react
  • @clerk/nextjs
  • @clerk/remix
  • @clerk/types
  • @clerk/themes
  • @clerk/localizations
  • @clerk/clerk-expo
  • @clerk/backend
  • @clerk/clerk-sdk-node
  • @clerk/shared
  • @clerk/fastify
  • @clerk/chrome-extension
  • gatsby-plugin-clerk
  • build/tooling/chore

@NikpolikNikpolik self-assigned this Sep 27, 2023
@changeset-bot

changeset-botBot commented Sep 27, 2023

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: f47a6ba

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
NameType
@clerk/backendPatch
@clerk/fastifyPatch
gatsby-plugin-clerkPatch
@clerk/nextjsPatch
@clerk/remixPatch
@clerk/clerk-sdk-nodePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@SokratisVidrosSokratisVidros left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Nikpolik excellent PR description!

Can you please elaborate on the comment about iat? Is this about updating the iat of the token when we compute the signature?

Comment threadpackages/backend/src/shared/isomorphicAtob.ts Outdated
@Nikpolik

Nikpolik commented Sep 29, 2023

Copy link
Copy Markdown
ContributorAuthor

@Nikpolik excellent PR description!

Can you please elaborate on the comment about iat? Is this about updating the iat of the token when we compute the signature?

Basically overwrite the iat payload.iat = Math.floor(Date.now() / 1000) to make sure that the signed token always has the correct timestamp of when it was signed. After thinking about it more clearly I need to add.

@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch from 5f9a83c to 2016926CompareOctober 3, 2023 08:37
@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch 2 times, most recently from 51b07ba to 7e4189cCompareOctober 6, 2023 10:02
@Nikpolik
Nikpolik marked this pull request as ready for review October 6, 2023 10:05
@Nikpolik
Nikpolik requested a review from a team as a code ownerOctober 6, 2023 10:05
Comment threadpackages/backend/src/tokens/jwt/signJwt.test.ts Outdated

@georgepsarakisgeorgepsarakis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👏 Nice work! Overall seems fine to me, just not approving since I'm not so well-versed in JS/TS and there might be some subtle issue with crypto I'm missing.

Comment threadpackages/backend/src/tokens/fixtures.ts Outdated
export { __unstable__signJwt } from './signJwt';

export type { VerifyJwtOptions } from './verifyJwt';
export type { SignJwtOptions } from './signJwt';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ Does it make sense to prefix these options as unstable? Unlikely to be used, but only for semantics purposes.

Comment threadpackages/backend/src/tokens/jwt/signJwt.test.ts Outdated
Comment thread.changeset/cold-bags-watch.md Outdated
Comment threadpackages/backend/src/tokens/jwt/assertions.test.ts
Comment threadpackages/backend/src/tokens/jwt/signJwt.ts Outdated
Comment threadpackages/backend/src/tokens/jwt/signJwt.ts Outdated
Comment threadpackages/backend/src/tokens/jwt/algorithms.ts Outdated
@dimkl

Copy link
Copy Markdown
Contributor

Really nice work! 🚀

@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch 3 times, most recently from b5b367e to c251845CompareOctober 12, 2023 10:24
Nikos Polykandriotis added 2 commits October 12, 2023 14:28
Also extracted some functionality to scr/tokens/jwt/algorithms so it can
be reused in the future and added some spec. Removed constants and tests
for ES256, ES384, ES512
This method is marked as internal since it will be only used on other
clerk packages for now.
@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch from c251845 to f47a6baCompareOctober 12, 2023 11:31
@Nikpolik
Nikpolik added this pull request to the merge queue Oct 12, 2023
Merged via the queue into main with commit 13e9dfbOct 12, 2023
@Nikpolik
Nikpolik deleted the introduce-jwt-signing-js-backend branch October 12, 2023 12:14
@clerk-cookieclerk-cookie mentioned this pull request Oct 12, 2023
@clerk-cookie

Copy link
Copy Markdown
Collaborator

This PR has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@clerkclerk locked as resolved and limited conversation to collaborators Oct 12, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@Nikpolik@dimkl@clerk-cookie@georgepsarakis@SokratisVidros@nikosdouvlis
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' PLT 155 - Introduce jwt signing js backend by Nikpolik · Pull Request #1786 · clerk/javascript · GitHub
Skip to content

PLT 155 - Introduce jwt signing js backend - #1786

Merged
Nikpolik merged 2 commits into
mainfrom
introduce-jwt-signing-js-backend
Oct 12, 2023
Merged

PLT 155 - Introduce jwt signing js backend#1786
Nikpolik merged 2 commits into
mainfrom
introduce-jwt-signing-js-backend

Conversation

@Nikpolik

@NikpolikNikpolik commented Sep 27, 2023

Copy link
Copy Markdown
Contributor

Description

Added a new signJwt(payload, secret, options) function to allow us to sign tokens.

Updated the hasValidSignature(jwt, secret) method to be able to verify tokens using PEM formatted keys.

The process for signing JWT was heavily inspired from another library cloudflare-worker-jwt and its sign method.

Quick overview of process for signing JWT

  1. JSON.stringify header and payload
  2. URL encode the two strings
  3. Create the first part of the token headerEncoded.payloadEncoded
  4. Import key
  5. Signing using the algorithm provided in the options and encode signature
  6. Return the final JWT headerEncoded.payloadEncoded.signature

Changes implemented

  1. Extract isomorphicAtob to separate file to reuse for key importing.
  2. Extract jwk to crypto algorithm mapping to separate file. This is will be shared between verify and sign.
  3. Create shared importKey function that handles multiple key formats.
  4. Use new importKey function inside hasValidSignature and verifyJWT also added tests for hasValidSignature.
  5. Implement signing procedure described above.
  6. Export new function.
  7. Added tests and updated docs.

