Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/five-carrots-laugh.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
---
'@clerk/chrome-extension': minor
'@clerk/ui': minor
---

Remove remotely hosted code from new @clerk/ui package
2 changes: 1 addition & 1 deletion packages/chrome-extension/src/react/ClerkProvider.tsx
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
import type { Clerk } from '@clerk/clerk-js/no-rhc';
import type { ClerkProviderProps as ClerkReactProviderProps } from '@clerk/react';
import { InternalClerkProvider as ClerkReactProvider } from '@clerk/react/internal';
import { ui } from '@clerk/ui';
import { ui } from '@clerk/ui/no-rhc';
import React from 'react';

import { createClerkClient } from '../internal/clerk';
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -11,7 +11,7 @@ vi.mock('@clerk/clerk-js/no-rhc', () => {
return { Clerk };
});

vi.mock('@clerk/ui', () => ({
vi.mock('@clerk/ui/no-rhc', () => ({
ui: mockUi,
}));

Expand Down
2 changes: 1 addition & 1 deletion packages/chrome-extension/src/utils/clerk-client.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -28,7 +28,7 @@ export function createClerkClient(opts: CreateClerkClientOptions): Clerk | Promi

const originalLoad = clerk.load.bind(clerk);
clerk.load = async (loadOpts?: Parameters<typeof clerk.load>[0]) => {
const { ui } = await import('@clerk/ui');
const { ui } = await import('@clerk/ui/no-rhc');
return originalLoad({ ...loadOpts, ui });
};

Expand Down
8 changes: 7 additions & 1 deletion packages/ui/package.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -25,6 +25,11 @@
"import": "./dist/index.js",
"default": "./dist/index.js"
},
"./no-rhc": {
"types": "./dist/index.d.ts",
"import": "./dist/no-rhc/index.js",
"default": "./dist/no-rhc/index.js"
},
"./entry": {
"types": "./dist/entry.d.ts",
"import": "./dist/entry.js",
Expand DownExpand Up@@ -64,13 +69,14 @@
"register"
],
"scripts": {
"build": "pnpm build:umd && pnpm build:esm",
"build": "pnpm build:umd && pnpm build:esm && pnpm check:no-rhc",
"build:analyze": "rspack build --config rspack.config.js --env production --env analyze --analyze",
"build:esm": "tsdown",
"build:rsdoctor": "RSDOCTOR=true rspack build --config rspack.config.js --env production",
"build:umd": "rspack build --config rspack.config.js --env production",
"bundlewatch": "FORCE_COLOR=1 bundlewatch --config bundlewatch.config.json",
"bundlewatch:fix": "node bundlewatch-fix.mjs",
"check:no-rhc": "node ../../scripts/search-for-rhc.mjs directory dist/no-rhc",
"clean": "rimraf ./dist",
"dev": "rspack serve --config rspack.config.js",
"dev:origin": "rspack serve --config rspack.config.js --env devOrigin=http://localhost:${PORT:-4011}",
Expand Down
3 changes: 3 additions & 0 deletions packages/ui/src/utils/one-tap.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -39,6 +39,9 @@ declare global {
}

async function loadGIS() {
if (__BUILD_DISABLE_RHC__) {
return undefined as unknown as Google;
}
Comment on lines +42 to +44

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Do not return undefined cast as Google in no-RHC builds.

Line 43 creates a type/runtime mismatch (undefined masquerading as Google). This can cause runtime crashes when consumers dereference the result.

🐛 Proposed fix
-async function loadGIS() {+async function loadGIS(): Promise<Google> {
if (__BUILD_DISABLE_RHC__) {
- return undefined as unknown as Google;+ clerkFailedToLoadThirdPartyScript('Google Identity Services');
}
if (!window.google) {
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/ui/src/utils/one-tap.ts` around lines 42 - 44, The branch that
returns "undefined as unknown as Google" when __BUILD_DISABLE_RHC__ is true must
be fixed: change the function's return type to allow undefined (e.g., Google |
undefined) or return a safe stub object instead of force-casting undefined;
update the code around the __BUILD_DISABLE_RHC__ check so it either returns a
proper fallback implementation or an unambiguous undefined/null (no cast) and
adjust all callers of the function (the function that contains the
__BUILD_DISABLE_RHC__ branch and any usages expecting a Google) to handle the
optional value accordingly.

