fix(clerk-js,shared): Move clientTrustState to SignIn - #7163

Merged
tmilewski merged 3 commits into
mainfrom
tom/fix-client-trust-state
Nov 5, 2025
Merged

fix(clerk-js,shared): Move clientTrustState to SignIn#7163
tmilewski merged 3 commits into
mainfrom
tom/fix-client-trust-state

Conversation

@tmilewski

@tmilewskitmilewski commented Nov 5, 2025

Copy link
Copy Markdown
Member

Description

Fixes a rebase issue where clientTrustState didn't get moved to SignIn.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Email-based authentication codes are now supported as a second-factor verification method.
  • Changes

    • Client trust state is now surfaced on the sign-in object instead of the client profile.
    • Public type surfaces updated to expose the trust state on sign-in and include the new second-factor option.

@vercel

vercelBot commented Nov 5, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentNov 5, 2025 8:51pm

@changeset-bot

changeset-botBot commented Nov 5, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eab6a9c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 22 packages
NameType
@clerk/clerk-jsPatch
@clerk/sharedPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/elementsPatch
@clerk/expo-passkeysPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/clerk-reactPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/themesPatch
@clerk/typesPatch
@clerk/vuePatch
@clerk/localizationsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Nov 5, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

clientTrustState is removed from Client (runtime and types) and added to SignIn (runtime and types); Client JSON no longer includes client_trust_state while SignIn JSON/snapshots may include it. SignInSecondFactor now includes EmailCodeFactor. A patch changeset records the move.

Changes

Cohort / File(s)Summary
Changeset
\.changeset/evil-aliens-hope.md
Adds a patch changeset documenting the behavioral rename: moving clientTrustState from Client to SignIn.
Client resource & JSON/types removed
packages/clerk-js/src/core/resources/Client.ts, packages/shared/src/types/client.ts, packages/shared/src/types/json.ts
Removes clientTrustState from the Client class and ClientResource interface; removes client_trust_state from ClientJSON; deletes related imports, initialization, (de)serialization code.
SignIn resource & types added
packages/clerk-js/src/core/resources/SignIn.ts, packages/shared/src/types/signIn.ts, packages/shared/src/types/snapshots.ts
Adds clientTrustState?: ClientTrustState to the SignIn class and SignInResource; adds client_trust_state?: ClientTrustState to SignIn JSON and snapshot shapes and imports ClientTrustState; populates from JSON.
SignIn second-factor expansion
packages/shared/src/types/signInCommon.ts
Extends SignInSecondFactor and AttemptSecondFactorParams unions to include EmailCodeFactor / EmailCodeAttempt.

Sequence Diagram(s)

sequenceDiagram
autonumber
participant API as Backend JSON
participant Client as Client (resource)
participant SignIn as SignIn (resource)
rect rgb(235,245,255)
Note over API,Client: Old flow (before change)
end
API->>Client: GET /client -> { ..., client_trust_state }
Client-->>API: serializes client (includes client_trust_state)
Note over Client: clientTrustState persisted on Client resource
Loading
sequenceDiagram
autonumber
participant API as Backend JSON
participant Client as Client (resource)
participant SignIn as SignIn (resource)
rect rgb(245,255,235)
Note over API,SignIn: New flow (after change)
end
API->>Client: GET /client -> { ... }
Note over Client: no client_trust_state persisted
API->>SignIn: GET /sign_in -> { ..., client_trust_state }
SignIn-->>API: serializes sign_in (includes client_trust_state)
Note over SignIn: clientTrustState persisted on SignIn resource
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

  • Focus areas:
    • packages/clerk-js/src/core/resources/Client.ts — verify all clientTrustState references removed and serialization snapshot updated.
    • packages/clerk-js/src/core/resources/SignIn.ts — confirm import, property typing, and fromJSON assignment for client_trust_state.
    • packages/shared/src/types/* — ensure JSON shapes, resource types, and snapshots are consistent.
    • packages/shared/src/types/signInCommon.ts — check callers for the new EmailCodeFactor/EmailCodeAttempt variants.

Poem

🐰 I hopped from Client to SignIn with glee,
A trust-state moved, now fresh and free.
Email codes joined the second-factor tune,
The rabbit winks beneath the moon 🌙
Change shipped swift — a happy hop, hooray!

Pre-merge checks and finishing touches

✅ Passed checks (2 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title directly and clearly summarizes the main change: moving clientTrustState from Client to SignIn, which aligns with the primary objective of this bug fix PR.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch tom/fix-client-trust-state

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between ba05615 and eab6a9c.

📒 Files selected for processing (1)
  • packages/shared/src/types/signInCommon.ts (2 hunks)
🧰 Additional context used
📓 Path-based instructions (6)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/shared/src/types/signInCommon.ts
packages/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/shared/src/types/signInCommon.ts
packages/**/*.{ts,tsx,d.ts}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Packages should export TypeScript types alongside runtime code

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Prefer readonly for properties that shouldn't change after construction
Prefer composition and interfaces over deep inheritance chains
Use mixins for shared behavior across unrelated classes
Implement dependency injection for loose coupling
Let TypeScript infer when types are obvious
Use const assertions for literal types: as const
Use satisfies operator for type checking without widening
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Use type-only imports: import type { ... } from ...
No any types without justification
Proper error handling with typed errors
Consistent use of readonly for immutable data
Proper generic constraints
No unused type parameters
Proper use of utility types instead of manual type construction
Type-only imports where possible
Proper tree-shaking friendly exports
No circular dependencies
Efficient type computations (avoid deep recursion)

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/shared/src/types/signInCommon.ts
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (3)
packages/shared/src/types/signInCommon.ts (3)

122-122: LGTM!

The addition of EmailCodeAttempt is consistent with EmailCodeFactor being added to SignInSecondFactor on line 88, maintaining proper alignment between factor types and their attempt parameters.


120-120: I need to check the actual implementation and definitions in the codebase to understand whether this is intentional design.

Review comment is incorrect and should be disregarded.

According to Clerk's official documentation, if the strategy is set to TOTP, it does not require preparation and you can directly attempt the second factor verification. Only the phone_code strategy requires calling the prepareSecondFactor method.

The asymmetry between PrepareSecondFactorParams (only PhoneCodeSecondFactorConfig) and AttemptSecondFactorParams (four factor types) is intentional by Clerk's design. Backup codes are a fallback when the user is unable to use their primary MFA method, and do not require a separate preparation step. EmailCode and TOTP similarly do not require preparation configuration, which is why no corresponding config types exist for them.

The type definition is correct and complete.

Likely an incorrect or invalid review comment.


88-88: EmailCodeFactor as second factor is intentional and properly implemented.

The changes add email code authentication as a supported second factor, paralleling existing patterns for phone code and backup code. The generic attemptSecondFactor implementation accepts {strategy, code} parameters, which EmailCodeAttempt provides. Types are properly exported and integrated into verification machines and UI components (clerk-js, elements packages). The addition to both SignInFirstFactor and SignInSecondFactor is correct—email authentication is designed to work as both primary and secondary authentication.


Comment @coderabbitai help to get the list of available commands and usage tips.

@tmilewskitmilewski changed the title fix: Move clientTrustState to SignInfix(clerk-js,shared): Move clientTrustState to SignInNov 5, 2025
@tmilewskitmilewski self-assigned this Nov 5, 2025
@tmilewski

Copy link
Copy Markdown
MemberAuthor

@coderabbitai full review

@coderabbitai

Copy link
Copy Markdown
Contributor
✅ Actions performed

Full review triggered.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/shared/src/types/signIn.ts (1)

46-46: LGTM! Consider adding JSDoc for the new property.

The clientTrustState property is correctly added to both interfaces with appropriate types and optional modifiers for backward compatibility. The naming follows conventions (camelCase in resource, snake_case in JSON).

Consider adding JSDoc documentation to explain what this property represents and its possible values, as per coding guidelines for public APIs.

Example JSDoc for line 46:

+ /**+ * The trust state of the client device for this sign-in attempt.+ * Possible values: 'new', 'known', 'pending'.+ */
clientTrustState?: ClientTrustState;

Also applies to: 99-99

📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 9ffa221 and ba05615.

📒 Files selected for processing (1)
  • packages/shared/src/types/signIn.ts (3 hunks)
🧰 Additional context used
📓 Path-based instructions (6)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/shared/src/types/signIn.ts
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/shared/src/types/signIn.ts
packages/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/shared/src/types/signIn.ts
packages/**/*.{ts,tsx,d.ts}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Packages should export TypeScript types alongside runtime code

Files:

  • packages/shared/src/types/signIn.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Prefer readonly for properties that shouldn't change after construction
Prefer composition and interfaces over deep inheritance chains
Use mixins for shared behavior across unrelated classes
Implement dependency injection for loose coupling
Let TypeScript infer when types are obvious
Use const assertions for literal types: as const
Use satisfies operator for type checking without widening
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Use type-only imports: import type { ... } from ...
No any types without justification
Proper error handling with typed errors
Consistent use of readonly for immutable data
Proper generic constraints
No unused type parameters
Proper use of utility types instead of manual type construction
Type-only imports where possible
Proper tree-shaking friendly exports
No circular dependencies
Efficient type computations (avoid deep recursion)

Files:

  • packages/shared/src/types/signIn.ts
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/shared/src/types/signIn.ts
🧬 Code graph analysis (1)
packages/shared/src/types/signIn.ts (1)
packages/shared/src/types/json.ts (1)
  • ClientTrustState (105-105)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

@pkg-pr-new

pkg-pr-newBot commented Nov 5, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7163

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7163

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7163

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7163

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7163

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7163

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7163

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7163

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7163

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7163

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7163

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7163

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7163

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7163

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7163

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7163

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7163

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7163

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7163

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7163

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7163

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7163

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7163

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7163

commit: eab6a9c

@blacksmith-sh

This comment has been minimized.

@blacksmith-sh

This comment was marked as resolved.

