feat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimental - #4016

Merged
panteliselef merged 33 commits into
mainfrom
elef/user-607-userverification-ui-component
Aug 29, 2024
Merged

feat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimental#4016
panteliselef merged 33 commits into
mainfrom
elef/user-607-userverification-ui-component

Conversation

@panteliselef

@panteliselefpanteliselef commented Aug 26, 2024

Copy link
Copy Markdown
Contributor

Description

This PR introduces a new UI component called UserVerification as experimental. The new UI component allows for a user to "re-enter" their credentials (1fa/2fa) which results in them being reverified.

<UserVerification/> allows developers to easily build flows where verification is required before performing a sensitive action like updating other stored credentials or an application specific action like making a bank transfer.

Unit tests have been added which should make reviewers more confident. But more will follow (maybe some e2es) before the official launch.

APIs

clerk-js

exporttype__experimental_UserVerificationProps=RoutingOptions&{afterVerification?: ()=>void;afterVerificationUrl?: string;level?: 'L1.firstFactor'|'L2.secondFactor'|'L3.multiFactor';appearance?: UserVerificationTheme;};
__experimental_openUserVerification: (props?: __experimental_UserVerificationModalProps)=>void;
__experimental_closeUserVerification: ()=>void;
__experimental_mountUserVerification: (targetNode: HTMLDivElement,props?: __experimental_UserVerificationProps,)=>void;
__experimental_unmountUserVerification: (targetNode: HTMLDivElement)=>void;

clerk-react

import{__experimental_UserVerification}from'@clerk/clerk-react'<__experimental_UserVerification/>

2fa flow (the default)

default.mov

1fa flow

1fa.mov

multi factor flow (the above two combined)

mfa.mov

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-botBot commented Aug 26, 2024

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0e5d8d2

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 18 packages
NameType
@clerk/localizationsMinor
@clerk/chrome-extensionMinor
@clerk/nextjsMinor
@clerk/clerk-reactMinor
@clerk/clerk-jsMinor
@clerk/typesMinor
@clerk/elementsPatch
@clerk/clerk-expoPatch
@clerk/remixPatch
@clerk/tanstack-startPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/clerk-sdk-nodePatch
@clerk/sharedPatch
@clerk/testingPatch
@clerk/themesPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch 2 times, most recently from c2a8280 to efd5e79CompareAugust 26, 2024 10:35
@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from efd5e79 to ee6706aCompareAugust 26, 2024 11:02
@panteliselefpanteliselef self-assigned this Aug 27, 2024
@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from 28a6490 to 02aea2aCompareAugust 27, 2024 14:11
routing: 'virtual',
}}
>
{/*TODO: Used by InvisibleRootBox, can we simplify? */}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For reviewers: Carried from SignIn

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from fb4b3ea to 8cb52f6CompareAugust 27, 2024 20:37
Comment on lines +8 to +14
export function useAlternativeStrategies({
filterOutFactor,
supportedFirstFactors: _supportedFirstFactors,
}: {
filterOutFactor: SignInFactor | null | undefined;
supportedFirstFactors: SignInFirstFactor[] | null | undefined;
}) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For reviewers: I made this change in order to share the functionality across SignIn and UserVerification. Simply having the caller doing const { supportedFirstFactors } = useCoreSignIn(); seems like a good trade off.

Comment on lines +63 to +69
{/*<input*/}
{/* readOnly*/}
{/* id='identifier-field'*/}
{/* name='identifier'*/}
{/* value={signIn.identifier || ''}*/}
{/* style={{ display: 'none' }}*/}
{/*/>*/}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chanioxaris any ideas what we can use to solve this while the user is signed in ?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can use the existing function that picks up the identifier based on the user attributes

Comment threadpackages/localizations/src/en-US.ts Outdated
getHelp: {
blockButton__emailSupport: 'Email support',
content:
'If you’re experiencing difficulty signing into your account, email us and we will work with you to restore access as soon as possible.',

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (2/2)

Comment threadpackages/localizations/src/en-US.ts Outdated
Comment on lines +562 to +563
content:
'If you’re experiencing difficulty verifying your account, email us and we will work with you to restore access as soon as possible.',

@panteliselefpanteliselefAug 27, 2024

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (2/4)

actionText: 'Don’t have any of these?',
blockButton__backupCode: 'Use a backup code',
blockButton__emailCode: 'Email code to {{identifier}}',
blockButton__password: 'Continue with your password',

@panteliselefpanteliselefAug 27, 2024

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (1/4)

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from 388258a to c0fa2c3CompareAugust 27, 2024 20:42
@panteliselef
panteliselef marked this pull request as ready for review August 28, 2024 09:19
@panteliselef
panteliselef requested a review from a teamAugust 28, 2024 09:19
…-component
# Conflicts:
#	packages/clerk-js/bundlewatch.config.json
#	packages/clerk-js/src/ui/components/SignIn/SignInFactorOne.tsx
#	packages/clerk-js/src/ui/components/SignIn/SignInFactorOnePasswordCard.tsx
#	packages/clerk-js/src/ui/lazyModules/components.ts
'If you’re experiencing difficulty verifying your account, email us and we will work with you to restore access as soon as possible.',
title: 'Get help',
},
subtitle: 'Facing issues? You can use any of these methods for verification.',

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (3/4)

title: 'Check your email',
},
noAvailableMethods: {
message: "Cannot proceed with verification. There's no available authentication factor.",

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (4/4)

@panteliselefpanteliselef changed the title Introduce UserVerificationIntroduce UserVerification as experimentalAug 28, 2024
@panteliselefpanteliselef changed the title Introduce UserVerification as experimentalfeat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimentalAug 28, 2024
Comment thread.changeset/calm-zoos-sort.md Outdated
Comment thread.changeset/fifty-ravens-attack.md Outdated
Comment thread.changeset/healthy-colts-look.md Outdated
Comment thread.changeset/healthy-colts-look.md Outdated
Comment thread.changeset/proud-dryers-smile.md Outdated
});
});

it.todo('renders the component for with strategy:phone_code');

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TODO ⚠️

Comment on lines +116 to +122
describe('Use another method', () => {
it.todo('should list enabled first factor methods without the current one');
});

describe('Get Help', () => {
it.todo('should render the get help component when clicking the "Get Help" button');
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TODOs

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These will be added in a future PR (soon)

Comment threadpackages/localizations/src/en-US.ts Outdated
Comment threadpackages/types/src/clerk.ts Outdated
Comment threadpackages/clerk-js/src/ui/Components.tsx Outdated
@@ -0,0 +1,135 @@
import type { __experimental_SessionVerificationFirstFactor, SignInFactor } from '@clerk/types';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@panteliselef what do you think about renaming this file to something UVFactorOneAlternativeMethods so it can match UVFactorTwoAlternativeMethods?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have no problem, there is a great chance that event the UV prefix will be replaced in the coming days as the component name is not final yet

@octoperoctoper left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔥

@panteliselef
panteliselef merged commit afad9af into mainAug 29, 2024
@panteliselef
panteliselef deleted the elef/user-607-userverification-ui-component branch August 29, 2024 17:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@panteliselef@alexcarpenter@octoper@LekoArts@chanioxaris@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimental - #4016

Merged
panteliselef merged 33 commits into
mainfrom
elef/user-607-userverification-ui-component
Aug 29, 2024
Merged

feat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimental#4016
panteliselef merged 33 commits into
mainfrom
elef/user-607-userverification-ui-component

Conversation

@panteliselef

@panteliselefpanteliselef commented Aug 26, 2024

Copy link
Copy Markdown
Contributor

Description

This PR introduces a new UI component called UserVerification as experimental. The new UI component allows for a user to "re-enter" their credentials (1fa/2fa) which results in them being reverified.