if (!window.google) {
try {
await loadScript('https://accounts.google.com/gsi/client', { defer: true });
Expand Down
11 changes: 11 additions & 0 deletions packages/ui/tsdown.config.mts
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,5 +55,16 @@ export default defineConfig(({ watch }) => {
}
},
},
{
...common,
dts: false,
entry: ['./src/index.ts'],
outDir: './dist/no-rhc',
unbundle: true,
define: {
...common.define,
__BUILD_DISABLE_RHC__: 'true',
},
},
];
});
1 change: 1 addition & 0 deletions scripts/search-for-rhc.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -27,6 +27,7 @@ async function asyncSearchRHC(name, search, regex = false) {
await Promise.allSettled([
asyncSearchRHC('Turnstile', 'cloudflare.com/turnstile/v0/api.js'),
asyncSearchRHC('clerk-js Hotloading', '/npm/@clerk/clerk-js'),
asyncSearchRHC('clerk-ui Hotloading', '/npm/@clerk/ui'),
asyncSearchRHC('Google One Tap', 'accounts.google.com/gsi/client'),
asyncSearchRHC('Coinbase', 'coinbase.com'),
asyncSearchRHC('Coinbase Wallet import', 'import\s*"@coinbase/wallet-sdk', true), // eslint-disable-line no-useless-escape
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(ui): Initial pass for adding RHC guards to ui package by royanger · Pull Request #7983 · clerk/javascript · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/five-carrots-laugh.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
---
'@clerk/chrome-extension': minor
'@clerk/ui': minor
---

Remove remotely hosted code from new @clerk/ui package
2 changes: 1 addition & 1 deletion packages/chrome-extension/src/react/ClerkProvider.tsx
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
import type { Clerk } from '@clerk/clerk-js/no-rhc';
import type { ClerkProviderProps as ClerkReactProviderProps } from '@clerk/react';
import { InternalClerkProvider as ClerkReactProvider } from '@clerk/react/internal';
import { ui } from '@clerk/ui';
import { ui } from '@clerk/ui/no-rhc';
import React from 'react';

import { createClerkClient } from '../internal/clerk';
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -11,7 +11,7 @@ vi.mock('@clerk/clerk-js/no-rhc', () => {
return { Clerk };
});

vi.mock('@clerk/ui', () => ({
vi.mock('@clerk/ui/no-rhc', () => ({
ui: mockUi,
}));

Expand Down
2 changes: 1 addition & 1 deletion packages/chrome-extension/src/utils/clerk-client.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -28,7 +28,7 @@ export function createClerkClient(opts: CreateClerkClientOptions): Clerk | Promi

const originalLoad = clerk.load.bind(clerk);
clerk.load = async (loadOpts?: Parameters<typeof clerk.load>[0]) => {
const { ui } = await import('@clerk/ui');
const { ui } = await import('@clerk/ui/no-rhc');
return originalLoad({ ...loadOpts, ui });
};

Expand Down
8 changes: 7 additions & 1 deletion packages/ui/package.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -25,6 +25,11 @@
"import": "./dist/index.js",
"default": "./dist/index.js"
},
"./no-rhc": {
"types": "./dist/index.d.ts",
"import": "./dist/no-rhc/index.js",
"default": "./dist/no-rhc/index.js"
},
"./entry": {
"types": "./dist/entry.d.ts",
"import": "./dist/entry.js",
Expand DownExpand Up@@ -64,13 +69,14 @@
"register"
],
"scripts": {
"build": "pnpm build:umd && pnpm build:esm",
"build": "pnpm build:umd && pnpm build:esm && pnpm check:no-rhc",
"build:analyze": "rspack build --config rspack.config.js --env production --env analyze --analyze",
"build:esm": "tsdown",
"build:rsdoctor": "RSDOCTOR=true rspack build --config rspack.config.js --env production",
"build:umd": "rspack build --config rspack.config.js --env production",
"bundlewatch": "FORCE_COLOR=1 bundlewatch --config bundlewatch.config.json",
"bundlewatch:fix": "node bundlewatch-fix.mjs",
"check:no-rhc": "node ../../scripts/search-for-rhc.mjs directory dist/no-rhc",
"clean": "rimraf ./dist",
"dev": "rspack serve --config rspack.config.js",
"dev:origin": "rspack serve --config rspack.config.js --env devOrigin=http://localhost:${PORT:-4011}",
Expand Down
3 changes: 3 additions & 0 deletions packages/ui/src/utils/one-tap.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -39,6 +39,9 @@ declare global {
}

async function loadGIS() {
if (__BUILD_DISABLE_RHC__) {
return undefined as unknown as Google;
}
Comment on lines +42 to +44

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Do not return undefined cast as Google in no-RHC builds.

Line 43 creates a type/runtime mismatch (undefined masquerading as Google). This can cause runtime crashes when consumers dereference the result.

🐛 Proposed fix
-async function loadGIS() {+async function loadGIS(): Promise<Google> {
if (__BUILD_DISABLE_RHC__) {
- return undefined as unknown as Google;+ clerkFailedToLoadThirdPartyScript('Google Identity Services');
}
if (!window.google) {
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/ui/src/utils/one-tap.ts` around lines 42 - 44, The branch that
returns "undefined as unknown as Google" when __BUILD_DISABLE_RHC__ is true must
be fixed: change the function's return type to allow undefined (e.g., Google |
undefined) or return a safe stub object instead of force-casting undefined;
update the code around the __BUILD_DISABLE_RHC__ check so it either returns a
proper fallback implementation or an unambiguous undefined/null (no cast) and
adjust all callers of the function (the function that contains the
__BUILD_DISABLE_RHC__ branch and any usages expecting a Google) to handle the
optional value accordingly.