Notes

  1. Since we only use RSASSA-PKCS1-v1_5 currently only added support for importing keys formatted jwk,pkcs8,spki and not raw.
  2. ~~signJwt was prefixed with unstable since its goal is to be used internally. ~~ marked with JSDocs that will be used internally
  3. Isomorphic atob could be imported from @clerk/shared (fix(shared, nextjs): Support importing @clerk/shared in @clerk/backend #1769)Done
  4. In the cloudflare-worker-jwt implementation of the sign method, the IAT (Issued at) field in the payload is updated. I am not sure if this is something that should be handled in the signing process or when we create the payload 🤔Changed to update IAT.
  5. verifyJWT method was not updated since it has its own implementation of hasValidSignature maybe it should use the updated one? This will allow us to use it PEM pem keys also.Fixed and removed duplicate (unused hasValidSignature)

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Packages affected

  • @clerk/clerk-js
  • @clerk/clerk-react
  • @clerk/nextjs
  • @clerk/remix
  • @clerk/types
  • @clerk/themes
  • @clerk/localizations
  • @clerk/clerk-expo
  • @clerk/backend
  • @clerk/clerk-sdk-node
  • @clerk/shared
  • @clerk/fastify
  • @clerk/chrome-extension
  • gatsby-plugin-clerk
  • build/tooling/chore

@NikpolikNikpolik self-assigned this Sep 27, 2023
@changeset-bot

changeset-botBot commented Sep 27, 2023

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: f47a6ba

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
NameType
@clerk/backendPatch
@clerk/fastifyPatch
gatsby-plugin-clerkPatch
@clerk/nextjsPatch
@clerk/remixPatch
@clerk/clerk-sdk-nodePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@SokratisVidrosSokratisVidros left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Nikpolik excellent PR description!

Can you please elaborate on the comment about iat? Is this about updating the iat of the token when we compute the signature?

Comment threadpackages/backend/src/shared/isomorphicAtob.ts Outdated
@Nikpolik

Nikpolik commented Sep 29, 2023

Copy link
Copy Markdown
ContributorAuthor

@Nikpolik excellent PR description!

Can you please elaborate on the comment about iat? Is this about updating the iat of the token when we compute the signature?

Basically overwrite the iat payload.iat = Math.floor(Date.now() / 1000) to make sure that the signed token always has the correct timestamp of when it was signed. After thinking about it more clearly I need to add.

@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch from 5f9a83c to 2016926CompareOctober 3, 2023 08:37
@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch 2 times, most recently from 51b07ba to 7e4189cCompareOctober 6, 2023 10:02
@Nikpolik
Nikpolik marked this pull request as ready for review October 6, 2023 10:05
@Nikpolik
Nikpolik requested a review from a team as a code ownerOctober 6, 2023 10:05
Comment threadpackages/backend/src/tokens/jwt/signJwt.test.ts Outdated

@georgepsarakisgeorgepsarakis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👏 Nice work! Overall seems fine to me, just not approving since I'm not so well-versed in JS/TS and there might be some subtle issue with crypto I'm missing.

Comment threadpackages/backend/src/tokens/fixtures.ts Outdated
export { __unstable__signJwt } from './signJwt';

export type { VerifyJwtOptions } from './verifyJwt';
export type { SignJwtOptions } from './signJwt';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ Does it make sense to prefix these options as unstable? Unlikely to be used, but only for semantics purposes.

Comment threadpackages/backend/src/tokens/jwt/signJwt.test.ts Outdated
Comment thread.changeset/cold-bags-watch.md Outdated
Comment threadpackages/backend/src/tokens/jwt/assertions.test.ts
Comment threadpackages/backend/src/tokens/jwt/signJwt.ts Outdated
Comment threadpackages/backend/src/tokens/jwt/signJwt.ts Outdated
Comment threadpackages/backend/src/tokens/jwt/algorithms.ts Outdated
@dimkl

Copy link
Copy Markdown
Contributor

Really nice work! 🚀

@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch 3 times, most recently from b5b367e to c251845CompareOctober 12, 2023 10:24
Nikos Polykandriotis added 2 commits October 12, 2023 14:28
Also extracted some functionality to scr/tokens/jwt/algorithms so it can
be reused in the future and added some spec. Removed constants and tests
for ES256, ES384, ES512
This method is marked as internal since it will be only used on other
clerk packages for now.
@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch from c251845 to f47a6baCompareOctober 12, 2023 11:31
@Nikpolik
Nikpolik added this pull request to the merge queue Oct 12, 2023
Merged via the queue into main with commit 13e9dfbOct 12, 2023
@Nikpolik
Nikpolik deleted the introduce-jwt-signing-js-backend branch October 12, 2023 12:14
@clerk-cookieclerk-cookie mentioned this pull request Oct 12, 2023
@clerk-cookie

Copy link
Copy Markdown
Collaborator

This PR has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@clerkclerk locked as resolved and limited conversation to collaborators Oct 12, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@Nikpolik@dimkl@clerk-cookie@georgepsarakis@SokratisVidros@nikosdouvlis
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' PLT 155 - Introduce jwt signing js backend by Nikpolik · Pull Request #1786 · clerk/javascript · GitHub
Skip to content

PLT 155 - Introduce jwt signing js backend - #1786

Merged
Nikpolik merged 2 commits into
mainfrom
introduce-jwt-signing-js-backend
Oct 12, 2023
Merged

PLT 155 - Introduce jwt signing js backend#1786
Nikpolik merged 2 commits into
mainfrom
introduce-jwt-signing-js-backend

Conversation

@Nikpolik

@NikpolikNikpolik commented Sep 27, 2023

Copy link
Copy Markdown
Contributor

Description

Added a new signJwt(payload, secret, options) function to allow us to sign tokens.