@tmilewski

Copy link
Copy Markdown
MemberAuthor

Pushing through. 429's are blocking the Next CI

@tmilewski
tmilewski merged commit a474c59 into mainNov 5, 2025
93 of 100 checks passed
@tmilewski
tmilewski deleted the tom/fix-client-trust-state branch November 5, 2025 21:19
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tmilewski@wobsoriano@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(clerk-js,shared): Move clientTrustState to SignIn - #7163

Merged
tmilewski merged 3 commits into
mainfrom
tom/fix-client-trust-state
Nov 5, 2025
Merged

fix(clerk-js,shared): Move clientTrustState to SignIn#7163
tmilewski merged 3 commits into
mainfrom
tom/fix-client-trust-state

Conversation

@tmilewski

@tmilewskitmilewski commented Nov 5, 2025

Copy link
Copy Markdown
Member

Description

Fixes a rebase issue where clientTrustState didn't get moved to SignIn.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Email-based authentication codes are now supported as a second-factor verification method.
  • Changes

    • Client trust state is now surfaced on the sign-in object instead of the client profile.
    • Public type surfaces updated to expose the trust state on sign-in and include the new second-factor option.

@vercel

vercelBot commented Nov 5, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentNov 5, 2025 8:51pm

@changeset-bot

changeset-botBot commented Nov 5, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eab6a9c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 22 packages
NameType
@clerk/clerk-jsPatch
@clerk/sharedPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/elementsPatch
@clerk/expo-passkeysPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/clerk-reactPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/themesPatch
@clerk/typesPatch
@clerk/vuePatch
@clerk/localizationsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Nov 5, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

clientTrustState is removed from Client (runtime and types) and added to SignIn (runtime and types); Client JSON no longer includes client_trust_state while SignIn JSON/snapshots may include it. SignInSecondFactor now includes EmailCodeFactor. A patch changeset records the move.

Changes

Cohort / File(s)Summary
Changeset
\.changeset/evil-aliens-hope.md
Adds a patch changeset documenting the behavioral rename: moving clientTrustState from Client to SignIn.
Client resource & JSON/types removed
packages/clerk-js/src/core/resources/Client.ts, packages/shared/src/types/client.ts, packages/shared/src/types/json.ts
Removes clientTrustState from the Client class and ClientResource interface; removes client_trust_state from ClientJSON; deletes related imports, initialization, (de)serialization code.
SignIn resource & types added
packages/clerk-js/src/core/resources/SignIn.ts, packages/shared/src/types/signIn.ts, packages/shared/src/types/snapshots.ts
Adds clientTrustState?: ClientTrustState to the SignIn class and SignInResource; adds client_trust_state?: ClientTrustState to SignIn JSON and snapshot shapes and imports ClientTrustState; populates from JSON.
SignIn second-factor expansion
packages/shared/src/types/signInCommon.ts
Extends SignInSecondFactor and AttemptSecondFactorParams unions to include EmailCodeFactor / EmailCodeAttempt.

Sequence Diagram(s)

sequenceDiagram
autonumber
participant API as Backend JSON
participant Client as Client (resource)
participant SignIn as SignIn (resource)
rect rgb(235,245,255)
Note over API,Client: Old flow (before change)
end
API->>Client: GET /client -> { ..., client_trust_state }
Client-->>API: serializes client (includes client_trust_state)
Note over Client: clientTrustState persisted on Client resource
Loading
sequenceDiagram
autonumber
participant API as Backend JSON
participant Client as Client (resource)
participant SignIn as SignIn (resource)
rect rgb(245,255,235)
Note over API,SignIn: New flow (after change)
end
API->>Client: GET /client -> { ... }
Note over Client: no client_trust_state persisted
API->>SignIn: GET /sign_in -> { ..., client_trust_state }
SignIn-->>API: serializes sign_in (includes client_trust_state)
Note over SignIn: clientTrustState persisted on SignIn resource
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

  • Focus areas:
    • packages/clerk-js/src/core/resources/Client.ts — verify all clientTrustState references removed and serialization snapshot updated.
    • packages/clerk-js/src/core/resources/SignIn.ts — confirm import, property typing, and fromJSON assignment for client_trust_state.
    • packages/shared/src/types/* — ensure JSON shapes, resource types, and snapshots are consistent.
    • packages/shared/src/types/signInCommon.ts — check callers for the new EmailCodeFactor/EmailCodeAttempt variants.

Poem

🐰 I hopped from Client to SignIn with glee,
A trust-state moved, now fresh and free.
Email codes joined the second-factor tune,
The rabbit winks beneath the moon 🌙
Change shipped swift — a happy hop, hooray!

Pre-merge checks and finishing touches

✅ Passed checks (2 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title directly and clearly summarizes the main change: moving clientTrustState from Client to SignIn, which aligns with the primary objective of this bug fix PR.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch tom/fix-client-trust-state

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between ba05615 and eab6a9c.

📒 Files selected for processing (1)
  • packages/shared/src/types/signInCommon.ts (2 hunks)
🧰 Additional context used
📓 Path-based instructions (6)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/shared/src/types/signInCommon.ts
packages/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/shared/src/types/signInCommon.ts
packages/**/*.{ts,tsx,d.ts}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Packages should export TypeScript types alongside runtime code

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Prefer readonly for properties that shouldn't change after construction
Prefer composition and interfaces over deep inheritance chains
Use mixins for shared behavior across unrelated classes
Implement dependency injection for loose coupling
Let TypeScript infer when types are obvious
Use const assertions for literal types: as const
Use satisfies operator for type checking without widening
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Use type-only imports: import type { ... } from ...
No any types without justification
Proper error handling with typed errors
Consistent use of readonly for immutable data
Proper generic constraints
No unused type parameters
Proper use of utility types instead of manual type construction
Type-only imports where possible
Proper tree-shaking friendly exports
No circular dependencies
Efficient type computations (avoid deep recursion)

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/shared/src/types/signInCommon.ts
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (3)
packages/shared/src/types/signInCommon.ts (3)

122-122: LGTM!

The addition of EmailCodeAttempt is consistent with EmailCodeFactor being added to SignInSecondFactor on line 88, maintaining proper alignment between factor types and their attempt parameters.


120-120: I need to check the actual implementation and definitions in the codebase to understand whether this is intentional design.

Review comment is incorrect and should be disregarded.

According to Clerk's official documentation, if the strategy is set to TOTP, it does not require preparation and you can directly attempt the second factor verification. Only the phone_code strategy requires calling the prepareSecondFactor method.

The asymmetry between PrepareSecondFactorParams (only PhoneCodeSecondFactorConfig) and AttemptSecondFactorParams (four factor types) is intentional by Clerk's design. Backup codes are a fallback when the user is unable to use their primary MFA method, and do not require a separate preparation step. EmailCode and TOTP similarly do not require preparation configuration, which is why no corresponding config types exist for them.

The type definition is correct and complete.

Likely an incorrect or invalid review comment.


88-88: EmailCodeFactor as second factor is intentional and properly implemented.

The changes add email code authentication as a supported second factor, paralleling existing patterns for phone code and backup code. The generic attemptSecondFactor implementation accepts {strategy, code} parameters, which EmailCodeAttempt provides. Types are properly exported and integrated into verification machines and UI components (clerk-js, elements packages). The addition to both SignInFirstFactor and SignInSecondFactor is correct—email authentication is designed to work as both primary and secondary authentication.


Comment @coderabbitai help to get the list of available commands and usage tips.

@tmilewskitmilewski changed the title fix: Move clientTrustState to SignInfix(clerk-js,shared): Move clientTrustState to SignInNov 5, 2025
@tmilewskitmilewski self-assigned this Nov 5, 2025
@tmilewski

Copy link
Copy Markdown
MemberAuthor

@coderabbitai full review

@coderabbitai

Copy link
Copy Markdown
Contributor
✅ Actions performed

Full review triggered.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/shared/src/types/signIn.ts (1)

46-46: LGTM! Consider adding JSDoc for the new property.

The clientTrustState property is correctly added to both interfaces with appropriate types and optional modifiers for backward compatibility. The naming follows conventions (camelCase in resource, snake_case in JSON).

Consider adding JSDoc documentation to explain what this property represents and its possible values, as per coding guidelines for public APIs.

Example JSDoc for line 46:

+ /**+ * The trust state of the client device for this sign-in attempt.+ * Possible values: 'new', 'known', 'pending'.+ */
clientTrustState?: ClientTrustState;

Also applies to: 99-99

📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 9ffa221 and ba05615.

📒 Files selected for processing (1)
  • packages/shared/src/types/signIn.ts (3 hunks)
🧰 Additional context used
📓 Path-based instructions (6)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/shared/src/types/signIn.ts
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/shared/src/types/signIn.ts
packages/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/shared/src/types/signIn.ts
packages/**/*.{ts,tsx,d.ts}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Packages should export TypeScript types alongside runtime code

Files:

  • packages/shared/src/types/signIn.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Prefer readonly for properties that shouldn't change after construction
Prefer composition and interfaces over deep inheritance chains
Use mixins for shared behavior across unrelated classes
Implement dependency injection for loose coupling
Let TypeScript infer when types are obvious
Use const assertions for literal types: as const
Use satisfies operator for type checking without widening
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Use type-only imports: import type { ... } from ...
No any types without justification
Proper error handling with typed errors
Consistent use of readonly for immutable data
Proper generic constraints
No unused type parameters
Proper use of utility types instead of manual type construction
Type-only imports where possible
Proper tree-shaking friendly exports
No circular dependencies
Efficient type computations (avoid deep recursion)

Files:

  • packages/shared/src/types/signIn.ts
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/shared/src/types/signIn.ts
🧬 Code graph analysis (1)
packages/shared/src/types/signIn.ts (1)
packages/shared/src/types/json.ts (1)
  • ClientTrustState (105-105)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

@pkg-pr-new

pkg-pr-newBot commented Nov 5, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7163

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7163

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7163

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7163

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7163

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7163

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7163

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7163

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7163

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7163

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7163

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7163

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7163

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7163

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7163

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7163

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7163

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7163

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7163

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7163

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7163

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7163

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7163

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7163

commit: eab6a9c

@blacksmith-sh

This comment has been minimized.

@blacksmith-sh

This comment was marked as resolved.

