fix(clerk-sdk-node): Inherit verifyToken options from clerkClient - #3296

Merged
panteliselef merged 8 commits into
mainfrom
elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification
May 10, 2024
Merged

fix(clerk-sdk-node): Inherit verifyToken options from clerkClient#3296
panteliselef merged 8 commits into
mainfrom
elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification

Conversation

@panteliselef

@panteliselefpanteliselef commented May 1, 2024

Copy link
Copy Markdown
Contributor

Description

This PR allows clerkClient.verifyToken from "@clerk/clerk-sdk-node" to inherit the VerifyTokenOptions set when clerkClient is instantiated.

Added an additional error when both jwtKey and secretKey are missing.

fixes#3283

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@panteliselefpanteliselef self-assigned this May 1, 2024
@changeset-bot

changeset-botBot commented May 1, 2024

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5782b00

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
NameType
@clerk/clerk-sdk-nodePatch
@clerk/backendPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/remixPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@panteliselef

Copy link
Copy Markdown
ContributorAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @panteliselef - the snapshot version command generated the following package versions:

PackageVersion
@clerk/backend1.1.2-snapshot.v9a7208b
@clerk/chrome-extension1.0.4-snapshot.v9a7208b
@clerk/clerk-js5.2.1-snapshot.v9a7208b
@clerk/clerk-expo1.0.4-snapshot.v9a7208b
@clerk/express0.0.5-snapshot.v9a7208b
@clerk/fastify1.0.4-snapshot.v9a7208b
gatsby-plugin-clerk5.0.0-beta.45
@clerk/nextjs5.0.5-snapshot.v9a7208b
@clerk/remix4.0.4-snapshot.v9a7208b
@clerk/clerk-sdk-node5.0.4-snapshot.v9a7208b

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/backend

npm i @clerk/backend@1.1.2-snapshot.v9a7208b --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@1.0.4-snapshot.v9a7208b --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.2.1-snapshot.v9a7208b --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@1.0.4-snapshot.v9a7208b --save-exact

@clerk/express

npm i @clerk/express@0.0.5-snapshot.v9a7208b --save-exact

@clerk/fastify

npm i @clerk/fastify@1.0.4-snapshot.v9a7208b --save-exact

gatsby-plugin-clerk

npm i gatsby-plugin-clerk@5.0.0-beta.45 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@5.0.5-snapshot.v9a7208b --save-exact

@clerk/remix

npm i @clerk/remix@4.0.4-snapshot.v9a7208b --save-exact

@clerk/clerk-sdk-node

npm i @clerk/clerk-sdk-node@5.0.4-snapshot.v9a7208b --save-exact

@panteliselef
panteliselef requested a review from brkalowMay 1, 2024 12:36
Comment on lines +34 to +45
if (!options.secretKey || !options.jwtKey) {
return {
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkSecretKey,
message: 'Both JWT Key and Secret Key are missing. Operation could not be completed.',
reason: TokenVerificationErrorReason.InvalidSecretKey,
}),
],
};
}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we think that this is a breaking change ? Tbh i think we can skip its introduction

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could also just throw a warning instead so we don't introduce a breaking change

Comment thread.changeset/modern-boxes-peel.md Outdated
```ts
import { clerkClient } from "@clerk/clerk-sdk-node";

clerkClient.verifyToken(token, {})

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only reason, i've not update the signature is that this package will be deprecated.

@dimkldimkl left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

☁️ I understand that the customer use case is valid and that we probably need to make a change to clerkClient.verifyToken(token, options) to support execution without passing options but i am not 100% sure that we should make it this way.
I would expect to either keep it as is and inform the customers using it explicitly that it's just a re-export from the @clerk/backend and all the arguments required should be passed. or support the following:

import{clerkClient}from"@clerk/clerk-sdk-node";// case #1: use options passed in clerkClientclerkClient.verifyToken(token)// case #2: options should be non-conflicting with the ones passed in clerkClient// as it does not make sense to have a different jwtKey set in the clerkClient and a different one used in verifyTokenclerkClient.verifyToken(token,options)

If they need to pass explicitly the options i would advise to either create a different clerkClient or use the verifytoken from the @clerk/backend.
I think we should go for ONLY the 1st case. We should check if the @clerk/express supports the same API and make the appropriate changes there.
cc: @nikosdouvlis

@panteliselef

Copy link
Copy Markdown
ContributorAuthor

@dimkl
Regarding case 1, Completely dropping the 2nd params, wouldn't that be a breaking change ?

If we are going the extra mile here, let's still support the 2nd param, but update the signature so that 2nd param is optional. It is the least disruptive solution.

Your suggestions make sense, but I would skip them for this package and only apply them to the new express package

Comment threadpackages/backend/src/tokens/verify.ts Outdated
@shadoworion

Copy link
Copy Markdown
Contributor

☁️ I understand that the customer use case is valid and that we probably need to make a change to clerkClient.verifyToken(token, options) to support execution without passing options but i am not 100% sure that we should make it this way. I would expect to either keep it as is and inform the customers using it explicitly that it's just a re-export from the @clerk/backend and all the arguments required should be passed. or support the following:

import{clerkClient}from"@clerk/clerk-sdk-node";// case #1: use options passed in clerkClientclerkClient.verifyToken(token)// case #2: options should be non-conflicting with the ones passed in clerkClient// as it does not make sense to have a different jwtKey set in the clerkClient and a different one used in verifyTokenclerkClient.verifyToken(token,options)

If they need to pass explicitly the options i would advise to either create a different clerkClient or use the verifytoken from the @clerk/backend. I think we should go for ONLY the 1st case. We should check if the @clerk/express supports the same API and make the appropriate changes there. cc: @nikosdouvlis

Hi, I use this function to create auth middleware for the "graphql-yoga" server. All options are default and secret from env (which doesn't work now), so "case #1" fits better.

If I use different options that conflict with the current "clerkClient," I'll use "createClerkClient" to create a new one (that also doesn't work now)

return (...args: Parameters<VerifyTokenWithOptionalSecondArgument>) =>
_verifyToken(args[0], {
...params,
...args[1],

@dimkldimklMay 10, 2024

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔧 Could you add 2 tests (with options, without options) to verify that everything works as expected?

Comment on lines -6 to -11
const mockNext = jest.fn();

afterEach(() => {
mockNext.mockReset();
});

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dimkl fyi, Just cleaning this up

@panteliselef
panteliselefforce-pushed the elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification branch from fd50eea to 1afcdcdCompareMay 10, 2024 17:24
@panteliselef
panteliselef enabled auto-merge (squash) May 10, 2024 18:36
@panteliselef
panteliselef merged commit b924022 into mainMay 10, 2024
@panteliselef
panteliselef deleted the elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification branch May 10, 2024 18:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Node SDK]: Failed to resolve JWK during verification

5 participants

@panteliselef@clerk-cookie@shadoworion@dimkl@octoper
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(clerk-sdk-node): Inherit verifyToken options from clerkClient - #3296

Merged
panteliselef merged 8 commits into
mainfrom
elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification
May 10, 2024
Merged

fix(clerk-sdk-node): Inherit verifyToken options from clerkClient#3296
panteliselef merged 8 commits into
mainfrom
elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification

Conversation

@panteliselef

@panteliselefpanteliselef commented May 1, 2024

Copy link
Copy Markdown
Contributor

Description

This PR allows clerkClient.verifyToken from "@clerk/clerk-sdk-node" to inherit the VerifyTokenOptions set when clerkClient is instantiated.

Added an additional error when both jwtKey and secretKey are missing.

fixes#3283

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@panteliselefpanteliselef self-assigned this May 1, 2024
@changeset-bot

changeset-botBot commented May 1, 2024

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5782b00

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
NameType
@clerk/clerk-sdk-nodePatch
@clerk/backendPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/remixPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@panteliselef

Copy link
Copy Markdown
ContributorAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @panteliselef - the snapshot version command generated the following package versions:

PackageVersion
@clerk/backend1.1.2-snapshot.v9a7208b
@clerk/chrome-extension1.0.4-snapshot.v9a7208b
@clerk/clerk-js5.2.1-snapshot.v9a7208b
@clerk/clerk-expo1.0.4-snapshot.v9a7208b
@clerk/express0.0.5-snapshot.v9a7208b
@clerk/fastify1.0.4-snapshot.v9a7208b
gatsby-plugin-clerk5.0.0-beta.45
@clerk/nextjs5.0.5-snapshot.v9a7208b
@clerk/remix4.0.4-snapshot.v9a7208b
@clerk/clerk-sdk-node5.0.4-snapshot.v9a7208b

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/backend

npm i @clerk/backend@1.1.2-snapshot.v9a7208b --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@1.0.4-snapshot.v9a7208b --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.2.1-snapshot.v9a7208b --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@1.0.4-snapshot.v9a7208b --save-exact

@clerk/express

npm i @clerk/express@0.0.5-snapshot.v9a7208b --save-exact

@clerk/fastify

npm i @clerk/fastify@1.0.4-snapshot.v9a7208b --save-exact

gatsby-plugin-clerk

npm i gatsby-plugin-clerk@5.0.0-beta.45 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@5.0.5-snapshot.v9a7208b --save-exact

@clerk/remix

npm i @clerk/remix@4.0.4-snapshot.v9a7208b --save-exact

@clerk/clerk-sdk-node

npm i @clerk/clerk-sdk-node@5.0.4-snapshot.v9a7208b --save-exact

@panteliselef
panteliselef requested a review from brkalowMay 1, 2024 12:36
Comment on lines +34 to +45
if (!options.secretKey || !options.jwtKey) {
return {
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkSecretKey,
message: 'Both JWT Key and Secret Key are missing. Operation could not be completed.',
reason: TokenVerificationErrorReason.InvalidSecretKey,
}),
],
};
}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we think that this is a breaking change ? Tbh i think we can skip its introduction

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could also just throw a warning instead so we don't introduce a breaking change

Comment thread.changeset/modern-boxes-peel.md Outdated
```ts
import { clerkClient } from "@clerk/clerk-sdk-node";

