5 changes: 5 additions & 0 deletions .changeset/new-fishes-rescue.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
---
'@clerk/clerk-js': patch
---

Bug fix: Broadcast a sign out event to all opened tabs when `Clerk.signOut()` or `User.delete()` is called.
12 changes: 8 additions & 4 deletions integration/testUtils/index.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -36,10 +36,14 @@ const createExpectPageObject = ({ page }: TestArgs) => {
expect(redirect.status()).toBe(307);
expect(redirect.headers()['x-clerk-auth-status']).toContain('handshake');
},
toBeSignedOut: () => {
return page.waitForFunction(() => {
return !window.Clerk?.user;
});
toBeSignedOut: (args?: { timeOut: number }) => {
return page.waitForFunction(
() => {
return !window.Clerk?.user;
},
null,
{ timeout: args?.timeOut },
);
},
toBeSignedIn: async () => {
return page.waitForFunction(() => {
Expand Down
2 changes: 1 addition & 1 deletion integration/tests/sign-out-smoke.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,7 +55,7 @@ testAgainstRunningApps({ withEnv: [appConfigs.envs.withEmailCodes] })('sign out
await m.po.expect.toBeSignedOut();
});

await mainTab.po.expect.toBeSignedOut();
await mainTab.po.expect.toBeSignedOut({ timeOut: 2 * 1_000 });

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously the test was passing after 40-50 seconds because either /touch or /tokens would force update the state.

});

test('sign out persisting client', async ({ page, context }) => {
Expand Down
30 changes: 16 additions & 14 deletions packages/clerk-js/src/core/clerk.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -374,6 +374,9 @@ export class Clerk implements ClerkInterface {

const handleSetActive = () => {
const signOutCallback = typeof callbackOrOptions === 'function' ? callbackOrOptions : undefined;

// Notify other tabs that user is signing out.
eventBus.dispatch(events.UserSignOut, null);
Comment on lines +378 to +379

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ should we be doing this later in the sign out flow?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously inside setActive it was one of the first things that got called. And since by that point we have already cleared cookies seems appropriate.

if (signOutCallback) {
return this.setActive({
session: null,
Expand DownExpand Up@@ -908,14 +911,6 @@ export class Clerk implements ClerkInterface {

await onBeforeSetActive();

// If this.session exists, then signOut was triggered by the current tab
// and should emit. Other tabs should not emit the same event again
const shouldSignOutSession = this.session && newSession === null;
if (shouldSignOutSession) {
this.#broadcastSignOutEvent();
eventBus.dispatch(events.TokenUpdate, { token: null });
}

Comment on lines -911 to -918

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since we are no longer delete the client on sign out, this.session would always be null, causing broadcasting to never occur.

Also removing eventBus.dispatch(events.TokenUpdate, { token: null }) does not cause issues, because the code a few lines below will handle it appropriately.

//1. setLastActiveSession to passed user session (add a param).
// Note that this will also update the session's active organization
// id.
Expand DownExpand Up@@ -1534,6 +1529,7 @@ export class Clerk implements ClerkInterface {
});
};

// TODO: Deprecate this one, and mark it as internal. Is there actual benefit for external developers to use this ? Should they ever reach for it ?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about this ? Would we ever ask people to use this in a custom flow ?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Most likely not, it should really be something that's handled internally.

public handleUnauthenticated = async (opts = { broadcast: true }): Promise<unknown> => {
if (!this.client || !this.session) {
return;
Expand All@@ -1545,7 +1541,7 @@ export class Clerk implements ClerkInterface {
return;
}
if (opts.broadcast) {
this.#broadcastSignOutEvent();
eventBus.dispatch(events.UserSignOut, null);
}
return this.setActive({ session: null });
} catch (err) {
Expand DownExpand Up@@ -2061,11 +2057,21 @@ export class Clerk implements ClerkInterface {
this.#sessionTouchOfflineScheduler.schedule(performTouch);
});

/**
* Background tabs get notified of a signout event from active tab.
*/
this.#broadcastChannel?.addEventListener('message', ({ data }) => {
if (data.type === 'signout') {
void this.handleUnauthenticated();
void this.handleUnauthenticated({ broadcast: false });
}
});

/**
* Allow resources within the singleton to notify other tabs about a signout event (scoped to a single tab)
*/
eventBus.on(events.UserSignOut, () => {
this.#broadcastChannel?.postMessage({ type: 'signout' });
});
};

// TODO: Be more conservative about touches. Throttle, don't touch when only one user, etc
Expand DownExpand Up@@ -2100,10 +2106,6 @@ export class Clerk implements ClerkInterface {
}
};

#broadcastSignOutEvent = () => {
this.#broadcastChannel?.postMessage({ type: 'signout' });
};

#setTransitiveState = () => {
this.session = undefined;
this.organization = undefined;
Expand Down
2 changes: 2 additions & 0 deletions packages/clerk-js/src/core/events.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,6 +2,7 @@ import type { TokenResource } from '@clerk/types';

export const events = {
TokenUpdate: 'token:update',
UserSignOut: 'user:signOut',

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💭 (optional) what do you think about just calling this even signOut? I'm not sure we need the user: scope.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking the same, I added the scope to respect the pattern. Since it does not do any harm, I think I'll leave it as is.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fair enough, I wouldn't say 1 event indicates a pattern though 😉

} as const;

type ClerkEvent = (typeof events)[keyof typeof events];
Expand All@@ -11,6 +12,7 @@ type TokenUpdatePayload = { token: TokenResource | null };

type EventPayload = {
[events.TokenUpdate]: TokenUpdatePayload;
[events.UserSignOut]: null;
};

const createEventBus = () => {
Expand Down
5 changes: 4 additions & 1 deletion packages/clerk-js/src/core/resources/Client.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -83,7 +83,10 @@ export class Client extends BaseResource implements ClientResource {
removeSessions(): Promise<ClientResource> {
return this._baseDelete({
path: this.path() + '/sessions',
}) as unknown as Promise<ClientResource>;
}).then(e => {
SessionTokenCache.clear();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this is the right place for this call. What's the desired behavior? SessionTokenCache is cleared on sign out?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correct, clearing the cache on sign out.

