Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/wise-hornets-sneeze.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
---
'@clerk/clerk-js': minor
'@clerk/types': minor
---

[Experimental] Signals reset password flow
2 changes: 1 addition & 1 deletion packages/clerk-js/bundlewatch.config.json
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
{
"files": [
{ "path": "./dist/clerk.js", "maxSize": "622KB" },
{ "path": "./dist/clerk.browser.js", "maxSize": "75KB" },
{ "path": "./dist/clerk.browser.js", "maxSize": "76KB" },
{ "path": "./dist/clerk.legacy.browser.js", "maxSize": "117KB" },
{ "path": "./dist/clerk.headless*.js", "maxSize": "58KB" },
{ "path": "./dist/ui-common*.js", "maxSize": "113KB" },
Expand Down
70 changes: 70 additions & 0 deletions packages/clerk-js/src/core/resources/SignIn.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -497,12 +497,82 @@ class SignInFuture implements SignInFutureResource {
verifyCode: this.verifyEmailCode.bind(this),
};

resetPasswordEmailCode = {
sendCode: this.sendResetPasswordEmailCode.bind(this),
verifyCode: this.verifyResetPasswordEmailCode.bind(this),
submitPassword: this.submitResetPassword.bind(this),
};

constructor(readonly resource: SignIn) {}

get status() {
return this.resource.status;
}

async sendResetPasswordEmailCode(): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
if (!this.resource.id) {
throw new Error('Cannot reset password without a sign in.');
}

const resetPasswordEmailCodeFactor = this.resource.supportedFirstFactors?.find(
f => f.strategy === 'reset_password_email_code',
);

if (!resetPasswordEmailCodeFactor) {
throw new Error('Reset password email code factor not found');
}

const { emailAddressId } = resetPasswordEmailCodeFactor;
await this.resource.__internal_basePost({
body: { emailAddressId, strategy: 'reset_password_email_code' },
action: 'prepare_first_factor',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}

async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { code, strategy: 'reset_password_email_code' },
action: 'attempt_first_factor',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}
Comment on lines +540 to +553

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

Validate input before network call (verification code).

Avoid a roundtrip when the code is empty/whitespace. Emit and return an error immediately.

- async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {- eventBus.emit('resource:error', { resource: this.resource, error: null });+ async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {+ if (!code?.trim()) {+ const err = new Error('Verification code is required');+ eventBus.emit('resource:error', { resource: this.resource, error: err });+ return { error: err };+ }+ eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { code, strategy: 'reset_password_email_code' },
action: 'attempt_first_factor',
});

Please add a unit test for the empty/whitespace code input case.

📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
asyncverifyResetPasswordEmailCode({ code }: {code: string}): Promise<{error: unknown}>{
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {code,strategy: 'reset_password_email_code'},
action: 'attempt_first_factor',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
asyncverifyResetPasswordEmailCode({ code }: {code: string}): Promise<{error: unknown}>{
if(!code?.trim()){
consterr=newError('Verification code is required');
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {code,strategy: 'reset_password_email_code'},
action: 'attempt_first_factor',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
🤖 Prompt for AI Agents
In packages/clerk-js/src/core/resources/SignIn.ts around lines 540 to 553, add
input validation to immediately handle empty or all-whitespace verification
codes: trim the incoming code and if it's empty, create an Error (e.g. new
Error('verification code is required')), emit eventBus.emit('resource:error', {
resource: this.resource, error }), and return { error } without calling
__internal_basePost. Update/ add unit tests to cover both empty string and
whitespace-only inputs: assert that an error is returned, eventBus emitted with
that error, and __internal_basePost was not invoked.


async submitResetPassword({
password,
signOutOfOtherSessions = true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { password, signOutOfOtherSessions },
action: 'reset_password',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}
Comment on lines +555 to +574

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

Validate password input before network call; optionally pre-check policy.

  • Ensure password is non-empty before sending the request.
  • Optionally, call the existing validatePassword (policy pre-check) to provide earlier feedback.
 async submitResetPassword({
password,
signOutOfOtherSessions = true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{ error: unknown }> {
- eventBus.emit('resource:error', { resource: this.resource, error: null });+ if (!password) {+ const err = new Error('Password is required');+ eventBus.emit('resource:error', { resource: this.resource, error: err });+ return { error: err };+ }+ eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { password, signOutOfOtherSessions },
action: 'reset_password',
});

Consider tests for:

  • empty password
  • successful submission with default signOutOfOtherSessions
  • explicit signOutOfOtherSessions: false
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
asyncsubmitResetPassword({
password,
signOutOfOtherSessions=true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{error: unknown}>{
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {password,signOutOfOtherSessions},
action: 'reset_password',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
asyncsubmitResetPassword({
password,
signOutOfOtherSessions=true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{error: unknown}>{
if(!password){
consterr=newError('Password is required');
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {password,signOutOfOtherSessions},
action: 'reset_password',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
🤖 Prompt for AI Agents
In packages/clerk-js/src/core/resources/SignIn.ts around lines 555 to 574, the
submitResetPassword method currently sends the network request without
validating the password; update it to first check that password is a non-empty
string and return an immediate error if empty, and optionally invoke the
existing validatePassword (policy pre-check) before the network call to produce
early, client-side feedback; preserve existing eventBus.error emissions on
failure and ensure returned error shape stays { error: unknown }; add unit tests
for empty password, successful submission with default signOutOfOtherSessions,
and explicit signOutOfOtherSessions: false.


async create(params: {
identifier?: string;
strategy?: OAuthStrategy | 'saml' | 'enterprise_sso';
Expand Down
5 changes: 5 additions & 0 deletions packages/types/src/signIn.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -133,6 +133,11 @@ export interface SignInFutureResource {
sendCode: (params: { email: string }) => Promise<{ error: unknown }>;
verifyCode: (params: { code: string }) => Promise<{ error: unknown }>;
};
resetPasswordEmailCode: {
sendCode: () => Promise<{ error: unknown }>;
verifyCode: (params: { code: string }) => Promise<{ error: unknown }>;
submitPassword: (params: { password: string; signOutOfOtherSessions?: boolean }) => Promise<{ error: unknown }>;
};
sso: (params: {
flow?: 'auto' | 'modal';
strategy: OAuthStrategy | 'saml' | 'enterprise_sso';
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/wise-hornets-sneeze.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
---
'@clerk/clerk-js': minor
'@clerk/types': minor
---