clerkClient.verifyToken(token, {})

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only reason, i've not update the signature is that this package will be deprecated.

@dimkldimkl left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

☁️ I understand that the customer use case is valid and that we probably need to make a change to clerkClient.verifyToken(token, options) to support execution without passing options but i am not 100% sure that we should make it this way.
I would expect to either keep it as is and inform the customers using it explicitly that it's just a re-export from the @clerk/backend and all the arguments required should be passed. or support the following:

import{clerkClient}from"@clerk/clerk-sdk-node";// case #1: use options passed in clerkClientclerkClient.verifyToken(token)// case #2: options should be non-conflicting with the ones passed in clerkClient// as it does not make sense to have a different jwtKey set in the clerkClient and a different one used in verifyTokenclerkClient.verifyToken(token,options)

If they need to pass explicitly the options i would advise to either create a different clerkClient or use the verifytoken from the @clerk/backend.
I think we should go for ONLY the 1st case. We should check if the @clerk/express supports the same API and make the appropriate changes there.
cc: @nikosdouvlis

@panteliselef

Copy link
Copy Markdown
ContributorAuthor

@dimkl
Regarding case 1, Completely dropping the 2nd params, wouldn't that be a breaking change ?

If we are going the extra mile here, let's still support the 2nd param, but update the signature so that 2nd param is optional. It is the least disruptive solution.

Your suggestions make sense, but I would skip them for this package and only apply them to the new express package

Comment threadpackages/backend/src/tokens/verify.ts Outdated
@shadoworion

Copy link
Copy Markdown
Contributor

☁️ I understand that the customer use case is valid and that we probably need to make a change to clerkClient.verifyToken(token, options) to support execution without passing options but i am not 100% sure that we should make it this way. I would expect to either keep it as is and inform the customers using it explicitly that it's just a re-export from the @clerk/backend and all the arguments required should be passed. or support the following:

import{clerkClient}from"@clerk/clerk-sdk-node";// case #1: use options passed in clerkClientclerkClient.verifyToken(token)// case #2: options should be non-conflicting with the ones passed in clerkClient// as it does not make sense to have a different jwtKey set in the clerkClient and a different one used in verifyTokenclerkClient.verifyToken(token,options)

If they need to pass explicitly the options i would advise to either create a different clerkClient or use the verifytoken from the @clerk/backend. I think we should go for ONLY the 1st case. We should check if the @clerk/express supports the same API and make the appropriate changes there. cc: @nikosdouvlis

Hi, I use this function to create auth middleware for the "graphql-yoga" server. All options are default and secret from env (which doesn't work now), so "case #1" fits better.

If I use different options that conflict with the current "clerkClient," I'll use "createClerkClient" to create a new one (that also doesn't work now)

return (...args: Parameters<VerifyTokenWithOptionalSecondArgument>) =>
_verifyToken(args[0], {
...params,
...args[1],

@dimkldimklMay 10, 2024

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔧 Could you add 2 tests (with options, without options) to verify that everything works as expected?

Comment on lines -6 to -11
const mockNext = jest.fn();

afterEach(() => {
mockNext.mockReset();
});

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dimkl fyi, Just cleaning this up

@panteliselef
panteliselefforce-pushed the elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification branch from fd50eea to 1afcdcdCompareMay 10, 2024 17:24
@panteliselef
panteliselef enabled auto-merge (squash) May 10, 2024 18:36
@panteliselef
panteliselef merged commit b924022 into mainMay 10, 2024
@panteliselef
panteliselef deleted the elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification branch May 10, 2024 18:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Node SDK]: Failed to resolve JWK during verification

5 participants

@panteliselef@clerk-cookie@shadoworion@dimkl@octoper
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-sdk-node): Inherit verifyToken options from clerkClient - #3296

Merged
panteliselef merged 8 commits into
mainfrom
elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification
May 10, 2024
Merged

fix(clerk-sdk-node): Inherit verifyToken options from clerkClient#3296
panteliselef merged 8 commits into
mainfrom
elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification

Conversation

@panteliselef

@panteliselefpanteliselef commented May 1, 2024

Copy link
Copy Markdown
Contributor

Description

This PR allows clerkClient.verifyToken from "@clerk/clerk-sdk-node" to inherit the VerifyTokenOptions set when clerkClient is instantiated.