@tmilewski

Copy link
Copy Markdown
MemberAuthor

Pushing through. 429's are blocking the Next CI

@tmilewski
tmilewski merged commit a474c59 into mainNov 5, 2025
93 of 100 checks passed
@tmilewski
tmilewski deleted the tom/fix-client-trust-state branch November 5, 2025 21:19
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tmilewski@wobsoriano@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-js,shared): Move clientTrustState to SignIn - #7163

Merged
tmilewski merged 3 commits into
mainfrom
tom/fix-client-trust-state
Nov 5, 2025
Merged

fix(clerk-js,shared): Move clientTrustState to SignIn#7163
tmilewski merged 3 commits into
mainfrom
tom/fix-client-trust-state

Conversation

@tmilewski

@tmilewskitmilewski commented Nov 5, 2025

Copy link
Copy Markdown
Member

Description

Fixes a rebase issue where clientTrustState didn't get moved to SignIn.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Email-based authentication codes are now supported as a second-factor verification method.
  • Changes

    • Client trust state is now surfaced on the sign-in object instead of the client profile.
    • Public type surfaces updated to expose the trust state on sign-in and include the new second-factor option.

@vercel

vercelBot commented Nov 5, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentNov 5, 2025 8:51pm

@changeset-bot

changeset-botBot commented Nov 5, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eab6a9c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 22 packages
NameType
@clerk/clerk-jsPatch
@clerk/sharedPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/elementsPatch
@clerk/expo-passkeysPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/clerk-reactPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/themesPatch
@clerk/typesPatch
@clerk/vuePatch
@clerk/localizationsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Nov 5, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

clientTrustState is removed from Client (runtime and types) and added to SignIn (runtime and types); Client JSON no longer includes client_trust_state while SignIn JSON/snapshots may include it. SignInSecondFactor now includes EmailCodeFactor. A patch changeset records the move.

Changes

Cohort / File(s)Summary
Changeset
\.changeset/evil-aliens-hope.md
Adds a patch changeset documenting the behavioral rename: moving clientTrustState from Client to SignIn.
Client resource & JSON/types removed
packages/clerk-js/src/core/resources/Client.ts, packages/shared/src/types/client.ts, packages/shared/src/types/json.ts
Removes clientTrustState from the Client class and ClientResource interface; removes client_trust_state from ClientJSON; deletes related imports, initialization, (de)serialization code.
SignIn resource & types added
packages/clerk-js/src/core/resources/SignIn.ts, packages/shared/src/types/signIn.ts, packages/shared/src/types/snapshots.ts
Adds clientTrustState?: ClientTrustState to the SignIn class and SignInResource; adds client_trust_state?: ClientTrustState to SignIn JSON and snapshot shapes and imports ClientTrustState; populates from JSON.
SignIn second-factor expansion
packages/shared/src/types/signInCommon.ts
Extends SignInSecondFactor and AttemptSecondFactorParams unions to include EmailCodeFactor / EmailCodeAttempt.

Sequence Diagram(s)

sequenceDiagram
autonumber
participant API as Backend JSON
participant Client as Client (resource)
participant SignIn as SignIn (resource)
rect rgb(235,245,255)
Note over API,Client: Old flow (before change)
end
API->>Client: GET /client -> { ..., client_trust_state }
Client-->>API: serializes client (includes client_trust_state)
Note over Client: clientTrustState persisted on Client resource
Loading
sequenceDiagram
autonumber
participant API as Backend JSON
participant Client as Client (resource)
participant SignIn as SignIn (resource)
rect rgb(245,255,235)
Note over API,SignIn: New flow (after change)
end
API->>Client: GET /client -> { ... }
Note over Client: no client_trust_state persisted
API->>SignIn: GET /sign_in -> { ..., client_trust_state }
SignIn-->>API: serializes sign_in (includes client_trust_state)
Note over SignIn: clientTrustState persisted on SignIn resource
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

  • Focus areas:
    • packages/clerk-js/src/core/resources/Client.ts — verify all clientTrustState references removed and serialization snapshot updated.
    • packages/clerk-js/src/core/resources/SignIn.ts — confirm import, property typing, and fromJSON assignment for client_trust_state.
    • packages/shared/src/types/* — ensure JSON shapes, resource types, and snapshots are consistent.
    • packages/shared/src/types/signInCommon.ts — check callers for the new EmailCodeFactor/EmailCodeAttempt variants.

Poem

🐰 I hopped from Client to SignIn with glee,
A trust-state moved, now fresh and free.
Email codes joined the second-factor tune,
The rabbit winks beneath the moon 🌙
Change shipped swift — a happy hop, hooray!

Pre-merge checks and finishing touches

✅ Passed checks (2 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title directly and clearly summarizes the main change: moving clientTrustState from Client to SignIn, which aligns with the primary objective of this bug fix PR.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch tom/fix-client-trust-state

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between ba05615 and eab6a9c.

📒 Files selected for processing (1)
  • packages/shared/src/types/signInCommon.ts (2 hunks)
🧰 Additional context used
📓 Path-based instructions (6)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/shared/src/types/signInCommon.ts
packages/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/shared/src/types/signInCommon.ts
packages/**/*.{ts,tsx,d.ts}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Packages should export TypeScript types alongside runtime code

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Prefer readonly for properties that shouldn't change after construction
Prefer composition and interfaces over deep inheritance chains
Use mixins for shared behavior across unrelated classes
Implement dependency injection for loose coupling
Let TypeScript infer when types are obvious
Use const assertions for literal types: as const
Use satisfies operator for type checking without widening
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Use type-only imports: import type { ... } from ...
No any types without justification
Proper error handling with typed errors
Consistent use of readonly for immutable data
Proper generic constraints
No unused type parameters
Proper use of utility types instead of manual type construction
Type-only imports where possible
Proper tree-shaking friendly exports
No circular dependencies
Efficient type computations (avoid deep recursion)

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/shared/src/types/signInCommon.ts
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (3)
packages/shared/src/types/signInCommon.ts (3)

122-122: LGTM!

The addition of EmailCodeAttempt is consistent with EmailCodeFactor being added to SignInSecondFactor on line 88, maintaining proper alignment between factor types and their attempt parameters.


120-120: I need to check the actual implementation and definitions in the codebase to understand whether this is intentional design.

Review comment is incorrect and should be disregarded.

According to Clerk's official documentation, if the strategy is set to TOTP, it does not require preparation and you can directly attempt the second factor verification. Only the phone_code strategy requires calling the prepareSecondFactor method.

The asymmetry between PrepareSecondFactorParams (only PhoneCodeSecondFactorConfig) and AttemptSecondFactorParams (four factor types) is intentional by Clerk's design. Backup codes are a fallback when the user is unable to use their primary MFA method, and do not require a separate preparation step. EmailCode and TOTP similarly do not require preparation configuration, which is why no corresponding config types exist for them.

The type definition is correct and complete.

Likely an incorrect or invalid review comment.


88-88: EmailCodeFactor as second factor is intentional and properly implemented.

The changes add email code authentication as a supported second factor, paralleling existing patterns for phone code and backup code. The generic attemptSecondFactor implementation accepts {strategy, code} parameters, which EmailCodeAttempt provides. Types are properly exported and integrated into verification machines and UI components (clerk-js, elements packages). The addition to both SignInFirstFactor and SignInSecondFactor is correct—email authentication is designed to work as both primary and secondary authentication.


Comment @coderabbitai help to get the list of available commands and usage tips.

@tmilewskitmilewski changed the title fix: Move clientTrustState to SignInfix(clerk-js,shared): Move clientTrustState to SignInNov 5, 2025
@tmilewskitmilewski self-assigned this Nov 5, 2025
@tmilewski

Copy link
Copy Markdown
MemberAuthor

@coderabbitai full review

@coderabbitai

Copy link
Copy Markdown
Contributor
✅ Actions performed

Full review triggered.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/shared/src/types/signIn.ts (1)

46-46: LGTM! Consider adding JSDoc for the new property.

The clientTrustState property is correctly added to both interfaces with appropriate types and optional modifiers for backward compatibility. The naming follows conventions (camelCase in resource, snake_case in JSON).

Consider adding JSDoc documentation to explain what this property represents and its possible values, as per coding guidelines for public APIs.

Example JSDoc for line 46:

+ /**+ * The trust state of the client device for this sign-in attempt.+ * Possible values: 'new', 'known', 'pending'.+ */
clientTrustState?: ClientTrustState;

Also applies to: 99-99

📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 9ffa221 and ba05615.

📒 Files selected for processing (1)
  • packages/shared/src/types/signIn.ts (3 hunks)
🧰 Additional context used
📓 Path-based instructions (6)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/shared/src/types/signIn.ts
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/shared/src/types/signIn.ts
packages/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/shared/src/types/signIn.ts
packages/**/*.{ts,tsx,d.ts}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Packages should export TypeScript types alongside runtime code

Files:

  • packages/shared/src/types/signIn.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Prefer readonly for properties that shouldn't change after construction
Prefer composition and interfaces over deep inheritance chains
Use mixins for shared behavior across unrelated classes
Implement dependency injection for loose coupling
Let TypeScript infer when types are obvious
Use const assertions for literal types: as const
Use satisfies operator for type checking without widening
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Use type-only imports: import type { ... } from ...
No any types without justification
Proper error handling with typed errors
Consistent use of readonly for immutable data
Proper generic constraints
No unused type parameters
Proper use of utility types instead of manual type construction
Type-only imports where possible
Proper tree-shaking friendly exports
No circular dependencies
Efficient type computations (avoid deep recursion)

Files:

  • packages/shared/src/types/signIn.ts
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/shared/src/types/signIn.ts
🧬 Code graph analysis (1)
packages/shared/src/types/signIn.ts (1)
packages/shared/src/types/json.ts (1)
  • ClientTrustState (105-105)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

@pkg-pr-new

pkg-pr-newBot commented Nov 5, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7163

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7163

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7163

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7163

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7163

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7163

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7163

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7163

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7163

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7163

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7163

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7163

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7163

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7163

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7163

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7163

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7163

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7163

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7163

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7163

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7163

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7163

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7163

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7163

commit: eab6a9c

@blacksmith-sh

This comment has been minimized.

@blacksmith-sh

This comment was marked as resolved.

@tmilewski

Copy link
Copy Markdown
MemberAuthor

Pushing through. 429's are blocking the Next CI

@tmilewski
tmilewski merged commit a474c59 into mainNov 5, 2025
93 of 100 checks passed
@tmilewski
tmilewski deleted the tom/fix-client-trust-state branch November 5, 2025 21:19
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tmilewski@wobsoriano@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-js,shared): Move clientTrustState to SignIn - #7163

Merged
tmilewski merged 3 commits into
mainfrom
tom/fix-client-trust-state
Nov 5, 2025
Merged

fix(clerk-js,shared): Move clientTrustState to SignIn#7163
tmilewski merged 3 commits into
mainfrom
tom/fix-client-trust-state

Conversation

@tmilewski

@tmilewskitmilewski commented Nov 5, 2025

Copy link
Copy Markdown
Member

Description

Fixes a rebase issue where clientTrustState didn't get moved to SignIn.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Email-based authentication codes are now supported as a second-factor verification method.
  • Changes

    • Client trust state is now surfaced on the sign-in object instead of the client profile.
    • Public type surfaces updated to expose the trust state on sign-in and include the new second-factor option.