if (!window.google) {
try {
await loadScript('https://accounts.google.com/gsi/client', { defer: true });
Expand Down
11 changes: 11 additions & 0 deletions packages/ui/tsdown.config.mts
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,5 +55,16 @@ export default defineConfig(({ watch }) => {
}
},
},
{
...common,
dts: false,
entry: ['./src/index.ts'],
outDir: './dist/no-rhc',
unbundle: true,
define: {
...common.define,
__BUILD_DISABLE_RHC__: 'true',
},
},
];
});
1 change: 1 addition & 0 deletions scripts/search-for-rhc.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -27,6 +27,7 @@ async function asyncSearchRHC(name, search, regex = false) {
await Promise.allSettled([
asyncSearchRHC('Turnstile', 'cloudflare.com/turnstile/v0/api.js'),
asyncSearchRHC('clerk-js Hotloading', '/npm/@clerk/clerk-js'),
asyncSearchRHC('clerk-ui Hotloading', '/npm/@clerk/ui'),
asyncSearchRHC('Google One Tap', 'accounts.google.com/gsi/client'),
asyncSearchRHC('Coinbase', 'coinbase.com'),
asyncSearchRHC('Coinbase Wallet import', 'import\s*"@coinbase/wallet-sdk', true), // eslint-disable-line no-useless-escape
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(ui): Initial pass for adding RHC guards to ui package by royanger · Pull Request #7983 · clerk/javascript · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/five-carrots-laugh.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
---
'@clerk/chrome-extension': minor
'@clerk/ui': minor
---

Remove remotely hosted code from new @clerk/ui package
2 changes: 1 addition & 1 deletion packages/chrome-extension/src/react/ClerkProvider.tsx
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
import type { Clerk } from '@clerk/clerk-js/no-rhc';
import type { ClerkProviderProps as ClerkReactProviderProps } from '@clerk/react';
import { InternalClerkProvider as ClerkReactProvider } from '@clerk/react/internal';
import { ui } from '@clerk/ui';
import { ui } from '@clerk/ui/no-rhc';
import React from 'react';

import { createClerkClient } from '../internal/clerk';
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -11,7 +11,7 @@ vi.mock('@clerk/clerk-js/no-rhc', () => {
return { Clerk };
});

vi.mock('@clerk/ui', () => ({
vi.mock('@clerk/ui/no-rhc', () => ({
ui: mockUi,
}));

Expand Down
2 changes: 1 addition & 1 deletion packages/chrome-extension/src/utils/clerk-client.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -28,7 +28,7 @@ export function createClerkClient(opts: CreateClerkClientOptions): Clerk | Promi

const originalLoad = clerk.load.bind(clerk);
clerk.load = async (loadOpts?: Parameters<typeof clerk.load>[0]) => {
const { ui } = await import('@clerk/ui');
const { ui } = await import('@clerk/ui/no-rhc');
return originalLoad({ ...loadOpts, ui });
};

Expand Down
8 changes: 7 additions & 1 deletion packages/ui/package.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -25,6 +25,11 @@
"import": "./dist/index.js",
"default": "./dist/index.js"
},
"./no-rhc": {
"types": "./dist/index.d.ts",
"import": "./dist/no-rhc/index.js",
"default": "./dist/no-rhc/index.js"
},
"./entry": {
"types": "./dist/entry.d.ts",
"import": "./dist/entry.js",
Expand DownExpand Up@@ -64,13 +69,14 @@
"register"
],
"scripts": {
"build": "pnpm build:umd && pnpm build:esm",
"build": "pnpm build:umd && pnpm build:esm && pnpm check:no-rhc",
"build:analyze": "rspack build --config rspack.config.js --env production --env analyze --analyze",
"build:esm": "tsdown",
"build:rsdoctor": "RSDOCTOR=true rspack build --config rspack.config.js --env production",
"build:umd": "rspack build --config rspack.config.js --env production",
"bundlewatch": "FORCE_COLOR=1 bundlewatch --config bundlewatch.config.json",
"bundlewatch:fix": "node bundlewatch-fix.mjs",
"check:no-rhc": "node ../../scripts/search-for-rhc.mjs directory dist/no-rhc",
"clean": "rimraf ./dist",
"dev": "rspack serve --config rspack.config.js",
"dev:origin": "rspack serve --config rspack.config.js --env devOrigin=http://localhost:${PORT:-4011}",
Expand Down
3 changes: 3 additions & 0 deletions packages/ui/src/utils/one-tap.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -39,6 +39,9 @@ declare global {
}

async function loadGIS() {
if (__BUILD_DISABLE_RHC__) {
return undefined as unknown as Google;
}
Comment on lines +42 to +44

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Do not return undefined cast as Google in no-RHC builds.

Line 43 creates a type/runtime mismatch (undefined masquerading as Google). This can cause runtime crashes when consumers dereference the result.