Updated the hasValidSignature(jwt, secret) method to be able to verify tokens using PEM formatted keys.

The process for signing JWT was heavily inspired from another library cloudflare-worker-jwt and its sign method.

Quick overview of process for signing JWT

  1. JSON.stringify header and payload
  2. URL encode the two strings
  3. Create the first part of the token headerEncoded.payloadEncoded
  4. Import key
  5. Signing using the algorithm provided in the options and encode signature
  6. Return the final JWT headerEncoded.payloadEncoded.signature

Changes implemented

  1. Extract isomorphicAtob to separate file to reuse for key importing.
  2. Extract jwk to crypto algorithm mapping to separate file. This is will be shared between verify and sign.
  3. Create shared importKey function that handles multiple key formats.
  4. Use new importKey function inside hasValidSignature and verifyJWT also added tests for hasValidSignature.
  5. Implement signing procedure described above.
  6. Export new function.
  7. Added tests and updated docs.

Notes

  1. Since we only use RSASSA-PKCS1-v1_5 currently only added support for importing keys formatted jwk,pkcs8,spki and not raw.
  2. ~~signJwt was prefixed with unstable since its goal is to be used internally. ~~ marked with JSDocs that will be used internally
  3. Isomorphic atob could be imported from @clerk/shared (fix(shared, nextjs): Support importing @clerk/shared in @clerk/backend #1769)Done
  4. In the cloudflare-worker-jwt implementation of the sign method, the IAT (Issued at) field in the payload is updated. I am not sure if this is something that should be handled in the signing process or when we create the payload 🤔Changed to update IAT.
  5. verifyJWT method was not updated since it has its own implementation of hasValidSignature maybe it should use the updated one? This will allow us to use it PEM pem keys also.Fixed and removed duplicate (unused hasValidSignature)

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Packages affected

  • @clerk/clerk-js
  • @clerk/clerk-react
  • @clerk/nextjs
  • @clerk/remix
  • @clerk/types
  • @clerk/themes
  • @clerk/localizations
  • @clerk/clerk-expo
  • @clerk/backend
  • @clerk/clerk-sdk-node
  • @clerk/shared
  • @clerk/fastify
  • @clerk/chrome-extension
  • gatsby-plugin-clerk
  • build/tooling/chore

@NikpolikNikpolik self-assigned this Sep 27, 2023
@changeset-bot

changeset-botBot commented Sep 27, 2023

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: f47a6ba

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
NameType
@clerk/backendPatch
@clerk/fastifyPatch
gatsby-plugin-clerkPatch
@clerk/nextjsPatch
@clerk/remixPatch
@clerk/clerk-sdk-nodePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@SokratisVidrosSokratisVidros left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Nikpolik excellent PR description!

Can you please elaborate on the comment about iat? Is this about updating the iat of the token when we compute the signature?

Comment threadpackages/backend/src/shared/isomorphicAtob.ts Outdated
@Nikpolik

Nikpolik commented Sep 29, 2023

Copy link
Copy Markdown
ContributorAuthor

@Nikpolik excellent PR description!

Can you please elaborate on the comment about iat? Is this about updating the iat of the token when we compute the signature?

Basically overwrite the iat payload.iat = Math.floor(Date.now() / 1000) to make sure that the signed token always has the correct timestamp of when it was signed. After thinking about it more clearly I need to add.

@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch from 5f9a83c to 2016926CompareOctober 3, 2023 08:37
@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch 2 times, most recently from 51b07ba to 7e4189cCompareOctober 6, 2023 10:02
@Nikpolik
Nikpolik marked this pull request as ready for review October 6, 2023 10:05
@Nikpolik
Nikpolik requested a review from a team as a code ownerOctober 6, 2023 10:05
Comment threadpackages/backend/src/tokens/jwt/signJwt.test.ts Outdated

@georgepsarakisgeorgepsarakis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👏 Nice work! Overall seems fine to me, just not approving since I'm not so well-versed in JS/TS and there might be some subtle issue with crypto I'm missing.

Comment threadpackages/backend/src/tokens/fixtures.ts Outdated
export { __unstable__signJwt } from './signJwt';

export type { VerifyJwtOptions } from './verifyJwt';
export type { SignJwtOptions } from './signJwt';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ Does it make sense to prefix these options as unstable? Unlikely to be used, but only for semantics purposes.

