feat(backend): Signal support for handshake nonce - #5905

Merged
jacekradko merged 17 commits into
mainfrom
feat/signal-support-for-handshake-nonce
Jun 26, 2025
Merged

feat(backend): Signal support for handshake nonce#5905
jacekradko merged 17 commits into
mainfrom
feat/signal-support-for-handshake-nonce

Conversation

@jacekradko

@jacekradkojacekradko commented May 12, 2025

Copy link
Copy Markdown
Contributor

Description

Send query string param to signal support for handshake nonce flow from current version of @clerk/backend

Related: SDKI-979

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Introduced an optimized handshake process for large session payloads using a nonce-based fetching mechanism.
    • Added a new query parameter to handshake URLs to indicate support for handshake nonce during redirects.
  • Tests

    • Enhanced tests to verify the presence of the new handshake format parameter in generated URLs.

@vercel

vercelBot commented May 12, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for Git ↗︎

NameStatusPreviewCommentsUpdated (UTC)
clerk-js-sandbox✅ Ready (Inspect)Visit Preview💬 Add feedbackJun 26, 2025 3:34am

@changeset-bot

changeset-botBot commented May 12, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 87cf34e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendMinor
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@jacekradko
jacekradko requested a review from CopilotMay 12, 2025 14:43

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds support for signaling the handshake nonce flow by including a query parameter.

  • In handshake.ts, the query parameter SupportsHandshakeNonce is appended to the URL.
  • In handshake.test.ts, corresponding tests ensure the parameter is correctly set in both regular and development modes.
  • In constants.ts, a new constant for SupportsHandshakeNonce is added to support the new query parameter.

Reviewed Changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.

FileDescription
packages/backend/src/tokens/handshake.tsAppends a new query parameter for handshake nonce support.
packages/backend/src/tokens/tests/handshake.test.tsAdds tests to validate the presence of the new query parameter.
packages/backend/src/constants.tsIntroduces the SupportsHandshakeNonce constant to hold the parameter key.

Comment threadpackages/backend/src/constants.ts Outdated
@jfoshee

Copy link
Copy Markdown
Contributor

LGTM. So to be doubly clear: this indicates "nonce support", but FAPI still has the option to return 'optimized' payload in initial response, right?
I'll work on API definition update and FAPI implementation.

@jacekradko

Copy link
Copy Markdown
ContributorAuthor

@jfoshee Yeah, this is just to signal to the API that it COULD send a handshake nonce

@jacekradko
jacekradko requested a review from a teamMay 12, 2025 20:27
@pkg-pr-new

pkg-pr-newBot commented May 15, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@5905

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@5905

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@5905

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@5905

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@5905

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@5905

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@5905

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@5905

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@5905

@clerk/express

npm i https://pkg.pr.new/@clerk/express@5905

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@5905

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@5905

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@5905

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@5905

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@5905

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@5905

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@5905

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@5905

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@5905

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@5905

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@5905

@clerk/types

npm i https://pkg.pr.new/@clerk/types@5905

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@5905

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@5905

commit: 87cf34e

@jacekradko
jacekradko requested a review from aeliox as a code ownerJune 18, 2025 14:48

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (3)
.changeset/six-ears-wash.md (3)

5-5: Use a proper Markdown heading instead of bold text

Markdown-lint flags MD036 here. Replacing the bold line with a level-2 heading keeps the file consistent with other changesets and avoids lint noise.

-**Optimize handshake payload delivery with nonce-based fetching**+## Optimize handshake payload delivery with nonce-based fetching

23-26: Fix typo in example domain

ecxample.comexample.com.

-3. Handshake resolves → `307 ecxample.com` with `__clerk_handshake_nonce` cookie containing the nonce+3. Handshake resolves → `307 example.com` with `__clerk_handshake_nonce` cookie containing the nonce

30-31: Optional: add a clarifying comma

Minor readability tweak; feel free to ignore if you prefer the current wording.

-Continues to work as before with direct payload delivery in cookies for optimal performance.+Continues to work as before, with direct payload delivery in cookies for optimal performance.
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between ef10516 and 7e3ad6e.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)


[uncategorized] ~31-~31: Possible missing comma found.
Context: ... payloads ≤2KB):** Continues to work as before with direct payload delivery in cookies...

(AI_HYDRA_LEO_MISSING_COMMA)

🪛 markdownlint-cli2 (0.17.2)
.changeset/six-ears-wash.md

5-5: Emphasis used instead of a heading
null

(MD036, no-emphasis-as-heading)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
.changeset/six-ears-wash.md (1)

10-11: Mixed tenses – change “restricted” → “restricts”

Present-tense “limit” pairs naturally with present-tense “restricts”.

-… this severely restricted the practical size …+… this severely restricts the practical size …
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 7e3ad6e and be1acc3.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)
🔇 Additional comments (1)
.changeset/six-ears-wash.md (1)

24-26: Step 3 wording is ambiguous

307 example.com doesn’t tell the reader which endpoint the browser is redirected to. Spell out the full redirected URL or path (e.g. / or the original page) so integrators know what to expect.

Comment thread.changeset/six-ears-wash.md

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
.changeset/six-ears-wash.md (1)

10-11: Minor grammar tweak for release-note polish

“restricts” reads slightly better with the present-tense “Since …” lead-in.

- Since browsers limit cookies to ~4KB, this severely restricted the practical size of session tokens,+ Since browsers limit cookies to ~4KB, this severely restricts the practical size of session tokens,
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between be1acc3 and 87cf34e.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🧠 Learnings (1)
.changeset/six-ears-wash.md (1)
Learnt from: jacekradko
PR: clerk/javascript#5905
File: .changeset/six-ears-wash.md:1-3
Timestamp: 2025-06-26T03:27:05.511Z
Learning: In the Clerk JavaScript repository, changeset headers support single quotes syntax (e.g., '@clerk/backend': minor) and work fine with their current changesets integration, so there's no need to change them to double quotes.
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)
🔇 Additional comments (1)
.changeset/six-ears-wash.md (1)

1-3: Header syntax is project-compliant – no action needed

Single-quoted package names are approved by the repo’s Changesets setup (per prior discussion).
Looks good as-is.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@jacekradko@jfoshee@dstaley@brkalow@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(backend): Signal support for handshake nonce - #5905

Merged
jacekradko merged 17 commits into
mainfrom
feat/signal-support-for-handshake-nonce
Jun 26, 2025
Merged

feat(backend): Signal support for handshake nonce#5905
jacekradko merged 17 commits into
mainfrom
feat/signal-support-for-handshake-nonce

Conversation

@jacekradko

@jacekradkojacekradko commented May 12, 2025

Copy link
Copy Markdown
Contributor

Description

Send query string param to signal support for handshake nonce flow from current version of @clerk/backend

Related: SDKI-979

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Introduced an optimized handshake process for large session payloads using a nonce-based fetching mechanism.
    • Added a new query parameter to handshake URLs to indicate support for handshake nonce during redirects.
  • Tests

    • Enhanced tests to verify the presence of the new handshake format parameter in generated URLs.

