fix(backend): Complete satellite domain sync - #7018

Merged
jacekradko merged 5 commits into
mainfrom
fix/localhost-satellite-sync
Oct 20, 2025
Merged

fix(backend): Complete satellite domain sync#7018
jacekradko merged 5 commits into
mainfrom
fix/localhost-satellite-sync

Conversation

@jacekradko

@jacekradkojacekradko commented Oct 17, 2025

Copy link
Copy Markdown
Contributor

Description

When a satellite app initiated a multi-domain sync by redirecting to the root domain with __clerk_redirect_url, the root domain was incorrectly triggering its own dev-browser-sync handshake before completing the satellite's sync request. This caused an infinite redirect loop between domains.

Reordered the authentication checks so that when the root domain detects it's handling a multi-domain sync request (via __clerk_redirect_url), it immediately redirects back to the satellite with __clerk_synced=true and the dev browser token—without triggering its own handshakes first.

Fixes: USER-3522

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Refactor

    • Reordered authentication handshake checks so multi-domain synchronization is evaluated before dev-browser sync, preventing redundant handshakes and reducing redirect loops in multi-domain development flows.
  • Tests

    • Added a test verifying primary-domain sync signals take precedence and produce the expected handshake result and redirect.
  • Documentation

    • Added clarifying comments describing sync precedence in the authentication flow.

@changeset-bot

changeset-botBot commented Oct 17, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 080a183

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Oct 17, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentOct 18, 2025 2:17am

💡 Enable Vercel Agent with $100 free credit for automated AI reviews

@coderabbitai

coderabbitaiBot commented Oct 17, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Reordered the DevBrowserSync handshake check in the token request authentication flow so multi-domain (MD) development sync handling runs first; added comments clarifying MD sync precedence to avoid root-domain handshakes during satellite handling. DevBrowserSync handling is re-applied after MD checks and returns via handleMaybeHandshakeStatus when triggered.

Changes

Cohort / File(s)Change Summary
Token request authentication flow
packages/backend/src/tokens/request.ts
Moved the DevBrowserSync handshake check to execute after the multi-domain (MD) sync handling block; added comments explaining that MD dev-sync must precede DevBrowser handshakes to prevent root-domain handshakes during satellite handling. Restored the DevBrowserSync early return via handleMaybeHandshakeStatus at the new location.
Tests
packages/backend/src/tokens/__tests__/request.test.ts
Added a test asserting that in a multi-domain flow a primary syncing signal (__clerk_db_jwt) takes precedence over dev-browser-sync, producing a handshake with reason PrimaryRespondsToSyncing and a redirect Location to the primary dashboard including __clerk_synced=true.
Release metadata
.changeset/tricky-pillows-juggle.md
Added a changeset describing a patch fix for an infinite redirect loop in multi-domain development flows by reordering authentication checks to prioritize satellite sync requests over dev-browser-sync handshakes.

Sequence Diagram(s)

sequenceDiagram
autonumber
participant Client
participant AuthFn as authenticateRequest
participant MDCheck as MultiDomainSyncCheck
participant DevBrowser as DevBrowserSyncCheck
participant Handshake as handleMaybeHandshakeStatus
participant Response
Client->>AuthFn: request with possible __clerk_db_jwt / dev sync params
AuthFn->>MDCheck: evaluate multi-domain (primary/satellite) sync
alt Primary sync present
MDCheck-->>Handshake: PrimaryRespondsToSyncing
Handshake-->>Response: redirect to primary with __clerk_synced=true
else No primary sync
MDCheck->>DevBrowser: evaluate dev-browser-sync
alt DevBrowser handshake needed
DevBrowser-->>Handshake: DevBrowser handshake
Handshake-->>Response: handshake response
else
DevBrowser-->>AuthFn: continue normal dev-cookie / auth flow
AuthFn-->>Response: normal authentication result
end
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Poem

🐰 I hopped through code with ears alert and quick,
Moved MD first so handshakes won't conflict,
Primary sync answers, dev-browser waits in line,
No more loops — the redirects now align. 🥕✨

Pre-merge checks and finishing touches

✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title Check✅ PassedThe title "fix(backend): Complete satellite domain sync" is directly related to the changes in the pull request. The changeset addresses reordering authentication checks to prioritize satellite domain synchronization, which is exactly what the title describes. While the title could be more specific about the underlying problem (infinite redirect loop), it accurately captures the essence of the fix by referring to satellite domain sync, which is the core objective. The title is concise, clear, and would allow a teammate scanning history to understand that this is a backend fix related to satellite domain synchronization.
Linked Issues Check✅ PassedThe code changes directly address all objectives from USER-3522. The modifications to request.ts reorder the authentication checks to prioritize multi-domain sync detection (via __clerk_redirect_url) over dev-browser-sync handshakes, preventing the root domain from initiating its own handshake before completing the satellite's sync request. The new test case in request.test.ts validates that the multi-domain sync flow with __clerk_db_jwt takes precedence, correctly resulting in a redirect with __clerk_synced=true to the primary domain. These changes implement the core fix required to stop the infinite redirect loop described in the issue by ensuring the root domain completes the multi-domain sync flow rather than triggering reciprocal redirects.
Out of Scope Changes Check✅ PassedAll changes in the pull request are directly scoped to the objective of fixing the redirect loop in multi-domain development flows. The modifications to request.ts reorder authentication checks specifically to address the satellite sync issue, the test additions validate the corrected behavior, and the changeset documents the fix. There are no unrelated changes such as refactoring, unrelated bug fixes, cleanup tasks, or other work items present in this pull request. Every modification directly supports resolving USER-3522.
Docstring Coverage✅ PassedNo functions found in the changes. Docstring coverage check skipped.
✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/localhost-satellite-sync

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 80a201a and 200b8a9.

📒 Files selected for processing (1)
  • .changeset/tricky-pillows-juggle.md (1 hunks)
✅ Files skipped from review due to trivial changes (1)
  • .changeset/tricky-pillows-juggle.md
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Oct 17, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7018

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7018

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7018

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7018

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7018

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7018

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7018

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7018

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7018

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7018

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7018

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7018

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7018

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7018

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7018

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7018

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7018

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7018

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7018

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7018

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7018

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7018

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7018

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7018

commit: 080a183

…irect loop
This test reproduces the bug where the root domain would incorrectly
trigger dev-browser-sync instead of handling multi-domain satellite
sync requests, causing an infinite redirect loop.
The test fails on main (broken behavior) and passes on this branch
(fixed behavior), demonstrating the fix works correctly.
@jacekradko
jacekradko merged commit 8ebbf1e into mainOct 20, 2025
39 checks passed
@jacekradko
jacekradko deleted the fix/localhost-satellite-sync branch October 20, 2025 19:22
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jacekradko@tmilewski@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(backend): Complete satellite domain sync - #7018

Merged
jacekradko merged 5 commits into
mainfrom
fix/localhost-satellite-sync
Oct 20, 2025
Merged

fix(backend): Complete satellite domain sync#7018
jacekradko merged 5 commits into
mainfrom
fix/localhost-satellite-sync

Conversation

@jacekradko

@jacekradkojacekradko commented Oct 17, 2025

Copy link
Copy Markdown
Contributor

Description

When a satellite app initiated a multi-domain sync by redirecting to the root domain with __clerk_redirect_url, the root domain was incorrectly triggering its own dev-browser-sync handshake before completing the satellite's sync request. This caused an infinite redirect loop between domains.