We're calling SessionTokenCache.clear() on Client.destroy(), on Session.end(), and on Session.remove(). Giving the fact that we clear the cache on an individual session removal, i think we should do the same when removing all of them.

return e as unknown as ClientResource;
});
}

clearCache(): void {
Expand Down
6 changes: 5 additions & 1 deletion packages/clerk-js/src/core/resources/User.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -35,6 +35,7 @@ import type {
import { unixEpochToDate } from '../../utils/date';
import { normalizeUnsafeMetadata } from '../../utils/resourceParams';
import { getFullName } from '../../utils/user';
import { eventBus, events } from '../events';
import { BackupCode } from './BackupCode';
import {
BaseResource,
Expand DownExpand Up@@ -241,7 +242,10 @@ export class User extends BaseResource implements UserResource {
};

delete = (): Promise<void> => {
return this._baseDelete({ path: '/me' });
return this._baseDelete({ path: '/me' }).then(res => {
eventBus.dispatch(events.UserSignOut, null);
return res;
});
};

getSessions = async (): Promise<SessionWithActivities[]> => {
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
5 changes: 5 additions & 0 deletions .changeset/new-fishes-rescue.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
---
'@clerk/clerk-js': patch
---

Bug fix: Broadcast a sign out event to all opened tabs when `Clerk.signOut()` or `User.delete()` is called.
12 changes: 8 additions & 4 deletions integration/testUtils/index.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -36,10 +36,14 @@ const createExpectPageObject = ({ page }: TestArgs) => {
expect(redirect.status()).toBe(307);
expect(redirect.headers()['x-clerk-auth-status']).toContain('handshake');
},
toBeSignedOut: () => {
return page.waitForFunction(() => {
return !window.Clerk?.user;
});
toBeSignedOut: (args?: { timeOut: number }) => {
return page.waitForFunction(
() => {
return !window.Clerk?.user;
},
null,
{ timeout: args?.timeOut },
);
},
toBeSignedIn: async () => {
return page.waitForFunction(() => {
Expand Down
2 changes: 1 addition & 1 deletion integration/tests/sign-out-smoke.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,7 +55,7 @@ testAgainstRunningApps({ withEnv: [appConfigs.envs.withEmailCodes] })('sign out
await m.po.expect.toBeSignedOut();
});

await mainTab.po.expect.toBeSignedOut();
await mainTab.po.expect.toBeSignedOut({ timeOut: 2 * 1_000 });

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously the test was passing after 40-50 seconds because either /touch or /tokens would force update the state.

});

test('sign out persisting client', async ({ page, context }) => {
Expand Down
30 changes: 16 additions & 14 deletions packages/clerk-js/src/core/clerk.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -374,6 +374,9 @@ export class Clerk implements ClerkInterface {

const handleSetActive = () => {
const signOutCallback = typeof callbackOrOptions === 'function' ? callbackOrOptions : undefined;

// Notify other tabs that user is signing out.
eventBus.dispatch(events.UserSignOut, null);
Comment on lines +378 to +379

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ should we be doing this later in the sign out flow?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously inside setActive it was one of the first things that got called. And since by that point we have already cleared cookies seems appropriate.

if (signOutCallback) {
return this.setActive({
session: null,
Expand DownExpand Up@@ -908,14 +911,6 @@ export class Clerk implements ClerkInterface {

await onBeforeSetActive();

// If this.session exists, then signOut was triggered by the current tab
// and should emit. Other tabs should not emit the same event again
const shouldSignOutSession = this.session && newSession === null;
if (shouldSignOutSession) {
this.#broadcastSignOutEvent();
eventBus.dispatch(events.TokenUpdate, { token: null });
}

Comment on lines -911 to -918

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since we are no longer delete the client on sign out, this.session would always be null, causing broadcasting to never occur.

Also removing eventBus.dispatch(events.TokenUpdate, { token: null }) does not cause issues, because the code a few lines below will handle it appropriately.

//1. setLastActiveSession to passed user session (add a param).
// Note that this will also update the session's active organization
// id.
Expand DownExpand Up@@ -1534,6 +1529,7 @@ export class Clerk implements ClerkInterface {
});
};

// TODO: Deprecate this one, and mark it as internal. Is there actual benefit for external developers to use this ? Should they ever reach for it ?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about this ? Would we ever ask people to use this in a custom flow ?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Most likely not, it should really be something that's handled internally.

public handleUnauthenticated = async (opts = { broadcast: true }): Promise<unknown> => {
if (!this.client || !this.session) {
return;
Expand All@@ -1545,7 +1541,7 @@ export class Clerk implements ClerkInterface {
return;
}
if (opts.broadcast) {
this.#broadcastSignOutEvent();
eventBus.dispatch(events.UserSignOut, null);
}
return this.setActive({ session: null });
} catch (err) {
Expand DownExpand Up@@ -2061,11 +2057,21 @@ export class Clerk implements ClerkInterface {
this.#sessionTouchOfflineScheduler.schedule(performTouch);
});

/**
* Background tabs get notified of a signout event from active tab.
*/
this.#broadcastChannel?.addEventListener('message', ({ data }) => {
if (data.type === 'signout') {
void this.handleUnauthenticated();
void this.handleUnauthenticated({ broadcast: false });
}
});

/**
* Allow resources within the singleton to notify other tabs about a signout event (scoped to a single tab)
*/
eventBus.on(events.UserSignOut, () => {
this.#broadcastChannel?.postMessage({ type: 'signout' });
});
};

// TODO: Be more conservative about touches. Throttle, don't touch when only one user, etc
Expand DownExpand Up@@ -2100,10 +2106,6 @@ export class Clerk implements ClerkInterface {
}
};

#broadcastSignOutEvent = () => {
this.#broadcastChannel?.postMessage({ type: 'signout' });
};

#setTransitiveState = () => {
this.session = undefined;
this.organization = undefined;
Expand Down
2 changes: 2 additions & 0 deletions packages/clerk-js/src/core/events.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,6 +2,7 @@ import type { TokenResource } from '@clerk/types';

export const events = {
TokenUpdate: 'token:update',
UserSignOut: 'user:signOut',

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💭 (optional) what do you think about just calling this even signOut? I'm not sure we need the user: scope.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking the same, I added the scope to respect the pattern. Since it does not do any harm, I think I'll leave it as is.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fair enough, I wouldn't say 1 event indicates a pattern though 😉

} as const;

type ClerkEvent = (typeof events)[keyof typeof events];
Expand All@@ -11,6 +12,7 @@ type TokenUpdatePayload = { token: TokenResource | null };

type EventPayload = {
[events.TokenUpdate]: TokenUpdatePayload;
[events.UserSignOut]: null;
};

const createEventBus = () => {
Expand Down
5 changes: 4 additions & 1 deletion packages/clerk-js/src/core/resources/Client.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -83,7 +83,10 @@ export class Client extends BaseResource implements ClientResource {
removeSessions(): Promise<ClientResource> {
return this._baseDelete({
path: this.path() + '/sessions',
}) as unknown as Promise<ClientResource>;
}).then(e => {
SessionTokenCache.clear();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this is the right place for this call. What's the desired behavior? SessionTokenCache is cleared on sign out?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correct, clearing the cache on sign out.

We're calling SessionTokenCache.clear() on Client.destroy(), on Session.end(), and on Session.remove(). Giving the fact that we clear the cache on an individual session removal, i think we should do the same when removing all of them.

return e as unknown as ClientResource;
});
}

clearCache(): void {
Expand Down
6 changes: 5 additions & 1 deletion packages/clerk-js/src/core/resources/User.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -35,6 +35,7 @@ import type {
import { unixEpochToDate } from '../../utils/date';
import { normalizeUnsafeMetadata } from '../../utils/resourceParams';
import { getFullName } from '../../utils/user';
import { eventBus, events } from '../events';
import { BackupCode } from './BackupCode';
import {
BaseResource,
Expand DownExpand Up@@ -241,7 +242,10 @@ export class User extends BaseResource implements UserResource {
};

delete = (): Promise<void> => {
return this._baseDelete({ path: '/me' });
return this._baseDelete({ path: '/me' }).then(res => {
eventBus.dispatch(events.UserSignOut, null);
return res;
});
};

getSessions = async (): Promise<SessionWithActivities[]> => {
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
5 changes: 5 additions & 0 deletions .changeset/new-fishes-rescue.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
---
'@clerk/clerk-js': patch
---

