fix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcher - #7316

Merged
wobsoriano merged 8 commits into
mainfrom
rob/fix-api-keys-freeze
Nov 26, 2025
Merged

fix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcher#7316
wobsoriano merged 8 commits into
mainfrom
rob/fix-api-keys-freeze

Conversation

@wobsoriano

@wobsorianowobsoriano commented Nov 26, 2025

Copy link
Copy Markdown
Member

Description

Fixes an issue where UserButton and OrganizationSwitcher would mutate their props in-place when custom pages were present, causing unpredictable behavior and infinite update loops.

Screen.Recording.2025-11-25.at.4.51.41.PM.mov

Resolves USER-4092

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes
    • Fixed an issue where the APIKeys component on a custom page could cause the application to freeze.

✏️ Tip: You can customize this high-level summary in your review settings.

@changeset-bot

changeset-botBot commented Nov 26, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 03208b0

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 8 packages
NameType
@clerk/clerk-reactPatch
@clerk/chrome-extensionPatch
@clerk/elementsPatch
@clerk/clerk-expoPatch
@clerk/nextjsPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Nov 26, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentNov 26, 2025 1:37am

@coderabbitai

coderabbitaiBot commented Nov 26, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Replaced mutation-based object composition with non-mutating spread syntax in UserButton and OrganizationSwitcher components to fix an issue where APIKeys component mounted on custom pages caused application freezing. Added corresponding changeset entry.

Changes

Cohort / File(s)Summary
Core Fix
packages/react/src/components/uiComponents.tsx
Replaced Object.assign(props.userProfileProps || {}, { customPages }) with spread syntax { ...props.userProfileProps, customPages } in UserButton; applied same pattern to OrganizationSwitcher's organizationProfileProps. Eliminates input prop mutation.
Changelog
.changeset/hot-ads-relate.md
Added changeset entry documenting Clerk React patch fixing APIKeys component freezing issue when mounted on custom pages within UserButton.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

  • Verify spread syntax correctly handles undefined/null cases (non-mutating behavior is key to fix)
  • Confirm changeset description accurately reflects the freeze fix and component scope

Poem

🐰 A freeze in custom pages met its end,
When mutations gave way to spread, my friend!
No more Object.assign's mutant ways,
Just pristine objects through the maze! ✨

Pre-merge checks and finishing touches

✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main fix: preventing prop mutation in UserButton and OrganizationSwitcher components.
Linked Issues check✅ PassedCode changes directly address USER-4092 by replacing Object.assign mutations with spread syntax, eliminating in-place prop mutation that caused infinite update loops.
Out of Scope Changes check✅ PassedAll changes are in-scope: UserButton and OrganizationSwitcher prop mutation fixes directly address the linked issue, and the changeset accurately documents the fix.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch rob/fix-api-keys-freeze

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between c061534 and 03208b0.

📒 Files selected for processing (1)
  • packages/react/src/components/uiComponents.tsx (2 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/react/src/components/uiComponents.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (29)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Static analysis
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Nov 26, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7316

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7316

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7316

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7316

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7316

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7316

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7316

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7316

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7316

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7316

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7316

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7316

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7316

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7316

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7316

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7316

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7316

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7316

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7316

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7316

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7316

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7316

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7316

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7316

commit: 03208b0

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/react/src/components/ClerkHostRenderer.tsx (1)

81-93: Consider extracting nested prop stripping to a helper function.

The logic correctly strips customPages from nested profile props, but the repetitive pattern could be simplified for better maintainability.

Consider extracting this into a helper function:

conststripNestedCustomPages=(props: any)=>{constresult={ ...props};if(result.userProfileProps){result.userProfileProps=without(result.userProfileProps,'customPages');}if(result.organizationProfileProps){result.organizationProfileProps=without(result.organizationProfileProps,'customPages');}returnresult;};// Then use it:constprevProps=stripNestedCustomPages(without(_prevProps.props,'customPages','customMenuItems','children'));constnewProps=stripNestedCustomPages(without(this.props.props,'customPages','customMenuItems','children'));
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between f115e56 and 9ec689d.

📒 Files selected for processing (2)
  • .changeset/nice-goats-visit.md (1 hunks)
  • packages/react/src/components/ClerkHostRenderer.tsx (1 hunks)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

All code must pass ESLint checks with the project's configuration

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{js,jsx,ts,tsx,json,md,yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
packages/**/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Follow established naming conventions (PascalCase for components, camelCase for variables)

Prefer importing types from @clerk/shared/types instead of the deprecated @clerk/types alias

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
packages/**/src/**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

packages/**/src/**/*.{ts,tsx,js,jsx}: Maintain comprehensive JSDoc comments for public APIs
Use tree-shaking friendly exports
Validate all inputs and sanitize outputs
All public APIs must be documented with JSDoc
Use dynamic imports for optional features
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Implement proper logging with different levels

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.ts?(x)

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.tsx

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.tsx: Use error boundaries in React components
Minimize re-renders in React components

**/*.tsx: Use proper type definitions for props and state in React components
Leverage TypeScript's type inference where possible in React components
Use proper event types for handlers in React components
Implement proper generic types for reusable React components
Use proper type guards for conditional rendering in React components

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{md,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Update documentation for API changes

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/react.mdc)

**/*.{jsx,tsx}: Always use functional components with hooks instead of class components
Follow PascalCase naming for components (e.g., UserProfile, NavigationMenu)
Keep components focused on a single responsibility - split large components
Limit component size to 150-200 lines; extract logic into custom hooks
Use composition over inheritance - prefer smaller, composable components
Export components as named exports for better tree-shaking
One component per file with matching filename and component name
Separate UI components from business logic components
Use useState for simple state management in React components
Use useReducer for complex state logic in React components
Implement proper state initialization in React components
Use proper state updates with callbacks in React components
Implement proper state cleanup in React components
Use Context API for theme/authentication state management
Implement proper state persistence in React applications
Use React.memo for expensive components
Implement proper useCallback for handlers in React components
Use proper useMemo for expensive computations in React components
Implement proper virtualization for lists in React components
Use proper code splitting with React.lazy in React applications
Implement proper cleanup in useEffect hooks
Use proper refs for DOM access in React components
Implement proper event listener cleanup in React components
Use proper abort controllers for fetch in React components
Implement proper subscription cleanup in React components
Use proper HTML elements for semantic HTML in React components
Implement proper ARIA attributes for accessibility in React components
Use proper heading hierarchy in React components
Implement proper form labels in React components
Use proper button types in React components
Implement proper focus management for keyboard navigation in React components
Use proper keyboard shortcuts in React components
Implement proper tab order in React components
Use proper ...

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/typescript.mdc)

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Implement type guards for unknown types using the pattern function isType(value: unknown): value is Type
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details in classes
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Use mixins for shared behavior across unrelated classes in TypeScript
Use generic constraints with bounded type parameters like <T extends { id: string }>
Use utility types like Omit, Partial, and Pick for data transformation instead of manual type construction
Use discriminated unions instead of boolean flags for state management and API responses
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation at the type level
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Document functions with JSDoc comments including @PARAM, @returns, @throws, and @example tags
Create custom error classes that extend Error for specific error types
Use the Result pattern for error handling instead of throwing exceptions
Use optional chaining (?.) and nullish coalescing (??) operators for safe property access
Let TypeScript infer obvious types to reduce verbosity
Use const assertions with as const for literal types
Use satisfies operator for type checking without widening types
Declare readonly arrays and objects for immutable data structures
Use spread operator and array spread for immutable updates instead of mutations
Use lazy loading for large types...

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (32)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Unit Tests (22, shared, clerk-js, RQ)
  • GitHub Check: Unit Tests (22, **)
  • GitHub Check: Publish with pkg-pr-new
  • GitHub Check: Static analysis
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (2)
.changeset/nice-goats-visit.md (1)

1-5: LGTM!

The changeset follows the standard format and correctly documents the patch release for the API keys freezing fix.

packages/react/src/components/ClerkHostRenderer.tsx (1)

96-104: LGTM! Change detection logic is correct.

The extended change detection properly handles:

  • Top-level customPages length comparison
  • Nested userProfileProps.customPages length comparison
  • Nested organizationProfileProps.customPages length comparison
  • Optional chaining correctly handles undefined cases

The extraction of customMenuItemsChanged on lines 103-104 also improves readability.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/react/src/components/uiComponents.tsx (1)

257-271: Immutability fix for userProfileProps looks correct

Using Object.assign({}, props.userProfileProps, { customPages }) now composes userProfileProps without mutating the caller’s object, while preserving the previous merge semantics (later sources override earlier ones). If you want stylistic consistency with nearby code, you could optionally switch to object spread (const userProfileProps = { ...props.userProfileProps, customPages };), but the current change is already solid.

📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 9ec689d and 0ddf58b.

📒 Files selected for processing (1)
  • packages/react/src/components/uiComponents.tsx (2 hunks)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

All code must pass ESLint checks with the project's configuration

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{js,jsx,ts,tsx,json,md,yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/react/src/components/uiComponents.tsx
packages/**/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Follow established naming conventions (PascalCase for components, camelCase for variables)

Prefer importing types from @clerk/shared/types instead of the deprecated @clerk/types alias

Files:

  • packages/react/src/components/uiComponents.tsx
packages/**/src/**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

packages/**/src/**/*.{ts,tsx,js,jsx}: Maintain comprehensive JSDoc comments for public APIs
Use tree-shaking friendly exports
Validate all inputs and sanitize outputs
All public APIs must be documented with JSDoc
Use dynamic imports for optional features
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Implement proper logging with different levels

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.ts?(x)

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.tsx

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.tsx: Use error boundaries in React components
Minimize re-renders in React components

**/*.tsx: Use proper type definitions for props and state in React components
Leverage TypeScript's type inference where possible in React components
Use proper event types for handlers in React components
Implement proper generic types for reusable React components
Use proper type guards for conditional rendering in React components

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{md,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Update documentation for API changes

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/react.mdc)

**/*.{jsx,tsx}: Always use functional components with hooks instead of class components
Follow PascalCase naming for components (e.g., UserProfile, NavigationMenu)
Keep components focused on a single responsibility - split large components
Limit component size to 150-200 lines; extract logic into custom hooks
Use composition over inheritance - prefer smaller, composable components
Export components as named exports for better tree-shaking
One component per file with matching filename and component name
Separate UI components from business logic components
Use useState for simple state management in React components
Use useReducer for complex state logic in React components
Implement proper state initialization in React components
Use proper state updates with callbacks in React components
Implement proper state cleanup in React components
Use Context API for theme/authentication state management
Implement proper state persistence in React applications
Use React.memo for expensive components
Implement proper useCallback for handlers in React components
Use proper useMemo for expensive computations in React components
Implement proper virtualization for lists in React components
Use proper code splitting with React.lazy in React applications
Implement proper cleanup in useEffect hooks
Use proper refs for DOM access in React components
Implement proper event listener cleanup in React components
Use proper abort controllers for fetch in React components
Implement proper subscription cleanup in React components
Use proper HTML elements for semantic HTML in React components
Implement proper ARIA attributes for accessibility in React components
Use proper heading hierarchy in React components
Implement proper form labels in React components
Use proper button types in React components
Implement proper focus management for keyboard navigation in React components
Use proper keyboard shortcuts in React components
Implement proper tab order in React components
Use proper ...

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/typescript.mdc)

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Implement type guards for unknown types using the pattern function isType(value: unknown): value is Type
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details in classes
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Use mixins for shared behavior across unrelated classes in TypeScript
Use generic constraints with bounded type parameters like <T extends { id: string }>
Use utility types like Omit, Partial, and Pick for data transformation instead of manual type construction
Use discriminated unions instead of boolean flags for state management and API responses
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation at the type level
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Document functions with JSDoc comments including @PARAM, @returns, @throws, and @example tags
Create custom error classes that extend Error for specific error types
Use the Result pattern for error handling instead of throwing exceptions
Use optional chaining (?.) and nullish coalescing (??) operators for safe property access
Let TypeScript infer obvious types to reduce verbosity
Use const assertions with as const for literal types
Use satisfies operator for type checking without widening types
Declare readonly arrays and objects for immutable data structures
Use spread operator and array spread for immutable updates instead of mutations
Use lazy loading for large types...

Files:

  • packages/react/src/components/uiComponents.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (1)
packages/react/src/components/uiComponents.tsx (1)

435-446: Non-mutating organizationProfileProps composition is consistent

Same pattern here: building organizationProfileProps via Object.assign({}, ...) avoids mutating props.organizationProfileProps and keeps behavior equivalent apart from the intentional immutability improvement. No further issues from this change.

@wobsorianowobsoriano changed the title fix(clerk-react): [do-not-review] Attempt to fix API keys AIO freezing within UserButton.UserProfilePagefix(clerk-react): Fixes an issue where API keys component within custom pages freezesNov 26, 2025
@wobsorianowobsoriano changed the title fix(clerk-react): Fixes an issue where API keys component within custom pages freezesfix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcherNov 26, 2025
Comment threadpackages/react/src/components/uiComponents.tsx Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
.changeset/hot-ads-relate.md (1)

1-5: Add issue reference to changeset for traceability.

The changeset should reference the related issue (USER-4092) to provide traceability. Update the description to include the issue reference.

---
"@clerk/clerk-react": patch
----Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze.+Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze (USER-4092).

Optionally, consider a more comprehensive description that hints at the root cause to help future maintainers understand what was fixed:

---
"@clerk/clerk-react": patch
----Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze.+Resolved an issue where prop mutation in UserButton and OrganizationSwitcher caused infinite update loops, freezing the API Keys component when mounted in custom pages (USER-4092).
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 0ddf58b and c061534.

📒 Files selected for processing (1)
  • .changeset/hot-ads-relate.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/hot-ads-relate.md

[style] ~4-~4: Consider using a different verb for a more formal wording.
Context: --- "@clerk/clerk-react": patch --- Fixed an issue where <APIKeys /> mounted in...

(FIX_RESOLVE)

⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (34)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Unit Tests (22, **)
  • GitHub Check: Static analysis
  • GitHub Check: Unit Tests (22, shared, clerk-js, RQ)
  • GitHub Check: Publish with pkg-pr-new
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan

Comment threadpackages/react/src/components/uiComponents.tsx Outdated
Comment threadpackages/react/src/components/uiComponents.tsx Outdated

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

wobsorianoand others added 2 commits November 25, 2025 17:36
Co-authored-by: Jacek Radko <jacek@clerk.dev>
Co-authored-by: Jacek Radko <jacek@clerk.dev>
@wobsoriano
wobsoriano enabled auto-merge (squash) November 26, 2025 01:40
@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.2.6-snapshot.v20251126014211
@clerk/astro2.16.4-snapshot.v20251126014211
@clerk/backend2.25.0-snapshot.v20251126014211
@clerk/chrome-extension2.8.7-snapshot.v20251126014211
@clerk/clerk-js5.111.1-snapshot.v20251126014211
@clerk/elements0.23.87-snapshot.v20251126014211
@clerk/clerk-expo2.19.7-snapshot.v20251126014211
@clerk/expo-passkeys0.4.23-snapshot.v20251126014211
@clerk/express1.7.54-snapshot.v20251126014211
@clerk/fastify2.6.6-snapshot.v20251126014211
@clerk/localizations3.28.6-snapshot.v20251126014211
@clerk/nextjs6.35.6-snapshot.v20251126014211
@clerk/nuxt1.13.4-snapshot.v20251126014211
@clerk/clerk-react5.57.1-snapshot.v20251126014211
@clerk/react-router2.3.1-snapshot.v20251126014211
@clerk/remix4.13.21-snapshot.v20251126014211
@clerk/shared3.37.0-snapshot.v20251126014211
@clerk/tanstack-react-start0.27.6-snapshot.v20251126014211
@clerk/testing1.13.20-snapshot.v20251126014211
@clerk/themes2.4.41-snapshot.v20251126014211
@clerk/types4.101.4-snapshot.v20251126014211
@clerk/vue1.17.1-snapshot.v20251126014211

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.2.6-snapshot.v20251126014211 --save-exact

@clerk/astro

npm i @clerk/astro@2.16.4-snapshot.v20251126014211 --save-exact

@clerk/backend

npm i @clerk/backend@2.25.0-snapshot.v20251126014211 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.8.7-snapshot.v20251126014211 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.111.1-snapshot.v20251126014211 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.87-snapshot.v20251126014211 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.19.7-snapshot.v20251126014211 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.4.23-snapshot.v20251126014211 --save-exact

@clerk/express

npm i @clerk/express@1.7.54-snapshot.v20251126014211 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.6.6-snapshot.v20251126014211 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.28.6-snapshot.v20251126014211 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.35.6-snapshot.v20251126014211 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.13.4-snapshot.v20251126014211 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.57.1-snapshot.v20251126014211 --save-exact

@clerk/react-router

npm i @clerk/react-router@2.3.1-snapshot.v20251126014211 --save-exact

@clerk/remix

npm i @clerk/remix@4.13.21-snapshot.v20251126014211 --save-exact

@clerk/shared

npm i @clerk/shared@3.37.0-snapshot.v20251126014211 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.27.6-snapshot.v20251126014211 --save-exact

@clerk/testing

npm i @clerk/testing@1.13.20-snapshot.v20251126014211 --save-exact

@clerk/themes

npm i @clerk/themes@2.4.41-snapshot.v20251126014211 --save-exact

@clerk/types

npm i @clerk/types@4.101.4-snapshot.v20251126014211 --save-exact

@clerk/vue

npm i @clerk/vue@1.17.1-snapshot.v20251126014211 --save-exact

@wobsoriano
wobsoriano merged commit cf66d07 into mainNov 26, 2025
71 of 79 checks passed
@wobsoriano
wobsoriano deleted the rob/fix-api-keys-freeze branch November 26, 2025 01:54
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@wobsoriano@clerk-cookie@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcher - #7316

Merged
wobsoriano merged 8 commits into
mainfrom
rob/fix-api-keys-freeze
Nov 26, 2025
Merged

fix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcher#7316
wobsoriano merged 8 commits into
mainfrom
rob/fix-api-keys-freeze

Conversation

@wobsoriano

@wobsorianowobsoriano commented Nov 26, 2025

Copy link
Copy Markdown
Member

Description

Fixes an issue where UserButton and OrganizationSwitcher would mutate their props in-place when custom pages were present, causing unpredictable behavior and infinite update loops.