[Experimental] Signals reset password flow
2 changes: 1 addition & 1 deletion packages/clerk-js/bundlewatch.config.json
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
{
"files": [
{ "path": "./dist/clerk.js", "maxSize": "622KB" },
{ "path": "./dist/clerk.browser.js", "maxSize": "75KB" },
{ "path": "./dist/clerk.browser.js", "maxSize": "76KB" },
{ "path": "./dist/clerk.legacy.browser.js", "maxSize": "117KB" },
{ "path": "./dist/clerk.headless*.js", "maxSize": "58KB" },
{ "path": "./dist/ui-common*.js", "maxSize": "113KB" },
Expand Down
70 changes: 70 additions & 0 deletions packages/clerk-js/src/core/resources/SignIn.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -497,12 +497,82 @@ class SignInFuture implements SignInFutureResource {
verifyCode: this.verifyEmailCode.bind(this),
};

resetPasswordEmailCode = {
sendCode: this.sendResetPasswordEmailCode.bind(this),
verifyCode: this.verifyResetPasswordEmailCode.bind(this),
submitPassword: this.submitResetPassword.bind(this),
};

constructor(readonly resource: SignIn) {}

get status() {
return this.resource.status;
}

async sendResetPasswordEmailCode(): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
if (!this.resource.id) {
throw new Error('Cannot reset password without a sign in.');
}

const resetPasswordEmailCodeFactor = this.resource.supportedFirstFactors?.find(
f => f.strategy === 'reset_password_email_code',
);

if (!resetPasswordEmailCodeFactor) {
throw new Error('Reset password email code factor not found');
}

const { emailAddressId } = resetPasswordEmailCodeFactor;
await this.resource.__internal_basePost({
body: { emailAddressId, strategy: 'reset_password_email_code' },
action: 'prepare_first_factor',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}

async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { code, strategy: 'reset_password_email_code' },
action: 'attempt_first_factor',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}
Comment on lines +540 to +553

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

Validate input before network call (verification code).

Avoid a roundtrip when the code is empty/whitespace. Emit and return an error immediately.

- async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {- eventBus.emit('resource:error', { resource: this.resource, error: null });+ async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {+ if (!code?.trim()) {+ const err = new Error('Verification code is required');+ eventBus.emit('resource:error', { resource: this.resource, error: err });+ return { error: err };+ }+ eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { code, strategy: 'reset_password_email_code' },
action: 'attempt_first_factor',
});

Please add a unit test for the empty/whitespace code input case.

📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
asyncverifyResetPasswordEmailCode({ code }: {code: string}): Promise<{error: unknown}>{
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {code,strategy: 'reset_password_email_code'},
action: 'attempt_first_factor',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
asyncverifyResetPasswordEmailCode({ code }: {code: string}): Promise<{error: unknown}>{
if(!code?.trim()){
consterr=newError('Verification code is required');
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {code,strategy: 'reset_password_email_code'},
action: 'attempt_first_factor',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
🤖 Prompt for AI Agents
In packages/clerk-js/src/core/resources/SignIn.ts around lines 540 to 553, add
input validation to immediately handle empty or all-whitespace verification
codes: trim the incoming code and if it's empty, create an Error (e.g. new
Error('verification code is required')), emit eventBus.emit('resource:error', {
resource: this.resource, error }), and return { error } without calling
__internal_basePost. Update/ add unit tests to cover both empty string and
whitespace-only inputs: assert that an error is returned, eventBus emitted with
that error, and __internal_basePost was not invoked.


async submitResetPassword({
password,
signOutOfOtherSessions = true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { password, signOutOfOtherSessions },
action: 'reset_password',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}
Comment on lines +555 to +574

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

Validate password input before network call; optionally pre-check policy.

  • Ensure password is non-empty before sending the request.
  • Optionally, call the existing validatePassword (policy pre-check) to provide earlier feedback.
 async submitResetPassword({
password,
signOutOfOtherSessions = true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{ error: unknown }> {
- eventBus.emit('resource:error', { resource: this.resource, error: null });+ if (!password) {+ const err = new Error('Password is required');+ eventBus.emit('resource:error', { resource: this.resource, error: err });+ return { error: err };+ }+ eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { password, signOutOfOtherSessions },
action: 'reset_password',
});

Consider tests for:

  • empty password
  • successful submission with default signOutOfOtherSessions
  • explicit signOutOfOtherSessions: false
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
asyncsubmitResetPassword({
password,
signOutOfOtherSessions=true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{error: unknown}>{
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {password,signOutOfOtherSessions},
action: 'reset_password',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
asyncsubmitResetPassword({
password,
signOutOfOtherSessions=true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{error: unknown}>{
if(!password){
consterr=newError('Password is required');
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {password,signOutOfOtherSessions},
action: 'reset_password',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
🤖 Prompt for AI Agents
In packages/clerk-js/src/core/resources/SignIn.ts around lines 555 to 574, the
submitResetPassword method currently sends the network request without
validating the password; update it to first check that password is a non-empty
string and return an immediate error if empty, and optionally invoke the
existing validatePassword (policy pre-check) before the network call to produce
early, client-side feedback; preserve existing eventBus.error emissions on
failure and ensure returned error shape stays { error: unknown }; add unit tests
for empty password, successful submission with default signOutOfOtherSessions,
and explicit signOutOfOtherSessions: false.


async create(params: {
identifier?: string;
strategy?: OAuthStrategy | 'saml' | 'enterprise_sso';
Expand Down
5 changes: 5 additions & 0 deletions packages/types/src/signIn.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -133,6 +133,11 @@ export interface SignInFutureResource {
sendCode: (params: { email: string }) => Promise<{ error: unknown }>;
verifyCode: (params: { code: string }) => Promise<{ error: unknown }>;
};
resetPasswordEmailCode: {
sendCode: () => Promise<{ error: unknown }>;
verifyCode: (params: { code: string }) => Promise<{ error: unknown }>;
submitPassword: (params: { password: string; signOutOfOtherSessions?: boolean }) => Promise<{ error: unknown }>;
};
sso: (params: {
flow?: 'auto' | 'modal';
strategy: OAuthStrategy | 'saml' | 'enterprise_sso';
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/wise-hornets-sneeze.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
---
'@clerk/clerk-js': minor
'@clerk/types': minor
---