@vercel

vercelBot commented May 12, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for Git ↗︎

NameStatusPreviewCommentsUpdated (UTC)
clerk-js-sandbox✅ Ready (Inspect)Visit Preview💬 Add feedbackJun 26, 2025 3:34am

@changeset-bot

changeset-botBot commented May 12, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 87cf34e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendMinor
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@jacekradko
jacekradko requested a review from CopilotMay 12, 2025 14:43

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds support for signaling the handshake nonce flow by including a query parameter.

  • In handshake.ts, the query parameter SupportsHandshakeNonce is appended to the URL.
  • In handshake.test.ts, corresponding tests ensure the parameter is correctly set in both regular and development modes.
  • In constants.ts, a new constant for SupportsHandshakeNonce is added to support the new query parameter.

Reviewed Changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.

FileDescription
packages/backend/src/tokens/handshake.tsAppends a new query parameter for handshake nonce support.
packages/backend/src/tokens/tests/handshake.test.tsAdds tests to validate the presence of the new query parameter.
packages/backend/src/constants.tsIntroduces the SupportsHandshakeNonce constant to hold the parameter key.

Comment threadpackages/backend/src/constants.ts Outdated
@jfoshee

Copy link
Copy Markdown
Contributor

LGTM. So to be doubly clear: this indicates "nonce support", but FAPI still has the option to return 'optimized' payload in initial response, right?
I'll work on API definition update and FAPI implementation.

@jacekradko

Copy link
Copy Markdown
ContributorAuthor

@jfoshee Yeah, this is just to signal to the API that it COULD send a handshake nonce

@jacekradko
jacekradko requested a review from a teamMay 12, 2025 20:27
@pkg-pr-new

pkg-pr-newBot commented May 15, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@5905

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@5905

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@5905

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@5905

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@5905

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@5905

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@5905

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@5905

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@5905

@clerk/express

npm i https://pkg.pr.new/@clerk/express@5905

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@5905

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@5905

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@5905

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@5905

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@5905

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@5905

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@5905

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@5905

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@5905

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@5905

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@5905

@clerk/types

npm i https://pkg.pr.new/@clerk/types@5905

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@5905

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@5905

commit: 87cf34e

@jacekradko
jacekradko requested a review from aeliox as a code ownerJune 18, 2025 14:48

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (3)
.changeset/six-ears-wash.md (3)

5-5: Use a proper Markdown heading instead of bold text

Markdown-lint flags MD036 here. Replacing the bold line with a level-2 heading keeps the file consistent with other changesets and avoids lint noise.

-**Optimize handshake payload delivery with nonce-based fetching**+## Optimize handshake payload delivery with nonce-based fetching

23-26: Fix typo in example domain

ecxample.comexample.com.

-3. Handshake resolves → `307 ecxample.com` with `__clerk_handshake_nonce` cookie containing the nonce+3. Handshake resolves → `307 example.com` with `__clerk_handshake_nonce` cookie containing the nonce

30-31: Optional: add a clarifying comma

Minor readability tweak; feel free to ignore if you prefer the current wording.

-Continues to work as before with direct payload delivery in cookies for optimal performance.+Continues to work as before, with direct payload delivery in cookies for optimal performance.
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between ef10516 and 7e3ad6e.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)


[uncategorized] ~31-~31: Possible missing comma found.
Context: ... payloads ≤2KB):** Continues to work as before with direct payload delivery in cookies...

(AI_HYDRA_LEO_MISSING_COMMA)

🪛 markdownlint-cli2 (0.17.2)
.changeset/six-ears-wash.md

5-5: Emphasis used instead of a heading
null

(MD036, no-emphasis-as-heading)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
.changeset/six-ears-wash.md (1)

10-11: Mixed tenses – change “restricted” → “restricts”

Present-tense “limit” pairs naturally with present-tense “restricts”.

-… this severely restricted the practical size …+… this severely restricts the practical size …
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 7e3ad6e and be1acc3.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)
🔇 Additional comments (1)
.changeset/six-ears-wash.md (1)

24-26: Step 3 wording is ambiguous

307 example.com doesn’t tell the reader which endpoint the browser is redirected to. Spell out the full redirected URL or path (e.g. / or the original page) so integrators know what to expect.

Comment thread.changeset/six-ears-wash.md

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
.changeset/six-ears-wash.md (1)

10-11: Minor grammar tweak for release-note polish

“restricts” reads slightly better with the present-tense “Since …” lead-in.

- Since browsers limit cookies to ~4KB, this severely restricted the practical size of session tokens,+ Since browsers limit cookies to ~4KB, this severely restricts the practical size of session tokens,
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between be1acc3 and 87cf34e.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🧠 Learnings (1)
.changeset/six-ears-wash.md (1)
Learnt from: jacekradko
PR: clerk/javascript#5905
File: .changeset/six-ears-wash.md:1-3
Timestamp: 2025-06-26T03:27:05.511Z
Learning: In the Clerk JavaScript repository, changeset headers support single quotes syntax (e.g., '@clerk/backend': minor) and work fine with their current changesets integration, so there's no need to change them to double quotes.
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)
🔇 Additional comments (1)
.changeset/six-ears-wash.md (1)

1-3: Header syntax is project-compliant – no action needed

Single-quoted package names are approved by the repo’s Changesets setup (per prior discussion).
Looks good as-is.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@jacekradko@jfoshee@dstaley@brkalow@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(backend): Signal support for handshake nonce - #5905

Merged
jacekradko merged 17 commits into
mainfrom
feat/signal-support-for-handshake-nonce
Jun 26, 2025
Merged

feat(backend): Signal support for handshake nonce#5905
jacekradko merged 17 commits into
mainfrom
feat/signal-support-for-handshake-nonce

Conversation

@jacekradko

@jacekradkojacekradko commented May 12, 2025

Copy link
Copy Markdown
Contributor

Description

Send query string param to signal support for handshake nonce flow from current version of @clerk/backend

Related: SDKI-979

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Introduced an optimized handshake process for large session payloads using a nonce-based fetching mechanism.
    • Added a new query parameter to handshake URLs to indicate support for handshake nonce during redirects.
  • Tests

    • Enhanced tests to verify the presence of the new handshake format parameter in generated URLs.