@vercel

vercelBot commented Nov 5, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentNov 5, 2025 8:51pm

@changeset-bot

changeset-botBot commented Nov 5, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eab6a9c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 22 packages
NameType
@clerk/clerk-jsPatch
@clerk/sharedPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/elementsPatch
@clerk/expo-passkeysPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/clerk-reactPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/themesPatch
@clerk/typesPatch
@clerk/vuePatch
@clerk/localizationsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Nov 5, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

clientTrustState is removed from Client (runtime and types) and added to SignIn (runtime and types); Client JSON no longer includes client_trust_state while SignIn JSON/snapshots may include it. SignInSecondFactor now includes EmailCodeFactor. A patch changeset records the move.

Changes

Cohort / File(s)Summary
Changeset
\.changeset/evil-aliens-hope.md
Adds a patch changeset documenting the behavioral rename: moving clientTrustState from Client to SignIn.
Client resource & JSON/types removed
packages/clerk-js/src/core/resources/Client.ts, packages/shared/src/types/client.ts, packages/shared/src/types/json.ts
Removes clientTrustState from the Client class and ClientResource interface; removes client_trust_state from ClientJSON; deletes related imports, initialization, (de)serialization code.
SignIn resource & types added
packages/clerk-js/src/core/resources/SignIn.ts, packages/shared/src/types/signIn.ts, packages/shared/src/types/snapshots.ts
Adds clientTrustState?: ClientTrustState to the SignIn class and SignInResource; adds client_trust_state?: ClientTrustState to SignIn JSON and snapshot shapes and imports ClientTrustState; populates from JSON.
SignIn second-factor expansion
packages/shared/src/types/signInCommon.ts
Extends SignInSecondFactor and AttemptSecondFactorParams unions to include EmailCodeFactor / EmailCodeAttempt.

Sequence Diagram(s)

sequenceDiagram
autonumber
participant API as Backend JSON
participant Client as Client (resource)
participant SignIn as SignIn (resource)
rect rgb(235,245,255)
Note over API,Client: Old flow (before change)
end
API->>Client: GET /client -> { ..., client_trust_state }
Client-->>API: serializes client (includes client_trust_state)
Note over Client: clientTrustState persisted on Client resource
Loading
sequenceDiagram
autonumber
participant API as Backend JSON
participant Client as Client (resource)
participant SignIn as SignIn (resource)
rect rgb(245,255,235)
Note over API,SignIn: New flow (after change)
end
API->>Client: GET /client -> { ... }
Note over Client: no client_trust_state persisted
API->>SignIn: GET /sign_in -> { ..., client_trust_state }
SignIn-->>API: serializes sign_in (includes client_trust_state)
Note over SignIn: clientTrustState persisted on SignIn resource
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

  • Focus areas:
    • packages/clerk-js/src/core/resources/Client.ts — verify all clientTrustState references removed and serialization snapshot updated.
    • packages/clerk-js/src/core/resources/SignIn.ts — confirm import, property typing, and fromJSON assignment for client_trust_state.
    • packages/shared/src/types/* — ensure JSON shapes, resource types, and snapshots are consistent.
    • packages/shared/src/types/signInCommon.ts — check callers for the new EmailCodeFactor/EmailCodeAttempt variants.

Poem

🐰 I hopped from Client to SignIn with glee,
A trust-state moved, now fresh and free.
Email codes joined the second-factor tune,
The rabbit winks beneath the moon 🌙
Change shipped swift — a happy hop, hooray!

Pre-merge checks and finishing touches

✅ Passed checks (2 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title directly and clearly summarizes the main change: moving clientTrustState from Client to SignIn, which aligns with the primary objective of this bug fix PR.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch tom/fix-client-trust-state

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between ba05615 and eab6a9c.

📒 Files selected for processing (1)
  • packages/shared/src/types/signInCommon.ts (2 hunks)
🧰 Additional context used
📓 Path-based instructions (6)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/shared/src/types/signInCommon.ts
packages/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/shared/src/types/signInCommon.ts
packages/**/*.{ts,tsx,d.ts}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Packages should export TypeScript types alongside runtime code

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Prefer readonly for properties that shouldn't change after construction
Prefer composition and interfaces over deep inheritance chains
Use mixins for shared behavior across unrelated classes
Implement dependency injection for loose coupling
Let TypeScript infer when types are obvious
Use const assertions for literal types: as const
Use satisfies operator for type checking without widening
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Use type-only imports: import type { ... } from ...
No any types without justification
Proper error handling with typed errors
Consistent use of readonly for immutable data
Proper generic constraints
No unused type parameters
Proper use of utility types instead of manual type construction
Type-only imports where possible
Proper tree-shaking friendly exports
No circular dependencies
Efficient type computations (avoid deep recursion)

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/shared/src/types/signInCommon.ts
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (3)
packages/shared/src/types/signInCommon.ts (3)

122-122: LGTM!

The addition of EmailCodeAttempt is consistent with EmailCodeFactor being added to SignInSecondFactor on line 88, maintaining proper alignment between factor types and their attempt parameters.


120-120: I need to check the actual implementation and definitions in the codebase to understand whether this is intentional design.

Review comment is incorrect and should be disregarded.

According to Clerk's official documentation, if the strategy is set to TOTP, it does not require preparation and you can directly attempt the second factor verification. Only the phone_code strategy requires calling the prepareSecondFactor method.

The asymmetry between PrepareSecondFactorParams (only PhoneCodeSecondFactorConfig) and AttemptSecondFactorParams (four factor types) is intentional by Clerk's design. Backup codes are a fallback when the user is unable to use their primary MFA method, and do not require a separate preparation step. EmailCode and TOTP similarly do not require preparation configuration, which is why no corresponding config types exist for them.

The type definition is correct and complete.

Likely an incorrect or invalid review comment.


88-88: EmailCodeFactor as second factor is intentional and properly implemented.

The changes add email code authentication as a supported second factor, paralleling existing patterns for phone code and backup code. The generic attemptSecondFactor implementation accepts {strategy, code} parameters, which EmailCodeAttempt provides. Types are properly exported and integrated into verification machines and UI components (clerk-js, elements packages). The addition to both SignInFirstFactor and SignInSecondFactor is correct—email authentication is designed to work as both primary and secondary authentication.


Comment @coderabbitai help to get the list of available commands and usage tips.

@tmilewskitmilewski changed the title fix: Move clientTrustState to SignInfix(clerk-js,shared): Move clientTrustState to SignInNov 5, 2025
@tmilewskitmilewski self-assigned this Nov 5, 2025
@tmilewski

Copy link
Copy Markdown
MemberAuthor

@coderabbitai full review

@coderabbitai

Copy link
Copy Markdown
Contributor
✅ Actions performed

Full review triggered.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/shared/src/types/signIn.ts (1)

46-46: LGTM! Consider adding JSDoc for the new property.

The clientTrustState property is correctly added to both interfaces with appropriate types and optional modifiers for backward compatibility. The naming follows conventions (camelCase in resource, snake_case in JSON).

Consider adding JSDoc documentation to explain what this property represents and its possible values, as per coding guidelines for public APIs.

Example JSDoc for line 46:

+ /**+ * The trust state of the client device for this sign-in attempt.+ * Possible values: 'new', 'known', 'pending'.+ */
clientTrustState?: ClientTrustState;

Also applies to: 99-99

📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 9ffa221 and ba05615.

📒 Files selected for processing (1)
  • packages/shared/src/types/signIn.ts (3 hunks)
🧰 Additional context used
📓 Path-based instructions (6)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/shared/src/types/signIn.ts
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/shared/src/types/signIn.ts
packages/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/shared/src/types/signIn.ts
packages/**/*.{ts,tsx,d.ts}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Packages should export TypeScript types alongside runtime code

Files:

  • packages/shared/src/types/signIn.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Prefer readonly for properties that shouldn't change after construction
Prefer composition and interfaces over deep inheritance chains
Use mixins for shared behavior across unrelated classes
Implement dependency injection for loose coupling
Let TypeScript infer when types are obvious
Use const assertions for literal types: as const
Use satisfies operator for type checking without widening
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Use type-only imports: import type { ... } from ...
No any types without justification
Proper error handling with typed errors
Consistent use of readonly for immutable data
Proper generic constraints
No unused type parameters
Proper use of utility types instead of manual type construction
Type-only imports where possible
Proper tree-shaking friendly exports
No circular dependencies
Efficient type computations (avoid deep recursion)

Files:

  • packages/shared/src/types/signIn.ts
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/shared/src/types/signIn.ts
🧬 Code graph analysis (1)
packages/shared/src/types/signIn.ts (1)
packages/shared/src/types/json.ts (1)
  • ClientTrustState (105-105)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

@pkg-pr-new

pkg-pr-newBot commented Nov 5, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7163

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7163

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7163

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7163

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7163

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7163

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7163

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7163

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7163

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7163

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7163

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7163

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7163

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7163

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7163

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7163

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7163

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7163

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7163

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7163

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7163

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7163

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7163

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7163

commit: eab6a9c

@blacksmith-sh

This comment has been minimized.

@blacksmith-sh

This comment was marked as resolved.

@tmilewski

Copy link
Copy Markdown
MemberAuthor

Pushing through. 429's are blocking the Next CI

@tmilewski
tmilewski merged commit a474c59 into mainNov 5, 2025
93 of 100 checks passed
@tmilewski
tmilewski deleted the tom/fix-client-trust-state branch November 5, 2025 21:19
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tmilewski@wobsoriano@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(clerk-js,shared): Move clientTrustState to SignIn - #7163

Merged
tmilewski merged 3 commits into
mainfrom
tom/fix-client-trust-state
Nov 5, 2025
Merged

fix(clerk-js,shared): Move clientTrustState to SignIn#7163
tmilewski merged 3 commits into
mainfrom
tom/fix-client-trust-state

Conversation

@tmilewski

@tmilewskitmilewski commented Nov 5, 2025

Copy link
Copy Markdown
Member

Description

Fixes a rebase issue where clientTrustState didn't get moved to SignIn.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Email-based authentication codes are now supported as a second-factor verification method.
  • Changes

    • Client trust state is now surfaced on the sign-in object instead of the client profile.
    • Public type surfaces updated to expose the trust state on sign-in and include the new second-factor option.