[Experimental] Signals reset password flow
2 changes: 1 addition & 1 deletion packages/clerk-js/bundlewatch.config.json
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
{
"files": [
{ "path": "./dist/clerk.js", "maxSize": "622KB" },
{ "path": "./dist/clerk.browser.js", "maxSize": "75KB" },
{ "path": "./dist/clerk.browser.js", "maxSize": "76KB" },
{ "path": "./dist/clerk.legacy.browser.js", "maxSize": "117KB" },
{ "path": "./dist/clerk.headless*.js", "maxSize": "58KB" },
{ "path": "./dist/ui-common*.js", "maxSize": "113KB" },
Expand Down
70 changes: 70 additions & 0 deletions packages/clerk-js/src/core/resources/SignIn.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -497,12 +497,82 @@ class SignInFuture implements SignInFutureResource {
verifyCode: this.verifyEmailCode.bind(this),
};

resetPasswordEmailCode = {
sendCode: this.sendResetPasswordEmailCode.bind(this),
verifyCode: this.verifyResetPasswordEmailCode.bind(this),
submitPassword: this.submitResetPassword.bind(this),
};

constructor(readonly resource: SignIn) {}

get status() {
return this.resource.status;
}

async sendResetPasswordEmailCode(): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
if (!this.resource.id) {
throw new Error('Cannot reset password without a sign in.');
}

const resetPasswordEmailCodeFactor = this.resource.supportedFirstFactors?.find(
f => f.strategy === 'reset_password_email_code',
);

if (!resetPasswordEmailCodeFactor) {
throw new Error('Reset password email code factor not found');
}

const { emailAddressId } = resetPasswordEmailCodeFactor;
await this.resource.__internal_basePost({
body: { emailAddressId, strategy: 'reset_password_email_code' },
action: 'prepare_first_factor',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}

async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { code, strategy: 'reset_password_email_code' },
action: 'attempt_first_factor',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}
Comment on lines +540 to +553

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

Validate input before network call (verification code).

Avoid a roundtrip when the code is empty/whitespace. Emit and return an error immediately.

- async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {- eventBus.emit('resource:error', { resource: this.resource, error: null });+ async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {+ if (!code?.trim()) {+ const err = new Error('Verification code is required');+ eventBus.emit('resource:error', { resource: this.resource, error: err });+ return { error: err };+ }+ eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { code, strategy: 'reset_password_email_code' },
action: 'attempt_first_factor',
});

Please add a unit test for the empty/whitespace code input case.

📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
asyncverifyResetPasswordEmailCode({ code }: {code: string}): Promise<{error: unknown}>{
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {code,strategy: 'reset_password_email_code'},
action: 'attempt_first_factor',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
asyncverifyResetPasswordEmailCode({ code }: {code: string}): Promise<{error: unknown}>{
if(!code?.trim()){
consterr=newError('Verification code is required');
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {code,strategy: 'reset_password_email_code'},
action: 'attempt_first_factor',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
🤖 Prompt for AI Agents
In packages/clerk-js/src/core/resources/SignIn.ts around lines 540 to 553, add
input validation to immediately handle empty or all-whitespace verification
codes: trim the incoming code and if it's empty, create an Error (e.g. new
Error('verification code is required')), emit eventBus.emit('resource:error', {
resource: this.resource, error }), and return { error } without calling
__internal_basePost. Update/ add unit tests to cover both empty string and
whitespace-only inputs: assert that an error is returned, eventBus emitted with
that error, and __internal_basePost was not invoked.


async submitResetPassword({
password,
signOutOfOtherSessions = true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { password, signOutOfOtherSessions },
action: 'reset_password',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}
Comment on lines +555 to +574

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

Validate password input before network call; optionally pre-check policy.

  • Ensure password is non-empty before sending the request.
  • Optionally, call the existing validatePassword (policy pre-check) to provide earlier feedback.
 async submitResetPassword({
password,
signOutOfOtherSessions = true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{ error: unknown }> {
- eventBus.emit('resource:error', { resource: this.resource, error: null });+ if (!password) {+ const err = new Error('Password is required');+ eventBus.emit('resource:error', { resource: this.resource, error: err });+ return { error: err };+ }+ eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { password, signOutOfOtherSessions },
action: 'reset_password',
});

Consider tests for:

  • empty password
  • successful submission with default signOutOfOtherSessions
  • explicit signOutOfOtherSessions: false
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
asyncsubmitResetPassword({
password,
signOutOfOtherSessions=true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{error: unknown}>{
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {password,signOutOfOtherSessions},
action: 'reset_password',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
asyncsubmitResetPassword({
password,
signOutOfOtherSessions=true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{error: unknown}>{
if(!password){
consterr=newError('Password is required');
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {password,signOutOfOtherSessions},
action: 'reset_password',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
🤖 Prompt for AI Agents
In packages/clerk-js/src/core/resources/SignIn.ts around lines 555 to 574, the
submitResetPassword method currently sends the network request without
validating the password; update it to first check that password is a non-empty
string and return an immediate error if empty, and optionally invoke the
existing validatePassword (policy pre-check) before the network call to produce
early, client-side feedback; preserve existing eventBus.error emissions on
failure and ensure returned error shape stays { error: unknown }; add unit tests
for empty password, successful submission with default signOutOfOtherSessions,
and explicit signOutOfOtherSessions: false.


async create(params: {
identifier?: string;
strategy?: OAuthStrategy | 'saml' | 'enterprise_sso';
Expand Down
5 changes: 5 additions & 0 deletions packages/types/src/signIn.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -133,6 +133,11 @@ export interface SignInFutureResource {
sendCode: (params: { email: string }) => Promise<{ error: unknown }>;
verifyCode: (params: { code: string }) => Promise<{ error: unknown }>;
};
resetPasswordEmailCode: {
sendCode: () => Promise<{ error: unknown }>;
verifyCode: (params: { code: string }) => Promise<{ error: unknown }>;
submitPassword: (params: { password: string; signOutOfOtherSessions?: boolean }) => Promise<{ error: unknown }>;
};
sso: (params: {
flow?: 'auto' | 'modal';
strategy: OAuthStrategy | 'saml' | 'enterprise_sso';
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/wise-hornets-sneeze.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
---
'@clerk/clerk-js': minor
'@clerk/types': minor
---