Reordered the authentication checks so that when the root domain detects it's handling a multi-domain sync request (via __clerk_redirect_url), it immediately redirects back to the satellite with __clerk_synced=true and the dev browser token—without triggering its own handshakes first.

Fixes: USER-3522

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Refactor

    • Reordered authentication handshake checks so multi-domain synchronization is evaluated before dev-browser sync, preventing redundant handshakes and reducing redirect loops in multi-domain development flows.
  • Tests

    • Added a test verifying primary-domain sync signals take precedence and produce the expected handshake result and redirect.
  • Documentation

    • Added clarifying comments describing sync precedence in the authentication flow.

@changeset-bot

changeset-botBot commented Oct 17, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 080a183

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Oct 17, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentOct 18, 2025 2:17am

💡 Enable Vercel Agent with $100 free credit for automated AI reviews

@coderabbitai

coderabbitaiBot commented Oct 17, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Reordered the DevBrowserSync handshake check in the token request authentication flow so multi-domain (MD) development sync handling runs first; added comments clarifying MD sync precedence to avoid root-domain handshakes during satellite handling. DevBrowserSync handling is re-applied after MD checks and returns via handleMaybeHandshakeStatus when triggered.

Changes

Cohort / File(s)Change Summary
Token request authentication flow
packages/backend/src/tokens/request.ts
Moved the DevBrowserSync handshake check to execute after the multi-domain (MD) sync handling block; added comments explaining that MD dev-sync must precede DevBrowser handshakes to prevent root-domain handshakes during satellite handling. Restored the DevBrowserSync early return via handleMaybeHandshakeStatus at the new location.
Tests
packages/backend/src/tokens/__tests__/request.test.ts
Added a test asserting that in a multi-domain flow a primary syncing signal (__clerk_db_jwt) takes precedence over dev-browser-sync, producing a handshake with reason PrimaryRespondsToSyncing and a redirect Location to the primary dashboard including __clerk_synced=true.
Release metadata
.changeset/tricky-pillows-juggle.md
Added a changeset describing a patch fix for an infinite redirect loop in multi-domain development flows by reordering authentication checks to prioritize satellite sync requests over dev-browser-sync handshakes.

Sequence Diagram(s)

sequenceDiagram
autonumber
participant Client
participant AuthFn as authenticateRequest
participant MDCheck as MultiDomainSyncCheck
participant DevBrowser as DevBrowserSyncCheck
participant Handshake as handleMaybeHandshakeStatus
participant Response
Client->>AuthFn: request with possible __clerk_db_jwt / dev sync params
AuthFn->>MDCheck: evaluate multi-domain (primary/satellite) sync
alt Primary sync present
MDCheck-->>Handshake: PrimaryRespondsToSyncing
Handshake-->>Response: redirect to primary with __clerk_synced=true
else No primary sync
MDCheck->>DevBrowser: evaluate dev-browser-sync
alt DevBrowser handshake needed
DevBrowser-->>Handshake: DevBrowser handshake
Handshake-->>Response: handshake response
else
DevBrowser-->>AuthFn: continue normal dev-cookie / auth flow
AuthFn-->>Response: normal authentication result
end
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Poem

🐰 I hopped through code with ears alert and quick,
Moved MD first so handshakes won't conflict,
Primary sync answers, dev-browser waits in line,
No more loops — the redirects now align. 🥕✨

Pre-merge checks and finishing touches

✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title Check✅ PassedThe title "fix(backend): Complete satellite domain sync" is directly related to the changes in the pull request. The changeset addresses reordering authentication checks to prioritize satellite domain synchronization, which is exactly what the title describes. While the title could be more specific about the underlying problem (infinite redirect loop), it accurately captures the essence of the fix by referring to satellite domain sync, which is the core objective. The title is concise, clear, and would allow a teammate scanning history to understand that this is a backend fix related to satellite domain synchronization.
Linked Issues Check✅ PassedThe code changes directly address all objectives from USER-3522. The modifications to request.ts reorder the authentication checks to prioritize multi-domain sync detection (via __clerk_redirect_url) over dev-browser-sync handshakes, preventing the root domain from initiating its own handshake before completing the satellite's sync request. The new test case in request.test.ts validates that the multi-domain sync flow with __clerk_db_jwt takes precedence, correctly resulting in a redirect with __clerk_synced=true to the primary domain. These changes implement the core fix required to stop the infinite redirect loop described in the issue by ensuring the root domain completes the multi-domain sync flow rather than triggering reciprocal redirects.
Out of Scope Changes Check✅ PassedAll changes in the pull request are directly scoped to the objective of fixing the redirect loop in multi-domain development flows. The modifications to request.ts reorder authentication checks specifically to address the satellite sync issue, the test additions validate the corrected behavior, and the changeset documents the fix. There are no unrelated changes such as refactoring, unrelated bug fixes, cleanup tasks, or other work items present in this pull request. Every modification directly supports resolving USER-3522.
Docstring Coverage✅ PassedNo functions found in the changes. Docstring coverage check skipped.
✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/localhost-satellite-sync

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 80a201a and 200b8a9.

📒 Files selected for processing (1)
  • .changeset/tricky-pillows-juggle.md (1 hunks)
✅ Files skipped from review due to trivial changes (1)
  • .changeset/tricky-pillows-juggle.md
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Oct 17, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7018

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7018

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7018

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7018

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7018

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7018

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7018

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7018

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7018

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7018

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7018

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7018

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7018

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7018

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7018

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7018

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7018

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7018

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7018

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7018

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7018

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7018

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7018

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7018

commit: 080a183

…irect loop
This test reproduces the bug where the root domain would incorrectly
trigger dev-browser-sync instead of handling multi-domain satellite
sync requests, causing an infinite redirect loop.
The test fails on main (broken behavior) and passes on this branch
(fixed behavior), demonstrating the fix works correctly.
@jacekradko
jacekradko merged commit 8ebbf1e into mainOct 20, 2025
39 checks passed
@jacekradko
jacekradko deleted the fix/localhost-satellite-sync branch October 20, 2025 19:22
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jacekradko@tmilewski@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(backend): Complete satellite domain sync - #7018

Merged
jacekradko merged 5 commits into
mainfrom
fix/localhost-satellite-sync
Oct 20, 2025
Merged

fix(backend): Complete satellite domain sync#7018
jacekradko merged 5 commits into
mainfrom
fix/localhost-satellite-sync

Conversation

@jacekradko

@jacekradkojacekradko commented Oct 17, 2025

Copy link
Copy Markdown
Contributor

Description

When a satellite app initiated a multi-domain sync by redirecting to the root domain with __clerk_redirect_url, the root domain was incorrectly triggering its own dev-browser-sync handshake before completing the satellite's sync request. This caused an infinite redirect loop between domains.