<UserVerification/> allows developers to easily build flows where verification is required before performing a sensitive action like updating other stored credentials or an application specific action like making a bank transfer.

Unit tests have been added which should make reviewers more confident. But more will follow (maybe some e2es) before the official launch.

APIs

clerk-js

exporttype__experimental_UserVerificationProps=RoutingOptions&{afterVerification?: ()=>void;afterVerificationUrl?: string;level?: 'L1.firstFactor'|'L2.secondFactor'|'L3.multiFactor';appearance?: UserVerificationTheme;};
__experimental_openUserVerification: (props?: __experimental_UserVerificationModalProps)=>void;
__experimental_closeUserVerification: ()=>void;
__experimental_mountUserVerification: (targetNode: HTMLDivElement,props?: __experimental_UserVerificationProps,)=>void;
__experimental_unmountUserVerification: (targetNode: HTMLDivElement)=>void;

clerk-react

import{__experimental_UserVerification}from'@clerk/clerk-react'<__experimental_UserVerification/>

2fa flow (the default)

default.mov

1fa flow

1fa.mov

multi factor flow (the above two combined)

mfa.mov

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-botBot commented Aug 26, 2024

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0e5d8d2

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 18 packages
NameType
@clerk/localizationsMinor
@clerk/chrome-extensionMinor
@clerk/nextjsMinor
@clerk/clerk-reactMinor
@clerk/clerk-jsMinor
@clerk/typesMinor
@clerk/elementsPatch
@clerk/clerk-expoPatch
@clerk/remixPatch
@clerk/tanstack-startPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/clerk-sdk-nodePatch
@clerk/sharedPatch
@clerk/testingPatch
@clerk/themesPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch 2 times, most recently from c2a8280 to efd5e79CompareAugust 26, 2024 10:35
@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from efd5e79 to ee6706aCompareAugust 26, 2024 11:02
@panteliselefpanteliselef self-assigned this Aug 27, 2024
@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from 28a6490 to 02aea2aCompareAugust 27, 2024 14:11
routing: 'virtual',
}}
>
{/*TODO: Used by InvisibleRootBox, can we simplify? */}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For reviewers: Carried from SignIn

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from fb4b3ea to 8cb52f6CompareAugust 27, 2024 20:37
Comment on lines +8 to +14
export function useAlternativeStrategies({
filterOutFactor,
supportedFirstFactors: _supportedFirstFactors,
}: {
filterOutFactor: SignInFactor | null | undefined;
supportedFirstFactors: SignInFirstFactor[] | null | undefined;
}) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For reviewers: I made this change in order to share the functionality across SignIn and UserVerification. Simply having the caller doing const { supportedFirstFactors } = useCoreSignIn(); seems like a good trade off.

Comment on lines +63 to +69
{/*<input*/}
{/* readOnly*/}
{/* id='identifier-field'*/}
{/* name='identifier'*/}
{/* value={signIn.identifier || ''}*/}
{/* style={{ display: 'none' }}*/}
{/*/>*/}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chanioxaris any ideas what we can use to solve this while the user is signed in ?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can use the existing function that picks up the identifier based on the user attributes

Comment threadpackages/localizations/src/en-US.ts Outdated
getHelp: {
blockButton__emailSupport: 'Email support',
content:
'If you’re experiencing difficulty signing into your account, email us and we will work with you to restore access as soon as possible.',

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (2/2)

Comment threadpackages/localizations/src/en-US.ts Outdated
Comment on lines +562 to +563
content:
'If you’re experiencing difficulty verifying your account, email us and we will work with you to restore access as soon as possible.',

@panteliselefpanteliselefAug 27, 2024

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (2/4)

actionText: 'Don’t have any of these?',
blockButton__backupCode: 'Use a backup code',
blockButton__emailCode: 'Email code to {{identifier}}',
blockButton__password: 'Continue with your password',

@panteliselefpanteliselefAug 27, 2024

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (1/4)

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from 388258a to c0fa2c3CompareAugust 27, 2024 20:42
@panteliselef
panteliselef marked this pull request as ready for review August 28, 2024 09:19
@panteliselef
panteliselef requested a review from a teamAugust 28, 2024 09:19
…-component
# Conflicts:
#	packages/clerk-js/bundlewatch.config.json
#	packages/clerk-js/src/ui/components/SignIn/SignInFactorOne.tsx
#	packages/clerk-js/src/ui/components/SignIn/SignInFactorOnePasswordCard.tsx
#	packages/clerk-js/src/ui/lazyModules/components.ts
'If you’re experiencing difficulty verifying your account, email us and we will work with you to restore access as soon as possible.',
title: 'Get help',
},
subtitle: 'Facing issues? You can use any of these methods for verification.',

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (3/4)

title: 'Check your email',
},
noAvailableMethods: {
message: "Cannot proceed with verification. There's no available authentication factor.",

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (4/4)

@panteliselefpanteliselef changed the title Introduce UserVerificationIntroduce UserVerification as experimentalAug 28, 2024
@panteliselefpanteliselef changed the title Introduce UserVerification as experimentalfeat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimentalAug 28, 2024
Comment thread.changeset/calm-zoos-sort.md Outdated
Comment thread.changeset/fifty-ravens-attack.md Outdated
Comment thread.changeset/healthy-colts-look.md Outdated
Comment thread.changeset/healthy-colts-look.md Outdated
Comment thread.changeset/proud-dryers-smile.md Outdated
});
});

it.todo('renders the component for with strategy:phone_code');

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TODO ⚠️

Comment on lines +116 to +122
describe('Use another method', () => {
it.todo('should list enabled first factor methods without the current one');
});

describe('Get Help', () => {
it.todo('should render the get help component when clicking the "Get Help" button');
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TODOs

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These will be added in a future PR (soon)

Comment threadpackages/localizations/src/en-US.ts Outdated
Comment threadpackages/types/src/clerk.ts Outdated
Comment threadpackages/clerk-js/src/ui/Components.tsx Outdated
@@ -0,0 +1,135 @@
import type { __experimental_SessionVerificationFirstFactor, SignInFactor } from '@clerk/types';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@panteliselef what do you think about renaming this file to something UVFactorOneAlternativeMethods so it can match UVFactorTwoAlternativeMethods?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have no problem, there is a great chance that event the UV prefix will be replaced in the coming days as the component name is not final yet

@octoperoctoper left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔥

@panteliselef
panteliselef merged commit afad9af into mainAug 29, 2024
@panteliselef
panteliselef deleted the elef/user-607-userverification-ui-component branch August 29, 2024 17:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@panteliselef@alexcarpenter@octoper@LekoArts@chanioxaris@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimental - #4016

Merged
panteliselef merged 33 commits into
mainfrom
elef/user-607-userverification-ui-component
Aug 29, 2024
Merged

feat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimental#4016
panteliselef merged 33 commits into
mainfrom
elef/user-607-userverification-ui-component

Conversation

@panteliselef

@panteliselefpanteliselef commented Aug 26, 2024

Copy link
Copy Markdown
Contributor

Description

This PR introduces a new UI component called UserVerification as experimental. The new UI component allows for a user to "re-enter" their credentials (1fa/2fa) which results in them being reverified.