[Experimental] Signals reset password flow
2 changes: 1 addition & 1 deletion packages/clerk-js/bundlewatch.config.json
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
{
"files": [
{ "path": "./dist/clerk.js", "maxSize": "622KB" },
{ "path": "./dist/clerk.browser.js", "maxSize": "75KB" },
{ "path": "./dist/clerk.browser.js", "maxSize": "76KB" },
{ "path": "./dist/clerk.legacy.browser.js", "maxSize": "117KB" },
{ "path": "./dist/clerk.headless*.js", "maxSize": "58KB" },
{ "path": "./dist/ui-common*.js", "maxSize": "113KB" },
Expand Down
70 changes: 70 additions & 0 deletions packages/clerk-js/src/core/resources/SignIn.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -497,12 +497,82 @@ class SignInFuture implements SignInFutureResource {
verifyCode: this.verifyEmailCode.bind(this),
};

resetPasswordEmailCode = {
sendCode: this.sendResetPasswordEmailCode.bind(this),
verifyCode: this.verifyResetPasswordEmailCode.bind(this),
submitPassword: this.submitResetPassword.bind(this),
};

constructor(readonly resource: SignIn) {}

get status() {
return this.resource.status;
}

async sendResetPasswordEmailCode(): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
if (!this.resource.id) {
throw new Error('Cannot reset password without a sign in.');
}

const resetPasswordEmailCodeFactor = this.resource.supportedFirstFactors?.find(
f => f.strategy === 'reset_password_email_code',
);

if (!resetPasswordEmailCodeFactor) {
throw new Error('Reset password email code factor not found');
}

const { emailAddressId } = resetPasswordEmailCodeFactor;
await this.resource.__internal_basePost({
body: { emailAddressId, strategy: 'reset_password_email_code' },
action: 'prepare_first_factor',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}

async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { code, strategy: 'reset_password_email_code' },
action: 'attempt_first_factor',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}
Comment on lines +540 to +553

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

Validate input before network call (verification code).

Avoid a roundtrip when the code is empty/whitespace. Emit and return an error immediately.

- async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {- eventBus.emit('resource:error', { resource: this.resource, error: null });+ async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {+ if (!code?.trim()) {+ const err = new Error('Verification code is required');+ eventBus.emit('resource:error', { resource: this.resource, error: err });+ return { error: err };+ }+ eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { code, strategy: 'reset_password_email_code' },
action: 'attempt_first_factor',
});

Please add a unit test for the empty/whitespace code input case.

📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
asyncverifyResetPasswordEmailCode({ code }: {code: string}): Promise<{error: unknown}>{
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {code,strategy: 'reset_password_email_code'},
action: 'attempt_first_factor',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
asyncverifyResetPasswordEmailCode({ code }: {code: string}): Promise<{error: unknown}>{
if(!code?.trim()){
consterr=newError('Verification code is required');
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {code,strategy: 'reset_password_email_code'},
action: 'attempt_first_factor',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
🤖 Prompt for AI Agents
In packages/clerk-js/src/core/resources/SignIn.ts around lines 540 to 553, add
input validation to immediately handle empty or all-whitespace verification
codes: trim the incoming code and if it's empty, create an Error (e.g. new
Error('verification code is required')), emit eventBus.emit('resource:error', {
resource: this.resource, error }), and return { error } without calling
__internal_basePost. Update/ add unit tests to cover both empty string and
whitespace-only inputs: assert that an error is returned, eventBus emitted with
that error, and __internal_basePost was not invoked.


async submitResetPassword({
password,
signOutOfOtherSessions = true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { password, signOutOfOtherSessions },
action: 'reset_password',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}
Comment on lines +555 to +574

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

Validate password input before network call; optionally pre-check policy.

  • Ensure password is non-empty before sending the request.
  • Optionally, call the existing validatePassword (policy pre-check) to provide earlier feedback.
 async submitResetPassword({
password,
signOutOfOtherSessions = true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{ error: unknown }> {
- eventBus.emit('resource:error', { resource: this.resource, error: null });+ if (!password) {+ const err = new Error('Password is required');+ eventBus.emit('resource:error', { resource: this.resource, error: err });+ return { error: err };+ }+ eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { password, signOutOfOtherSessions },
action: 'reset_password',
});

Consider tests for:

  • empty password
  • successful submission with default signOutOfOtherSessions
  • explicit signOutOfOtherSessions: false
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
asyncsubmitResetPassword({
password,
signOutOfOtherSessions=true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{error: unknown}>{
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {password,signOutOfOtherSessions},
action: 'reset_password',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
asyncsubmitResetPassword({
password,
signOutOfOtherSessions=true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{error: unknown}>{
if(!password){
consterr=newError('Password is required');
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {password,signOutOfOtherSessions},
action: 'reset_password',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
🤖 Prompt for AI Agents
In packages/clerk-js/src/core/resources/SignIn.ts around lines 555 to 574, the
submitResetPassword method currently sends the network request without
validating the password; update it to first check that password is a non-empty
string and return an immediate error if empty, and optionally invoke the
existing validatePassword (policy pre-check) before the network call to produce
early, client-side feedback; preserve existing eventBus.error emissions on
failure and ensure returned error shape stays { error: unknown }; add unit tests
for empty password, successful submission with default signOutOfOtherSessions,
and explicit signOutOfOtherSessions: false.


async create(params: {
identifier?: string;
strategy?: OAuthStrategy | 'saml' | 'enterprise_sso';
Expand Down
5 changes: 5 additions & 0 deletions packages/types/src/signIn.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -133,6 +133,11 @@ export interface SignInFutureResource {
sendCode: (params: { email: string }) => Promise<{ error: unknown }>;
verifyCode: (params: { code: string }) => Promise<{ error: unknown }>;
};
resetPasswordEmailCode: {
sendCode: () => Promise<{ error: unknown }>;
verifyCode: (params: { code: string }) => Promise<{ error: unknown }>;
submitPassword: (params: { password: string; signOutOfOtherSessions?: boolean }) => Promise<{ error: unknown }>;
};
sso: (params: {
flow?: 'auto' | 'modal';
strategy: OAuthStrategy | 'saml' | 'enterprise_sso';
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/wise-hornets-sneeze.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
---
'@clerk/clerk-js': minor
'@clerk/types': minor
---