🐛 Proposed fix
-async function loadGIS() {+async function loadGIS(): Promise<Google> {
if (__BUILD_DISABLE_RHC__) {
- return undefined as unknown as Google;+ clerkFailedToLoadThirdPartyScript('Google Identity Services');
}
if (!window.google) {
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/ui/src/utils/one-tap.ts` around lines 42 - 44, The branch that
returns "undefined as unknown as Google" when __BUILD_DISABLE_RHC__ is true must
be fixed: change the function's return type to allow undefined (e.g., Google |
undefined) or return a safe stub object instead of force-casting undefined;
update the code around the __BUILD_DISABLE_RHC__ check so it either returns a
proper fallback implementation or an unambiguous undefined/null (no cast) and
adjust all callers of the function (the function that contains the
__BUILD_DISABLE_RHC__ branch and any usages expecting a Google) to handle the
optional value accordingly.

if (!window.google) {
try {
await loadScript('https://accounts.google.com/gsi/client', { defer: true });
Expand Down
11 changes: 11 additions & 0 deletions packages/ui/tsdown.config.mts
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,5 +55,16 @@ export default defineConfig(({ watch }) => {
}
},
},
{
...common,
dts: false,
entry: ['./src/index.ts'],
outDir: './dist/no-rhc',
unbundle: true,
define: {
...common.define,
__BUILD_DISABLE_RHC__: 'true',
},
},
];
});
1 change: 1 addition & 0 deletions scripts/search-for-rhc.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -27,6 +27,7 @@ async function asyncSearchRHC(name, search, regex = false) {
await Promise.allSettled([
asyncSearchRHC('Turnstile', 'cloudflare.com/turnstile/v0/api.js'),
asyncSearchRHC('clerk-js Hotloading', '/npm/@clerk/clerk-js'),
asyncSearchRHC('clerk-ui Hotloading', '/npm/@clerk/ui'),
asyncSearchRHC('Google One Tap', 'accounts.google.com/gsi/client'),
asyncSearchRHC('Coinbase', 'coinbase.com'),
asyncSearchRHC('Coinbase Wallet import', 'import\s*"@coinbase/wallet-sdk', true), // eslint-disable-line no-useless-escape
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(ui): Initial pass for adding RHC guards to ui package by royanger · Pull Request #7983 · clerk/javascript · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/five-carrots-laugh.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
---
'@clerk/chrome-extension': minor
'@clerk/ui': minor
---

Remove remotely hosted code from new @clerk/ui package
2 changes: 1 addition & 1 deletion packages/chrome-extension/src/react/ClerkProvider.tsx
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
import type { Clerk } from '@clerk/clerk-js/no-rhc';
import type { ClerkProviderProps as ClerkReactProviderProps } from '@clerk/react';
import { InternalClerkProvider as ClerkReactProvider } from '@clerk/react/internal';
import { ui } from '@clerk/ui';
import { ui } from '@clerk/ui/no-rhc';
import React from 'react';

import { createClerkClient } from '../internal/clerk';
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -11,7 +11,7 @@ vi.mock('@clerk/clerk-js/no-rhc', () => {
return { Clerk };
});

vi.mock('@clerk/ui', () => ({
vi.mock('@clerk/ui/no-rhc', () => ({
ui: mockUi,
}));

Expand Down
2 changes: 1 addition & 1 deletion packages/chrome-extension/src/utils/clerk-client.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -28,7 +28,7 @@ export function createClerkClient(opts: CreateClerkClientOptions): Clerk | Promi

const originalLoad = clerk.load.bind(clerk);
clerk.load = async (loadOpts?: Parameters<typeof clerk.load>[0]) => {
const { ui } = await import('@clerk/ui');
const { ui } = await import('@clerk/ui/no-rhc');
return originalLoad({ ...loadOpts, ui });
};

Expand Down
8 changes: 7 additions & 1 deletion packages/ui/package.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -25,6 +25,11 @@
"import": "./dist/index.js",
"default": "./dist/index.js"
},
"./no-rhc": {
"types": "./dist/index.d.ts",
"import": "./dist/no-rhc/index.js",
"default": "./dist/no-rhc/index.js"
},
"./entry": {
"types": "./dist/entry.d.ts",
"import": "./dist/entry.js",
Expand DownExpand Up@@ -64,13 +69,14 @@
"register"
],
"scripts": {
"build": "pnpm build:umd && pnpm build:esm",
"build": "pnpm build:umd && pnpm build:esm && pnpm check:no-rhc",
"build:analyze": "rspack build --config rspack.config.js --env production --env analyze --analyze",
"build:esm": "tsdown",
"build:rsdoctor": "RSDOCTOR=true rspack build --config rspack.config.js --env production",
"build:umd": "rspack build --config rspack.config.js --env production",
"bundlewatch": "FORCE_COLOR=1 bundlewatch --config bundlewatch.config.json",
"bundlewatch:fix": "node bundlewatch-fix.mjs",
"check:no-rhc": "node ../../scripts/search-for-rhc.mjs directory dist/no-rhc",
"clean": "rimraf ./dist",
"dev": "rspack serve --config rspack.config.js",
"dev:origin": "rspack serve --config rspack.config.js --env devOrigin=http://localhost:${PORT:-4011}",
Expand Down
3 changes: 3 additions & 0 deletions packages/ui/src/utils/one-tap.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -39,6 +39,9 @@ declare global {
}

async function loadGIS() {
if (__BUILD_DISABLE_RHC__) {
return undefined as unknown as Google;
}
Comment on lines +42 to +44

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Do not return undefined cast as Google in no-RHC builds.