Comment threadpackages/backend/src/tokens/jwt/signJwt.test.ts Outdated
Comment thread.changeset/cold-bags-watch.md Outdated
Comment threadpackages/backend/src/tokens/jwt/assertions.test.ts
Comment threadpackages/backend/src/tokens/jwt/signJwt.ts Outdated
Comment threadpackages/backend/src/tokens/jwt/signJwt.ts Outdated
Comment threadpackages/backend/src/tokens/jwt/algorithms.ts Outdated
@dimkl

Copy link
Copy Markdown
Contributor

Really nice work! 🚀

@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch 3 times, most recently from b5b367e to c251845CompareOctober 12, 2023 10:24
Nikos Polykandriotis added 2 commits October 12, 2023 14:28
Also extracted some functionality to scr/tokens/jwt/algorithms so it can
be reused in the future and added some spec. Removed constants and tests
for ES256, ES384, ES512
This method is marked as internal since it will be only used on other
clerk packages for now.
@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch from c251845 to f47a6baCompareOctober 12, 2023 11:31
@Nikpolik
Nikpolik added this pull request to the merge queue Oct 12, 2023
Merged via the queue into main with commit 13e9dfbOct 12, 2023
@Nikpolik
Nikpolik deleted the introduce-jwt-signing-js-backend branch October 12, 2023 12:14
@clerk-cookieclerk-cookie mentioned this pull request Oct 12, 2023
@clerk-cookie

Copy link
Copy Markdown
Collaborator

This PR has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@clerkclerk locked as resolved and limited conversation to collaborators Oct 12, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@Nikpolik@dimkl@clerk-cookie@georgepsarakis@SokratisVidros@nikosdouvlis
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' PLT 155 - Introduce jwt signing js backend by Nikpolik · Pull Request #1786 · clerk/javascript · GitHub
Skip to content

PLT 155 - Introduce jwt signing js backend - #1786

Merged
Nikpolik merged 2 commits into
mainfrom
introduce-jwt-signing-js-backend
Oct 12, 2023
Merged

PLT 155 - Introduce jwt signing js backend#1786
Nikpolik merged 2 commits into
mainfrom
introduce-jwt-signing-js-backend

Conversation

@Nikpolik

@NikpolikNikpolik commented Sep 27, 2023

Copy link
Copy Markdown
Contributor

Description

Added a new signJwt(payload, secret, options) function to allow us to sign tokens.

Updated the hasValidSignature(jwt, secret) method to be able to verify tokens using PEM formatted keys.

The process for signing JWT was heavily inspired from another library cloudflare-worker-jwt and its sign method.

Quick overview of process for signing JWT

  1. JSON.stringify header and payload
  2. URL encode the two strings
  3. Create the first part of the token headerEncoded.payloadEncoded
  4. Import key
  5. Signing using the algorithm provided in the options and encode signature
  6. Return the final JWT headerEncoded.payloadEncoded.signature

Changes implemented

  1. Extract isomorphicAtob to separate file to reuse for key importing.
  2. Extract jwk to crypto algorithm mapping to separate file. This is will be shared between verify and sign.
  3. Create shared importKey function that handles multiple key formats.
  4. Use new importKey function inside hasValidSignature and verifyJWT also added tests for hasValidSignature.
  5. Implement signing procedure described above.
  6. Export new function.
  7. Added tests and updated docs.

Notes

  1. Since we only use RSASSA-PKCS1-v1_5 currently only added support for importing keys formatted jwk,pkcs8,spki and not raw.
  2. ~~signJwt was prefixed with unstable since its goal is to be used internally. ~~ marked with JSDocs that will be used internally
  3. Isomorphic atob could be imported from @clerk/shared (fix(shared, nextjs): Support importing @clerk/shared in @clerk/backend #1769)Done
  4. In the cloudflare-worker-jwt implementation of the sign method, the IAT (Issued at) field in the payload is updated. I am not sure if this is something that should be handled in the signing process or when we create the payload 🤔Changed to update IAT.
  5. verifyJWT method was not updated since it has its own implementation of hasValidSignature maybe it should use the updated one? This will allow us to use it PEM pem keys also.Fixed and removed duplicate (unused hasValidSignature)

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Packages affected

  • @clerk/clerk-js
  • @clerk/clerk-react
  • @clerk/nextjs
  • @clerk/remix
  • @clerk/types
  • @clerk/themes
  • @clerk/localizations
  • @clerk/clerk-expo
  • @clerk/backend
  • @clerk/clerk-sdk-node
  • @clerk/shared
  • @clerk/fastify
  • @clerk/chrome-extension
  • gatsby-plugin-clerk
  • build/tooling/chore

@NikpolikNikpolik self-assigned this Sep 27, 2023
@changeset-bot

changeset-botBot commented Sep 27, 2023

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: f47a6ba

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
NameType
@clerk/backendPatch
@clerk/fastifyPatch
gatsby-plugin-clerkPatch
@clerk/nextjsPatch
@clerk/remixPatch
@clerk/clerk-sdk-nodePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@SokratisVidrosSokratisVidros left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Nikpolik excellent PR description!

Can you please elaborate on the comment about iat? Is this about updating the iat of the token when we compute the signature?

Comment threadpackages/backend/src/shared/isomorphicAtob.ts Outdated
@Nikpolik

Nikpolik commented Sep 29, 2023

Copy link
Copy Markdown
ContributorAuthor

@Nikpolik excellent PR description!

Can you please elaborate on the comment about iat? Is this about updating the iat of the token when we compute the signature?

Basically overwrite the iat payload.iat = Math.floor(Date.now() / 1000) to make sure that the signed token always has the correct timestamp of when it was signed. After thinking about it more clearly I need to add.

@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch from 5f9a83c to 2016926CompareOctober 3, 2023 08:37
@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch 2 times, most recently from 51b07ba to 7e4189cCompareOctober 6, 2023 10:02
@Nikpolik
Nikpolik marked this pull request as ready for review October 6, 2023 10:05
@Nikpolik
Nikpolik requested a review from a team as a code ownerOctober 6, 2023 10:05
Comment threadpackages/backend/src/tokens/jwt/signJwt.test.ts Outdated

@georgepsarakisgeorgepsarakis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👏 Nice work! Overall seems fine to me, just not approving since I'm not so well-versed in JS/TS and there might be some subtle issue with crypto I'm missing.