@vercel

vercelBot commented May 12, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for Git ↗︎

NameStatusPreviewCommentsUpdated (UTC)
clerk-js-sandbox✅ Ready (Inspect)Visit Preview💬 Add feedbackJun 26, 2025 3:34am

@changeset-bot

changeset-botBot commented May 12, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 87cf34e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendMinor
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@jacekradko
jacekradko requested a review from CopilotMay 12, 2025 14:43

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds support for signaling the handshake nonce flow by including a query parameter.

  • In handshake.ts, the query parameter SupportsHandshakeNonce is appended to the URL.
  • In handshake.test.ts, corresponding tests ensure the parameter is correctly set in both regular and development modes.
  • In constants.ts, a new constant for SupportsHandshakeNonce is added to support the new query parameter.

Reviewed Changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.

FileDescription
packages/backend/src/tokens/handshake.tsAppends a new query parameter for handshake nonce support.
packages/backend/src/tokens/tests/handshake.test.tsAdds tests to validate the presence of the new query parameter.
packages/backend/src/constants.tsIntroduces the SupportsHandshakeNonce constant to hold the parameter key.

Comment threadpackages/backend/src/constants.ts Outdated
@jfoshee

Copy link
Copy Markdown
Contributor

LGTM. So to be doubly clear: this indicates "nonce support", but FAPI still has the option to return 'optimized' payload in initial response, right?
I'll work on API definition update and FAPI implementation.

@jacekradko

Copy link
Copy Markdown
ContributorAuthor

@jfoshee Yeah, this is just to signal to the API that it COULD send a handshake nonce

@jacekradko
jacekradko requested a review from a teamMay 12, 2025 20:27
@pkg-pr-new

pkg-pr-newBot commented May 15, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@5905

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@5905

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@5905

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@5905

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@5905

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@5905

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@5905

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@5905

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@5905

@clerk/express

npm i https://pkg.pr.new/@clerk/express@5905

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@5905

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@5905

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@5905

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@5905

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@5905

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@5905

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@5905

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@5905

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@5905

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@5905

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@5905

@clerk/types

npm i https://pkg.pr.new/@clerk/types@5905

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@5905

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@5905

commit: 87cf34e

@jacekradko
jacekradko requested a review from aeliox as a code ownerJune 18, 2025 14:48

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (3)
.changeset/six-ears-wash.md (3)

5-5: Use a proper Markdown heading instead of bold text

Markdown-lint flags MD036 here. Replacing the bold line with a level-2 heading keeps the file consistent with other changesets and avoids lint noise.

-**Optimize handshake payload delivery with nonce-based fetching**+## Optimize handshake payload delivery with nonce-based fetching

23-26: Fix typo in example domain

ecxample.comexample.com.

-3. Handshake resolves → `307 ecxample.com` with `__clerk_handshake_nonce` cookie containing the nonce+3. Handshake resolves → `307 example.com` with `__clerk_handshake_nonce` cookie containing the nonce

30-31: Optional: add a clarifying comma

Minor readability tweak; feel free to ignore if you prefer the current wording.

-Continues to work as before with direct payload delivery in cookies for optimal performance.+Continues to work as before, with direct payload delivery in cookies for optimal performance.
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between ef10516 and 7e3ad6e.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)


[uncategorized] ~31-~31: Possible missing comma found.
Context: ... payloads ≤2KB):** Continues to work as before with direct payload delivery in cookies...

(AI_HYDRA_LEO_MISSING_COMMA)

🪛 markdownlint-cli2 (0.17.2)
.changeset/six-ears-wash.md

5-5: Emphasis used instead of a heading
null

(MD036, no-emphasis-as-heading)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
.changeset/six-ears-wash.md (1)

10-11: Mixed tenses – change “restricted” → “restricts”

Present-tense “limit” pairs naturally with present-tense “restricts”.

-… this severely restricted the practical size …+… this severely restricts the practical size …
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 7e3ad6e and be1acc3.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)
🔇 Additional comments (1)
.changeset/six-ears-wash.md (1)

24-26: Step 3 wording is ambiguous

307 example.com doesn’t tell the reader which endpoint the browser is redirected to. Spell out the full redirected URL or path (e.g. / or the original page) so integrators know what to expect.

Comment thread.changeset/six-ears-wash.md

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
.changeset/six-ears-wash.md (1)

10-11: Minor grammar tweak for release-note polish

“restricts” reads slightly better with the present-tense “Since …” lead-in.

- Since browsers limit cookies to ~4KB, this severely restricted the practical size of session tokens,+ Since browsers limit cookies to ~4KB, this severely restricts the practical size of session tokens,
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between be1acc3 and 87cf34e.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🧠 Learnings (1)
.changeset/six-ears-wash.md (1)
Learnt from: jacekradko
PR: clerk/javascript#5905
File: .changeset/six-ears-wash.md:1-3
Timestamp: 2025-06-26T03:27:05.511Z
Learning: In the Clerk JavaScript repository, changeset headers support single quotes syntax (e.g., '@clerk/backend': minor) and work fine with their current changesets integration, so there's no need to change them to double quotes.
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)
🔇 Additional comments (1)
.changeset/six-ears-wash.md (1)

1-3: Header syntax is project-compliant – no action needed

Single-quoted package names are approved by the repo’s Changesets setup (per prior discussion).
Looks good as-is.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@jacekradko@jfoshee@dstaley@brkalow@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(backend): Signal support for handshake nonce - #5905

Merged
jacekradko merged 17 commits into
mainfrom
feat/signal-support-for-handshake-nonce
Jun 26, 2025
Merged

feat(backend): Signal support for handshake nonce#5905
jacekradko merged 17 commits into
mainfrom
feat/signal-support-for-handshake-nonce

Conversation

@jacekradko

@jacekradkojacekradko commented May 12, 2025

Copy link
Copy Markdown
Contributor

Description

Send query string param to signal support for handshake nonce flow from current version of @clerk/backend

Related: SDKI-979

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Introduced an optimized handshake process for large session payloads using a nonce-based fetching mechanism.
    • Added a new query parameter to handshake URLs to indicate support for handshake nonce during redirects.
  • Tests

    • Enhanced tests to verify the presence of the new handshake format parameter in generated URLs.