[Experimental] Signals reset password flow
2 changes: 1 addition & 1 deletion packages/clerk-js/bundlewatch.config.json
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
{
"files": [
{ "path": "./dist/clerk.js", "maxSize": "622KB" },
{ "path": "./dist/clerk.browser.js", "maxSize": "75KB" },
{ "path": "./dist/clerk.browser.js", "maxSize": "76KB" },
{ "path": "./dist/clerk.legacy.browser.js", "maxSize": "117KB" },
{ "path": "./dist/clerk.headless*.js", "maxSize": "58KB" },
{ "path": "./dist/ui-common*.js", "maxSize": "113KB" },
Expand Down
70 changes: 70 additions & 0 deletions packages/clerk-js/src/core/resources/SignIn.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -497,12 +497,82 @@ class SignInFuture implements SignInFutureResource {
verifyCode: this.verifyEmailCode.bind(this),
};

resetPasswordEmailCode = {
sendCode: this.sendResetPasswordEmailCode.bind(this),
verifyCode: this.verifyResetPasswordEmailCode.bind(this),
submitPassword: this.submitResetPassword.bind(this),
};

constructor(readonly resource: SignIn) {}

get status() {
return this.resource.status;
}

async sendResetPasswordEmailCode(): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
if (!this.resource.id) {
throw new Error('Cannot reset password without a sign in.');
}

const resetPasswordEmailCodeFactor = this.resource.supportedFirstFactors?.find(
f => f.strategy === 'reset_password_email_code',
);

if (!resetPasswordEmailCodeFactor) {
throw new Error('Reset password email code factor not found');
}

const { emailAddressId } = resetPasswordEmailCodeFactor;
await this.resource.__internal_basePost({
body: { emailAddressId, strategy: 'reset_password_email_code' },
action: 'prepare_first_factor',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}

async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { code, strategy: 'reset_password_email_code' },
action: 'attempt_first_factor',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}
Comment on lines +540 to +553

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

Validate input before network call (verification code).

Avoid a roundtrip when the code is empty/whitespace. Emit and return an error immediately.

- async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {- eventBus.emit('resource:error', { resource: this.resource, error: null });+ async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {+ if (!code?.trim()) {+ const err = new Error('Verification code is required');+ eventBus.emit('resource:error', { resource: this.resource, error: err });+ return { error: err };+ }+ eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { code, strategy: 'reset_password_email_code' },
action: 'attempt_first_factor',
});

Please add a unit test for the empty/whitespace code input case.

📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
asyncverifyResetPasswordEmailCode({ code }: {code: string}): Promise<{error: unknown}>{
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {code,strategy: 'reset_password_email_code'},
action: 'attempt_first_factor',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
asyncverifyResetPasswordEmailCode({ code }: {code: string}): Promise<{error: unknown}>{
if(!code?.trim()){
consterr=newError('Verification code is required');
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {code,strategy: 'reset_password_email_code'},
action: 'attempt_first_factor',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
🤖 Prompt for AI Agents
In packages/clerk-js/src/core/resources/SignIn.ts around lines 540 to 553, add
input validation to immediately handle empty or all-whitespace verification
codes: trim the incoming code and if it's empty, create an Error (e.g. new
Error('verification code is required')), emit eventBus.emit('resource:error', {
resource: this.resource, error }), and return { error } without calling
__internal_basePost. Update/ add unit tests to cover both empty string and
whitespace-only inputs: assert that an error is returned, eventBus emitted with
that error, and __internal_basePost was not invoked.


async submitResetPassword({
password,
signOutOfOtherSessions = true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { password, signOutOfOtherSessions },
action: 'reset_password',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}
Comment on lines +555 to +574

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

Validate password input before network call; optionally pre-check policy.

  • Ensure password is non-empty before sending the request.
  • Optionally, call the existing validatePassword (policy pre-check) to provide earlier feedback.
 async submitResetPassword({
password,
signOutOfOtherSessions = true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{ error: unknown }> {
- eventBus.emit('resource:error', { resource: this.resource, error: null });+ if (!password) {+ const err = new Error('Password is required');+ eventBus.emit('resource:error', { resource: this.resource, error: err });+ return { error: err };+ }+ eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { password, signOutOfOtherSessions },
action: 'reset_password',
});

Consider tests for:

  • empty password
  • successful submission with default signOutOfOtherSessions
  • explicit signOutOfOtherSessions: false
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
asyncsubmitResetPassword({
password,
signOutOfOtherSessions=true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{error: unknown}>{
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {password,signOutOfOtherSessions},
action: 'reset_password',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
asyncsubmitResetPassword({
password,
signOutOfOtherSessions=true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{error: unknown}>{
if(!password){
consterr=newError('Password is required');
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {password,signOutOfOtherSessions},
action: 'reset_password',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
🤖 Prompt for AI Agents
In packages/clerk-js/src/core/resources/SignIn.ts around lines 555 to 574, the
submitResetPassword method currently sends the network request without
validating the password; update it to first check that password is a non-empty
string and return an immediate error if empty, and optionally invoke the
existing validatePassword (policy pre-check) before the network call to produce
early, client-side feedback; preserve existing eventBus.error emissions on
failure and ensure returned error shape stays { error: unknown }; add unit tests
for empty password, successful submission with default signOutOfOtherSessions,
and explicit signOutOfOtherSessions: false.


async create(params: {
identifier?: string;
strategy?: OAuthStrategy | 'saml' | 'enterprise_sso';
Expand Down
5 changes: 5 additions & 0 deletions packages/types/src/signIn.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -133,6 +133,11 @@ export interface SignInFutureResource {
sendCode: (params: { email: string }) => Promise<{ error: unknown }>;
verifyCode: (params: { code: string }) => Promise<{ error: unknown }>;
};
resetPasswordEmailCode: {
sendCode: () => Promise<{ error: unknown }>;
verifyCode: (params: { code: string }) => Promise<{ error: unknown }>;
submitPassword: (params: { password: string; signOutOfOtherSessions?: boolean }) => Promise<{ error: unknown }>;
};
sso: (params: {
flow?: 'auto' | 'modal';
strategy: OAuthStrategy | 'saml' | 'enterprise_sso';
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/wise-hornets-sneeze.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
---
'@clerk/clerk-js': minor
'@clerk/types': minor
---