Comment threadpackages/backend/src/tokens/fixtures.ts Outdated
export { __unstable__signJwt } from './signJwt';

export type { VerifyJwtOptions } from './verifyJwt';
export type { SignJwtOptions } from './signJwt';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ Does it make sense to prefix these options as unstable? Unlikely to be used, but only for semantics purposes.

Comment threadpackages/backend/src/tokens/jwt/signJwt.test.ts Outdated
Comment thread.changeset/cold-bags-watch.md Outdated
Comment threadpackages/backend/src/tokens/jwt/assertions.test.ts
Comment threadpackages/backend/src/tokens/jwt/signJwt.ts Outdated
Comment threadpackages/backend/src/tokens/jwt/signJwt.ts Outdated
Comment threadpackages/backend/src/tokens/jwt/algorithms.ts Outdated
@dimkl

Copy link
Copy Markdown
Contributor

Really nice work! 🚀

@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch 3 times, most recently from b5b367e to c251845CompareOctober 12, 2023 10:24
Nikos Polykandriotis added 2 commits October 12, 2023 14:28
Also extracted some functionality to scr/tokens/jwt/algorithms so it can
be reused in the future and added some spec. Removed constants and tests
for ES256, ES384, ES512
This method is marked as internal since it will be only used on other
clerk packages for now.
@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch from c251845 to f47a6baCompareOctober 12, 2023 11:31
@Nikpolik
Nikpolik added this pull request to the merge queue Oct 12, 2023
Merged via the queue into main with commit 13e9dfbOct 12, 2023
@Nikpolik
Nikpolik deleted the introduce-jwt-signing-js-backend branch October 12, 2023 12:14
@clerk-cookieclerk-cookie mentioned this pull request Oct 12, 2023
@clerk-cookie

Copy link
Copy Markdown
Collaborator

This PR has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@clerkclerk locked as resolved and limited conversation to collaborators Oct 12, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@Nikpolik@dimkl@clerk-cookie@georgepsarakis@SokratisVidros@nikosdouvlis
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' PLT 155 - Introduce jwt signing js backend by Nikpolik · Pull Request #1786 · clerk/javascript · GitHub
Skip to content

PLT 155 - Introduce jwt signing js backend - #1786

Merged
Nikpolik merged 2 commits into
mainfrom
introduce-jwt-signing-js-backend
Oct 12, 2023
Merged

PLT 155 - Introduce jwt signing js backend#1786
Nikpolik merged 2 commits into
mainfrom
introduce-jwt-signing-js-backend

Conversation

@Nikpolik

@NikpolikNikpolik commented Sep 27, 2023

Copy link
Copy Markdown
Contributor

Description

Added a new signJwt(payload, secret, options) function to allow us to sign tokens.

Updated the hasValidSignature(jwt, secret) method to be able to verify tokens using PEM formatted keys.

The process for signing JWT was heavily inspired from another library cloudflare-worker-jwt and its sign method.

Quick overview of process for signing JWT

  1. JSON.stringify header and payload
  2. URL encode the two strings
  3. Create the first part of the token headerEncoded.payloadEncoded
  4. Import key
  5. Signing using the algorithm provided in the options and encode signature
  6. Return the final JWT headerEncoded.payloadEncoded.signature

Changes implemented

  1. Extract isomorphicAtob to separate file to reuse for key importing.
  2. Extract jwk to crypto algorithm mapping to separate file. This is will be shared between verify and sign.
  3. Create shared importKey function that handles multiple key formats.
  4. Use new importKey function inside hasValidSignature and verifyJWT also added tests for hasValidSignature.
  5. Implement signing procedure described above.
  6. Export new function.
  7. Added tests and updated docs.

Notes

  1. Since we only use RSASSA-PKCS1-v1_5 currently only added support for importing keys formatted jwk,pkcs8,spki and not raw.
  2. ~~signJwt was prefixed with unstable since its goal is to be used internally. ~~ marked with JSDocs that will be used internally
  3. Isomorphic atob could be imported from @clerk/shared (fix(shared, nextjs): Support importing @clerk/shared in @clerk/backend #1769)Done
  4. In the cloudflare-worker-jwt implementation of the sign method, the IAT (Issued at) field in the payload is updated. I am not sure if this is something that should be handled in the signing process or when we create the payload 🤔Changed to update IAT.
  5. verifyJWT method was not updated since it has its own implementation of hasValidSignature maybe it should use the updated one? This will allow us to use it PEM pem keys also.Fixed and removed duplicate (unused hasValidSignature)

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Packages affected

  • @clerk/clerk-js
  • @clerk/clerk-react
  • @clerk/nextjs
  • @clerk/remix
  • @clerk/types
  • @clerk/themes
  • @clerk/localizations
  • @clerk/clerk-expo
  • @clerk/backend
  • @clerk/clerk-sdk-node
  • @clerk/shared
  • @clerk/fastify
  • @clerk/chrome-extension
  • gatsby-plugin-clerk
  • build/tooling/chore

@NikpolikNikpolik self-assigned this Sep 27, 2023
@changeset-bot

changeset-botBot commented Sep 27, 2023

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: f47a6ba

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
NameType
@clerk/backendPatch
@clerk/fastifyPatch
gatsby-plugin-clerkPatch
@clerk/nextjsPatch
@clerk/remixPatch
@clerk/clerk-sdk-nodePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@SokratisVidrosSokratisVidros left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Nikpolik excellent PR description!

Can you please elaborate on the comment about iat? Is this about updating the iat of the token when we compute the signature?

