Skip to content

fix(backend,clerk-js): treat undefined satelliteAutoSync as false - #8001

Merged
nikosdouvlis merged 6 commits into
mainfrom
nikos/fix-satellite-auto-sync-default
Mar 23, 2026
Merged

fix(backend,clerk-js): treat undefined satelliteAutoSync as false#8001
nikosdouvlis merged 6 commits into
mainfrom
nikos/fix-satellite-auto-sync-default

Conversation

@nikosdouvlis

@nikosdouvlisnikosdouvlis commented Mar 5, 2026

Copy link
Copy Markdown
Member

Why

Users upgrading to Core 3 expect satelliteAutoSync to default to false as documented in the JSDoc (@default false) and as the Core 3 upgrade codemod implies (it adds satelliteAutoSync={true} to existing satellite configs to preserve Core 2 behavior).

However, the runtime check used === false (strict equality), so undefined (not passing the prop) behaved identically to true, preserving Core 2 auto-sync-on-every-page-load behavior. A customer reported that their satellite domain was redirecting on every page load despite not opting into auto-sync.

What changed

  • Changed the satellite auto-sync gate from === false to !== true in both @clerk/backend (SSR middleware path in request.ts) and @clerk/clerk-js (CSR initialization in clerk.ts)
  • undefined and false now both skip automatic satellite handshake, matching the documented Core 3 default
  • true must be explicitly passed to enable auto-sync (opt-in)
  • __clerk_synced=false (post sign-in redirect) still triggers handshake regardless of the setting

Test coverage

  • Updated existing unit tests that relied on implicit auto-sync to explicitly pass satelliteAutoSync: true
  • Added new unit tests for undefined default behavior (prod + dev, with and without __clerk_synced=false)
  • Updated integration test that expected 307 redirect with unset satelliteAutoSync to expect 200
  • Added integration test verifying __clerk_synced=false still triggers handshake when satelliteAutoSync is unset

Packages affected

  • @clerk/backend: satellite handshake decision logic in request.ts
  • @clerk/clerk-js: #shouldSyncWithPrimary in clerk.ts

Summary by CodeRabbit

  • Bug Fixes

    • satelliteAutoSync now defaults to false (opt-in); automatic cross-domain satellite sync runs only when explicitly enabled.
    • Sign-out detection corrected so signed-out state is reported accurately.
  • Tests

    • Updated and added tests to cover auto-sync opt-in behavior and handshake/redirect expectations.
  • Documentation

    • Added changelog entry documenting the satelliteAutoSync default fix.

…re 3 default)
The JSDoc on satelliteAutoSync says @default false, and the Core 3
upgrade codemod adds satelliteAutoSync={true} to existing satellite
configs, but the runtime check used === false (strict equality).
This meant undefined (not passing the prop) behaved like true,
preserving Core 2 auto-sync behavior instead of the intended Core 3
default of no auto-sync.
Change the check from === false to !== true so that undefined is
treated the same as false, matching the documented default.
@changeset-bot

changeset-botBot commented Mar 5, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: e664eb1

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 14 packages
NameType
@clerk/backendPatch
@clerk/clerk-jsPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/chrome-extensionPatch
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Mar 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxSkippedSkippedMar 6, 2026 7:45am

Request Review

@coderabbitai

coderabbitaiBot commented Mar 5, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 81066520-9770-48b6-b559-61ad633ea590

📥 Commits

Reviewing files that changed from the base of the PR and between 90fed2d and e664eb1.

📒 Files selected for processing (1)
  • packages/clerk-js/src/core/__tests__/clerk.test.ts

📝 Walkthrough

Walkthrough

The PR changes satellite auto-sync behavior: satelliteAutoSync now enables auto-sync only when explicitly true; undefined or false skip auto-sync. Backend and client checks were updated to use the stricter condition. Tests were added/updated and a changelog entry added to document the default change. AuthCookieService.isSignedOut() was corrected to return true when no user is present.