Added an additional error when both jwtKey and secretKey are missing.

fixes#3283

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@panteliselefpanteliselef self-assigned this May 1, 2024
@changeset-bot

changeset-botBot commented May 1, 2024

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5782b00

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
NameType
@clerk/clerk-sdk-nodePatch
@clerk/backendPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/remixPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@panteliselef

Copy link
Copy Markdown
ContributorAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @panteliselef - the snapshot version command generated the following package versions:

PackageVersion
@clerk/backend1.1.2-snapshot.v9a7208b
@clerk/chrome-extension1.0.4-snapshot.v9a7208b
@clerk/clerk-js5.2.1-snapshot.v9a7208b
@clerk/clerk-expo1.0.4-snapshot.v9a7208b
@clerk/express0.0.5-snapshot.v9a7208b
@clerk/fastify1.0.4-snapshot.v9a7208b
gatsby-plugin-clerk5.0.0-beta.45
@clerk/nextjs5.0.5-snapshot.v9a7208b
@clerk/remix4.0.4-snapshot.v9a7208b
@clerk/clerk-sdk-node5.0.4-snapshot.v9a7208b

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/backend

npm i @clerk/backend@1.1.2-snapshot.v9a7208b --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@1.0.4-snapshot.v9a7208b --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.2.1-snapshot.v9a7208b --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@1.0.4-snapshot.v9a7208b --save-exact

@clerk/express

npm i @clerk/express@0.0.5-snapshot.v9a7208b --save-exact

@clerk/fastify

npm i @clerk/fastify@1.0.4-snapshot.v9a7208b --save-exact

gatsby-plugin-clerk

npm i gatsby-plugin-clerk@5.0.0-beta.45 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@5.0.5-snapshot.v9a7208b --save-exact

@clerk/remix

npm i @clerk/remix@4.0.4-snapshot.v9a7208b --save-exact

@clerk/clerk-sdk-node

npm i @clerk/clerk-sdk-node@5.0.4-snapshot.v9a7208b --save-exact

@panteliselef
panteliselef requested a review from brkalowMay 1, 2024 12:36
Comment on lines +34 to +45
if (!options.secretKey || !options.jwtKey) {
return {
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkSecretKey,
message: 'Both JWT Key and Secret Key are missing. Operation could not be completed.',
reason: TokenVerificationErrorReason.InvalidSecretKey,
}),
],
};
}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we think that this is a breaking change ? Tbh i think we can skip its introduction

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could also just throw a warning instead so we don't introduce a breaking change

Comment thread.changeset/modern-boxes-peel.md Outdated
```ts
import { clerkClient } from "@clerk/clerk-sdk-node";

clerkClient.verifyToken(token, {})

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only reason, i've not update the signature is that this package will be deprecated.

@dimkldimkl left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

☁️ I understand that the customer use case is valid and that we probably need to make a change to clerkClient.verifyToken(token, options) to support execution without passing options but i am not 100% sure that we should make it this way.
I would expect to either keep it as is and inform the customers using it explicitly that it's just a re-export from the @clerk/backend and all the arguments required should be passed. or support the following:

import{clerkClient}from"@clerk/clerk-sdk-node";// case #1: use options passed in clerkClientclerkClient.verifyToken(token)// case #2: options should be non-conflicting with the ones passed in clerkClient// as it does not make sense to have a different jwtKey set in the clerkClient and a different one used in verifyTokenclerkClient.verifyToken(token,options)

If they need to pass explicitly the options i would advise to either create a different clerkClient or use the verifytoken from the @clerk/backend.
I think we should go for ONLY the 1st case. We should check if the @clerk/express supports the same API and make the appropriate changes there.
cc: @nikosdouvlis

@panteliselef

Copy link
Copy Markdown
ContributorAuthor

@dimkl
Regarding case 1, Completely dropping the 2nd params, wouldn't that be a breaking change ?

If we are going the extra mile here, let's still support the 2nd param, but update the signature so that 2nd param is optional. It is the least disruptive solution.

Your suggestions make sense, but I would skip them for this package and only apply them to the new express package

Comment threadpackages/backend/src/tokens/verify.ts Outdated
@shadoworion

Copy link
Copy Markdown
Contributor

☁️ I understand that the customer use case is valid and that we probably need to make a change to clerkClient.verifyToken(token, options) to support execution without passing options but i am not 100% sure that we should make it this way. I would expect to either keep it as is and inform the customers using it explicitly that it's just a re-export from the @clerk/backend and all the arguments required should be passed. or support the following:

import{clerkClient}from"@clerk/clerk-sdk-node";// case #1: use options passed in clerkClientclerkClient.verifyToken(token)// case #2: options should be non-conflicting with the ones passed in clerkClient// as it does not make sense to have a different jwtKey set in the clerkClient and a different one used in verifyTokenclerkClient.verifyToken(token,options)

If they need to pass explicitly the options i would advise to either create a different clerkClient or use the verifytoken from the @clerk/backend. I think we should go for ONLY the 1st case. We should check if the @clerk/express supports the same API and make the appropriate changes there. cc: @nikosdouvlis

Hi, I use this function to create auth middleware for the "graphql-yoga" server. All options are default and secret from env (which doesn't work now), so "case #1" fits better.

If I use different options that conflict with the current "clerkClient," I'll use "createClerkClient" to create a new one (that also doesn't work now)

return (...args: Parameters<VerifyTokenWithOptionalSecondArgument>) =>
_verifyToken(args[0], {
...params,
...args[1],

@dimkldimklMay 10, 2024

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔧 Could you add 2 tests (with options, without options) to verify that everything works as expected?

Comment on lines -6 to -11
const mockNext = jest.fn();

afterEach(() => {
mockNext.mockReset();
});

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dimkl fyi, Just cleaning this up

@panteliselef
panteliselefforce-pushed the elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification branch from fd50eea to 1afcdcdCompareMay 10, 2024 17:24
@panteliselef
panteliselef enabled auto-merge (squash) May 10, 2024 18:36
@panteliselef
panteliselef merged commit b924022 into mainMay 10, 2024
@panteliselef
panteliselef deleted the elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification branch May 10, 2024 18:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Node SDK]: Failed to resolve JWK during verification

5 participants

@panteliselef@clerk-cookie@shadoworion@dimkl@octoper
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-sdk-node): Inherit verifyToken options from clerkClient - #3296

Merged
panteliselef merged 8 commits into
mainfrom
elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification
May 10, 2024
Merged

fix(clerk-sdk-node): Inherit verifyToken options from clerkClient#3296
panteliselef merged 8 commits into
mainfrom
elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification

Conversation

@panteliselef

@panteliselefpanteliselef commented May 1, 2024

Copy link
Copy Markdown
Contributor

Description

This PR allows clerkClient.verifyToken from "@clerk/clerk-sdk-node" to inherit the VerifyTokenOptions set when clerkClient is instantiated.

Added an additional error when both jwtKey and secretKey are missing.

fixes#3283

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@panteliselefpanteliselef self-assigned this May 1, 2024
@changeset-bot

changeset-botBot commented May 1, 2024

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5782b00

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
NameType
@clerk/clerk-sdk-nodePatch
@clerk/backendPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/remixPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@panteliselef

Copy link
Copy Markdown
ContributorAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @panteliselef - the snapshot version command generated the following package versions:

PackageVersion
@clerk/backend1.1.2-snapshot.v9a7208b
@clerk/chrome-extension1.0.4-snapshot.v9a7208b
@clerk/clerk-js5.2.1-snapshot.v9a7208b
@clerk/clerk-expo1.0.4-snapshot.v9a7208b
@clerk/express0.0.5-snapshot.v9a7208b
@clerk/fastify1.0.4-snapshot.v9a7208b
gatsby-plugin-clerk5.0.0-beta.45
@clerk/nextjs5.0.5-snapshot.v9a7208b
@clerk/remix4.0.4-snapshot.v9a7208b
@clerk/clerk-sdk-node5.0.4-snapshot.v9a7208b

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/backend

npm i @clerk/backend@1.1.2-snapshot.v9a7208b --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@1.0.4-snapshot.v9a7208b --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.2.1-snapshot.v9a7208b --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@1.0.4-snapshot.v9a7208b --save-exact

@clerk/express

npm i @clerk/express@0.0.5-snapshot.v9a7208b --save-exact

@clerk/fastify

npm i @clerk/fastify@1.0.4-snapshot.v9a7208b --save-exact

gatsby-plugin-clerk

npm i gatsby-plugin-clerk@5.0.0-beta.45 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@5.0.5-snapshot.v9a7208b --save-exact

@clerk/remix

npm i @clerk/remix@4.0.4-snapshot.v9a7208b --save-exact

@clerk/clerk-sdk-node

npm i @clerk/clerk-sdk-node@5.0.4-snapshot.v9a7208b --save-exact

@panteliselef
panteliselef requested a review from brkalowMay 1, 2024 12:36
Comment on lines +34 to +45
if (!options.secretKey || !options.jwtKey) {
return {
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkSecretKey,
message: 'Both JWT Key and Secret Key are missing. Operation could not be completed.',
reason: TokenVerificationErrorReason.InvalidSecretKey,
}),
],
};
}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we think that this is a breaking change ? Tbh i think we can skip its introduction

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could also just throw a warning instead so we don't introduce a breaking change

Comment thread.changeset/modern-boxes-peel.md Outdated
```ts
import { clerkClient } from "@clerk/clerk-sdk-node";