Comment threadpackages/backend/src/shared/isomorphicAtob.ts Outdated
@Nikpolik

Nikpolik commented Sep 29, 2023

Copy link
Copy Markdown
ContributorAuthor

@Nikpolik excellent PR description!

Can you please elaborate on the comment about iat? Is this about updating the iat of the token when we compute the signature?

Basically overwrite the iat payload.iat = Math.floor(Date.now() / 1000) to make sure that the signed token always has the correct timestamp of when it was signed. After thinking about it more clearly I need to add.

@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch from 5f9a83c to 2016926CompareOctober 3, 2023 08:37
@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch 2 times, most recently from 51b07ba to 7e4189cCompareOctober 6, 2023 10:02
@Nikpolik
Nikpolik marked this pull request as ready for review October 6, 2023 10:05
@Nikpolik
Nikpolik requested a review from a team as a code ownerOctober 6, 2023 10:05
Comment threadpackages/backend/src/tokens/jwt/signJwt.test.ts Outdated

@georgepsarakisgeorgepsarakis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👏 Nice work! Overall seems fine to me, just not approving since I'm not so well-versed in JS/TS and there might be some subtle issue with crypto I'm missing.

Comment threadpackages/backend/src/tokens/fixtures.ts Outdated
export { __unstable__signJwt } from './signJwt';

export type { VerifyJwtOptions } from './verifyJwt';
export type { SignJwtOptions } from './signJwt';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ Does it make sense to prefix these options as unstable? Unlikely to be used, but only for semantics purposes.

Comment threadpackages/backend/src/tokens/jwt/signJwt.test.ts Outdated
Comment thread.changeset/cold-bags-watch.md Outdated
Comment threadpackages/backend/src/tokens/jwt/assertions.test.ts
Comment threadpackages/backend/src/tokens/jwt/signJwt.ts Outdated
Comment threadpackages/backend/src/tokens/jwt/signJwt.ts Outdated
Comment threadpackages/backend/src/tokens/jwt/algorithms.ts Outdated
@dimkl

Copy link
Copy Markdown
Contributor

Really nice work! 🚀

@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch 3 times, most recently from b5b367e to c251845CompareOctober 12, 2023 10:24
Nikos Polykandriotis added 2 commits October 12, 2023 14:28
Also extracted some functionality to scr/tokens/jwt/algorithms so it can
be reused in the future and added some spec. Removed constants and tests
for ES256, ES384, ES512
This method is marked as internal since it will be only used on other
clerk packages for now.
@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch from c251845 to f47a6baCompareOctober 12, 2023 11:31
@Nikpolik
Nikpolik added this pull request to the merge queue Oct 12, 2023
Merged via the queue into main with commit 13e9dfbOct 12, 2023
@Nikpolik
Nikpolik deleted the introduce-jwt-signing-js-backend branch October 12, 2023 12:14
@clerk-cookieclerk-cookie mentioned this pull request Oct 12, 2023
@clerk-cookie

Copy link
Copy Markdown
Collaborator

This PR has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@clerkclerk locked as resolved and limited conversation to collaborators Oct 12, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@Nikpolik@dimkl@clerk-cookie@georgepsarakis@SokratisVidros@nikosdouvlis
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' PLT 155 - Introduce jwt signing js backend by Nikpolik · Pull Request #1786 · clerk/javascript · GitHub
Skip to content

PLT 155 - Introduce jwt signing js backend - #1786

Merged
Nikpolik merged 2 commits into
mainfrom
introduce-jwt-signing-js-backend
Oct 12, 2023
Merged

PLT 155 - Introduce jwt signing js backend#1786
Nikpolik merged 2 commits into
mainfrom
introduce-jwt-signing-js-backend

Conversation

@Nikpolik

@NikpolikNikpolik commented Sep 27, 2023

Copy link
Copy Markdown
Contributor

Description

Added a new signJwt(payload, secret, options) function to allow us to sign tokens.

Updated the hasValidSignature(jwt, secret) method to be able to verify tokens using PEM formatted keys.

The process for signing JWT was heavily inspired from another library cloudflare-worker-jwt and its sign method.

Quick overview of process for signing JWT

  1. JSON.stringify header and payload
  2. URL encode the two strings
  3. Create the first part of the token headerEncoded.payloadEncoded
  4. Import key
  5. Signing using the algorithm provided in the options and encode signature
  6. Return the final JWT headerEncoded.payloadEncoded.signature

Changes implemented

  1. Extract isomorphicAtob to separate file to reuse for key importing.
  2. Extract jwk to crypto algorithm mapping to separate file. This is will be shared between verify and sign.
  3. Create shared importKey function that handles multiple key formats.
  4. Use new importKey function inside hasValidSignature and verifyJWT also added tests for hasValidSignature.
  5. Implement signing procedure described above.
  6. Export new function.
  7. Added tests and updated docs.