Screen.Recording.2025-11-25.at.4.51.41.PM.mov

Resolves USER-4092

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes
    • Fixed an issue where the APIKeys component on a custom page could cause the application to freeze.

✏️ Tip: You can customize this high-level summary in your review settings.

@changeset-bot

changeset-botBot commented Nov 26, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 03208b0

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 8 packages
NameType
@clerk/clerk-reactPatch
@clerk/chrome-extensionPatch
@clerk/elementsPatch
@clerk/clerk-expoPatch
@clerk/nextjsPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Nov 26, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentNov 26, 2025 1:37am

@coderabbitai

coderabbitaiBot commented Nov 26, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Replaced mutation-based object composition with non-mutating spread syntax in UserButton and OrganizationSwitcher components to fix an issue where APIKeys component mounted on custom pages caused application freezing. Added corresponding changeset entry.

Changes

Cohort / File(s)Summary
Core Fix
packages/react/src/components/uiComponents.tsx
Replaced Object.assign(props.userProfileProps || {}, { customPages }) with spread syntax { ...props.userProfileProps, customPages } in UserButton; applied same pattern to OrganizationSwitcher's organizationProfileProps. Eliminates input prop mutation.
Changelog
.changeset/hot-ads-relate.md
Added changeset entry documenting Clerk React patch fixing APIKeys component freezing issue when mounted on custom pages within UserButton.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

  • Verify spread syntax correctly handles undefined/null cases (non-mutating behavior is key to fix)
  • Confirm changeset description accurately reflects the freeze fix and component scope

Poem

🐰 A freeze in custom pages met its end,
When mutations gave way to spread, my friend!
No more Object.assign's mutant ways,
Just pristine objects through the maze! ✨

Pre-merge checks and finishing touches

✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main fix: preventing prop mutation in UserButton and OrganizationSwitcher components.
Linked Issues check✅ PassedCode changes directly address USER-4092 by replacing Object.assign mutations with spread syntax, eliminating in-place prop mutation that caused infinite update loops.
Out of Scope Changes check✅ PassedAll changes are in-scope: UserButton and OrganizationSwitcher prop mutation fixes directly address the linked issue, and the changeset accurately documents the fix.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch rob/fix-api-keys-freeze

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between c061534 and 03208b0.

📒 Files selected for processing (1)
  • packages/react/src/components/uiComponents.tsx (2 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/react/src/components/uiComponents.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (29)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Static analysis
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Nov 26, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7316

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7316

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7316

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7316

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7316

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7316

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7316

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7316

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7316

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7316

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7316

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7316

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7316

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7316

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7316

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7316

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7316

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7316

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7316

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7316

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7316

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7316

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7316

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7316

commit: 03208b0

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/react/src/components/ClerkHostRenderer.tsx (1)

81-93: Consider extracting nested prop stripping to a helper function.

The logic correctly strips customPages from nested profile props, but the repetitive pattern could be simplified for better maintainability.

Consider extracting this into a helper function:

conststripNestedCustomPages=(props: any)=>{constresult={ ...props};if(result.userProfileProps){result.userProfileProps=without(result.userProfileProps,'customPages');}if(result.organizationProfileProps){result.organizationProfileProps=without(result.organizationProfileProps,'customPages');}returnresult;};// Then use it:constprevProps=stripNestedCustomPages(without(_prevProps.props,'customPages','customMenuItems','children'));constnewProps=stripNestedCustomPages(without(this.props.props,'customPages','customMenuItems','children'));
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between f115e56 and 9ec689d.

📒 Files selected for processing (2)
  • .changeset/nice-goats-visit.md (1 hunks)
  • packages/react/src/components/ClerkHostRenderer.tsx (1 hunks)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

All code must pass ESLint checks with the project's configuration

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{js,jsx,ts,tsx,json,md,yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
packages/**/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Follow established naming conventions (PascalCase for components, camelCase for variables)

Prefer importing types from @clerk/shared/types instead of the deprecated @clerk/types alias

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
packages/**/src/**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

packages/**/src/**/*.{ts,tsx,js,jsx}: Maintain comprehensive JSDoc comments for public APIs
Use tree-shaking friendly exports
Validate all inputs and sanitize outputs
All public APIs must be documented with JSDoc
Use dynamic imports for optional features
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Implement proper logging with different levels

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.ts?(x)

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.tsx

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.tsx: Use error boundaries in React components
Minimize re-renders in React components

**/*.tsx: Use proper type definitions for props and state in React components
Leverage TypeScript's type inference where possible in React components
Use proper event types for handlers in React components
Implement proper generic types for reusable React components
Use proper type guards for conditional rendering in React components

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{md,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Update documentation for API changes

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/react.mdc)

**/*.{jsx,tsx}: Always use functional components with hooks instead of class components
Follow PascalCase naming for components (e.g., UserProfile, NavigationMenu)
Keep components focused on a single responsibility - split large components
Limit component size to 150-200 lines; extract logic into custom hooks
Use composition over inheritance - prefer smaller, composable components
Export components as named exports for better tree-shaking
One component per file with matching filename and component name
Separate UI components from business logic components
Use useState for simple state management in React components
Use useReducer for complex state logic in React components
Implement proper state initialization in React components
Use proper state updates with callbacks in React components
Implement proper state cleanup in React components
Use Context API for theme/authentication state management
Implement proper state persistence in React applications
Use React.memo for expensive components
Implement proper useCallback for handlers in React components
Use proper useMemo for expensive computations in React components
Implement proper virtualization for lists in React components
Use proper code splitting with React.lazy in React applications
Implement proper cleanup in useEffect hooks
Use proper refs for DOM access in React components
Implement proper event listener cleanup in React components
Use proper abort controllers for fetch in React components
Implement proper subscription cleanup in React components
Use proper HTML elements for semantic HTML in React components
Implement proper ARIA attributes for accessibility in React components
Use proper heading hierarchy in React components
Implement proper form labels in React components
Use proper button types in React components
Implement proper focus management for keyboard navigation in React components
Use proper keyboard shortcuts in React components
Implement proper tab order in React components
Use proper ...

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/typescript.mdc)

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Implement type guards for unknown types using the pattern function isType(value: unknown): value is Type
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details in classes
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Use mixins for shared behavior across unrelated classes in TypeScript
Use generic constraints with bounded type parameters like <T extends { id: string }>
Use utility types like Omit, Partial, and Pick for data transformation instead of manual type construction
Use discriminated unions instead of boolean flags for state management and API responses
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation at the type level
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Document functions with JSDoc comments including @PARAM, @returns, @throws, and @example tags
Create custom error classes that extend Error for specific error types
Use the Result pattern for error handling instead of throwing exceptions
Use optional chaining (?.) and nullish coalescing (??) operators for safe property access
Let TypeScript infer obvious types to reduce verbosity
Use const assertions with as const for literal types
Use satisfies operator for type checking without widening types
Declare readonly arrays and objects for immutable data structures
Use spread operator and array spread for immutable updates instead of mutations
Use lazy loading for large types...

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (32)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Unit Tests (22, shared, clerk-js, RQ)
  • GitHub Check: Unit Tests (22, **)
  • GitHub Check: Publish with pkg-pr-new
  • GitHub Check: Static analysis
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (2)
.changeset/nice-goats-visit.md (1)

1-5: LGTM!

The changeset follows the standard format and correctly documents the patch release for the API keys freezing fix.

packages/react/src/components/ClerkHostRenderer.tsx (1)

96-104: LGTM! Change detection logic is correct.

The extended change detection properly handles:

  • Top-level customPages length comparison
  • Nested userProfileProps.customPages length comparison
  • Nested organizationProfileProps.customPages length comparison
  • Optional chaining correctly handles undefined cases

The extraction of customMenuItemsChanged on lines 103-104 also improves readability.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/react/src/components/uiComponents.tsx (1)

257-271: Immutability fix for userProfileProps looks correct

Using Object.assign({}, props.userProfileProps, { customPages }) now composes userProfileProps without mutating the caller’s object, while preserving the previous merge semantics (later sources override earlier ones). If you want stylistic consistency with nearby code, you could optionally switch to object spread (const userProfileProps = { ...props.userProfileProps, customPages };), but the current change is already solid.

📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 9ec689d and 0ddf58b.

📒 Files selected for processing (1)
  • packages/react/src/components/uiComponents.tsx (2 hunks)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

All code must pass ESLint checks with the project's configuration

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{js,jsx,ts,tsx,json,md,yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/react/src/components/uiComponents.tsx
packages/**/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Follow established naming conventions (PascalCase for components, camelCase for variables)

Prefer importing types from @clerk/shared/types instead of the deprecated @clerk/types alias

Files:

  • packages/react/src/components/uiComponents.tsx
packages/**/src/**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

packages/**/src/**/*.{ts,tsx,js,jsx}: Maintain comprehensive JSDoc comments for public APIs
Use tree-shaking friendly exports
Validate all inputs and sanitize outputs
All public APIs must be documented with JSDoc
Use dynamic imports for optional features
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Implement proper logging with different levels

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.ts?(x)

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.tsx

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.tsx: Use error boundaries in React components
Minimize re-renders in React components

**/*.tsx: Use proper type definitions for props and state in React components
Leverage TypeScript's type inference where possible in React components
Use proper event types for handlers in React components
Implement proper generic types for reusable React components
Use proper type guards for conditional rendering in React components

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{md,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Update documentation for API changes

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/react.mdc)

**/*.{jsx,tsx}: Always use functional components with hooks instead of class components
Follow PascalCase naming for components (e.g., UserProfile, NavigationMenu)
Keep components focused on a single responsibility - split large components
Limit component size to 150-200 lines; extract logic into custom hooks
Use composition over inheritance - prefer smaller, composable components
Export components as named exports for better tree-shaking
One component per file with matching filename and component name
Separate UI components from business logic components
Use useState for simple state management in React components
Use useReducer for complex state logic in React components
Implement proper state initialization in React components
Use proper state updates with callbacks in React components
Implement proper state cleanup in React components
Use Context API for theme/authentication state management
Implement proper state persistence in React applications
Use React.memo for expensive components
Implement proper useCallback for handlers in React components
Use proper useMemo for expensive computations in React components
Implement proper virtualization for lists in React components
Use proper code splitting with React.lazy in React applications
Implement proper cleanup in useEffect hooks
Use proper refs for DOM access in React components
Implement proper event listener cleanup in React components
Use proper abort controllers for fetch in React components
Implement proper subscription cleanup in React components
Use proper HTML elements for semantic HTML in React components
Implement proper ARIA attributes for accessibility in React components
Use proper heading hierarchy in React components
Implement proper form labels in React components
Use proper button types in React components
Implement proper focus management for keyboard navigation in React components
Use proper keyboard shortcuts in React components
Implement proper tab order in React components
Use proper ...

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/typescript.mdc)

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Implement type guards for unknown types using the pattern function isType(value: unknown): value is Type
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details in classes
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Use mixins for shared behavior across unrelated classes in TypeScript
Use generic constraints with bounded type parameters like <T extends { id: string }>
Use utility types like Omit, Partial, and Pick for data transformation instead of manual type construction
Use discriminated unions instead of boolean flags for state management and API responses
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation at the type level
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Document functions with JSDoc comments including @PARAM, @returns, @throws, and @example tags
Create custom error classes that extend Error for specific error types
Use the Result pattern for error handling instead of throwing exceptions
Use optional chaining (?.) and nullish coalescing (??) operators for safe property access
Let TypeScript infer obvious types to reduce verbosity
Use const assertions with as const for literal types
Use satisfies operator for type checking without widening types
Declare readonly arrays and objects for immutable data structures
Use spread operator and array spread for immutable updates instead of mutations
Use lazy loading for large types...

Files:

  • packages/react/src/components/uiComponents.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (1)
packages/react/src/components/uiComponents.tsx (1)

435-446: Non-mutating organizationProfileProps composition is consistent

Same pattern here: building organizationProfileProps via Object.assign({}, ...) avoids mutating props.organizationProfileProps and keeps behavior equivalent apart from the intentional immutability improvement. No further issues from this change.

@wobsorianowobsoriano changed the title fix(clerk-react): [do-not-review] Attempt to fix API keys AIO freezing within UserButton.UserProfilePagefix(clerk-react): Fixes an issue where API keys component within custom pages freezesNov 26, 2025
@wobsorianowobsoriano changed the title fix(clerk-react): Fixes an issue where API keys component within custom pages freezesfix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcherNov 26, 2025
Comment threadpackages/react/src/components/uiComponents.tsx Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
.changeset/hot-ads-relate.md (1)

1-5: Add issue reference to changeset for traceability.

The changeset should reference the related issue (USER-4092) to provide traceability. Update the description to include the issue reference.

---
"@clerk/clerk-react": patch
----Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze.+Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze (USER-4092).

Optionally, consider a more comprehensive description that hints at the root cause to help future maintainers understand what was fixed:

---
"@clerk/clerk-react": patch
----Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze.+Resolved an issue where prop mutation in UserButton and OrganizationSwitcher caused infinite update loops, freezing the API Keys component when mounted in custom pages (USER-4092).
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 0ddf58b and c061534.

📒 Files selected for processing (1)
  • .changeset/hot-ads-relate.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/hot-ads-relate.md

[style] ~4-~4: Consider using a different verb for a more formal wording.
Context: --- "@clerk/clerk-react": patch --- Fixed an issue where <APIKeys /> mounted in...

(FIX_RESOLVE)

⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (34)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Unit Tests (22, **)
  • GitHub Check: Static analysis
  • GitHub Check: Unit Tests (22, shared, clerk-js, RQ)
  • GitHub Check: Publish with pkg-pr-new
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan

Comment threadpackages/react/src/components/uiComponents.tsx Outdated
Comment threadpackages/react/src/components/uiComponents.tsx Outdated

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

wobsorianoand others added 2 commits November 25, 2025 17:36
Co-authored-by: Jacek Radko <jacek@clerk.dev>
Co-authored-by: Jacek Radko <jacek@clerk.dev>
@wobsoriano
wobsoriano enabled auto-merge (squash) November 26, 2025 01:40
@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.2.6-snapshot.v20251126014211
@clerk/astro2.16.4-snapshot.v20251126014211
@clerk/backend2.25.0-snapshot.v20251126014211
@clerk/chrome-extension2.8.7-snapshot.v20251126014211
@clerk/clerk-js5.111.1-snapshot.v20251126014211
@clerk/elements0.23.87-snapshot.v20251126014211
@clerk/clerk-expo2.19.7-snapshot.v20251126014211
@clerk/expo-passkeys0.4.23-snapshot.v20251126014211
@clerk/express1.7.54-snapshot.v20251126014211
@clerk/fastify2.6.6-snapshot.v20251126014211
@clerk/localizations3.28.6-snapshot.v20251126014211
@clerk/nextjs6.35.6-snapshot.v20251126014211
@clerk/nuxt1.13.4-snapshot.v20251126014211
@clerk/clerk-react5.57.1-snapshot.v20251126014211
@clerk/react-router2.3.1-snapshot.v20251126014211
@clerk/remix4.13.21-snapshot.v20251126014211
@clerk/shared3.37.0-snapshot.v20251126014211
@clerk/tanstack-react-start0.27.6-snapshot.v20251126014211
@clerk/testing1.13.20-snapshot.v20251126014211
@clerk/themes2.4.41-snapshot.v20251126014211
@clerk/types4.101.4-snapshot.v20251126014211
@clerk/vue1.17.1-snapshot.v20251126014211

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.2.6-snapshot.v20251126014211 --save-exact

@clerk/astro

npm i @clerk/astro@2.16.4-snapshot.v20251126014211 --save-exact

@clerk/backend

npm i @clerk/backend@2.25.0-snapshot.v20251126014211 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.8.7-snapshot.v20251126014211 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.111.1-snapshot.v20251126014211 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.87-snapshot.v20251126014211 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.19.7-snapshot.v20251126014211 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.4.23-snapshot.v20251126014211 --save-exact

@clerk/express

npm i @clerk/express@1.7.54-snapshot.v20251126014211 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.6.6-snapshot.v20251126014211 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.28.6-snapshot.v20251126014211 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.35.6-snapshot.v20251126014211 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.13.4-snapshot.v20251126014211 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.57.1-snapshot.v20251126014211 --save-exact

@clerk/react-router

npm i @clerk/react-router@2.3.1-snapshot.v20251126014211 --save-exact

@clerk/remix

npm i @clerk/remix@4.13.21-snapshot.v20251126014211 --save-exact

@clerk/shared

npm i @clerk/shared@3.37.0-snapshot.v20251126014211 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.27.6-snapshot.v20251126014211 --save-exact

@clerk/testing

npm i @clerk/testing@1.13.20-snapshot.v20251126014211 --save-exact

@clerk/themes

npm i @clerk/themes@2.4.41-snapshot.v20251126014211 --save-exact

@clerk/types

npm i @clerk/types@4.101.4-snapshot.v20251126014211 --save-exact

@clerk/vue

npm i @clerk/vue@1.17.1-snapshot.v20251126014211 --save-exact

@wobsoriano
wobsoriano merged commit cf66d07 into mainNov 26, 2025
71 of 79 checks passed
@wobsoriano
wobsoriano deleted the rob/fix-api-keys-freeze branch November 26, 2025 01:54
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@wobsoriano@clerk-cookie@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcher - #7316

Merged
wobsoriano merged 8 commits into
mainfrom
rob/fix-api-keys-freeze
Nov 26, 2025
Merged

fix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcher#7316
wobsoriano merged 8 commits into
mainfrom
rob/fix-api-keys-freeze

Conversation

@wobsoriano

@wobsorianowobsoriano commented Nov 26, 2025

Copy link
Copy Markdown
Member

Description

Fixes an issue where UserButton and OrganizationSwitcher would mutate their props in-place when custom pages were present, causing unpredictable behavior and infinite update loops.

Screen.Recording.2025-11-25.at.4.51.41.PM.mov

Resolves USER-4092

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes
    • Fixed an issue where the APIKeys component on a custom page could cause the application to freeze.

✏️ Tip: You can customize this high-level summary in your review settings.

@changeset-bot

changeset-botBot commented Nov 26, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 03208b0

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 8 packages
NameType
@clerk/clerk-reactPatch
@clerk/chrome-extensionPatch
@clerk/elementsPatch
@clerk/clerk-expoPatch
@clerk/nextjsPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Nov 26, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentNov 26, 2025 1:37am

@coderabbitai

coderabbitaiBot commented Nov 26, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Replaced mutation-based object composition with non-mutating spread syntax in UserButton and OrganizationSwitcher components to fix an issue where APIKeys component mounted on custom pages caused application freezing. Added corresponding changeset entry.