Bug fix: Broadcast a sign out event to all opened tabs when `Clerk.signOut()` or `User.delete()` is called.
12 changes: 8 additions & 4 deletions integration/testUtils/index.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -36,10 +36,14 @@ const createExpectPageObject = ({ page }: TestArgs) => {
expect(redirect.status()).toBe(307);
expect(redirect.headers()['x-clerk-auth-status']).toContain('handshake');
},
toBeSignedOut: () => {
return page.waitForFunction(() => {
return !window.Clerk?.user;
});
toBeSignedOut: (args?: { timeOut: number }) => {
return page.waitForFunction(
() => {
return !window.Clerk?.user;
},
null,
{ timeout: args?.timeOut },
);
},
toBeSignedIn: async () => {
return page.waitForFunction(() => {
Expand Down
2 changes: 1 addition & 1 deletion integration/tests/sign-out-smoke.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,7 +55,7 @@ testAgainstRunningApps({ withEnv: [appConfigs.envs.withEmailCodes] })('sign out
await m.po.expect.toBeSignedOut();
});

await mainTab.po.expect.toBeSignedOut();
await mainTab.po.expect.toBeSignedOut({ timeOut: 2 * 1_000 });

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously the test was passing after 40-50 seconds because either /touch or /tokens would force update the state.

});

test('sign out persisting client', async ({ page, context }) => {
Expand Down
30 changes: 16 additions & 14 deletions packages/clerk-js/src/core/clerk.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -374,6 +374,9 @@ export class Clerk implements ClerkInterface {

const handleSetActive = () => {
const signOutCallback = typeof callbackOrOptions === 'function' ? callbackOrOptions : undefined;

// Notify other tabs that user is signing out.
eventBus.dispatch(events.UserSignOut, null);
Comment on lines +378 to +379

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ should we be doing this later in the sign out flow?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously inside setActive it was one of the first things that got called. And since by that point we have already cleared cookies seems appropriate.

if (signOutCallback) {
return this.setActive({
session: null,
Expand DownExpand Up@@ -908,14 +911,6 @@ export class Clerk implements ClerkInterface {

await onBeforeSetActive();

// If this.session exists, then signOut was triggered by the current tab
// and should emit. Other tabs should not emit the same event again
const shouldSignOutSession = this.session && newSession === null;
if (shouldSignOutSession) {
this.#broadcastSignOutEvent();
eventBus.dispatch(events.TokenUpdate, { token: null });
}

Comment on lines -911 to -918

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since we are no longer delete the client on sign out, this.session would always be null, causing broadcasting to never occur.

Also removing eventBus.dispatch(events.TokenUpdate, { token: null }) does not cause issues, because the code a few lines below will handle it appropriately.

//1. setLastActiveSession to passed user session (add a param).
// Note that this will also update the session's active organization
// id.
Expand DownExpand Up@@ -1534,6 +1529,7 @@ export class Clerk implements ClerkInterface {
});
};

// TODO: Deprecate this one, and mark it as internal. Is there actual benefit for external developers to use this ? Should they ever reach for it ?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about this ? Would we ever ask people to use this in a custom flow ?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Most likely not, it should really be something that's handled internally.

public handleUnauthenticated = async (opts = { broadcast: true }): Promise<unknown> => {
if (!this.client || !this.session) {
return;
Expand All@@ -1545,7 +1541,7 @@ export class Clerk implements ClerkInterface {
return;
}
if (opts.broadcast) {
this.#broadcastSignOutEvent();
eventBus.dispatch(events.UserSignOut, null);
}
return this.setActive({ session: null });
} catch (err) {
Expand DownExpand Up@@ -2061,11 +2057,21 @@ export class Clerk implements ClerkInterface {
this.#sessionTouchOfflineScheduler.schedule(performTouch);
});

/**
* Background tabs get notified of a signout event from active tab.
*/
this.#broadcastChannel?.addEventListener('message', ({ data }) => {
if (data.type === 'signout') {
void this.handleUnauthenticated();
void this.handleUnauthenticated({ broadcast: false });
}
});

/**
* Allow resources within the singleton to notify other tabs about a signout event (scoped to a single tab)
*/
eventBus.on(events.UserSignOut, () => {
this.#broadcastChannel?.postMessage({ type: 'signout' });
});
};

// TODO: Be more conservative about touches. Throttle, don't touch when only one user, etc
Expand DownExpand Up@@ -2100,10 +2106,6 @@ export class Clerk implements ClerkInterface {
}
};

#broadcastSignOutEvent = () => {
this.#broadcastChannel?.postMessage({ type: 'signout' });
};

#setTransitiveState = () => {
this.session = undefined;
this.organization = undefined;
Expand Down
2 changes: 2 additions & 0 deletions packages/clerk-js/src/core/events.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,6 +2,7 @@ import type { TokenResource } from '@clerk/types';

export const events = {
TokenUpdate: 'token:update',
UserSignOut: 'user:signOut',

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💭 (optional) what do you think about just calling this even signOut? I'm not sure we need the user: scope.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking the same, I added the scope to respect the pattern. Since it does not do any harm, I think I'll leave it as is.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fair enough, I wouldn't say 1 event indicates a pattern though 😉

} as const;

type ClerkEvent = (typeof events)[keyof typeof events];
Expand All@@ -11,6 +12,7 @@ type TokenUpdatePayload = { token: TokenResource | null };

type EventPayload = {
[events.TokenUpdate]: TokenUpdatePayload;
[events.UserSignOut]: null;
};

const createEventBus = () => {
Expand Down
5 changes: 4 additions & 1 deletion packages/clerk-js/src/core/resources/Client.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -83,7 +83,10 @@ export class Client extends BaseResource implements ClientResource {
removeSessions(): Promise<ClientResource> {
return this._baseDelete({
path: this.path() + '/sessions',
}) as unknown as Promise<ClientResource>;
}).then(e => {
SessionTokenCache.clear();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this is the right place for this call. What's the desired behavior? SessionTokenCache is cleared on sign out?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correct, clearing the cache on sign out.

We're calling SessionTokenCache.clear() on Client.destroy(), on Session.end(), and on Session.remove(). Giving the fact that we clear the cache on an individual session removal, i think we should do the same when removing all of them.

return e as unknown as ClientResource;
});
}

clearCache(): void {
Expand Down
6 changes: 5 additions & 1 deletion packages/clerk-js/src/core/resources/User.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -35,6 +35,7 @@ import type {
import { unixEpochToDate } from '../../utils/date';
import { normalizeUnsafeMetadata } from '../../utils/resourceParams';
import { getFullName } from '../../utils/user';
import { eventBus, events } from '../events';
import { BackupCode } from './BackupCode';
import {
BaseResource,
Expand DownExpand Up@@ -241,7 +242,10 @@ export class User extends BaseResource implements UserResource {
};

delete = (): Promise<void> => {
return this._baseDelete({ path: '/me' });
return this._baseDelete({ path: '/me' }).then(res => {
eventBus.dispatch(events.UserSignOut, null);
return res;
});
};

getSessions = async (): Promise<SessionWithActivities[]> => {
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
5 changes: 5 additions & 0 deletions .changeset/new-fishes-rescue.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
---
'@clerk/clerk-js': patch
---