Notes

  1. Since we only use RSASSA-PKCS1-v1_5 currently only added support for importing keys formatted jwk,pkcs8,spki and not raw.
  2. ~~signJwt was prefixed with unstable since its goal is to be used internally. ~~ marked with JSDocs that will be used internally
  3. Isomorphic atob could be imported from @clerk/shared (fix(shared, nextjs): Support importing @clerk/shared in @clerk/backend #1769)Done
  4. In the cloudflare-worker-jwt implementation of the sign method, the IAT (Issued at) field in the payload is updated. I am not sure if this is something that should be handled in the signing process or when we create the payload 🤔Changed to update IAT.
  5. verifyJWT method was not updated since it has its own implementation of hasValidSignature maybe it should use the updated one? This will allow us to use it PEM pem keys also.Fixed and removed duplicate (unused hasValidSignature)

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Packages affected

  • @clerk/clerk-js
  • @clerk/clerk-react
  • @clerk/nextjs
  • @clerk/remix
  • @clerk/types
  • @clerk/themes
  • @clerk/localizations
  • @clerk/clerk-expo
  • @clerk/backend
  • @clerk/clerk-sdk-node
  • @clerk/shared
  • @clerk/fastify
  • @clerk/chrome-extension
  • gatsby-plugin-clerk
  • build/tooling/chore

@NikpolikNikpolik self-assigned this Sep 27, 2023
@changeset-bot

changeset-botBot commented Sep 27, 2023

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: f47a6ba

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
NameType
@clerk/backendPatch
@clerk/fastifyPatch
gatsby-plugin-clerkPatch
@clerk/nextjsPatch
@clerk/remixPatch
@clerk/clerk-sdk-nodePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@SokratisVidrosSokratisVidros left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Nikpolik excellent PR description!

Can you please elaborate on the comment about iat? Is this about updating the iat of the token when we compute the signature?

Comment threadpackages/backend/src/shared/isomorphicAtob.ts Outdated
@Nikpolik

Nikpolik commented Sep 29, 2023

Copy link
Copy Markdown
ContributorAuthor

@Nikpolik excellent PR description!

Can you please elaborate on the comment about iat? Is this about updating the iat of the token when we compute the signature?

Basically overwrite the iat payload.iat = Math.floor(Date.now() / 1000) to make sure that the signed token always has the correct timestamp of when it was signed. After thinking about it more clearly I need to add.

@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch from 5f9a83c to 2016926CompareOctober 3, 2023 08:37
@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch 2 times, most recently from 51b07ba to 7e4189cCompareOctober 6, 2023 10:02
@Nikpolik
Nikpolik marked this pull request as ready for review October 6, 2023 10:05
@Nikpolik
Nikpolik requested a review from a team as a code ownerOctober 6, 2023 10:05
Comment threadpackages/backend/src/tokens/jwt/signJwt.test.ts Outdated

@georgepsarakisgeorgepsarakis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👏 Nice work! Overall seems fine to me, just not approving since I'm not so well-versed in JS/TS and there might be some subtle issue with crypto I'm missing.

Comment threadpackages/backend/src/tokens/fixtures.ts Outdated
export { __unstable__signJwt } from './signJwt';

export type { VerifyJwtOptions } from './verifyJwt';
export type { SignJwtOptions } from './signJwt';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ Does it make sense to prefix these options as unstable? Unlikely to be used, but only for semantics purposes.

Comment threadpackages/backend/src/tokens/jwt/signJwt.test.ts Outdated
Comment thread.changeset/cold-bags-watch.md Outdated
Comment threadpackages/backend/src/tokens/jwt/assertions.test.ts
Comment threadpackages/backend/src/tokens/jwt/signJwt.ts Outdated
Comment threadpackages/backend/src/tokens/jwt/signJwt.ts Outdated
Comment threadpackages/backend/src/tokens/jwt/algorithms.ts Outdated
@dimkl

Copy link
Copy Markdown
Contributor

Really nice work! 🚀

@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch 3 times, most recently from b5b367e to c251845CompareOctober 12, 2023 10:24
Nikos Polykandriotis added 2 commits October 12, 2023 14:28
Also extracted some functionality to scr/tokens/jwt/algorithms so it can
be reused in the future and added some spec. Removed constants and tests
for ES256, ES384, ES512
This method is marked as internal since it will be only used on other
clerk packages for now.
@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch from c251845 to f47a6baCompareOctober 12, 2023 11:31
@Nikpolik
Nikpolik added this pull request to the merge queue Oct 12, 2023
Merged via the queue into main with commit 13e9dfbOct 12, 2023
@Nikpolik
Nikpolik deleted the introduce-jwt-signing-js-backend branch October 12, 2023 12:14
@clerk-cookieclerk-cookie mentioned this pull request Oct 12, 2023
@clerk-cookie

Copy link
Copy Markdown
Collaborator

This PR has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@clerkclerk locked as resolved and limited conversation to collaborators Oct 12, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@Nikpolik@dimkl@clerk-cookie@georgepsarakis@SokratisVidros@nikosdouvlis
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); PLT 155 - Introduce jwt signing js backend by Nikpolik · Pull Request #1786 · clerk/javascript · GitHub
Skip to content

PLT 155 - Introduce jwt signing js backend - #1786

Merged
Nikpolik merged 2 commits into
mainfrom
introduce-jwt-signing-js-backend
Oct 12, 2023
Merged

PLT 155 - Introduce jwt signing js backend#1786
Nikpolik merged 2 commits into
mainfrom
introduce-jwt-signing-js-backend

Conversation

@Nikpolik

@NikpolikNikpolik commented Sep 27, 2023

Copy link
Copy Markdown
Contributor

Description

Added a new signJwt(payload, secret, options) function to allow us to sign tokens.

Updated the hasValidSignature(jwt, secret) method to be able to verify tokens using PEM formatted keys.

The process for signing JWT was heavily inspired from another library cloudflare-worker-jwt and its sign method.