<UserVerification/> allows developers to easily build flows where verification is required before performing a sensitive action like updating other stored credentials or an application specific action like making a bank transfer.

Unit tests have been added which should make reviewers more confident. But more will follow (maybe some e2es) before the official launch.

APIs

clerk-js

exporttype__experimental_UserVerificationProps=RoutingOptions&{afterVerification?: ()=>void;afterVerificationUrl?: string;level?: 'L1.firstFactor'|'L2.secondFactor'|'L3.multiFactor';appearance?: UserVerificationTheme;};
__experimental_openUserVerification: (props?: __experimental_UserVerificationModalProps)=>void;
__experimental_closeUserVerification: ()=>void;
__experimental_mountUserVerification: (targetNode: HTMLDivElement,props?: __experimental_UserVerificationProps,)=>void;
__experimental_unmountUserVerification: (targetNode: HTMLDivElement)=>void;

clerk-react

import{__experimental_UserVerification}from'@clerk/clerk-react'<__experimental_UserVerification/>

2fa flow (the default)

default.mov

1fa flow

1fa.mov

multi factor flow (the above two combined)

mfa.mov

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-botBot commented Aug 26, 2024

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0e5d8d2

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 18 packages
NameType
@clerk/localizationsMinor
@clerk/chrome-extensionMinor
@clerk/nextjsMinor
@clerk/clerk-reactMinor
@clerk/clerk-jsMinor
@clerk/typesMinor
@clerk/elementsPatch
@clerk/clerk-expoPatch
@clerk/remixPatch
@clerk/tanstack-startPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/clerk-sdk-nodePatch
@clerk/sharedPatch
@clerk/testingPatch
@clerk/themesPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch 2 times, most recently from c2a8280 to efd5e79CompareAugust 26, 2024 10:35
@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from efd5e79 to ee6706aCompareAugust 26, 2024 11:02
@panteliselefpanteliselef self-assigned this Aug 27, 2024
@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from 28a6490 to 02aea2aCompareAugust 27, 2024 14:11
routing: 'virtual',
}}
>
{/*TODO: Used by InvisibleRootBox, can we simplify? */}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For reviewers: Carried from SignIn

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from fb4b3ea to 8cb52f6CompareAugust 27, 2024 20:37
Comment on lines +8 to +14
export function useAlternativeStrategies({
filterOutFactor,
supportedFirstFactors: _supportedFirstFactors,
}: {
filterOutFactor: SignInFactor | null | undefined;
supportedFirstFactors: SignInFirstFactor[] | null | undefined;
}) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For reviewers: I made this change in order to share the functionality across SignIn and UserVerification. Simply having the caller doing const { supportedFirstFactors } = useCoreSignIn(); seems like a good trade off.

Comment on lines +63 to +69
{/*<input*/}
{/* readOnly*/}
{/* id='identifier-field'*/}
{/* name='identifier'*/}
{/* value={signIn.identifier || ''}*/}
{/* style={{ display: 'none' }}*/}
{/*/>*/}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chanioxaris any ideas what we can use to solve this while the user is signed in ?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can use the existing function that picks up the identifier based on the user attributes

Comment threadpackages/localizations/src/en-US.ts Outdated
getHelp: {
blockButton__emailSupport: 'Email support',
content:
'If you’re experiencing difficulty signing into your account, email us and we will work with you to restore access as soon as possible.',

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (2/2)

Comment threadpackages/localizations/src/en-US.ts Outdated
Comment on lines +562 to +563
content:
'If you’re experiencing difficulty verifying your account, email us and we will work with you to restore access as soon as possible.',

@panteliselefpanteliselefAug 27, 2024

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (2/4)

actionText: 'Don’t have any of these?',
blockButton__backupCode: 'Use a backup code',
blockButton__emailCode: 'Email code to {{identifier}}',
blockButton__password: 'Continue with your password',

@panteliselefpanteliselefAug 27, 2024

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (1/4)

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from 388258a to c0fa2c3CompareAugust 27, 2024 20:42
@panteliselef
panteliselef marked this pull request as ready for review August 28, 2024 09:19
@panteliselef
panteliselef requested a review from a teamAugust 28, 2024 09:19
…-component
# Conflicts:
#	packages/clerk-js/bundlewatch.config.json
#	packages/clerk-js/src/ui/components/SignIn/SignInFactorOne.tsx
#	packages/clerk-js/src/ui/components/SignIn/SignInFactorOnePasswordCard.tsx
#	packages/clerk-js/src/ui/lazyModules/components.ts
'If you’re experiencing difficulty verifying your account, email us and we will work with you to restore access as soon as possible.',
title: 'Get help',
},
subtitle: 'Facing issues? You can use any of these methods for verification.',

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (3/4)

title: 'Check your email',
},
noAvailableMethods: {
message: "Cannot proceed with verification. There's no available authentication factor.",

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (4/4)

@panteliselefpanteliselef changed the title Introduce UserVerificationIntroduce UserVerification as experimentalAug 28, 2024
@panteliselefpanteliselef changed the title Introduce UserVerification as experimentalfeat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimentalAug 28, 2024
Comment thread.changeset/calm-zoos-sort.md Outdated
Comment thread.changeset/fifty-ravens-attack.md Outdated
Comment thread.changeset/healthy-colts-look.md Outdated
Comment thread.changeset/healthy-colts-look.md Outdated
Comment thread.changeset/proud-dryers-smile.md Outdated
});
});

it.todo('renders the component for with strategy:phone_code');

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TODO ⚠️

Comment on lines +116 to +122
describe('Use another method', () => {
it.todo('should list enabled first factor methods without the current one');
});

describe('Get Help', () => {
it.todo('should render the get help component when clicking the "Get Help" button');
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TODOs

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These will be added in a future PR (soon)

Comment threadpackages/localizations/src/en-US.ts Outdated
Comment threadpackages/types/src/clerk.ts Outdated
Comment threadpackages/clerk-js/src/ui/Components.tsx Outdated
@@ -0,0 +1,135 @@
import type { __experimental_SessionVerificationFirstFactor, SignInFactor } from '@clerk/types';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@panteliselef what do you think about renaming this file to something UVFactorOneAlternativeMethods so it can match UVFactorTwoAlternativeMethods?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have no problem, there is a great chance that event the UV prefix will be replaced in the coming days as the component name is not final yet

@octoperoctoper left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔥

@panteliselef
panteliselef merged commit afad9af into mainAug 29, 2024
@panteliselef
panteliselef deleted the elef/user-607-userverification-ui-component branch August 29, 2024 17:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@panteliselef@alexcarpenter@octoper@LekoArts@chanioxaris@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimental - #4016

Merged
panteliselef merged 33 commits into
mainfrom
elef/user-607-userverification-ui-component
Aug 29, 2024
Merged

feat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimental#4016
panteliselef merged 33 commits into
mainfrom
elef/user-607-userverification-ui-component

Conversation

@panteliselef

@panteliselefpanteliselef commented Aug 26, 2024

Copy link
Copy Markdown
Contributor

Description

This PR introduces a new UI component called UserVerification as experimental. The new UI component allows for a user to "re-enter" their credentials (1fa/2fa) which results in them being reverified.