Reordered the authentication checks so that when the root domain detects it's handling a multi-domain sync request (via __clerk_redirect_url), it immediately redirects back to the satellite with __clerk_synced=true and the dev browser token—without triggering its own handshakes first.

Fixes: USER-3522

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Refactor

    • Reordered authentication handshake checks so multi-domain synchronization is evaluated before dev-browser sync, preventing redundant handshakes and reducing redirect loops in multi-domain development flows.
  • Tests

    • Added a test verifying primary-domain sync signals take precedence and produce the expected handshake result and redirect.
  • Documentation

    • Added clarifying comments describing sync precedence in the authentication flow.

@changeset-bot

changeset-botBot commented Oct 17, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 080a183

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Oct 17, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentOct 18, 2025 2:17am

💡 Enable Vercel Agent with $100 free credit for automated AI reviews

@coderabbitai

coderabbitaiBot commented Oct 17, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Reordered the DevBrowserSync handshake check in the token request authentication flow so multi-domain (MD) development sync handling runs first; added comments clarifying MD sync precedence to avoid root-domain handshakes during satellite handling. DevBrowserSync handling is re-applied after MD checks and returns via handleMaybeHandshakeStatus when triggered.

Changes

Cohort / File(s)Change Summary
Token request authentication flow
packages/backend/src/tokens/request.ts
Moved the DevBrowserSync handshake check to execute after the multi-domain (MD) sync handling block; added comments explaining that MD dev-sync must precede DevBrowser handshakes to prevent root-domain handshakes during satellite handling. Restored the DevBrowserSync early return via handleMaybeHandshakeStatus at the new location.
Tests
packages/backend/src/tokens/__tests__/request.test.ts
Added a test asserting that in a multi-domain flow a primary syncing signal (__clerk_db_jwt) takes precedence over dev-browser-sync, producing a handshake with reason PrimaryRespondsToSyncing and a redirect Location to the primary dashboard including __clerk_synced=true.
Release metadata
.changeset/tricky-pillows-juggle.md
Added a changeset describing a patch fix for an infinite redirect loop in multi-domain development flows by reordering authentication checks to prioritize satellite sync requests over dev-browser-sync handshakes.

Sequence Diagram(s)

sequenceDiagram
autonumber
participant Client
participant AuthFn as authenticateRequest
participant MDCheck as MultiDomainSyncCheck
participant DevBrowser as DevBrowserSyncCheck
participant Handshake as handleMaybeHandshakeStatus
participant Response
Client->>AuthFn: request with possible __clerk_db_jwt / dev sync params
AuthFn->>MDCheck: evaluate multi-domain (primary/satellite) sync
alt Primary sync present
MDCheck-->>Handshake: PrimaryRespondsToSyncing
Handshake-->>Response: redirect to primary with __clerk_synced=true
else No primary sync
MDCheck->>DevBrowser: evaluate dev-browser-sync
alt DevBrowser handshake needed
DevBrowser-->>Handshake: DevBrowser handshake
Handshake-->>Response: handshake response
else
DevBrowser-->>AuthFn: continue normal dev-cookie / auth flow
AuthFn-->>Response: normal authentication result
end
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Poem

🐰 I hopped through code with ears alert and quick,
Moved MD first so handshakes won't conflict,
Primary sync answers, dev-browser waits in line,
No more loops — the redirects now align. 🥕✨

Pre-merge checks and finishing touches

✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title Check✅ PassedThe title "fix(backend): Complete satellite domain sync" is directly related to the changes in the pull request. The changeset addresses reordering authentication checks to prioritize satellite domain synchronization, which is exactly what the title describes. While the title could be more specific about the underlying problem (infinite redirect loop), it accurately captures the essence of the fix by referring to satellite domain sync, which is the core objective. The title is concise, clear, and would allow a teammate scanning history to understand that this is a backend fix related to satellite domain synchronization.
Linked Issues Check✅ PassedThe code changes directly address all objectives from USER-3522. The modifications to request.ts reorder the authentication checks to prioritize multi-domain sync detection (via __clerk_redirect_url) over dev-browser-sync handshakes, preventing the root domain from initiating its own handshake before completing the satellite's sync request. The new test case in request.test.ts validates that the multi-domain sync flow with __clerk_db_jwt takes precedence, correctly resulting in a redirect with __clerk_synced=true to the primary domain. These changes implement the core fix required to stop the infinite redirect loop described in the issue by ensuring the root domain completes the multi-domain sync flow rather than triggering reciprocal redirects.
Out of Scope Changes Check✅ PassedAll changes in the pull request are directly scoped to the objective of fixing the redirect loop in multi-domain development flows. The modifications to request.ts reorder authentication checks specifically to address the satellite sync issue, the test additions validate the corrected behavior, and the changeset documents the fix. There are no unrelated changes such as refactoring, unrelated bug fixes, cleanup tasks, or other work items present in this pull request. Every modification directly supports resolving USER-3522.
Docstring Coverage✅ PassedNo functions found in the changes. Docstring coverage check skipped.
✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/localhost-satellite-sync

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 80a201a and 200b8a9.

📒 Files selected for processing (1)
  • .changeset/tricky-pillows-juggle.md (1 hunks)
✅ Files skipped from review due to trivial changes (1)
  • .changeset/tricky-pillows-juggle.md
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Oct 17, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7018

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7018

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7018

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7018

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7018

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7018

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7018

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7018

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7018

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7018

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7018

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7018

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7018

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7018

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7018

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7018

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7018

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7018

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7018

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7018

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7018

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7018

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7018

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7018

commit: 080a183

…irect loop
This test reproduces the bug where the root domain would incorrectly
trigger dev-browser-sync instead of handling multi-domain satellite
sync requests, causing an infinite redirect loop.
The test fails on main (broken behavior) and passes on this branch
(fixed behavior), demonstrating the fix works correctly.
@jacekradko
jacekradko merged commit 8ebbf1e into mainOct 20, 2025
39 checks passed
@jacekradko
jacekradko deleted the fix/localhost-satellite-sync branch October 20, 2025 19:22
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jacekradko@tmilewski@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(backend): Complete satellite domain sync - #7018

Merged
jacekradko merged 5 commits into
mainfrom
fix/localhost-satellite-sync
Oct 20, 2025
Merged

fix(backend): Complete satellite domain sync#7018
jacekradko merged 5 commits into
mainfrom
fix/localhost-satellite-sync

Conversation

@jacekradko

@jacekradkojacekradko commented Oct 17, 2025

Copy link
Copy Markdown
Contributor

Description

When a satellite app initiated a multi-domain sync by redirecting to the root domain with __clerk_redirect_url, the root domain was incorrectly triggering its own dev-browser-sync handshake before completing the satellite's sync request. This caused an infinite redirect loop between domains.