Line 43 creates a type/runtime mismatch (undefined masquerading as Google). This can cause runtime crashes when consumers dereference the result.

🐛 Proposed fix
-async function loadGIS() {+async function loadGIS(): Promise<Google> {
if (__BUILD_DISABLE_RHC__) {
- return undefined as unknown as Google;+ clerkFailedToLoadThirdPartyScript('Google Identity Services');
}
if (!window.google) {
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/ui/src/utils/one-tap.ts` around lines 42 - 44, The branch that
returns "undefined as unknown as Google" when __BUILD_DISABLE_RHC__ is true must
be fixed: change the function's return type to allow undefined (e.g., Google |
undefined) or return a safe stub object instead of force-casting undefined;
update the code around the __BUILD_DISABLE_RHC__ check so it either returns a
proper fallback implementation or an unambiguous undefined/null (no cast) and
adjust all callers of the function (the function that contains the
__BUILD_DISABLE_RHC__ branch and any usages expecting a Google) to handle the
optional value accordingly.

if (!window.google) {
try {
await loadScript('https://accounts.google.com/gsi/client', { defer: true });
Expand Down
11 changes: 11 additions & 0 deletions packages/ui/tsdown.config.mts
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,5 +55,16 @@ export default defineConfig(({ watch }) => {
}
},
},
{
...common,
dts: false,
entry: ['./src/index.ts'],
outDir: './dist/no-rhc',
unbundle: true,
define: {
...common.define,
__BUILD_DISABLE_RHC__: 'true',
},
},
];
});
1 change: 1 addition & 0 deletions scripts/search-for-rhc.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -27,6 +27,7 @@ async function asyncSearchRHC(name, search, regex = false) {
await Promise.allSettled([
asyncSearchRHC('Turnstile', 'cloudflare.com/turnstile/v0/api.js'),
asyncSearchRHC('clerk-js Hotloading', '/npm/@clerk/clerk-js'),
asyncSearchRHC('clerk-ui Hotloading', '/npm/@clerk/ui'),
asyncSearchRHC('Google One Tap', 'accounts.google.com/gsi/client'),
asyncSearchRHC('Coinbase', 'coinbase.com'),
asyncSearchRHC('Coinbase Wallet import', 'import\s*"@coinbase/wallet-sdk', true), // eslint-disable-line no-useless-escape
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(ui): Initial pass for adding RHC guards to ui package by royanger · Pull Request #7983 · clerk/javascript · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/five-carrots-laugh.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
---
'@clerk/chrome-extension': minor
'@clerk/ui': minor
---

Remove remotely hosted code from new @clerk/ui package
2 changes: 1 addition & 1 deletion packages/chrome-extension/src/react/ClerkProvider.tsx
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
import type { Clerk } from '@clerk/clerk-js/no-rhc';
import type { ClerkProviderProps as ClerkReactProviderProps } from '@clerk/react';
import { InternalClerkProvider as ClerkReactProvider } from '@clerk/react/internal';
import { ui } from '@clerk/ui';
import { ui } from '@clerk/ui/no-rhc';
import React from 'react';

import { createClerkClient } from '../internal/clerk';
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -11,7 +11,7 @@ vi.mock('@clerk/clerk-js/no-rhc', () => {
return { Clerk };
});

vi.mock('@clerk/ui', () => ({
vi.mock('@clerk/ui/no-rhc', () => ({
ui: mockUi,
}));

Expand Down
2 changes: 1 addition & 1 deletion packages/chrome-extension/src/utils/clerk-client.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -28,7 +28,7 @@ export function createClerkClient(opts: CreateClerkClientOptions): Clerk | Promi

const originalLoad = clerk.load.bind(clerk);
clerk.load = async (loadOpts?: Parameters<typeof clerk.load>[0]) => {
const { ui } = await import('@clerk/ui');
const { ui } = await import('@clerk/ui/no-rhc');
return originalLoad({ ...loadOpts, ui });
};