Bug fix: Broadcast a sign out event to all opened tabs when `Clerk.signOut()` or `User.delete()` is called.
12 changes: 8 additions & 4 deletions integration/testUtils/index.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -36,10 +36,14 @@ const createExpectPageObject = ({ page }: TestArgs) => {
expect(redirect.status()).toBe(307);
expect(redirect.headers()['x-clerk-auth-status']).toContain('handshake');
},
toBeSignedOut: () => {
return page.waitForFunction(() => {
return !window.Clerk?.user;
});
toBeSignedOut: (args?: { timeOut: number }) => {
return page.waitForFunction(
() => {
return !window.Clerk?.user;
},
null,
{ timeout: args?.timeOut },
);
},
toBeSignedIn: async () => {
return page.waitForFunction(() => {
Expand Down
2 changes: 1 addition & 1 deletion integration/tests/sign-out-smoke.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,7 +55,7 @@ testAgainstRunningApps({ withEnv: [appConfigs.envs.withEmailCodes] })('sign out
await m.po.expect.toBeSignedOut();
});

await mainTab.po.expect.toBeSignedOut();
await mainTab.po.expect.toBeSignedOut({ timeOut: 2 * 1_000 });

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously the test was passing after 40-50 seconds because either /touch or /tokens would force update the state.

});

test('sign out persisting client', async ({ page, context }) => {
Expand Down
30 changes: 16 additions & 14 deletions packages/clerk-js/src/core/clerk.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -374,6 +374,9 @@ export class Clerk implements ClerkInterface {

const handleSetActive = () => {
const signOutCallback = typeof callbackOrOptions === 'function' ? callbackOrOptions : undefined;

// Notify other tabs that user is signing out.
eventBus.dispatch(events.UserSignOut, null);
Comment on lines +378 to +379

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ should we be doing this later in the sign out flow?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously inside setActive it was one of the first things that got called. And since by that point we have already cleared cookies seems appropriate.

if (signOutCallback) {
return this.setActive({
session: null,
Expand DownExpand Up@@ -908,14 +911,6 @@ export class Clerk implements ClerkInterface {

await onBeforeSetActive();

// If this.session exists, then signOut was triggered by the current tab
// and should emit. Other tabs should not emit the same event again
const shouldSignOutSession = this.session && newSession === null;
if (shouldSignOutSession) {
this.#broadcastSignOutEvent();
eventBus.dispatch(events.TokenUpdate, { token: null });
}

Comment on lines -911 to -918

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since we are no longer delete the client on sign out, this.session would always be null, causing broadcasting to never occur.

Also removing eventBus.dispatch(events.TokenUpdate, { token: null }) does not cause issues, because the code a few lines below will handle it appropriately.

//1. setLastActiveSession to passed user session (add a param).
// Note that this will also update the session's active organization
// id.
Expand DownExpand Up@@ -1534,6 +1529,7 @@ export class Clerk implements ClerkInterface {
});
};

// TODO: Deprecate this one, and mark it as internal. Is there actual benefit for external developers to use this ? Should they ever reach for it ?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about this ? Would we ever ask people to use this in a custom flow ?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Most likely not, it should really be something that's handled internally.

public handleUnauthenticated = async (opts = { broadcast: true }): Promise<unknown> => {
if (!this.client || !this.session) {
return;
Expand All@@ -1545,7 +1541,7 @@ export class Clerk implements ClerkInterface {
return;
}
if (opts.broadcast) {
this.#broadcastSignOutEvent();
eventBus.dispatch(events.UserSignOut, null);
}
return this.setActive({ session: null });
} catch (err) {
Expand DownExpand Up@@ -2061,11 +2057,21 @@ export class Clerk implements ClerkInterface {
this.#sessionTouchOfflineScheduler.schedule(performTouch);
});

/**
* Background tabs get notified of a signout event from active tab.
*/
this.#broadcastChannel?.addEventListener('message', ({ data }) => {
if (data.type === 'signout') {
void this.handleUnauthenticated();
void this.handleUnauthenticated({ broadcast: false });
}
});

/**
* Allow resources within the singleton to notify other tabs about a signout event (scoped to a single tab)
*/
eventBus.on(events.UserSignOut, () => {
this.#broadcastChannel?.postMessage({ type: 'signout' });
});
};

// TODO: Be more conservative about touches. Throttle, don't touch when only one user, etc
Expand DownExpand Up@@ -2100,10 +2106,6 @@ export class Clerk implements ClerkInterface {
}
};

#broadcastSignOutEvent = () => {
this.#broadcastChannel?.postMessage({ type: 'signout' });
};

#setTransitiveState = () => {
this.session = undefined;
this.organization = undefined;
Expand Down
2 changes: 2 additions & 0 deletions packages/clerk-js/src/core/events.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,6 +2,7 @@ import type { TokenResource } from '@clerk/types';

export const events = {
TokenUpdate: 'token:update',
UserSignOut: 'user:signOut',

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💭 (optional) what do you think about just calling this even signOut? I'm not sure we need the user: scope.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking the same, I added the scope to respect the pattern. Since it does not do any harm, I think I'll leave it as is.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fair enough, I wouldn't say 1 event indicates a pattern though 😉

} as const;

type ClerkEvent = (typeof events)[keyof typeof events];
Expand All@@ -11,6 +12,7 @@ type TokenUpdatePayload = { token: TokenResource | null };

type EventPayload = {
[events.TokenUpdate]: TokenUpdatePayload;
[events.UserSignOut]: null;
};

const createEventBus = () => {
Expand Down
5 changes: 4 additions & 1 deletion packages/clerk-js/src/core/resources/Client.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -83,7 +83,10 @@ export class Client extends BaseResource implements ClientResource {
removeSessions(): Promise<ClientResource> {
return this._baseDelete({
path: this.path() + '/sessions',
}) as unknown as Promise<ClientResource>;
}).then(e => {
SessionTokenCache.clear();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this is the right place for this call. What's the desired behavior? SessionTokenCache is cleared on sign out?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correct, clearing the cache on sign out.

We're calling SessionTokenCache.clear() on Client.destroy(), on Session.end(), and on Session.remove(). Giving the fact that we clear the cache on an individual session removal, i think we should do the same when removing all of them.

return e as unknown as ClientResource;
});
}

clearCache(): void {
Expand Down
6 changes: 5 additions & 1 deletion packages/clerk-js/src/core/resources/User.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -35,6 +35,7 @@ import type {
import { unixEpochToDate } from '../../utils/date';
import { normalizeUnsafeMetadata } from '../../utils/resourceParams';
import { getFullName } from '../../utils/user';
import { eventBus, events } from '../events';
import { BackupCode } from './BackupCode';
import {
BaseResource,
Expand DownExpand Up@@ -241,7 +242,10 @@ export class User extends BaseResource implements UserResource {
};

delete = (): Promise<void> => {
return this._baseDelete({ path: '/me' });
return this._baseDelete({ path: '/me' }).then(res => {
eventBus.dispatch(events.UserSignOut, null);
return res;
});
};

getSessions = async (): Promise<SessionWithActivities[]> => {
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
5 changes: 5 additions & 0 deletions .changeset/new-fishes-rescue.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
---
'@clerk/clerk-js': patch
---

