fix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environments - #6742

Merged
tmilewski merged 3 commits into
mainfrom
tm/user-4320-rhc-coinbase
Sep 9, 2025
Merged

fix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environments#6742
tmilewski merged 3 commits into
mainfrom
tm/user-4320-rhc-coinbase

Conversation

@tmilewski

@tmilewskitmilewski commented Sep 9, 2025

Copy link
Copy Markdown
Member

Description

Ensures Base & Coinbase Wallet dependencies aren't bundled for non-RHC environments.

Note: Base now includes CB Wallet.

USER-4320

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes

    • Prevents Coinbase Wallet and Base account dependencies from being bundled in non-RHC (no-RHC/production) builds, reducing runtime issues and improving compatibility. Added additional build-time searches to detect remote-hosted Coinbase/Base usages.
  • Chores

    • Adds a patch-release changeset recording the bundling behavior change for non-RHC environments.

@tmilewskitmilewski self-assigned this Sep 9, 2025
@changeset-bot

changeset-botBot commented Sep 9, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0d7a724

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Sep 9, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentSep 9, 2025 9:23pm

@coderabbitai

coderabbitaiBot commented Sep 9, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Adds a changeset and updates build config to externalize/ignore Coinbase/Base deps when RHC is disabled or in certain prod builds; also adds new searches for Coinbase/Base in the RHC scanning script.

Changes

Cohort / File(s)Summary
Changeset
.changeset/funny-laws-fetch.md
Adds a patch changeset for @clerk/clerk-js noting Coinbase dependencies should not be bundled in non-RHC environments.
Build config (rspack)
packages/clerk-js/rspack.config.js
Extends externals when RHC is disabled to include @coinbase/wallet-sdk and @base-org/account; adds rspack.IgnorePlugin entries for those packages in no-RHC and production configs alongside existing Stripe ignores.
RHC search script
scripts/search-for-rhc.mjs
Adds three parallel search tasks: coinbase.com, an import regex for @coinbase/wallet-sdk, and an import regex for @base-org/account; integrates them into existing Promise.allSettled flow.

Sequence Diagram(s)

sequenceDiagram
participant Dev as Developer
participant Build as Rspack Build
participant Ignore as IgnorePlugin
participant Search as search-for-rhc.mjs
participant Output as Build Output Scanner
rect #E8F5E9
Dev->>Build: trigger build (disableRHC = true / prod)
Build->>Ignore: register IgnorePlugin for @coinbase/wallet-sdk & @base-org/account
Build->>Output: produce bundle (Coinbase/Base excluded)
end
rect #FFF3E0
Dev->>Search: run search-for-rhc
Search->>Output: scan for "coinbase.com"
Search->>Output: scan for import regex "@coinbase/wallet-sdk"
Search->>Output: scan for import regex "@base-org/account"
Output-->>Search: results
Search->>Dev: report findings (errors aggregated)
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Pre-merge checks (3 passed)

✅ Passed checks (3 passed)
Check nameStatusExplanation
Title Check✅ PassedThe pull request title clearly and concisely summarizes the main change by stating that Base and Coinbase dependencies will not be bundled in non-RHC environments, and it follows conventional commit style with the “fix(clerk-js)” prefix, making it specific, relevant, and easily understandable for team members scanning the history.
Description Check✅ PassedThe description directly relates to the changeset by explaining that Base and Coinbase Wallet dependencies will be excluded from non-RHC bundles, references the relevant issue, and includes a checklist for tests and documentation, so it provides context and aligns with the modifications.
Docstring Coverage✅ PassedNo functions found in the changes. Docstring coverage check skipped.

Poem

A rabbit hops through config and patch,
Nudging coinbase code out of the batch.
Builds breathe lighter, scans run anew,
Thump! A tiny change—clean and true. 🥕

Warning

Review ran into problems

🔥 Problems

Errors were encountered while retrieving linked issues.

Errors (1)
  • USER-4320: Entity not found: Issue - Could not find referenced Issue.
✨ Finishing Touches
  • 📝 Generate Docstrings
🧪 Generate unit tests
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch tm/user-4320-rhc-coinbase

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Sep 9, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@6742

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@6742

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@6742

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@6742

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@6742

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@6742

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@6742

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@6742

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@6742

@clerk/express

npm i https://pkg.pr.new/@clerk/express@6742

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@6742

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@6742

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@6742

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@6742

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@6742

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@6742

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@6742

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@6742

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@6742

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@6742

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@6742

@clerk/types

npm i https://pkg.pr.new/@clerk/types@6742

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@6742

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@6742

commit: 0d7a724

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/clerk-js/rspack.config.js (1)

621-625: Fix undefined variant key in dev config
In packages/clerk-js/rspack.config.js (lines 621–625), replace the nonexistent variants.clerkBrowserNoRHC with the defined variants.clerkNoRHC to avoid undefined keys in dev builds:

- [variants.clerkBrowserNoRHC]: merge(- entryForVariant(variants.clerkBrowserNoRHC),- common({ mode, disableRHC: true, variant: variants.clerkBrowserNoRHC }),+ [variants.clerkNoRHC]: merge(+ entryForVariant(variants.clerkNoRHC),+ common({ mode, disableRHC: true, variant: variants.clerkNoRHC }),
commonForDev(),
),
🧹 Nitpick comments (2)
.changeset/funny-laws-fetch.md (1)

1-5: Changeset looks good; add ticket reference for traceability.

Consider appending "Refs USER-4320" (or the appropriate tracker key) to the summary line so it’s linked in release notes.

-Ensure Coinbase dependencies aren't bundled for non-RHC environments+Ensure Coinbase dependencies aren't bundled for non-RHC environments (refs USER-4320)
packages/clerk-js/rspack.config.js (1)

80-84: Update the comment to reflect Coinbase too.

Stripe is mentioned but Coinbase is now treated similarly; keep comments in sync.

- * Remove the Stripe dependencies from the bundle, if RHC is disabled.- * Necessary to prevent the Stripe dependencies from being bundled into+ * Remove Stripe and Coinbase dependencies from the bundle when RHC is disabled.+ * Necessary to prevent these payment dependencies from being bundled into
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

💡 Knowledge Base configuration:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between c0a643f and 8aa5e85.

📒 Files selected for processing (2)
  • .changeset/funny-laws-fetch.md (1 hunks)
  • packages/clerk-js/rspack.config.js (2 hunks)
🧰 Additional context used
📓 Path-based instructions (4)
.changeset/**

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Automated releases must use Changesets.

Files:

  • .changeset/funny-laws-fetch.md
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/clerk-js/rspack.config.js
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (6)
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep/ci
🔇 Additional comments (1)
packages/clerk-js/rspack.config.js (1)

85-85: Switch externals to regex patterns for deep imports
Current string externals only match package roots. To ensure no @coinbase/wallet-sdk (or Stripe) subpaths slip through, use regex:

 externals: disableRHC
? [
- '@stripe/stripe-js',- '@stripe/react-stripe-js',- '@coinbase/wallet-sdk',+ /^@stripe\/stripe-js(?:\/.*)?$/,+ /^@stripe\/react-stripe-js(?:\/.*)?$/,+ /^@coinbase\/wallet-sdk(?:\/.*)?$/,
]
: undefined,

Scan the repo (and any downstream consumers) for @coinbase/wallet-sdk/ imports to confirm no deep paths remain.

Comment threadpackages/clerk-js/rspack.config.js
@tmilewskitmilewski changed the title fix(clerk-js): Ensure Coinbase dependencies aren't bundled for non-RHC environmentsfix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environmentsSep 9, 2025
@tmilewski
tmilewski enabled auto-merge (squash) September 9, 2025 21:27

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
scripts/search-for-rhc.mjs (1)

16-18: Directory search isn’t recursive; grep will miss matches.

Add -r so --include filters apply and directories are traversed.

- ? $`grep -${flag}q --include=\\*.js --include=\\*.mjs ${search} ${target}`+ ? $`grep -r -${flag}q --include=\\*.js --include=\\*.mjs ${search} ${target}`
♻️ Duplicate comments (1)
packages/clerk-js/rspack.config.js (1)

484-489: Broaden IgnorePlugin to catch deep imports (matches prior feedback).

Mirror externals by allowing optional subpaths so “@…/foo/bar” is ignored too.

 new rspack.IgnorePlugin({
- resourceRegExp: /^@coinbase\/wallet-sdk$/,+ resourceRegExp: /^@coinbase\/wallet-sdk(?:\/.*)?$/,
}),
new rspack.IgnorePlugin({
- resourceRegExp: /^@base-org\/account$/,+ resourceRegExp: /^@base-org\/account(?:\/.*)?$/,
}),
🧹 Nitpick comments (2)
scripts/search-for-rhc.mjs (1)

31-31: Consider scanning wallet subdomains too.

Add wallet.coinbase.com (and optionally walletlink) to reduce false negatives.

 asyncSearchRHC('Coinbase', 'coinbase.com'),
+ asyncSearchRHC('Coinbase Wallet domain', 'wallet.coinbase.com'),+ // (optional legacy) asyncSearchRHC('WalletLink', 'walletlink.org'),
packages/clerk-js/rspack.config.js (1)

479-490: DRY: centralize RHC module patterns and reuse for externals + IgnorePlugin.

Define a single array of RegExp patterns (e.g., RHC_MODULES) and reference it in both places to avoid drift.

Example:

// top-levelconstRHC_MODULES=[/^@stripe\/stripe-js(?:\/.*)?$/,/^@stripe\/react-stripe-js(?:\/.*)?$/,/^@coinbase\/wallet-sdk(?:\/.*)?$/,/^@base-org\/account(?:\/.*)?$/,];// usage
externals: disableRHC ? RHC_MODULES : undefined// ...
plugins: [ ...RHC_MODULES.map(rx=>newrspack.IgnorePlugin({resourceRegExp: rx})), ... ]
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

💡 Knowledge Base configuration:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 8aa5e85 and 0d7a724.

📒 Files selected for processing (3)
  • .changeset/funny-laws-fetch.md (1 hunks)
  • packages/clerk-js/rspack.config.js (2 hunks)
  • scripts/search-for-rhc.mjs (1 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • .changeset/funny-laws-fetch.md
🧰 Additional context used
📓 Path-based instructions (5)
scripts/**

📄 CodeRabbit inference engine (.cursor/rules/global.mdc)

Build automation and utility scripts should be placed under the scripts/ directory

Files:

  • scripts/search-for-rhc.mjs
scripts/**/*

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Build and automation scripts must be located in the 'scripts/' directory.

Files:

  • scripts/search-for-rhc.mjs
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/clerk-js/rspack.config.js
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep/ci
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)

Comment threadpackages/clerk-js/rspack.config.js
Comment threadscripts/search-for-rhc.mjs
Comment threadscripts/search-for-rhc.mjs
@tmilewski
tmilewski enabled auto-merge (squash) September 9, 2025 21:31
@tmilewski
tmilewski merged commit 7fe00d6 into mainSep 9, 2025
44 checks passed
@tmilewski
tmilewski deleted the tm/user-4320-rhc-coinbase branch September 9, 2025 21:32
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tmilewski@wobsoriano@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environments - #6742

Merged
tmilewski merged 3 commits into
mainfrom
tm/user-4320-rhc-coinbase
Sep 9, 2025
Merged

fix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environments#6742
tmilewski merged 3 commits into
mainfrom
tm/user-4320-rhc-coinbase

Conversation

@tmilewski

@tmilewskitmilewski commented Sep 9, 2025

Copy link
Copy Markdown
Member

Description

Ensures Base & Coinbase Wallet dependencies aren't bundled for non-RHC environments.