Quick overview of process for signing JWT

  1. JSON.stringify header and payload
  2. URL encode the two strings
  3. Create the first part of the token headerEncoded.payloadEncoded
  4. Import key
  5. Signing using the algorithm provided in the options and encode signature
  6. Return the final JWT headerEncoded.payloadEncoded.signature

Changes implemented

  1. Extract isomorphicAtob to separate file to reuse for key importing.
  2. Extract jwk to crypto algorithm mapping to separate file. This is will be shared between verify and sign.
  3. Create shared importKey function that handles multiple key formats.
  4. Use new importKey function inside hasValidSignature and verifyJWT also added tests for hasValidSignature.
  5. Implement signing procedure described above.
  6. Export new function.
  7. Added tests and updated docs.

Notes

  1. Since we only use RSASSA-PKCS1-v1_5 currently only added support for importing keys formatted jwk,pkcs8,spki and not raw.
  2. ~~signJwt was prefixed with unstable since its goal is to be used internally. ~~ marked with JSDocs that will be used internally
  3. Isomorphic atob could be imported from @clerk/shared (fix(shared, nextjs): Support importing @clerk/shared in @clerk/backend #1769)Done
  4. In the cloudflare-worker-jwt implementation of the sign method, the IAT (Issued at) field in the payload is updated. I am not sure if this is something that should be handled in the signing process or when we create the payload 🤔Changed to update IAT.
  5. verifyJWT method was not updated since it has its own implementation of hasValidSignature maybe it should use the updated one? This will allow us to use it PEM pem keys also.Fixed and removed duplicate (unused hasValidSignature)

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Packages affected

  • @clerk/clerk-js
  • @clerk/clerk-react
  • @clerk/nextjs
  • @clerk/remix
  • @clerk/types
  • @clerk/themes
  • @clerk/localizations
  • @clerk/clerk-expo
  • @clerk/backend
  • @clerk/clerk-sdk-node
  • @clerk/shared
  • @clerk/fastify
  • @clerk/chrome-extension
  • gatsby-plugin-clerk
  • build/tooling/chore

@NikpolikNikpolik self-assigned this Sep 27, 2023
@changeset-bot

changeset-botBot commented Sep 27, 2023

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: f47a6ba

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
NameType
@clerk/backendPatch
@clerk/fastifyPatch
gatsby-plugin-clerkPatch
@clerk/nextjsPatch
@clerk/remixPatch
@clerk/clerk-sdk-nodePatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@SokratisVidrosSokratisVidros left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Nikpolik excellent PR description!

Can you please elaborate on the comment about iat? Is this about updating the iat of the token when we compute the signature?

Comment threadpackages/backend/src/shared/isomorphicAtob.ts Outdated
@Nikpolik

Nikpolik commented Sep 29, 2023

Copy link
Copy Markdown
ContributorAuthor

@Nikpolik excellent PR description!

Can you please elaborate on the comment about iat? Is this about updating the iat of the token when we compute the signature?

Basically overwrite the iat payload.iat = Math.floor(Date.now() / 1000) to make sure that the signed token always has the correct timestamp of when it was signed. After thinking about it more clearly I need to add.

@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch from 5f9a83c to 2016926CompareOctober 3, 2023 08:37
@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch 2 times, most recently from 51b07ba to 7e4189cCompareOctober 6, 2023 10:02
@Nikpolik
Nikpolik marked this pull request as ready for review October 6, 2023 10:05
@Nikpolik
Nikpolik requested a review from a team as a code ownerOctober 6, 2023 10:05
Comment threadpackages/backend/src/tokens/jwt/signJwt.test.ts Outdated

@georgepsarakisgeorgepsarakis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👏 Nice work! Overall seems fine to me, just not approving since I'm not so well-versed in JS/TS and there might be some subtle issue with crypto I'm missing.

Comment threadpackages/backend/src/tokens/fixtures.ts Outdated
export { __unstable__signJwt } from './signJwt';

export type { VerifyJwtOptions } from './verifyJwt';
export type { SignJwtOptions } from './signJwt';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ Does it make sense to prefix these options as unstable? Unlikely to be used, but only for semantics purposes.

Comment threadpackages/backend/src/tokens/jwt/signJwt.test.ts Outdated
Comment thread.changeset/cold-bags-watch.md Outdated
Comment threadpackages/backend/src/tokens/jwt/assertions.test.ts
Comment threadpackages/backend/src/tokens/jwt/signJwt.ts Outdated
Comment threadpackages/backend/src/tokens/jwt/signJwt.ts Outdated
Comment threadpackages/backend/src/tokens/jwt/algorithms.ts Outdated
@dimkl

Copy link
Copy Markdown
Contributor

Really nice work! 🚀

@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch 3 times, most recently from b5b367e to c251845CompareOctober 12, 2023 10:24
Nikos Polykandriotis added 2 commits October 12, 2023 14:28
Also extracted some functionality to scr/tokens/jwt/algorithms so it can
be reused in the future and added some spec. Removed constants and tests
for ES256, ES384, ES512
This method is marked as internal since it will be only used on other
clerk packages for now.
@Nikpolik
Nikpolikforce-pushed the introduce-jwt-signing-js-backend branch from c251845 to f47a6baCompareOctober 12, 2023 11:31
@Nikpolik
Nikpolik added this pull request to the merge queue Oct 12, 2023
Merged via the queue into main with commit 13e9dfbOct 12, 2023
@Nikpolik
Nikpolik deleted the introduce-jwt-signing-js-backend branch October 12, 2023 12:14
@clerk-cookieclerk-cookie mentioned this pull request Oct 12, 2023
@clerk-cookie

Copy link
Copy Markdown
Collaborator

This PR has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@clerkclerk locked as resolved and limited conversation to collaborators Oct 12, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@Nikpolik@dimkl@clerk-cookie@georgepsarakis@SokratisVidros@nikosdouvlis