Reordered the authentication checks so that when the root domain detects it's handling a multi-domain sync request (via __clerk_redirect_url), it immediately redirects back to the satellite with __clerk_synced=true and the dev browser token—without triggering its own handshakes first.

Fixes: USER-3522

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Refactor

    • Reordered authentication handshake checks so multi-domain synchronization is evaluated before dev-browser sync, preventing redundant handshakes and reducing redirect loops in multi-domain development flows.
  • Tests

    • Added a test verifying primary-domain sync signals take precedence and produce the expected handshake result and redirect.
  • Documentation

    • Added clarifying comments describing sync precedence in the authentication flow.

@changeset-bot

changeset-botBot commented Oct 17, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 080a183

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Oct 17, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentOct 18, 2025 2:17am

💡 Enable Vercel Agent with $100 free credit for automated AI reviews

@coderabbitai

coderabbitaiBot commented Oct 17, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Reordered the DevBrowserSync handshake check in the token request authentication flow so multi-domain (MD) development sync handling runs first; added comments clarifying MD sync precedence to avoid root-domain handshakes during satellite handling. DevBrowserSync handling is re-applied after MD checks and returns via handleMaybeHandshakeStatus when triggered.

Changes

Cohort / File(s)Change Summary
Token request authentication flow
packages/backend/src/tokens/request.ts
Moved the DevBrowserSync handshake check to execute after the multi-domain (MD) sync handling block; added comments explaining that MD dev-sync must precede DevBrowser handshakes to prevent root-domain handshakes during satellite handling. Restored the DevBrowserSync early return via handleMaybeHandshakeStatus at the new location.
Tests
packages/backend/src/tokens/__tests__/request.test.ts
Added a test asserting that in a multi-domain flow a primary syncing signal (__clerk_db_jwt) takes precedence over dev-browser-sync, producing a handshake with reason PrimaryRespondsToSyncing and a redirect Location to the primary dashboard including __clerk_synced=true.
Release metadata
.changeset/tricky-pillows-juggle.md
Added a changeset describing a patch fix for an infinite redirect loop in multi-domain development flows by reordering authentication checks to prioritize satellite sync requests over dev-browser-sync handshakes.

Sequence Diagram(s)

sequenceDiagram
autonumber
participant Client
participant AuthFn as authenticateRequest
participant MDCheck as MultiDomainSyncCheck
participant DevBrowser as DevBrowserSyncCheck
participant Handshake as handleMaybeHandshakeStatus
participant Response
Client->>AuthFn: request with possible __clerk_db_jwt / dev sync params
AuthFn->>MDCheck: evaluate multi-domain (primary/satellite) sync
alt Primary sync present
MDCheck-->>Handshake: PrimaryRespondsToSyncing
Handshake-->>Response: redirect to primary with __clerk_synced=true
else No primary sync
MDCheck->>DevBrowser: evaluate dev-browser-sync
alt DevBrowser handshake needed
DevBrowser-->>Handshake: DevBrowser handshake
Handshake-->>Response: handshake response
else
DevBrowser-->>AuthFn: continue normal dev-cookie / auth flow
AuthFn-->>Response: normal authentication result
end
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Poem

🐰 I hopped through code with ears alert and quick,
Moved MD first so handshakes won't conflict,
Primary sync answers, dev-browser waits in line,
No more loops — the redirects now align. 🥕✨

Pre-merge checks and finishing touches

✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title Check✅ PassedThe title "fix(backend): Complete satellite domain sync" is directly related to the changes in the pull request. The changeset addresses reordering authentication checks to prioritize satellite domain synchronization, which is exactly what the title describes. While the title could be more specific about the underlying problem (infinite redirect loop), it accurately captures the essence of the fix by referring to satellite domain sync, which is the core objective. The title is concise, clear, and would allow a teammate scanning history to understand that this is a backend fix related to satellite domain synchronization.
Linked Issues Check✅ PassedThe code changes directly address all objectives from USER-3522. The modifications to request.ts reorder the authentication checks to prioritize multi-domain sync detection (via __clerk_redirect_url) over dev-browser-sync handshakes, preventing the root domain from initiating its own handshake before completing the satellite's sync request. The new test case in request.test.ts validates that the multi-domain sync flow with __clerk_db_jwt takes precedence, correctly resulting in a redirect with __clerk_synced=true to the primary domain. These changes implement the core fix required to stop the infinite redirect loop described in the issue by ensuring the root domain completes the multi-domain sync flow rather than triggering reciprocal redirects.
Out of Scope Changes Check✅ PassedAll changes in the pull request are directly scoped to the objective of fixing the redirect loop in multi-domain development flows. The modifications to request.ts reorder authentication checks specifically to address the satellite sync issue, the test additions validate the corrected behavior, and the changeset documents the fix. There are no unrelated changes such as refactoring, unrelated bug fixes, cleanup tasks, or other work items present in this pull request. Every modification directly supports resolving USER-3522.
Docstring Coverage✅ PassedNo functions found in the changes. Docstring coverage check skipped.
✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/localhost-satellite-sync

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 80a201a and 200b8a9.

📒 Files selected for processing (1)
  • .changeset/tricky-pillows-juggle.md (1 hunks)
✅ Files skipped from review due to trivial changes (1)
  • .changeset/tricky-pillows-juggle.md
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Oct 17, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7018

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7018

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7018

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7018

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7018

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7018

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7018

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7018

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7018

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7018

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7018

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7018

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7018

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7018

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7018

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7018

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7018

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7018

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7018

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7018

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7018

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7018

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7018

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7018

commit: 080a183

…irect loop
This test reproduces the bug where the root domain would incorrectly
trigger dev-browser-sync instead of handling multi-domain satellite
sync requests, causing an infinite redirect loop.
The test fails on main (broken behavior) and passes on this branch
(fixed behavior), demonstrating the fix works correctly.
@jacekradko
jacekradko merged commit 8ebbf1e into mainOct 20, 2025
39 checks passed
@jacekradko
jacekradko deleted the fix/localhost-satellite-sync branch October 20, 2025 19:22
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jacekradko@tmilewski@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(backend): Complete satellite domain sync - #7018

Merged
jacekradko merged 5 commits into
mainfrom
fix/localhost-satellite-sync
Oct 20, 2025
Merged

fix(backend): Complete satellite domain sync#7018
jacekradko merged 5 commits into
mainfrom
fix/localhost-satellite-sync

Conversation

@jacekradko

@jacekradkojacekradko commented Oct 17, 2025

Copy link
Copy Markdown
Contributor

Description

When a satellite app initiated a multi-domain sync by redirecting to the root domain with __clerk_redirect_url, the root domain was incorrectly triggering its own dev-browser-sync handshake before completing the satellite's sync request. This caused an infinite redirect loop between domains.