<UserVerification/> allows developers to easily build flows where verification is required before performing a sensitive action like updating other stored credentials or an application specific action like making a bank transfer.

Unit tests have been added which should make reviewers more confident. But more will follow (maybe some e2es) before the official launch.

APIs

clerk-js

exporttype__experimental_UserVerificationProps=RoutingOptions&{afterVerification?: ()=>void;afterVerificationUrl?: string;level?: 'L1.firstFactor'|'L2.secondFactor'|'L3.multiFactor';appearance?: UserVerificationTheme;};
__experimental_openUserVerification: (props?: __experimental_UserVerificationModalProps)=>void;
__experimental_closeUserVerification: ()=>void;
__experimental_mountUserVerification: (targetNode: HTMLDivElement,props?: __experimental_UserVerificationProps,)=>void;
__experimental_unmountUserVerification: (targetNode: HTMLDivElement)=>void;

clerk-react

import{__experimental_UserVerification}from'@clerk/clerk-react'<__experimental_UserVerification/>

2fa flow (the default)

default.mov

1fa flow

1fa.mov

multi factor flow (the above two combined)

mfa.mov

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-botBot commented Aug 26, 2024

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0e5d8d2

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 18 packages
NameType
@clerk/localizationsMinor
@clerk/chrome-extensionMinor
@clerk/nextjsMinor
@clerk/clerk-reactMinor
@clerk/clerk-jsMinor
@clerk/typesMinor
@clerk/elementsPatch
@clerk/clerk-expoPatch
@clerk/remixPatch
@clerk/tanstack-startPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/clerk-sdk-nodePatch
@clerk/sharedPatch
@clerk/testingPatch
@clerk/themesPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch 2 times, most recently from c2a8280 to efd5e79CompareAugust 26, 2024 10:35
@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from efd5e79 to ee6706aCompareAugust 26, 2024 11:02
@panteliselefpanteliselef self-assigned this Aug 27, 2024
@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from 28a6490 to 02aea2aCompareAugust 27, 2024 14:11
routing: 'virtual',
}}
>
{/*TODO: Used by InvisibleRootBox, can we simplify? */}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For reviewers: Carried from SignIn

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from fb4b3ea to 8cb52f6CompareAugust 27, 2024 20:37
Comment on lines +8 to +14
export function useAlternativeStrategies({
filterOutFactor,
supportedFirstFactors: _supportedFirstFactors,
}: {
filterOutFactor: SignInFactor | null | undefined;
supportedFirstFactors: SignInFirstFactor[] | null | undefined;
}) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For reviewers: I made this change in order to share the functionality across SignIn and UserVerification. Simply having the caller doing const { supportedFirstFactors } = useCoreSignIn(); seems like a good trade off.

Comment on lines +63 to +69
{/*<input*/}
{/* readOnly*/}
{/* id='identifier-field'*/}
{/* name='identifier'*/}
{/* value={signIn.identifier || ''}*/}
{/* style={{ display: 'none' }}*/}
{/*/>*/}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chanioxaris any ideas what we can use to solve this while the user is signed in ?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can use the existing function that picks up the identifier based on the user attributes

Comment threadpackages/localizations/src/en-US.ts Outdated
getHelp: {
blockButton__emailSupport: 'Email support',
content:
'If you’re experiencing difficulty signing into your account, email us and we will work with you to restore access as soon as possible.',

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (2/2)

Comment threadpackages/localizations/src/en-US.ts Outdated
Comment on lines +562 to +563
content:
'If you’re experiencing difficulty verifying your account, email us and we will work with you to restore access as soon as possible.',

@panteliselefpanteliselefAug 27, 2024

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (2/4)

actionText: 'Don’t have any of these?',
blockButton__backupCode: 'Use a backup code',
blockButton__emailCode: 'Email code to {{identifier}}',
blockButton__password: 'Continue with your password',

@panteliselefpanteliselefAug 27, 2024

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (1/4)

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from 388258a to c0fa2c3CompareAugust 27, 2024 20:42
@panteliselef
panteliselef marked this pull request as ready for review August 28, 2024 09:19
@panteliselef
panteliselef requested a review from a teamAugust 28, 2024 09:19
…-component
# Conflicts:
#	packages/clerk-js/bundlewatch.config.json
#	packages/clerk-js/src/ui/components/SignIn/SignInFactorOne.tsx
#	packages/clerk-js/src/ui/components/SignIn/SignInFactorOnePasswordCard.tsx
#	packages/clerk-js/src/ui/lazyModules/components.ts
'If you’re experiencing difficulty verifying your account, email us and we will work with you to restore access as soon as possible.',
title: 'Get help',
},
subtitle: 'Facing issues? You can use any of these methods for verification.',

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (3/4)

title: 'Check your email',
},
noAvailableMethods: {
message: "Cannot proceed with verification. There's no available authentication factor.",

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (4/4)

@panteliselefpanteliselef changed the title Introduce UserVerificationIntroduce UserVerification as experimentalAug 28, 2024
@panteliselefpanteliselef changed the title Introduce UserVerification as experimentalfeat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimentalAug 28, 2024
Comment thread.changeset/calm-zoos-sort.md Outdated
Comment thread.changeset/fifty-ravens-attack.md Outdated
Comment thread.changeset/healthy-colts-look.md Outdated
Comment thread.changeset/healthy-colts-look.md Outdated
Comment thread.changeset/proud-dryers-smile.md Outdated
});
});

it.todo('renders the component for with strategy:phone_code');

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TODO ⚠️

Comment on lines +116 to +122
describe('Use another method', () => {
it.todo('should list enabled first factor methods without the current one');
});

describe('Get Help', () => {
it.todo('should render the get help component when clicking the "Get Help" button');
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TODOs

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These will be added in a future PR (soon)

Comment threadpackages/localizations/src/en-US.ts Outdated
Comment threadpackages/types/src/clerk.ts Outdated
Comment threadpackages/clerk-js/src/ui/Components.tsx Outdated
@@ -0,0 +1,135 @@
import type { __experimental_SessionVerificationFirstFactor, SignInFactor } from '@clerk/types';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@panteliselef what do you think about renaming this file to something UVFactorOneAlternativeMethods so it can match UVFactorTwoAlternativeMethods?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have no problem, there is a great chance that event the UV prefix will be replaced in the coming days as the component name is not final yet

@octoperoctoper left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔥

@panteliselef
panteliselef merged commit afad9af into mainAug 29, 2024
@panteliselef
panteliselef deleted the elef/user-607-userverification-ui-component branch August 29, 2024 17:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@panteliselef@alexcarpenter@octoper@LekoArts@chanioxaris@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimental - #4016

Merged
panteliselef merged 33 commits into
mainfrom
elef/user-607-userverification-ui-component
Aug 29, 2024
Merged

feat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimental#4016
panteliselef merged 33 commits into
mainfrom
elef/user-607-userverification-ui-component

Conversation

@panteliselef

@panteliselefpanteliselef commented Aug 26, 2024

Copy link
Copy Markdown
Contributor

Description

This PR introduces a new UI component called UserVerification as experimental. The new UI component allows for a user to "re-enter" their credentials (1fa/2fa) which results in them being reverified.