Note: Base now includes CB Wallet.

USER-4320

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes

    • Prevents Coinbase Wallet and Base account dependencies from being bundled in non-RHC (no-RHC/production) builds, reducing runtime issues and improving compatibility. Added additional build-time searches to detect remote-hosted Coinbase/Base usages.
  • Chores

    • Adds a patch-release changeset recording the bundling behavior change for non-RHC environments.

@tmilewskitmilewski self-assigned this Sep 9, 2025
@changeset-bot

changeset-botBot commented Sep 9, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0d7a724

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Sep 9, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentSep 9, 2025 9:23pm

@coderabbitai

coderabbitaiBot commented Sep 9, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Adds a changeset and updates build config to externalize/ignore Coinbase/Base deps when RHC is disabled or in certain prod builds; also adds new searches for Coinbase/Base in the RHC scanning script.

Changes

Cohort / File(s)Summary
Changeset
.changeset/funny-laws-fetch.md
Adds a patch changeset for @clerk/clerk-js noting Coinbase dependencies should not be bundled in non-RHC environments.
Build config (rspack)
packages/clerk-js/rspack.config.js
Extends externals when RHC is disabled to include @coinbase/wallet-sdk and @base-org/account; adds rspack.IgnorePlugin entries for those packages in no-RHC and production configs alongside existing Stripe ignores.
RHC search script
scripts/search-for-rhc.mjs
Adds three parallel search tasks: coinbase.com, an import regex for @coinbase/wallet-sdk, and an import regex for @base-org/account; integrates them into existing Promise.allSettled flow.

Sequence Diagram(s)

sequenceDiagram
participant Dev as Developer
participant Build as Rspack Build
participant Ignore as IgnorePlugin
participant Search as search-for-rhc.mjs
participant Output as Build Output Scanner
rect #E8F5E9
Dev->>Build: trigger build (disableRHC = true / prod)
Build->>Ignore: register IgnorePlugin for @coinbase/wallet-sdk & @base-org/account
Build->>Output: produce bundle (Coinbase/Base excluded)
end
rect #FFF3E0
Dev->>Search: run search-for-rhc
Search->>Output: scan for "coinbase.com"
Search->>Output: scan for import regex "@coinbase/wallet-sdk"
Search->>Output: scan for import regex "@base-org/account"
Output-->>Search: results
Search->>Dev: report findings (errors aggregated)
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Pre-merge checks (3 passed)

✅ Passed checks (3 passed)
Check nameStatusExplanation
Title Check✅ PassedThe pull request title clearly and concisely summarizes the main change by stating that Base and Coinbase dependencies will not be bundled in non-RHC environments, and it follows conventional commit style with the “fix(clerk-js)” prefix, making it specific, relevant, and easily understandable for team members scanning the history.
Description Check✅ PassedThe description directly relates to the changeset by explaining that Base and Coinbase Wallet dependencies will be excluded from non-RHC bundles, references the relevant issue, and includes a checklist for tests and documentation, so it provides context and aligns with the modifications.
Docstring Coverage✅ PassedNo functions found in the changes. Docstring coverage check skipped.

Poem

A rabbit hops through config and patch,
Nudging coinbase code out of the batch.
Builds breathe lighter, scans run anew,
Thump! A tiny change—clean and true. 🥕

Warning

Review ran into problems

🔥 Problems

Errors were encountered while retrieving linked issues.

Errors (1)
  • USER-4320: Entity not found: Issue - Could not find referenced Issue.
✨ Finishing Touches
  • 📝 Generate Docstrings
🧪 Generate unit tests
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch tm/user-4320-rhc-coinbase

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Sep 9, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@6742

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@6742

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@6742

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@6742

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@6742

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@6742

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@6742

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@6742

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@6742

@clerk/express

npm i https://pkg.pr.new/@clerk/express@6742

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@6742

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@6742

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@6742

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@6742

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@6742

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@6742

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@6742

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@6742

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@6742

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@6742

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@6742

@clerk/types

npm i https://pkg.pr.new/@clerk/types@6742

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@6742

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@6742

commit: 0d7a724

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/clerk-js/rspack.config.js (1)

621-625: Fix undefined variant key in dev config
In packages/clerk-js/rspack.config.js (lines 621–625), replace the nonexistent variants.clerkBrowserNoRHC with the defined variants.clerkNoRHC to avoid undefined keys in dev builds:

- [variants.clerkBrowserNoRHC]: merge(- entryForVariant(variants.clerkBrowserNoRHC),- common({ mode, disableRHC: true, variant: variants.clerkBrowserNoRHC }),+ [variants.clerkNoRHC]: merge(+ entryForVariant(variants.clerkNoRHC),+ common({ mode, disableRHC: true, variant: variants.clerkNoRHC }),
commonForDev(),
),
🧹 Nitpick comments (2)
.changeset/funny-laws-fetch.md (1)

1-5: Changeset looks good; add ticket reference for traceability.

Consider appending "Refs USER-4320" (or the appropriate tracker key) to the summary line so it’s linked in release notes.

-Ensure Coinbase dependencies aren't bundled for non-RHC environments+Ensure Coinbase dependencies aren't bundled for non-RHC environments (refs USER-4320)
packages/clerk-js/rspack.config.js (1)

80-84: Update the comment to reflect Coinbase too.

Stripe is mentioned but Coinbase is now treated similarly; keep comments in sync.

- * Remove the Stripe dependencies from the bundle, if RHC is disabled.- * Necessary to prevent the Stripe dependencies from being bundled into+ * Remove Stripe and Coinbase dependencies from the bundle when RHC is disabled.+ * Necessary to prevent these payment dependencies from being bundled into
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

💡 Knowledge Base configuration:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between c0a643f and 8aa5e85.

📒 Files selected for processing (2)
  • .changeset/funny-laws-fetch.md (1 hunks)
  • packages/clerk-js/rspack.config.js (2 hunks)
🧰 Additional context used
📓 Path-based instructions (4)
.changeset/**

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Automated releases must use Changesets.

Files:

  • .changeset/funny-laws-fetch.md
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/clerk-js/rspack.config.js
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (6)
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep/ci
🔇 Additional comments (1)
packages/clerk-js/rspack.config.js (1)

85-85: Switch externals to regex patterns for deep imports
Current string externals only match package roots. To ensure no @coinbase/wallet-sdk (or Stripe) subpaths slip through, use regex:

 externals: disableRHC
? [
- '@stripe/stripe-js',- '@stripe/react-stripe-js',- '@coinbase/wallet-sdk',+ /^@stripe\/stripe-js(?:\/.*)?$/,+ /^@stripe\/react-stripe-js(?:\/.*)?$/,+ /^@coinbase\/wallet-sdk(?:\/.*)?$/,
]
: undefined,

Scan the repo (and any downstream consumers) for @coinbase/wallet-sdk/ imports to confirm no deep paths remain.

Comment threadpackages/clerk-js/rspack.config.js
@tmilewskitmilewski changed the title fix(clerk-js): Ensure Coinbase dependencies aren't bundled for non-RHC environmentsfix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environmentsSep 9, 2025
@tmilewski
tmilewski enabled auto-merge (squash) September 9, 2025 21:27

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
scripts/search-for-rhc.mjs (1)

16-18: Directory search isn’t recursive; grep will miss matches.

Add -r so --include filters apply and directories are traversed.

- ? $`grep -${flag}q --include=\\*.js --include=\\*.mjs ${search} ${target}`+ ? $`grep -r -${flag}q --include=\\*.js --include=\\*.mjs ${search} ${target}`
♻️ Duplicate comments (1)
packages/clerk-js/rspack.config.js (1)

484-489: Broaden IgnorePlugin to catch deep imports (matches prior feedback).

Mirror externals by allowing optional subpaths so “@…/foo/bar” is ignored too.

 new rspack.IgnorePlugin({
- resourceRegExp: /^@coinbase\/wallet-sdk$/,+ resourceRegExp: /^@coinbase\/wallet-sdk(?:\/.*)?$/,
}),
new rspack.IgnorePlugin({
- resourceRegExp: /^@base-org\/account$/,+ resourceRegExp: /^@base-org\/account(?:\/.*)?$/,
}),
🧹 Nitpick comments (2)
scripts/search-for-rhc.mjs (1)

31-31: Consider scanning wallet subdomains too.

Add wallet.coinbase.com (and optionally walletlink) to reduce false negatives.

 asyncSearchRHC('Coinbase', 'coinbase.com'),
+ asyncSearchRHC('Coinbase Wallet domain', 'wallet.coinbase.com'),+ // (optional legacy) asyncSearchRHC('WalletLink', 'walletlink.org'),
packages/clerk-js/rspack.config.js (1)

479-490: DRY: centralize RHC module patterns and reuse for externals + IgnorePlugin.

Define a single array of RegExp patterns (e.g., RHC_MODULES) and reference it in both places to avoid drift.

Example:

// top-levelconstRHC_MODULES=[/^@stripe\/stripe-js(?:\/.*)?$/,/^@stripe\/react-stripe-js(?:\/.*)?$/,/^@coinbase\/wallet-sdk(?:\/.*)?$/,/^@base-org\/account(?:\/.*)?$/,];// usage
externals: disableRHC ? RHC_MODULES : undefined// ...
plugins: [ ...RHC_MODULES.map(rx=>newrspack.IgnorePlugin({resourceRegExp: rx})), ... ]
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

💡 Knowledge Base configuration:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 8aa5e85 and 0d7a724.

📒 Files selected for processing (3)
  • .changeset/funny-laws-fetch.md (1 hunks)
  • packages/clerk-js/rspack.config.js (2 hunks)
  • scripts/search-for-rhc.mjs (1 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • .changeset/funny-laws-fetch.md
🧰 Additional context used
📓 Path-based instructions (5)
scripts/**

📄 CodeRabbit inference engine (.cursor/rules/global.mdc)

Build automation and utility scripts should be placed under the scripts/ directory

Files:

  • scripts/search-for-rhc.mjs
scripts/**/*

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Build and automation scripts must be located in the 'scripts/' directory.

Files:

  • scripts/search-for-rhc.mjs
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/clerk-js/rspack.config.js
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep/ci
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)

Comment threadpackages/clerk-js/rspack.config.js
Comment threadscripts/search-for-rhc.mjs
Comment threadscripts/search-for-rhc.mjs
@tmilewski
tmilewski enabled auto-merge (squash) September 9, 2025 21:31
@tmilewski
tmilewski merged commit 7fe00d6 into mainSep 9, 2025
44 checks passed
@tmilewski
tmilewski deleted the tm/user-4320-rhc-coinbase branch September 9, 2025 21:32
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tmilewski@wobsoriano@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environments - #6742

Merged
tmilewski merged 3 commits into
mainfrom
tm/user-4320-rhc-coinbase
Sep 9, 2025
Merged

fix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environments#6742
tmilewski merged 3 commits into
mainfrom
tm/user-4320-rhc-coinbase

Conversation

@tmilewski

@tmilewskitmilewski commented Sep 9, 2025

Copy link
Copy Markdown
Member

Description

Ensures Base & Coinbase Wallet dependencies aren't bundled for non-RHC environments.