@vercel

vercelBot commented May 12, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for Git ↗︎

NameStatusPreviewCommentsUpdated (UTC)
clerk-js-sandbox✅ Ready (Inspect)Visit Preview💬 Add feedbackJun 26, 2025 3:34am

@changeset-bot

changeset-botBot commented May 12, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 87cf34e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendMinor
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@jacekradko
jacekradko requested a review from CopilotMay 12, 2025 14:43

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds support for signaling the handshake nonce flow by including a query parameter.

  • In handshake.ts, the query parameter SupportsHandshakeNonce is appended to the URL.
  • In handshake.test.ts, corresponding tests ensure the parameter is correctly set in both regular and development modes.
  • In constants.ts, a new constant for SupportsHandshakeNonce is added to support the new query parameter.

Reviewed Changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.

FileDescription
packages/backend/src/tokens/handshake.tsAppends a new query parameter for handshake nonce support.
packages/backend/src/tokens/tests/handshake.test.tsAdds tests to validate the presence of the new query parameter.
packages/backend/src/constants.tsIntroduces the SupportsHandshakeNonce constant to hold the parameter key.

Comment threadpackages/backend/src/constants.ts Outdated
@jfoshee

Copy link
Copy Markdown
Contributor

LGTM. So to be doubly clear: this indicates "nonce support", but FAPI still has the option to return 'optimized' payload in initial response, right?
I'll work on API definition update and FAPI implementation.

@jacekradko

Copy link
Copy Markdown
ContributorAuthor

@jfoshee Yeah, this is just to signal to the API that it COULD send a handshake nonce

@jacekradko
jacekradko requested a review from a teamMay 12, 2025 20:27
@pkg-pr-new

pkg-pr-newBot commented May 15, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@5905

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@5905

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@5905

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@5905

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@5905

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@5905

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@5905

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@5905

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@5905

@clerk/express

npm i https://pkg.pr.new/@clerk/express@5905

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@5905

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@5905

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@5905

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@5905

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@5905

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@5905

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@5905

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@5905

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@5905

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@5905

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@5905

@clerk/types

npm i https://pkg.pr.new/@clerk/types@5905

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@5905

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@5905

commit: 87cf34e

@jacekradko
jacekradko requested a review from aeliox as a code ownerJune 18, 2025 14:48

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (3)
.changeset/six-ears-wash.md (3)

5-5: Use a proper Markdown heading instead of bold text

Markdown-lint flags MD036 here. Replacing the bold line with a level-2 heading keeps the file consistent with other changesets and avoids lint noise.

-**Optimize handshake payload delivery with nonce-based fetching**+## Optimize handshake payload delivery with nonce-based fetching

23-26: Fix typo in example domain

ecxample.comexample.com.

-3. Handshake resolves → `307 ecxample.com` with `__clerk_handshake_nonce` cookie containing the nonce+3. Handshake resolves → `307 example.com` with `__clerk_handshake_nonce` cookie containing the nonce

30-31: Optional: add a clarifying comma

Minor readability tweak; feel free to ignore if you prefer the current wording.

-Continues to work as before with direct payload delivery in cookies for optimal performance.+Continues to work as before, with direct payload delivery in cookies for optimal performance.
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between ef10516 and 7e3ad6e.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)


[uncategorized] ~31-~31: Possible missing comma found.
Context: ... payloads ≤2KB):** Continues to work as before with direct payload delivery in cookies...

(AI_HYDRA_LEO_MISSING_COMMA)

🪛 markdownlint-cli2 (0.17.2)
.changeset/six-ears-wash.md

5-5: Emphasis used instead of a heading
null

(MD036, no-emphasis-as-heading)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
.changeset/six-ears-wash.md (1)

10-11: Mixed tenses – change “restricted” → “restricts”

Present-tense “limit” pairs naturally with present-tense “restricts”.

-… this severely restricted the practical size …+… this severely restricts the practical size …
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 7e3ad6e and be1acc3.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)
🔇 Additional comments (1)
.changeset/six-ears-wash.md (1)

24-26: Step 3 wording is ambiguous

307 example.com doesn’t tell the reader which endpoint the browser is redirected to. Spell out the full redirected URL or path (e.g. / or the original page) so integrators know what to expect.

Comment thread.changeset/six-ears-wash.md

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
.changeset/six-ears-wash.md (1)

10-11: Minor grammar tweak for release-note polish

“restricts” reads slightly better with the present-tense “Since …” lead-in.

- Since browsers limit cookies to ~4KB, this severely restricted the practical size of session tokens,+ Since browsers limit cookies to ~4KB, this severely restricts the practical size of session tokens,
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between be1acc3 and 87cf34e.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🧠 Learnings (1)
.changeset/six-ears-wash.md (1)
Learnt from: jacekradko
PR: clerk/javascript#5905
File: .changeset/six-ears-wash.md:1-3
Timestamp: 2025-06-26T03:27:05.511Z
Learning: In the Clerk JavaScript repository, changeset headers support single quotes syntax (e.g., '@clerk/backend': minor) and work fine with their current changesets integration, so there's no need to change them to double quotes.
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)
🔇 Additional comments (1)
.changeset/six-ears-wash.md (1)

1-3: Header syntax is project-compliant – no action needed

Single-quoted package names are approved by the repo’s Changesets setup (per prior discussion).
Looks good as-is.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@jacekradko@jfoshee@dstaley@brkalow@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(backend): Signal support for handshake nonce - #5905

Merged
jacekradko merged 17 commits into
mainfrom
feat/signal-support-for-handshake-nonce
Jun 26, 2025
Merged

feat(backend): Signal support for handshake nonce#5905
jacekradko merged 17 commits into
mainfrom
feat/signal-support-for-handshake-nonce

Conversation

@jacekradko

@jacekradkojacekradko commented May 12, 2025

Copy link
Copy Markdown
Contributor

Description

Send query string param to signal support for handshake nonce flow from current version of @clerk/backend

Related: SDKI-979

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Introduced an optimized handshake process for large session payloads using a nonce-based fetching mechanism.
    • Added a new query parameter to handshake URLs to indicate support for handshake nonce during redirects.
  • Tests

    • Enhanced tests to verify the presence of the new handshake format parameter in generated URLs.