Changes

Cohort / File(s)Summary
Core Fix
packages/react/src/components/uiComponents.tsx
Replaced Object.assign(props.userProfileProps || {}, { customPages }) with spread syntax { ...props.userProfileProps, customPages } in UserButton; applied same pattern to OrganizationSwitcher's organizationProfileProps. Eliminates input prop mutation.
Changelog
.changeset/hot-ads-relate.md
Added changeset entry documenting Clerk React patch fixing APIKeys component freezing issue when mounted on custom pages within UserButton.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

  • Verify spread syntax correctly handles undefined/null cases (non-mutating behavior is key to fix)
  • Confirm changeset description accurately reflects the freeze fix and component scope

Poem

🐰 A freeze in custom pages met its end,
When mutations gave way to spread, my friend!
No more Object.assign's mutant ways,
Just pristine objects through the maze! ✨

Pre-merge checks and finishing touches

✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main fix: preventing prop mutation in UserButton and OrganizationSwitcher components.
Linked Issues check✅ PassedCode changes directly address USER-4092 by replacing Object.assign mutations with spread syntax, eliminating in-place prop mutation that caused infinite update loops.
Out of Scope Changes check✅ PassedAll changes are in-scope: UserButton and OrganizationSwitcher prop mutation fixes directly address the linked issue, and the changeset accurately documents the fix.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch rob/fix-api-keys-freeze

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between c061534 and 03208b0.

📒 Files selected for processing (1)
  • packages/react/src/components/uiComponents.tsx (2 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/react/src/components/uiComponents.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (29)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Static analysis
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Nov 26, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7316

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7316

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7316

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7316

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7316

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7316

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7316

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7316

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7316

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7316

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7316

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7316

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7316

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7316

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7316

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7316

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7316

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7316

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7316

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7316

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7316

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7316

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7316

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7316

commit: 03208b0

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/react/src/components/ClerkHostRenderer.tsx (1)

81-93: Consider extracting nested prop stripping to a helper function.

The logic correctly strips customPages from nested profile props, but the repetitive pattern could be simplified for better maintainability.

Consider extracting this into a helper function:

conststripNestedCustomPages=(props: any)=>{constresult={ ...props};if(result.userProfileProps){result.userProfileProps=without(result.userProfileProps,'customPages');}if(result.organizationProfileProps){result.organizationProfileProps=without(result.organizationProfileProps,'customPages');}returnresult;};// Then use it:constprevProps=stripNestedCustomPages(without(_prevProps.props,'customPages','customMenuItems','children'));constnewProps=stripNestedCustomPages(without(this.props.props,'customPages','customMenuItems','children'));
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between f115e56 and 9ec689d.

📒 Files selected for processing (2)
  • .changeset/nice-goats-visit.md (1 hunks)
  • packages/react/src/components/ClerkHostRenderer.tsx (1 hunks)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

All code must pass ESLint checks with the project's configuration

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{js,jsx,ts,tsx,json,md,yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
packages/**/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Follow established naming conventions (PascalCase for components, camelCase for variables)

Prefer importing types from @clerk/shared/types instead of the deprecated @clerk/types alias

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
packages/**/src/**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

packages/**/src/**/*.{ts,tsx,js,jsx}: Maintain comprehensive JSDoc comments for public APIs
Use tree-shaking friendly exports
Validate all inputs and sanitize outputs
All public APIs must be documented with JSDoc
Use dynamic imports for optional features
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Implement proper logging with different levels

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.ts?(x)

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.tsx

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.tsx: Use error boundaries in React components
Minimize re-renders in React components

**/*.tsx: Use proper type definitions for props and state in React components
Leverage TypeScript's type inference where possible in React components
Use proper event types for handlers in React components
Implement proper generic types for reusable React components
Use proper type guards for conditional rendering in React components

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{md,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Update documentation for API changes

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/react.mdc)

**/*.{jsx,tsx}: Always use functional components with hooks instead of class components
Follow PascalCase naming for components (e.g., UserProfile, NavigationMenu)
Keep components focused on a single responsibility - split large components
Limit component size to 150-200 lines; extract logic into custom hooks
Use composition over inheritance - prefer smaller, composable components
Export components as named exports for better tree-shaking
One component per file with matching filename and component name
Separate UI components from business logic components
Use useState for simple state management in React components
Use useReducer for complex state logic in React components
Implement proper state initialization in React components
Use proper state updates with callbacks in React components
Implement proper state cleanup in React components
Use Context API for theme/authentication state management
Implement proper state persistence in React applications
Use React.memo for expensive components
Implement proper useCallback for handlers in React components
Use proper useMemo for expensive computations in React components
Implement proper virtualization for lists in React components
Use proper code splitting with React.lazy in React applications
Implement proper cleanup in useEffect hooks
Use proper refs for DOM access in React components
Implement proper event listener cleanup in React components
Use proper abort controllers for fetch in React components
Implement proper subscription cleanup in React components
Use proper HTML elements for semantic HTML in React components
Implement proper ARIA attributes for accessibility in React components
Use proper heading hierarchy in React components
Implement proper form labels in React components
Use proper button types in React components
Implement proper focus management for keyboard navigation in React components
Use proper keyboard shortcuts in React components
Implement proper tab order in React components
Use proper ...

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/typescript.mdc)

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Implement type guards for unknown types using the pattern function isType(value: unknown): value is Type
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details in classes
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Use mixins for shared behavior across unrelated classes in TypeScript
Use generic constraints with bounded type parameters like <T extends { id: string }>
Use utility types like Omit, Partial, and Pick for data transformation instead of manual type construction
Use discriminated unions instead of boolean flags for state management and API responses
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation at the type level
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Document functions with JSDoc comments including @PARAM, @returns, @throws, and @example tags
Create custom error classes that extend Error for specific error types
Use the Result pattern for error handling instead of throwing exceptions
Use optional chaining (?.) and nullish coalescing (??) operators for safe property access
Let TypeScript infer obvious types to reduce verbosity
Use const assertions with as const for literal types
Use satisfies operator for type checking without widening types
Declare readonly arrays and objects for immutable data structures
Use spread operator and array spread for immutable updates instead of mutations
Use lazy loading for large types...

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (32)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Unit Tests (22, shared, clerk-js, RQ)
  • GitHub Check: Unit Tests (22, **)
  • GitHub Check: Publish with pkg-pr-new
  • GitHub Check: Static analysis
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (2)
.changeset/nice-goats-visit.md (1)

1-5: LGTM!

The changeset follows the standard format and correctly documents the patch release for the API keys freezing fix.

packages/react/src/components/ClerkHostRenderer.tsx (1)

96-104: LGTM! Change detection logic is correct.

The extended change detection properly handles:

  • Top-level customPages length comparison
  • Nested userProfileProps.customPages length comparison
  • Nested organizationProfileProps.customPages length comparison
  • Optional chaining correctly handles undefined cases

The extraction of customMenuItemsChanged on lines 103-104 also improves readability.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/react/src/components/uiComponents.tsx (1)

257-271: Immutability fix for userProfileProps looks correct

Using Object.assign({}, props.userProfileProps, { customPages }) now composes userProfileProps without mutating the caller’s object, while preserving the previous merge semantics (later sources override earlier ones). If you want stylistic consistency with nearby code, you could optionally switch to object spread (const userProfileProps = { ...props.userProfileProps, customPages };), but the current change is already solid.

📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 9ec689d and 0ddf58b.

📒 Files selected for processing (1)
  • packages/react/src/components/uiComponents.tsx (2 hunks)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

All code must pass ESLint checks with the project's configuration

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{js,jsx,ts,tsx,json,md,yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/react/src/components/uiComponents.tsx
packages/**/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Follow established naming conventions (PascalCase for components, camelCase for variables)

Prefer importing types from @clerk/shared/types instead of the deprecated @clerk/types alias

Files:

  • packages/react/src/components/uiComponents.tsx
packages/**/src/**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

packages/**/src/**/*.{ts,tsx,js,jsx}: Maintain comprehensive JSDoc comments for public APIs
Use tree-shaking friendly exports
Validate all inputs and sanitize outputs
All public APIs must be documented with JSDoc
Use dynamic imports for optional features
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Implement proper logging with different levels

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.ts?(x)

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.tsx

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.tsx: Use error boundaries in React components
Minimize re-renders in React components

**/*.tsx: Use proper type definitions for props and state in React components
Leverage TypeScript's type inference where possible in React components
Use proper event types for handlers in React components
Implement proper generic types for reusable React components
Use proper type guards for conditional rendering in React components

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{md,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Update documentation for API changes

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/react.mdc)

**/*.{jsx,tsx}: Always use functional components with hooks instead of class components
Follow PascalCase naming for components (e.g., UserProfile, NavigationMenu)
Keep components focused on a single responsibility - split large components
Limit component size to 150-200 lines; extract logic into custom hooks
Use composition over inheritance - prefer smaller, composable components
Export components as named exports for better tree-shaking
One component per file with matching filename and component name
Separate UI components from business logic components
Use useState for simple state management in React components
Use useReducer for complex state logic in React components
Implement proper state initialization in React components
Use proper state updates with callbacks in React components
Implement proper state cleanup in React components
Use Context API for theme/authentication state management
Implement proper state persistence in React applications
Use React.memo for expensive components
Implement proper useCallback for handlers in React components
Use proper useMemo for expensive computations in React components
Implement proper virtualization for lists in React components
Use proper code splitting with React.lazy in React applications
Implement proper cleanup in useEffect hooks
Use proper refs for DOM access in React components
Implement proper event listener cleanup in React components
Use proper abort controllers for fetch in React components
Implement proper subscription cleanup in React components
Use proper HTML elements for semantic HTML in React components
Implement proper ARIA attributes for accessibility in React components
Use proper heading hierarchy in React components
Implement proper form labels in React components
Use proper button types in React components
Implement proper focus management for keyboard navigation in React components
Use proper keyboard shortcuts in React components
Implement proper tab order in React components
Use proper ...

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/typescript.mdc)

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Implement type guards for unknown types using the pattern function isType(value: unknown): value is Type
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details in classes
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Use mixins for shared behavior across unrelated classes in TypeScript
Use generic constraints with bounded type parameters like <T extends { id: string }>
Use utility types like Omit, Partial, and Pick for data transformation instead of manual type construction
Use discriminated unions instead of boolean flags for state management and API responses
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation at the type level
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Document functions with JSDoc comments including @PARAM, @returns, @throws, and @example tags
Create custom error classes that extend Error for specific error types
Use the Result pattern for error handling instead of throwing exceptions
Use optional chaining (?.) and nullish coalescing (??) operators for safe property access
Let TypeScript infer obvious types to reduce verbosity
Use const assertions with as const for literal types
Use satisfies operator for type checking without widening types
Declare readonly arrays and objects for immutable data structures
Use spread operator and array spread for immutable updates instead of mutations
Use lazy loading for large types...

Files:

  • packages/react/src/components/uiComponents.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (1)
packages/react/src/components/uiComponents.tsx (1)

435-446: Non-mutating organizationProfileProps composition is consistent

Same pattern here: building organizationProfileProps via Object.assign({}, ...) avoids mutating props.organizationProfileProps and keeps behavior equivalent apart from the intentional immutability improvement. No further issues from this change.

@wobsorianowobsoriano changed the title fix(clerk-react): [do-not-review] Attempt to fix API keys AIO freezing within UserButton.UserProfilePagefix(clerk-react): Fixes an issue where API keys component within custom pages freezesNov 26, 2025
@wobsorianowobsoriano changed the title fix(clerk-react): Fixes an issue where API keys component within custom pages freezesfix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcherNov 26, 2025
Comment threadpackages/react/src/components/uiComponents.tsx Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
.changeset/hot-ads-relate.md (1)

1-5: Add issue reference to changeset for traceability.

The changeset should reference the related issue (USER-4092) to provide traceability. Update the description to include the issue reference.

---
"@clerk/clerk-react": patch
----Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze.+Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze (USER-4092).

Optionally, consider a more comprehensive description that hints at the root cause to help future maintainers understand what was fixed:

---
"@clerk/clerk-react": patch
----Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze.+Resolved an issue where prop mutation in UserButton and OrganizationSwitcher caused infinite update loops, freezing the API Keys component when mounted in custom pages (USER-4092).
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 0ddf58b and c061534.

📒 Files selected for processing (1)
  • .changeset/hot-ads-relate.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/hot-ads-relate.md

[style] ~4-~4: Consider using a different verb for a more formal wording.
Context: --- "@clerk/clerk-react": patch --- Fixed an issue where <APIKeys /> mounted in...

(FIX_RESOLVE)

⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (34)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Unit Tests (22, **)
  • GitHub Check: Static analysis
  • GitHub Check: Unit Tests (22, shared, clerk-js, RQ)
  • GitHub Check: Publish with pkg-pr-new
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan

Comment threadpackages/react/src/components/uiComponents.tsx Outdated
Comment threadpackages/react/src/components/uiComponents.tsx Outdated

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

wobsorianoand others added 2 commits November 25, 2025 17:36
Co-authored-by: Jacek Radko <jacek@clerk.dev>
Co-authored-by: Jacek Radko <jacek@clerk.dev>
@wobsoriano
wobsoriano enabled auto-merge (squash) November 26, 2025 01:40
@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.2.6-snapshot.v20251126014211
@clerk/astro2.16.4-snapshot.v20251126014211
@clerk/backend2.25.0-snapshot.v20251126014211
@clerk/chrome-extension2.8.7-snapshot.v20251126014211
@clerk/clerk-js5.111.1-snapshot.v20251126014211
@clerk/elements0.23.87-snapshot.v20251126014211
@clerk/clerk-expo2.19.7-snapshot.v20251126014211
@clerk/expo-passkeys0.4.23-snapshot.v20251126014211
@clerk/express1.7.54-snapshot.v20251126014211
@clerk/fastify2.6.6-snapshot.v20251126014211
@clerk/localizations3.28.6-snapshot.v20251126014211
@clerk/nextjs6.35.6-snapshot.v20251126014211
@clerk/nuxt1.13.4-snapshot.v20251126014211
@clerk/clerk-react5.57.1-snapshot.v20251126014211
@clerk/react-router2.3.1-snapshot.v20251126014211
@clerk/remix4.13.21-snapshot.v20251126014211
@clerk/shared3.37.0-snapshot.v20251126014211
@clerk/tanstack-react-start0.27.6-snapshot.v20251126014211
@clerk/testing1.13.20-snapshot.v20251126014211
@clerk/themes2.4.41-snapshot.v20251126014211
@clerk/types4.101.4-snapshot.v20251126014211
@clerk/vue1.17.1-snapshot.v20251126014211

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.2.6-snapshot.v20251126014211 --save-exact

@clerk/astro

npm i @clerk/astro@2.16.4-snapshot.v20251126014211 --save-exact

@clerk/backend

npm i @clerk/backend@2.25.0-snapshot.v20251126014211 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.8.7-snapshot.v20251126014211 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.111.1-snapshot.v20251126014211 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.87-snapshot.v20251126014211 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.19.7-snapshot.v20251126014211 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.4.23-snapshot.v20251126014211 --save-exact

@clerk/express

npm i @clerk/express@1.7.54-snapshot.v20251126014211 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.6.6-snapshot.v20251126014211 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.28.6-snapshot.v20251126014211 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.35.6-snapshot.v20251126014211 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.13.4-snapshot.v20251126014211 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.57.1-snapshot.v20251126014211 --save-exact

@clerk/react-router

npm i @clerk/react-router@2.3.1-snapshot.v20251126014211 --save-exact

@clerk/remix

npm i @clerk/remix@4.13.21-snapshot.v20251126014211 --save-exact

@clerk/shared

npm i @clerk/shared@3.37.0-snapshot.v20251126014211 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.27.6-snapshot.v20251126014211 --save-exact

@clerk/testing

npm i @clerk/testing@1.13.20-snapshot.v20251126014211 --save-exact

@clerk/themes

npm i @clerk/themes@2.4.41-snapshot.v20251126014211 --save-exact

@clerk/types

npm i @clerk/types@4.101.4-snapshot.v20251126014211 --save-exact

@clerk/vue

npm i @clerk/vue@1.17.1-snapshot.v20251126014211 --save-exact

@wobsoriano
wobsoriano merged commit cf66d07 into mainNov 26, 2025
71 of 79 checks passed
@wobsoriano
wobsoriano deleted the rob/fix-api-keys-freeze branch November 26, 2025 01:54
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@wobsoriano@clerk-cookie@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcher - #7316

Merged
wobsoriano merged 8 commits into
mainfrom
rob/fix-api-keys-freeze
Nov 26, 2025
Merged

fix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcher#7316
wobsoriano merged 8 commits into
mainfrom
rob/fix-api-keys-freeze

Conversation

@wobsoriano

@wobsorianowobsoriano commented Nov 26, 2025

Copy link
Copy Markdown
Member

Description

Fixes an issue where UserButton and OrganizationSwitcher would mutate their props in-place when custom pages were present, causing unpredictable behavior and infinite update loops.

Screen.Recording.2025-11-25.at.4.51.41.PM.mov

Resolves USER-4092

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes
    • Fixed an issue where the APIKeys component on a custom page could cause the application to freeze.

✏️ Tip: You can customize this high-level summary in your review settings.

@changeset-bot

changeset-botBot commented Nov 26, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 03208b0

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 8 packages
NameType
@clerk/clerk-reactPatch
@clerk/chrome-extensionPatch
@clerk/elementsPatch
@clerk/clerk-expoPatch
@clerk/nextjsPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Nov 26, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentNov 26, 2025 1:37am

@coderabbitai

coderabbitaiBot commented Nov 26, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Replaced mutation-based object composition with non-mutating spread syntax in UserButton and OrganizationSwitcher components to fix an issue where APIKeys component mounted on custom pages caused application freezing. Added corresponding changeset entry.