Reordered the authentication checks so that when the root domain detects it's handling a multi-domain sync request (via __clerk_redirect_url), it immediately redirects back to the satellite with __clerk_synced=true and the dev browser token—without triggering its own handshakes first.

Fixes: USER-3522

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Refactor

    • Reordered authentication handshake checks so multi-domain synchronization is evaluated before dev-browser sync, preventing redundant handshakes and reducing redirect loops in multi-domain development flows.
  • Tests

    • Added a test verifying primary-domain sync signals take precedence and produce the expected handshake result and redirect.
  • Documentation

    • Added clarifying comments describing sync precedence in the authentication flow.

@changeset-bot

changeset-botBot commented Oct 17, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 080a183

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Oct 17, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentOct 18, 2025 2:17am

💡 Enable Vercel Agent with $100 free credit for automated AI reviews

@coderabbitai

coderabbitaiBot commented Oct 17, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Reordered the DevBrowserSync handshake check in the token request authentication flow so multi-domain (MD) development sync handling runs first; added comments clarifying MD sync precedence to avoid root-domain handshakes during satellite handling. DevBrowserSync handling is re-applied after MD checks and returns via handleMaybeHandshakeStatus when triggered.

Changes

Cohort / File(s)Change Summary
Token request authentication flow
packages/backend/src/tokens/request.ts
Moved the DevBrowserSync handshake check to execute after the multi-domain (MD) sync handling block; added comments explaining that MD dev-sync must precede DevBrowser handshakes to prevent root-domain handshakes during satellite handling. Restored the DevBrowserSync early return via handleMaybeHandshakeStatus at the new location.
Tests
packages/backend/src/tokens/__tests__/request.test.ts
Added a test asserting that in a multi-domain flow a primary syncing signal (__clerk_db_jwt) takes precedence over dev-browser-sync, producing a handshake with reason PrimaryRespondsToSyncing and a redirect Location to the primary dashboard including __clerk_synced=true.
Release metadata
.changeset/tricky-pillows-juggle.md
Added a changeset describing a patch fix for an infinite redirect loop in multi-domain development flows by reordering authentication checks to prioritize satellite sync requests over dev-browser-sync handshakes.

Sequence Diagram(s)

sequenceDiagram
autonumber
participant Client
participant AuthFn as authenticateRequest
participant MDCheck as MultiDomainSyncCheck
participant DevBrowser as DevBrowserSyncCheck
participant Handshake as handleMaybeHandshakeStatus
participant Response
Client->>AuthFn: request with possible __clerk_db_jwt / dev sync params
AuthFn->>MDCheck: evaluate multi-domain (primary/satellite) sync
alt Primary sync present
MDCheck-->>Handshake: PrimaryRespondsToSyncing
Handshake-->>Response: redirect to primary with __clerk_synced=true
else No primary sync
MDCheck->>DevBrowser: evaluate dev-browser-sync
alt DevBrowser handshake needed
DevBrowser-->>Handshake: DevBrowser handshake
Handshake-->>Response: handshake response
else
DevBrowser-->>AuthFn: continue normal dev-cookie / auth flow
AuthFn-->>Response: normal authentication result
end
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Poem

🐰 I hopped through code with ears alert and quick,
Moved MD first so handshakes won't conflict,
Primary sync answers, dev-browser waits in line,
No more loops — the redirects now align. 🥕✨

Pre-merge checks and finishing touches

✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title Check✅ PassedThe title "fix(backend): Complete satellite domain sync" is directly related to the changes in the pull request. The changeset addresses reordering authentication checks to prioritize satellite domain synchronization, which is exactly what the title describes. While the title could be more specific about the underlying problem (infinite redirect loop), it accurately captures the essence of the fix by referring to satellite domain sync, which is the core objective. The title is concise, clear, and would allow a teammate scanning history to understand that this is a backend fix related to satellite domain synchronization.
Linked Issues Check✅ PassedThe code changes directly address all objectives from USER-3522. The modifications to request.ts reorder the authentication checks to prioritize multi-domain sync detection (via __clerk_redirect_url) over dev-browser-sync handshakes, preventing the root domain from initiating its own handshake before completing the satellite's sync request. The new test case in request.test.ts validates that the multi-domain sync flow with __clerk_db_jwt takes precedence, correctly resulting in a redirect with __clerk_synced=true to the primary domain. These changes implement the core fix required to stop the infinite redirect loop described in the issue by ensuring the root domain completes the multi-domain sync flow rather than triggering reciprocal redirects.
Out of Scope Changes Check✅ PassedAll changes in the pull request are directly scoped to the objective of fixing the redirect loop in multi-domain development flows. The modifications to request.ts reorder authentication checks specifically to address the satellite sync issue, the test additions validate the corrected behavior, and the changeset documents the fix. There are no unrelated changes such as refactoring, unrelated bug fixes, cleanup tasks, or other work items present in this pull request. Every modification directly supports resolving USER-3522.
Docstring Coverage✅ PassedNo functions found in the changes. Docstring coverage check skipped.
✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/localhost-satellite-sync

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 80a201a and 200b8a9.

📒 Files selected for processing (1)
  • .changeset/tricky-pillows-juggle.md (1 hunks)
✅ Files skipped from review due to trivial changes (1)
  • .changeset/tricky-pillows-juggle.md
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Oct 17, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7018

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7018

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7018

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7018

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7018

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7018

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7018

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7018

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7018

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7018

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7018

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7018

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7018

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7018

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7018

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7018

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7018

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7018

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7018

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7018

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7018

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7018

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7018

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7018

commit: 080a183

…irect loop
This test reproduces the bug where the root domain would incorrectly
trigger dev-browser-sync instead of handling multi-domain satellite
sync requests, causing an infinite redirect loop.
The test fails on main (broken behavior) and passes on this branch
(fixed behavior), demonstrating the fix works correctly.
@jacekradko
jacekradko merged commit 8ebbf1e into mainOct 20, 2025
39 checks passed
@jacekradko
jacekradko deleted the fix/localhost-satellite-sync branch October 20, 2025 19:22
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jacekradko@tmilewski@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(backend): Complete satellite domain sync - #7018

Merged
jacekradko merged 5 commits into
mainfrom
fix/localhost-satellite-sync
Oct 20, 2025
Merged

fix(backend): Complete satellite domain sync#7018
jacekradko merged 5 commits into
mainfrom
fix/localhost-satellite-sync

Conversation

@jacekradko

@jacekradkojacekradko commented Oct 17, 2025

Copy link
Copy Markdown
Contributor

Description

When a satellite app initiated a multi-domain sync by redirecting to the root domain with __clerk_redirect_url, the root domain was incorrectly triggering its own dev-browser-sync handshake before completing the satellite's sync request. This caused an infinite redirect loop between domains.