@vercel

vercelBot commented May 12, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for Git ↗︎

NameStatusPreviewCommentsUpdated (UTC)
clerk-js-sandbox✅ Ready (Inspect)Visit Preview💬 Add feedbackJun 26, 2025 3:34am

@changeset-bot

changeset-botBot commented May 12, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 87cf34e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendMinor
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@jacekradko
jacekradko requested a review from CopilotMay 12, 2025 14:43

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds support for signaling the handshake nonce flow by including a query parameter.

  • In handshake.ts, the query parameter SupportsHandshakeNonce is appended to the URL.
  • In handshake.test.ts, corresponding tests ensure the parameter is correctly set in both regular and development modes.
  • In constants.ts, a new constant for SupportsHandshakeNonce is added to support the new query parameter.

Reviewed Changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.

FileDescription
packages/backend/src/tokens/handshake.tsAppends a new query parameter for handshake nonce support.
packages/backend/src/tokens/tests/handshake.test.tsAdds tests to validate the presence of the new query parameter.
packages/backend/src/constants.tsIntroduces the SupportsHandshakeNonce constant to hold the parameter key.

Comment threadpackages/backend/src/constants.ts Outdated
@jfoshee

Copy link
Copy Markdown
Contributor

LGTM. So to be doubly clear: this indicates "nonce support", but FAPI still has the option to return 'optimized' payload in initial response, right?
I'll work on API definition update and FAPI implementation.

@jacekradko

Copy link
Copy Markdown
ContributorAuthor

@jfoshee Yeah, this is just to signal to the API that it COULD send a handshake nonce

@jacekradko
jacekradko requested a review from a teamMay 12, 2025 20:27
@pkg-pr-new

pkg-pr-newBot commented May 15, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@5905

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@5905

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@5905

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@5905

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@5905

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@5905

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@5905

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@5905

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@5905

@clerk/express

npm i https://pkg.pr.new/@clerk/express@5905

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@5905

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@5905

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@5905

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@5905

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@5905

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@5905

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@5905

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@5905

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@5905

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@5905

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@5905

@clerk/types

npm i https://pkg.pr.new/@clerk/types@5905

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@5905

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@5905

commit: 87cf34e

@jacekradko
jacekradko requested a review from aeliox as a code ownerJune 18, 2025 14:48

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (3)
.changeset/six-ears-wash.md (3)

5-5: Use a proper Markdown heading instead of bold text

Markdown-lint flags MD036 here. Replacing the bold line with a level-2 heading keeps the file consistent with other changesets and avoids lint noise.

-**Optimize handshake payload delivery with nonce-based fetching**+## Optimize handshake payload delivery with nonce-based fetching

23-26: Fix typo in example domain

ecxample.comexample.com.

-3. Handshake resolves → `307 ecxample.com` with `__clerk_handshake_nonce` cookie containing the nonce+3. Handshake resolves → `307 example.com` with `__clerk_handshake_nonce` cookie containing the nonce

30-31: Optional: add a clarifying comma

Minor readability tweak; feel free to ignore if you prefer the current wording.

-Continues to work as before with direct payload delivery in cookies for optimal performance.+Continues to work as before, with direct payload delivery in cookies for optimal performance.
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between ef10516 and 7e3ad6e.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)


[uncategorized] ~31-~31: Possible missing comma found.
Context: ... payloads ≤2KB):** Continues to work as before with direct payload delivery in cookies...

(AI_HYDRA_LEO_MISSING_COMMA)

🪛 markdownlint-cli2 (0.17.2)
.changeset/six-ears-wash.md

5-5: Emphasis used instead of a heading
null

(MD036, no-emphasis-as-heading)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
.changeset/six-ears-wash.md (1)

10-11: Mixed tenses – change “restricted” → “restricts”

Present-tense “limit” pairs naturally with present-tense “restricts”.

-… this severely restricted the practical size …+… this severely restricts the practical size …
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 7e3ad6e and be1acc3.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)
🔇 Additional comments (1)
.changeset/six-ears-wash.md (1)

24-26: Step 3 wording is ambiguous

307 example.com doesn’t tell the reader which endpoint the browser is redirected to. Spell out the full redirected URL or path (e.g. / or the original page) so integrators know what to expect.

Comment thread.changeset/six-ears-wash.md

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
.changeset/six-ears-wash.md (1)

10-11: Minor grammar tweak for release-note polish

“restricts” reads slightly better with the present-tense “Since …” lead-in.

- Since browsers limit cookies to ~4KB, this severely restricted the practical size of session tokens,+ Since browsers limit cookies to ~4KB, this severely restricts the practical size of session tokens,
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between be1acc3 and 87cf34e.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🧠 Learnings (1)
.changeset/six-ears-wash.md (1)
Learnt from: jacekradko
PR: clerk/javascript#5905
File: .changeset/six-ears-wash.md:1-3
Timestamp: 2025-06-26T03:27:05.511Z
Learning: In the Clerk JavaScript repository, changeset headers support single quotes syntax (e.g., '@clerk/backend': minor) and work fine with their current changesets integration, so there's no need to change them to double quotes.
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)
🔇 Additional comments (1)
.changeset/six-ears-wash.md (1)

1-3: Header syntax is project-compliant – no action needed

Single-quoted package names are approved by the repo’s Changesets setup (per prior discussion).
Looks good as-is.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@jacekradko@jfoshee@dstaley@brkalow@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(backend): Signal support for handshake nonce - #5905

Merged
jacekradko merged 17 commits into
mainfrom
feat/signal-support-for-handshake-nonce
Jun 26, 2025
Merged

feat(backend): Signal support for handshake nonce#5905
jacekradko merged 17 commits into
mainfrom
feat/signal-support-for-handshake-nonce

Conversation

@jacekradko

@jacekradkojacekradko commented May 12, 2025

Copy link
Copy Markdown
Contributor

Description

Send query string param to signal support for handshake nonce flow from current version of @clerk/backend

Related: SDKI-979

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Introduced an optimized handshake process for large session payloads using a nonce-based fetching mechanism.
    • Added a new query parameter to handshake URLs to indicate support for handshake nonce during redirects.
  • Tests

    • Enhanced tests to verify the presence of the new handshake format parameter in generated URLs.