<UserVerification/> allows developers to easily build flows where verification is required before performing a sensitive action like updating other stored credentials or an application specific action like making a bank transfer.

Unit tests have been added which should make reviewers more confident. But more will follow (maybe some e2es) before the official launch.

APIs

clerk-js

exporttype__experimental_UserVerificationProps=RoutingOptions&{afterVerification?: ()=>void;afterVerificationUrl?: string;level?: 'L1.firstFactor'|'L2.secondFactor'|'L3.multiFactor';appearance?: UserVerificationTheme;};
__experimental_openUserVerification: (props?: __experimental_UserVerificationModalProps)=>void;
__experimental_closeUserVerification: ()=>void;
__experimental_mountUserVerification: (targetNode: HTMLDivElement,props?: __experimental_UserVerificationProps,)=>void;
__experimental_unmountUserVerification: (targetNode: HTMLDivElement)=>void;

clerk-react

import{__experimental_UserVerification}from'@clerk/clerk-react'<__experimental_UserVerification/>

2fa flow (the default)

default.mov

1fa flow

1fa.mov

multi factor flow (the above two combined)

mfa.mov

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-botBot commented Aug 26, 2024

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0e5d8d2

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 18 packages
NameType
@clerk/localizationsMinor
@clerk/chrome-extensionMinor
@clerk/nextjsMinor
@clerk/clerk-reactMinor
@clerk/clerk-jsMinor
@clerk/typesMinor
@clerk/elementsPatch
@clerk/clerk-expoPatch
@clerk/remixPatch
@clerk/tanstack-startPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/clerk-sdk-nodePatch
@clerk/sharedPatch
@clerk/testingPatch
@clerk/themesPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch 2 times, most recently from c2a8280 to efd5e79CompareAugust 26, 2024 10:35
@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from efd5e79 to ee6706aCompareAugust 26, 2024 11:02
@panteliselefpanteliselef self-assigned this Aug 27, 2024
@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from 28a6490 to 02aea2aCompareAugust 27, 2024 14:11
routing: 'virtual',
}}
>
{/*TODO: Used by InvisibleRootBox, can we simplify? */}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For reviewers: Carried from SignIn

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from fb4b3ea to 8cb52f6CompareAugust 27, 2024 20:37
Comment on lines +8 to +14
export function useAlternativeStrategies({
filterOutFactor,
supportedFirstFactors: _supportedFirstFactors,
}: {
filterOutFactor: SignInFactor | null | undefined;
supportedFirstFactors: SignInFirstFactor[] | null | undefined;
}) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For reviewers: I made this change in order to share the functionality across SignIn and UserVerification. Simply having the caller doing const { supportedFirstFactors } = useCoreSignIn(); seems like a good trade off.

Comment on lines +63 to +69
{/*<input*/}
{/* readOnly*/}
{/* id='identifier-field'*/}
{/* name='identifier'*/}
{/* value={signIn.identifier || ''}*/}
{/* style={{ display: 'none' }}*/}
{/*/>*/}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chanioxaris any ideas what we can use to solve this while the user is signed in ?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can use the existing function that picks up the identifier based on the user attributes

Comment threadpackages/localizations/src/en-US.ts Outdated
getHelp: {
blockButton__emailSupport: 'Email support',
content:
'If you’re experiencing difficulty signing into your account, email us and we will work with you to restore access as soon as possible.',

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (2/2)

Comment threadpackages/localizations/src/en-US.ts Outdated
Comment on lines +562 to +563
content:
'If you’re experiencing difficulty verifying your account, email us and we will work with you to restore access as soon as possible.',

@panteliselefpanteliselefAug 27, 2024

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (2/4)

actionText: 'Don’t have any of these?',
blockButton__backupCode: 'Use a backup code',
blockButton__emailCode: 'Email code to {{identifier}}',
blockButton__password: 'Continue with your password',

@panteliselefpanteliselefAug 27, 2024

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (1/4)

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from 388258a to c0fa2c3CompareAugust 27, 2024 20:42
@panteliselef
panteliselef marked this pull request as ready for review August 28, 2024 09:19
@panteliselef
panteliselef requested a review from a teamAugust 28, 2024 09:19
…-component
# Conflicts:
#	packages/clerk-js/bundlewatch.config.json
#	packages/clerk-js/src/ui/components/SignIn/SignInFactorOne.tsx
#	packages/clerk-js/src/ui/components/SignIn/SignInFactorOnePasswordCard.tsx
#	packages/clerk-js/src/ui/lazyModules/components.ts
'If you’re experiencing difficulty verifying your account, email us and we will work with you to restore access as soon as possible.',
title: 'Get help',
},
subtitle: 'Facing issues? You can use any of these methods for verification.',

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (3/4)

title: 'Check your email',
},
noAvailableMethods: {
message: "Cannot proceed with verification. There's no available authentication factor.",

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (4/4)

@panteliselefpanteliselef changed the title Introduce UserVerificationIntroduce UserVerification as experimentalAug 28, 2024
@panteliselefpanteliselef changed the title Introduce UserVerification as experimentalfeat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimentalAug 28, 2024
Comment thread.changeset/calm-zoos-sort.md Outdated
Comment thread.changeset/fifty-ravens-attack.md Outdated
Comment thread.changeset/healthy-colts-look.md Outdated
Comment thread.changeset/healthy-colts-look.md Outdated
Comment thread.changeset/proud-dryers-smile.md Outdated
});
});

it.todo('renders the component for with strategy:phone_code');

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TODO ⚠️

Comment on lines +116 to +122
describe('Use another method', () => {
it.todo('should list enabled first factor methods without the current one');
});

describe('Get Help', () => {
it.todo('should render the get help component when clicking the "Get Help" button');
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TODOs

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These will be added in a future PR (soon)

Comment threadpackages/localizations/src/en-US.ts Outdated
Comment threadpackages/types/src/clerk.ts Outdated
Comment threadpackages/clerk-js/src/ui/Components.tsx Outdated
@@ -0,0 +1,135 @@
import type { __experimental_SessionVerificationFirstFactor, SignInFactor } from '@clerk/types';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@panteliselef what do you think about renaming this file to something UVFactorOneAlternativeMethods so it can match UVFactorTwoAlternativeMethods?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have no problem, there is a great chance that event the UV prefix will be replaced in the coming days as the component name is not final yet

@octoperoctoper left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔥

@panteliselef
panteliselef merged commit afad9af into mainAug 29, 2024
@panteliselef
panteliselef deleted the elef/user-607-userverification-ui-component branch August 29, 2024 17:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@panteliselef@alexcarpenter@octoper@LekoArts@chanioxaris@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimental - #4016

Merged
panteliselef merged 33 commits into
mainfrom
elef/user-607-userverification-ui-component
Aug 29, 2024
Merged

feat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimental#4016
panteliselef merged 33 commits into
mainfrom
elef/user-607-userverification-ui-component

Conversation

@panteliselef

@panteliselefpanteliselef commented Aug 26, 2024

Copy link
Copy Markdown
Contributor

Description

This PR introduces a new UI component called UserVerification as experimental. The new UI component allows for a user to "re-enter" their credentials (1fa/2fa) which results in them being reverified.