Changes

Cohort / File(s)Summary
Core Fix
packages/react/src/components/uiComponents.tsx
Replaced Object.assign(props.userProfileProps || {}, { customPages }) with spread syntax { ...props.userProfileProps, customPages } in UserButton; applied same pattern to OrganizationSwitcher's organizationProfileProps. Eliminates input prop mutation.
Changelog
.changeset/hot-ads-relate.md
Added changeset entry documenting Clerk React patch fixing APIKeys component freezing issue when mounted on custom pages within UserButton.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

  • Verify spread syntax correctly handles undefined/null cases (non-mutating behavior is key to fix)
  • Confirm changeset description accurately reflects the freeze fix and component scope

Poem

🐰 A freeze in custom pages met its end,
When mutations gave way to spread, my friend!
No more Object.assign's mutant ways,
Just pristine objects through the maze! ✨

Pre-merge checks and finishing touches

✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main fix: preventing prop mutation in UserButton and OrganizationSwitcher components.
Linked Issues check✅ PassedCode changes directly address USER-4092 by replacing Object.assign mutations with spread syntax, eliminating in-place prop mutation that caused infinite update loops.
Out of Scope Changes check✅ PassedAll changes are in-scope: UserButton and OrganizationSwitcher prop mutation fixes directly address the linked issue, and the changeset accurately documents the fix.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch rob/fix-api-keys-freeze

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between c061534 and 03208b0.

📒 Files selected for processing (1)
  • packages/react/src/components/uiComponents.tsx (2 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/react/src/components/uiComponents.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (29)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Static analysis
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Nov 26, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7316

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7316

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7316

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7316

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7316

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7316

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7316

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7316

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7316

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7316

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7316

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7316

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7316

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7316

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7316

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7316

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7316

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7316

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7316

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7316

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7316

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7316

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7316

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7316

commit: 03208b0

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/react/src/components/ClerkHostRenderer.tsx (1)

81-93: Consider extracting nested prop stripping to a helper function.

The logic correctly strips customPages from nested profile props, but the repetitive pattern could be simplified for better maintainability.

Consider extracting this into a helper function:

conststripNestedCustomPages=(props: any)=>{constresult={ ...props};if(result.userProfileProps){result.userProfileProps=without(result.userProfileProps,'customPages');}if(result.organizationProfileProps){result.organizationProfileProps=without(result.organizationProfileProps,'customPages');}returnresult;};// Then use it:constprevProps=stripNestedCustomPages(without(_prevProps.props,'customPages','customMenuItems','children'));constnewProps=stripNestedCustomPages(without(this.props.props,'customPages','customMenuItems','children'));
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between f115e56 and 9ec689d.

📒 Files selected for processing (2)
  • .changeset/nice-goats-visit.md (1 hunks)
  • packages/react/src/components/ClerkHostRenderer.tsx (1 hunks)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

All code must pass ESLint checks with the project's configuration

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{js,jsx,ts,tsx,json,md,yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
packages/**/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Follow established naming conventions (PascalCase for components, camelCase for variables)

Prefer importing types from @clerk/shared/types instead of the deprecated @clerk/types alias

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
packages/**/src/**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

packages/**/src/**/*.{ts,tsx,js,jsx}: Maintain comprehensive JSDoc comments for public APIs
Use tree-shaking friendly exports
Validate all inputs and sanitize outputs
All public APIs must be documented with JSDoc
Use dynamic imports for optional features
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Implement proper logging with different levels

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.ts?(x)

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.tsx

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.tsx: Use error boundaries in React components
Minimize re-renders in React components

**/*.tsx: Use proper type definitions for props and state in React components
Leverage TypeScript's type inference where possible in React components
Use proper event types for handlers in React components
Implement proper generic types for reusable React components
Use proper type guards for conditional rendering in React components

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{md,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Update documentation for API changes

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/react.mdc)

**/*.{jsx,tsx}: Always use functional components with hooks instead of class components
Follow PascalCase naming for components (e.g., UserProfile, NavigationMenu)
Keep components focused on a single responsibility - split large components
Limit component size to 150-200 lines; extract logic into custom hooks
Use composition over inheritance - prefer smaller, composable components
Export components as named exports for better tree-shaking
One component per file with matching filename and component name
Separate UI components from business logic components
Use useState for simple state management in React components
Use useReducer for complex state logic in React components
Implement proper state initialization in React components
Use proper state updates with callbacks in React components
Implement proper state cleanup in React components
Use Context API for theme/authentication state management
Implement proper state persistence in React applications
Use React.memo for expensive components
Implement proper useCallback for handlers in React components
Use proper useMemo for expensive computations in React components
Implement proper virtualization for lists in React components
Use proper code splitting with React.lazy in React applications
Implement proper cleanup in useEffect hooks
Use proper refs for DOM access in React components
Implement proper event listener cleanup in React components
Use proper abort controllers for fetch in React components
Implement proper subscription cleanup in React components
Use proper HTML elements for semantic HTML in React components
Implement proper ARIA attributes for accessibility in React components
Use proper heading hierarchy in React components
Implement proper form labels in React components
Use proper button types in React components
Implement proper focus management for keyboard navigation in React components
Use proper keyboard shortcuts in React components
Implement proper tab order in React components
Use proper ...

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/typescript.mdc)

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Implement type guards for unknown types using the pattern function isType(value: unknown): value is Type
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details in classes
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Use mixins for shared behavior across unrelated classes in TypeScript
Use generic constraints with bounded type parameters like <T extends { id: string }>
Use utility types like Omit, Partial, and Pick for data transformation instead of manual type construction
Use discriminated unions instead of boolean flags for state management and API responses
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation at the type level
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Document functions with JSDoc comments including @PARAM, @returns, @throws, and @example tags
Create custom error classes that extend Error for specific error types
Use the Result pattern for error handling instead of throwing exceptions
Use optional chaining (?.) and nullish coalescing (??) operators for safe property access
Let TypeScript infer obvious types to reduce verbosity
Use const assertions with as const for literal types
Use satisfies operator for type checking without widening types
Declare readonly arrays and objects for immutable data structures
Use spread operator and array spread for immutable updates instead of mutations
Use lazy loading for large types...

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (32)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Unit Tests (22, shared, clerk-js, RQ)
  • GitHub Check: Unit Tests (22, **)
  • GitHub Check: Publish with pkg-pr-new
  • GitHub Check: Static analysis
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (2)
.changeset/nice-goats-visit.md (1)

1-5: LGTM!

The changeset follows the standard format and correctly documents the patch release for the API keys freezing fix.

packages/react/src/components/ClerkHostRenderer.tsx (1)

96-104: LGTM! Change detection logic is correct.

The extended change detection properly handles:

  • Top-level customPages length comparison
  • Nested userProfileProps.customPages length comparison
  • Nested organizationProfileProps.customPages length comparison
  • Optional chaining correctly handles undefined cases

The extraction of customMenuItemsChanged on lines 103-104 also improves readability.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/react/src/components/uiComponents.tsx (1)

257-271: Immutability fix for userProfileProps looks correct

Using Object.assign({}, props.userProfileProps, { customPages }) now composes userProfileProps without mutating the caller’s object, while preserving the previous merge semantics (later sources override earlier ones). If you want stylistic consistency with nearby code, you could optionally switch to object spread (const userProfileProps = { ...props.userProfileProps, customPages };), but the current change is already solid.

📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 9ec689d and 0ddf58b.

📒 Files selected for processing (1)
  • packages/react/src/components/uiComponents.tsx (2 hunks)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

All code must pass ESLint checks with the project's configuration

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{js,jsx,ts,tsx,json,md,yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/react/src/components/uiComponents.tsx
packages/**/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Follow established naming conventions (PascalCase for components, camelCase for variables)

Prefer importing types from @clerk/shared/types instead of the deprecated @clerk/types alias

Files:

  • packages/react/src/components/uiComponents.tsx
packages/**/src/**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

packages/**/src/**/*.{ts,tsx,js,jsx}: Maintain comprehensive JSDoc comments for public APIs
Use tree-shaking friendly exports
Validate all inputs and sanitize outputs
All public APIs must be documented with JSDoc
Use dynamic imports for optional features
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Implement proper logging with different levels

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.ts?(x)

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.tsx

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.tsx: Use error boundaries in React components
Minimize re-renders in React components

**/*.tsx: Use proper type definitions for props and state in React components
Leverage TypeScript's type inference where possible in React components
Use proper event types for handlers in React components
Implement proper generic types for reusable React components
Use proper type guards for conditional rendering in React components

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{md,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Update documentation for API changes

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/react.mdc)

**/*.{jsx,tsx}: Always use functional components with hooks instead of class components
Follow PascalCase naming for components (e.g., UserProfile, NavigationMenu)
Keep components focused on a single responsibility - split large components
Limit component size to 150-200 lines; extract logic into custom hooks
Use composition over inheritance - prefer smaller, composable components
Export components as named exports for better tree-shaking
One component per file with matching filename and component name
Separate UI components from business logic components
Use useState for simple state management in React components
Use useReducer for complex state logic in React components
Implement proper state initialization in React components
Use proper state updates with callbacks in React components
Implement proper state cleanup in React components
Use Context API for theme/authentication state management
Implement proper state persistence in React applications
Use React.memo for expensive components
Implement proper useCallback for handlers in React components
Use proper useMemo for expensive computations in React components
Implement proper virtualization for lists in React components
Use proper code splitting with React.lazy in React applications
Implement proper cleanup in useEffect hooks
Use proper refs for DOM access in React components
Implement proper event listener cleanup in React components
Use proper abort controllers for fetch in React components
Implement proper subscription cleanup in React components
Use proper HTML elements for semantic HTML in React components
Implement proper ARIA attributes for accessibility in React components
Use proper heading hierarchy in React components
Implement proper form labels in React components
Use proper button types in React components
Implement proper focus management for keyboard navigation in React components
Use proper keyboard shortcuts in React components
Implement proper tab order in React components
Use proper ...

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/typescript.mdc)

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Implement type guards for unknown types using the pattern function isType(value: unknown): value is Type
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details in classes
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Use mixins for shared behavior across unrelated classes in TypeScript
Use generic constraints with bounded type parameters like <T extends { id: string }>
Use utility types like Omit, Partial, and Pick for data transformation instead of manual type construction
Use discriminated unions instead of boolean flags for state management and API responses
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation at the type level
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Document functions with JSDoc comments including @PARAM, @returns, @throws, and @example tags
Create custom error classes that extend Error for specific error types
Use the Result pattern for error handling instead of throwing exceptions
Use optional chaining (?.) and nullish coalescing (??) operators for safe property access
Let TypeScript infer obvious types to reduce verbosity
Use const assertions with as const for literal types
Use satisfies operator for type checking without widening types
Declare readonly arrays and objects for immutable data structures
Use spread operator and array spread for immutable updates instead of mutations
Use lazy loading for large types...

Files:

  • packages/react/src/components/uiComponents.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (1)
packages/react/src/components/uiComponents.tsx (1)

435-446: Non-mutating organizationProfileProps composition is consistent

Same pattern here: building organizationProfileProps via Object.assign({}, ...) avoids mutating props.organizationProfileProps and keeps behavior equivalent apart from the intentional immutability improvement. No further issues from this change.

@wobsorianowobsoriano changed the title fix(clerk-react): [do-not-review] Attempt to fix API keys AIO freezing within UserButton.UserProfilePagefix(clerk-react): Fixes an issue where API keys component within custom pages freezesNov 26, 2025
@wobsorianowobsoriano changed the title fix(clerk-react): Fixes an issue where API keys component within custom pages freezesfix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcherNov 26, 2025
Comment threadpackages/react/src/components/uiComponents.tsx Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
.changeset/hot-ads-relate.md (1)

1-5: Add issue reference to changeset for traceability.

The changeset should reference the related issue (USER-4092) to provide traceability. Update the description to include the issue reference.

---
"@clerk/clerk-react": patch
----Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze.+Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze (USER-4092).

Optionally, consider a more comprehensive description that hints at the root cause to help future maintainers understand what was fixed:

---
"@clerk/clerk-react": patch
----Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze.+Resolved an issue where prop mutation in UserButton and OrganizationSwitcher caused infinite update loops, freezing the API Keys component when mounted in custom pages (USER-4092).
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 0ddf58b and c061534.

📒 Files selected for processing (1)
  • .changeset/hot-ads-relate.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/hot-ads-relate.md

[style] ~4-~4: Consider using a different verb for a more formal wording.
Context: --- "@clerk/clerk-react": patch --- Fixed an issue where <APIKeys /> mounted in...

(FIX_RESOLVE)

⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (34)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Unit Tests (22, **)
  • GitHub Check: Static analysis
  • GitHub Check: Unit Tests (22, shared, clerk-js, RQ)
  • GitHub Check: Publish with pkg-pr-new
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan

Comment threadpackages/react/src/components/uiComponents.tsx Outdated
Comment threadpackages/react/src/components/uiComponents.tsx Outdated

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

wobsorianoand others added 2 commits November 25, 2025 17:36
Co-authored-by: Jacek Radko <jacek@clerk.dev>
Co-authored-by: Jacek Radko <jacek@clerk.dev>
@wobsoriano
wobsoriano enabled auto-merge (squash) November 26, 2025 01:40
@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.2.6-snapshot.v20251126014211
@clerk/astro2.16.4-snapshot.v20251126014211
@clerk/backend2.25.0-snapshot.v20251126014211
@clerk/chrome-extension2.8.7-snapshot.v20251126014211
@clerk/clerk-js5.111.1-snapshot.v20251126014211
@clerk/elements0.23.87-snapshot.v20251126014211
@clerk/clerk-expo2.19.7-snapshot.v20251126014211
@clerk/expo-passkeys0.4.23-snapshot.v20251126014211
@clerk/express1.7.54-snapshot.v20251126014211
@clerk/fastify2.6.6-snapshot.v20251126014211
@clerk/localizations3.28.6-snapshot.v20251126014211
@clerk/nextjs6.35.6-snapshot.v20251126014211
@clerk/nuxt1.13.4-snapshot.v20251126014211
@clerk/clerk-react5.57.1-snapshot.v20251126014211
@clerk/react-router2.3.1-snapshot.v20251126014211
@clerk/remix4.13.21-snapshot.v20251126014211
@clerk/shared3.37.0-snapshot.v20251126014211
@clerk/tanstack-react-start0.27.6-snapshot.v20251126014211
@clerk/testing1.13.20-snapshot.v20251126014211
@clerk/themes2.4.41-snapshot.v20251126014211
@clerk/types4.101.4-snapshot.v20251126014211
@clerk/vue1.17.1-snapshot.v20251126014211

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.2.6-snapshot.v20251126014211 --save-exact

@clerk/astro

npm i @clerk/astro@2.16.4-snapshot.v20251126014211 --save-exact

@clerk/backend

npm i @clerk/backend@2.25.0-snapshot.v20251126014211 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.8.7-snapshot.v20251126014211 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.111.1-snapshot.v20251126014211 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.87-snapshot.v20251126014211 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.19.7-snapshot.v20251126014211 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.4.23-snapshot.v20251126014211 --save-exact

@clerk/express

npm i @clerk/express@1.7.54-snapshot.v20251126014211 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.6.6-snapshot.v20251126014211 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.28.6-snapshot.v20251126014211 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.35.6-snapshot.v20251126014211 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.13.4-snapshot.v20251126014211 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.57.1-snapshot.v20251126014211 --save-exact

@clerk/react-router

npm i @clerk/react-router@2.3.1-snapshot.v20251126014211 --save-exact

@clerk/remix

npm i @clerk/remix@4.13.21-snapshot.v20251126014211 --save-exact

@clerk/shared

npm i @clerk/shared@3.37.0-snapshot.v20251126014211 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.27.6-snapshot.v20251126014211 --save-exact

@clerk/testing

npm i @clerk/testing@1.13.20-snapshot.v20251126014211 --save-exact

@clerk/themes

npm i @clerk/themes@2.4.41-snapshot.v20251126014211 --save-exact

@clerk/types

npm i @clerk/types@4.101.4-snapshot.v20251126014211 --save-exact

@clerk/vue

npm i @clerk/vue@1.17.1-snapshot.v20251126014211 --save-exact

@wobsoriano
wobsoriano merged commit cf66d07 into mainNov 26, 2025
71 of 79 checks passed
@wobsoriano
wobsoriano deleted the rob/fix-api-keys-freeze branch November 26, 2025 01:54
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@wobsoriano@clerk-cookie@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcher - #7316

Merged
wobsoriano merged 8 commits into
mainfrom
rob/fix-api-keys-freeze
Nov 26, 2025
Merged

fix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcher#7316
wobsoriano merged 8 commits into
mainfrom
rob/fix-api-keys-freeze

Conversation

@wobsoriano

@wobsorianowobsoriano commented Nov 26, 2025

Copy link
Copy Markdown
Member

Description

Fixes an issue where UserButton and OrganizationSwitcher would mutate their props in-place when custom pages were present, causing unpredictable behavior and infinite update loops.

Screen.Recording.2025-11-25.at.4.51.41.PM.mov

Resolves USER-4092

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes
    • Fixed an issue where the APIKeys component on a custom page could cause the application to freeze.

✏️ Tip: You can customize this high-level summary in your review settings.

@changeset-bot

changeset-botBot commented Nov 26, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 03208b0

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 8 packages
NameType
@clerk/clerk-reactPatch
@clerk/chrome-extensionPatch
@clerk/elementsPatch
@clerk/clerk-expoPatch
@clerk/nextjsPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Nov 26, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentNov 26, 2025 1:37am

@coderabbitai

coderabbitaiBot commented Nov 26, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Replaced mutation-based object composition with non-mutating spread syntax in UserButton and OrganizationSwitcher components to fix an issue where APIKeys component mounted on custom pages caused application freezing. Added corresponding changeset entry.

Changes

Cohort / File(s)Summary
Core Fix
packages/react/src/components/uiComponents.tsx
Replaced Object.assign(props.userProfileProps || {}, { customPages }) with spread syntax { ...props.userProfileProps, customPages } in UserButton; applied same pattern to OrganizationSwitcher's organizationProfileProps. Eliminates input prop mutation.
Changelog
.changeset/hot-ads-relate.md
Added changeset entry documenting Clerk React patch fixing APIKeys component freezing issue when mounted on custom pages within UserButton.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

  • Verify spread syntax correctly handles undefined/null cases (non-mutating behavior is key to fix)
  • Confirm changeset description accurately reflects the freeze fix and component scope

Poem

🐰 A freeze in custom pages met its end,
When mutations gave way to spread, my friend!
No more Object.assign's mutant ways,
Just pristine objects through the maze! ✨

Pre-merge checks and finishing touches

✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main fix: preventing prop mutation in UserButton and OrganizationSwitcher components.
Linked Issues check✅ PassedCode changes directly address USER-4092 by replacing Object.assign mutations with spread syntax, eliminating in-place prop mutation that caused infinite update loops.
Out of Scope Changes check✅ PassedAll changes are in-scope: UserButton and OrganizationSwitcher prop mutation fixes directly address the linked issue, and the changeset accurately documents the fix.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch rob/fix-api-keys-freeze

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between c061534 and 03208b0.