Bug fix: Broadcast a sign out event to all opened tabs when `Clerk.signOut()` or `User.delete()` is called.
12 changes: 8 additions & 4 deletions integration/testUtils/index.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -36,10 +36,14 @@ const createExpectPageObject = ({ page }: TestArgs) => {
expect(redirect.status()).toBe(307);
expect(redirect.headers()['x-clerk-auth-status']).toContain('handshake');
},
toBeSignedOut: () => {
return page.waitForFunction(() => {
return !window.Clerk?.user;
});
toBeSignedOut: (args?: { timeOut: number }) => {
return page.waitForFunction(
() => {
return !window.Clerk?.user;
},
null,
{ timeout: args?.timeOut },
);
},
toBeSignedIn: async () => {
return page.waitForFunction(() => {
Expand Down
2 changes: 1 addition & 1 deletion integration/tests/sign-out-smoke.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,7 +55,7 @@ testAgainstRunningApps({ withEnv: [appConfigs.envs.withEmailCodes] })('sign out
await m.po.expect.toBeSignedOut();
});

await mainTab.po.expect.toBeSignedOut();
await mainTab.po.expect.toBeSignedOut({ timeOut: 2 * 1_000 });

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously the test was passing after 40-50 seconds because either /touch or /tokens would force update the state.

});

test('sign out persisting client', async ({ page, context }) => {
Expand Down
30 changes: 16 additions & 14 deletions packages/clerk-js/src/core/clerk.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -374,6 +374,9 @@ export class Clerk implements ClerkInterface {

const handleSetActive = () => {
const signOutCallback = typeof callbackOrOptions === 'function' ? callbackOrOptions : undefined;

// Notify other tabs that user is signing out.
eventBus.dispatch(events.UserSignOut, null);
Comment on lines +378 to +379

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ should we be doing this later in the sign out flow?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously inside setActive it was one of the first things that got called. And since by that point we have already cleared cookies seems appropriate.

if (signOutCallback) {
return this.setActive({
session: null,
Expand DownExpand Up@@ -908,14 +911,6 @@ export class Clerk implements ClerkInterface {

await onBeforeSetActive();

// If this.session exists, then signOut was triggered by the current tab
// and should emit. Other tabs should not emit the same event again
const shouldSignOutSession = this.session && newSession === null;
if (shouldSignOutSession) {
this.#broadcastSignOutEvent();
eventBus.dispatch(events.TokenUpdate, { token: null });
}

Comment on lines -911 to -918

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since we are no longer delete the client on sign out, this.session would always be null, causing broadcasting to never occur.

Also removing eventBus.dispatch(events.TokenUpdate, { token: null }) does not cause issues, because the code a few lines below will handle it appropriately.

//1. setLastActiveSession to passed user session (add a param).
// Note that this will also update the session's active organization
// id.
Expand DownExpand Up@@ -1534,6 +1529,7 @@ export class Clerk implements ClerkInterface {
});
};

// TODO: Deprecate this one, and mark it as internal. Is there actual benefit for external developers to use this ? Should they ever reach for it ?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about this ? Would we ever ask people to use this in a custom flow ?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Most likely not, it should really be something that's handled internally.

public handleUnauthenticated = async (opts = { broadcast: true }): Promise<unknown> => {
if (!this.client || !this.session) {
return;
Expand All@@ -1545,7 +1541,7 @@ export class Clerk implements ClerkInterface {
return;
}
if (opts.broadcast) {
this.#broadcastSignOutEvent();
eventBus.dispatch(events.UserSignOut, null);
}
return this.setActive({ session: null });
} catch (err) {
Expand DownExpand Up@@ -2061,11 +2057,21 @@ export class Clerk implements ClerkInterface {
this.#sessionTouchOfflineScheduler.schedule(performTouch);
});

/**
* Background tabs get notified of a signout event from active tab.
*/
this.#broadcastChannel?.addEventListener('message', ({ data }) => {
if (data.type === 'signout') {
void this.handleUnauthenticated();
void this.handleUnauthenticated({ broadcast: false });
}
});

/**
* Allow resources within the singleton to notify other tabs about a signout event (scoped to a single tab)
*/
eventBus.on(events.UserSignOut, () => {
this.#broadcastChannel?.postMessage({ type: 'signout' });
});
};

// TODO: Be more conservative about touches. Throttle, don't touch when only one user, etc
Expand DownExpand Up@@ -2100,10 +2106,6 @@ export class Clerk implements ClerkInterface {
}
};

#broadcastSignOutEvent = () => {
this.#broadcastChannel?.postMessage({ type: 'signout' });
};

#setTransitiveState = () => {
this.session = undefined;
this.organization = undefined;
Expand Down
2 changes: 2 additions & 0 deletions packages/clerk-js/src/core/events.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,6 +2,7 @@ import type { TokenResource } from '@clerk/types';

export const events = {
TokenUpdate: 'token:update',
UserSignOut: 'user:signOut',

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💭 (optional) what do you think about just calling this even signOut? I'm not sure we need the user: scope.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking the same, I added the scope to respect the pattern. Since it does not do any harm, I think I'll leave it as is.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fair enough, I wouldn't say 1 event indicates a pattern though 😉

} as const;

type ClerkEvent = (typeof events)[keyof typeof events];
Expand All@@ -11,6 +12,7 @@ type TokenUpdatePayload = { token: TokenResource | null };

type EventPayload = {
[events.TokenUpdate]: TokenUpdatePayload;
[events.UserSignOut]: null;
};

const createEventBus = () => {
Expand Down
5 changes: 4 additions & 1 deletion packages/clerk-js/src/core/resources/Client.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -83,7 +83,10 @@ export class Client extends BaseResource implements ClientResource {
removeSessions(): Promise<ClientResource> {
return this._baseDelete({
path: this.path() + '/sessions',
}) as unknown as Promise<ClientResource>;
}).then(e => {
SessionTokenCache.clear();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this is the right place for this call. What's the desired behavior? SessionTokenCache is cleared on sign out?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correct, clearing the cache on sign out.

We're calling SessionTokenCache.clear() on Client.destroy(), on Session.end(), and on Session.remove(). Giving the fact that we clear the cache on an individual session removal, i think we should do the same when removing all of them.

return e as unknown as ClientResource;
});
}

clearCache(): void {
Expand Down
6 changes: 5 additions & 1 deletion packages/clerk-js/src/core/resources/User.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -35,6 +35,7 @@ import type {
import { unixEpochToDate } from '../../utils/date';
import { normalizeUnsafeMetadata } from '../../utils/resourceParams';
import { getFullName } from '../../utils/user';
import { eventBus, events } from '../events';
import { BackupCode } from './BackupCode';
import {
BaseResource,
Expand DownExpand Up@@ -241,7 +242,10 @@ export class User extends BaseResource implements UserResource {
};

delete = (): Promise<void> => {
return this._baseDelete({ path: '/me' });
return this._baseDelete({ path: '/me' }).then(res => {
eventBus.dispatch(events.UserSignOut, null);
return res;
});
};

getSessions = async (): Promise<SessionWithActivities[]> => {
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
5 changes: 5 additions & 0 deletions .changeset/new-fishes-rescue.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
---
'@clerk/clerk-js': patch
---