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely summarizes the main change: treating undefined satelliteAutoSync as false, which is the primary fix across backend and clerk-js packages.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

The post-load branch of isSignedOut() returned !!this.clerk.user,
which is true when the user IS signed in. This is inverted from
what the method name implies. Currently dead code (the only caller
runs before clerk.loaded is true), but fixing it prevents a latent
bug where signed-in satellite users with satelliteAutoSync=true
would get bounced to primary unnecessarily if this method were
ever called post-load.
@nikosdouvlisnikosdouvlis changed the title fix(backend,clerk-js): treat undefined satelliteAutoSync as false (Core 3 default)fix(backend,clerk-js): treat undefined satelliteAutoSync as falseMar 5, 2026
@nikosdouvlis
nikosdouvlis marked this pull request as draft March 5, 2026 23:24
@pkg-pr-new

pkg-pr-newBot commented Mar 6, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8001

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8001

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8001

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8001

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8001

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8001

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8001

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8001

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8001

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8001

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8001

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8001

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8001

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8001

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8001

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8001

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8001

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8001

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8001

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8001

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8001

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8001

commit: e664eb1

These tests reset mockClientFetch in their beforeEach but didn't
set up a return value. Previously this was fine because
#shouldSyncWithPrimary() returned true and the code never reached
Client.fetch(). Now that satelliteAutoSync defaults to false, the
code falls through to the client fetch, so a mock is needed.
@nikosdouvlis
nikosdouvlis marked this pull request as ready for review March 6, 2026 07:44
return this.clientUat.get() <= 0;
}
return !!this.clerk.user;
return !this.clerk.user;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems to be outside of the scope of this PR. Should we split this out into its own change so it has a changelog entry?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the change is small enough to not warrant a new PR, I also dont think a changeset is needed as its internal behavior

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The change looks good. Just wondering how we want to communicate this to users that already upgraded to Core 3

@nikosdouvlis
nikosdouvlis merged commit 3efdd2c into mainMar 23, 2026
41 checks passed
@nikosdouvlis
nikosdouvlis deleted the nikos/fix-satellite-auto-sync-default branch March 23, 2026 09:37
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nikosdouvlis@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(backend,clerk-js): treat undefined satelliteAutoSync as false by nikosdouvlis · Pull Request #8001 · clerk/javascript · GitHub
Skip to content

fix(backend,clerk-js): treat undefined satelliteAutoSync as false - #8001

Merged
nikosdouvlis merged 6 commits into
mainfrom
nikos/fix-satellite-auto-sync-default
Mar 23, 2026
Merged

fix(backend,clerk-js): treat undefined satelliteAutoSync as false#8001
nikosdouvlis merged 6 commits into
mainfrom
nikos/fix-satellite-auto-sync-default

Conversation

@nikosdouvlis

@nikosdouvlisnikosdouvlis commented Mar 5, 2026

Copy link
Copy Markdown
Member

Why

Users upgrading to Core 3 expect satelliteAutoSync to default to false as documented in the JSDoc (@default false) and as the Core 3 upgrade codemod implies (it adds satelliteAutoSync={true} to existing satellite configs to preserve Core 2 behavior).

However, the runtime check used === false (strict equality), so undefined (not passing the prop) behaved identically to true, preserving Core 2 auto-sync-on-every-page-load behavior. A customer reported that their satellite domain was redirecting on every page load despite not opting into auto-sync.

What changed

  • Changed the satellite auto-sync gate from === false to !== true in both @clerk/backend (SSR middleware path in request.ts) and @clerk/clerk-js (CSR initialization in clerk.ts)
  • undefined and false now both skip automatic satellite handshake, matching the documented Core 3 default
  • true must be explicitly passed to enable auto-sync (opt-in)
  • __clerk_synced=false (post sign-in redirect) still triggers handshake regardless of the setting

Test coverage

  • Updated existing unit tests that relied on implicit auto-sync to explicitly pass satelliteAutoSync: true
  • Added new unit tests for undefined default behavior (prod + dev, with and without __clerk_synced=false)
  • Updated integration test that expected 307 redirect with unset satelliteAutoSync to expect 200
  • Added integration test verifying __clerk_synced=false still triggers handshake when satelliteAutoSync is unset

Packages affected

  • @clerk/backend: satellite handshake decision logic in request.ts
  • @clerk/clerk-js: #shouldSyncWithPrimary in clerk.ts

Summary by CodeRabbit

  • Bug Fixes

    • satelliteAutoSync now defaults to false (opt-in); automatic cross-domain satellite sync runs only when explicitly enabled.
    • Sign-out detection corrected so signed-out state is reported accurately.
  • Tests

    • Updated and added tests to cover auto-sync opt-in behavior and handshake/redirect expectations.
  • Documentation

    • Added changelog entry documenting the satelliteAutoSync default fix.