[Experimental] Signals reset password flow
2 changes: 1 addition & 1 deletion packages/clerk-js/bundlewatch.config.json
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
{
"files": [
{ "path": "./dist/clerk.js", "maxSize": "622KB" },
{ "path": "./dist/clerk.browser.js", "maxSize": "75KB" },
{ "path": "./dist/clerk.browser.js", "maxSize": "76KB" },
{ "path": "./dist/clerk.legacy.browser.js", "maxSize": "117KB" },
{ "path": "./dist/clerk.headless*.js", "maxSize": "58KB" },
{ "path": "./dist/ui-common*.js", "maxSize": "113KB" },
Expand Down
70 changes: 70 additions & 0 deletions packages/clerk-js/src/core/resources/SignIn.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -497,12 +497,82 @@ class SignInFuture implements SignInFutureResource {
verifyCode: this.verifyEmailCode.bind(this),
};

resetPasswordEmailCode = {
sendCode: this.sendResetPasswordEmailCode.bind(this),
verifyCode: this.verifyResetPasswordEmailCode.bind(this),
submitPassword: this.submitResetPassword.bind(this),
};

constructor(readonly resource: SignIn) {}

get status() {
return this.resource.status;
}

async sendResetPasswordEmailCode(): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
if (!this.resource.id) {
throw new Error('Cannot reset password without a sign in.');
}

const resetPasswordEmailCodeFactor = this.resource.supportedFirstFactors?.find(
f => f.strategy === 'reset_password_email_code',
);

if (!resetPasswordEmailCodeFactor) {
throw new Error('Reset password email code factor not found');
}

const { emailAddressId } = resetPasswordEmailCodeFactor;
await this.resource.__internal_basePost({
body: { emailAddressId, strategy: 'reset_password_email_code' },
action: 'prepare_first_factor',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}

async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { code, strategy: 'reset_password_email_code' },
action: 'attempt_first_factor',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}
Comment on lines +540 to +553

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

Validate input before network call (verification code).

Avoid a roundtrip when the code is empty/whitespace. Emit and return an error immediately.

- async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {- eventBus.emit('resource:error', { resource: this.resource, error: null });+ async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {+ if (!code?.trim()) {+ const err = new Error('Verification code is required');+ eventBus.emit('resource:error', { resource: this.resource, error: err });+ return { error: err };+ }+ eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { code, strategy: 'reset_password_email_code' },
action: 'attempt_first_factor',
});

Please add a unit test for the empty/whitespace code input case.

📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
asyncverifyResetPasswordEmailCode({ code }: {code: string}): Promise<{error: unknown}>{
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {code,strategy: 'reset_password_email_code'},
action: 'attempt_first_factor',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
asyncverifyResetPasswordEmailCode({ code }: {code: string}): Promise<{error: unknown}>{
if(!code?.trim()){
consterr=newError('Verification code is required');
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {code,strategy: 'reset_password_email_code'},
action: 'attempt_first_factor',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
🤖 Prompt for AI Agents
In packages/clerk-js/src/core/resources/SignIn.ts around lines 540 to 553, add
input validation to immediately handle empty or all-whitespace verification
codes: trim the incoming code and if it's empty, create an Error (e.g. new
Error('verification code is required')), emit eventBus.emit('resource:error', {
resource: this.resource, error }), and return { error } without calling
__internal_basePost. Update/ add unit tests to cover both empty string and
whitespace-only inputs: assert that an error is returned, eventBus emitted with
that error, and __internal_basePost was not invoked.


async submitResetPassword({
password,
signOutOfOtherSessions = true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { password, signOutOfOtherSessions },
action: 'reset_password',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}
Comment on lines +555 to +574

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

Validate password input before network call; optionally pre-check policy.

  • Ensure password is non-empty before sending the request.
  • Optionally, call the existing validatePassword (policy pre-check) to provide earlier feedback.
 async submitResetPassword({
password,
signOutOfOtherSessions = true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{ error: unknown }> {
- eventBus.emit('resource:error', { resource: this.resource, error: null });+ if (!password) {+ const err = new Error('Password is required');+ eventBus.emit('resource:error', { resource: this.resource, error: err });+ return { error: err };+ }+ eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { password, signOutOfOtherSessions },
action: 'reset_password',
});

Consider tests for:

  • empty password
  • successful submission with default signOutOfOtherSessions
  • explicit signOutOfOtherSessions: false
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
asyncsubmitResetPassword({
password,
signOutOfOtherSessions=true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{error: unknown}>{
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {password,signOutOfOtherSessions},
action: 'reset_password',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
asyncsubmitResetPassword({
password,
signOutOfOtherSessions=true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{error: unknown}>{
if(!password){
consterr=newError('Password is required');
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {password,signOutOfOtherSessions},
action: 'reset_password',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
🤖 Prompt for AI Agents
In packages/clerk-js/src/core/resources/SignIn.ts around lines 555 to 574, the
submitResetPassword method currently sends the network request without
validating the password; update it to first check that password is a non-empty
string and return an immediate error if empty, and optionally invoke the
existing validatePassword (policy pre-check) before the network call to produce
early, client-side feedback; preserve existing eventBus.error emissions on
failure and ensure returned error shape stays { error: unknown }; add unit tests
for empty password, successful submission with default signOutOfOtherSessions,
and explicit signOutOfOtherSessions: false.


async create(params: {
identifier?: string;
strategy?: OAuthStrategy | 'saml' | 'enterprise_sso';
Expand Down
5 changes: 5 additions & 0 deletions packages/types/src/signIn.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -133,6 +133,11 @@ export interface SignInFutureResource {
sendCode: (params: { email: string }) => Promise<{ error: unknown }>;
verifyCode: (params: { code: string }) => Promise<{ error: unknown }>;
};
resetPasswordEmailCode: {
sendCode: () => Promise<{ error: unknown }>;
verifyCode: (params: { code: string }) => Promise<{ error: unknown }>;
submitPassword: (params: { password: string; signOutOfOtherSessions?: boolean }) => Promise<{ error: unknown }>;
};
sso: (params: {
flow?: 'auto' | 'modal';
strategy: OAuthStrategy | 'saml' | 'enterprise_sso';
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/wise-hornets-sneeze.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
---
'@clerk/clerk-js': minor
'@clerk/types': minor
---