Bug fix: Broadcast a sign out event to all opened tabs when `Clerk.signOut()` or `User.delete()` is called.
12 changes: 8 additions & 4 deletions integration/testUtils/index.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -36,10 +36,14 @@ const createExpectPageObject = ({ page }: TestArgs) => {
expect(redirect.status()).toBe(307);
expect(redirect.headers()['x-clerk-auth-status']).toContain('handshake');
},
toBeSignedOut: () => {
return page.waitForFunction(() => {
return !window.Clerk?.user;
});
toBeSignedOut: (args?: { timeOut: number }) => {
return page.waitForFunction(
() => {
return !window.Clerk?.user;
},
null,
{ timeout: args?.timeOut },
);
},
toBeSignedIn: async () => {
return page.waitForFunction(() => {
Expand Down
2 changes: 1 addition & 1 deletion integration/tests/sign-out-smoke.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,7 +55,7 @@ testAgainstRunningApps({ withEnv: [appConfigs.envs.withEmailCodes] })('sign out
await m.po.expect.toBeSignedOut();
});

await mainTab.po.expect.toBeSignedOut();
await mainTab.po.expect.toBeSignedOut({ timeOut: 2 * 1_000 });

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously the test was passing after 40-50 seconds because either /touch or /tokens would force update the state.

});

test('sign out persisting client', async ({ page, context }) => {
Expand Down
30 changes: 16 additions & 14 deletions packages/clerk-js/src/core/clerk.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -374,6 +374,9 @@ export class Clerk implements ClerkInterface {

const handleSetActive = () => {
const signOutCallback = typeof callbackOrOptions === 'function' ? callbackOrOptions : undefined;

// Notify other tabs that user is signing out.
eventBus.dispatch(events.UserSignOut, null);
Comment on lines +378 to +379

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ should we be doing this later in the sign out flow?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously inside setActive it was one of the first things that got called. And since by that point we have already cleared cookies seems appropriate.

if (signOutCallback) {
return this.setActive({
session: null,
Expand DownExpand Up@@ -908,14 +911,6 @@ export class Clerk implements ClerkInterface {

await onBeforeSetActive();

// If this.session exists, then signOut was triggered by the current tab
// and should emit. Other tabs should not emit the same event again
const shouldSignOutSession = this.session && newSession === null;
if (shouldSignOutSession) {
this.#broadcastSignOutEvent();
eventBus.dispatch(events.TokenUpdate, { token: null });
}

Comment on lines -911 to -918

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since we are no longer delete the client on sign out, this.session would always be null, causing broadcasting to never occur.

Also removing eventBus.dispatch(events.TokenUpdate, { token: null }) does not cause issues, because the code a few lines below will handle it appropriately.

//1. setLastActiveSession to passed user session (add a param).
// Note that this will also update the session's active organization
// id.
Expand DownExpand Up@@ -1534,6 +1529,7 @@ export class Clerk implements ClerkInterface {
});
};

// TODO: Deprecate this one, and mark it as internal. Is there actual benefit for external developers to use this ? Should they ever reach for it ?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about this ? Would we ever ask people to use this in a custom flow ?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Most likely not, it should really be something that's handled internally.

public handleUnauthenticated = async (opts = { broadcast: true }): Promise<unknown> => {
if (!this.client || !this.session) {
return;
Expand All@@ -1545,7 +1541,7 @@ export class Clerk implements ClerkInterface {
return;
}
if (opts.broadcast) {
this.#broadcastSignOutEvent();
eventBus.dispatch(events.UserSignOut, null);
}
return this.setActive({ session: null });
} catch (err) {
Expand DownExpand Up@@ -2061,11 +2057,21 @@ export class Clerk implements ClerkInterface {
this.#sessionTouchOfflineScheduler.schedule(performTouch);
});

/**
* Background tabs get notified of a signout event from active tab.
*/
this.#broadcastChannel?.addEventListener('message', ({ data }) => {
if (data.type === 'signout') {
void this.handleUnauthenticated();
void this.handleUnauthenticated({ broadcast: false });
}
});

/**
* Allow resources within the singleton to notify other tabs about a signout event (scoped to a single tab)
*/
eventBus.on(events.UserSignOut, () => {
this.#broadcastChannel?.postMessage({ type: 'signout' });
});
};

// TODO: Be more conservative about touches. Throttle, don't touch when only one user, etc
Expand DownExpand Up@@ -2100,10 +2106,6 @@ export class Clerk implements ClerkInterface {
}
};

#broadcastSignOutEvent = () => {
this.#broadcastChannel?.postMessage({ type: 'signout' });
};

#setTransitiveState = () => {
this.session = undefined;
this.organization = undefined;
Expand Down
2 changes: 2 additions & 0 deletions packages/clerk-js/src/core/events.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,6 +2,7 @@ import type { TokenResource } from '@clerk/types';

export const events = {
TokenUpdate: 'token:update',
UserSignOut: 'user:signOut',

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💭 (optional) what do you think about just calling this even signOut? I'm not sure we need the user: scope.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking the same, I added the scope to respect the pattern. Since it does not do any harm, I think I'll leave it as is.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fair enough, I wouldn't say 1 event indicates a pattern though 😉

} as const;

type ClerkEvent = (typeof events)[keyof typeof events];
Expand All@@ -11,6 +12,7 @@ type TokenUpdatePayload = { token: TokenResource | null };

type EventPayload = {
[events.TokenUpdate]: TokenUpdatePayload;
[events.UserSignOut]: null;
};

const createEventBus = () => {
Expand Down
5 changes: 4 additions & 1 deletion packages/clerk-js/src/core/resources/Client.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -83,7 +83,10 @@ export class Client extends BaseResource implements ClientResource {
removeSessions(): Promise<ClientResource> {
return this._baseDelete({
path: this.path() + '/sessions',
}) as unknown as Promise<ClientResource>;
}).then(e => {
SessionTokenCache.clear();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this is the right place for this call. What's the desired behavior? SessionTokenCache is cleared on sign out?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correct, clearing the cache on sign out.

We're calling SessionTokenCache.clear() on Client.destroy(), on Session.end(), and on Session.remove(). Giving the fact that we clear the cache on an individual session removal, i think we should do the same when removing all of them.

return e as unknown as ClientResource;
});
}

clearCache(): void {
Expand Down
6 changes: 5 additions & 1 deletion packages/clerk-js/src/core/resources/User.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -35,6 +35,7 @@ import type {
import { unixEpochToDate } from '../../utils/date';
import { normalizeUnsafeMetadata } from '../../utils/resourceParams';
import { getFullName } from '../../utils/user';
import { eventBus, events } from '../events';
import { BackupCode } from './BackupCode';
import {
BaseResource,
Expand DownExpand Up@@ -241,7 +242,10 @@ export class User extends BaseResource implements UserResource {
};

delete = (): Promise<void> => {
return this._baseDelete({ path: '/me' });
return this._baseDelete({ path: '/me' }).then(res => {
eventBus.dispatch(events.UserSignOut, null);
return res;
});
};

getSessions = async (): Promise<SessionWithActivities[]> => {
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
5 changes: 5 additions & 0 deletions .changeset/new-fishes-rescue.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
---
'@clerk/clerk-js': patch
---