📒 Files selected for processing (1)
  • packages/react/src/components/uiComponents.tsx (2 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/react/src/components/uiComponents.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (29)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Static analysis
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Nov 26, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7316

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7316

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7316

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7316

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7316

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7316

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7316

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7316

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7316

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7316

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7316

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7316

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7316

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7316

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7316

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7316

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7316

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7316

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7316

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7316

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7316

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7316

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7316

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7316

commit: 03208b0

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/react/src/components/ClerkHostRenderer.tsx (1)

81-93: Consider extracting nested prop stripping to a helper function.

The logic correctly strips customPages from nested profile props, but the repetitive pattern could be simplified for better maintainability.

Consider extracting this into a helper function:

conststripNestedCustomPages=(props: any)=>{constresult={ ...props};if(result.userProfileProps){result.userProfileProps=without(result.userProfileProps,'customPages');}if(result.organizationProfileProps){result.organizationProfileProps=without(result.organizationProfileProps,'customPages');}returnresult;};// Then use it:constprevProps=stripNestedCustomPages(without(_prevProps.props,'customPages','customMenuItems','children'));constnewProps=stripNestedCustomPages(without(this.props.props,'customPages','customMenuItems','children'));
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between f115e56 and 9ec689d.

📒 Files selected for processing (2)
  • .changeset/nice-goats-visit.md (1 hunks)
  • packages/react/src/components/ClerkHostRenderer.tsx (1 hunks)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

All code must pass ESLint checks with the project's configuration

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{js,jsx,ts,tsx,json,md,yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
packages/**/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Follow established naming conventions (PascalCase for components, camelCase for variables)

Prefer importing types from @clerk/shared/types instead of the deprecated @clerk/types alias

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
packages/**/src/**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

packages/**/src/**/*.{ts,tsx,js,jsx}: Maintain comprehensive JSDoc comments for public APIs
Use tree-shaking friendly exports
Validate all inputs and sanitize outputs
All public APIs must be documented with JSDoc
Use dynamic imports for optional features
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Implement proper logging with different levels

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.ts?(x)

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.tsx

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.tsx: Use error boundaries in React components
Minimize re-renders in React components

**/*.tsx: Use proper type definitions for props and state in React components
Leverage TypeScript's type inference where possible in React components
Use proper event types for handlers in React components
Implement proper generic types for reusable React components
Use proper type guards for conditional rendering in React components

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{md,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Update documentation for API changes

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/react.mdc)

**/*.{jsx,tsx}: Always use functional components with hooks instead of class components
Follow PascalCase naming for components (e.g., UserProfile, NavigationMenu)
Keep components focused on a single responsibility - split large components
Limit component size to 150-200 lines; extract logic into custom hooks
Use composition over inheritance - prefer smaller, composable components
Export components as named exports for better tree-shaking
One component per file with matching filename and component name
Separate UI components from business logic components
Use useState for simple state management in React components
Use useReducer for complex state logic in React components
Implement proper state initialization in React components
Use proper state updates with callbacks in React components
Implement proper state cleanup in React components
Use Context API for theme/authentication state management
Implement proper state persistence in React applications
Use React.memo for expensive components
Implement proper useCallback for handlers in React components
Use proper useMemo for expensive computations in React components
Implement proper virtualization for lists in React components
Use proper code splitting with React.lazy in React applications
Implement proper cleanup in useEffect hooks
Use proper refs for DOM access in React components
Implement proper event listener cleanup in React components
Use proper abort controllers for fetch in React components
Implement proper subscription cleanup in React components
Use proper HTML elements for semantic HTML in React components
Implement proper ARIA attributes for accessibility in React components
Use proper heading hierarchy in React components
Implement proper form labels in React components
Use proper button types in React components
Implement proper focus management for keyboard navigation in React components
Use proper keyboard shortcuts in React components
Implement proper tab order in React components
Use proper ...

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/typescript.mdc)

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Implement type guards for unknown types using the pattern function isType(value: unknown): value is Type
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details in classes
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Use mixins for shared behavior across unrelated classes in TypeScript
Use generic constraints with bounded type parameters like <T extends { id: string }>
Use utility types like Omit, Partial, and Pick for data transformation instead of manual type construction
Use discriminated unions instead of boolean flags for state management and API responses
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation at the type level
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Document functions with JSDoc comments including @PARAM, @returns, @throws, and @example tags
Create custom error classes that extend Error for specific error types
Use the Result pattern for error handling instead of throwing exceptions
Use optional chaining (?.) and nullish coalescing (??) operators for safe property access
Let TypeScript infer obvious types to reduce verbosity
Use const assertions with as const for literal types
Use satisfies operator for type checking without widening types
Declare readonly arrays and objects for immutable data structures
Use spread operator and array spread for immutable updates instead of mutations
Use lazy loading for large types...

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (32)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Unit Tests (22, shared, clerk-js, RQ)
  • GitHub Check: Unit Tests (22, **)
  • GitHub Check: Publish with pkg-pr-new
  • GitHub Check: Static analysis
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (2)
.changeset/nice-goats-visit.md (1)

1-5: LGTM!

The changeset follows the standard format and correctly documents the patch release for the API keys freezing fix.

packages/react/src/components/ClerkHostRenderer.tsx (1)

96-104: LGTM! Change detection logic is correct.

The extended change detection properly handles:

  • Top-level customPages length comparison
  • Nested userProfileProps.customPages length comparison
  • Nested organizationProfileProps.customPages length comparison
  • Optional chaining correctly handles undefined cases

The extraction of customMenuItemsChanged on lines 103-104 also improves readability.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/react/src/components/uiComponents.tsx (1)

257-271: Immutability fix for userProfileProps looks correct

Using Object.assign({}, props.userProfileProps, { customPages }) now composes userProfileProps without mutating the caller’s object, while preserving the previous merge semantics (later sources override earlier ones). If you want stylistic consistency with nearby code, you could optionally switch to object spread (const userProfileProps = { ...props.userProfileProps, customPages };), but the current change is already solid.

📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 9ec689d and 0ddf58b.

📒 Files selected for processing (1)
  • packages/react/src/components/uiComponents.tsx (2 hunks)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

All code must pass ESLint checks with the project's configuration

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{js,jsx,ts,tsx,json,md,yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/react/src/components/uiComponents.tsx
packages/**/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Follow established naming conventions (PascalCase for components, camelCase for variables)

Prefer importing types from @clerk/shared/types instead of the deprecated @clerk/types alias

Files:

  • packages/react/src/components/uiComponents.tsx
packages/**/src/**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

packages/**/src/**/*.{ts,tsx,js,jsx}: Maintain comprehensive JSDoc comments for public APIs
Use tree-shaking friendly exports
Validate all inputs and sanitize outputs
All public APIs must be documented with JSDoc
Use dynamic imports for optional features
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Implement proper logging with different levels

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.ts?(x)

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.tsx

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.tsx: Use error boundaries in React components
Minimize re-renders in React components

**/*.tsx: Use proper type definitions for props and state in React components
Leverage TypeScript's type inference where possible in React components
Use proper event types for handlers in React components
Implement proper generic types for reusable React components
Use proper type guards for conditional rendering in React components

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{md,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Update documentation for API changes

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/react.mdc)

**/*.{jsx,tsx}: Always use functional components with hooks instead of class components
Follow PascalCase naming for components (e.g., UserProfile, NavigationMenu)
Keep components focused on a single responsibility - split large components
Limit component size to 150-200 lines; extract logic into custom hooks
Use composition over inheritance - prefer smaller, composable components
Export components as named exports for better tree-shaking
One component per file with matching filename and component name
Separate UI components from business logic components
Use useState for simple state management in React components
Use useReducer for complex state logic in React components
Implement proper state initialization in React components
Use proper state updates with callbacks in React components
Implement proper state cleanup in React components
Use Context API for theme/authentication state management
Implement proper state persistence in React applications
Use React.memo for expensive components
Implement proper useCallback for handlers in React components
Use proper useMemo for expensive computations in React components
Implement proper virtualization for lists in React components
Use proper code splitting with React.lazy in React applications
Implement proper cleanup in useEffect hooks
Use proper refs for DOM access in React components
Implement proper event listener cleanup in React components
Use proper abort controllers for fetch in React components
Implement proper subscription cleanup in React components
Use proper HTML elements for semantic HTML in React components
Implement proper ARIA attributes for accessibility in React components
Use proper heading hierarchy in React components
Implement proper form labels in React components
Use proper button types in React components
Implement proper focus management for keyboard navigation in React components
Use proper keyboard shortcuts in React components
Implement proper tab order in React components
Use proper ...

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/typescript.mdc)

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Implement type guards for unknown types using the pattern function isType(value: unknown): value is Type
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details in classes
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Use mixins for shared behavior across unrelated classes in TypeScript
Use generic constraints with bounded type parameters like <T extends { id: string }>
Use utility types like Omit, Partial, and Pick for data transformation instead of manual type construction
Use discriminated unions instead of boolean flags for state management and API responses
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation at the type level
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Document functions with JSDoc comments including @PARAM, @returns, @throws, and @example tags
Create custom error classes that extend Error for specific error types
Use the Result pattern for error handling instead of throwing exceptions
Use optional chaining (?.) and nullish coalescing (??) operators for safe property access
Let TypeScript infer obvious types to reduce verbosity
Use const assertions with as const for literal types
Use satisfies operator for type checking without widening types
Declare readonly arrays and objects for immutable data structures
Use spread operator and array spread for immutable updates instead of mutations
Use lazy loading for large types...

Files:

  • packages/react/src/components/uiComponents.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (1)
packages/react/src/components/uiComponents.tsx (1)

435-446: Non-mutating organizationProfileProps composition is consistent

Same pattern here: building organizationProfileProps via Object.assign({}, ...) avoids mutating props.organizationProfileProps and keeps behavior equivalent apart from the intentional immutability improvement. No further issues from this change.

@wobsorianowobsoriano changed the title fix(clerk-react): [do-not-review] Attempt to fix API keys AIO freezing within UserButton.UserProfilePagefix(clerk-react): Fixes an issue where API keys component within custom pages freezesNov 26, 2025
@wobsorianowobsoriano changed the title fix(clerk-react): Fixes an issue where API keys component within custom pages freezesfix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcherNov 26, 2025
Comment threadpackages/react/src/components/uiComponents.tsx Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
.changeset/hot-ads-relate.md (1)

1-5: Add issue reference to changeset for traceability.

The changeset should reference the related issue (USER-4092) to provide traceability. Update the description to include the issue reference.

---
"@clerk/clerk-react": patch
----Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze.+Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze (USER-4092).

Optionally, consider a more comprehensive description that hints at the root cause to help future maintainers understand what was fixed:

---
"@clerk/clerk-react": patch
----Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze.+Resolved an issue where prop mutation in UserButton and OrganizationSwitcher caused infinite update loops, freezing the API Keys component when mounted in custom pages (USER-4092).
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 0ddf58b and c061534.

📒 Files selected for processing (1)
  • .changeset/hot-ads-relate.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/hot-ads-relate.md

[style] ~4-~4: Consider using a different verb for a more formal wording.
Context: --- "@clerk/clerk-react": patch --- Fixed an issue where <APIKeys /> mounted in...

(FIX_RESOLVE)

⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (34)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Unit Tests (22, **)
  • GitHub Check: Static analysis
  • GitHub Check: Unit Tests (22, shared, clerk-js, RQ)
  • GitHub Check: Publish with pkg-pr-new
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan

Comment threadpackages/react/src/components/uiComponents.tsx Outdated
Comment threadpackages/react/src/components/uiComponents.tsx Outdated

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

wobsorianoand others added 2 commits November 25, 2025 17:36
Co-authored-by: Jacek Radko <jacek@clerk.dev>
Co-authored-by: Jacek Radko <jacek@clerk.dev>
@wobsoriano
wobsoriano enabled auto-merge (squash) November 26, 2025 01:40
@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.2.6-snapshot.v20251126014211
@clerk/astro2.16.4-snapshot.v20251126014211
@clerk/backend2.25.0-snapshot.v20251126014211
@clerk/chrome-extension2.8.7-snapshot.v20251126014211
@clerk/clerk-js5.111.1-snapshot.v20251126014211
@clerk/elements0.23.87-snapshot.v20251126014211
@clerk/clerk-expo2.19.7-snapshot.v20251126014211
@clerk/expo-passkeys0.4.23-snapshot.v20251126014211
@clerk/express1.7.54-snapshot.v20251126014211
@clerk/fastify2.6.6-snapshot.v20251126014211
@clerk/localizations3.28.6-snapshot.v20251126014211
@clerk/nextjs6.35.6-snapshot.v20251126014211
@clerk/nuxt1.13.4-snapshot.v20251126014211
@clerk/clerk-react5.57.1-snapshot.v20251126014211
@clerk/react-router2.3.1-snapshot.v20251126014211
@clerk/remix4.13.21-snapshot.v20251126014211
@clerk/shared3.37.0-snapshot.v20251126014211
@clerk/tanstack-react-start0.27.6-snapshot.v20251126014211
@clerk/testing1.13.20-snapshot.v20251126014211
@clerk/themes2.4.41-snapshot.v20251126014211
@clerk/types4.101.4-snapshot.v20251126014211
@clerk/vue1.17.1-snapshot.v20251126014211

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.2.6-snapshot.v20251126014211 --save-exact

@clerk/astro

npm i @clerk/astro@2.16.4-snapshot.v20251126014211 --save-exact

@clerk/backend

npm i @clerk/backend@2.25.0-snapshot.v20251126014211 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.8.7-snapshot.v20251126014211 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.111.1-snapshot.v20251126014211 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.87-snapshot.v20251126014211 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.19.7-snapshot.v20251126014211 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.4.23-snapshot.v20251126014211 --save-exact

@clerk/express

npm i @clerk/express@1.7.54-snapshot.v20251126014211 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.6.6-snapshot.v20251126014211 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.28.6-snapshot.v20251126014211 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.35.6-snapshot.v20251126014211 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.13.4-snapshot.v20251126014211 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.57.1-snapshot.v20251126014211 --save-exact

@clerk/react-router

npm i @clerk/react-router@2.3.1-snapshot.v20251126014211 --save-exact

@clerk/remix

npm i @clerk/remix@4.13.21-snapshot.v20251126014211 --save-exact

@clerk/shared

npm i @clerk/shared@3.37.0-snapshot.v20251126014211 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.27.6-snapshot.v20251126014211 --save-exact

@clerk/testing

npm i @clerk/testing@1.13.20-snapshot.v20251126014211 --save-exact

@clerk/themes

npm i @clerk/themes@2.4.41-snapshot.v20251126014211 --save-exact

@clerk/types

npm i @clerk/types@4.101.4-snapshot.v20251126014211 --save-exact

@clerk/vue

npm i @clerk/vue@1.17.1-snapshot.v20251126014211 --save-exact

@wobsoriano
wobsoriano merged commit cf66d07 into mainNov 26, 2025
71 of 79 checks passed
@wobsoriano
wobsoriano deleted the rob/fix-api-keys-freeze branch November 26, 2025 01:54
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@wobsoriano@clerk-cookie@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcher - #7316

Merged
wobsoriano merged 8 commits into
mainfrom
rob/fix-api-keys-freeze
Nov 26, 2025
Merged

fix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcher#7316
wobsoriano merged 8 commits into
mainfrom
rob/fix-api-keys-freeze

Conversation

@wobsoriano

@wobsorianowobsoriano commented Nov 26, 2025

Copy link
Copy Markdown
Member

Description

Fixes an issue where UserButton and OrganizationSwitcher would mutate their props in-place when custom pages were present, causing unpredictable behavior and infinite update loops.

Screen.Recording.2025-11-25.at.4.51.41.PM.mov

Resolves USER-4092

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes
    • Fixed an issue where the APIKeys component on a custom page could cause the application to freeze.

✏️ Tip: You can customize this high-level summary in your review settings.

@changeset-bot

changeset-botBot commented Nov 26, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 03208b0

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 8 packages
NameType
@clerk/clerk-reactPatch
@clerk/chrome-extensionPatch
@clerk/elementsPatch
@clerk/clerk-expoPatch
@clerk/nextjsPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Nov 26, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentNov 26, 2025 1:37am

@coderabbitai

coderabbitaiBot commented Nov 26, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Replaced mutation-based object composition with non-mutating spread syntax in UserButton and OrganizationSwitcher components to fix an issue where APIKeys component mounted on custom pages caused application freezing. Added corresponding changeset entry.

Changes

Cohort / File(s)Summary
Core Fix
packages/react/src/components/uiComponents.tsx
Replaced Object.assign(props.userProfileProps || {}, { customPages }) with spread syntax { ...props.userProfileProps, customPages } in UserButton; applied same pattern to OrganizationSwitcher's organizationProfileProps. Eliminates input prop mutation.
Changelog
.changeset/hot-ads-relate.md
Added changeset entry documenting Clerk React patch fixing APIKeys component freezing issue when mounted on custom pages within UserButton.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

  • Verify spread syntax correctly handles undefined/null cases (non-mutating behavior is key to fix)
  • Confirm changeset description accurately reflects the freeze fix and component scope

Poem

🐰 A freeze in custom pages met its end,
When mutations gave way to spread, my friend!
No more Object.assign's mutant ways,
Just pristine objects through the maze! ✨

Pre-merge checks and finishing touches

✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main fix: preventing prop mutation in UserButton and OrganizationSwitcher components.
Linked Issues check✅ PassedCode changes directly address USER-4092 by replacing Object.assign mutations with spread syntax, eliminating in-place prop mutation that caused infinite update loops.
Out of Scope Changes check✅ PassedAll changes are in-scope: UserButton and OrganizationSwitcher prop mutation fixes directly address the linked issue, and the changeset accurately documents the fix.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch rob/fix-api-keys-freeze

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between c061534 and 03208b0.