@vercel

vercelBot commented Nov 5, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentNov 5, 2025 8:51pm

@changeset-bot

changeset-botBot commented Nov 5, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eab6a9c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 22 packages
NameType
@clerk/clerk-jsPatch
@clerk/sharedPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/elementsPatch
@clerk/expo-passkeysPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/clerk-reactPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/themesPatch
@clerk/typesPatch
@clerk/vuePatch
@clerk/localizationsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Nov 5, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

clientTrustState is removed from Client (runtime and types) and added to SignIn (runtime and types); Client JSON no longer includes client_trust_state while SignIn JSON/snapshots may include it. SignInSecondFactor now includes EmailCodeFactor. A patch changeset records the move.

Changes

Cohort / File(s)Summary
Changeset
\.changeset/evil-aliens-hope.md
Adds a patch changeset documenting the behavioral rename: moving clientTrustState from Client to SignIn.
Client resource & JSON/types removed
packages/clerk-js/src/core/resources/Client.ts, packages/shared/src/types/client.ts, packages/shared/src/types/json.ts
Removes clientTrustState from the Client class and ClientResource interface; removes client_trust_state from ClientJSON; deletes related imports, initialization, (de)serialization code.
SignIn resource & types added
packages/clerk-js/src/core/resources/SignIn.ts, packages/shared/src/types/signIn.ts, packages/shared/src/types/snapshots.ts
Adds clientTrustState?: ClientTrustState to the SignIn class and SignInResource; adds client_trust_state?: ClientTrustState to SignIn JSON and snapshot shapes and imports ClientTrustState; populates from JSON.
SignIn second-factor expansion
packages/shared/src/types/signInCommon.ts
Extends SignInSecondFactor and AttemptSecondFactorParams unions to include EmailCodeFactor / EmailCodeAttempt.

Sequence Diagram(s)

sequenceDiagram
autonumber
participant API as Backend JSON
participant Client as Client (resource)
participant SignIn as SignIn (resource)
rect rgb(235,245,255)
Note over API,Client: Old flow (before change)
end
API->>Client: GET /client -> { ..., client_trust_state }
Client-->>API: serializes client (includes client_trust_state)
Note over Client: clientTrustState persisted on Client resource
Loading
sequenceDiagram
autonumber
participant API as Backend JSON
participant Client as Client (resource)
participant SignIn as SignIn (resource)
rect rgb(245,255,235)
Note over API,SignIn: New flow (after change)
end
API->>Client: GET /client -> { ... }
Note over Client: no client_trust_state persisted
API->>SignIn: GET /sign_in -> { ..., client_trust_state }
SignIn-->>API: serializes sign_in (includes client_trust_state)
Note over SignIn: clientTrustState persisted on SignIn resource
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

  • Focus areas:
    • packages/clerk-js/src/core/resources/Client.ts — verify all clientTrustState references removed and serialization snapshot updated.
    • packages/clerk-js/src/core/resources/SignIn.ts — confirm import, property typing, and fromJSON assignment for client_trust_state.
    • packages/shared/src/types/* — ensure JSON shapes, resource types, and snapshots are consistent.
    • packages/shared/src/types/signInCommon.ts — check callers for the new EmailCodeFactor/EmailCodeAttempt variants.

Poem

🐰 I hopped from Client to SignIn with glee,
A trust-state moved, now fresh and free.
Email codes joined the second-factor tune,
The rabbit winks beneath the moon 🌙
Change shipped swift — a happy hop, hooray!

Pre-merge checks and finishing touches

✅ Passed checks (2 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title directly and clearly summarizes the main change: moving clientTrustState from Client to SignIn, which aligns with the primary objective of this bug fix PR.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch tom/fix-client-trust-state

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between ba05615 and eab6a9c.

📒 Files selected for processing (1)
  • packages/shared/src/types/signInCommon.ts (2 hunks)
🧰 Additional context used
📓 Path-based instructions (6)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/shared/src/types/signInCommon.ts
packages/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/shared/src/types/signInCommon.ts
packages/**/*.{ts,tsx,d.ts}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Packages should export TypeScript types alongside runtime code

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Prefer readonly for properties that shouldn't change after construction
Prefer composition and interfaces over deep inheritance chains
Use mixins for shared behavior across unrelated classes
Implement dependency injection for loose coupling
Let TypeScript infer when types are obvious
Use const assertions for literal types: as const
Use satisfies operator for type checking without widening
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Use type-only imports: import type { ... } from ...
No any types without justification
Proper error handling with typed errors
Consistent use of readonly for immutable data
Proper generic constraints
No unused type parameters
Proper use of utility types instead of manual type construction
Type-only imports where possible
Proper tree-shaking friendly exports
No circular dependencies
Efficient type computations (avoid deep recursion)

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/shared/src/types/signInCommon.ts
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (3)
packages/shared/src/types/signInCommon.ts (3)

122-122: LGTM!

The addition of EmailCodeAttempt is consistent with EmailCodeFactor being added to SignInSecondFactor on line 88, maintaining proper alignment between factor types and their attempt parameters.


120-120: I need to check the actual implementation and definitions in the codebase to understand whether this is intentional design.

Review comment is incorrect and should be disregarded.

According to Clerk's official documentation, if the strategy is set to TOTP, it does not require preparation and you can directly attempt the second factor verification. Only the phone_code strategy requires calling the prepareSecondFactor method.

The asymmetry between PrepareSecondFactorParams (only PhoneCodeSecondFactorConfig) and AttemptSecondFactorParams (four factor types) is intentional by Clerk's design. Backup codes are a fallback when the user is unable to use their primary MFA method, and do not require a separate preparation step. EmailCode and TOTP similarly do not require preparation configuration, which is why no corresponding config types exist for them.

The type definition is correct and complete.

Likely an incorrect or invalid review comment.


88-88: EmailCodeFactor as second factor is intentional and properly implemented.

The changes add email code authentication as a supported second factor, paralleling existing patterns for phone code and backup code. The generic attemptSecondFactor implementation accepts {strategy, code} parameters, which EmailCodeAttempt provides. Types are properly exported and integrated into verification machines and UI components (clerk-js, elements packages). The addition to both SignInFirstFactor and SignInSecondFactor is correct—email authentication is designed to work as both primary and secondary authentication.


Comment @coderabbitai help to get the list of available commands and usage tips.

@tmilewskitmilewski changed the title fix: Move clientTrustState to SignInfix(clerk-js,shared): Move clientTrustState to SignInNov 5, 2025
@tmilewskitmilewski self-assigned this Nov 5, 2025
@tmilewski

Copy link
Copy Markdown
MemberAuthor

@coderabbitai full review

@coderabbitai

Copy link
Copy Markdown
Contributor
✅ Actions performed

Full review triggered.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/shared/src/types/signIn.ts (1)

46-46: LGTM! Consider adding JSDoc for the new property.

The clientTrustState property is correctly added to both interfaces with appropriate types and optional modifiers for backward compatibility. The naming follows conventions (camelCase in resource, snake_case in JSON).

Consider adding JSDoc documentation to explain what this property represents and its possible values, as per coding guidelines for public APIs.

Example JSDoc for line 46:

+ /**+ * The trust state of the client device for this sign-in attempt.+ * Possible values: 'new', 'known', 'pending'.+ */
clientTrustState?: ClientTrustState;

Also applies to: 99-99

📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 9ffa221 and ba05615.

📒 Files selected for processing (1)
  • packages/shared/src/types/signIn.ts (3 hunks)
🧰 Additional context used
📓 Path-based instructions (6)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/shared/src/types/signIn.ts
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/shared/src/types/signIn.ts
packages/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/shared/src/types/signIn.ts
packages/**/*.{ts,tsx,d.ts}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Packages should export TypeScript types alongside runtime code

Files:

  • packages/shared/src/types/signIn.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Prefer readonly for properties that shouldn't change after construction
Prefer composition and interfaces over deep inheritance chains
Use mixins for shared behavior across unrelated classes
Implement dependency injection for loose coupling
Let TypeScript infer when types are obvious
Use const assertions for literal types: as const
Use satisfies operator for type checking without widening
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Use type-only imports: import type { ... } from ...
No any types without justification
Proper error handling with typed errors
Consistent use of readonly for immutable data
Proper generic constraints
No unused type parameters
Proper use of utility types instead of manual type construction
Type-only imports where possible
Proper tree-shaking friendly exports
No circular dependencies
Efficient type computations (avoid deep recursion)

Files:

  • packages/shared/src/types/signIn.ts
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/shared/src/types/signIn.ts
🧬 Code graph analysis (1)
packages/shared/src/types/signIn.ts (1)
packages/shared/src/types/json.ts (1)
  • ClientTrustState (105-105)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

@pkg-pr-new

pkg-pr-newBot commented Nov 5, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7163

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7163

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7163

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7163

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7163

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7163

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7163

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7163

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7163

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7163

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7163

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7163

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7163

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7163

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7163

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7163

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7163

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7163

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7163

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7163

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7163

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7163

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7163

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7163

commit: eab6a9c

@blacksmith-sh

This comment has been minimized.

@blacksmith-sh

This comment was marked as resolved.

@tmilewski

Copy link
Copy Markdown
MemberAuthor

Pushing through. 429's are blocking the Next CI

@tmilewski
tmilewski merged commit a474c59 into mainNov 5, 2025
93 of 100 checks passed
@tmilewski
tmilewski deleted the tom/fix-client-trust-state branch November 5, 2025 21:19
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tmilewski@wobsoriano@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-js,shared): Move clientTrustState to SignIn - #7163

Merged
tmilewski merged 3 commits into
mainfrom
tom/fix-client-trust-state
Nov 5, 2025
Merged

fix(clerk-js,shared): Move clientTrustState to SignIn#7163
tmilewski merged 3 commits into
mainfrom
tom/fix-client-trust-state

Conversation

@tmilewski

@tmilewskitmilewski commented Nov 5, 2025

Copy link
Copy Markdown
Member

Description

Fixes a rebase issue where clientTrustState didn't get moved to SignIn.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Email-based authentication codes are now supported as a second-factor verification method.
  • Changes

    • Client trust state is now surfaced on the sign-in object instead of the client profile.
    • Public type surfaces updated to expose the trust state on sign-in and include the new second-factor option.