clerkClient.verifyToken(token, {})

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only reason, i've not update the signature is that this package will be deprecated.

@dimkldimkl left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

☁️ I understand that the customer use case is valid and that we probably need to make a change to clerkClient.verifyToken(token, options) to support execution without passing options but i am not 100% sure that we should make it this way.
I would expect to either keep it as is and inform the customers using it explicitly that it's just a re-export from the @clerk/backend and all the arguments required should be passed. or support the following:

import{clerkClient}from"@clerk/clerk-sdk-node";// case #1: use options passed in clerkClientclerkClient.verifyToken(token)// case #2: options should be non-conflicting with the ones passed in clerkClient// as it does not make sense to have a different jwtKey set in the clerkClient and a different one used in verifyTokenclerkClient.verifyToken(token,options)

If they need to pass explicitly the options i would advise to either create a different clerkClient or use the verifytoken from the @clerk/backend.
I think we should go for ONLY the 1st case. We should check if the @clerk/express supports the same API and make the appropriate changes there.
cc: @nikosdouvlis

@panteliselef

Copy link
Copy Markdown
ContributorAuthor

@dimkl
Regarding case 1, Completely dropping the 2nd params, wouldn't that be a breaking change ?

If we are going the extra mile here, let's still support the 2nd param, but update the signature so that 2nd param is optional. It is the least disruptive solution.

Your suggestions make sense, but I would skip them for this package and only apply them to the new express package

Comment threadpackages/backend/src/tokens/verify.ts Outdated
@shadoworion

Copy link
Copy Markdown
Contributor

☁️ I understand that the customer use case is valid and that we probably need to make a change to clerkClient.verifyToken(token, options) to support execution without passing options but i am not 100% sure that we should make it this way. I would expect to either keep it as is and inform the customers using it explicitly that it's just a re-export from the @clerk/backend and all the arguments required should be passed. or support the following:

import{clerkClient}from"@clerk/clerk-sdk-node";// case #1: use options passed in clerkClientclerkClient.verifyToken(token)// case #2: options should be non-conflicting with the ones passed in clerkClient// as it does not make sense to have a different jwtKey set in the clerkClient and a different one used in verifyTokenclerkClient.verifyToken(token,options)

If they need to pass explicitly the options i would advise to either create a different clerkClient or use the verifytoken from the @clerk/backend. I think we should go for ONLY the 1st case. We should check if the @clerk/express supports the same API and make the appropriate changes there. cc: @nikosdouvlis

Hi, I use this function to create auth middleware for the "graphql-yoga" server. All options are default and secret from env (which doesn't work now), so "case #1" fits better.

If I use different options that conflict with the current "clerkClient," I'll use "createClerkClient" to create a new one (that also doesn't work now)

return (...args: Parameters<VerifyTokenWithOptionalSecondArgument>) =>
_verifyToken(args[0], {
...params,
...args[1],

@dimkldimklMay 10, 2024

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔧 Could you add 2 tests (with options, without options) to verify that everything works as expected?

Comment on lines -6 to -11
const mockNext = jest.fn();

afterEach(() => {
mockNext.mockReset();
});

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dimkl fyi, Just cleaning this up

@panteliselef
panteliselefforce-pushed the elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification branch from fd50eea to 1afcdcdCompareMay 10, 2024 17:24
@panteliselef
panteliselef enabled auto-merge (squash) May 10, 2024 18:36
@panteliselef
panteliselef merged commit b924022 into mainMay 10, 2024
@panteliselef
panteliselef deleted the elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification branch May 10, 2024 18:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Node SDK]: Failed to resolve JWK during verification

5 participants

@panteliselef@clerk-cookie@shadoworion@dimkl@octoper
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(clerk-sdk-node): Inherit verifyToken options from clerkClient - #3296

Merged
panteliselef merged 8 commits into
mainfrom
elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification
May 10, 2024
Merged

fix(clerk-sdk-node): Inherit verifyToken options from clerkClient#3296
panteliselef merged 8 commits into
mainfrom
elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification

Conversation

@panteliselef

@panteliselefpanteliselef commented May 1, 2024

Copy link
Copy Markdown
Contributor

Description

This PR allows clerkClient.verifyToken from "@clerk/clerk-sdk-node" to inherit the VerifyTokenOptions set when clerkClient is instantiated.