📒 Files selected for processing (1)
  • packages/react/src/components/uiComponents.tsx (2 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/react/src/components/uiComponents.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (29)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Static analysis
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Nov 26, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7316

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7316

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7316

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7316

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7316

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7316

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7316

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7316

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7316

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7316

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7316

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7316

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7316

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7316

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7316

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7316

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7316

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7316

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7316

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7316

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7316

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7316

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7316

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7316

commit: 03208b0

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/react/src/components/ClerkHostRenderer.tsx (1)

81-93: Consider extracting nested prop stripping to a helper function.

The logic correctly strips customPages from nested profile props, but the repetitive pattern could be simplified for better maintainability.

Consider extracting this into a helper function:

conststripNestedCustomPages=(props: any)=>{constresult={ ...props};if(result.userProfileProps){result.userProfileProps=without(result.userProfileProps,'customPages');}if(result.organizationProfileProps){result.organizationProfileProps=without(result.organizationProfileProps,'customPages');}returnresult;};// Then use it:constprevProps=stripNestedCustomPages(without(_prevProps.props,'customPages','customMenuItems','children'));constnewProps=stripNestedCustomPages(without(this.props.props,'customPages','customMenuItems','children'));
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between f115e56 and 9ec689d.

📒 Files selected for processing (2)
  • .changeset/nice-goats-visit.md (1 hunks)
  • packages/react/src/components/ClerkHostRenderer.tsx (1 hunks)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

All code must pass ESLint checks with the project's configuration

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{js,jsx,ts,tsx,json,md,yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
packages/**/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Follow established naming conventions (PascalCase for components, camelCase for variables)

Prefer importing types from @clerk/shared/types instead of the deprecated @clerk/types alias

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
packages/**/src/**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

packages/**/src/**/*.{ts,tsx,js,jsx}: Maintain comprehensive JSDoc comments for public APIs
Use tree-shaking friendly exports
Validate all inputs and sanitize outputs
All public APIs must be documented with JSDoc
Use dynamic imports for optional features
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Implement proper logging with different levels

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.ts?(x)

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.tsx

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.tsx: Use error boundaries in React components
Minimize re-renders in React components

**/*.tsx: Use proper type definitions for props and state in React components
Leverage TypeScript's type inference where possible in React components
Use proper event types for handlers in React components
Implement proper generic types for reusable React components
Use proper type guards for conditional rendering in React components

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{md,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Update documentation for API changes

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/react.mdc)

**/*.{jsx,tsx}: Always use functional components with hooks instead of class components
Follow PascalCase naming for components (e.g., UserProfile, NavigationMenu)
Keep components focused on a single responsibility - split large components
Limit component size to 150-200 lines; extract logic into custom hooks
Use composition over inheritance - prefer smaller, composable components
Export components as named exports for better tree-shaking
One component per file with matching filename and component name
Separate UI components from business logic components
Use useState for simple state management in React components
Use useReducer for complex state logic in React components
Implement proper state initialization in React components
Use proper state updates with callbacks in React components
Implement proper state cleanup in React components
Use Context API for theme/authentication state management
Implement proper state persistence in React applications
Use React.memo for expensive components
Implement proper useCallback for handlers in React components
Use proper useMemo for expensive computations in React components
Implement proper virtualization for lists in React components
Use proper code splitting with React.lazy in React applications
Implement proper cleanup in useEffect hooks
Use proper refs for DOM access in React components
Implement proper event listener cleanup in React components
Use proper abort controllers for fetch in React components
Implement proper subscription cleanup in React components
Use proper HTML elements for semantic HTML in React components
Implement proper ARIA attributes for accessibility in React components
Use proper heading hierarchy in React components
Implement proper form labels in React components
Use proper button types in React components
Implement proper focus management for keyboard navigation in React components
Use proper keyboard shortcuts in React components
Implement proper tab order in React components
Use proper ...

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/typescript.mdc)

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Implement type guards for unknown types using the pattern function isType(value: unknown): value is Type
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details in classes
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Use mixins for shared behavior across unrelated classes in TypeScript
Use generic constraints with bounded type parameters like <T extends { id: string }>
Use utility types like Omit, Partial, and Pick for data transformation instead of manual type construction
Use discriminated unions instead of boolean flags for state management and API responses
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation at the type level
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Document functions with JSDoc comments including @PARAM, @returns, @throws, and @example tags
Create custom error classes that extend Error for specific error types
Use the Result pattern for error handling instead of throwing exceptions
Use optional chaining (?.) and nullish coalescing (??) operators for safe property access
Let TypeScript infer obvious types to reduce verbosity
Use const assertions with as const for literal types
Use satisfies operator for type checking without widening types
Declare readonly arrays and objects for immutable data structures
Use spread operator and array spread for immutable updates instead of mutations
Use lazy loading for large types...

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (32)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Unit Tests (22, shared, clerk-js, RQ)
  • GitHub Check: Unit Tests (22, **)
  • GitHub Check: Publish with pkg-pr-new
  • GitHub Check: Static analysis
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (2)
.changeset/nice-goats-visit.md (1)

1-5: LGTM!

The changeset follows the standard format and correctly documents the patch release for the API keys freezing fix.

packages/react/src/components/ClerkHostRenderer.tsx (1)

96-104: LGTM! Change detection logic is correct.

The extended change detection properly handles:

  • Top-level customPages length comparison
  • Nested userProfileProps.customPages length comparison
  • Nested organizationProfileProps.customPages length comparison
  • Optional chaining correctly handles undefined cases

The extraction of customMenuItemsChanged on lines 103-104 also improves readability.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/react/src/components/uiComponents.tsx (1)

257-271: Immutability fix for userProfileProps looks correct

Using Object.assign({}, props.userProfileProps, { customPages }) now composes userProfileProps without mutating the caller’s object, while preserving the previous merge semantics (later sources override earlier ones). If you want stylistic consistency with nearby code, you could optionally switch to object spread (const userProfileProps = { ...props.userProfileProps, customPages };), but the current change is already solid.

📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 9ec689d and 0ddf58b.

📒 Files selected for processing (1)
  • packages/react/src/components/uiComponents.tsx (2 hunks)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

All code must pass ESLint checks with the project's configuration

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{js,jsx,ts,tsx,json,md,yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/react/src/components/uiComponents.tsx
packages/**/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Follow established naming conventions (PascalCase for components, camelCase for variables)

Prefer importing types from @clerk/shared/types instead of the deprecated @clerk/types alias

Files:

  • packages/react/src/components/uiComponents.tsx
packages/**/src/**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

packages/**/src/**/*.{ts,tsx,js,jsx}: Maintain comprehensive JSDoc comments for public APIs
Use tree-shaking friendly exports
Validate all inputs and sanitize outputs
All public APIs must be documented with JSDoc
Use dynamic imports for optional features
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Implement proper logging with different levels

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.ts?(x)

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.tsx

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.tsx: Use error boundaries in React components
Minimize re-renders in React components

**/*.tsx: Use proper type definitions for props and state in React components
Leverage TypeScript's type inference where possible in React components
Use proper event types for handlers in React components
Implement proper generic types for reusable React components
Use proper type guards for conditional rendering in React components

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{md,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Update documentation for API changes

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/react.mdc)

**/*.{jsx,tsx}: Always use functional components with hooks instead of class components
Follow PascalCase naming for components (e.g., UserProfile, NavigationMenu)
Keep components focused on a single responsibility - split large components
Limit component size to 150-200 lines; extract logic into custom hooks
Use composition over inheritance - prefer smaller, composable components
Export components as named exports for better tree-shaking
One component per file with matching filename and component name
Separate UI components from business logic components
Use useState for simple state management in React components
Use useReducer for complex state logic in React components
Implement proper state initialization in React components
Use proper state updates with callbacks in React components
Implement proper state cleanup in React components
Use Context API for theme/authentication state management
Implement proper state persistence in React applications
Use React.memo for expensive components
Implement proper useCallback for handlers in React components
Use proper useMemo for expensive computations in React components
Implement proper virtualization for lists in React components
Use proper code splitting with React.lazy in React applications
Implement proper cleanup in useEffect hooks
Use proper refs for DOM access in React components
Implement proper event listener cleanup in React components
Use proper abort controllers for fetch in React components
Implement proper subscription cleanup in React components
Use proper HTML elements for semantic HTML in React components
Implement proper ARIA attributes for accessibility in React components
Use proper heading hierarchy in React components
Implement proper form labels in React components
Use proper button types in React components
Implement proper focus management for keyboard navigation in React components
Use proper keyboard shortcuts in React components
Implement proper tab order in React components
Use proper ...

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/typescript.mdc)

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Implement type guards for unknown types using the pattern function isType(value: unknown): value is Type
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details in classes
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Use mixins for shared behavior across unrelated classes in TypeScript
Use generic constraints with bounded type parameters like <T extends { id: string }>
Use utility types like Omit, Partial, and Pick for data transformation instead of manual type construction
Use discriminated unions instead of boolean flags for state management and API responses
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation at the type level
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Document functions with JSDoc comments including @PARAM, @returns, @throws, and @example tags
Create custom error classes that extend Error for specific error types
Use the Result pattern for error handling instead of throwing exceptions
Use optional chaining (?.) and nullish coalescing (??) operators for safe property access
Let TypeScript infer obvious types to reduce verbosity
Use const assertions with as const for literal types
Use satisfies operator for type checking without widening types
Declare readonly arrays and objects for immutable data structures
Use spread operator and array spread for immutable updates instead of mutations
Use lazy loading for large types...

Files:

  • packages/react/src/components/uiComponents.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (1)
packages/react/src/components/uiComponents.tsx (1)

435-446: Non-mutating organizationProfileProps composition is consistent

Same pattern here: building organizationProfileProps via Object.assign({}, ...) avoids mutating props.organizationProfileProps and keeps behavior equivalent apart from the intentional immutability improvement. No further issues from this change.

@wobsorianowobsoriano changed the title fix(clerk-react): [do-not-review] Attempt to fix API keys AIO freezing within UserButton.UserProfilePagefix(clerk-react): Fixes an issue where API keys component within custom pages freezesNov 26, 2025
@wobsorianowobsoriano changed the title fix(clerk-react): Fixes an issue where API keys component within custom pages freezesfix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcherNov 26, 2025
Comment threadpackages/react/src/components/uiComponents.tsx Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
.changeset/hot-ads-relate.md (1)

1-5: Add issue reference to changeset for traceability.

The changeset should reference the related issue (USER-4092) to provide traceability. Update the description to include the issue reference.

---
"@clerk/clerk-react": patch
----Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze.+Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze (USER-4092).

Optionally, consider a more comprehensive description that hints at the root cause to help future maintainers understand what was fixed:

---
"@clerk/clerk-react": patch
----Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze.+Resolved an issue where prop mutation in UserButton and OrganizationSwitcher caused infinite update loops, freezing the API Keys component when mounted in custom pages (USER-4092).
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 0ddf58b and c061534.

📒 Files selected for processing (1)
  • .changeset/hot-ads-relate.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/hot-ads-relate.md

[style] ~4-~4: Consider using a different verb for a more formal wording.
Context: --- "@clerk/clerk-react": patch --- Fixed an issue where <APIKeys /> mounted in...

(FIX_RESOLVE)

⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (34)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Unit Tests (22, **)
  • GitHub Check: Static analysis
  • GitHub Check: Unit Tests (22, shared, clerk-js, RQ)
  • GitHub Check: Publish with pkg-pr-new
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan

Comment threadpackages/react/src/components/uiComponents.tsx Outdated
Comment threadpackages/react/src/components/uiComponents.tsx Outdated

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

wobsorianoand others added 2 commits November 25, 2025 17:36
Co-authored-by: Jacek Radko <jacek@clerk.dev>
Co-authored-by: Jacek Radko <jacek@clerk.dev>
@wobsoriano
wobsoriano enabled auto-merge (squash) November 26, 2025 01:40
@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.2.6-snapshot.v20251126014211
@clerk/astro2.16.4-snapshot.v20251126014211
@clerk/backend2.25.0-snapshot.v20251126014211
@clerk/chrome-extension2.8.7-snapshot.v20251126014211
@clerk/clerk-js5.111.1-snapshot.v20251126014211
@clerk/elements0.23.87-snapshot.v20251126014211
@clerk/clerk-expo2.19.7-snapshot.v20251126014211
@clerk/expo-passkeys0.4.23-snapshot.v20251126014211
@clerk/express1.7.54-snapshot.v20251126014211
@clerk/fastify2.6.6-snapshot.v20251126014211
@clerk/localizations3.28.6-snapshot.v20251126014211
@clerk/nextjs6.35.6-snapshot.v20251126014211
@clerk/nuxt1.13.4-snapshot.v20251126014211
@clerk/clerk-react5.57.1-snapshot.v20251126014211
@clerk/react-router2.3.1-snapshot.v20251126014211
@clerk/remix4.13.21-snapshot.v20251126014211
@clerk/shared3.37.0-snapshot.v20251126014211
@clerk/tanstack-react-start0.27.6-snapshot.v20251126014211
@clerk/testing1.13.20-snapshot.v20251126014211
@clerk/themes2.4.41-snapshot.v20251126014211
@clerk/types4.101.4-snapshot.v20251126014211
@clerk/vue1.17.1-snapshot.v20251126014211

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.2.6-snapshot.v20251126014211 --save-exact

@clerk/astro

npm i @clerk/astro@2.16.4-snapshot.v20251126014211 --save-exact

@clerk/backend

npm i @clerk/backend@2.25.0-snapshot.v20251126014211 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.8.7-snapshot.v20251126014211 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.111.1-snapshot.v20251126014211 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.87-snapshot.v20251126014211 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.19.7-snapshot.v20251126014211 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.4.23-snapshot.v20251126014211 --save-exact

@clerk/express

npm i @clerk/express@1.7.54-snapshot.v20251126014211 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.6.6-snapshot.v20251126014211 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.28.6-snapshot.v20251126014211 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.35.6-snapshot.v20251126014211 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.13.4-snapshot.v20251126014211 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.57.1-snapshot.v20251126014211 --save-exact

@clerk/react-router

npm i @clerk/react-router@2.3.1-snapshot.v20251126014211 --save-exact

@clerk/remix

npm i @clerk/remix@4.13.21-snapshot.v20251126014211 --save-exact

@clerk/shared

npm i @clerk/shared@3.37.0-snapshot.v20251126014211 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.27.6-snapshot.v20251126014211 --save-exact

@clerk/testing

npm i @clerk/testing@1.13.20-snapshot.v20251126014211 --save-exact

@clerk/themes

npm i @clerk/themes@2.4.41-snapshot.v20251126014211 --save-exact

@clerk/types

npm i @clerk/types@4.101.4-snapshot.v20251126014211 --save-exact

@clerk/vue

npm i @clerk/vue@1.17.1-snapshot.v20251126014211 --save-exact

@wobsoriano
wobsoriano merged commit cf66d07 into mainNov 26, 2025
71 of 79 checks passed
@wobsoriano
wobsoriano deleted the rob/fix-api-keys-freeze branch November 26, 2025 01:54
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@wobsoriano@clerk-cookie@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcher - #7316

Merged
wobsoriano merged 8 commits into
mainfrom
rob/fix-api-keys-freeze
Nov 26, 2025
Merged

fix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcher#7316
wobsoriano merged 8 commits into
mainfrom
rob/fix-api-keys-freeze

Conversation

@wobsoriano

@wobsorianowobsoriano commented Nov 26, 2025

Copy link
Copy Markdown
Member

Description

Fixes an issue where UserButton and OrganizationSwitcher would mutate their props in-place when custom pages were present, causing unpredictable behavior and infinite update loops.

Screen.Recording.2025-11-25.at.4.51.41.PM.mov

Resolves USER-4092

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes
    • Fixed an issue where the APIKeys component on a custom page could cause the application to freeze.

✏️ Tip: You can customize this high-level summary in your review settings.

@changeset-bot

changeset-botBot commented Nov 26, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 03208b0

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 8 packages
NameType
@clerk/clerk-reactPatch
@clerk/chrome-extensionPatch
@clerk/elementsPatch
@clerk/clerk-expoPatch
@clerk/nextjsPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Nov 26, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentNov 26, 2025 1:37am

@coderabbitai

coderabbitaiBot commented Nov 26, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Replaced mutation-based object composition with non-mutating spread syntax in UserButton and OrganizationSwitcher components to fix an issue where APIKeys component mounted on custom pages caused application freezing. Added corresponding changeset entry.

Changes

Cohort / File(s)Summary
Core Fix
packages/react/src/components/uiComponents.tsx
Replaced Object.assign(props.userProfileProps || {}, { customPages }) with spread syntax { ...props.userProfileProps, customPages } in UserButton; applied same pattern to OrganizationSwitcher's organizationProfileProps. Eliminates input prop mutation.
Changelog
.changeset/hot-ads-relate.md
Added changeset entry documenting Clerk React patch fixing APIKeys component freezing issue when mounted on custom pages within UserButton.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

  • Verify spread syntax correctly handles undefined/null cases (non-mutating behavior is key to fix)
  • Confirm changeset description accurately reflects the freeze fix and component scope

Poem

🐰 A freeze in custom pages met its end,
When mutations gave way to spread, my friend!
No more Object.assign's mutant ways,
Just pristine objects through the maze! ✨

Pre-merge checks and finishing touches

✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main fix: preventing prop mutation in UserButton and OrganizationSwitcher components.
Linked Issues check✅ PassedCode changes directly address USER-4092 by replacing Object.assign mutations with spread syntax, eliminating in-place prop mutation that caused infinite update loops.
Out of Scope Changes check✅ PassedAll changes are in-scope: UserButton and OrganizationSwitcher prop mutation fixes directly address the linked issue, and the changeset accurately documents the fix.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch rob/fix-api-keys-freeze

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between c061534 and 03208b0.

📒 Files selected for processing (1)
  • packages/react/src/components/uiComponents.tsx (2 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/react/src/components/uiComponents.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (29)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Static analysis
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Nov 26, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7316

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7316

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7316

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7316

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7316

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7316

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7316

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7316

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7316

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7316

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7316

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7316

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7316

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7316

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7316

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7316

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7316

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7316

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7316

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7316

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7316

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7316

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7316

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7316

commit: 03208b0

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/react/src/components/ClerkHostRenderer.tsx (1)

81-93: Consider extracting nested prop stripping to a helper function.