@vercel

vercelBot commented Nov 5, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentNov 5, 2025 8:51pm

@changeset-bot

changeset-botBot commented Nov 5, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eab6a9c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 22 packages
NameType
@clerk/clerk-jsPatch
@clerk/sharedPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/elementsPatch
@clerk/expo-passkeysPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/clerk-reactPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/themesPatch
@clerk/typesPatch
@clerk/vuePatch
@clerk/localizationsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Nov 5, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

clientTrustState is removed from Client (runtime and types) and added to SignIn (runtime and types); Client JSON no longer includes client_trust_state while SignIn JSON/snapshots may include it. SignInSecondFactor now includes EmailCodeFactor. A patch changeset records the move.

Changes

Cohort / File(s)Summary
Changeset
\.changeset/evil-aliens-hope.md
Adds a patch changeset documenting the behavioral rename: moving clientTrustState from Client to SignIn.
Client resource & JSON/types removed
packages/clerk-js/src/core/resources/Client.ts, packages/shared/src/types/client.ts, packages/shared/src/types/json.ts
Removes clientTrustState from the Client class and ClientResource interface; removes client_trust_state from ClientJSON; deletes related imports, initialization, (de)serialization code.
SignIn resource & types added
packages/clerk-js/src/core/resources/SignIn.ts, packages/shared/src/types/signIn.ts, packages/shared/src/types/snapshots.ts
Adds clientTrustState?: ClientTrustState to the SignIn class and SignInResource; adds client_trust_state?: ClientTrustState to SignIn JSON and snapshot shapes and imports ClientTrustState; populates from JSON.
SignIn second-factor expansion
packages/shared/src/types/signInCommon.ts
Extends SignInSecondFactor and AttemptSecondFactorParams unions to include EmailCodeFactor / EmailCodeAttempt.

Sequence Diagram(s)

sequenceDiagram
autonumber
participant API as Backend JSON
participant Client as Client (resource)
participant SignIn as SignIn (resource)
rect rgb(235,245,255)
Note over API,Client: Old flow (before change)
end
API->>Client: GET /client -> { ..., client_trust_state }
Client-->>API: serializes client (includes client_trust_state)
Note over Client: clientTrustState persisted on Client resource
Loading
sequenceDiagram
autonumber
participant API as Backend JSON
participant Client as Client (resource)
participant SignIn as SignIn (resource)
rect rgb(245,255,235)
Note over API,SignIn: New flow (after change)
end
API->>Client: GET /client -> { ... }
Note over Client: no client_trust_state persisted
API->>SignIn: GET /sign_in -> { ..., client_trust_state }
SignIn-->>API: serializes sign_in (includes client_trust_state)
Note over SignIn: clientTrustState persisted on SignIn resource
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

  • Focus areas:
    • packages/clerk-js/src/core/resources/Client.ts — verify all clientTrustState references removed and serialization snapshot updated.
    • packages/clerk-js/src/core/resources/SignIn.ts — confirm import, property typing, and fromJSON assignment for client_trust_state.
    • packages/shared/src/types/* — ensure JSON shapes, resource types, and snapshots are consistent.
    • packages/shared/src/types/signInCommon.ts — check callers for the new EmailCodeFactor/EmailCodeAttempt variants.

Poem

🐰 I hopped from Client to SignIn with glee,
A trust-state moved, now fresh and free.
Email codes joined the second-factor tune,
The rabbit winks beneath the moon 🌙
Change shipped swift — a happy hop, hooray!

Pre-merge checks and finishing touches

✅ Passed checks (2 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title directly and clearly summarizes the main change: moving clientTrustState from Client to SignIn, which aligns with the primary objective of this bug fix PR.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch tom/fix-client-trust-state

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between ba05615 and eab6a9c.

📒 Files selected for processing (1)
  • packages/shared/src/types/signInCommon.ts (2 hunks)
🧰 Additional context used
📓 Path-based instructions (6)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/shared/src/types/signInCommon.ts
packages/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/shared/src/types/signInCommon.ts
packages/**/*.{ts,tsx,d.ts}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Packages should export TypeScript types alongside runtime code

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Prefer readonly for properties that shouldn't change after construction
Prefer composition and interfaces over deep inheritance chains
Use mixins for shared behavior across unrelated classes
Implement dependency injection for loose coupling
Let TypeScript infer when types are obvious
Use const assertions for literal types: as const
Use satisfies operator for type checking without widening
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Use type-only imports: import type { ... } from ...
No any types without justification
Proper error handling with typed errors
Consistent use of readonly for immutable data
Proper generic constraints
No unused type parameters
Proper use of utility types instead of manual type construction
Type-only imports where possible
Proper tree-shaking friendly exports
No circular dependencies
Efficient type computations (avoid deep recursion)

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/shared/src/types/signInCommon.ts
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (3)
packages/shared/src/types/signInCommon.ts (3)

122-122: LGTM!

The addition of EmailCodeAttempt is consistent with EmailCodeFactor being added to SignInSecondFactor on line 88, maintaining proper alignment between factor types and their attempt parameters.


120-120: I need to check the actual implementation and definitions in the codebase to understand whether this is intentional design.

Review comment is incorrect and should be disregarded.

According to Clerk's official documentation, if the strategy is set to TOTP, it does not require preparation and you can directly attempt the second factor verification. Only the phone_code strategy requires calling the prepareSecondFactor method.

The asymmetry between PrepareSecondFactorParams (only PhoneCodeSecondFactorConfig) and AttemptSecondFactorParams (four factor types) is intentional by Clerk's design. Backup codes are a fallback when the user is unable to use their primary MFA method, and do not require a separate preparation step. EmailCode and TOTP similarly do not require preparation configuration, which is why no corresponding config types exist for them.

The type definition is correct and complete.

Likely an incorrect or invalid review comment.


88-88: EmailCodeFactor as second factor is intentional and properly implemented.

The changes add email code authentication as a supported second factor, paralleling existing patterns for phone code and backup code. The generic attemptSecondFactor implementation accepts {strategy, code} parameters, which EmailCodeAttempt provides. Types are properly exported and integrated into verification machines and UI components (clerk-js, elements packages). The addition to both SignInFirstFactor and SignInSecondFactor is correct—email authentication is designed to work as both primary and secondary authentication.


Comment @coderabbitai help to get the list of available commands and usage tips.

@tmilewskitmilewski changed the title fix: Move clientTrustState to SignInfix(clerk-js,shared): Move clientTrustState to SignInNov 5, 2025
@tmilewskitmilewski self-assigned this Nov 5, 2025
@tmilewski

Copy link
Copy Markdown
MemberAuthor

@coderabbitai full review

@coderabbitai

Copy link
Copy Markdown
Contributor
✅ Actions performed

Full review triggered.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/shared/src/types/signIn.ts (1)

46-46: LGTM! Consider adding JSDoc for the new property.

The clientTrustState property is correctly added to both interfaces with appropriate types and optional modifiers for backward compatibility. The naming follows conventions (camelCase in resource, snake_case in JSON).

Consider adding JSDoc documentation to explain what this property represents and its possible values, as per coding guidelines for public APIs.

Example JSDoc for line 46:

+ /**+ * The trust state of the client device for this sign-in attempt.+ * Possible values: 'new', 'known', 'pending'.+ */
clientTrustState?: ClientTrustState;

Also applies to: 99-99

📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 9ffa221 and ba05615.

📒 Files selected for processing (1)
  • packages/shared/src/types/signIn.ts (3 hunks)
🧰 Additional context used
📓 Path-based instructions (6)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/shared/src/types/signIn.ts
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/shared/src/types/signIn.ts
packages/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/shared/src/types/signIn.ts
packages/**/*.{ts,tsx,d.ts}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Packages should export TypeScript types alongside runtime code

Files:

  • packages/shared/src/types/signIn.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Prefer readonly for properties that shouldn't change after construction
Prefer composition and interfaces over deep inheritance chains
Use mixins for shared behavior across unrelated classes
Implement dependency injection for loose coupling
Let TypeScript infer when types are obvious
Use const assertions for literal types: as const
Use satisfies operator for type checking without widening
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Use type-only imports: import type { ... } from ...
No any types without justification
Proper error handling with typed errors
Consistent use of readonly for immutable data
Proper generic constraints
No unused type parameters
Proper use of utility types instead of manual type construction
Type-only imports where possible
Proper tree-shaking friendly exports
No circular dependencies
Efficient type computations (avoid deep recursion)

Files:

  • packages/shared/src/types/signIn.ts
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/shared/src/types/signIn.ts
🧬 Code graph analysis (1)
packages/shared/src/types/signIn.ts (1)
packages/shared/src/types/json.ts (1)
  • ClientTrustState (105-105)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

@pkg-pr-new

pkg-pr-newBot commented Nov 5, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7163

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7163

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7163

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7163

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7163

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7163

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7163

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7163

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7163

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7163

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7163

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7163

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7163

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7163

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7163

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7163

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7163

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7163

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7163

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7163

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7163

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7163

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7163

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7163

commit: eab6a9c

@blacksmith-sh

This comment has been minimized.

@blacksmith-sh

This comment was marked as resolved.

@tmilewski

Copy link
Copy Markdown
MemberAuthor

Pushing through. 429's are blocking the Next CI

@tmilewski
tmilewski merged commit a474c59 into mainNov 5, 2025
93 of 100 checks passed
@tmilewski
tmilewski deleted the tom/fix-client-trust-state branch November 5, 2025 21:19
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tmilewski@wobsoriano@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-js,shared): Move clientTrustState to SignIn - #7163

Merged
tmilewski merged 3 commits into
mainfrom
tom/fix-client-trust-state
Nov 5, 2025
Merged

fix(clerk-js,shared): Move clientTrustState to SignIn#7163
tmilewski merged 3 commits into
mainfrom
tom/fix-client-trust-state

Conversation

@tmilewski

@tmilewskitmilewski commented Nov 5, 2025

Copy link
Copy Markdown
Member

Description

Fixes a rebase issue where clientTrustState didn't get moved to SignIn.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Email-based authentication codes are now supported as a second-factor verification method.
  • Changes

    • Client trust state is now surfaced on the sign-in object instead of the client profile.
    • Public type surfaces updated to expose the trust state on sign-in and include the new second-factor option.