<UserVerification/> allows developers to easily build flows where verification is required before performing a sensitive action like updating other stored credentials or an application specific action like making a bank transfer.

Unit tests have been added which should make reviewers more confident. But more will follow (maybe some e2es) before the official launch.

APIs

clerk-js

exporttype__experimental_UserVerificationProps=RoutingOptions&{afterVerification?: ()=>void;afterVerificationUrl?: string;level?: 'L1.firstFactor'|'L2.secondFactor'|'L3.multiFactor';appearance?: UserVerificationTheme;};
__experimental_openUserVerification: (props?: __experimental_UserVerificationModalProps)=>void;
__experimental_closeUserVerification: ()=>void;
__experimental_mountUserVerification: (targetNode: HTMLDivElement,props?: __experimental_UserVerificationProps,)=>void;
__experimental_unmountUserVerification: (targetNode: HTMLDivElement)=>void;

clerk-react

import{__experimental_UserVerification}from'@clerk/clerk-react'<__experimental_UserVerification/>

2fa flow (the default)

default.mov

1fa flow

1fa.mov

multi factor flow (the above two combined)

mfa.mov

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-botBot commented Aug 26, 2024

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0e5d8d2

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 18 packages
NameType
@clerk/localizationsMinor
@clerk/chrome-extensionMinor
@clerk/nextjsMinor
@clerk/clerk-reactMinor
@clerk/clerk-jsMinor
@clerk/typesMinor
@clerk/elementsPatch
@clerk/clerk-expoPatch
@clerk/remixPatch
@clerk/tanstack-startPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/clerk-sdk-nodePatch
@clerk/sharedPatch
@clerk/testingPatch
@clerk/themesPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch 2 times, most recently from c2a8280 to efd5e79CompareAugust 26, 2024 10:35
@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from efd5e79 to ee6706aCompareAugust 26, 2024 11:02
@panteliselefpanteliselef self-assigned this Aug 27, 2024
@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from 28a6490 to 02aea2aCompareAugust 27, 2024 14:11
routing: 'virtual',
}}
>
{/*TODO: Used by InvisibleRootBox, can we simplify? */}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For reviewers: Carried from SignIn

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from fb4b3ea to 8cb52f6CompareAugust 27, 2024 20:37
Comment on lines +8 to +14
export function useAlternativeStrategies({
filterOutFactor,
supportedFirstFactors: _supportedFirstFactors,
}: {
filterOutFactor: SignInFactor | null | undefined;
supportedFirstFactors: SignInFirstFactor[] | null | undefined;
}) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For reviewers: I made this change in order to share the functionality across SignIn and UserVerification. Simply having the caller doing const { supportedFirstFactors } = useCoreSignIn(); seems like a good trade off.

Comment on lines +63 to +69
{/*<input*/}
{/* readOnly*/}
{/* id='identifier-field'*/}
{/* name='identifier'*/}
{/* value={signIn.identifier || ''}*/}
{/* style={{ display: 'none' }}*/}
{/*/>*/}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chanioxaris any ideas what we can use to solve this while the user is signed in ?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can use the existing function that picks up the identifier based on the user attributes

Comment threadpackages/localizations/src/en-US.ts Outdated
getHelp: {
blockButton__emailSupport: 'Email support',
content:
'If you’re experiencing difficulty signing into your account, email us and we will work with you to restore access as soon as possible.',

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (2/2)

Comment threadpackages/localizations/src/en-US.ts Outdated
Comment on lines +562 to +563
content:
'If you’re experiencing difficulty verifying your account, email us and we will work with you to restore access as soon as possible.',

@panteliselefpanteliselefAug 27, 2024

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (2/4)

actionText: 'Don’t have any of these?',
blockButton__backupCode: 'Use a backup code',
blockButton__emailCode: 'Email code to {{identifier}}',
blockButton__password: 'Continue with your password',

@panteliselefpanteliselefAug 27, 2024

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (1/4)

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from 388258a to c0fa2c3CompareAugust 27, 2024 20:42
@panteliselef
panteliselef marked this pull request as ready for review August 28, 2024 09:19
@panteliselef
panteliselef requested a review from a teamAugust 28, 2024 09:19
…-component
# Conflicts:
#	packages/clerk-js/bundlewatch.config.json
#	packages/clerk-js/src/ui/components/SignIn/SignInFactorOne.tsx
#	packages/clerk-js/src/ui/components/SignIn/SignInFactorOnePasswordCard.tsx
#	packages/clerk-js/src/ui/lazyModules/components.ts
'If you’re experiencing difficulty verifying your account, email us and we will work with you to restore access as soon as possible.',
title: 'Get help',
},
subtitle: 'Facing issues? You can use any of these methods for verification.',

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (3/4)

title: 'Check your email',
},
noAvailableMethods: {
message: "Cannot proceed with verification. There's no available authentication factor.",

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (4/4)

@panteliselefpanteliselef changed the title Introduce UserVerificationIntroduce UserVerification as experimentalAug 28, 2024
@panteliselefpanteliselef changed the title Introduce UserVerification as experimentalfeat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimentalAug 28, 2024
Comment thread.changeset/calm-zoos-sort.md Outdated
Comment thread.changeset/fifty-ravens-attack.md Outdated
Comment thread.changeset/healthy-colts-look.md Outdated
Comment thread.changeset/healthy-colts-look.md Outdated
Comment thread.changeset/proud-dryers-smile.md Outdated
});
});

it.todo('renders the component for with strategy:phone_code');

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TODO ⚠️

Comment on lines +116 to +122
describe('Use another method', () => {
it.todo('should list enabled first factor methods without the current one');
});

describe('Get Help', () => {
it.todo('should render the get help component when clicking the "Get Help" button');
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TODOs

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These will be added in a future PR (soon)

Comment threadpackages/localizations/src/en-US.ts Outdated
Comment threadpackages/types/src/clerk.ts Outdated
Comment threadpackages/clerk-js/src/ui/Components.tsx Outdated
@@ -0,0 +1,135 @@
import type { __experimental_SessionVerificationFirstFactor, SignInFactor } from '@clerk/types';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@panteliselef what do you think about renaming this file to something UVFactorOneAlternativeMethods so it can match UVFactorTwoAlternativeMethods?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have no problem, there is a great chance that event the UV prefix will be replaced in the coming days as the component name is not final yet

@octoperoctoper left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔥

@panteliselef
panteliselef merged commit afad9af into mainAug 29, 2024
@panteliselef
panteliselef deleted the elef/user-607-userverification-ui-component branch August 29, 2024 17:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@panteliselef@alexcarpenter@octoper@LekoArts@chanioxaris@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimental - #4016

Merged
panteliselef merged 33 commits into
mainfrom
elef/user-607-userverification-ui-component
Aug 29, 2024
Merged

feat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimental#4016
panteliselef merged 33 commits into
mainfrom
elef/user-607-userverification-ui-component

Conversation

@panteliselef

@panteliselefpanteliselef commented Aug 26, 2024

Copy link
Copy Markdown
Contributor

Description

This PR introduces a new UI component called UserVerification as experimental. The new UI component allows for a user to "re-enter" their credentials (1fa/2fa) which results in them being reverified.