Expand Down
8 changes: 7 additions & 1 deletion packages/ui/package.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -25,6 +25,11 @@
"import": "./dist/index.js",
"default": "./dist/index.js"
},
"./no-rhc": {
"types": "./dist/index.d.ts",
"import": "./dist/no-rhc/index.js",
"default": "./dist/no-rhc/index.js"
},
"./entry": {
"types": "./dist/entry.d.ts",
"import": "./dist/entry.js",
Expand DownExpand Up@@ -64,13 +69,14 @@
"register"
],
"scripts": {
"build": "pnpm build:umd && pnpm build:esm",
"build": "pnpm build:umd && pnpm build:esm && pnpm check:no-rhc",
"build:analyze": "rspack build --config rspack.config.js --env production --env analyze --analyze",
"build:esm": "tsdown",
"build:rsdoctor": "RSDOCTOR=true rspack build --config rspack.config.js --env production",
"build:umd": "rspack build --config rspack.config.js --env production",
"bundlewatch": "FORCE_COLOR=1 bundlewatch --config bundlewatch.config.json",
"bundlewatch:fix": "node bundlewatch-fix.mjs",
"check:no-rhc": "node ../../scripts/search-for-rhc.mjs directory dist/no-rhc",
"clean": "rimraf ./dist",
"dev": "rspack serve --config rspack.config.js",
"dev:origin": "rspack serve --config rspack.config.js --env devOrigin=http://localhost:${PORT:-4011}",
Expand Down
3 changes: 3 additions & 0 deletions packages/ui/src/utils/one-tap.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -39,6 +39,9 @@ declare global {
}

async function loadGIS() {
if (__BUILD_DISABLE_RHC__) {
return undefined as unknown as Google;
}
Comment on lines +42 to +44

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Do not return undefined cast as Google in no-RHC builds.

Line 43 creates a type/runtime mismatch (undefined masquerading as Google). This can cause runtime crashes when consumers dereference the result.

🐛 Proposed fix
-async function loadGIS() {+async function loadGIS(): Promise<Google> {
if (__BUILD_DISABLE_RHC__) {
- return undefined as unknown as Google;+ clerkFailedToLoadThirdPartyScript('Google Identity Services');
}
if (!window.google) {
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/ui/src/utils/one-tap.ts` around lines 42 - 44, The branch that
returns "undefined as unknown as Google" when __BUILD_DISABLE_RHC__ is true must
be fixed: change the function's return type to allow undefined (e.g., Google |
undefined) or return a safe stub object instead of force-casting undefined;
update the code around the __BUILD_DISABLE_RHC__ check so it either returns a
proper fallback implementation or an unambiguous undefined/null (no cast) and
adjust all callers of the function (the function that contains the
__BUILD_DISABLE_RHC__ branch and any usages expecting a Google) to handle the
optional value accordingly.

if (!window.google) {
try {
await loadScript('https://accounts.google.com/gsi/client', { defer: true });
Expand Down
11 changes: 11 additions & 0 deletions packages/ui/tsdown.config.mts
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,5 +55,16 @@ export default defineConfig(({ watch }) => {
}
},
},
{
...common,
dts: false,
entry: ['./src/index.ts'],
outDir: './dist/no-rhc',
unbundle: true,
define: {
...common.define,
__BUILD_DISABLE_RHC__: 'true',
},
},
];
});
1 change: 1 addition & 0 deletions scripts/search-for-rhc.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -27,6 +27,7 @@ async function asyncSearchRHC(name, search, regex = false) {
await Promise.allSettled([
asyncSearchRHC('Turnstile', 'cloudflare.com/turnstile/v0/api.js'),
asyncSearchRHC('clerk-js Hotloading', '/npm/@clerk/clerk-js'),
asyncSearchRHC('clerk-ui Hotloading', '/npm/@clerk/ui'),
asyncSearchRHC('Google One Tap', 'accounts.google.com/gsi/client'),
asyncSearchRHC('Coinbase', 'coinbase.com'),
asyncSearchRHC('Coinbase Wallet import', 'import\s*"@coinbase/wallet-sdk', true), // eslint-disable-line no-useless-escape
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(ui): Initial pass for adding RHC guards to ui package by royanger · Pull Request #7983 · clerk/javascript · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/five-carrots-laugh.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
---
'@clerk/chrome-extension': minor
'@clerk/ui': minor
---

Remove remotely hosted code from new @clerk/ui package
2 changes: 1 addition & 1 deletion packages/chrome-extension/src/react/ClerkProvider.tsx
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
import type { Clerk } from '@clerk/clerk-js/no-rhc';
import type { ClerkProviderProps as ClerkReactProviderProps } from '@clerk/react';
import { InternalClerkProvider as ClerkReactProvider } from '@clerk/react/internal';
import { ui } from '@clerk/ui';
import { ui } from '@clerk/ui/no-rhc';
import React from 'react';

import { createClerkClient } from '../internal/clerk';
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -11,7 +11,7 @@ vi.mock('@clerk/clerk-js/no-rhc', () => {
return { Clerk };
});

vi.mock('@clerk/ui', () => ({
vi.mock('@clerk/ui/no-rhc', () => ({
ui: mockUi,
}));

Expand Down
2 changes: 1 addition & 1 deletion packages/chrome-extension/src/utils/clerk-client.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -28,7 +28,7 @@ export function createClerkClient(opts: CreateClerkClientOptions): Clerk | Promi

const originalLoad = clerk.load.bind(clerk);
clerk.load = async (loadOpts?: Parameters<typeof clerk.load>[0]) => {
const { ui } = await import('@clerk/ui');
const { ui } = await import('@clerk/ui/no-rhc');
return originalLoad({ ...loadOpts, ui });
};