@vercel

vercelBot commented Nov 5, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentNov 5, 2025 8:51pm

@changeset-bot

changeset-botBot commented Nov 5, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eab6a9c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 22 packages
NameType
@clerk/clerk-jsPatch
@clerk/sharedPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/elementsPatch
@clerk/expo-passkeysPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/clerk-reactPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/themesPatch
@clerk/typesPatch
@clerk/vuePatch
@clerk/localizationsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Nov 5, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

clientTrustState is removed from Client (runtime and types) and added to SignIn (runtime and types); Client JSON no longer includes client_trust_state while SignIn JSON/snapshots may include it. SignInSecondFactor now includes EmailCodeFactor. A patch changeset records the move.

Changes

Cohort / File(s)Summary
Changeset
\.changeset/evil-aliens-hope.md
Adds a patch changeset documenting the behavioral rename: moving clientTrustState from Client to SignIn.
Client resource & JSON/types removed
packages/clerk-js/src/core/resources/Client.ts, packages/shared/src/types/client.ts, packages/shared/src/types/json.ts
Removes clientTrustState from the Client class and ClientResource interface; removes client_trust_state from ClientJSON; deletes related imports, initialization, (de)serialization code.
SignIn resource & types added
packages/clerk-js/src/core/resources/SignIn.ts, packages/shared/src/types/signIn.ts, packages/shared/src/types/snapshots.ts
Adds clientTrustState?: ClientTrustState to the SignIn class and SignInResource; adds client_trust_state?: ClientTrustState to SignIn JSON and snapshot shapes and imports ClientTrustState; populates from JSON.
SignIn second-factor expansion
packages/shared/src/types/signInCommon.ts
Extends SignInSecondFactor and AttemptSecondFactorParams unions to include EmailCodeFactor / EmailCodeAttempt.

Sequence Diagram(s)

sequenceDiagram
autonumber
participant API as Backend JSON
participant Client as Client (resource)
participant SignIn as SignIn (resource)
rect rgb(235,245,255)
Note over API,Client: Old flow (before change)
end
API->>Client: GET /client -> { ..., client_trust_state }
Client-->>API: serializes client (includes client_trust_state)
Note over Client: clientTrustState persisted on Client resource
Loading
sequenceDiagram
autonumber
participant API as Backend JSON
participant Client as Client (resource)
participant SignIn as SignIn (resource)
rect rgb(245,255,235)
Note over API,SignIn: New flow (after change)
end
API->>Client: GET /client -> { ... }
Note over Client: no client_trust_state persisted
API->>SignIn: GET /sign_in -> { ..., client_trust_state }
SignIn-->>API: serializes sign_in (includes client_trust_state)
Note over SignIn: clientTrustState persisted on SignIn resource
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

  • Focus areas:
    • packages/clerk-js/src/core/resources/Client.ts — verify all clientTrustState references removed and serialization snapshot updated.
    • packages/clerk-js/src/core/resources/SignIn.ts — confirm import, property typing, and fromJSON assignment for client_trust_state.
    • packages/shared/src/types/* — ensure JSON shapes, resource types, and snapshots are consistent.
    • packages/shared/src/types/signInCommon.ts — check callers for the new EmailCodeFactor/EmailCodeAttempt variants.

Poem

🐰 I hopped from Client to SignIn with glee,
A trust-state moved, now fresh and free.
Email codes joined the second-factor tune,
The rabbit winks beneath the moon 🌙
Change shipped swift — a happy hop, hooray!

Pre-merge checks and finishing touches

✅ Passed checks (2 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title directly and clearly summarizes the main change: moving clientTrustState from Client to SignIn, which aligns with the primary objective of this bug fix PR.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch tom/fix-client-trust-state

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between ba05615 and eab6a9c.

📒 Files selected for processing (1)
  • packages/shared/src/types/signInCommon.ts (2 hunks)
🧰 Additional context used
📓 Path-based instructions (6)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/shared/src/types/signInCommon.ts
packages/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/shared/src/types/signInCommon.ts
packages/**/*.{ts,tsx,d.ts}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Packages should export TypeScript types alongside runtime code

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Prefer readonly for properties that shouldn't change after construction
Prefer composition and interfaces over deep inheritance chains
Use mixins for shared behavior across unrelated classes
Implement dependency injection for loose coupling
Let TypeScript infer when types are obvious
Use const assertions for literal types: as const
Use satisfies operator for type checking without widening
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Use type-only imports: import type { ... } from ...
No any types without justification
Proper error handling with typed errors
Consistent use of readonly for immutable data
Proper generic constraints
No unused type parameters
Proper use of utility types instead of manual type construction
Type-only imports where possible
Proper tree-shaking friendly exports
No circular dependencies
Efficient type computations (avoid deep recursion)

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/shared/src/types/signInCommon.ts
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (3)
packages/shared/src/types/signInCommon.ts (3)

122-122: LGTM!

The addition of EmailCodeAttempt is consistent with EmailCodeFactor being added to SignInSecondFactor on line 88, maintaining proper alignment between factor types and their attempt parameters.


120-120: I need to check the actual implementation and definitions in the codebase to understand whether this is intentional design.

Review comment is incorrect and should be disregarded.

According to Clerk's official documentation, if the strategy is set to TOTP, it does not require preparation and you can directly attempt the second factor verification. Only the phone_code strategy requires calling the prepareSecondFactor method.

The asymmetry between PrepareSecondFactorParams (only PhoneCodeSecondFactorConfig) and AttemptSecondFactorParams (four factor types) is intentional by Clerk's design. Backup codes are a fallback when the user is unable to use their primary MFA method, and do not require a separate preparation step. EmailCode and TOTP similarly do not require preparation configuration, which is why no corresponding config types exist for them.

The type definition is correct and complete.

Likely an incorrect or invalid review comment.


88-88: EmailCodeFactor as second factor is intentional and properly implemented.

The changes add email code authentication as a supported second factor, paralleling existing patterns for phone code and backup code. The generic attemptSecondFactor implementation accepts {strategy, code} parameters, which EmailCodeAttempt provides. Types are properly exported and integrated into verification machines and UI components (clerk-js, elements packages). The addition to both SignInFirstFactor and SignInSecondFactor is correct—email authentication is designed to work as both primary and secondary authentication.


Comment @coderabbitai help to get the list of available commands and usage tips.

@tmilewskitmilewski changed the title fix: Move clientTrustState to SignInfix(clerk-js,shared): Move clientTrustState to SignInNov 5, 2025
@tmilewskitmilewski self-assigned this Nov 5, 2025
@tmilewski

Copy link
Copy Markdown
MemberAuthor

@coderabbitai full review

@coderabbitai

Copy link
Copy Markdown
Contributor
✅ Actions performed

Full review triggered.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/shared/src/types/signIn.ts (1)

46-46: LGTM! Consider adding JSDoc for the new property.

The clientTrustState property is correctly added to both interfaces with appropriate types and optional modifiers for backward compatibility. The naming follows conventions (camelCase in resource, snake_case in JSON).

Consider adding JSDoc documentation to explain what this property represents and its possible values, as per coding guidelines for public APIs.

Example JSDoc for line 46:

+ /**+ * The trust state of the client device for this sign-in attempt.+ * Possible values: 'new', 'known', 'pending'.+ */
clientTrustState?: ClientTrustState;

Also applies to: 99-99

📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 9ffa221 and ba05615.

📒 Files selected for processing (1)
  • packages/shared/src/types/signIn.ts (3 hunks)
🧰 Additional context used
📓 Path-based instructions (6)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/shared/src/types/signIn.ts
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/shared/src/types/signIn.ts
packages/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/shared/src/types/signIn.ts
packages/**/*.{ts,tsx,d.ts}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Packages should export TypeScript types alongside runtime code

Files:

  • packages/shared/src/types/signIn.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Prefer readonly for properties that shouldn't change after construction
Prefer composition and interfaces over deep inheritance chains
Use mixins for shared behavior across unrelated classes
Implement dependency injection for loose coupling
Let TypeScript infer when types are obvious
Use const assertions for literal types: as const
Use satisfies operator for type checking without widening
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Use type-only imports: import type { ... } from ...
No any types without justification
Proper error handling with typed errors
Consistent use of readonly for immutable data
Proper generic constraints
No unused type parameters
Proper use of utility types instead of manual type construction
Type-only imports where possible
Proper tree-shaking friendly exports
No circular dependencies
Efficient type computations (avoid deep recursion)

Files:

  • packages/shared/src/types/signIn.ts
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/shared/src/types/signIn.ts
🧬 Code graph analysis (1)
packages/shared/src/types/signIn.ts (1)
packages/shared/src/types/json.ts (1)
  • ClientTrustState (105-105)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

@pkg-pr-new

pkg-pr-newBot commented Nov 5, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7163

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7163

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7163

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7163

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7163

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7163

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7163

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7163

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7163

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7163

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7163

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7163

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7163

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7163

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7163

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7163

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7163

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7163

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7163

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7163

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7163

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7163

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7163

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7163

commit: eab6a9c

@blacksmith-sh

This comment has been minimized.

@blacksmith-sh

This comment was marked as resolved.

@tmilewski

Copy link
Copy Markdown
MemberAuthor

Pushing through. 429's are blocking the Next CI

@tmilewski
tmilewski merged commit a474c59 into mainNov 5, 2025
93 of 100 checks passed
@tmilewski
tmilewski deleted the tom/fix-client-trust-state branch November 5, 2025 21:19
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tmilewski@wobsoriano@clerk-cookie
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(clerk-js,shared): Move clientTrustState to SignIn - #7163

Merged
tmilewski merged 3 commits into
mainfrom
tom/fix-client-trust-state
Nov 5, 2025
Merged

fix(clerk-js,shared): Move clientTrustState to SignIn#7163
tmilewski merged 3 commits into
mainfrom
tom/fix-client-trust-state

Conversation

@tmilewski

@tmilewskitmilewski commented Nov 5, 2025

Copy link
Copy Markdown
Member

Description

Fixes a rebase issue where clientTrustState didn't get moved to SignIn.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • New Features

    • Email-based authentication codes are now supported as a second-factor verification method.
  • Changes

    • Client trust state is now surfaced on the sign-in object instead of the client profile.
    • Public type surfaces updated to expose the trust state on sign-in and include the new second-factor option.