@vercel

vercelBot commented May 12, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for Git ↗︎

NameStatusPreviewCommentsUpdated (UTC)
clerk-js-sandbox✅ Ready (Inspect)Visit Preview💬 Add feedbackJun 26, 2025 3:34am

@changeset-bot

changeset-botBot commented May 12, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 87cf34e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendMinor
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@jacekradko
jacekradko requested a review from CopilotMay 12, 2025 14:43

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds support for signaling the handshake nonce flow by including a query parameter.

  • In handshake.ts, the query parameter SupportsHandshakeNonce is appended to the URL.
  • In handshake.test.ts, corresponding tests ensure the parameter is correctly set in both regular and development modes.
  • In constants.ts, a new constant for SupportsHandshakeNonce is added to support the new query parameter.

Reviewed Changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.

FileDescription
packages/backend/src/tokens/handshake.tsAppends a new query parameter for handshake nonce support.
packages/backend/src/tokens/tests/handshake.test.tsAdds tests to validate the presence of the new query parameter.
packages/backend/src/constants.tsIntroduces the SupportsHandshakeNonce constant to hold the parameter key.

Comment threadpackages/backend/src/constants.ts Outdated
@jfoshee

Copy link
Copy Markdown
Contributor

LGTM. So to be doubly clear: this indicates "nonce support", but FAPI still has the option to return 'optimized' payload in initial response, right?
I'll work on API definition update and FAPI implementation.

@jacekradko

Copy link
Copy Markdown
ContributorAuthor

@jfoshee Yeah, this is just to signal to the API that it COULD send a handshake nonce

@jacekradko
jacekradko requested a review from a teamMay 12, 2025 20:27
@pkg-pr-new

pkg-pr-newBot commented May 15, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@5905

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@5905

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@5905

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@5905

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@5905

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@5905

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@5905

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@5905

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@5905

@clerk/express

npm i https://pkg.pr.new/@clerk/express@5905

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@5905

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@5905

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@5905

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@5905

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@5905

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@5905

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@5905

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@5905

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@5905

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@5905

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@5905

@clerk/types

npm i https://pkg.pr.new/@clerk/types@5905

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@5905

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@5905

commit: 87cf34e

@jacekradko
jacekradko requested a review from aeliox as a code ownerJune 18, 2025 14:48

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (3)
.changeset/six-ears-wash.md (3)

5-5: Use a proper Markdown heading instead of bold text

Markdown-lint flags MD036 here. Replacing the bold line with a level-2 heading keeps the file consistent with other changesets and avoids lint noise.

-**Optimize handshake payload delivery with nonce-based fetching**+## Optimize handshake payload delivery with nonce-based fetching

23-26: Fix typo in example domain

ecxample.comexample.com.

-3. Handshake resolves → `307 ecxample.com` with `__clerk_handshake_nonce` cookie containing the nonce+3. Handshake resolves → `307 example.com` with `__clerk_handshake_nonce` cookie containing the nonce

30-31: Optional: add a clarifying comma

Minor readability tweak; feel free to ignore if you prefer the current wording.

-Continues to work as before with direct payload delivery in cookies for optimal performance.+Continues to work as before, with direct payload delivery in cookies for optimal performance.
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between ef10516 and 7e3ad6e.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)


[uncategorized] ~31-~31: Possible missing comma found.
Context: ... payloads ≤2KB):** Continues to work as before with direct payload delivery in cookies...

(AI_HYDRA_LEO_MISSING_COMMA)

🪛 markdownlint-cli2 (0.17.2)
.changeset/six-ears-wash.md

5-5: Emphasis used instead of a heading
null

(MD036, no-emphasis-as-heading)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
.changeset/six-ears-wash.md (1)

10-11: Mixed tenses – change “restricted” → “restricts”

Present-tense “limit” pairs naturally with present-tense “restricts”.

-… this severely restricted the practical size …+… this severely restricts the practical size …
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 7e3ad6e and be1acc3.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)
🔇 Additional comments (1)
.changeset/six-ears-wash.md (1)

24-26: Step 3 wording is ambiguous

307 example.com doesn’t tell the reader which endpoint the browser is redirected to. Spell out the full redirected URL or path (e.g. / or the original page) so integrators know what to expect.

Comment thread.changeset/six-ears-wash.md

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
.changeset/six-ears-wash.md (1)

10-11: Minor grammar tweak for release-note polish

“restricts” reads slightly better with the present-tense “Since …” lead-in.

- Since browsers limit cookies to ~4KB, this severely restricted the practical size of session tokens,+ Since browsers limit cookies to ~4KB, this severely restricts the practical size of session tokens,
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between be1acc3 and 87cf34e.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🧠 Learnings (1)
.changeset/six-ears-wash.md (1)
Learnt from: jacekradko
PR: clerk/javascript#5905
File: .changeset/six-ears-wash.md:1-3
Timestamp: 2025-06-26T03:27:05.511Z
Learning: In the Clerk JavaScript repository, changeset headers support single quotes syntax (e.g., '@clerk/backend': minor) and work fine with their current changesets integration, so there's no need to change them to double quotes.
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)
🔇 Additional comments (1)
.changeset/six-ears-wash.md (1)

1-3: Header syntax is project-compliant – no action needed

Single-quoted package names are approved by the repo’s Changesets setup (per prior discussion).
Looks good as-is.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@jacekradko@jfoshee@dstaley@brkalow@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(backend): Signal support for handshake nonce - #5905

Merged
jacekradko merged 17 commits into
mainfrom
feat/signal-support-for-handshake-nonce
Jun 26, 2025
Merged

feat(backend): Signal support for handshake nonce#5905
jacekradko merged 17 commits into
mainfrom
feat/signal-support-for-handshake-nonce

Conversation

@jacekradko

@jacekradkojacekradko commented May 12, 2025

Copy link
Copy Markdown
Contributor

Description

Send query string param to signal support for handshake nonce flow from current version of @clerk/backend

Related: SDKI-979

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Introduced an optimized handshake process for large session payloads using a nonce-based fetching mechanism.
    • Added a new query parameter to handshake URLs to indicate support for handshake nonce during redirects.
  • Tests

    • Enhanced tests to verify the presence of the new handshake format parameter in generated URLs.