Added an additional error when both jwtKey and secretKey are missing.

fixes#3283

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@panteliselefpanteliselef self-assigned this May 1, 2024
@changeset-bot

changeset-botBot commented May 1, 2024

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5782b00

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
NameType
@clerk/clerk-sdk-nodePatch
@clerk/backendPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/remixPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@panteliselef

Copy link
Copy Markdown
ContributorAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @panteliselef - the snapshot version command generated the following package versions:

PackageVersion
@clerk/backend1.1.2-snapshot.v9a7208b
@clerk/chrome-extension1.0.4-snapshot.v9a7208b
@clerk/clerk-js5.2.1-snapshot.v9a7208b
@clerk/clerk-expo1.0.4-snapshot.v9a7208b
@clerk/express0.0.5-snapshot.v9a7208b
@clerk/fastify1.0.4-snapshot.v9a7208b
gatsby-plugin-clerk5.0.0-beta.45
@clerk/nextjs5.0.5-snapshot.v9a7208b
@clerk/remix4.0.4-snapshot.v9a7208b
@clerk/clerk-sdk-node5.0.4-snapshot.v9a7208b

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/backend

npm i @clerk/backend@1.1.2-snapshot.v9a7208b --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@1.0.4-snapshot.v9a7208b --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.2.1-snapshot.v9a7208b --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@1.0.4-snapshot.v9a7208b --save-exact

@clerk/express

npm i @clerk/express@0.0.5-snapshot.v9a7208b --save-exact

@clerk/fastify

npm i @clerk/fastify@1.0.4-snapshot.v9a7208b --save-exact

gatsby-plugin-clerk

npm i gatsby-plugin-clerk@5.0.0-beta.45 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@5.0.5-snapshot.v9a7208b --save-exact

@clerk/remix

npm i @clerk/remix@4.0.4-snapshot.v9a7208b --save-exact

@clerk/clerk-sdk-node

npm i @clerk/clerk-sdk-node@5.0.4-snapshot.v9a7208b --save-exact

@panteliselef
panteliselef requested a review from brkalowMay 1, 2024 12:36
Comment on lines +34 to +45
if (!options.secretKey || !options.jwtKey) {
return {
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkSecretKey,
message: 'Both JWT Key and Secret Key are missing. Operation could not be completed.',
reason: TokenVerificationErrorReason.InvalidSecretKey,
}),
],
};
}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we think that this is a breaking change ? Tbh i think we can skip its introduction

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could also just throw a warning instead so we don't introduce a breaking change

Comment thread.changeset/modern-boxes-peel.md Outdated
```ts
import { clerkClient } from "@clerk/clerk-sdk-node";

clerkClient.verifyToken(token, {})

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only reason, i've not update the signature is that this package will be deprecated.

@dimkldimkl left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

☁️ I understand that the customer use case is valid and that we probably need to make a change to clerkClient.verifyToken(token, options) to support execution without passing options but i am not 100% sure that we should make it this way.
I would expect to either keep it as is and inform the customers using it explicitly that it's just a re-export from the @clerk/backend and all the arguments required should be passed. or support the following:

import{clerkClient}from"@clerk/clerk-sdk-node";// case #1: use options passed in clerkClientclerkClient.verifyToken(token)// case #2: options should be non-conflicting with the ones passed in clerkClient// as it does not make sense to have a different jwtKey set in the clerkClient and a different one used in verifyTokenclerkClient.verifyToken(token,options)

If they need to pass explicitly the options i would advise to either create a different clerkClient or use the verifytoken from the @clerk/backend.
I think we should go for ONLY the 1st case. We should check if the @clerk/express supports the same API and make the appropriate changes there.
cc: @nikosdouvlis

@panteliselef

Copy link
Copy Markdown
ContributorAuthor

@dimkl
Regarding case 1, Completely dropping the 2nd params, wouldn't that be a breaking change ?

If we are going the extra mile here, let's still support the 2nd param, but update the signature so that 2nd param is optional. It is the least disruptive solution.

Your suggestions make sense, but I would skip them for this package and only apply them to the new express package

Comment threadpackages/backend/src/tokens/verify.ts Outdated
@shadoworion

Copy link
Copy Markdown
Contributor

☁️ I understand that the customer use case is valid and that we probably need to make a change to clerkClient.verifyToken(token, options) to support execution without passing options but i am not 100% sure that we should make it this way. I would expect to either keep it as is and inform the customers using it explicitly that it's just a re-export from the @clerk/backend and all the arguments required should be passed. or support the following:

import{clerkClient}from"@clerk/clerk-sdk-node";// case #1: use options passed in clerkClientclerkClient.verifyToken(token)// case #2: options should be non-conflicting with the ones passed in clerkClient// as it does not make sense to have a different jwtKey set in the clerkClient and a different one used in verifyTokenclerkClient.verifyToken(token,options)

If they need to pass explicitly the options i would advise to either create a different clerkClient or use the verifytoken from the @clerk/backend. I think we should go for ONLY the 1st case. We should check if the @clerk/express supports the same API and make the appropriate changes there. cc: @nikosdouvlis

Hi, I use this function to create auth middleware for the "graphql-yoga" server. All options are default and secret from env (which doesn't work now), so "case #1" fits better.

If I use different options that conflict with the current "clerkClient," I'll use "createClerkClient" to create a new one (that also doesn't work now)

return (...args: Parameters<VerifyTokenWithOptionalSecondArgument>) =>
_verifyToken(args[0], {
...params,
...args[1],

@dimkldimklMay 10, 2024

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔧 Could you add 2 tests (with options, without options) to verify that everything works as expected?

Comment on lines -6 to -11
const mockNext = jest.fn();

afterEach(() => {
mockNext.mockReset();
});

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dimkl fyi, Just cleaning this up

@panteliselef
panteliselefforce-pushed the elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification branch from fd50eea to 1afcdcdCompareMay 10, 2024 17:24
@panteliselef
panteliselef enabled auto-merge (squash) May 10, 2024 18:36
@panteliselef
panteliselef merged commit b924022 into mainMay 10, 2024
@panteliselef
panteliselef deleted the elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification branch May 10, 2024 18:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Node SDK]: Failed to resolve JWK during verification

5 participants

@panteliselef@clerk-cookie@shadoworion@dimkl@octoper
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-sdk-node): Inherit verifyToken options from clerkClient - #3296

Merged
panteliselef merged 8 commits into
mainfrom
elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification
May 10, 2024
Merged

fix(clerk-sdk-node): Inherit verifyToken options from clerkClient#3296
panteliselef merged 8 commits into
mainfrom
elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification

Conversation

@panteliselef

@panteliselefpanteliselef commented May 1, 2024

Copy link
Copy Markdown
Contributor

Description

This PR allows clerkClient.verifyToken from "@clerk/clerk-sdk-node" to inherit the VerifyTokenOptions set when clerkClient is instantiated.

Added an additional error when both jwtKey and secretKey are missing.

fixes#3283

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@panteliselefpanteliselef self-assigned this May 1, 2024
@changeset-bot

changeset-botBot commented May 1, 2024

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5782b00

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
NameType
@clerk/clerk-sdk-nodePatch
@clerk/backendPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/remixPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@panteliselef

Copy link
Copy Markdown
ContributorAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @panteliselef - the snapshot version command generated the following package versions:

PackageVersion
@clerk/backend1.1.2-snapshot.v9a7208b
@clerk/chrome-extension1.0.4-snapshot.v9a7208b
@clerk/clerk-js5.2.1-snapshot.v9a7208b
@clerk/clerk-expo1.0.4-snapshot.v9a7208b
@clerk/express0.0.5-snapshot.v9a7208b
@clerk/fastify1.0.4-snapshot.v9a7208b
gatsby-plugin-clerk5.0.0-beta.45
@clerk/nextjs5.0.5-snapshot.v9a7208b
@clerk/remix4.0.4-snapshot.v9a7208b
@clerk/clerk-sdk-node5.0.4-snapshot.v9a7208b

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/backend

npm i @clerk/backend@1.1.2-snapshot.v9a7208b --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@1.0.4-snapshot.v9a7208b --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.2.1-snapshot.v9a7208b --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@1.0.4-snapshot.v9a7208b --save-exact

@clerk/express

npm i @clerk/express@0.0.5-snapshot.v9a7208b --save-exact

@clerk/fastify

npm i @clerk/fastify@1.0.4-snapshot.v9a7208b --save-exact

gatsby-plugin-clerk

npm i gatsby-plugin-clerk@5.0.0-beta.45 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@5.0.5-snapshot.v9a7208b --save-exact

@clerk/remix

npm i @clerk/remix@4.0.4-snapshot.v9a7208b --save-exact

@clerk/clerk-sdk-node

npm i @clerk/clerk-sdk-node@5.0.4-snapshot.v9a7208b --save-exact

@panteliselef
panteliselef requested a review from brkalowMay 1, 2024 12:36
Comment on lines +34 to +45
if (!options.secretKey || !options.jwtKey) {
return {
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkSecretKey,
message: 'Both JWT Key and Secret Key are missing. Operation could not be completed.',
reason: TokenVerificationErrorReason.InvalidSecretKey,
}),
],
};
}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we think that this is a breaking change ? Tbh i think we can skip its introduction

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could also just throw a warning instead so we don't introduce a breaking change

Comment thread.changeset/modern-boxes-peel.md Outdated
```ts
import { clerkClient } from "@clerk/clerk-sdk-node";