[Experimental] Signals reset password flow
2 changes: 1 addition & 1 deletion packages/clerk-js/bundlewatch.config.json
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
{
"files": [
{ "path": "./dist/clerk.js", "maxSize": "622KB" },
{ "path": "./dist/clerk.browser.js", "maxSize": "75KB" },
{ "path": "./dist/clerk.browser.js", "maxSize": "76KB" },
{ "path": "./dist/clerk.legacy.browser.js", "maxSize": "117KB" },
{ "path": "./dist/clerk.headless*.js", "maxSize": "58KB" },
{ "path": "./dist/ui-common*.js", "maxSize": "113KB" },
Expand Down
70 changes: 70 additions & 0 deletions packages/clerk-js/src/core/resources/SignIn.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -497,12 +497,82 @@ class SignInFuture implements SignInFutureResource {
verifyCode: this.verifyEmailCode.bind(this),
};

resetPasswordEmailCode = {
sendCode: this.sendResetPasswordEmailCode.bind(this),
verifyCode: this.verifyResetPasswordEmailCode.bind(this),
submitPassword: this.submitResetPassword.bind(this),
};

constructor(readonly resource: SignIn) {}

get status() {
return this.resource.status;
}

async sendResetPasswordEmailCode(): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
if (!this.resource.id) {
throw new Error('Cannot reset password without a sign in.');
}

const resetPasswordEmailCodeFactor = this.resource.supportedFirstFactors?.find(
f => f.strategy === 'reset_password_email_code',
);

if (!resetPasswordEmailCodeFactor) {
throw new Error('Reset password email code factor not found');
}

const { emailAddressId } = resetPasswordEmailCodeFactor;
await this.resource.__internal_basePost({
body: { emailAddressId, strategy: 'reset_password_email_code' },
action: 'prepare_first_factor',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}

async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { code, strategy: 'reset_password_email_code' },
action: 'attempt_first_factor',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}
Comment on lines +540 to +553

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

Validate input before network call (verification code).

Avoid a roundtrip when the code is empty/whitespace. Emit and return an error immediately.

- async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {- eventBus.emit('resource:error', { resource: this.resource, error: null });+ async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {+ if (!code?.trim()) {+ const err = new Error('Verification code is required');+ eventBus.emit('resource:error', { resource: this.resource, error: err });+ return { error: err };+ }+ eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { code, strategy: 'reset_password_email_code' },
action: 'attempt_first_factor',
});

Please add a unit test for the empty/whitespace code input case.

📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
asyncverifyResetPasswordEmailCode({ code }: {code: string}): Promise<{error: unknown}>{
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {code,strategy: 'reset_password_email_code'},
action: 'attempt_first_factor',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
asyncverifyResetPasswordEmailCode({ code }: {code: string}): Promise<{error: unknown}>{
if(!code?.trim()){
consterr=newError('Verification code is required');
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {code,strategy: 'reset_password_email_code'},
action: 'attempt_first_factor',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
🤖 Prompt for AI Agents
In packages/clerk-js/src/core/resources/SignIn.ts around lines 540 to 553, add
input validation to immediately handle empty or all-whitespace verification
codes: trim the incoming code and if it's empty, create an Error (e.g. new
Error('verification code is required')), emit eventBus.emit('resource:error', {
resource: this.resource, error }), and return { error } without calling
__internal_basePost. Update/ add unit tests to cover both empty string and
whitespace-only inputs: assert that an error is returned, eventBus emitted with
that error, and __internal_basePost was not invoked.


async submitResetPassword({
password,
signOutOfOtherSessions = true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { password, signOutOfOtherSessions },
action: 'reset_password',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}
Comment on lines +555 to +574

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

Validate password input before network call; optionally pre-check policy.

  • Ensure password is non-empty before sending the request.
  • Optionally, call the existing validatePassword (policy pre-check) to provide earlier feedback.
 async submitResetPassword({
password,
signOutOfOtherSessions = true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{ error: unknown }> {
- eventBus.emit('resource:error', { resource: this.resource, error: null });+ if (!password) {+ const err = new Error('Password is required');+ eventBus.emit('resource:error', { resource: this.resource, error: err });+ return { error: err };+ }+ eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { password, signOutOfOtherSessions },
action: 'reset_password',
});

Consider tests for:

  • empty password
  • successful submission with default signOutOfOtherSessions
  • explicit signOutOfOtherSessions: false
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
asyncsubmitResetPassword({
password,
signOutOfOtherSessions=true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{error: unknown}>{
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {password,signOutOfOtherSessions},
action: 'reset_password',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
asyncsubmitResetPassword({
password,
signOutOfOtherSessions=true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{error: unknown}>{
if(!password){
consterr=newError('Password is required');
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {password,signOutOfOtherSessions},
action: 'reset_password',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
🤖 Prompt for AI Agents
In packages/clerk-js/src/core/resources/SignIn.ts around lines 555 to 574, the
submitResetPassword method currently sends the network request without
validating the password; update it to first check that password is a non-empty
string and return an immediate error if empty, and optionally invoke the
existing validatePassword (policy pre-check) before the network call to produce
early, client-side feedback; preserve existing eventBus.error emissions on
failure and ensure returned error shape stays { error: unknown }; add unit tests
for empty password, successful submission with default signOutOfOtherSessions,
and explicit signOutOfOtherSessions: false.


async create(params: {
identifier?: string;
strategy?: OAuthStrategy | 'saml' | 'enterprise_sso';
Expand Down
5 changes: 5 additions & 0 deletions packages/types/src/signIn.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -133,6 +133,11 @@ export interface SignInFutureResource {
sendCode: (params: { email: string }) => Promise<{ error: unknown }>;
verifyCode: (params: { code: string }) => Promise<{ error: unknown }>;
};
resetPasswordEmailCode: {
sendCode: () => Promise<{ error: unknown }>;
verifyCode: (params: { code: string }) => Promise<{ error: unknown }>;
submitPassword: (params: { password: string; signOutOfOtherSessions?: boolean }) => Promise<{ error: unknown }>;
};
sso: (params: {
flow?: 'auto' | 'modal';
strategy: OAuthStrategy | 'saml' | 'enterprise_sso';
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/wise-hornets-sneeze.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
---
'@clerk/clerk-js': minor
'@clerk/types': minor
---