<UserVerification/> allows developers to easily build flows where verification is required before performing a sensitive action like updating other stored credentials or an application specific action like making a bank transfer.

Unit tests have been added which should make reviewers more confident. But more will follow (maybe some e2es) before the official launch.

APIs

clerk-js

exporttype__experimental_UserVerificationProps=RoutingOptions&{afterVerification?: ()=>void;afterVerificationUrl?: string;level?: 'L1.firstFactor'|'L2.secondFactor'|'L3.multiFactor';appearance?: UserVerificationTheme;};
__experimental_openUserVerification: (props?: __experimental_UserVerificationModalProps)=>void;
__experimental_closeUserVerification: ()=>void;
__experimental_mountUserVerification: (targetNode: HTMLDivElement,props?: __experimental_UserVerificationProps,)=>void;
__experimental_unmountUserVerification: (targetNode: HTMLDivElement)=>void;

clerk-react

import{__experimental_UserVerification}from'@clerk/clerk-react'<__experimental_UserVerification/>

2fa flow (the default)

default.mov

1fa flow

1fa.mov

multi factor flow (the above two combined)

mfa.mov

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-botBot commented Aug 26, 2024

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0e5d8d2

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 18 packages
NameType
@clerk/localizationsMinor
@clerk/chrome-extensionMinor
@clerk/nextjsMinor
@clerk/clerk-reactMinor
@clerk/clerk-jsMinor
@clerk/typesMinor
@clerk/elementsPatch
@clerk/clerk-expoPatch
@clerk/remixPatch
@clerk/tanstack-startPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/clerk-sdk-nodePatch
@clerk/sharedPatch
@clerk/testingPatch
@clerk/themesPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch 2 times, most recently from c2a8280 to efd5e79CompareAugust 26, 2024 10:35
@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from efd5e79 to ee6706aCompareAugust 26, 2024 11:02
@panteliselefpanteliselef self-assigned this Aug 27, 2024
@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from 28a6490 to 02aea2aCompareAugust 27, 2024 14:11
routing: 'virtual',
}}
>
{/*TODO: Used by InvisibleRootBox, can we simplify? */}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For reviewers: Carried from SignIn

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from fb4b3ea to 8cb52f6CompareAugust 27, 2024 20:37
Comment on lines +8 to +14
export function useAlternativeStrategies({
filterOutFactor,
supportedFirstFactors: _supportedFirstFactors,
}: {
filterOutFactor: SignInFactor | null | undefined;
supportedFirstFactors: SignInFirstFactor[] | null | undefined;
}) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For reviewers: I made this change in order to share the functionality across SignIn and UserVerification. Simply having the caller doing const { supportedFirstFactors } = useCoreSignIn(); seems like a good trade off.

Comment on lines +63 to +69
{/*<input*/}
{/* readOnly*/}
{/* id='identifier-field'*/}
{/* name='identifier'*/}
{/* value={signIn.identifier || ''}*/}
{/* style={{ display: 'none' }}*/}
{/*/>*/}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chanioxaris any ideas what we can use to solve this while the user is signed in ?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can use the existing function that picks up the identifier based on the user attributes

Comment threadpackages/localizations/src/en-US.ts Outdated
getHelp: {
blockButton__emailSupport: 'Email support',
content:
'If you’re experiencing difficulty signing into your account, email us and we will work with you to restore access as soon as possible.',

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (2/2)

Comment threadpackages/localizations/src/en-US.ts Outdated
Comment on lines +562 to +563
content:
'If you’re experiencing difficulty verifying your account, email us and we will work with you to restore access as soon as possible.',

@panteliselefpanteliselefAug 27, 2024

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (2/4)

actionText: 'Don’t have any of these?',
blockButton__backupCode: 'Use a backup code',
blockButton__emailCode: 'Email code to {{identifier}}',
blockButton__password: 'Continue with your password',

@panteliselefpanteliselefAug 27, 2024

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (1/4)

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from 388258a to c0fa2c3CompareAugust 27, 2024 20:42
@panteliselef
panteliselef marked this pull request as ready for review August 28, 2024 09:19
@panteliselef
panteliselef requested a review from a teamAugust 28, 2024 09:19
…-component
# Conflicts:
#	packages/clerk-js/bundlewatch.config.json
#	packages/clerk-js/src/ui/components/SignIn/SignInFactorOne.tsx
#	packages/clerk-js/src/ui/components/SignIn/SignInFactorOnePasswordCard.tsx
#	packages/clerk-js/src/ui/lazyModules/components.ts
'If you’re experiencing difficulty verifying your account, email us and we will work with you to restore access as soon as possible.',
title: 'Get help',
},
subtitle: 'Facing issues? You can use any of these methods for verification.',

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (3/4)

title: 'Check your email',
},
noAvailableMethods: {
message: "Cannot proceed with verification. There's no available authentication factor.",

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (4/4)

@panteliselefpanteliselef changed the title Introduce UserVerificationIntroduce UserVerification as experimentalAug 28, 2024
@panteliselefpanteliselef changed the title Introduce UserVerification as experimentalfeat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimentalAug 28, 2024
Comment thread.changeset/calm-zoos-sort.md Outdated
Comment thread.changeset/fifty-ravens-attack.md Outdated
Comment thread.changeset/healthy-colts-look.md Outdated
Comment thread.changeset/healthy-colts-look.md Outdated
Comment thread.changeset/proud-dryers-smile.md Outdated
});
});

it.todo('renders the component for with strategy:phone_code');

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TODO ⚠️

Comment on lines +116 to +122
describe('Use another method', () => {
it.todo('should list enabled first factor methods without the current one');
});

describe('Get Help', () => {
it.todo('should render the get help component when clicking the "Get Help" button');
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TODOs

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These will be added in a future PR (soon)

Comment threadpackages/localizations/src/en-US.ts Outdated
Comment threadpackages/types/src/clerk.ts Outdated
Comment threadpackages/clerk-js/src/ui/Components.tsx Outdated
@@ -0,0 +1,135 @@
import type { __experimental_SessionVerificationFirstFactor, SignInFactor } from '@clerk/types';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@panteliselef what do you think about renaming this file to something UVFactorOneAlternativeMethods so it can match UVFactorTwoAlternativeMethods?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have no problem, there is a great chance that event the UV prefix will be replaced in the coming days as the component name is not final yet

@octoperoctoper left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔥

@panteliselef
panteliselef merged commit afad9af into mainAug 29, 2024
@panteliselef
panteliselef deleted the elef/user-607-userverification-ui-component branch August 29, 2024 17:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@panteliselef@alexcarpenter@octoper@LekoArts@chanioxaris@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimental - #4016

Merged
panteliselef merged 33 commits into
mainfrom
elef/user-607-userverification-ui-component
Aug 29, 2024
Merged

feat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimental#4016
panteliselef merged 33 commits into
mainfrom
elef/user-607-userverification-ui-component

Conversation

@panteliselef

@panteliselefpanteliselef commented Aug 26, 2024

Copy link
Copy Markdown
Contributor

Description

This PR introduces a new UI component called UserVerification as experimental. The new UI component allows for a user to "re-enter" their credentials (1fa/2fa) which results in them being reverified.