clerkClient.verifyToken(token, {})

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only reason, i've not update the signature is that this package will be deprecated.

@dimkldimkl left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

☁️ I understand that the customer use case is valid and that we probably need to make a change to clerkClient.verifyToken(token, options) to support execution without passing options but i am not 100% sure that we should make it this way.
I would expect to either keep it as is and inform the customers using it explicitly that it's just a re-export from the @clerk/backend and all the arguments required should be passed. or support the following:

import{clerkClient}from"@clerk/clerk-sdk-node";// case #1: use options passed in clerkClientclerkClient.verifyToken(token)// case #2: options should be non-conflicting with the ones passed in clerkClient// as it does not make sense to have a different jwtKey set in the clerkClient and a different one used in verifyTokenclerkClient.verifyToken(token,options)

If they need to pass explicitly the options i would advise to either create a different clerkClient or use the verifytoken from the @clerk/backend.
I think we should go for ONLY the 1st case. We should check if the @clerk/express supports the same API and make the appropriate changes there.
cc: @nikosdouvlis

@panteliselef

Copy link
Copy Markdown
ContributorAuthor

@dimkl
Regarding case 1, Completely dropping the 2nd params, wouldn't that be a breaking change ?

If we are going the extra mile here, let's still support the 2nd param, but update the signature so that 2nd param is optional. It is the least disruptive solution.

Your suggestions make sense, but I would skip them for this package and only apply them to the new express package

Comment threadpackages/backend/src/tokens/verify.ts Outdated
@shadoworion

Copy link
Copy Markdown
Contributor

☁️ I understand that the customer use case is valid and that we probably need to make a change to clerkClient.verifyToken(token, options) to support execution without passing options but i am not 100% sure that we should make it this way. I would expect to either keep it as is and inform the customers using it explicitly that it's just a re-export from the @clerk/backend and all the arguments required should be passed. or support the following:

import{clerkClient}from"@clerk/clerk-sdk-node";// case #1: use options passed in clerkClientclerkClient.verifyToken(token)// case #2: options should be non-conflicting with the ones passed in clerkClient// as it does not make sense to have a different jwtKey set in the clerkClient and a different one used in verifyTokenclerkClient.verifyToken(token,options)

If they need to pass explicitly the options i would advise to either create a different clerkClient or use the verifytoken from the @clerk/backend. I think we should go for ONLY the 1st case. We should check if the @clerk/express supports the same API and make the appropriate changes there. cc: @nikosdouvlis

Hi, I use this function to create auth middleware for the "graphql-yoga" server. All options are default and secret from env (which doesn't work now), so "case #1" fits better.

If I use different options that conflict with the current "clerkClient," I'll use "createClerkClient" to create a new one (that also doesn't work now)

return (...args: Parameters<VerifyTokenWithOptionalSecondArgument>) =>
_verifyToken(args[0], {
...params,
...args[1],

@dimkldimklMay 10, 2024

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔧 Could you add 2 tests (with options, without options) to verify that everything works as expected?

Comment on lines -6 to -11
const mockNext = jest.fn();

afterEach(() => {
mockNext.mockReset();
});

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dimkl fyi, Just cleaning this up

@panteliselef
panteliselefforce-pushed the elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification branch from fd50eea to 1afcdcdCompareMay 10, 2024 17:24
@panteliselef
panteliselef enabled auto-merge (squash) May 10, 2024 18:36
@panteliselef
panteliselef merged commit b924022 into mainMay 10, 2024
@panteliselef
panteliselef deleted the elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification branch May 10, 2024 18:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Node SDK]: Failed to resolve JWK during verification

5 participants

@panteliselef@clerk-cookie@shadoworion@dimkl@octoper
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-sdk-node): Inherit verifyToken options from clerkClient - #3296

Merged
panteliselef merged 8 commits into
mainfrom
elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification
May 10, 2024
Merged

fix(clerk-sdk-node): Inherit verifyToken options from clerkClient#3296
panteliselef merged 8 commits into
mainfrom
elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification

Conversation

@panteliselef

@panteliselefpanteliselef commented May 1, 2024

Copy link
Copy Markdown
Contributor

Description

This PR allows clerkClient.verifyToken from "@clerk/clerk-sdk-node" to inherit the VerifyTokenOptions set when clerkClient is instantiated.