Expand Down
8 changes: 7 additions & 1 deletion packages/ui/package.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -25,6 +25,11 @@
"import": "./dist/index.js",
"default": "./dist/index.js"
},
"./no-rhc": {
"types": "./dist/index.d.ts",
"import": "./dist/no-rhc/index.js",
"default": "./dist/no-rhc/index.js"
},
"./entry": {
"types": "./dist/entry.d.ts",
"import": "./dist/entry.js",
Expand DownExpand Up@@ -64,13 +69,14 @@
"register"
],
"scripts": {
"build": "pnpm build:umd && pnpm build:esm",
"build": "pnpm build:umd && pnpm build:esm && pnpm check:no-rhc",
"build:analyze": "rspack build --config rspack.config.js --env production --env analyze --analyze",
"build:esm": "tsdown",
"build:rsdoctor": "RSDOCTOR=true rspack build --config rspack.config.js --env production",
"build:umd": "rspack build --config rspack.config.js --env production",
"bundlewatch": "FORCE_COLOR=1 bundlewatch --config bundlewatch.config.json",
"bundlewatch:fix": "node bundlewatch-fix.mjs",
"check:no-rhc": "node ../../scripts/search-for-rhc.mjs directory dist/no-rhc",
"clean": "rimraf ./dist",
"dev": "rspack serve --config rspack.config.js",
"dev:origin": "rspack serve --config rspack.config.js --env devOrigin=http://localhost:${PORT:-4011}",
Expand Down
3 changes: 3 additions & 0 deletions packages/ui/src/utils/one-tap.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -39,6 +39,9 @@ declare global {
}

async function loadGIS() {
if (__BUILD_DISABLE_RHC__) {
return undefined as unknown as Google;
}
Comment on lines +42 to +44

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Do not return undefined cast as Google in no-RHC builds.

Line 43 creates a type/runtime mismatch (undefined masquerading as Google). This can cause runtime crashes when consumers dereference the result.

🐛 Proposed fix
-async function loadGIS() {+async function loadGIS(): Promise<Google> {
if (__BUILD_DISABLE_RHC__) {
- return undefined as unknown as Google;+ clerkFailedToLoadThirdPartyScript('Google Identity Services');
}
if (!window.google) {
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/ui/src/utils/one-tap.ts` around lines 42 - 44, The branch that
returns "undefined as unknown as Google" when __BUILD_DISABLE_RHC__ is true must
be fixed: change the function's return type to allow undefined (e.g., Google |
undefined) or return a safe stub object instead of force-casting undefined;
update the code around the __BUILD_DISABLE_RHC__ check so it either returns a
proper fallback implementation or an unambiguous undefined/null (no cast) and
adjust all callers of the function (the function that contains the
__BUILD_DISABLE_RHC__ branch and any usages expecting a Google) to handle the
optional value accordingly.

if (!window.google) {
try {
await loadScript('https://accounts.google.com/gsi/client', { defer: true });
Expand Down
11 changes: 11 additions & 0 deletions packages/ui/tsdown.config.mts
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,5 +55,16 @@ export default defineConfig(({ watch }) => {
}
},
},
{
...common,
dts: false,
entry: ['./src/index.ts'],
outDir: './dist/no-rhc',
unbundle: true,
define: {
...common.define,
__BUILD_DISABLE_RHC__: 'true',
},
},
];
});
1 change: 1 addition & 0 deletions scripts/search-for-rhc.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -27,6 +27,7 @@ async function asyncSearchRHC(name, search, regex = false) {
await Promise.allSettled([
asyncSearchRHC('Turnstile', 'cloudflare.com/turnstile/v0/api.js'),
asyncSearchRHC('clerk-js Hotloading', '/npm/@clerk/clerk-js'),
asyncSearchRHC('clerk-ui Hotloading', '/npm/@clerk/ui'),
asyncSearchRHC('Google One Tap', 'accounts.google.com/gsi/client'),
asyncSearchRHC('Coinbase', 'coinbase.com'),
asyncSearchRHC('Coinbase Wallet import', 'import\s*"@coinbase/wallet-sdk', true), // eslint-disable-line no-useless-escape
Expand Down
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); fix(ui): Initial pass for adding RHC guards to ui package by royanger · Pull Request #7983 · clerk/javascript · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/five-carrots-laugh.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
---
'@clerk/chrome-extension': minor
'@clerk/ui': minor
---

Remove remotely hosted code from new @clerk/ui package
2 changes: 1 addition & 1 deletion packages/chrome-extension/src/react/ClerkProvider.tsx
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
import type { Clerk } from '@clerk/clerk-js/no-rhc';
import type { ClerkProviderProps as ClerkReactProviderProps } from '@clerk/react';
import { InternalClerkProvider as ClerkReactProvider } from '@clerk/react/internal';
import { ui } from '@clerk/ui';
import { ui } from '@clerk/ui/no-rhc';
import React from 'react';

import { createClerkClient } from '../internal/clerk';
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -11,7 +11,7 @@ vi.mock('@clerk/clerk-js/no-rhc', () => {
return { Clerk };
});

vi.mock('@clerk/ui', () => ({
vi.mock('@clerk/ui/no-rhc', () => ({
ui: mockUi,
}));