Reordered the authentication checks so that when the root domain detects it's handling a multi-domain sync request (via __clerk_redirect_url), it immediately redirects back to the satellite with __clerk_synced=true and the dev browser token—without triggering its own handshakes first.

Fixes: USER-3522

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Refactor

    • Reordered authentication handshake checks so multi-domain synchronization is evaluated before dev-browser sync, preventing redundant handshakes and reducing redirect loops in multi-domain development flows.
  • Tests

    • Added a test verifying primary-domain sync signals take precedence and produce the expected handshake result and redirect.
  • Documentation

    • Added clarifying comments describing sync precedence in the authentication flow.

@changeset-bot

changeset-botBot commented Oct 17, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 080a183

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Oct 17, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentOct 18, 2025 2:17am

💡 Enable Vercel Agent with $100 free credit for automated AI reviews

@coderabbitai

coderabbitaiBot commented Oct 17, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Reordered the DevBrowserSync handshake check in the token request authentication flow so multi-domain (MD) development sync handling runs first; added comments clarifying MD sync precedence to avoid root-domain handshakes during satellite handling. DevBrowserSync handling is re-applied after MD checks and returns via handleMaybeHandshakeStatus when triggered.

Changes

Cohort / File(s)Change Summary
Token request authentication flow
packages/backend/src/tokens/request.ts
Moved the DevBrowserSync handshake check to execute after the multi-domain (MD) sync handling block; added comments explaining that MD dev-sync must precede DevBrowser handshakes to prevent root-domain handshakes during satellite handling. Restored the DevBrowserSync early return via handleMaybeHandshakeStatus at the new location.
Tests
packages/backend/src/tokens/__tests__/request.test.ts
Added a test asserting that in a multi-domain flow a primary syncing signal (__clerk_db_jwt) takes precedence over dev-browser-sync, producing a handshake with reason PrimaryRespondsToSyncing and a redirect Location to the primary dashboard including __clerk_synced=true.
Release metadata
.changeset/tricky-pillows-juggle.md
Added a changeset describing a patch fix for an infinite redirect loop in multi-domain development flows by reordering authentication checks to prioritize satellite sync requests over dev-browser-sync handshakes.

Sequence Diagram(s)

sequenceDiagram
autonumber
participant Client
participant AuthFn as authenticateRequest
participant MDCheck as MultiDomainSyncCheck
participant DevBrowser as DevBrowserSyncCheck
participant Handshake as handleMaybeHandshakeStatus
participant Response
Client->>AuthFn: request with possible __clerk_db_jwt / dev sync params
AuthFn->>MDCheck: evaluate multi-domain (primary/satellite) sync
alt Primary sync present
MDCheck-->>Handshake: PrimaryRespondsToSyncing
Handshake-->>Response: redirect to primary with __clerk_synced=true
else No primary sync
MDCheck->>DevBrowser: evaluate dev-browser-sync
alt DevBrowser handshake needed
DevBrowser-->>Handshake: DevBrowser handshake
Handshake-->>Response: handshake response
else
DevBrowser-->>AuthFn: continue normal dev-cookie / auth flow
AuthFn-->>Response: normal authentication result
end
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Poem

🐰 I hopped through code with ears alert and quick,
Moved MD first so handshakes won't conflict,
Primary sync answers, dev-browser waits in line,
No more loops — the redirects now align. 🥕✨

Pre-merge checks and finishing touches

✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title Check✅ PassedThe title "fix(backend): Complete satellite domain sync" is directly related to the changes in the pull request. The changeset addresses reordering authentication checks to prioritize satellite domain synchronization, which is exactly what the title describes. While the title could be more specific about the underlying problem (infinite redirect loop), it accurately captures the essence of the fix by referring to satellite domain sync, which is the core objective. The title is concise, clear, and would allow a teammate scanning history to understand that this is a backend fix related to satellite domain synchronization.
Linked Issues Check✅ PassedThe code changes directly address all objectives from USER-3522. The modifications to request.ts reorder the authentication checks to prioritize multi-domain sync detection (via __clerk_redirect_url) over dev-browser-sync handshakes, preventing the root domain from initiating its own handshake before completing the satellite's sync request. The new test case in request.test.ts validates that the multi-domain sync flow with __clerk_db_jwt takes precedence, correctly resulting in a redirect with __clerk_synced=true to the primary domain. These changes implement the core fix required to stop the infinite redirect loop described in the issue by ensuring the root domain completes the multi-domain sync flow rather than triggering reciprocal redirects.
Out of Scope Changes Check✅ PassedAll changes in the pull request are directly scoped to the objective of fixing the redirect loop in multi-domain development flows. The modifications to request.ts reorder authentication checks specifically to address the satellite sync issue, the test additions validate the corrected behavior, and the changeset documents the fix. There are no unrelated changes such as refactoring, unrelated bug fixes, cleanup tasks, or other work items present in this pull request. Every modification directly supports resolving USER-3522.
Docstring Coverage✅ PassedNo functions found in the changes. Docstring coverage check skipped.
✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/localhost-satellite-sync

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 80a201a and 200b8a9.

📒 Files selected for processing (1)
  • .changeset/tricky-pillows-juggle.md (1 hunks)
✅ Files skipped from review due to trivial changes (1)
  • .changeset/tricky-pillows-juggle.md
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Oct 17, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7018

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7018

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7018

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7018

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7018

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7018

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7018

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7018

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7018

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7018

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7018

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7018

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7018

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7018

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7018

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7018

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7018

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7018

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7018

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7018

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7018

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7018

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7018

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7018

commit: 080a183

…irect loop
This test reproduces the bug where the root domain would incorrectly
trigger dev-browser-sync instead of handling multi-domain satellite
sync requests, causing an infinite redirect loop.
The test fails on main (broken behavior) and passes on this branch
(fixed behavior), demonstrating the fix works correctly.
@jacekradko
jacekradko merged commit 8ebbf1e into mainOct 20, 2025
39 checks passed
@jacekradko
jacekradko deleted the fix/localhost-satellite-sync branch October 20, 2025 19:22
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jacekradko@tmilewski@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(backend): Complete satellite domain sync - #7018

Merged
jacekradko merged 5 commits into
mainfrom
fix/localhost-satellite-sync
Oct 20, 2025
Merged

fix(backend): Complete satellite domain sync#7018
jacekradko merged 5 commits into
mainfrom
fix/localhost-satellite-sync

Conversation

@jacekradko

@jacekradkojacekradko commented Oct 17, 2025

Copy link
Copy Markdown
Contributor

Description

When a satellite app initiated a multi-domain sync by redirecting to the root domain with __clerk_redirect_url, the root domain was incorrectly triggering its own dev-browser-sync handshake before completing the satellite's sync request. This caused an infinite redirect loop between domains.