Added an additional error when both jwtKey and secretKey are missing.

fixes#3283

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@panteliselefpanteliselef self-assigned this May 1, 2024
@changeset-bot

changeset-botBot commented May 1, 2024

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5782b00

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
NameType
@clerk/clerk-sdk-nodePatch
@clerk/backendPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/remixPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@panteliselef

Copy link
Copy Markdown
ContributorAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @panteliselef - the snapshot version command generated the following package versions:

PackageVersion
@clerk/backend1.1.2-snapshot.v9a7208b
@clerk/chrome-extension1.0.4-snapshot.v9a7208b
@clerk/clerk-js5.2.1-snapshot.v9a7208b
@clerk/clerk-expo1.0.4-snapshot.v9a7208b
@clerk/express0.0.5-snapshot.v9a7208b
@clerk/fastify1.0.4-snapshot.v9a7208b
gatsby-plugin-clerk5.0.0-beta.45
@clerk/nextjs5.0.5-snapshot.v9a7208b
@clerk/remix4.0.4-snapshot.v9a7208b
@clerk/clerk-sdk-node5.0.4-snapshot.v9a7208b

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/backend

npm i @clerk/backend@1.1.2-snapshot.v9a7208b --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@1.0.4-snapshot.v9a7208b --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.2.1-snapshot.v9a7208b --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@1.0.4-snapshot.v9a7208b --save-exact

@clerk/express

npm i @clerk/express@0.0.5-snapshot.v9a7208b --save-exact

@clerk/fastify

npm i @clerk/fastify@1.0.4-snapshot.v9a7208b --save-exact

gatsby-plugin-clerk

npm i gatsby-plugin-clerk@5.0.0-beta.45 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@5.0.5-snapshot.v9a7208b --save-exact

@clerk/remix

npm i @clerk/remix@4.0.4-snapshot.v9a7208b --save-exact

@clerk/clerk-sdk-node

npm i @clerk/clerk-sdk-node@5.0.4-snapshot.v9a7208b --save-exact

@panteliselef
panteliselef requested a review from brkalowMay 1, 2024 12:36
Comment on lines +34 to +45
if (!options.secretKey || !options.jwtKey) {
return {
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkSecretKey,
message: 'Both JWT Key and Secret Key are missing. Operation could not be completed.',
reason: TokenVerificationErrorReason.InvalidSecretKey,
}),
],
};
}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we think that this is a breaking change ? Tbh i think we can skip its introduction

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could also just throw a warning instead so we don't introduce a breaking change

Comment thread.changeset/modern-boxes-peel.md Outdated
```ts
import { clerkClient } from "@clerk/clerk-sdk-node";

clerkClient.verifyToken(token, {})

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only reason, i've not update the signature is that this package will be deprecated.

@dimkldimkl left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

☁️ I understand that the customer use case is valid and that we probably need to make a change to clerkClient.verifyToken(token, options) to support execution without passing options but i am not 100% sure that we should make it this way.
I would expect to either keep it as is and inform the customers using it explicitly that it's just a re-export from the @clerk/backend and all the arguments required should be passed. or support the following:

import{clerkClient}from"@clerk/clerk-sdk-node";// case #1: use options passed in clerkClientclerkClient.verifyToken(token)// case #2: options should be non-conflicting with the ones passed in clerkClient// as it does not make sense to have a different jwtKey set in the clerkClient and a different one used in verifyTokenclerkClient.verifyToken(token,options)

If they need to pass explicitly the options i would advise to either create a different clerkClient or use the verifytoken from the @clerk/backend.
I think we should go for ONLY the 1st case. We should check if the @clerk/express supports the same API and make the appropriate changes there.
cc: @nikosdouvlis

@panteliselef

Copy link
Copy Markdown
ContributorAuthor

@dimkl
Regarding case 1, Completely dropping the 2nd params, wouldn't that be a breaking change ?

If we are going the extra mile here, let's still support the 2nd param, but update the signature so that 2nd param is optional. It is the least disruptive solution.

Your suggestions make sense, but I would skip them for this package and only apply them to the new express package

Comment threadpackages/backend/src/tokens/verify.ts Outdated
@shadoworion

Copy link
Copy Markdown
Contributor

☁️ I understand that the customer use case is valid and that we probably need to make a change to clerkClient.verifyToken(token, options) to support execution without passing options but i am not 100% sure that we should make it this way. I would expect to either keep it as is and inform the customers using it explicitly that it's just a re-export from the @clerk/backend and all the arguments required should be passed. or support the following:

import{clerkClient}from"@clerk/clerk-sdk-node";// case #1: use options passed in clerkClientclerkClient.verifyToken(token)// case #2: options should be non-conflicting with the ones passed in clerkClient// as it does not make sense to have a different jwtKey set in the clerkClient and a different one used in verifyTokenclerkClient.verifyToken(token,options)

If they need to pass explicitly the options i would advise to either create a different clerkClient or use the verifytoken from the @clerk/backend. I think we should go for ONLY the 1st case. We should check if the @clerk/express supports the same API and make the appropriate changes there. cc: @nikosdouvlis

Hi, I use this function to create auth middleware for the "graphql-yoga" server. All options are default and secret from env (which doesn't work now), so "case #1" fits better.

If I use different options that conflict with the current "clerkClient," I'll use "createClerkClient" to create a new one (that also doesn't work now)

return (...args: Parameters<VerifyTokenWithOptionalSecondArgument>) =>
_verifyToken(args[0], {
...params,
...args[1],

@dimkldimklMay 10, 2024

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔧 Could you add 2 tests (with options, without options) to verify that everything works as expected?

Comment on lines -6 to -11
const mockNext = jest.fn();

afterEach(() => {
mockNext.mockReset();
});

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dimkl fyi, Just cleaning this up

@panteliselef
panteliselefforce-pushed the elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification branch from fd50eea to 1afcdcdCompareMay 10, 2024 17:24
@panteliselef
panteliselef enabled auto-merge (squash) May 10, 2024 18:36
@panteliselef
panteliselef merged commit b924022 into mainMay 10, 2024
@panteliselef
panteliselef deleted the elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification branch May 10, 2024 18:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Node SDK]: Failed to resolve JWK during verification

5 participants

@panteliselef@clerk-cookie@shadoworion@dimkl@octoper
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(clerk-sdk-node): Inherit verifyToken options from clerkClient - #3296

Merged
panteliselef merged 8 commits into
mainfrom
elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification
May 10, 2024
Merged

fix(clerk-sdk-node): Inherit verifyToken options from clerkClient#3296
panteliselef merged 8 commits into
mainfrom
elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification

Conversation

@panteliselef

@panteliselefpanteliselef commented May 1, 2024

Copy link
Copy Markdown
Contributor

Description

This PR allows clerkClient.verifyToken from "@clerk/clerk-sdk-node" to inherit the VerifyTokenOptions set when clerkClient is instantiated.

Added an additional error when both jwtKey and secretKey are missing.

fixes#3283

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@panteliselefpanteliselef self-assigned this May 1, 2024
@changeset-bot

changeset-botBot commented May 1, 2024

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5782b00

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 6 packages
NameType
@clerk/clerk-sdk-nodePatch
@clerk/backendPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/remixPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@panteliselef

Copy link
Copy Markdown
ContributorAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @panteliselef - the snapshot version command generated the following package versions:

PackageVersion
@clerk/backend1.1.2-snapshot.v9a7208b
@clerk/chrome-extension1.0.4-snapshot.v9a7208b
@clerk/clerk-js5.2.1-snapshot.v9a7208b
@clerk/clerk-expo1.0.4-snapshot.v9a7208b
@clerk/express0.0.5-snapshot.v9a7208b
@clerk/fastify1.0.4-snapshot.v9a7208b
gatsby-plugin-clerk5.0.0-beta.45
@clerk/nextjs5.0.5-snapshot.v9a7208b
@clerk/remix4.0.4-snapshot.v9a7208b
@clerk/clerk-sdk-node5.0.4-snapshot.v9a7208b

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/backend

npm i @clerk/backend@1.1.2-snapshot.v9a7208b --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@1.0.4-snapshot.v9a7208b --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.2.1-snapshot.v9a7208b --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@1.0.4-snapshot.v9a7208b --save-exact

@clerk/express

npm i @clerk/express@0.0.5-snapshot.v9a7208b --save-exact

@clerk/fastify

npm i @clerk/fastify@1.0.4-snapshot.v9a7208b --save-exact

gatsby-plugin-clerk

npm i gatsby-plugin-clerk@5.0.0-beta.45 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@5.0.5-snapshot.v9a7208b --save-exact

@clerk/remix

npm i @clerk/remix@4.0.4-snapshot.v9a7208b --save-exact

@clerk/clerk-sdk-node

npm i @clerk/clerk-sdk-node@5.0.4-snapshot.v9a7208b --save-exact

@panteliselef
panteliselef requested a review from brkalowMay 1, 2024 12:36
Comment on lines +34 to +45
if (!options.secretKey || !options.jwtKey) {
return {
errors: [
new TokenVerificationError({
action: TokenVerificationErrorAction.SetClerkSecretKey,
message: 'Both JWT Key and Secret Key are missing. Operation could not be completed.',
reason: TokenVerificationErrorReason.InvalidSecretKey,
}),
],
};
}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we think that this is a breaking change ? Tbh i think we can skip its introduction

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could also just throw a warning instead so we don't introduce a breaking change

Comment thread.changeset/modern-boxes-peel.md Outdated
```ts
import { clerkClient } from "@clerk/clerk-sdk-node";