Bug fix: Broadcast a sign out event to all opened tabs when `Clerk.signOut()` or `User.delete()` is called.
12 changes: 8 additions & 4 deletions integration/testUtils/index.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -36,10 +36,14 @@ const createExpectPageObject = ({ page }: TestArgs) => {
expect(redirect.status()).toBe(307);
expect(redirect.headers()['x-clerk-auth-status']).toContain('handshake');
},
toBeSignedOut: () => {
return page.waitForFunction(() => {
return !window.Clerk?.user;
});
toBeSignedOut: (args?: { timeOut: number }) => {
return page.waitForFunction(
() => {
return !window.Clerk?.user;
},
null,
{ timeout: args?.timeOut },
);
},
toBeSignedIn: async () => {
return page.waitForFunction(() => {
Expand Down
2 changes: 1 addition & 1 deletion integration/tests/sign-out-smoke.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,7 +55,7 @@ testAgainstRunningApps({ withEnv: [appConfigs.envs.withEmailCodes] })('sign out
await m.po.expect.toBeSignedOut();
});

await mainTab.po.expect.toBeSignedOut();
await mainTab.po.expect.toBeSignedOut({ timeOut: 2 * 1_000 });

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously the test was passing after 40-50 seconds because either /touch or /tokens would force update the state.

});

test('sign out persisting client', async ({ page, context }) => {
Expand Down
30 changes: 16 additions & 14 deletions packages/clerk-js/src/core/clerk.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -374,6 +374,9 @@ export class Clerk implements ClerkInterface {

const handleSetActive = () => {
const signOutCallback = typeof callbackOrOptions === 'function' ? callbackOrOptions : undefined;

// Notify other tabs that user is signing out.
eventBus.dispatch(events.UserSignOut, null);
Comment on lines +378 to +379

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ should we be doing this later in the sign out flow?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously inside setActive it was one of the first things that got called. And since by that point we have already cleared cookies seems appropriate.

if (signOutCallback) {
return this.setActive({
session: null,
Expand DownExpand Up@@ -908,14 +911,6 @@ export class Clerk implements ClerkInterface {

await onBeforeSetActive();

// If this.session exists, then signOut was triggered by the current tab
// and should emit. Other tabs should not emit the same event again
const shouldSignOutSession = this.session && newSession === null;
if (shouldSignOutSession) {
this.#broadcastSignOutEvent();
eventBus.dispatch(events.TokenUpdate, { token: null });
}

Comment on lines -911 to -918

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since we are no longer delete the client on sign out, this.session would always be null, causing broadcasting to never occur.

Also removing eventBus.dispatch(events.TokenUpdate, { token: null }) does not cause issues, because the code a few lines below will handle it appropriately.

//1. setLastActiveSession to passed user session (add a param).
// Note that this will also update the session's active organization
// id.
Expand DownExpand Up@@ -1534,6 +1529,7 @@ export class Clerk implements ClerkInterface {
});
};

// TODO: Deprecate this one, and mark it as internal. Is there actual benefit for external developers to use this ? Should they ever reach for it ?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about this ? Would we ever ask people to use this in a custom flow ?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Most likely not, it should really be something that's handled internally.

public handleUnauthenticated = async (opts = { broadcast: true }): Promise<unknown> => {
if (!this.client || !this.session) {
return;
Expand All@@ -1545,7 +1541,7 @@ export class Clerk implements ClerkInterface {
return;
}
if (opts.broadcast) {
this.#broadcastSignOutEvent();
eventBus.dispatch(events.UserSignOut, null);
}
return this.setActive({ session: null });
} catch (err) {
Expand DownExpand Up@@ -2061,11 +2057,21 @@ export class Clerk implements ClerkInterface {
this.#sessionTouchOfflineScheduler.schedule(performTouch);
});

/**
* Background tabs get notified of a signout event from active tab.
*/
this.#broadcastChannel?.addEventListener('message', ({ data }) => {
if (data.type === 'signout') {
void this.handleUnauthenticated();
void this.handleUnauthenticated({ broadcast: false });
}
});

/**
* Allow resources within the singleton to notify other tabs about a signout event (scoped to a single tab)
*/
eventBus.on(events.UserSignOut, () => {
this.#broadcastChannel?.postMessage({ type: 'signout' });
});
};

// TODO: Be more conservative about touches. Throttle, don't touch when only one user, etc
Expand DownExpand Up@@ -2100,10 +2106,6 @@ export class Clerk implements ClerkInterface {
}
};

#broadcastSignOutEvent = () => {
this.#broadcastChannel?.postMessage({ type: 'signout' });
};

#setTransitiveState = () => {
this.session = undefined;
this.organization = undefined;
Expand Down
2 changes: 2 additions & 0 deletions packages/clerk-js/src/core/events.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,6 +2,7 @@ import type { TokenResource } from '@clerk/types';

export const events = {
TokenUpdate: 'token:update',
UserSignOut: 'user:signOut',

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💭 (optional) what do you think about just calling this even signOut? I'm not sure we need the user: scope.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking the same, I added the scope to respect the pattern. Since it does not do any harm, I think I'll leave it as is.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fair enough, I wouldn't say 1 event indicates a pattern though 😉

} as const;

type ClerkEvent = (typeof events)[keyof typeof events];
Expand All@@ -11,6 +12,7 @@ type TokenUpdatePayload = { token: TokenResource | null };

type EventPayload = {
[events.TokenUpdate]: TokenUpdatePayload;
[events.UserSignOut]: null;
};

const createEventBus = () => {
Expand Down
5 changes: 4 additions & 1 deletion packages/clerk-js/src/core/resources/Client.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -83,7 +83,10 @@ export class Client extends BaseResource implements ClientResource {
removeSessions(): Promise<ClientResource> {
return this._baseDelete({
path: this.path() + '/sessions',
}) as unknown as Promise<ClientResource>;
}).then(e => {
SessionTokenCache.clear();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this is the right place for this call. What's the desired behavior? SessionTokenCache is cleared on sign out?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correct, clearing the cache on sign out.

We're calling SessionTokenCache.clear() on Client.destroy(), on Session.end(), and on Session.remove(). Giving the fact that we clear the cache on an individual session removal, i think we should do the same when removing all of them.

return e as unknown as ClientResource;
});
}

clearCache(): void {
Expand Down
6 changes: 5 additions & 1 deletion packages/clerk-js/src/core/resources/User.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -35,6 +35,7 @@ import type {
import { unixEpochToDate } from '../../utils/date';
import { normalizeUnsafeMetadata } from '../../utils/resourceParams';
import { getFullName } from '../../utils/user';
import { eventBus, events } from '../events';
import { BackupCode } from './BackupCode';
import {
BaseResource,
Expand DownExpand Up@@ -241,7 +242,10 @@ export class User extends BaseResource implements UserResource {
};

delete = (): Promise<void> => {
return this._baseDelete({ path: '/me' });
return this._baseDelete({ path: '/me' }).then(res => {
eventBus.dispatch(events.UserSignOut, null);
return res;
});
};

getSessions = async (): Promise<SessionWithActivities[]> => {
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
5 changes: 5 additions & 0 deletions .changeset/new-fishes-rescue.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
---
'@clerk/clerk-js': patch
---