<UserVerification/> allows developers to easily build flows where verification is required before performing a sensitive action like updating other stored credentials or an application specific action like making a bank transfer.

Unit tests have been added which should make reviewers more confident. But more will follow (maybe some e2es) before the official launch.

APIs

clerk-js

exporttype__experimental_UserVerificationProps=RoutingOptions&{afterVerification?: ()=>void;afterVerificationUrl?: string;level?: 'L1.firstFactor'|'L2.secondFactor'|'L3.multiFactor';appearance?: UserVerificationTheme;};
__experimental_openUserVerification: (props?: __experimental_UserVerificationModalProps)=>void;
__experimental_closeUserVerification: ()=>void;
__experimental_mountUserVerification: (targetNode: HTMLDivElement,props?: __experimental_UserVerificationProps,)=>void;
__experimental_unmountUserVerification: (targetNode: HTMLDivElement)=>void;

clerk-react

import{__experimental_UserVerification}from'@clerk/clerk-react'<__experimental_UserVerification/>

2fa flow (the default)

default.mov

1fa flow

1fa.mov

multi factor flow (the above two combined)

mfa.mov

Checklist

  • npm test runs as expected.
  • npm run build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-botBot commented Aug 26, 2024

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0e5d8d2

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 18 packages
NameType
@clerk/localizationsMinor
@clerk/chrome-extensionMinor
@clerk/nextjsMinor
@clerk/clerk-reactMinor
@clerk/clerk-jsMinor
@clerk/typesMinor
@clerk/elementsPatch
@clerk/clerk-expoPatch
@clerk/remixPatch
@clerk/tanstack-startPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/clerk-sdk-nodePatch
@clerk/sharedPatch
@clerk/testingPatch
@clerk/themesPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch 2 times, most recently from c2a8280 to efd5e79CompareAugust 26, 2024 10:35
@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from efd5e79 to ee6706aCompareAugust 26, 2024 11:02
@panteliselefpanteliselef self-assigned this Aug 27, 2024
@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from 28a6490 to 02aea2aCompareAugust 27, 2024 14:11
routing: 'virtual',
}}
>
{/*TODO: Used by InvisibleRootBox, can we simplify? */}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For reviewers: Carried from SignIn

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from fb4b3ea to 8cb52f6CompareAugust 27, 2024 20:37
Comment on lines +8 to +14
export function useAlternativeStrategies({
filterOutFactor,
supportedFirstFactors: _supportedFirstFactors,
}: {
filterOutFactor: SignInFactor | null | undefined;
supportedFirstFactors: SignInFirstFactor[] | null | undefined;
}) {

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For reviewers: I made this change in order to share the functionality across SignIn and UserVerification. Simply having the caller doing const { supportedFirstFactors } = useCoreSignIn(); seems like a good trade off.

Comment on lines +63 to +69
{/*<input*/}
{/* readOnly*/}
{/* id='identifier-field'*/}
{/* name='identifier'*/}
{/* value={signIn.identifier || ''}*/}
{/* style={{ display: 'none' }}*/}
{/*/>*/}

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chanioxaris any ideas what we can use to solve this while the user is signed in ?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can use the existing function that picks up the identifier based on the user attributes

Comment threadpackages/localizations/src/en-US.ts Outdated
getHelp: {
blockButton__emailSupport: 'Email support',
content:
'If you’re experiencing difficulty signing into your account, email us and we will work with you to restore access as soon as possible.',

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (2/2)

Comment threadpackages/localizations/src/en-US.ts Outdated
Comment on lines +562 to +563
content:
'If you’re experiencing difficulty verifying your account, email us and we will work with you to restore access as soon as possible.',

@panteliselefpanteliselefAug 27, 2024

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (2/4)

actionText: 'Don’t have any of these?',
blockButton__backupCode: 'Use a backup code',
blockButton__emailCode: 'Email code to {{identifier}}',
blockButton__password: 'Continue with your password',

@panteliselefpanteliselefAug 27, 2024

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (1/4)

@panteliselef
panteliselefforce-pushed the elef/user-607-userverification-ui-component branch from 388258a to c0fa2c3CompareAugust 27, 2024 20:42
@panteliselef
panteliselef marked this pull request as ready for review August 28, 2024 09:19
@panteliselef
panteliselef requested a review from a teamAugust 28, 2024 09:19
…-component
# Conflicts:
#	packages/clerk-js/bundlewatch.config.json
#	packages/clerk-js/src/ui/components/SignIn/SignInFactorOne.tsx
#	packages/clerk-js/src/ui/components/SignIn/SignInFactorOnePasswordCard.tsx
#	packages/clerk-js/src/ui/lazyModules/components.ts
'If you’re experiencing difficulty verifying your account, email us and we will work with you to restore access as soon as possible.',
title: 'Get help',
},
subtitle: 'Facing issues? You can use any of these methods for verification.',

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (3/4)

title: 'Check your email',
},
noAvailableMethods: {
message: "Cannot proceed with verification. There's no available authentication factor.",

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All items are the same as sign in, except this one (4/4)

@panteliselefpanteliselef changed the title Introduce UserVerificationIntroduce UserVerification as experimentalAug 28, 2024
@panteliselefpanteliselef changed the title Introduce UserVerification as experimentalfeat(clerk-js,types,nextjs,localizations,clerk-react): Introduce UserVerification as experimentalAug 28, 2024
Comment thread.changeset/calm-zoos-sort.md Outdated
Comment thread.changeset/fifty-ravens-attack.md Outdated
Comment thread.changeset/healthy-colts-look.md Outdated
Comment thread.changeset/healthy-colts-look.md Outdated
Comment thread.changeset/proud-dryers-smile.md Outdated
});
});

it.todo('renders the component for with strategy:phone_code');

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TODO ⚠️

Comment on lines +116 to +122
describe('Use another method', () => {
it.todo('should list enabled first factor methods without the current one');
});

describe('Get Help', () => {
it.todo('should render the get help component when clicking the "Get Help" button');
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TODOs

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These will be added in a future PR (soon)

Comment threadpackages/localizations/src/en-US.ts Outdated
Comment threadpackages/types/src/clerk.ts Outdated
Comment threadpackages/clerk-js/src/ui/Components.tsx Outdated
@@ -0,0 +1,135 @@
import type { __experimental_SessionVerificationFirstFactor, SignInFactor } from '@clerk/types';

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@panteliselef what do you think about renaming this file to something UVFactorOneAlternativeMethods so it can match UVFactorTwoAlternativeMethods?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have no problem, there is a great chance that event the UV prefix will be replaced in the coming days as the component name is not final yet

@octoperoctoper left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔥

@panteliselef
panteliselef merged commit afad9af into mainAug 29, 2024
@panteliselef
panteliselef deleted the elef/user-607-userverification-ui-component branch August 29, 2024 17:18
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@panteliselef@alexcarpenter@octoper@LekoArts@chanioxaris@clerk-cookie