@vercel

vercelBot commented May 12, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for Git ↗︎

NameStatusPreviewCommentsUpdated (UTC)
clerk-js-sandbox✅ Ready (Inspect)Visit Preview💬 Add feedbackJun 26, 2025 3:34am

@changeset-bot

changeset-botBot commented May 12, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 87cf34e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendMinor
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@jacekradko
jacekradko requested a review from CopilotMay 12, 2025 14:43

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds support for signaling the handshake nonce flow by including a query parameter.

  • In handshake.ts, the query parameter SupportsHandshakeNonce is appended to the URL.
  • In handshake.test.ts, corresponding tests ensure the parameter is correctly set in both regular and development modes.
  • In constants.ts, a new constant for SupportsHandshakeNonce is added to support the new query parameter.

Reviewed Changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.

FileDescription
packages/backend/src/tokens/handshake.tsAppends a new query parameter for handshake nonce support.
packages/backend/src/tokens/tests/handshake.test.tsAdds tests to validate the presence of the new query parameter.
packages/backend/src/constants.tsIntroduces the SupportsHandshakeNonce constant to hold the parameter key.

Comment threadpackages/backend/src/constants.ts Outdated
@jfoshee

Copy link
Copy Markdown
Contributor

LGTM. So to be doubly clear: this indicates "nonce support", but FAPI still has the option to return 'optimized' payload in initial response, right?
I'll work on API definition update and FAPI implementation.

@jacekradko

Copy link
Copy Markdown
ContributorAuthor

@jfoshee Yeah, this is just to signal to the API that it COULD send a handshake nonce

@jacekradko
jacekradko requested a review from a teamMay 12, 2025 20:27
@pkg-pr-new

pkg-pr-newBot commented May 15, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@5905

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@5905

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@5905

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@5905

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@5905

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@5905

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@5905

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@5905

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@5905

@clerk/express

npm i https://pkg.pr.new/@clerk/express@5905

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@5905

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@5905

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@5905

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@5905

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@5905

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@5905

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@5905

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@5905

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@5905

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@5905

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@5905

@clerk/types

npm i https://pkg.pr.new/@clerk/types@5905

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@5905

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@5905

commit: 87cf34e

@jacekradko
jacekradko requested a review from aeliox as a code ownerJune 18, 2025 14:48

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (3)
.changeset/six-ears-wash.md (3)

5-5: Use a proper Markdown heading instead of bold text

Markdown-lint flags MD036 here. Replacing the bold line with a level-2 heading keeps the file consistent with other changesets and avoids lint noise.

-**Optimize handshake payload delivery with nonce-based fetching**+## Optimize handshake payload delivery with nonce-based fetching

23-26: Fix typo in example domain

ecxample.comexample.com.

-3. Handshake resolves → `307 ecxample.com` with `__clerk_handshake_nonce` cookie containing the nonce+3. Handshake resolves → `307 example.com` with `__clerk_handshake_nonce` cookie containing the nonce

30-31: Optional: add a clarifying comma

Minor readability tweak; feel free to ignore if you prefer the current wording.

-Continues to work as before with direct payload delivery in cookies for optimal performance.+Continues to work as before, with direct payload delivery in cookies for optimal performance.
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between ef10516 and 7e3ad6e.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)


[uncategorized] ~31-~31: Possible missing comma found.
Context: ... payloads ≤2KB):** Continues to work as before with direct payload delivery in cookies...

(AI_HYDRA_LEO_MISSING_COMMA)

🪛 markdownlint-cli2 (0.17.2)
.changeset/six-ears-wash.md

5-5: Emphasis used instead of a heading
null

(MD036, no-emphasis-as-heading)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
.changeset/six-ears-wash.md (1)

10-11: Mixed tenses – change “restricted” → “restricts”

Present-tense “limit” pairs naturally with present-tense “restricts”.

-… this severely restricted the practical size …+… this severely restricts the practical size …
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 7e3ad6e and be1acc3.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)
🔇 Additional comments (1)
.changeset/six-ears-wash.md (1)

24-26: Step 3 wording is ambiguous

307 example.com doesn’t tell the reader which endpoint the browser is redirected to. Spell out the full redirected URL or path (e.g. / or the original page) so integrators know what to expect.

Comment thread.changeset/six-ears-wash.md

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
.changeset/six-ears-wash.md (1)

10-11: Minor grammar tweak for release-note polish

“restricts” reads slightly better with the present-tense “Since …” lead-in.

- Since browsers limit cookies to ~4KB, this severely restricted the practical size of session tokens,+ Since browsers limit cookies to ~4KB, this severely restricts the practical size of session tokens,
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between be1acc3 and 87cf34e.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🧠 Learnings (1)
.changeset/six-ears-wash.md (1)
Learnt from: jacekradko
PR: clerk/javascript#5905
File: .changeset/six-ears-wash.md:1-3
Timestamp: 2025-06-26T03:27:05.511Z
Learning: In the Clerk JavaScript repository, changeset headers support single quotes syntax (e.g., '@clerk/backend': minor) and work fine with their current changesets integration, so there's no need to change them to double quotes.
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)
🔇 Additional comments (1)
.changeset/six-ears-wash.md (1)

1-3: Header syntax is project-compliant – no action needed

Single-quoted package names are approved by the repo’s Changesets setup (per prior discussion).
Looks good as-is.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@jacekradko@jfoshee@dstaley@brkalow@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(backend): Signal support for handshake nonce - #5905

Merged
jacekradko merged 17 commits into
mainfrom
feat/signal-support-for-handshake-nonce
Jun 26, 2025
Merged

feat(backend): Signal support for handshake nonce#5905
jacekradko merged 17 commits into
mainfrom
feat/signal-support-for-handshake-nonce

Conversation

@jacekradko

@jacekradkojacekradko commented May 12, 2025

Copy link
Copy Markdown
Contributor

Description

Send query string param to signal support for handshake nonce flow from current version of @clerk/backend

Related: SDKI-979

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Introduced an optimized handshake process for large session payloads using a nonce-based fetching mechanism.
    • Added a new query parameter to handshake URLs to indicate support for handshake nonce during redirects.
  • Tests

    • Enhanced tests to verify the presence of the new handshake format parameter in generated URLs.