The logic correctly strips customPages from nested profile props, but the repetitive pattern could be simplified for better maintainability.

Consider extracting this into a helper function:

conststripNestedCustomPages=(props: any)=>{constresult={ ...props};if(result.userProfileProps){result.userProfileProps=without(result.userProfileProps,'customPages');}if(result.organizationProfileProps){result.organizationProfileProps=without(result.organizationProfileProps,'customPages');}returnresult;};// Then use it:constprevProps=stripNestedCustomPages(without(_prevProps.props,'customPages','customMenuItems','children'));constnewProps=stripNestedCustomPages(without(this.props.props,'customPages','customMenuItems','children'));
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between f115e56 and 9ec689d.

📒 Files selected for processing (2)
  • .changeset/nice-goats-visit.md (1 hunks)
  • packages/react/src/components/ClerkHostRenderer.tsx (1 hunks)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

All code must pass ESLint checks with the project's configuration

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{js,jsx,ts,tsx,json,md,yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
packages/**/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Follow established naming conventions (PascalCase for components, camelCase for variables)

Prefer importing types from @clerk/shared/types instead of the deprecated @clerk/types alias

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
packages/**/src/**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

packages/**/src/**/*.{ts,tsx,js,jsx}: Maintain comprehensive JSDoc comments for public APIs
Use tree-shaking friendly exports
Validate all inputs and sanitize outputs
All public APIs must be documented with JSDoc
Use dynamic imports for optional features
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Implement proper logging with different levels

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.ts?(x)

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.tsx

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.tsx: Use error boundaries in React components
Minimize re-renders in React components

**/*.tsx: Use proper type definitions for props and state in React components
Leverage TypeScript's type inference where possible in React components
Use proper event types for handlers in React components
Implement proper generic types for reusable React components
Use proper type guards for conditional rendering in React components

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{md,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Update documentation for API changes

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/react.mdc)

**/*.{jsx,tsx}: Always use functional components with hooks instead of class components
Follow PascalCase naming for components (e.g., UserProfile, NavigationMenu)
Keep components focused on a single responsibility - split large components
Limit component size to 150-200 lines; extract logic into custom hooks
Use composition over inheritance - prefer smaller, composable components
Export components as named exports for better tree-shaking
One component per file with matching filename and component name
Separate UI components from business logic components
Use useState for simple state management in React components
Use useReducer for complex state logic in React components
Implement proper state initialization in React components
Use proper state updates with callbacks in React components
Implement proper state cleanup in React components
Use Context API for theme/authentication state management
Implement proper state persistence in React applications
Use React.memo for expensive components
Implement proper useCallback for handlers in React components
Use proper useMemo for expensive computations in React components
Implement proper virtualization for lists in React components
Use proper code splitting with React.lazy in React applications
Implement proper cleanup in useEffect hooks
Use proper refs for DOM access in React components
Implement proper event listener cleanup in React components
Use proper abort controllers for fetch in React components
Implement proper subscription cleanup in React components
Use proper HTML elements for semantic HTML in React components
Implement proper ARIA attributes for accessibility in React components
Use proper heading hierarchy in React components
Implement proper form labels in React components
Use proper button types in React components
Implement proper focus management for keyboard navigation in React components
Use proper keyboard shortcuts in React components
Implement proper tab order in React components
Use proper ...

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/typescript.mdc)

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Implement type guards for unknown types using the pattern function isType(value: unknown): value is Type
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details in classes
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Use mixins for shared behavior across unrelated classes in TypeScript
Use generic constraints with bounded type parameters like <T extends { id: string }>
Use utility types like Omit, Partial, and Pick for data transformation instead of manual type construction
Use discriminated unions instead of boolean flags for state management and API responses
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation at the type level
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Document functions with JSDoc comments including @PARAM, @returns, @throws, and @example tags
Create custom error classes that extend Error for specific error types
Use the Result pattern for error handling instead of throwing exceptions
Use optional chaining (?.) and nullish coalescing (??) operators for safe property access
Let TypeScript infer obvious types to reduce verbosity
Use const assertions with as const for literal types
Use satisfies operator for type checking without widening types
Declare readonly arrays and objects for immutable data structures
Use spread operator and array spread for immutable updates instead of mutations
Use lazy loading for large types...

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (32)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Unit Tests (22, shared, clerk-js, RQ)
  • GitHub Check: Unit Tests (22, **)
  • GitHub Check: Publish with pkg-pr-new
  • GitHub Check: Static analysis
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (2)
.changeset/nice-goats-visit.md (1)

1-5: LGTM!

The changeset follows the standard format and correctly documents the patch release for the API keys freezing fix.

packages/react/src/components/ClerkHostRenderer.tsx (1)

96-104: LGTM! Change detection logic is correct.

The extended change detection properly handles:

  • Top-level customPages length comparison
  • Nested userProfileProps.customPages length comparison
  • Nested organizationProfileProps.customPages length comparison
  • Optional chaining correctly handles undefined cases

The extraction of customMenuItemsChanged on lines 103-104 also improves readability.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/react/src/components/uiComponents.tsx (1)

257-271: Immutability fix for userProfileProps looks correct

Using Object.assign({}, props.userProfileProps, { customPages }) now composes userProfileProps without mutating the caller’s object, while preserving the previous merge semantics (later sources override earlier ones). If you want stylistic consistency with nearby code, you could optionally switch to object spread (const userProfileProps = { ...props.userProfileProps, customPages };), but the current change is already solid.

📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 9ec689d and 0ddf58b.

📒 Files selected for processing (1)
  • packages/react/src/components/uiComponents.tsx (2 hunks)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

All code must pass ESLint checks with the project's configuration

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{js,jsx,ts,tsx,json,md,yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/react/src/components/uiComponents.tsx
packages/**/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Follow established naming conventions (PascalCase for components, camelCase for variables)

Prefer importing types from @clerk/shared/types instead of the deprecated @clerk/types alias

Files:

  • packages/react/src/components/uiComponents.tsx
packages/**/src/**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

packages/**/src/**/*.{ts,tsx,js,jsx}: Maintain comprehensive JSDoc comments for public APIs
Use tree-shaking friendly exports
Validate all inputs and sanitize outputs
All public APIs must be documented with JSDoc
Use dynamic imports for optional features
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Implement proper logging with different levels

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.ts?(x)

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.tsx

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.tsx: Use error boundaries in React components
Minimize re-renders in React components

**/*.tsx: Use proper type definitions for props and state in React components
Leverage TypeScript's type inference where possible in React components
Use proper event types for handlers in React components
Implement proper generic types for reusable React components
Use proper type guards for conditional rendering in React components

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{md,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Update documentation for API changes

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/react.mdc)

**/*.{jsx,tsx}: Always use functional components with hooks instead of class components
Follow PascalCase naming for components (e.g., UserProfile, NavigationMenu)
Keep components focused on a single responsibility - split large components
Limit component size to 150-200 lines; extract logic into custom hooks
Use composition over inheritance - prefer smaller, composable components
Export components as named exports for better tree-shaking
One component per file with matching filename and component name
Separate UI components from business logic components
Use useState for simple state management in React components
Use useReducer for complex state logic in React components
Implement proper state initialization in React components
Use proper state updates with callbacks in React components
Implement proper state cleanup in React components
Use Context API for theme/authentication state management
Implement proper state persistence in React applications
Use React.memo for expensive components
Implement proper useCallback for handlers in React components
Use proper useMemo for expensive computations in React components
Implement proper virtualization for lists in React components
Use proper code splitting with React.lazy in React applications
Implement proper cleanup in useEffect hooks
Use proper refs for DOM access in React components
Implement proper event listener cleanup in React components
Use proper abort controllers for fetch in React components
Implement proper subscription cleanup in React components
Use proper HTML elements for semantic HTML in React components
Implement proper ARIA attributes for accessibility in React components
Use proper heading hierarchy in React components
Implement proper form labels in React components
Use proper button types in React components
Implement proper focus management for keyboard navigation in React components
Use proper keyboard shortcuts in React components
Implement proper tab order in React components
Use proper ...

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/typescript.mdc)

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Implement type guards for unknown types using the pattern function isType(value: unknown): value is Type
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details in classes
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Use mixins for shared behavior across unrelated classes in TypeScript
Use generic constraints with bounded type parameters like <T extends { id: string }>
Use utility types like Omit, Partial, and Pick for data transformation instead of manual type construction
Use discriminated unions instead of boolean flags for state management and API responses
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation at the type level
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Document functions with JSDoc comments including @PARAM, @returns, @throws, and @example tags
Create custom error classes that extend Error for specific error types
Use the Result pattern for error handling instead of throwing exceptions
Use optional chaining (?.) and nullish coalescing (??) operators for safe property access
Let TypeScript infer obvious types to reduce verbosity
Use const assertions with as const for literal types
Use satisfies operator for type checking without widening types
Declare readonly arrays and objects for immutable data structures
Use spread operator and array spread for immutable updates instead of mutations
Use lazy loading for large types...

Files:

  • packages/react/src/components/uiComponents.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (1)
packages/react/src/components/uiComponents.tsx (1)

435-446: Non-mutating organizationProfileProps composition is consistent

Same pattern here: building organizationProfileProps via Object.assign({}, ...) avoids mutating props.organizationProfileProps and keeps behavior equivalent apart from the intentional immutability improvement. No further issues from this change.

@wobsorianowobsoriano changed the title fix(clerk-react): [do-not-review] Attempt to fix API keys AIO freezing within UserButton.UserProfilePagefix(clerk-react): Fixes an issue where API keys component within custom pages freezesNov 26, 2025
@wobsorianowobsoriano changed the title fix(clerk-react): Fixes an issue where API keys component within custom pages freezesfix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcherNov 26, 2025
Comment threadpackages/react/src/components/uiComponents.tsx Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
.changeset/hot-ads-relate.md (1)

1-5: Add issue reference to changeset for traceability.

The changeset should reference the related issue (USER-4092) to provide traceability. Update the description to include the issue reference.

---
"@clerk/clerk-react": patch
----Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze.+Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze (USER-4092).

Optionally, consider a more comprehensive description that hints at the root cause to help future maintainers understand what was fixed:

---
"@clerk/clerk-react": patch
----Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze.+Resolved an issue where prop mutation in UserButton and OrganizationSwitcher caused infinite update loops, freezing the API Keys component when mounted in custom pages (USER-4092).
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 0ddf58b and c061534.

📒 Files selected for processing (1)
  • .changeset/hot-ads-relate.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/hot-ads-relate.md

[style] ~4-~4: Consider using a different verb for a more formal wording.
Context: --- "@clerk/clerk-react": patch --- Fixed an issue where <APIKeys /> mounted in...

(FIX_RESOLVE)

⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (34)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Unit Tests (22, **)
  • GitHub Check: Static analysis
  • GitHub Check: Unit Tests (22, shared, clerk-js, RQ)
  • GitHub Check: Publish with pkg-pr-new
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan

Comment threadpackages/react/src/components/uiComponents.tsx Outdated
Comment threadpackages/react/src/components/uiComponents.tsx Outdated

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

wobsorianoand others added 2 commits November 25, 2025 17:36
Co-authored-by: Jacek Radko <jacek@clerk.dev>
Co-authored-by: Jacek Radko <jacek@clerk.dev>
@wobsoriano
wobsoriano enabled auto-merge (squash) November 26, 2025 01:40
@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.2.6-snapshot.v20251126014211
@clerk/astro2.16.4-snapshot.v20251126014211
@clerk/backend2.25.0-snapshot.v20251126014211
@clerk/chrome-extension2.8.7-snapshot.v20251126014211
@clerk/clerk-js5.111.1-snapshot.v20251126014211
@clerk/elements0.23.87-snapshot.v20251126014211
@clerk/clerk-expo2.19.7-snapshot.v20251126014211
@clerk/expo-passkeys0.4.23-snapshot.v20251126014211
@clerk/express1.7.54-snapshot.v20251126014211
@clerk/fastify2.6.6-snapshot.v20251126014211
@clerk/localizations3.28.6-snapshot.v20251126014211
@clerk/nextjs6.35.6-snapshot.v20251126014211
@clerk/nuxt1.13.4-snapshot.v20251126014211
@clerk/clerk-react5.57.1-snapshot.v20251126014211
@clerk/react-router2.3.1-snapshot.v20251126014211
@clerk/remix4.13.21-snapshot.v20251126014211
@clerk/shared3.37.0-snapshot.v20251126014211
@clerk/tanstack-react-start0.27.6-snapshot.v20251126014211
@clerk/testing1.13.20-snapshot.v20251126014211
@clerk/themes2.4.41-snapshot.v20251126014211
@clerk/types4.101.4-snapshot.v20251126014211
@clerk/vue1.17.1-snapshot.v20251126014211

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.2.6-snapshot.v20251126014211 --save-exact

@clerk/astro

npm i @clerk/astro@2.16.4-snapshot.v20251126014211 --save-exact

@clerk/backend

npm i @clerk/backend@2.25.0-snapshot.v20251126014211 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.8.7-snapshot.v20251126014211 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.111.1-snapshot.v20251126014211 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.87-snapshot.v20251126014211 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.19.7-snapshot.v20251126014211 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.4.23-snapshot.v20251126014211 --save-exact

@clerk/express

npm i @clerk/express@1.7.54-snapshot.v20251126014211 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.6.6-snapshot.v20251126014211 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.28.6-snapshot.v20251126014211 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.35.6-snapshot.v20251126014211 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.13.4-snapshot.v20251126014211 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.57.1-snapshot.v20251126014211 --save-exact

@clerk/react-router

npm i @clerk/react-router@2.3.1-snapshot.v20251126014211 --save-exact

@clerk/remix

npm i @clerk/remix@4.13.21-snapshot.v20251126014211 --save-exact

@clerk/shared

npm i @clerk/shared@3.37.0-snapshot.v20251126014211 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.27.6-snapshot.v20251126014211 --save-exact

@clerk/testing

npm i @clerk/testing@1.13.20-snapshot.v20251126014211 --save-exact

@clerk/themes

npm i @clerk/themes@2.4.41-snapshot.v20251126014211 --save-exact

@clerk/types

npm i @clerk/types@4.101.4-snapshot.v20251126014211 --save-exact

@clerk/vue

npm i @clerk/vue@1.17.1-snapshot.v20251126014211 --save-exact

@wobsoriano
wobsoriano merged commit cf66d07 into mainNov 26, 2025
71 of 79 checks passed
@wobsoriano
wobsoriano deleted the rob/fix-api-keys-freeze branch November 26, 2025 01:54
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@wobsoriano@clerk-cookie@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcher - #7316

Merged
wobsoriano merged 8 commits into
mainfrom
rob/fix-api-keys-freeze
Nov 26, 2025
Merged

fix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcher#7316
wobsoriano merged 8 commits into
mainfrom
rob/fix-api-keys-freeze

Conversation

@wobsoriano

@wobsorianowobsoriano commented Nov 26, 2025

Copy link
Copy Markdown
Member

Description

Fixes an issue where UserButton and OrganizationSwitcher would mutate their props in-place when custom pages were present, causing unpredictable behavior and infinite update loops.

Screen.Recording.2025-11-25.at.4.51.41.PM.mov

Resolves USER-4092

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes
    • Fixed an issue where the APIKeys component on a custom page could cause the application to freeze.

✏️ Tip: You can customize this high-level summary in your review settings.

@changeset-bot

changeset-botBot commented Nov 26, 2025

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 03208b0

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 8 packages
NameType
@clerk/clerk-reactPatch
@clerk/chrome-extensionPatch
@clerk/elementsPatch
@clerk/clerk-expoPatch
@clerk/nextjsPatch
@clerk/react-routerPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Nov 26, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentPreviewCommentsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewCommentNov 26, 2025 1:37am

@coderabbitai

coderabbitaiBot commented Nov 26, 2025

Copy link
Copy Markdown
Contributor

Walkthrough

Replaced mutation-based object composition with non-mutating spread syntax in UserButton and OrganizationSwitcher components to fix an issue where APIKeys component mounted on custom pages caused application freezing. Added corresponding changeset entry.

Changes

Cohort / File(s)Summary
Core Fix
packages/react/src/components/uiComponents.tsx
Replaced Object.assign(props.userProfileProps || {}, { customPages }) with spread syntax { ...props.userProfileProps, customPages } in UserButton; applied same pattern to OrganizationSwitcher's organizationProfileProps. Eliminates input prop mutation.
Changelog
.changeset/hot-ads-relate.md
Added changeset entry documenting Clerk React patch fixing APIKeys component freezing issue when mounted on custom pages within UserButton.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

  • Verify spread syntax correctly handles undefined/null cases (non-mutating behavior is key to fix)
  • Confirm changeset description accurately reflects the freeze fix and component scope

Poem

🐰 A freeze in custom pages met its end,
When mutations gave way to spread, my friend!
No more Object.assign's mutant ways,
Just pristine objects through the maze! ✨

Pre-merge checks and finishing touches

✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main fix: preventing prop mutation in UserButton and OrganizationSwitcher components.
Linked Issues check✅ PassedCode changes directly address USER-4092 by replacing Object.assign mutations with spread syntax, eliminating in-place prop mutation that caused infinite update loops.
Out of Scope Changes check✅ PassedAll changes are in-scope: UserButton and OrganizationSwitcher prop mutation fixes directly address the linked issue, and the changeset accurately documents the fix.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing touches
  • 📝 Generate docstrings
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch rob/fix-api-keys-freeze

📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between c061534 and 03208b0.

📒 Files selected for processing (1)
  • packages/react/src/components/uiComponents.tsx (2 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/react/src/components/uiComponents.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (29)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Static analysis
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan

Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Nov 26, 2025

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@7316

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@7316

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@7316

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@7316

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@7316

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@7316

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@7316

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@7316

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@7316

@clerk/express

npm i https://pkg.pr.new/@clerk/express@7316

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@7316

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@7316

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@7316

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@7316

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@7316

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@7316

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@7316

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@7316

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@7316

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@7316

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@7316

@clerk/types

npm i https://pkg.pr.new/@clerk/types@7316

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@7316

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@7316

commit: 03208b0

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/react/src/components/ClerkHostRenderer.tsx (1)

81-93: Consider extracting nested prop stripping to a helper function.

The logic correctly strips customPages from nested profile props, but the repetitive pattern could be simplified for better maintainability.