Expand Down
2 changes: 1 addition & 1 deletion packages/chrome-extension/src/utils/clerk-client.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -28,7 +28,7 @@ export function createClerkClient(opts: CreateClerkClientOptions): Clerk | Promi

const originalLoad = clerk.load.bind(clerk);
clerk.load = async (loadOpts?: Parameters<typeof clerk.load>[0]) => {
const { ui } = await import('@clerk/ui');
const { ui } = await import('@clerk/ui/no-rhc');
return originalLoad({ ...loadOpts, ui });
};

Expand Down
8 changes: 7 additions & 1 deletion packages/ui/package.json
Original file line numberDiff line numberDiff line change
Expand Up@@ -25,6 +25,11 @@
"import": "./dist/index.js",
"default": "./dist/index.js"
},
"./no-rhc": {
"types": "./dist/index.d.ts",
"import": "./dist/no-rhc/index.js",
"default": "./dist/no-rhc/index.js"
},
"./entry": {
"types": "./dist/entry.d.ts",
"import": "./dist/entry.js",
Expand DownExpand Up@@ -64,13 +69,14 @@
"register"
],
"scripts": {
"build": "pnpm build:umd && pnpm build:esm",
"build": "pnpm build:umd && pnpm build:esm && pnpm check:no-rhc",
"build:analyze": "rspack build --config rspack.config.js --env production --env analyze --analyze",
"build:esm": "tsdown",
"build:rsdoctor": "RSDOCTOR=true rspack build --config rspack.config.js --env production",
"build:umd": "rspack build --config rspack.config.js --env production",
"bundlewatch": "FORCE_COLOR=1 bundlewatch --config bundlewatch.config.json",
"bundlewatch:fix": "node bundlewatch-fix.mjs",
"check:no-rhc": "node ../../scripts/search-for-rhc.mjs directory dist/no-rhc",
"clean": "rimraf ./dist",
"dev": "rspack serve --config rspack.config.js",
"dev:origin": "rspack serve --config rspack.config.js --env devOrigin=http://localhost:${PORT:-4011}",
Expand Down
3 changes: 3 additions & 0 deletions packages/ui/src/utils/one-tap.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -39,6 +39,9 @@ declare global {
}

async function loadGIS() {
if (__BUILD_DISABLE_RHC__) {
return undefined as unknown as Google;
}
Comment on lines +42 to +44

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Do not return undefined cast as Google in no-RHC builds.

Line 43 creates a type/runtime mismatch (undefined masquerading as Google). This can cause runtime crashes when consumers dereference the result.

🐛 Proposed fix
-async function loadGIS() {+async function loadGIS(): Promise<Google> {
if (__BUILD_DISABLE_RHC__) {
- return undefined as unknown as Google;+ clerkFailedToLoadThirdPartyScript('Google Identity Services');
}
if (!window.google) {
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/ui/src/utils/one-tap.ts` around lines 42 - 44, The branch that
returns "undefined as unknown as Google" when __BUILD_DISABLE_RHC__ is true must
be fixed: change the function's return type to allow undefined (e.g., Google |
undefined) or return a safe stub object instead of force-casting undefined;
update the code around the __BUILD_DISABLE_RHC__ check so it either returns a
proper fallback implementation or an unambiguous undefined/null (no cast) and
adjust all callers of the function (the function that contains the
__BUILD_DISABLE_RHC__ branch and any usages expecting a Google) to handle the
optional value accordingly.

if (!window.google) {
try {
await loadScript('https://accounts.google.com/gsi/client', { defer: true });
Expand Down
11 changes: 11 additions & 0 deletions packages/ui/tsdown.config.mts
Original file line numberDiff line numberDiff line change
Expand Up@@ -55,5 +55,16 @@ export default defineConfig(({ watch }) => {
}
},
},
{
...common,
dts: false,
entry: ['./src/index.ts'],
outDir: './dist/no-rhc',
unbundle: true,
define: {
...common.define,
__BUILD_DISABLE_RHC__: 'true',
},
},
];
});
1 change: 1 addition & 0 deletions scripts/search-for-rhc.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -27,6 +27,7 @@ async function asyncSearchRHC(name, search, regex = false) {
await Promise.allSettled([
asyncSearchRHC('Turnstile', 'cloudflare.com/turnstile/v0/api.js'),
asyncSearchRHC('clerk-js Hotloading', '/npm/@clerk/clerk-js'),
asyncSearchRHC('clerk-ui Hotloading', '/npm/@clerk/ui'),
asyncSearchRHC('Google One Tap', 'accounts.google.com/gsi/client'),
asyncSearchRHC('Coinbase', 'coinbase.com'),
asyncSearchRHC('Coinbase Wallet import', 'import\s*"@coinbase/wallet-sdk', true), // eslint-disable-line no-useless-escape
Expand Down