Note: Base now includes CB Wallet.

USER-4320

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes

    • Prevents Coinbase Wallet and Base account dependencies from being bundled in non-RHC (no-RHC/production) builds, reducing runtime issues and improving compatibility. Added additional build-time searches to detect remote-hosted Coinbase/Base usages.
  • Chores

    • Adds a patch-release changeset recording the bundling behavior change for non-RHC environments.

@tmilewskitmilewski self-assigned this Sep 9, 2025
@changeset-bot

changeset-botBot commented Sep 9, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0d7a724

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Sep 9, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentSep 9, 2025 9:23pm

@coderabbitai

coderabbitaiBot commented Sep 9, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Adds a changeset and updates build config to externalize/ignore Coinbase/Base deps when RHC is disabled or in certain prod builds; also adds new searches for Coinbase/Base in the RHC scanning script.

Changes

Cohort / File(s)Summary
Changeset
.changeset/funny-laws-fetch.md
Adds a patch changeset for @clerk/clerk-js noting Coinbase dependencies should not be bundled in non-RHC environments.
Build config (rspack)
packages/clerk-js/rspack.config.js
Extends externals when RHC is disabled to include @coinbase/wallet-sdk and @base-org/account; adds rspack.IgnorePlugin entries for those packages in no-RHC and production configs alongside existing Stripe ignores.
RHC search script
scripts/search-for-rhc.mjs
Adds three parallel search tasks: coinbase.com, an import regex for @coinbase/wallet-sdk, and an import regex for @base-org/account; integrates them into existing Promise.allSettled flow.

Sequence Diagram(s)

sequenceDiagram
participant Dev as Developer
participant Build as Rspack Build
participant Ignore as IgnorePlugin
participant Search as search-for-rhc.mjs
participant Output as Build Output Scanner
rect #E8F5E9
Dev->>Build: trigger build (disableRHC = true / prod)
Build->>Ignore: register IgnorePlugin for @coinbase/wallet-sdk & @base-org/account
Build->>Output: produce bundle (Coinbase/Base excluded)
end
rect #FFF3E0
Dev->>Search: run search-for-rhc
Search->>Output: scan for "coinbase.com"
Search->>Output: scan for import regex "@coinbase/wallet-sdk"
Search->>Output: scan for import regex "@base-org/account"
Output-->>Search: results
Search->>Dev: report findings (errors aggregated)
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Pre-merge checks (3 passed)

✅ Passed checks (3 passed)
Check nameStatusExplanation
Title Check✅ PassedThe pull request title clearly and concisely summarizes the main change by stating that Base and Coinbase dependencies will not be bundled in non-RHC environments, and it follows conventional commit style with the “fix(clerk-js)” prefix, making it specific, relevant, and easily understandable for team members scanning the history.
Description Check✅ PassedThe description directly relates to the changeset by explaining that Base and Coinbase Wallet dependencies will be excluded from non-RHC bundles, references the relevant issue, and includes a checklist for tests and documentation, so it provides context and aligns with the modifications.
Docstring Coverage✅ PassedNo functions found in the changes. Docstring coverage check skipped.

Poem

A rabbit hops through config and patch,
Nudging coinbase code out of the batch.
Builds breathe lighter, scans run anew,
Thump! A tiny change—clean and true. 🥕

Warning

Review ran into problems

🔥 Problems

Errors were encountered while retrieving linked issues.

Errors (1)
  • USER-4320: Entity not found: Issue - Could not find referenced Issue.
✨ Finishing Touches
  • 📝 Generate Docstrings
🧪 Generate unit tests
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch tm/user-4320-rhc-coinbase

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Sep 9, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@6742

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@6742

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@6742

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@6742

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@6742

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@6742

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@6742

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@6742

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@6742

@clerk/express

npm i https://pkg.pr.new/@clerk/express@6742

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@6742

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@6742

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@6742

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@6742

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@6742

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@6742

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@6742

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@6742

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@6742

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@6742

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@6742

@clerk/types

npm i https://pkg.pr.new/@clerk/types@6742

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@6742

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@6742

commit: 0d7a724

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/clerk-js/rspack.config.js (1)

621-625: Fix undefined variant key in dev config
In packages/clerk-js/rspack.config.js (lines 621–625), replace the nonexistent variants.clerkBrowserNoRHC with the defined variants.clerkNoRHC to avoid undefined keys in dev builds:

- [variants.clerkBrowserNoRHC]: merge(- entryForVariant(variants.clerkBrowserNoRHC),- common({ mode, disableRHC: true, variant: variants.clerkBrowserNoRHC }),+ [variants.clerkNoRHC]: merge(+ entryForVariant(variants.clerkNoRHC),+ common({ mode, disableRHC: true, variant: variants.clerkNoRHC }),
commonForDev(),
),
🧹 Nitpick comments (2)
.changeset/funny-laws-fetch.md (1)

1-5: Changeset looks good; add ticket reference for traceability.

Consider appending "Refs USER-4320" (or the appropriate tracker key) to the summary line so it’s linked in release notes.

-Ensure Coinbase dependencies aren't bundled for non-RHC environments+Ensure Coinbase dependencies aren't bundled for non-RHC environments (refs USER-4320)
packages/clerk-js/rspack.config.js (1)

80-84: Update the comment to reflect Coinbase too.

Stripe is mentioned but Coinbase is now treated similarly; keep comments in sync.

- * Remove the Stripe dependencies from the bundle, if RHC is disabled.- * Necessary to prevent the Stripe dependencies from being bundled into+ * Remove Stripe and Coinbase dependencies from the bundle when RHC is disabled.+ * Necessary to prevent these payment dependencies from being bundled into
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

💡 Knowledge Base configuration:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between c0a643f and 8aa5e85.

📒 Files selected for processing (2)
  • .changeset/funny-laws-fetch.md (1 hunks)
  • packages/clerk-js/rspack.config.js (2 hunks)
🧰 Additional context used
📓 Path-based instructions (4)
.changeset/**

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Automated releases must use Changesets.

Files:

  • .changeset/funny-laws-fetch.md
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/clerk-js/rspack.config.js
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (6)
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep/ci
🔇 Additional comments (1)
packages/clerk-js/rspack.config.js (1)

85-85: Switch externals to regex patterns for deep imports
Current string externals only match package roots. To ensure no @coinbase/wallet-sdk (or Stripe) subpaths slip through, use regex:

 externals: disableRHC
? [
- '@stripe/stripe-js',- '@stripe/react-stripe-js',- '@coinbase/wallet-sdk',+ /^@stripe\/stripe-js(?:\/.*)?$/,+ /^@stripe\/react-stripe-js(?:\/.*)?$/,+ /^@coinbase\/wallet-sdk(?:\/.*)?$/,
]
: undefined,

Scan the repo (and any downstream consumers) for @coinbase/wallet-sdk/ imports to confirm no deep paths remain.

Comment threadpackages/clerk-js/rspack.config.js
@tmilewskitmilewski changed the title fix(clerk-js): Ensure Coinbase dependencies aren't bundled for non-RHC environmentsfix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environmentsSep 9, 2025
@tmilewski
tmilewski enabled auto-merge (squash) September 9, 2025 21:27

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
scripts/search-for-rhc.mjs (1)

16-18: Directory search isn’t recursive; grep will miss matches.

Add -r so --include filters apply and directories are traversed.

- ? $`grep -${flag}q --include=\\*.js --include=\\*.mjs ${search} ${target}`+ ? $`grep -r -${flag}q --include=\\*.js --include=\\*.mjs ${search} ${target}`
♻️ Duplicate comments (1)
packages/clerk-js/rspack.config.js (1)

484-489: Broaden IgnorePlugin to catch deep imports (matches prior feedback).

Mirror externals by allowing optional subpaths so “@…/foo/bar” is ignored too.

 new rspack.IgnorePlugin({
- resourceRegExp: /^@coinbase\/wallet-sdk$/,+ resourceRegExp: /^@coinbase\/wallet-sdk(?:\/.*)?$/,
}),
new rspack.IgnorePlugin({
- resourceRegExp: /^@base-org\/account$/,+ resourceRegExp: /^@base-org\/account(?:\/.*)?$/,
}),
🧹 Nitpick comments (2)
scripts/search-for-rhc.mjs (1)

31-31: Consider scanning wallet subdomains too.

Add wallet.coinbase.com (and optionally walletlink) to reduce false negatives.

 asyncSearchRHC('Coinbase', 'coinbase.com'),
+ asyncSearchRHC('Coinbase Wallet domain', 'wallet.coinbase.com'),+ // (optional legacy) asyncSearchRHC('WalletLink', 'walletlink.org'),
packages/clerk-js/rspack.config.js (1)

479-490: DRY: centralize RHC module patterns and reuse for externals + IgnorePlugin.

Define a single array of RegExp patterns (e.g., RHC_MODULES) and reference it in both places to avoid drift.

Example:

// top-levelconstRHC_MODULES=[/^@stripe\/stripe-js(?:\/.*)?$/,/^@stripe\/react-stripe-js(?:\/.*)?$/,/^@coinbase\/wallet-sdk(?:\/.*)?$/,/^@base-org\/account(?:\/.*)?$/,];// usage
externals: disableRHC ? RHC_MODULES : undefined// ...
plugins: [ ...RHC_MODULES.map(rx=>newrspack.IgnorePlugin({resourceRegExp: rx})), ... ]
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

💡 Knowledge Base configuration:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 8aa5e85 and 0d7a724.

📒 Files selected for processing (3)
  • .changeset/funny-laws-fetch.md (1 hunks)
  • packages/clerk-js/rspack.config.js (2 hunks)
  • scripts/search-for-rhc.mjs (1 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • .changeset/funny-laws-fetch.md
🧰 Additional context used
📓 Path-based instructions (5)
scripts/**

📄 CodeRabbit inference engine (.cursor/rules/global.mdc)

Build automation and utility scripts should be placed under the scripts/ directory

Files:

  • scripts/search-for-rhc.mjs
scripts/**/*

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Build and automation scripts must be located in the 'scripts/' directory.

Files:

  • scripts/search-for-rhc.mjs
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/clerk-js/rspack.config.js
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep/ci
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)

Comment threadpackages/clerk-js/rspack.config.js
Comment threadscripts/search-for-rhc.mjs
Comment threadscripts/search-for-rhc.mjs
@tmilewski
tmilewski enabled auto-merge (squash) September 9, 2025 21:31
@tmilewski
tmilewski merged commit 7fe00d6 into mainSep 9, 2025
44 checks passed
@tmilewski
tmilewski deleted the tm/user-4320-rhc-coinbase branch September 9, 2025 21:32
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tmilewski@wobsoriano@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environments - #6742

Merged
tmilewski merged 3 commits into
mainfrom
tm/user-4320-rhc-coinbase
Sep 9, 2025
Merged

fix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environments#6742
tmilewski merged 3 commits into
mainfrom
tm/user-4320-rhc-coinbase

Conversation

@tmilewski

@tmilewskitmilewski commented Sep 9, 2025

Copy link
Copy Markdown
Member

Description

Ensures Base & Coinbase Wallet dependencies aren't bundled for non-RHC environments.