Reordered the authentication checks so that when the root domain detects it's handling a multi-domain sync request (via __clerk_redirect_url), it immediately redirects back to the satellite with __clerk_synced=true and the dev browser token—without triggering its own handshakes first.

Fixes: USER-3522

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Refactor

    • Reordered authentication handshake checks so multi-domain synchronization is evaluated before dev-browser sync, preventing redundant handshakes and reducing redirect loops in multi-domain development flows.
  • Tests

    • Added a test verifying primary-domain sync signals take precedence and produce the expected handshake result and redirect.
  • Documentation

    • Added clarifying comments describing sync precedence in the authentication flow.

@changeset-bot

changeset-botBot commented Oct 17, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 080a183

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Oct 17, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentOct 18, 2025 2:17am

💡 Enable Vercel Agent with $100 free credit for automated AI reviews

@coderabbitai

coderabbitaiBot commented Oct 17, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Reordered the DevBrowserSync handshake check in the token request authentication flow so multi-domain (MD) development sync handling runs first; added comments clarifying MD sync precedence to avoid root-domain handshakes during satellite handling. DevBrowserSync handling is re-applied after MD checks and returns via handleMaybeHandshakeStatus when triggered.

Changes

Cohort / File(s)Change Summary
Token request authentication flow
packages/backend/src/tokens/request.ts
Moved the DevBrowserSync handshake check to execute after the multi-domain (MD) sync handling block; added comments explaining that MD dev-sync must precede DevBrowser handshakes to prevent root-domain handshakes during satellite handling. Restored the DevBrowserSync early return via handleMaybeHandshakeStatus at the new location.
Tests
packages/backend/src/tokens/__tests__/request.test.ts
Added a test asserting that in a multi-domain flow a primary syncing signal (__clerk_db_jwt) takes precedence over dev-browser-sync, producing a handshake with reason PrimaryRespondsToSyncing and a redirect Location to the primary dashboard including __clerk_synced=true.
Release metadata
.changeset/tricky-pillows-juggle.md
Added a changeset describing a patch fix for an infinite redirect loop in multi-domain development flows by reordering authentication checks to prioritize satellite sync requests over dev-browser-sync handshakes.

Sequence Diagram(s)

sequenceDiagram
autonumber
participant Client
participant AuthFn as authenticateRequest
participant MDCheck as MultiDomainSyncCheck
participant DevBrowser as DevBrowserSyncCheck
participant Handshake as handleMaybeHandshakeStatus
participant Response
Client->>AuthFn: request with possible __clerk_db_jwt / dev sync params
AuthFn->>MDCheck: evaluate multi-domain (primary/satellite) sync
alt Primary sync present
MDCheck-->>Handshake: PrimaryRespondsToSyncing
Handshake-->>Response: redirect to primary with __clerk_synced=true
else No primary sync
MDCheck->>DevBrowser: evaluate dev-browser-sync
alt DevBrowser handshake needed
DevBrowser-->>Handshake: DevBrowser handshake
Handshake-->>Response: handshake response
else
DevBrowser-->>AuthFn: continue normal dev-cookie / auth flow
AuthFn-->>Response: normal authentication result
end
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Poem

🐰 I hopped through code with ears alert and quick,
Moved MD first so handshakes won't conflict,
Primary sync answers, dev-browser waits in line,
No more loops — the redirects now align. 🥕✨

Pre-merge checks and finishing touches

✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title Check✅ PassedThe title "fix(backend): Complete satellite domain sync" is directly related to the changes in the pull request. The changeset addresses reordering authentication checks to prioritize satellite domain synchronization, which is exactly what the title describes. While the title could be more specific about the underlying problem (infinite redirect loop), it accurately captures the essence of the fix by referring to satellite domain sync, which is the core objective. The title is concise, clear, and would allow a teammate scanning history to understand that this is a backend fix related to satellite domain synchronization.
Linked Issues Check✅ PassedThe code changes directly address all objectives from USER-3522. The modifications to request.ts reorder the authentication checks to prioritize multi-domain sync detection (via __clerk_redirect_url) over dev-browser-sync handshakes, preventing the root domain from initiating its own handshake before completing the satellite's sync request. The new test case in request.test.ts validates that the multi-domain sync flow with __clerk_db_jwt takes precedence, correctly resulting in a redirect with __clerk_synced=true to the primary domain. These changes implement the core fix required to stop the infinite redirect loop described in the issue by ensuring the root domain completes the multi-domain sync flow rather than triggering reciprocal redirects.
Out of Scope Changes Check✅ PassedAll changes in the pull request are directly scoped to the objective of fixing the redirect loop in multi-domain development flows. The modifications to request.ts reorder authentication checks specifically to address the satellite sync issue, the test additions validate the corrected behavior, and the changeset documents the fix. There are no unrelated changes such as refactoring, unrelated bug fixes, cleanup tasks, or other work items present in this pull request. Every modification directly supports resolving USER-3522.
Docstring Coverage✅ PassedNo functions found in the changes. Docstring coverage check skipped.
✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/localhost-satellite-sync

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 80a201a and 200b8a9.

📒 Files selected for processing (1)
  • .changeset/tricky-pillows-juggle.md (1 hunks)
✅ Files skipped from review due to trivial changes (1)
  • .changeset/tricky-pillows-juggle.md
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Oct 17, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7018

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7018

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7018

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7018

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7018

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7018

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7018

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7018

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7018

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7018

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7018

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7018

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7018

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7018

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7018

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7018

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7018

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7018

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7018

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7018

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7018

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7018

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7018

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7018

commit: 080a183

…irect loop
This test reproduces the bug where the root domain would incorrectly
trigger dev-browser-sync instead of handling multi-domain satellite
sync requests, causing an infinite redirect loop.
The test fails on main (broken behavior) and passes on this branch
(fixed behavior), demonstrating the fix works correctly.
@jacekradko
jacekradko merged commit 8ebbf1e into mainOct 20, 2025
39 checks passed
@jacekradko
jacekradko deleted the fix/localhost-satellite-sync branch October 20, 2025 19:22
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jacekradko@tmilewski@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(backend): Complete satellite domain sync - #7018

Merged
jacekradko merged 5 commits into
mainfrom
fix/localhost-satellite-sync
Oct 20, 2025
Merged

fix(backend): Complete satellite domain sync#7018
jacekradko merged 5 commits into
mainfrom
fix/localhost-satellite-sync

Conversation

@jacekradko

@jacekradkojacekradko commented Oct 17, 2025

Copy link
Copy Markdown
Contributor

Description

When a satellite app initiated a multi-domain sync by redirecting to the root domain with __clerk_redirect_url, the root domain was incorrectly triggering its own dev-browser-sync handshake before completing the satellite's sync request. This caused an infinite redirect loop between domains.