Consider extracting this into a helper function:

conststripNestedCustomPages=(props: any)=>{constresult={ ...props};if(result.userProfileProps){result.userProfileProps=without(result.userProfileProps,'customPages');}if(result.organizationProfileProps){result.organizationProfileProps=without(result.organizationProfileProps,'customPages');}returnresult;};// Then use it:constprevProps=stripNestedCustomPages(without(_prevProps.props,'customPages','customMenuItems','children'));constnewProps=stripNestedCustomPages(without(this.props.props,'customPages','customMenuItems','children'));
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between f115e56 and 9ec689d.

📒 Files selected for processing (2)
  • .changeset/nice-goats-visit.md (1 hunks)
  • packages/react/src/components/ClerkHostRenderer.tsx (1 hunks)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

All code must pass ESLint checks with the project's configuration

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{js,jsx,ts,tsx,json,md,yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
packages/**/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Follow established naming conventions (PascalCase for components, camelCase for variables)

Prefer importing types from @clerk/shared/types instead of the deprecated @clerk/types alias

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
packages/**/src/**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

packages/**/src/**/*.{ts,tsx,js,jsx}: Maintain comprehensive JSDoc comments for public APIs
Use tree-shaking friendly exports
Validate all inputs and sanitize outputs
All public APIs must be documented with JSDoc
Use dynamic imports for optional features
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Implement proper logging with different levels

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.ts?(x)

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.tsx

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.tsx: Use error boundaries in React components
Minimize re-renders in React components

**/*.tsx: Use proper type definitions for props and state in React components
Leverage TypeScript's type inference where possible in React components
Use proper event types for handlers in React components
Implement proper generic types for reusable React components
Use proper type guards for conditional rendering in React components

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{md,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Update documentation for API changes

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/react.mdc)

**/*.{jsx,tsx}: Always use functional components with hooks instead of class components
Follow PascalCase naming for components (e.g., UserProfile, NavigationMenu)
Keep components focused on a single responsibility - split large components
Limit component size to 150-200 lines; extract logic into custom hooks
Use composition over inheritance - prefer smaller, composable components
Export components as named exports for better tree-shaking
One component per file with matching filename and component name
Separate UI components from business logic components
Use useState for simple state management in React components
Use useReducer for complex state logic in React components
Implement proper state initialization in React components
Use proper state updates with callbacks in React components
Implement proper state cleanup in React components
Use Context API for theme/authentication state management
Implement proper state persistence in React applications
Use React.memo for expensive components
Implement proper useCallback for handlers in React components
Use proper useMemo for expensive computations in React components
Implement proper virtualization for lists in React components
Use proper code splitting with React.lazy in React applications
Implement proper cleanup in useEffect hooks
Use proper refs for DOM access in React components
Implement proper event listener cleanup in React components
Use proper abort controllers for fetch in React components
Implement proper subscription cleanup in React components
Use proper HTML elements for semantic HTML in React components
Implement proper ARIA attributes for accessibility in React components
Use proper heading hierarchy in React components
Implement proper form labels in React components
Use proper button types in React components
Implement proper focus management for keyboard navigation in React components
Use proper keyboard shortcuts in React components
Implement proper tab order in React components
Use proper ...

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/typescript.mdc)

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Implement type guards for unknown types using the pattern function isType(value: unknown): value is Type
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details in classes
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Use mixins for shared behavior across unrelated classes in TypeScript
Use generic constraints with bounded type parameters like <T extends { id: string }>
Use utility types like Omit, Partial, and Pick for data transformation instead of manual type construction
Use discriminated unions instead of boolean flags for state management and API responses
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation at the type level
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Document functions with JSDoc comments including @PARAM, @returns, @throws, and @example tags
Create custom error classes that extend Error for specific error types
Use the Result pattern for error handling instead of throwing exceptions
Use optional chaining (?.) and nullish coalescing (??) operators for safe property access
Let TypeScript infer obvious types to reduce verbosity
Use const assertions with as const for literal types
Use satisfies operator for type checking without widening types
Declare readonly arrays and objects for immutable data structures
Use spread operator and array spread for immutable updates instead of mutations
Use lazy loading for large types...

Files:

  • packages/react/src/components/ClerkHostRenderer.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (32)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Unit Tests (22, shared, clerk-js, RQ)
  • GitHub Check: Unit Tests (22, **)
  • GitHub Check: Publish with pkg-pr-new
  • GitHub Check: Static analysis
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (2)
.changeset/nice-goats-visit.md (1)

1-5: LGTM!

The changeset follows the standard format and correctly documents the patch release for the API keys freezing fix.

packages/react/src/components/ClerkHostRenderer.tsx (1)

96-104: LGTM! Change detection logic is correct.

The extended change detection properly handles:

  • Top-level customPages length comparison
  • Nested userProfileProps.customPages length comparison
  • Nested organizationProfileProps.customPages length comparison
  • Optional chaining correctly handles undefined cases

The extraction of customMenuItemsChanged on lines 103-104 also improves readability.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/react/src/components/uiComponents.tsx (1)

257-271: Immutability fix for userProfileProps looks correct

Using Object.assign({}, props.userProfileProps, { customPages }) now composes userProfileProps without mutating the caller’s object, while preserving the previous merge semantics (later sources override earlier ones). If you want stylistic consistency with nearby code, you could optionally switch to object spread (const userProfileProps = { ...props.userProfileProps, customPages };), but the current change is already solid.

📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 9ec689d and 0ddf58b.

📒 Files selected for processing (1)
  • packages/react/src/components/uiComponents.tsx (2 hunks)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

All code must pass ESLint checks with the project's configuration

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{js,jsx,ts,tsx,json,md,yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use Prettier for consistent code formatting

Files:

  • packages/react/src/components/uiComponents.tsx
packages/**/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

TypeScript is required for all packages

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Follow established naming conventions (PascalCase for components, camelCase for variables)

Prefer importing types from @clerk/shared/types instead of the deprecated @clerk/types alias

Files:

  • packages/react/src/components/uiComponents.tsx
packages/**/src/**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

packages/**/src/**/*.{ts,tsx,js,jsx}: Maintain comprehensive JSDoc comments for public APIs
Use tree-shaking friendly exports
Validate all inputs and sanitize outputs
All public APIs must be documented with JSDoc
Use dynamic imports for optional features
Provide meaningful error messages to developers
Include error recovery suggestions where applicable
Log errors appropriately for debugging
Lazy load components and features when possible
Implement proper caching strategies
Use efficient data structures and algorithms
Implement proper logging with different levels

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.ts?(x)

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Use proper TypeScript error types

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.tsx

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

**/*.tsx: Use error boundaries in React components
Minimize re-renders in React components

**/*.tsx: Use proper type definitions for props and state in React components
Leverage TypeScript's type inference where possible in React components
Use proper event types for handlers in React components
Implement proper generic types for reusable React components
Use proper type guards for conditional rendering in React components

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{md,tsx}

📄 CodeRabbit inference engine (.cursor/rules/development.mdc)

Update documentation for API changes

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{jsx,tsx}

📄 CodeRabbit inference engine (.cursor/rules/react.mdc)

**/*.{jsx,tsx}: Always use functional components with hooks instead of class components
Follow PascalCase naming for components (e.g., UserProfile, NavigationMenu)
Keep components focused on a single responsibility - split large components
Limit component size to 150-200 lines; extract logic into custom hooks
Use composition over inheritance - prefer smaller, composable components
Export components as named exports for better tree-shaking
One component per file with matching filename and component name
Separate UI components from business logic components
Use useState for simple state management in React components
Use useReducer for complex state logic in React components
Implement proper state initialization in React components
Use proper state updates with callbacks in React components
Implement proper state cleanup in React components
Use Context API for theme/authentication state management
Implement proper state persistence in React applications
Use React.memo for expensive components
Implement proper useCallback for handlers in React components
Use proper useMemo for expensive computations in React components
Implement proper virtualization for lists in React components
Use proper code splitting with React.lazy in React applications
Implement proper cleanup in useEffect hooks
Use proper refs for DOM access in React components
Implement proper event listener cleanup in React components
Use proper abort controllers for fetch in React components
Implement proper subscription cleanup in React components
Use proper HTML elements for semantic HTML in React components
Implement proper ARIA attributes for accessibility in React components
Use proper heading hierarchy in React components
Implement proper form labels in React components
Use proper button types in React components
Implement proper focus management for keyboard navigation in React components
Use proper keyboard shortcuts in React components
Implement proper tab order in React components
Use proper ...

Files:

  • packages/react/src/components/uiComponents.tsx
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/typescript.mdc)

**/*.{ts,tsx}: Always define explicit return types for functions, especially public APIs
Use proper type annotations for variables and parameters where inference isn't clear
Avoid any type - prefer unknown when type is uncertain, then narrow with type guards
Implement type guards for unknown types using the pattern function isType(value: unknown): value is Type
Use interface for object shapes that might be extended
Use type for unions, primitives, and computed types
Prefer readonly properties for immutable data structures
Use private for internal implementation details in classes
Use protected for inheritance hierarchies
Use public explicitly for clarity in public APIs
Use mixins for shared behavior across unrelated classes in TypeScript
Use generic constraints with bounded type parameters like <T extends { id: string }>
Use utility types like Omit, Partial, and Pick for data transformation instead of manual type construction
Use discriminated unions instead of boolean flags for state management and API responses
Use mapped types for transforming object types
Use conditional types for type-level logic
Leverage template literal types for string manipulation at the type level
Use ES6 imports/exports consistently
Use default exports sparingly, prefer named exports
Document functions with JSDoc comments including @PARAM, @returns, @throws, and @example tags
Create custom error classes that extend Error for specific error types
Use the Result pattern for error handling instead of throwing exceptions
Use optional chaining (?.) and nullish coalescing (??) operators for safe property access
Let TypeScript infer obvious types to reduce verbosity
Use const assertions with as const for literal types
Use satisfies operator for type checking without widening types
Declare readonly arrays and objects for immutable data structures
Use spread operator and array spread for immutable updates instead of mutations
Use lazy loading for large types...

Files:

  • packages/react/src/components/uiComponents.tsx
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: Build Packages
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (1)
packages/react/src/components/uiComponents.tsx (1)

435-446: Non-mutating organizationProfileProps composition is consistent

Same pattern here: building organizationProfileProps via Object.assign({}, ...) avoids mutating props.organizationProfileProps and keeps behavior equivalent apart from the intentional immutability improvement. No further issues from this change.

@wobsorianowobsoriano changed the title fix(clerk-react): [do-not-review] Attempt to fix API keys AIO freezing within UserButton.UserProfilePagefix(clerk-react): Fixes an issue where API keys component within custom pages freezesNov 26, 2025
@wobsorianowobsoriano changed the title fix(clerk-react): Fixes an issue where API keys component within custom pages freezesfix(clerk-react): Prevent prop mutation in UserButton and OrganizationSwitcherNov 26, 2025
Comment threadpackages/react/src/components/uiComponents.tsx Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
.changeset/hot-ads-relate.md (1)

1-5: Add issue reference to changeset for traceability.

The changeset should reference the related issue (USER-4092) to provide traceability. Update the description to include the issue reference.

---
"@clerk/clerk-react": patch
----Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze.+Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze (USER-4092).

Optionally, consider a more comprehensive description that hints at the root cause to help future maintainers understand what was fixed:

---
"@clerk/clerk-react": patch
----Fixed an issue where `<APIKeys />` mounted in a custom page caused an application to freeze.+Resolved an issue where prop mutation in UserButton and OrganizationSwitcher caused infinite update loops, freezing the API Keys component when mounted in custom pages (USER-4092).
📜 Review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Disabled knowledge base sources:

  • Linear integration is disabled by default for public repositories

You can enable these sources in your CodeRabbit configuration.

📥 Commits

Reviewing files that changed from the base of the PR and between 0ddf58b and c061534.

📒 Files selected for processing (1)
  • .changeset/hot-ads-relate.md (1 hunks)
🧰 Additional context used
🪛 LanguageTool
.changeset/hot-ads-relate.md

[style] ~4-~4: Consider using a different verb for a more formal wording.
Context: --- "@clerk/clerk-react": patch --- Fixed an issue where <APIKeys /> mounted in...

(FIX_RESOLVE)

⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (34)
  • GitHub Check: Integration Tests (quickstart, chrome, 16)
  • GitHub Check: Integration Tests (nextjs, chrome, 15)
  • GitHub Check: Integration Tests (quickstart, chrome, 15)
  • GitHub Check: Integration Tests (nextjs, chrome, 15, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 14)
  • GitHub Check: Integration Tests (machine, chrome, RQ)
  • GitHub Check: Integration Tests (nextjs, chrome, 16)
  • GitHub Check: Integration Tests (billing, chrome)
  • GitHub Check: Integration Tests (nuxt, chrome)
  • GitHub Check: Integration Tests (handshake, chrome)
  • GitHub Check: Integration Tests (machine, chrome)
  • GitHub Check: Integration Tests (vue, chrome)
  • GitHub Check: Integration Tests (custom, chrome)
  • GitHub Check: Integration Tests (expo-web, chrome)
  • GitHub Check: Integration Tests (sessions:staging, chrome)
  • GitHub Check: Integration Tests (tanstack-react-start, chrome)
  • GitHub Check: Integration Tests (billing, chrome, RQ)
  • GitHub Check: Integration Tests (generic, chrome)
  • GitHub Check: Integration Tests (react-router, chrome)
  • GitHub Check: Integration Tests (sessions, chrome)
  • GitHub Check: Integration Tests (express, chrome)
  • GitHub Check: Integration Tests (astro, chrome)
  • GitHub Check: Integration Tests (localhost, chrome)
  • GitHub Check: Integration Tests (handshake:staging, chrome)
  • GitHub Check: Integration Tests (elements, chrome)
  • GitHub Check: Integration Tests (ap-flows, chrome)
  • GitHub Check: Unit Tests (22, **)
  • GitHub Check: Static analysis
  • GitHub Check: Unit Tests (22, shared, clerk-js, RQ)
  • GitHub Check: Publish with pkg-pr-new
  • GitHub Check: Formatting | Dedupe | Changeset
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: semgrep-cloud-platform/scan

Comment threadpackages/react/src/components/uiComponents.tsx Outdated
Comment threadpackages/react/src/components/uiComponents.tsx Outdated

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

wobsorianoand others added 2 commits November 25, 2025 17:36
Co-authored-by: Jacek Radko <jacek@clerk.dev>
Co-authored-by: Jacek Radko <jacek@clerk.dev>
@wobsoriano
wobsoriano enabled auto-merge (squash) November 26, 2025 01:40
@wobsoriano

Copy link
Copy Markdown
MemberAuthor

!snapshot

@clerk-cookie

Copy link
Copy Markdown
Collaborator

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/agent-toolkit0.2.6-snapshot.v20251126014211
@clerk/astro2.16.4-snapshot.v20251126014211
@clerk/backend2.25.0-snapshot.v20251126014211
@clerk/chrome-extension2.8.7-snapshot.v20251126014211
@clerk/clerk-js5.111.1-snapshot.v20251126014211
@clerk/elements0.23.87-snapshot.v20251126014211
@clerk/clerk-expo2.19.7-snapshot.v20251126014211
@clerk/expo-passkeys0.4.23-snapshot.v20251126014211
@clerk/express1.7.54-snapshot.v20251126014211
@clerk/fastify2.6.6-snapshot.v20251126014211
@clerk/localizations3.28.6-snapshot.v20251126014211
@clerk/nextjs6.35.6-snapshot.v20251126014211
@clerk/nuxt1.13.4-snapshot.v20251126014211
@clerk/clerk-react5.57.1-snapshot.v20251126014211
@clerk/react-router2.3.1-snapshot.v20251126014211
@clerk/remix4.13.21-snapshot.v20251126014211
@clerk/shared3.37.0-snapshot.v20251126014211
@clerk/tanstack-react-start0.27.6-snapshot.v20251126014211
@clerk/testing1.13.20-snapshot.v20251126014211
@clerk/themes2.4.41-snapshot.v20251126014211
@clerk/types4.101.4-snapshot.v20251126014211
@clerk/vue1.17.1-snapshot.v20251126014211

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/agent-toolkit

npm i @clerk/agent-toolkit@0.2.6-snapshot.v20251126014211 --save-exact

@clerk/astro

npm i @clerk/astro@2.16.4-snapshot.v20251126014211 --save-exact

@clerk/backend

npm i @clerk/backend@2.25.0-snapshot.v20251126014211 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@2.8.7-snapshot.v20251126014211 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@5.111.1-snapshot.v20251126014211 --save-exact

@clerk/elements

npm i @clerk/elements@0.23.87-snapshot.v20251126014211 --save-exact

@clerk/clerk-expo

npm i @clerk/clerk-expo@2.19.7-snapshot.v20251126014211 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@0.4.23-snapshot.v20251126014211 --save-exact

@clerk/express

npm i @clerk/express@1.7.54-snapshot.v20251126014211 --save-exact

@clerk/fastify

npm i @clerk/fastify@2.6.6-snapshot.v20251126014211 --save-exact

@clerk/localizations

npm i @clerk/localizations@3.28.6-snapshot.v20251126014211 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@6.35.6-snapshot.v20251126014211 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@1.13.4-snapshot.v20251126014211 --save-exact

@clerk/clerk-react

npm i @clerk/clerk-react@5.57.1-snapshot.v20251126014211 --save-exact

@clerk/react-router

npm i @clerk/react-router@2.3.1-snapshot.v20251126014211 --save-exact

@clerk/remix

npm i @clerk/remix@4.13.21-snapshot.v20251126014211 --save-exact

@clerk/shared

npm i @clerk/shared@3.37.0-snapshot.v20251126014211 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@0.27.6-snapshot.v20251126014211 --save-exact

@clerk/testing

npm i @clerk/testing@1.13.20-snapshot.v20251126014211 --save-exact

@clerk/themes

npm i @clerk/themes@2.4.41-snapshot.v20251126014211 --save-exact

@clerk/types

npm i @clerk/types@4.101.4-snapshot.v20251126014211 --save-exact

@clerk/vue

npm i @clerk/vue@1.17.1-snapshot.v20251126014211 --save-exact

@wobsoriano
wobsoriano merged commit cf66d07 into mainNov 26, 2025
71 of 79 checks passed
@wobsoriano
wobsoriano deleted the rob/fix-api-keys-freeze branch November 26, 2025 01:54
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@wobsoriano@clerk-cookie@jacekradko