Note: Base now includes CB Wallet.

USER-4320

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes

    • Prevents Coinbase Wallet and Base account dependencies from being bundled in non-RHC (no-RHC/production) builds, reducing runtime issues and improving compatibility. Added additional build-time searches to detect remote-hosted Coinbase/Base usages.
  • Chores

    • Adds a patch-release changeset recording the bundling behavior change for non-RHC environments.

@tmilewskitmilewski self-assigned this Sep 9, 2025
@changeset-bot

changeset-botBot commented Sep 9, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0d7a724

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Sep 9, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentSep 9, 2025 9:23pm

@coderabbitai

coderabbitaiBot commented Sep 9, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Adds a changeset and updates build config to externalize/ignore Coinbase/Base deps when RHC is disabled or in certain prod builds; also adds new searches for Coinbase/Base in the RHC scanning script.

Changes

Cohort / File(s)Summary
Changeset
.changeset/funny-laws-fetch.md
Adds a patch changeset for @clerk/clerk-js noting Coinbase dependencies should not be bundled in non-RHC environments.
Build config (rspack)
packages/clerk-js/rspack.config.js
Extends externals when RHC is disabled to include @coinbase/wallet-sdk and @base-org/account; adds rspack.IgnorePlugin entries for those packages in no-RHC and production configs alongside existing Stripe ignores.
RHC search script
scripts/search-for-rhc.mjs
Adds three parallel search tasks: coinbase.com, an import regex for @coinbase/wallet-sdk, and an import regex for @base-org/account; integrates them into existing Promise.allSettled flow.

Sequence Diagram(s)

sequenceDiagram
participant Dev as Developer
participant Build as Rspack Build
participant Ignore as IgnorePlugin
participant Search as search-for-rhc.mjs
participant Output as Build Output Scanner
rect #E8F5E9
Dev->>Build: trigger build (disableRHC = true / prod)
Build->>Ignore: register IgnorePlugin for @coinbase/wallet-sdk & @base-org/account
Build->>Output: produce bundle (Coinbase/Base excluded)
end
rect #FFF3E0
Dev->>Search: run search-for-rhc
Search->>Output: scan for "coinbase.com"
Search->>Output: scan for import regex "@coinbase/wallet-sdk"
Search->>Output: scan for import regex "@base-org/account"
Output-->>Search: results
Search->>Dev: report findings (errors aggregated)
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Pre-merge checks (3 passed)

✅ Passed checks (3 passed)
Check nameStatusExplanation
Title Check✅ PassedThe pull request title clearly and concisely summarizes the main change by stating that Base and Coinbase dependencies will not be bundled in non-RHC environments, and it follows conventional commit style with the “fix(clerk-js)” prefix, making it specific, relevant, and easily understandable for team members scanning the history.
Description Check✅ PassedThe description directly relates to the changeset by explaining that Base and Coinbase Wallet dependencies will be excluded from non-RHC bundles, references the relevant issue, and includes a checklist for tests and documentation, so it provides context and aligns with the modifications.
Docstring Coverage✅ PassedNo functions found in the changes. Docstring coverage check skipped.

Poem

A rabbit hops through config and patch,
Nudging coinbase code out of the batch.
Builds breathe lighter, scans run anew,
Thump! A tiny change—clean and true. 🥕

Warning

Review ran into problems

🔥 Problems

Errors were encountered while retrieving linked issues.

Errors (1)
  • USER-4320: Entity not found: Issue - Could not find referenced Issue.
✨ Finishing Touches
  • 📝 Generate Docstrings
🧪 Generate unit tests
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch tm/user-4320-rhc-coinbase

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Sep 9, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@6742

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@6742

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@6742

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@6742

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@6742

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@6742

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@6742

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@6742

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@6742

@clerk/express

npm i https://pkg.pr.new/@clerk/express@6742

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@6742

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@6742

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@6742

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@6742

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@6742

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@6742

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@6742

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@6742

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@6742

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@6742

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@6742

@clerk/types

npm i https://pkg.pr.new/@clerk/types@6742

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@6742

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@6742

commit: 0d7a724

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/clerk-js/rspack.config.js (1)

621-625: Fix undefined variant key in dev config
In packages/clerk-js/rspack.config.js (lines 621–625), replace the nonexistent variants.clerkBrowserNoRHC with the defined variants.clerkNoRHC to avoid undefined keys in dev builds:

- [variants.clerkBrowserNoRHC]: merge(- entryForVariant(variants.clerkBrowserNoRHC),- common({ mode, disableRHC: true, variant: variants.clerkBrowserNoRHC }),+ [variants.clerkNoRHC]: merge(+ entryForVariant(variants.clerkNoRHC),+ common({ mode, disableRHC: true, variant: variants.clerkNoRHC }),
commonForDev(),
),
🧹 Nitpick comments (2)
.changeset/funny-laws-fetch.md (1)

1-5: Changeset looks good; add ticket reference for traceability.

Consider appending "Refs USER-4320" (or the appropriate tracker key) to the summary line so it’s linked in release notes.

-Ensure Coinbase dependencies aren't bundled for non-RHC environments+Ensure Coinbase dependencies aren't bundled for non-RHC environments (refs USER-4320)
packages/clerk-js/rspack.config.js (1)

80-84: Update the comment to reflect Coinbase too.

Stripe is mentioned but Coinbase is now treated similarly; keep comments in sync.

- * Remove the Stripe dependencies from the bundle, if RHC is disabled.- * Necessary to prevent the Stripe dependencies from being bundled into+ * Remove Stripe and Coinbase dependencies from the bundle when RHC is disabled.+ * Necessary to prevent these payment dependencies from being bundled into
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

💡 Knowledge Base configuration:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between c0a643f and 8aa5e85.

📒 Files selected for processing (2)
  • .changeset/funny-laws-fetch.md (1 hunks)
  • packages/clerk-js/rspack.config.js (2 hunks)
🧰 Additional context used
📓 Path-based instructions (4)
.changeset/**

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Automated releases must use Changesets.

Files:

  • .changeset/funny-laws-fetch.md
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/clerk-js/rspack.config.js
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (6)
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep/ci
🔇 Additional comments (1)
packages/clerk-js/rspack.config.js (1)

85-85: Switch externals to regex patterns for deep imports
Current string externals only match package roots. To ensure no @coinbase/wallet-sdk (or Stripe) subpaths slip through, use regex:

 externals: disableRHC
? [
- '@stripe/stripe-js',- '@stripe/react-stripe-js',- '@coinbase/wallet-sdk',+ /^@stripe\/stripe-js(?:\/.*)?$/,+ /^@stripe\/react-stripe-js(?:\/.*)?$/,+ /^@coinbase\/wallet-sdk(?:\/.*)?$/,
]
: undefined,

Scan the repo (and any downstream consumers) for @coinbase/wallet-sdk/ imports to confirm no deep paths remain.

Comment threadpackages/clerk-js/rspack.config.js
@tmilewskitmilewski changed the title fix(clerk-js): Ensure Coinbase dependencies aren't bundled for non-RHC environmentsfix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environmentsSep 9, 2025
@tmilewski
tmilewski enabled auto-merge (squash) September 9, 2025 21:27

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
scripts/search-for-rhc.mjs (1)

16-18: Directory search isn’t recursive; grep will miss matches.

Add -r so --include filters apply and directories are traversed.

- ? $`grep -${flag}q --include=\\*.js --include=\\*.mjs ${search} ${target}`+ ? $`grep -r -${flag}q --include=\\*.js --include=\\*.mjs ${search} ${target}`
♻️ Duplicate comments (1)
packages/clerk-js/rspack.config.js (1)

484-489: Broaden IgnorePlugin to catch deep imports (matches prior feedback).

Mirror externals by allowing optional subpaths so “@…/foo/bar” is ignored too.

 new rspack.IgnorePlugin({
- resourceRegExp: /^@coinbase\/wallet-sdk$/,+ resourceRegExp: /^@coinbase\/wallet-sdk(?:\/.*)?$/,
}),
new rspack.IgnorePlugin({
- resourceRegExp: /^@base-org\/account$/,+ resourceRegExp: /^@base-org\/account(?:\/.*)?$/,
}),
🧹 Nitpick comments (2)
scripts/search-for-rhc.mjs (1)

31-31: Consider scanning wallet subdomains too.

Add wallet.coinbase.com (and optionally walletlink) to reduce false negatives.

 asyncSearchRHC('Coinbase', 'coinbase.com'),
+ asyncSearchRHC('Coinbase Wallet domain', 'wallet.coinbase.com'),+ // (optional legacy) asyncSearchRHC('WalletLink', 'walletlink.org'),
packages/clerk-js/rspack.config.js (1)

479-490: DRY: centralize RHC module patterns and reuse for externals + IgnorePlugin.

Define a single array of RegExp patterns (e.g., RHC_MODULES) and reference it in both places to avoid drift.

Example:

// top-levelconstRHC_MODULES=[/^@stripe\/stripe-js(?:\/.*)?$/,/^@stripe\/react-stripe-js(?:\/.*)?$/,/^@coinbase\/wallet-sdk(?:\/.*)?$/,/^@base-org\/account(?:\/.*)?$/,];// usage
externals: disableRHC ? RHC_MODULES : undefined// ...
plugins: [ ...RHC_MODULES.map(rx=>newrspack.IgnorePlugin({resourceRegExp: rx})), ... ]
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

💡 Knowledge Base configuration:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 8aa5e85 and 0d7a724.

📒 Files selected for processing (3)
  • .changeset/funny-laws-fetch.md (1 hunks)
  • packages/clerk-js/rspack.config.js (2 hunks)
  • scripts/search-for-rhc.mjs (1 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • .changeset/funny-laws-fetch.md
🧰 Additional context used
📓 Path-based instructions (5)
scripts/**

📄 CodeRabbit inference engine (.cursor/rules/global.mdc)

Build automation and utility scripts should be placed under the scripts/ directory

Files:

  • scripts/search-for-rhc.mjs
scripts/**/*

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Build and automation scripts must be located in the 'scripts/' directory.

Files:

  • scripts/search-for-rhc.mjs
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/clerk-js/rspack.config.js
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep/ci
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)

Comment threadpackages/clerk-js/rspack.config.js
Comment threadscripts/search-for-rhc.mjs
Comment threadscripts/search-for-rhc.mjs
@tmilewski
tmilewski enabled auto-merge (squash) September 9, 2025 21:31
@tmilewski
tmilewski merged commit 7fe00d6 into mainSep 9, 2025
44 checks passed
@tmilewski
tmilewski deleted the tm/user-4320-rhc-coinbase branch September 9, 2025 21:32
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tmilewski@wobsoriano@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environments - #6742

Merged
tmilewski merged 3 commits into
mainfrom
tm/user-4320-rhc-coinbase
Sep 9, 2025
Merged

fix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environments#6742
tmilewski merged 3 commits into
mainfrom
tm/user-4320-rhc-coinbase

Conversation

@tmilewski

@tmilewskitmilewski commented Sep 9, 2025

Copy link
Copy Markdown
Member

Description

Ensures Base & Coinbase Wallet dependencies aren't bundled for non-RHC environments.