Bug fix: Broadcast a sign out event to all opened tabs when `Clerk.signOut()` or `User.delete()` is called.
12 changes: 8 additions & 4 deletions integration/testUtils/index.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -36,10 +36,14 @@ const createExpectPageObject = ({ page }: TestArgs) => {
expect(redirect.status()).toBe(307);
expect(redirect.headers()['x-clerk-auth-status']).toContain('handshake');
},
toBeSignedOut: () => {
return page.waitForFunction(() => {
return !window.Clerk?.user;
});
toBeSignedOut: (args?: { timeOut: number }) => {
return page.waitForFunction(
() => {
return !window.Clerk?.user;
},
null,
{ timeout: args?.timeOut },
);
},
toBeSignedIn: async () => {
return page.waitForFunction(() => {
Expand Down
2 changes: 1 addition & 1 deletion integration/tests/sign-out-smoke.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,7 +55,7 @@ testAgainstRunningApps({ withEnv: [appConfigs.envs.withEmailCodes] })('sign out
await m.po.expect.toBeSignedOut();
});

await mainTab.po.expect.toBeSignedOut();
await mainTab.po.expect.toBeSignedOut({ timeOut: 2 * 1_000 });

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously the test was passing after 40-50 seconds because either /touch or /tokens would force update the state.

});

test('sign out persisting client', async ({ page, context }) => {
Expand Down
30 changes: 16 additions & 14 deletions packages/clerk-js/src/core/clerk.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -374,6 +374,9 @@ export class Clerk implements ClerkInterface {

const handleSetActive = () => {
const signOutCallback = typeof callbackOrOptions === 'function' ? callbackOrOptions : undefined;

// Notify other tabs that user is signing out.
eventBus.dispatch(events.UserSignOut, null);
Comment on lines +378 to +379

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❓ should we be doing this later in the sign out flow?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Previously inside setActive it was one of the first things that got called. And since by that point we have already cleared cookies seems appropriate.

if (signOutCallback) {
return this.setActive({
session: null,
Expand DownExpand Up@@ -908,14 +911,6 @@ export class Clerk implements ClerkInterface {

await onBeforeSetActive();

// If this.session exists, then signOut was triggered by the current tab
// and should emit. Other tabs should not emit the same event again
const shouldSignOutSession = this.session && newSession === null;
if (shouldSignOutSession) {
this.#broadcastSignOutEvent();
eventBus.dispatch(events.TokenUpdate, { token: null });
}

Comment on lines -911 to -918

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since we are no longer delete the client on sign out, this.session would always be null, causing broadcasting to never occur.

Also removing eventBus.dispatch(events.TokenUpdate, { token: null }) does not cause issues, because the code a few lines below will handle it appropriately.

//1. setLastActiveSession to passed user session (add a param).
// Note that this will also update the session's active organization
// id.
Expand DownExpand Up@@ -1534,6 +1529,7 @@ export class Clerk implements ClerkInterface {
});
};

// TODO: Deprecate this one, and mark it as internal. Is there actual benefit for external developers to use this ? Should they ever reach for it ?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What do you think about this ? Would we ever ask people to use this in a custom flow ?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Most likely not, it should really be something that's handled internally.

public handleUnauthenticated = async (opts = { broadcast: true }): Promise<unknown> => {
if (!this.client || !this.session) {
return;
Expand All@@ -1545,7 +1541,7 @@ export class Clerk implements ClerkInterface {
return;
}
if (opts.broadcast) {
this.#broadcastSignOutEvent();
eventBus.dispatch(events.UserSignOut, null);
}
return this.setActive({ session: null });
} catch (err) {
Expand DownExpand Up@@ -2061,11 +2057,21 @@ export class Clerk implements ClerkInterface {
this.#sessionTouchOfflineScheduler.schedule(performTouch);
});

/**
* Background tabs get notified of a signout event from active tab.
*/
this.#broadcastChannel?.addEventListener('message', ({ data }) => {
if (data.type === 'signout') {
void this.handleUnauthenticated();
void this.handleUnauthenticated({ broadcast: false });
}
});

/**
* Allow resources within the singleton to notify other tabs about a signout event (scoped to a single tab)
*/
eventBus.on(events.UserSignOut, () => {
this.#broadcastChannel?.postMessage({ type: 'signout' });
});
};

// TODO: Be more conservative about touches. Throttle, don't touch when only one user, etc
Expand DownExpand Up@@ -2100,10 +2106,6 @@ export class Clerk implements ClerkInterface {
}
};

#broadcastSignOutEvent = () => {
this.#broadcastChannel?.postMessage({ type: 'signout' });
};

#setTransitiveState = () => {
this.session = undefined;
this.organization = undefined;
Expand Down
2 changes: 2 additions & 0 deletions packages/clerk-js/src/core/events.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,6 +2,7 @@ import type { TokenResource } from '@clerk/types';

export const events = {
TokenUpdate: 'token:update',
UserSignOut: 'user:signOut',

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💭 (optional) what do you think about just calling this even signOut? I'm not sure we need the user: scope.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking the same, I added the scope to respect the pattern. Since it does not do any harm, I think I'll leave it as is.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fair enough, I wouldn't say 1 event indicates a pattern though 😉

} as const;

type ClerkEvent = (typeof events)[keyof typeof events];
Expand All@@ -11,6 +12,7 @@ type TokenUpdatePayload = { token: TokenResource | null };

type EventPayload = {
[events.TokenUpdate]: TokenUpdatePayload;
[events.UserSignOut]: null;
};

const createEventBus = () => {
Expand Down
5 changes: 4 additions & 1 deletion packages/clerk-js/src/core/resources/Client.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -83,7 +83,10 @@ export class Client extends BaseResource implements ClientResource {
removeSessions(): Promise<ClientResource> {
return this._baseDelete({
path: this.path() + '/sessions',
}) as unknown as Promise<ClientResource>;
}).then(e => {
SessionTokenCache.clear();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this is the right place for this call. What's the desired behavior? SessionTokenCache is cleared on sign out?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correct, clearing the cache on sign out.

We're calling SessionTokenCache.clear() on Client.destroy(), on Session.end(), and on Session.remove(). Giving the fact that we clear the cache on an individual session removal, i think we should do the same when removing all of them.

return e as unknown as ClientResource;
});
}

clearCache(): void {
Expand Down
6 changes: 5 additions & 1 deletion packages/clerk-js/src/core/resources/User.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -35,6 +35,7 @@ import type {
import { unixEpochToDate } from '../../utils/date';
import { normalizeUnsafeMetadata } from '../../utils/resourceParams';
import { getFullName } from '../../utils/user';
import { eventBus, events } from '../events';
import { BackupCode } from './BackupCode';
import {
BaseResource,
Expand DownExpand Up@@ -241,7 +242,10 @@ export class User extends BaseResource implements UserResource {
};

delete = (): Promise<void> => {
return this._baseDelete({ path: '/me' });
return this._baseDelete({ path: '/me' }).then(res => {
eventBus.dispatch(events.UserSignOut, null);
return res;
});
};

getSessions = async (): Promise<SessionWithActivities[]> => {
Expand Down