Reordered the authentication checks so that when the root domain detects it's handling a multi-domain sync request (via __clerk_redirect_url), it immediately redirects back to the satellite with __clerk_synced=true and the dev browser token—without triggering its own handshakes first.

Fixes: USER-3522

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Refactor

    • Reordered authentication handshake checks so multi-domain synchronization is evaluated before dev-browser sync, preventing redundant handshakes and reducing redirect loops in multi-domain development flows.
  • Tests

    • Added a test verifying primary-domain sync signals take precedence and produce the expected handshake result and redirect.
  • Documentation

    • Added clarifying comments describing sync precedence in the authentication flow.

@changeset-bot

changeset-botBot commented Oct 17, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 080a183

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 11 packages
NameType
@clerk/backendPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Oct 17, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentOct 18, 2025 2:17am

💡 Enable Vercel Agent with $100 free credit for automated AI reviews

@coderabbitai

coderabbitaiBot commented Oct 17, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Reordered the DevBrowserSync handshake check in the token request authentication flow so multi-domain (MD) development sync handling runs first; added comments clarifying MD sync precedence to avoid root-domain handshakes during satellite handling. DevBrowserSync handling is re-applied after MD checks and returns via handleMaybeHandshakeStatus when triggered.

Changes

Cohort / File(s)Change Summary
Token request authentication flow
packages/backend/src/tokens/request.ts
Moved the DevBrowserSync handshake check to execute after the multi-domain (MD) sync handling block; added comments explaining that MD dev-sync must precede DevBrowser handshakes to prevent root-domain handshakes during satellite handling. Restored the DevBrowserSync early return via handleMaybeHandshakeStatus at the new location.
Tests
packages/backend/src/tokens/__tests__/request.test.ts
Added a test asserting that in a multi-domain flow a primary syncing signal (__clerk_db_jwt) takes precedence over dev-browser-sync, producing a handshake with reason PrimaryRespondsToSyncing and a redirect Location to the primary dashboard including __clerk_synced=true.
Release metadata
.changeset/tricky-pillows-juggle.md
Added a changeset describing a patch fix for an infinite redirect loop in multi-domain development flows by reordering authentication checks to prioritize satellite sync requests over dev-browser-sync handshakes.

Sequence Diagram(s)

sequenceDiagram
autonumber
participant Client
participant AuthFn as authenticateRequest
participant MDCheck as MultiDomainSyncCheck
participant DevBrowser as DevBrowserSyncCheck
participant Handshake as handleMaybeHandshakeStatus
participant Response
Client->>AuthFn: request with possible __clerk_db_jwt / dev sync params
AuthFn->>MDCheck: evaluate multi-domain (primary/satellite) sync
alt Primary sync present
MDCheck-->>Handshake: PrimaryRespondsToSyncing
Handshake-->>Response: redirect to primary with __clerk_synced=true
else No primary sync
MDCheck->>DevBrowser: evaluate dev-browser-sync
alt DevBrowser handshake needed
DevBrowser-->>Handshake: DevBrowser handshake
Handshake-->>Response: handshake response
else
DevBrowser-->>AuthFn: continue normal dev-cookie / auth flow
AuthFn-->>Response: normal authentication result
end
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Poem

🐰 I hopped through code with ears alert and quick,
Moved MD first so handshakes won't conflict,
Primary sync answers, dev-browser waits in line,
No more loops — the redirects now align. 🥕✨

Pre-merge checks and finishing touches

✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title Check✅ PassedThe title "fix(backend): Complete satellite domain sync" is directly related to the changes in the pull request. The changeset addresses reordering authentication checks to prioritize satellite domain synchronization, which is exactly what the title describes. While the title could be more specific about the underlying problem (infinite redirect loop), it accurately captures the essence of the fix by referring to satellite domain sync, which is the core objective. The title is concise, clear, and would allow a teammate scanning history to understand that this is a backend fix related to satellite domain synchronization.
Linked Issues Check✅ PassedThe code changes directly address all objectives from USER-3522. The modifications to request.ts reorder the authentication checks to prioritize multi-domain sync detection (via __clerk_redirect_url) over dev-browser-sync handshakes, preventing the root domain from initiating its own handshake before completing the satellite's sync request. The new test case in request.test.ts validates that the multi-domain sync flow with __clerk_db_jwt takes precedence, correctly resulting in a redirect with __clerk_synced=true to the primary domain. These changes implement the core fix required to stop the infinite redirect loop described in the issue by ensuring the root domain completes the multi-domain sync flow rather than triggering reciprocal redirects.
Out of Scope Changes Check✅ PassedAll changes in the pull request are directly scoped to the objective of fixing the redirect loop in multi-domain development flows. The modifications to request.ts reorder authentication checks specifically to address the satellite sync issue, the test additions validate the corrected behavior, and the changeset documents the fix. There are no unrelated changes such as refactoring, unrelated bug fixes, cleanup tasks, or other work items present in this pull request. Every modification directly supports resolving USER-3522.
Docstring Coverage✅ PassedNo functions found in the changes. Docstring coverage check skipped.
✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/localhost-satellite-sync

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 80a201a and 200b8a9.

📒 Files selected for processing (1)
  • .changeset/tricky-pillows-juggle.md (1 hunks)
✅ Files skipped from review due to trivial changes (1)
  • .changeset/tricky-pillows-juggle.md
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Oct 17, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7018

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7018

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7018

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7018

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7018

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7018

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7018

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7018

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7018

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7018

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7018

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7018

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7018

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7018

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7018

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7018

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7018

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7018

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7018

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7018

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7018

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7018

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7018

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7018

commit: 080a183

…irect loop
This test reproduces the bug where the root domain would incorrectly
trigger dev-browser-sync instead of handling multi-domain satellite
sync requests, causing an infinite redirect loop.
The test fails on main (broken behavior) and passes on this branch
(fixed behavior), demonstrating the fix works correctly.
@jacekradko
jacekradko merged commit 8ebbf1e into mainOct 20, 2025
39 checks passed
@jacekradko
jacekradko deleted the fix/localhost-satellite-sync branch October 20, 2025 19:22
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jacekradko@tmilewski@clerk-cookie