Note: Base now includes CB Wallet.

USER-4320

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes

    • Prevents Coinbase Wallet and Base account dependencies from being bundled in non-RHC (no-RHC/production) builds, reducing runtime issues and improving compatibility. Added additional build-time searches to detect remote-hosted Coinbase/Base usages.
  • Chores

    • Adds a patch-release changeset recording the bundling behavior change for non-RHC environments.

@tmilewskitmilewski self-assigned this Sep 9, 2025
@changeset-bot

changeset-botBot commented Sep 9, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0d7a724

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Sep 9, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentSep 9, 2025 9:23pm

@coderabbitai

coderabbitaiBot commented Sep 9, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Adds a changeset and updates build config to externalize/ignore Coinbase/Base deps when RHC is disabled or in certain prod builds; also adds new searches for Coinbase/Base in the RHC scanning script.

Changes

Cohort / File(s)Summary
Changeset
.changeset/funny-laws-fetch.md
Adds a patch changeset for @clerk/clerk-js noting Coinbase dependencies should not be bundled in non-RHC environments.
Build config (rspack)
packages/clerk-js/rspack.config.js
Extends externals when RHC is disabled to include @coinbase/wallet-sdk and @base-org/account; adds rspack.IgnorePlugin entries for those packages in no-RHC and production configs alongside existing Stripe ignores.
RHC search script
scripts/search-for-rhc.mjs
Adds three parallel search tasks: coinbase.com, an import regex for @coinbase/wallet-sdk, and an import regex for @base-org/account; integrates them into existing Promise.allSettled flow.

Sequence Diagram(s)

sequenceDiagram
participant Dev as Developer
participant Build as Rspack Build
participant Ignore as IgnorePlugin
participant Search as search-for-rhc.mjs
participant Output as Build Output Scanner
rect #E8F5E9
Dev->>Build: trigger build (disableRHC = true / prod)
Build->>Ignore: register IgnorePlugin for @coinbase/wallet-sdk & @base-org/account
Build->>Output: produce bundle (Coinbase/Base excluded)
end
rect #FFF3E0
Dev->>Search: run search-for-rhc
Search->>Output: scan for "coinbase.com"
Search->>Output: scan for import regex "@coinbase/wallet-sdk"
Search->>Output: scan for import regex "@base-org/account"
Output-->>Search: results
Search->>Dev: report findings (errors aggregated)
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Pre-merge checks (3 passed)

✅ Passed checks (3 passed)
Check nameStatusExplanation
Title Check✅ PassedThe pull request title clearly and concisely summarizes the main change by stating that Base and Coinbase dependencies will not be bundled in non-RHC environments, and it follows conventional commit style with the “fix(clerk-js)” prefix, making it specific, relevant, and easily understandable for team members scanning the history.
Description Check✅ PassedThe description directly relates to the changeset by explaining that Base and Coinbase Wallet dependencies will be excluded from non-RHC bundles, references the relevant issue, and includes a checklist for tests and documentation, so it provides context and aligns with the modifications.
Docstring Coverage✅ PassedNo functions found in the changes. Docstring coverage check skipped.

Poem

A rabbit hops through config and patch,
Nudging coinbase code out of the batch.
Builds breathe lighter, scans run anew,
Thump! A tiny change—clean and true. 🥕

Warning

Review ran into problems

🔥 Problems

Errors were encountered while retrieving linked issues.

Errors (1)
  • USER-4320: Entity not found: Issue - Could not find referenced Issue.
✨ Finishing Touches
  • 📝 Generate Docstrings
🧪 Generate unit tests
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch tm/user-4320-rhc-coinbase

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Sep 9, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@6742

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@6742

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@6742

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@6742

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@6742

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@6742

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@6742

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@6742

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@6742

@clerk/express

npm i https://pkg.pr.new/@clerk/express@6742

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@6742

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@6742

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@6742

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@6742

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@6742

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@6742

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@6742

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@6742

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@6742

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@6742

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@6742

@clerk/types

npm i https://pkg.pr.new/@clerk/types@6742

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@6742

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@6742

commit: 0d7a724

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/clerk-js/rspack.config.js (1)

621-625: Fix undefined variant key in dev config
In packages/clerk-js/rspack.config.js (lines 621–625), replace the nonexistent variants.clerkBrowserNoRHC with the defined variants.clerkNoRHC to avoid undefined keys in dev builds:

- [variants.clerkBrowserNoRHC]: merge(- entryForVariant(variants.clerkBrowserNoRHC),- common({ mode, disableRHC: true, variant: variants.clerkBrowserNoRHC }),+ [variants.clerkNoRHC]: merge(+ entryForVariant(variants.clerkNoRHC),+ common({ mode, disableRHC: true, variant: variants.clerkNoRHC }),
commonForDev(),
),
🧹 Nitpick comments (2)
.changeset/funny-laws-fetch.md (1)

1-5: Changeset looks good; add ticket reference for traceability.

Consider appending "Refs USER-4320" (or the appropriate tracker key) to the summary line so it’s linked in release notes.

-Ensure Coinbase dependencies aren't bundled for non-RHC environments+Ensure Coinbase dependencies aren't bundled for non-RHC environments (refs USER-4320)
packages/clerk-js/rspack.config.js (1)

80-84: Update the comment to reflect Coinbase too.

Stripe is mentioned but Coinbase is now treated similarly; keep comments in sync.

- * Remove the Stripe dependencies from the bundle, if RHC is disabled.- * Necessary to prevent the Stripe dependencies from being bundled into+ * Remove Stripe and Coinbase dependencies from the bundle when RHC is disabled.+ * Necessary to prevent these payment dependencies from being bundled into
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

💡 Knowledge Base configuration:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between c0a643f and 8aa5e85.

📒 Files selected for processing (2)
  • .changeset/funny-laws-fetch.md (1 hunks)
  • packages/clerk-js/rspack.config.js (2 hunks)
🧰 Additional context used
📓 Path-based instructions (4)
.changeset/**

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Automated releases must use Changesets.

Files:

  • .changeset/funny-laws-fetch.md
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/clerk-js/rspack.config.js
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (6)
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep/ci
🔇 Additional comments (1)
packages/clerk-js/rspack.config.js (1)

85-85: Switch externals to regex patterns for deep imports
Current string externals only match package roots. To ensure no @coinbase/wallet-sdk (or Stripe) subpaths slip through, use regex:

 externals: disableRHC
? [
- '@stripe/stripe-js',- '@stripe/react-stripe-js',- '@coinbase/wallet-sdk',+ /^@stripe\/stripe-js(?:\/.*)?$/,+ /^@stripe\/react-stripe-js(?:\/.*)?$/,+ /^@coinbase\/wallet-sdk(?:\/.*)?$/,
]
: undefined,

Scan the repo (and any downstream consumers) for @coinbase/wallet-sdk/ imports to confirm no deep paths remain.

Comment threadpackages/clerk-js/rspack.config.js
@tmilewskitmilewski changed the title fix(clerk-js): Ensure Coinbase dependencies aren't bundled for non-RHC environmentsfix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environmentsSep 9, 2025
@tmilewski
tmilewski enabled auto-merge (squash) September 9, 2025 21:27

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
scripts/search-for-rhc.mjs (1)

16-18: Directory search isn’t recursive; grep will miss matches.

Add -r so --include filters apply and directories are traversed.

- ? $`grep -${flag}q --include=\\*.js --include=\\*.mjs ${search} ${target}`+ ? $`grep -r -${flag}q --include=\\*.js --include=\\*.mjs ${search} ${target}`
♻️ Duplicate comments (1)
packages/clerk-js/rspack.config.js (1)

484-489: Broaden IgnorePlugin to catch deep imports (matches prior feedback).

Mirror externals by allowing optional subpaths so “@…/foo/bar” is ignored too.

 new rspack.IgnorePlugin({
- resourceRegExp: /^@coinbase\/wallet-sdk$/,+ resourceRegExp: /^@coinbase\/wallet-sdk(?:\/.*)?$/,
}),
new rspack.IgnorePlugin({
- resourceRegExp: /^@base-org\/account$/,+ resourceRegExp: /^@base-org\/account(?:\/.*)?$/,
}),
🧹 Nitpick comments (2)
scripts/search-for-rhc.mjs (1)

31-31: Consider scanning wallet subdomains too.

Add wallet.coinbase.com (and optionally walletlink) to reduce false negatives.

 asyncSearchRHC('Coinbase', 'coinbase.com'),
+ asyncSearchRHC('Coinbase Wallet domain', 'wallet.coinbase.com'),+ // (optional legacy) asyncSearchRHC('WalletLink', 'walletlink.org'),
packages/clerk-js/rspack.config.js (1)

479-490: DRY: centralize RHC module patterns and reuse for externals + IgnorePlugin.

Define a single array of RegExp patterns (e.g., RHC_MODULES) and reference it in both places to avoid drift.

Example:

// top-levelconstRHC_MODULES=[/^@stripe\/stripe-js(?:\/.*)?$/,/^@stripe\/react-stripe-js(?:\/.*)?$/,/^@coinbase\/wallet-sdk(?:\/.*)?$/,/^@base-org\/account(?:\/.*)?$/,];// usage
externals: disableRHC ? RHC_MODULES : undefined// ...
plugins: [ ...RHC_MODULES.map(rx=>newrspack.IgnorePlugin({resourceRegExp: rx})), ... ]
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

💡 Knowledge Base configuration:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 8aa5e85 and 0d7a724.

📒 Files selected for processing (3)
  • .changeset/funny-laws-fetch.md (1 hunks)
  • packages/clerk-js/rspack.config.js (2 hunks)
  • scripts/search-for-rhc.mjs (1 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • .changeset/funny-laws-fetch.md
🧰 Additional context used
📓 Path-based instructions (5)
scripts/**

📄 CodeRabbit inference engine (.cursor/rules/global.mdc)

Build automation and utility scripts should be placed under the scripts/ directory

Files:

  • scripts/search-for-rhc.mjs
scripts/**/*

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Build and automation scripts must be located in the 'scripts/' directory.

Files:

  • scripts/search-for-rhc.mjs
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/clerk-js/rspack.config.js
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep/ci
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)

Comment threadpackages/clerk-js/rspack.config.js
Comment threadscripts/search-for-rhc.mjs
Comment threadscripts/search-for-rhc.mjs
@tmilewski
tmilewski enabled auto-merge (squash) September 9, 2025 21:31
@tmilewski
tmilewski merged commit 7fe00d6 into mainSep 9, 2025
44 checks passed
@tmilewski
tmilewski deleted the tm/user-4320-rhc-coinbase branch September 9, 2025 21:32
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tmilewski@wobsoriano@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environments - #6742

Merged
tmilewski merged 3 commits into
mainfrom
tm/user-4320-rhc-coinbase
Sep 9, 2025
Merged

fix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environments#6742
tmilewski merged 3 commits into
mainfrom
tm/user-4320-rhc-coinbase

Conversation

@tmilewski

@tmilewskitmilewski commented Sep 9, 2025

Copy link
Copy Markdown
Member

Description

Ensures Base & Coinbase Wallet dependencies aren't bundled for non-RHC environments.