@vercel

vercelBot commented May 12, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for Git ↗︎

NameStatusPreviewCommentsUpdated (UTC)
clerk-js-sandbox✅ Ready (Inspect)Visit Preview💬 Add feedbackJun 26, 2025 3:34am

@changeset-bot

changeset-botBot commented May 12, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 87cf34e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendMinor
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@jacekradko
jacekradko requested a review from CopilotMay 12, 2025 14:43

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds support for signaling the handshake nonce flow by including a query parameter.

  • In handshake.ts, the query parameter SupportsHandshakeNonce is appended to the URL.
  • In handshake.test.ts, corresponding tests ensure the parameter is correctly set in both regular and development modes.
  • In constants.ts, a new constant for SupportsHandshakeNonce is added to support the new query parameter.

Reviewed Changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.

FileDescription
packages/backend/src/tokens/handshake.tsAppends a new query parameter for handshake nonce support.
packages/backend/src/tokens/tests/handshake.test.tsAdds tests to validate the presence of the new query parameter.
packages/backend/src/constants.tsIntroduces the SupportsHandshakeNonce constant to hold the parameter key.

Comment threadpackages/backend/src/constants.ts Outdated
@jfoshee

Copy link
Copy Markdown
Contributor

LGTM. So to be doubly clear: this indicates "nonce support", but FAPI still has the option to return 'optimized' payload in initial response, right?
I'll work on API definition update and FAPI implementation.

@jacekradko

Copy link
Copy Markdown
ContributorAuthor

@jfoshee Yeah, this is just to signal to the API that it COULD send a handshake nonce

@jacekradko
jacekradko requested a review from a teamMay 12, 2025 20:27
@pkg-pr-new

pkg-pr-newBot commented May 15, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@5905

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@5905

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@5905

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@5905

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@5905

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@5905

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@5905

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@5905

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@5905

@clerk/express

npm i https://pkg.pr.new/@clerk/express@5905

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@5905

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@5905

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@5905

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@5905

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@5905

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@5905

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@5905

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@5905

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@5905

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@5905

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@5905

@clerk/types

npm i https://pkg.pr.new/@clerk/types@5905

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@5905

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@5905

commit: 87cf34e

@jacekradko
jacekradko requested a review from aeliox as a code ownerJune 18, 2025 14:48

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (3)
.changeset/six-ears-wash.md (3)

5-5: Use a proper Markdown heading instead of bold text

Markdown-lint flags MD036 here. Replacing the bold line with a level-2 heading keeps the file consistent with other changesets and avoids lint noise.

-**Optimize handshake payload delivery with nonce-based fetching**+## Optimize handshake payload delivery with nonce-based fetching

23-26: Fix typo in example domain

ecxample.comexample.com.

-3. Handshake resolves → `307 ecxample.com` with `__clerk_handshake_nonce` cookie containing the nonce+3. Handshake resolves → `307 example.com` with `__clerk_handshake_nonce` cookie containing the nonce

30-31: Optional: add a clarifying comma

Minor readability tweak; feel free to ignore if you prefer the current wording.

-Continues to work as before with direct payload delivery in cookies for optimal performance.+Continues to work as before, with direct payload delivery in cookies for optimal performance.
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between ef10516 and 7e3ad6e.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)


[uncategorized] ~31-~31: Possible missing comma found.
Context: ... payloads ≤2KB):** Continues to work as before with direct payload delivery in cookies...

(AI_HYDRA_LEO_MISSING_COMMA)

🪛 markdownlint-cli2 (0.17.2)
.changeset/six-ears-wash.md

5-5: Emphasis used instead of a heading
null

(MD036, no-emphasis-as-heading)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
.changeset/six-ears-wash.md (1)

10-11: Mixed tenses – change “restricted” → “restricts”

Present-tense “limit” pairs naturally with present-tense “restricts”.

-… this severely restricted the practical size …+… this severely restricts the practical size …
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 7e3ad6e and be1acc3.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)
🔇 Additional comments (1)
.changeset/six-ears-wash.md (1)

24-26: Step 3 wording is ambiguous

307 example.com doesn’t tell the reader which endpoint the browser is redirected to. Spell out the full redirected URL or path (e.g. / or the original page) so integrators know what to expect.

Comment thread.changeset/six-ears-wash.md

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
.changeset/six-ears-wash.md (1)

10-11: Minor grammar tweak for release-note polish

“restricts” reads slightly better with the present-tense “Since …” lead-in.

- Since browsers limit cookies to ~4KB, this severely restricted the practical size of session tokens,+ Since browsers limit cookies to ~4KB, this severely restricts the practical size of session tokens,
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between be1acc3 and 87cf34e.

📒 Files selected for processing (1)
  • .changeset/six-ears-wash.md (1 hunks)
🧰 Additional context used
🧠 Learnings (1)
.changeset/six-ears-wash.md (1)
Learnt from: jacekradko
PR: clerk/javascript#5905
File: .changeset/six-ears-wash.md:1-3
Timestamp: 2025-06-26T03:27:05.511Z
Learning: In the Clerk JavaScript repository, changeset headers support single quotes syntax (e.g., '@clerk/backend': minor) and work fine with their current changesets integration, so there's no need to change them to double quotes.
🪛 LanguageTool
.changeset/six-ears-wash.md

[uncategorized] ~10-~10: This verb may not be in the correct tense. Consider changing the tense to fit the context better.
Context: ...rs limit cookies to ~4KB, this severely restricted the practical size of session tokens, w...

(AI_EN_LECTOR_REPLACEMENT_VERB_TENSE)

⏰ Context from checks skipped due to timeout of 90000ms (5)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep/ci
  • GitHub Check: Analyze (javascript-typescript)
🔇 Additional comments (1)
.changeset/six-ears-wash.md (1)

1-3: Header syntax is project-compliant – no action needed

Single-quoted package names are approved by the repo’s Changesets setup (per prior discussion).
Looks good as-is.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@jacekradko@jfoshee@dstaley@brkalow@clerk-cookie