clerkClient.verifyToken(token, {})

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only reason, i've not update the signature is that this package will be deprecated.

@dimkldimkl left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

☁️ I understand that the customer use case is valid and that we probably need to make a change to clerkClient.verifyToken(token, options) to support execution without passing options but i am not 100% sure that we should make it this way.
I would expect to either keep it as is and inform the customers using it explicitly that it's just a re-export from the @clerk/backend and all the arguments required should be passed. or support the following:

import{clerkClient}from"@clerk/clerk-sdk-node";// case #1: use options passed in clerkClientclerkClient.verifyToken(token)// case #2: options should be non-conflicting with the ones passed in clerkClient// as it does not make sense to have a different jwtKey set in the clerkClient and a different one used in verifyTokenclerkClient.verifyToken(token,options)

If they need to pass explicitly the options i would advise to either create a different clerkClient or use the verifytoken from the @clerk/backend.
I think we should go for ONLY the 1st case. We should check if the @clerk/express supports the same API and make the appropriate changes there.
cc: @nikosdouvlis

@panteliselef

Copy link
Copy Markdown
ContributorAuthor

@dimkl
Regarding case 1, Completely dropping the 2nd params, wouldn't that be a breaking change ?

If we are going the extra mile here, let's still support the 2nd param, but update the signature so that 2nd param is optional. It is the least disruptive solution.

Your suggestions make sense, but I would skip them for this package and only apply them to the new express package

Comment threadpackages/backend/src/tokens/verify.ts Outdated
@shadoworion

Copy link
Copy Markdown
Contributor

☁️ I understand that the customer use case is valid and that we probably need to make a change to clerkClient.verifyToken(token, options) to support execution without passing options but i am not 100% sure that we should make it this way. I would expect to either keep it as is and inform the customers using it explicitly that it's just a re-export from the @clerk/backend and all the arguments required should be passed. or support the following:

import{clerkClient}from"@clerk/clerk-sdk-node";// case #1: use options passed in clerkClientclerkClient.verifyToken(token)// case #2: options should be non-conflicting with the ones passed in clerkClient// as it does not make sense to have a different jwtKey set in the clerkClient and a different one used in verifyTokenclerkClient.verifyToken(token,options)

If they need to pass explicitly the options i would advise to either create a different clerkClient or use the verifytoken from the @clerk/backend. I think we should go for ONLY the 1st case. We should check if the @clerk/express supports the same API and make the appropriate changes there. cc: @nikosdouvlis

Hi, I use this function to create auth middleware for the "graphql-yoga" server. All options are default and secret from env (which doesn't work now), so "case #1" fits better.

If I use different options that conflict with the current "clerkClient," I'll use "createClerkClient" to create a new one (that also doesn't work now)

return (...args: Parameters<VerifyTokenWithOptionalSecondArgument>) =>
_verifyToken(args[0], {
...params,
...args[1],

@dimkldimklMay 10, 2024

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔧 Could you add 2 tests (with options, without options) to verify that everything works as expected?

Comment on lines -6 to -11
const mockNext = jest.fn();

afterEach(() => {
mockNext.mockReset();
});

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dimkl fyi, Just cleaning this up

@panteliselef
panteliselefforce-pushed the elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification branch from fd50eea to 1afcdcdCompareMay 10, 2024 17:24
@panteliselef
panteliselef enabled auto-merge (squash) May 10, 2024 18:36
@panteliselef
panteliselef merged commit b924022 into mainMay 10, 2024
@panteliselef
panteliselef deleted the elef/sdk-1698-node-sdk-failed-to-resolve-jwk-during-verification branch May 10, 2024 18:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Node SDK]: Failed to resolve JWK during verification

5 participants

@panteliselef@clerk-cookie@shadoworion@dimkl@octoper