Note: Base now includes CB Wallet.

USER-4320

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes

    • Prevents Coinbase Wallet and Base account dependencies from being bundled in non-RHC (no-RHC/production) builds, reducing runtime issues and improving compatibility. Added additional build-time searches to detect remote-hosted Coinbase/Base usages.
  • Chores

    • Adds a patch-release changeset recording the bundling behavior change for non-RHC environments.

@tmilewskitmilewski self-assigned this Sep 9, 2025
@changeset-bot

changeset-botBot commented Sep 9, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0d7a724

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Sep 9, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentSep 9, 2025 9:23pm

@coderabbitai

coderabbitaiBot commented Sep 9, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Adds a changeset and updates build config to externalize/ignore Coinbase/Base deps when RHC is disabled or in certain prod builds; also adds new searches for Coinbase/Base in the RHC scanning script.

Changes

Cohort / File(s)Summary
Changeset
.changeset/funny-laws-fetch.md
Adds a patch changeset for @clerk/clerk-js noting Coinbase dependencies should not be bundled in non-RHC environments.
Build config (rspack)
packages/clerk-js/rspack.config.js
Extends externals when RHC is disabled to include @coinbase/wallet-sdk and @base-org/account; adds rspack.IgnorePlugin entries for those packages in no-RHC and production configs alongside existing Stripe ignores.
RHC search script
scripts/search-for-rhc.mjs
Adds three parallel search tasks: coinbase.com, an import regex for @coinbase/wallet-sdk, and an import regex for @base-org/account; integrates them into existing Promise.allSettled flow.

Sequence Diagram(s)

sequenceDiagram
participant Dev as Developer
participant Build as Rspack Build
participant Ignore as IgnorePlugin
participant Search as search-for-rhc.mjs
participant Output as Build Output Scanner
rect #E8F5E9
Dev->>Build: trigger build (disableRHC = true / prod)
Build->>Ignore: register IgnorePlugin for @coinbase/wallet-sdk & @base-org/account
Build->>Output: produce bundle (Coinbase/Base excluded)
end
rect #FFF3E0
Dev->>Search: run search-for-rhc
Search->>Output: scan for "coinbase.com"
Search->>Output: scan for import regex "@coinbase/wallet-sdk"
Search->>Output: scan for import regex "@base-org/account"
Output-->>Search: results
Search->>Dev: report findings (errors aggregated)
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Pre-merge checks (3 passed)

✅ Passed checks (3 passed)
Check nameStatusExplanation
Title Check✅ PassedThe pull request title clearly and concisely summarizes the main change by stating that Base and Coinbase dependencies will not be bundled in non-RHC environments, and it follows conventional commit style with the “fix(clerk-js)” prefix, making it specific, relevant, and easily understandable for team members scanning the history.
Description Check✅ PassedThe description directly relates to the changeset by explaining that Base and Coinbase Wallet dependencies will be excluded from non-RHC bundles, references the relevant issue, and includes a checklist for tests and documentation, so it provides context and aligns with the modifications.
Docstring Coverage✅ PassedNo functions found in the changes. Docstring coverage check skipped.

Poem

A rabbit hops through config and patch,
Nudging coinbase code out of the batch.
Builds breathe lighter, scans run anew,
Thump! A tiny change—clean and true. 🥕

Warning

Review ran into problems

🔥 Problems

Errors were encountered while retrieving linked issues.

Errors (1)
  • USER-4320: Entity not found: Issue - Could not find referenced Issue.
✨ Finishing Touches
  • 📝 Generate Docstrings
🧪 Generate unit tests
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch tm/user-4320-rhc-coinbase

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Sep 9, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@6742

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@6742

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@6742

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@6742

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@6742

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@6742

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@6742

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@6742

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@6742

@clerk/express

npm i https://pkg.pr.new/@clerk/express@6742

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@6742

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@6742

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@6742

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@6742

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@6742

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@6742

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@6742

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@6742

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@6742

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@6742

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@6742

@clerk/types

npm i https://pkg.pr.new/@clerk/types@6742

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@6742

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@6742

commit: 0d7a724

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/clerk-js/rspack.config.js (1)

621-625: Fix undefined variant key in dev config
In packages/clerk-js/rspack.config.js (lines 621–625), replace the nonexistent variants.clerkBrowserNoRHC with the defined variants.clerkNoRHC to avoid undefined keys in dev builds:

- [variants.clerkBrowserNoRHC]: merge(- entryForVariant(variants.clerkBrowserNoRHC),- common({ mode, disableRHC: true, variant: variants.clerkBrowserNoRHC }),+ [variants.clerkNoRHC]: merge(+ entryForVariant(variants.clerkNoRHC),+ common({ mode, disableRHC: true, variant: variants.clerkNoRHC }),
commonForDev(),
),
🧹 Nitpick comments (2)
.changeset/funny-laws-fetch.md (1)

1-5: Changeset looks good; add ticket reference for traceability.

Consider appending "Refs USER-4320" (or the appropriate tracker key) to the summary line so it’s linked in release notes.

-Ensure Coinbase dependencies aren't bundled for non-RHC environments+Ensure Coinbase dependencies aren't bundled for non-RHC environments (refs USER-4320)
packages/clerk-js/rspack.config.js (1)

80-84: Update the comment to reflect Coinbase too.

Stripe is mentioned but Coinbase is now treated similarly; keep comments in sync.

- * Remove the Stripe dependencies from the bundle, if RHC is disabled.- * Necessary to prevent the Stripe dependencies from being bundled into+ * Remove Stripe and Coinbase dependencies from the bundle when RHC is disabled.+ * Necessary to prevent these payment dependencies from being bundled into
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

💡 Knowledge Base configuration:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between c0a643f and 8aa5e85.

📒 Files selected for processing (2)
  • .changeset/funny-laws-fetch.md (1 hunks)
  • packages/clerk-js/rspack.config.js (2 hunks)
🧰 Additional context used
📓 Path-based instructions (4)
.changeset/**

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Automated releases must use Changesets.

Files:

  • .changeset/funny-laws-fetch.md
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/clerk-js/rspack.config.js
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (6)
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep/ci
🔇 Additional comments (1)
packages/clerk-js/rspack.config.js (1)

85-85: Switch externals to regex patterns for deep imports
Current string externals only match package roots. To ensure no @coinbase/wallet-sdk (or Stripe) subpaths slip through, use regex:

 externals: disableRHC
? [
- '@stripe/stripe-js',- '@stripe/react-stripe-js',- '@coinbase/wallet-sdk',+ /^@stripe\/stripe-js(?:\/.*)?$/,+ /^@stripe\/react-stripe-js(?:\/.*)?$/,+ /^@coinbase\/wallet-sdk(?:\/.*)?$/,
]
: undefined,

Scan the repo (and any downstream consumers) for @coinbase/wallet-sdk/ imports to confirm no deep paths remain.

Comment threadpackages/clerk-js/rspack.config.js
@tmilewskitmilewski changed the title fix(clerk-js): Ensure Coinbase dependencies aren't bundled for non-RHC environmentsfix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environmentsSep 9, 2025
@tmilewski
tmilewski enabled auto-merge (squash) September 9, 2025 21:27

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
scripts/search-for-rhc.mjs (1)

16-18: Directory search isn’t recursive; grep will miss matches.

Add -r so --include filters apply and directories are traversed.

- ? $`grep -${flag}q --include=\\*.js --include=\\*.mjs ${search} ${target}`+ ? $`grep -r -${flag}q --include=\\*.js --include=\\*.mjs ${search} ${target}`
♻️ Duplicate comments (1)
packages/clerk-js/rspack.config.js (1)

484-489: Broaden IgnorePlugin to catch deep imports (matches prior feedback).

Mirror externals by allowing optional subpaths so “@…/foo/bar” is ignored too.

 new rspack.IgnorePlugin({
- resourceRegExp: /^@coinbase\/wallet-sdk$/,+ resourceRegExp: /^@coinbase\/wallet-sdk(?:\/.*)?$/,
}),
new rspack.IgnorePlugin({
- resourceRegExp: /^@base-org\/account$/,+ resourceRegExp: /^@base-org\/account(?:\/.*)?$/,
}),
🧹 Nitpick comments (2)
scripts/search-for-rhc.mjs (1)

31-31: Consider scanning wallet subdomains too.

Add wallet.coinbase.com (and optionally walletlink) to reduce false negatives.

 asyncSearchRHC('Coinbase', 'coinbase.com'),
+ asyncSearchRHC('Coinbase Wallet domain', 'wallet.coinbase.com'),+ // (optional legacy) asyncSearchRHC('WalletLink', 'walletlink.org'),
packages/clerk-js/rspack.config.js (1)

479-490: DRY: centralize RHC module patterns and reuse for externals + IgnorePlugin.

Define a single array of RegExp patterns (e.g., RHC_MODULES) and reference it in both places to avoid drift.

Example:

// top-levelconstRHC_MODULES=[/^@stripe\/stripe-js(?:\/.*)?$/,/^@stripe\/react-stripe-js(?:\/.*)?$/,/^@coinbase\/wallet-sdk(?:\/.*)?$/,/^@base-org\/account(?:\/.*)?$/,];// usage
externals: disableRHC ? RHC_MODULES : undefined// ...
plugins: [ ...RHC_MODULES.map(rx=>newrspack.IgnorePlugin({resourceRegExp: rx})), ... ]
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

💡 Knowledge Base configuration:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 8aa5e85 and 0d7a724.

📒 Files selected for processing (3)
  • .changeset/funny-laws-fetch.md (1 hunks)
  • packages/clerk-js/rspack.config.js (2 hunks)
  • scripts/search-for-rhc.mjs (1 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • .changeset/funny-laws-fetch.md
🧰 Additional context used
📓 Path-based instructions (5)
scripts/**

📄 CodeRabbit inference engine (.cursor/rules/global.mdc)

Build automation and utility scripts should be placed under the scripts/ directory

Files:

  • scripts/search-for-rhc.mjs
scripts/**/*

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Build and automation scripts must be located in the 'scripts/' directory.

Files:

  • scripts/search-for-rhc.mjs
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/clerk-js/rspack.config.js
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep/ci
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)

Comment threadpackages/clerk-js/rspack.config.js
Comment threadscripts/search-for-rhc.mjs
Comment threadscripts/search-for-rhc.mjs
@tmilewski
tmilewski enabled auto-merge (squash) September 9, 2025 21:31
@tmilewski
tmilewski merged commit 7fe00d6 into mainSep 9, 2025
44 checks passed
@tmilewski
tmilewski deleted the tm/user-4320-rhc-coinbase branch September 9, 2025 21:32
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tmilewski@wobsoriano@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environments - #6742

Merged
tmilewski merged 3 commits into
mainfrom
tm/user-4320-rhc-coinbase
Sep 9, 2025
Merged

fix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environments#6742
tmilewski merged 3 commits into
mainfrom
tm/user-4320-rhc-coinbase

Conversation

@tmilewski

@tmilewskitmilewski commented Sep 9, 2025

Copy link
Copy Markdown
Member

Description

Ensures Base & Coinbase Wallet dependencies aren't bundled for non-RHC environments.