@vercel

vercelBot commented Nov 5, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentNov 5, 2025 8:51pm

@changeset-bot

changeset-botBot commented Nov 5, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: eab6a9c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 22 packages
NameType
@clerk/clerk-jsPatch
@clerk/sharedPatch
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/elementsPatch
@clerk/expo-passkeysPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/clerk-reactPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/themesPatch
@clerk/typesPatch
@clerk/vuePatch
@clerk/localizationsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitaiBot commented Nov 5, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

clientTrustState is removed from Client (runtime and types) and added to SignIn (runtime and types); Client JSON no longer includes client_trust_state while SignIn JSON/snapshots may include it. SignInSecondFactor now includes EmailCodeFactor. A patch changeset records the move.

Changes

Cohort / File(s)Summary
Changeset
\.changeset/evil-aliens-hope.md
Adds a patch changeset documenting the behavioral rename: moving clientTrustState from Client to SignIn.
Client resource & JSON/types removed
packages/clerk-js/src/core/resources/Client.ts, packages/shared/src/types/client.ts, packages/shared/src/types/json.ts
Removes clientTrustState from the Client class and ClientResource interface; removes client_trust_state from ClientJSON; deletes related imports, initialization, (de)serialization code.
SignIn resource & types added
packages/clerk-js/src/core/resources/SignIn.ts, packages/shared/src/types/signIn.ts, packages/shared/src/types/snapshots.ts
Adds clientTrustState?: ClientTrustState to the SignIn class and SignInResource; adds client_trust_state?: ClientTrustState to SignIn JSON and snapshot shapes and imports ClientTrustState; populates from JSON.
SignIn second-factor expansion
packages/shared/src/types/signInCommon.ts
Extends SignInSecondFactor and AttemptSecondFactorParams unions to include EmailCodeFactor / EmailCodeAttempt.

Sequence Diagram(s)

sequenceDiagram
autonumber
participant API as Backend JSON
participant Client as Client (resource)
participant SignIn as SignIn (resource)
rect rgb(235,245,255)
Note over API,Client: Old flow (before change)
end
API->>Client: GET /client -> { ..., client_trust_state }
Client-->>API: serializes client (includes client_trust_state)
Note over Client: clientTrustState persisted on Client resource
Loading
sequenceDiagram
autonumber
participant API as Backend JSON
participant Client as Client (resource)
participant SignIn as SignIn (resource)
rect rgb(245,255,235)
Note over API,SignIn: New flow (after change)
end
API->>Client: GET /client -> { ... }
Note over Client: no client_trust_state persisted
API->>SignIn: GET /sign_in -> { ..., client_trust_state }
SignIn-->>API: serializes sign_in (includes client_trust_state)
Note over SignIn: clientTrustState persisted on SignIn resource
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

  • Focus areas:
    • packages/clerk-js/src/core/resources/Client.ts — verify all clientTrustState references removed and serialization snapshot updated.
    • packages/clerk-js/src/core/resources/SignIn.ts — confirm import, property typing, and fromJSON assignment for client_trust_state.
    • packages/shared/src/types/* — ensure JSON shapes, resource types, and snapshots are consistent.
    • packages/shared/src/types/signInCommon.ts — check callers for the new EmailCodeFactor/EmailCodeAttempt variants.

Poem

🐰 I hopped from Client to SignIn with glee,
A trust-state moved, now fresh and free.
Email codes joined the second-factor tune,
The rabbit winks beneath the moon 🌙
Change shipped swift — a happy hop, hooray!

Pre-merge checks and finishing touches

✅ Passed checks (2 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title directly and clearly summarizes the main change: moving clientTrustState from Client to SignIn, which aligns with the primary objective of this bug fix PR.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch tom/fix-client-trust-state

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between ba05615 and eab6a9c.

📒 Files selected for processing (1)
  • packages/shared/src/types/signInCommon.ts (2 hunks)
🧰 Additional context used
📓 Path-based instructions (6)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/shared/src/types/signInCommon.ts
packages/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/shared/src/types/signInCommon.ts
packages/**/*.{ts,tsx,d.ts}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Packages should export TypeScript types alongside runtime code

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Prefer readonly for properties that shouldn't change after construction
Prefer composition and interfaces over deep inheritance chains
Use mixins for shared behavior across unrelated classes
Implement dependency injection for loose coupling
Let TypeScript infer when types are obvious
Use const assertions for literal types: as const
Use satisfies operator for type checking without widening
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Use type-only imports: import type { ... } from ...
No any types without justification
Proper error handling with typed errors
Consistent use of readonly for immutable data
Proper generic constraints
No unused type parameters
Proper use of utility types instead of manual type construction
Type-only imports where possible
Proper tree-shaking friendly exports
No circular dependencies
Efficient type computations (avoid deep recursion)

Files:

  • packages/shared/src/types/signInCommon.ts
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/shared/src/types/signInCommon.ts
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (3)
packages/shared/src/types/signInCommon.ts (3)

122-122: LGTM!

The addition of EmailCodeAttempt is consistent with EmailCodeFactor being added to SignInSecondFactor on line 88, maintaining proper alignment between factor types and their attempt parameters.


120-120: I need to check the actual implementation and definitions in the codebase to understand whether this is intentional design.

Review comment is incorrect and should be disregarded.

According to Clerk's official documentation, if the strategy is set to TOTP, it does not require preparation and you can directly attempt the second factor verification. Only the phone_code strategy requires calling the prepareSecondFactor method.

The asymmetry between PrepareSecondFactorParams (only PhoneCodeSecondFactorConfig) and AttemptSecondFactorParams (four factor types) is intentional by Clerk's design. Backup codes are a fallback when the user is unable to use their primary MFA method, and do not require a separate preparation step. EmailCode and TOTP similarly do not require preparation configuration, which is why no corresponding config types exist for them.

The type definition is correct and complete.

Likely an incorrect or invalid review comment.


88-88: EmailCodeFactor as second factor is intentional and properly implemented.

The changes add email code authentication as a supported second factor, paralleling existing patterns for phone code and backup code. The generic attemptSecondFactor implementation accepts {strategy, code} parameters, which EmailCodeAttempt provides. Types are properly exported and integrated into verification machines and UI components (clerk-js, elements packages). The addition to both SignInFirstFactor and SignInSecondFactor is correct—email authentication is designed to work as both primary and secondary authentication.


Comment @coderabbitai help to get the list of available commands and usage tips.

@tmilewskitmilewski changed the title fix: Move clientTrustState to SignInfix(clerk-js,shared): Move clientTrustState to SignInNov 5, 2025
@tmilewskitmilewski self-assigned this Nov 5, 2025
@tmilewski

Copy link
Copy Markdown
MemberAuthor

@coderabbitai full review

@coderabbitai

Copy link
Copy Markdown
Contributor
✅ Actions performed

Full review triggered.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/shared/src/types/signIn.ts (1)

46-46: LGTM! Consider adding JSDoc for the new property.

The clientTrustState property is correctly added to both interfaces with appropriate types and optional modifiers for backward compatibility. The naming follows conventions (camelCase in resource, snake_case in JSON).

Consider adding JSDoc documentation to explain what this property represents and its possible values, as per coding guidelines for public APIs.

Example JSDoc for line 46:

+ /**+ * The trust state of the client device for this sign-in attempt.+ * Possible values: 'new', 'known', 'pending'.+ */
clientTrustState?: ClientTrustState;

Also applies to: 99-99

📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 9ffa221 and ba05615.

📒 Files selected for processing (1)
  • packages/shared/src/types/signIn.ts (3 hunks)
🧰 Additional context used
📓 Path-based instructions (6)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.{js,jsx,ts,tsx}: All code must pass ESLint checks with the project's configuration
Follow established naming conventions (PascalCase for components, camelCase for variables)
Maintain comprehensive JSDoc comments for public APIs
Use dynamic imports for optional features
All public APIs must be documented with JSDoc
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Profile and optimize critical paths
Validate all inputs and sanitize outputs
Implement proper logging with different levels

Files:

  • packages/shared/src/types/signIn.ts
**/*.{js,jsx,ts,tsx,json,css,scss,md,yaml,yml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/shared/src/types/signIn.ts
packages/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/shared/src/types/signIn.ts
packages/**/*.{ts,tsx,d.ts}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Packages should export TypeScript types alongside runtime code

Files:

  • packages/shared/src/types/signIn.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Prefer readonly for properties that shouldn't change after construction
Prefer composition and interfaces over deep inheritance chains
Use mixins for shared behavior across unrelated classes
Implement dependency injection for loose coupling
Let TypeScript infer when types are obvious
Use const assertions for literal types: as const
Use satisfies operator for type checking without widening
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Use type-only imports: import type { ... } from ...
No any types without justification
Proper error handling with typed errors
Consistent use of readonly for immutable data
Proper generic constraints
No unused type parameters
Proper use of utility types instead of manual type construction
Type-only imports where possible
Proper tree-shaking friendly exports
No circular dependencies
Efficient type computations (avoid deep recursion)

Files:

  • packages/shared/src/types/signIn.ts
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/monorepo.mdc)

Support multiple Clerk environment variables (CLERK_, NEXT_PUBLIC_CLERK_, etc.) for configuration.

Files:

  • packages/shared/src/types/signIn.ts
🧬 Code graph analysis (1)
packages/shared/src/types/signIn.ts (1)
packages/shared/src/types/json.ts (1)
  • ClientTrustState (105-105)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

@pkg-pr-new

pkg-pr-newBot commented Nov 5, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7163

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7163

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7163

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7163

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7163

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7163

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7163

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7163

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7163

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7163

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7163

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7163

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7163

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7163

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7163

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7163

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7163

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7163

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7163

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7163

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7163

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7163

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7163

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7163

commit: eab6a9c

@blacksmith-sh

This comment has been minimized.

@blacksmith-sh

This comment was marked as resolved.

@tmilewski

Copy link
Copy Markdown
MemberAuthor

Pushing through. 429's are blocking the Next CI

@tmilewski
tmilewski merged commit a474c59 into mainNov 5, 2025
93 of 100 checks passed
@tmilewski
tmilewski deleted the tom/fix-client-trust-state branch November 5, 2025 21:19
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tmilewski@wobsoriano@clerk-cookie