[Experimental] Signals reset password flow
2 changes: 1 addition & 1 deletion packages/clerk-js/bundlewatch.config.json
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
{
"files": [
{ "path": "./dist/clerk.js", "maxSize": "622KB" },
{ "path": "./dist/clerk.browser.js", "maxSize": "75KB" },
{ "path": "./dist/clerk.browser.js", "maxSize": "76KB" },
{ "path": "./dist/clerk.legacy.browser.js", "maxSize": "117KB" },
{ "path": "./dist/clerk.headless*.js", "maxSize": "58KB" },
{ "path": "./dist/ui-common*.js", "maxSize": "113KB" },
Expand Down
70 changes: 70 additions & 0 deletions packages/clerk-js/src/core/resources/SignIn.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -497,12 +497,82 @@ class SignInFuture implements SignInFutureResource {
verifyCode: this.verifyEmailCode.bind(this),
};

resetPasswordEmailCode = {
sendCode: this.sendResetPasswordEmailCode.bind(this),
verifyCode: this.verifyResetPasswordEmailCode.bind(this),
submitPassword: this.submitResetPassword.bind(this),
};

constructor(readonly resource: SignIn) {}

get status() {
return this.resource.status;
}

async sendResetPasswordEmailCode(): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
if (!this.resource.id) {
throw new Error('Cannot reset password without a sign in.');
}

const resetPasswordEmailCodeFactor = this.resource.supportedFirstFactors?.find(
f => f.strategy === 'reset_password_email_code',
);

if (!resetPasswordEmailCodeFactor) {
throw new Error('Reset password email code factor not found');
}

const { emailAddressId } = resetPasswordEmailCodeFactor;
await this.resource.__internal_basePost({
body: { emailAddressId, strategy: 'reset_password_email_code' },
action: 'prepare_first_factor',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}

async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { code, strategy: 'reset_password_email_code' },
action: 'attempt_first_factor',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}
Comment on lines +540 to +553

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

Validate input before network call (verification code).

Avoid a roundtrip when the code is empty/whitespace. Emit and return an error immediately.

- async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {- eventBus.emit('resource:error', { resource: this.resource, error: null });+ async verifyResetPasswordEmailCode({ code }: { code: string }): Promise<{ error: unknown }> {+ if (!code?.trim()) {+ const err = new Error('Verification code is required');+ eventBus.emit('resource:error', { resource: this.resource, error: err });+ return { error: err };+ }+ eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { code, strategy: 'reset_password_email_code' },
action: 'attempt_first_factor',
});

Please add a unit test for the empty/whitespace code input case.

📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
asyncverifyResetPasswordEmailCode({ code }: {code: string}): Promise<{error: unknown}>{
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {code,strategy: 'reset_password_email_code'},
action: 'attempt_first_factor',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
asyncverifyResetPasswordEmailCode({ code }: {code: string}): Promise<{error: unknown}>{
if(!code?.trim()){
consterr=newError('Verification code is required');
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {code,strategy: 'reset_password_email_code'},
action: 'attempt_first_factor',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
🤖 Prompt for AI Agents
In packages/clerk-js/src/core/resources/SignIn.ts around lines 540 to 553, add
input validation to immediately handle empty or all-whitespace verification
codes: trim the incoming code and if it's empty, create an Error (e.g. new
Error('verification code is required')), emit eventBus.emit('resource:error', {
resource: this.resource, error }), and return { error } without calling
__internal_basePost. Update/ add unit tests to cover both empty string and
whitespace-only inputs: assert that an error is returned, eventBus emitted with
that error, and __internal_basePost was not invoked.


async submitResetPassword({
password,
signOutOfOtherSessions = true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{ error: unknown }> {
eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { password, signOutOfOtherSessions },
action: 'reset_password',
});
} catch (err: unknown) {
eventBus.emit('resource:error', { resource: this.resource, error: err });
return { error: err };
}

return { error: null };
}
Comment on lines +555 to +574

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion

Validate password input before network call; optionally pre-check policy.

  • Ensure password is non-empty before sending the request.
  • Optionally, call the existing validatePassword (policy pre-check) to provide earlier feedback.
 async submitResetPassword({
password,
signOutOfOtherSessions = true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{ error: unknown }> {
- eventBus.emit('resource:error', { resource: this.resource, error: null });+ if (!password) {+ const err = new Error('Password is required');+ eventBus.emit('resource:error', { resource: this.resource, error: err });+ return { error: err };+ }+ eventBus.emit('resource:error', { resource: this.resource, error: null });
try {
await this.resource.__internal_basePost({
body: { password, signOutOfOtherSessions },
action: 'reset_password',
});

Consider tests for:

  • empty password
  • successful submission with default signOutOfOtherSessions
  • explicit signOutOfOtherSessions: false
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
asyncsubmitResetPassword({
password,
signOutOfOtherSessions=true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{error: unknown}>{
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {password,signOutOfOtherSessions},
action: 'reset_password',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
asyncsubmitResetPassword({
password,
signOutOfOtherSessions=true,
}: {
password: string;
signOutOfOtherSessions?: boolean;
}): Promise<{error: unknown}>{
if(!password){
consterr=newError('Password is required');
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
eventBus.emit('resource:error',{resource: this.resource,error: null});
try{
awaitthis.resource.__internal_basePost({
body: {password,signOutOfOtherSessions},
action: 'reset_password',
});
}catch(err: unknown){
eventBus.emit('resource:error',{resource: this.resource,error: err});
return{error: err};
}
return{error: null};
}
🤖 Prompt for AI Agents
In packages/clerk-js/src/core/resources/SignIn.ts around lines 555 to 574, the
submitResetPassword method currently sends the network request without
validating the password; update it to first check that password is a non-empty
string and return an immediate error if empty, and optionally invoke the
existing validatePassword (policy pre-check) before the network call to produce
early, client-side feedback; preserve existing eventBus.error emissions on
failure and ensure returned error shape stays { error: unknown }; add unit tests
for empty password, successful submission with default signOutOfOtherSessions,
and explicit signOutOfOtherSessions: false.


async create(params: {
identifier?: string;
strategy?: OAuthStrategy | 'saml' | 'enterprise_sso';
Expand Down
5 changes: 5 additions & 0 deletions packages/types/src/signIn.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -133,6 +133,11 @@ export interface SignInFutureResource {
sendCode: (params: { email: string }) => Promise<{ error: unknown }>;
verifyCode: (params: { code: string }) => Promise<{ error: unknown }>;
};
resetPasswordEmailCode: {
sendCode: () => Promise<{ error: unknown }>;
verifyCode: (params: { code: string }) => Promise<{ error: unknown }>;
submitPassword: (params: { password: string; signOutOfOtherSessions?: boolean }) => Promise<{ error: unknown }>;
};
sso: (params: {
flow?: 'auto' | 'modal';
strategy: OAuthStrategy | 'saml' | 'enterprise_sso';
Expand Down
Loading