Note: Base now includes CB Wallet.

USER-4320

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes

    • Prevents Coinbase Wallet and Base account dependencies from being bundled in non-RHC (no-RHC/production) builds, reducing runtime issues and improving compatibility. Added additional build-time searches to detect remote-hosted Coinbase/Base usages.
  • Chores

    • Adds a patch-release changeset recording the bundling behavior change for non-RHC environments.

@tmilewskitmilewski self-assigned this Sep 9, 2025
@changeset-bot

changeset-botBot commented Sep 9, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0d7a724

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Sep 9, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentSep 9, 2025 9:23pm

@coderabbitai

coderabbitaiBot commented Sep 9, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Adds a changeset and updates build config to externalize/ignore Coinbase/Base deps when RHC is disabled or in certain prod builds; also adds new searches for Coinbase/Base in the RHC scanning script.

Changes

Cohort / File(s)Summary
Changeset
.changeset/funny-laws-fetch.md
Adds a patch changeset for @clerk/clerk-js noting Coinbase dependencies should not be bundled in non-RHC environments.
Build config (rspack)
packages/clerk-js/rspack.config.js
Extends externals when RHC is disabled to include @coinbase/wallet-sdk and @base-org/account; adds rspack.IgnorePlugin entries for those packages in no-RHC and production configs alongside existing Stripe ignores.
RHC search script
scripts/search-for-rhc.mjs
Adds three parallel search tasks: coinbase.com, an import regex for @coinbase/wallet-sdk, and an import regex for @base-org/account; integrates them into existing Promise.allSettled flow.

Sequence Diagram(s)

sequenceDiagram
participant Dev as Developer
participant Build as Rspack Build
participant Ignore as IgnorePlugin
participant Search as search-for-rhc.mjs
participant Output as Build Output Scanner
rect #E8F5E9
Dev->>Build: trigger build (disableRHC = true / prod)
Build->>Ignore: register IgnorePlugin for @coinbase/wallet-sdk & @base-org/account
Build->>Output: produce bundle (Coinbase/Base excluded)
end
rect #FFF3E0
Dev->>Search: run search-for-rhc
Search->>Output: scan for "coinbase.com"
Search->>Output: scan for import regex "@coinbase/wallet-sdk"
Search->>Output: scan for import regex "@base-org/account"
Output-->>Search: results
Search->>Dev: report findings (errors aggregated)
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Pre-merge checks (3 passed)

✅ Passed checks (3 passed)
Check nameStatusExplanation
Title Check✅ PassedThe pull request title clearly and concisely summarizes the main change by stating that Base and Coinbase dependencies will not be bundled in non-RHC environments, and it follows conventional commit style with the “fix(clerk-js)” prefix, making it specific, relevant, and easily understandable for team members scanning the history.
Description Check✅ PassedThe description directly relates to the changeset by explaining that Base and Coinbase Wallet dependencies will be excluded from non-RHC bundles, references the relevant issue, and includes a checklist for tests and documentation, so it provides context and aligns with the modifications.
Docstring Coverage✅ PassedNo functions found in the changes. Docstring coverage check skipped.

Poem

A rabbit hops through config and patch,
Nudging coinbase code out of the batch.
Builds breathe lighter, scans run anew,
Thump! A tiny change—clean and true. 🥕

Warning

Review ran into problems

🔥 Problems

Errors were encountered while retrieving linked issues.

Errors (1)
  • USER-4320: Entity not found: Issue - Could not find referenced Issue.
✨ Finishing Touches
  • 📝 Generate Docstrings
🧪 Generate unit tests
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch tm/user-4320-rhc-coinbase

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Sep 9, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@6742

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@6742

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@6742

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@6742

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@6742

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@6742

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@6742

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@6742

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@6742

@clerk/express

npm i https://pkg.pr.new/@clerk/express@6742

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@6742

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@6742

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@6742

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@6742

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@6742

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@6742

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@6742

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@6742

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@6742

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@6742

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@6742

@clerk/types

npm i https://pkg.pr.new/@clerk/types@6742

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@6742

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@6742

commit: 0d7a724

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/clerk-js/rspack.config.js (1)

621-625: Fix undefined variant key in dev config
In packages/clerk-js/rspack.config.js (lines 621–625), replace the nonexistent variants.clerkBrowserNoRHC with the defined variants.clerkNoRHC to avoid undefined keys in dev builds:

- [variants.clerkBrowserNoRHC]: merge(- entryForVariant(variants.clerkBrowserNoRHC),- common({ mode, disableRHC: true, variant: variants.clerkBrowserNoRHC }),+ [variants.clerkNoRHC]: merge(+ entryForVariant(variants.clerkNoRHC),+ common({ mode, disableRHC: true, variant: variants.clerkNoRHC }),
commonForDev(),
),
🧹 Nitpick comments (2)
.changeset/funny-laws-fetch.md (1)

1-5: Changeset looks good; add ticket reference for traceability.

Consider appending "Refs USER-4320" (or the appropriate tracker key) to the summary line so it’s linked in release notes.

-Ensure Coinbase dependencies aren't bundled for non-RHC environments+Ensure Coinbase dependencies aren't bundled for non-RHC environments (refs USER-4320)
packages/clerk-js/rspack.config.js (1)

80-84: Update the comment to reflect Coinbase too.

Stripe is mentioned but Coinbase is now treated similarly; keep comments in sync.

- * Remove the Stripe dependencies from the bundle, if RHC is disabled.- * Necessary to prevent the Stripe dependencies from being bundled into+ * Remove Stripe and Coinbase dependencies from the bundle when RHC is disabled.+ * Necessary to prevent these payment dependencies from being bundled into
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

💡 Knowledge Base configuration:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between c0a643f and 8aa5e85.

📒 Files selected for processing (2)
  • .changeset/funny-laws-fetch.md (1 hunks)
  • packages/clerk-js/rspack.config.js (2 hunks)
🧰 Additional context used
📓 Path-based instructions (4)
.changeset/**

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Automated releases must use Changesets.

Files:

  • .changeset/funny-laws-fetch.md
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/clerk-js/rspack.config.js
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (6)
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep/ci
🔇 Additional comments (1)
packages/clerk-js/rspack.config.js (1)

85-85: Switch externals to regex patterns for deep imports
Current string externals only match package roots. To ensure no @coinbase/wallet-sdk (or Stripe) subpaths slip through, use regex:

 externals: disableRHC
? [
- '@stripe/stripe-js',- '@stripe/react-stripe-js',- '@coinbase/wallet-sdk',+ /^@stripe\/stripe-js(?:\/.*)?$/,+ /^@stripe\/react-stripe-js(?:\/.*)?$/,+ /^@coinbase\/wallet-sdk(?:\/.*)?$/,
]
: undefined,

Scan the repo (and any downstream consumers) for @coinbase/wallet-sdk/ imports to confirm no deep paths remain.

Comment threadpackages/clerk-js/rspack.config.js
@tmilewskitmilewski changed the title fix(clerk-js): Ensure Coinbase dependencies aren't bundled for non-RHC environmentsfix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environmentsSep 9, 2025
@tmilewski
tmilewski enabled auto-merge (squash) September 9, 2025 21:27

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
scripts/search-for-rhc.mjs (1)

16-18: Directory search isn’t recursive; grep will miss matches.

Add -r so --include filters apply and directories are traversed.

- ? $`grep -${flag}q --include=\\*.js --include=\\*.mjs ${search} ${target}`+ ? $`grep -r -${flag}q --include=\\*.js --include=\\*.mjs ${search} ${target}`
♻️ Duplicate comments (1)
packages/clerk-js/rspack.config.js (1)

484-489: Broaden IgnorePlugin to catch deep imports (matches prior feedback).

Mirror externals by allowing optional subpaths so “@…/foo/bar” is ignored too.

 new rspack.IgnorePlugin({
- resourceRegExp: /^@coinbase\/wallet-sdk$/,+ resourceRegExp: /^@coinbase\/wallet-sdk(?:\/.*)?$/,
}),
new rspack.IgnorePlugin({
- resourceRegExp: /^@base-org\/account$/,+ resourceRegExp: /^@base-org\/account(?:\/.*)?$/,
}),
🧹 Nitpick comments (2)
scripts/search-for-rhc.mjs (1)

31-31: Consider scanning wallet subdomains too.

Add wallet.coinbase.com (and optionally walletlink) to reduce false negatives.

 asyncSearchRHC('Coinbase', 'coinbase.com'),
+ asyncSearchRHC('Coinbase Wallet domain', 'wallet.coinbase.com'),+ // (optional legacy) asyncSearchRHC('WalletLink', 'walletlink.org'),
packages/clerk-js/rspack.config.js (1)

479-490: DRY: centralize RHC module patterns and reuse for externals + IgnorePlugin.

Define a single array of RegExp patterns (e.g., RHC_MODULES) and reference it in both places to avoid drift.

Example:

// top-levelconstRHC_MODULES=[/^@stripe\/stripe-js(?:\/.*)?$/,/^@stripe\/react-stripe-js(?:\/.*)?$/,/^@coinbase\/wallet-sdk(?:\/.*)?$/,/^@base-org\/account(?:\/.*)?$/,];// usage
externals: disableRHC ? RHC_MODULES : undefined// ...
plugins: [ ...RHC_MODULES.map(rx=>newrspack.IgnorePlugin({resourceRegExp: rx})), ... ]
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

💡 Knowledge Base configuration:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 8aa5e85 and 0d7a724.

📒 Files selected for processing (3)
  • .changeset/funny-laws-fetch.md (1 hunks)
  • packages/clerk-js/rspack.config.js (2 hunks)
  • scripts/search-for-rhc.mjs (1 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • .changeset/funny-laws-fetch.md
🧰 Additional context used
📓 Path-based instructions (5)
scripts/**

📄 CodeRabbit inference engine (.cursor/rules/global.mdc)

Build automation and utility scripts should be placed under the scripts/ directory

Files:

  • scripts/search-for-rhc.mjs
scripts/**/*

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Build and automation scripts must be located in the 'scripts/' directory.

Files:

  • scripts/search-for-rhc.mjs
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/clerk-js/rspack.config.js
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep/ci
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)

Comment threadpackages/clerk-js/rspack.config.js
Comment threadscripts/search-for-rhc.mjs
Comment threadscripts/search-for-rhc.mjs
@tmilewski
tmilewski enabled auto-merge (squash) September 9, 2025 21:31
@tmilewski
tmilewski merged commit 7fe00d6 into mainSep 9, 2025
44 checks passed
@tmilewski
tmilewski deleted the tm/user-4320-rhc-coinbase branch September 9, 2025 21:32
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tmilewski@wobsoriano@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environments - #6742

Merged
tmilewski merged 3 commits into
mainfrom
tm/user-4320-rhc-coinbase
Sep 9, 2025
Merged

fix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environments#6742
tmilewski merged 3 commits into
mainfrom
tm/user-4320-rhc-coinbase

Conversation

@tmilewski

@tmilewskitmilewski commented Sep 9, 2025

Copy link
Copy Markdown
Member

Description

Ensures Base & Coinbase Wallet dependencies aren't bundled for non-RHC environments.

Note: Base now includes CB Wallet.

USER-4320

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes

    • Prevents Coinbase Wallet and Base account dependencies from being bundled in non-RHC (no-RHC/production) builds, reducing runtime issues and improving compatibility. Added additional build-time searches to detect remote-hosted Coinbase/Base usages.
  • Chores

    • Adds a patch-release changeset recording the bundling behavior change for non-RHC environments.

@tmilewskitmilewski self-assigned this Sep 9, 2025
@changeset-bot

changeset-botBot commented Sep 9, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0d7a724

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Sep 9, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentSep 9, 2025 9:23pm

@coderabbitai

coderabbitaiBot commented Sep 9, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Adds a changeset and updates build config to externalize/ignore Coinbase/Base deps when RHC is disabled or in certain prod builds; also adds new searches for Coinbase/Base in the RHC scanning script.

Changes

Cohort / File(s)Summary
Changeset
.changeset/funny-laws-fetch.md
Adds a patch changeset for @clerk/clerk-js noting Coinbase dependencies should not be bundled in non-RHC environments.
Build config (rspack)
packages/clerk-js/rspack.config.js
Extends externals when RHC is disabled to include @coinbase/wallet-sdk and @base-org/account; adds rspack.IgnorePlugin entries for those packages in no-RHC and production configs alongside existing Stripe ignores.
RHC search script
scripts/search-for-rhc.mjs
Adds three parallel search tasks: coinbase.com, an import regex for @coinbase/wallet-sdk, and an import regex for @base-org/account; integrates them into existing Promise.allSettled flow.

Sequence Diagram(s)

sequenceDiagram
participant Dev as Developer
participant Build as Rspack Build
participant Ignore as IgnorePlugin
participant Search as search-for-rhc.mjs
participant Output as Build Output Scanner
rect #E8F5E9
Dev->>Build: trigger build (disableRHC = true / prod)
Build->>Ignore: register IgnorePlugin for @coinbase/wallet-sdk & @base-org/account
Build->>Output: produce bundle (Coinbase/Base excluded)
end
rect #FFF3E0
Dev->>Search: run search-for-rhc
Search->>Output: scan for "coinbase.com"
Search->>Output: scan for import regex "@coinbase/wallet-sdk"
Search->>Output: scan for import regex "@base-org/account"
Output-->>Search: results
Search->>Dev: report findings (errors aggregated)
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Pre-merge checks (3 passed)

✅ Passed checks (3 passed)
Check nameStatusExplanation
Title Check✅ PassedThe pull request title clearly and concisely summarizes the main change by stating that Base and Coinbase dependencies will not be bundled in non-RHC environments, and it follows conventional commit style with the “fix(clerk-js)” prefix, making it specific, relevant, and easily understandable for team members scanning the history.
Description Check✅ PassedThe description directly relates to the changeset by explaining that Base and Coinbase Wallet dependencies will be excluded from non-RHC bundles, references the relevant issue, and includes a checklist for tests and documentation, so it provides context and aligns with the modifications.
Docstring Coverage✅ PassedNo functions found in the changes. Docstring coverage check skipped.

Poem

A rabbit hops through config and patch,
Nudging coinbase code out of the batch.
Builds breathe lighter, scans run anew,
Thump! A tiny change—clean and true. 🥕

Warning

Review ran into problems

🔥 Problems

Errors were encountered while retrieving linked issues.

Errors (1)
  • USER-4320: Entity not found: Issue - Could not find referenced Issue.
✨ Finishing Touches
  • 📝 Generate Docstrings
🧪 Generate unit tests
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch tm/user-4320-rhc-coinbase

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Sep 9, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@6742

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@6742

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@6742

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@6742

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@6742

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@6742

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@6742

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@6742

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@6742

@clerk/express

npm i https://pkg.pr.new/@clerk/express@6742

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@6742

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@6742

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@6742

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@6742

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@6742

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@6742

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@6742

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@6742

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@6742

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@6742

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@6742

@clerk/types

npm i https://pkg.pr.new/@clerk/types@6742

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@6742

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@6742

commit: 0d7a724

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/clerk-js/rspack.config.js (1)

621-625: Fix undefined variant key in dev config
In packages/clerk-js/rspack.config.js (lines 621–625), replace the nonexistent variants.clerkBrowserNoRHC with the defined variants.clerkNoRHC to avoid undefined keys in dev builds:

- [variants.clerkBrowserNoRHC]: merge(- entryForVariant(variants.clerkBrowserNoRHC),- common({ mode, disableRHC: true, variant: variants.clerkBrowserNoRHC }),+ [variants.clerkNoRHC]: merge(+ entryForVariant(variants.clerkNoRHC),+ common({ mode, disableRHC: true, variant: variants.clerkNoRHC }),
commonForDev(),
),
🧹 Nitpick comments (2)
.changeset/funny-laws-fetch.md (1)

1-5: Changeset looks good; add ticket reference for traceability.

Consider appending "Refs USER-4320" (or the appropriate tracker key) to the summary line so it’s linked in release notes.

-Ensure Coinbase dependencies aren't bundled for non-RHC environments+Ensure Coinbase dependencies aren't bundled for non-RHC environments (refs USER-4320)
packages/clerk-js/rspack.config.js (1)

80-84: Update the comment to reflect Coinbase too.

Stripe is mentioned but Coinbase is now treated similarly; keep comments in sync.

- * Remove the Stripe dependencies from the bundle, if RHC is disabled.- * Necessary to prevent the Stripe dependencies from being bundled into+ * Remove Stripe and Coinbase dependencies from the bundle when RHC is disabled.+ * Necessary to prevent these payment dependencies from being bundled into
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

💡 Knowledge Base configuration:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between c0a643f and 8aa5e85.

📒 Files selected for processing (2)
  • .changeset/funny-laws-fetch.md (1 hunks)
  • packages/clerk-js/rspack.config.js (2 hunks)
🧰 Additional context used
📓 Path-based instructions (4)
.changeset/**

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Automated releases must use Changesets.

Files:

  • .changeset/funny-laws-fetch.md
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/clerk-js/rspack.config.js
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (6)
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Build Packages
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep/ci
🔇 Additional comments (1)
packages/clerk-js/rspack.config.js (1)

85-85: Switch externals to regex patterns for deep imports
Current string externals only match package roots. To ensure no @coinbase/wallet-sdk (or Stripe) subpaths slip through, use regex:

 externals: disableRHC
? [
- '@stripe/stripe-js',- '@stripe/react-stripe-js',- '@coinbase/wallet-sdk',+ /^@stripe\/stripe-js(?:\/.*)?$/,+ /^@stripe\/react-stripe-js(?:\/.*)?$/,+ /^@coinbase\/wallet-sdk(?:\/.*)?$/,
]
: undefined,

Scan the repo (and any downstream consumers) for @coinbase/wallet-sdk/ imports to confirm no deep paths remain.

Comment threadpackages/clerk-js/rspack.config.js
@tmilewskitmilewski changed the title fix(clerk-js): Ensure Coinbase dependencies aren't bundled for non-RHC environmentsfix(clerk-js): Ensure Base & Coinbase dependencies aren't bundled for non-RHC environmentsSep 9, 2025
@tmilewski
tmilewski enabled auto-merge (squash) September 9, 2025 21:27

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
scripts/search-for-rhc.mjs (1)

16-18: Directory search isn’t recursive; grep will miss matches.

Add -r so --include filters apply and directories are traversed.

- ? $`grep -${flag}q --include=\\*.js --include=\\*.mjs ${search} ${target}`+ ? $`grep -r -${flag}q --include=\\*.js --include=\\*.mjs ${search} ${target}`
♻️ Duplicate comments (1)
packages/clerk-js/rspack.config.js (1)

484-489: Broaden IgnorePlugin to catch deep imports (matches prior feedback).

Mirror externals by allowing optional subpaths so “@…/foo/bar” is ignored too.

 new rspack.IgnorePlugin({
- resourceRegExp: /^@coinbase\/wallet-sdk$/,+ resourceRegExp: /^@coinbase\/wallet-sdk(?:\/.*)?$/,
}),
new rspack.IgnorePlugin({
- resourceRegExp: /^@base-org\/account$/,+ resourceRegExp: /^@base-org\/account(?:\/.*)?$/,
}),
🧹 Nitpick comments (2)
scripts/search-for-rhc.mjs (1)

31-31: Consider scanning wallet subdomains too.

Add wallet.coinbase.com (and optionally walletlink) to reduce false negatives.

 asyncSearchRHC('Coinbase', 'coinbase.com'),
+ asyncSearchRHC('Coinbase Wallet domain', 'wallet.coinbase.com'),+ // (optional legacy) asyncSearchRHC('WalletLink', 'walletlink.org'),
packages/clerk-js/rspack.config.js (1)

479-490: DRY: centralize RHC module patterns and reuse for externals + IgnorePlugin.

Define a single array of RegExp patterns (e.g., RHC_MODULES) and reference it in both places to avoid drift.

Example:

// top-levelconstRHC_MODULES=[/^@stripe\/stripe-js(?:\/.*)?$/,/^@stripe\/react-stripe-js(?:\/.*)?$/,/^@coinbase\/wallet-sdk(?:\/.*)?$/,/^@base-org\/account(?:\/.*)?$/,];// usage
externals: disableRHC ? RHC_MODULES : undefined// ...
plugins: [ ...RHC_MODULES.map(rx=>newrspack.IgnorePlugin({resourceRegExp: rx})), ... ]
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

💡 Knowledge Base configuration:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 8aa5e85 and 0d7a724.

📒 Files selected for processing (3)
  • .changeset/funny-laws-fetch.md (1 hunks)
  • packages/clerk-js/rspack.config.js (2 hunks)
  • scripts/search-for-rhc.mjs (1 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • .changeset/funny-laws-fetch.md
🧰 Additional context used
📓 Path-based instructions (5)
scripts/**

📄 CodeRabbit inference engine (.cursor/rules/global.mdc)

Build automation and utility scripts should be placed under the scripts/ directory

Files:

  • scripts/search-for-rhc.mjs
scripts/**/*

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Build and automation scripts must be located in the 'scripts/' directory.

Files:

  • scripts/search-for-rhc.mjs
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/clerk-js/rspack.config.js
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/clerk-js/rspack.config.js
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep/ci
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)

Comment threadpackages/clerk-js/rspack.config.js
Comment threadscripts/search-for-rhc.mjs
Comment threadscripts/search-for-rhc.mjs
@tmilewski
tmilewski enabled auto-merge (squash) September 9, 2025 21:31
@tmilewski
tmilewski merged commit 7fe00d6 into mainSep 9, 2025
44 checks passed
@tmilewski
tmilewski deleted the tm/user-4320-rhc-coinbase branch September 9, 2025 21:32
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tmilewski@wobsoriano@clerk-cookie