…re 3 default)
The JSDoc on satelliteAutoSync says @default false, and the Core 3
upgrade codemod adds satelliteAutoSync={true} to existing satellite
configs, but the runtime check used === false (strict equality).
This meant undefined (not passing the prop) behaved like true,
preserving Core 2 auto-sync behavior instead of the intended Core 3
default of no auto-sync.
Change the check from === false to !== true so that undefined is
treated the same as false, matching the documented default.
@changeset-bot

changeset-botBot commented Mar 5, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: e664eb1

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 14 packages
NameType
@clerk/backendPatch
@clerk/clerk-jsPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/chrome-extensionPatch
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Mar 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxSkippedSkippedMar 6, 2026 7:45am

Request Review

@coderabbitai

coderabbitaiBot commented Mar 5, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 81066520-9770-48b6-b559-61ad633ea590

📥 Commits

Reviewing files that changed from the base of the PR and between 90fed2d and e664eb1.

📒 Files selected for processing (1)
  • packages/clerk-js/src/core/__tests__/clerk.test.ts

📝 Walkthrough

Walkthrough

The PR changes satellite auto-sync behavior: satelliteAutoSync now enables auto-sync only when explicitly true; undefined or false skip auto-sync. Backend and client checks were updated to use the stricter condition. Tests were added/updated and a changelog entry added to document the default change. AuthCookieService.isSignedOut() was corrected to return true when no user is present.

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely summarizes the main change: treating undefined satelliteAutoSync as false, which is the primary fix across backend and clerk-js packages.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

The post-load branch of isSignedOut() returned !!this.clerk.user,
which is true when the user IS signed in. This is inverted from
what the method name implies. Currently dead code (the only caller
runs before clerk.loaded is true), but fixing it prevents a latent
bug where signed-in satellite users with satelliteAutoSync=true
would get bounced to primary unnecessarily if this method were
ever called post-load.
@nikosdouvlisnikosdouvlis changed the title fix(backend,clerk-js): treat undefined satelliteAutoSync as false (Core 3 default)fix(backend,clerk-js): treat undefined satelliteAutoSync as falseMar 5, 2026
@nikosdouvlis
nikosdouvlis marked this pull request as draft March 5, 2026 23:24
@pkg-pr-new

pkg-pr-newBot commented Mar 6, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8001

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8001

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8001

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8001

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8001

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8001

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8001

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8001

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8001

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8001

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8001

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8001

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8001

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8001

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8001

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8001

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8001

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8001

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8001

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8001

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8001

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8001

commit: e664eb1

These tests reset mockClientFetch in their beforeEach but didn't
set up a return value. Previously this was fine because
#shouldSyncWithPrimary() returned true and the code never reached
Client.fetch(). Now that satelliteAutoSync defaults to false, the
code falls through to the client fetch, so a mock is needed.
@nikosdouvlis
nikosdouvlis marked this pull request as ready for review March 6, 2026 07:44
return this.clientUat.get() <= 0;
}
return !!this.clerk.user;
return !this.clerk.user;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems to be outside of the scope of this PR. Should we split this out into its own change so it has a changelog entry?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the change is small enough to not warrant a new PR, I also dont think a changeset is needed as its internal behavior

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The change looks good. Just wondering how we want to communicate this to users that already upgraded to Core 3

@nikosdouvlis
nikosdouvlis merged commit 3efdd2c into mainMar 23, 2026
41 checks passed
@nikosdouvlis
nikosdouvlis deleted the nikos/fix-satellite-auto-sync-default branch March 23, 2026 09:37
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nikosdouvlis@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(backend,clerk-js): treat undefined satelliteAutoSync as false by nikosdouvlis · Pull Request #8001 · clerk/javascript · GitHub
Skip to content

fix(backend,clerk-js): treat undefined satelliteAutoSync as false - #8001

Merged
nikosdouvlis merged 6 commits into
mainfrom
nikos/fix-satellite-auto-sync-default
Mar 23, 2026
Merged

fix(backend,clerk-js): treat undefined satelliteAutoSync as false#8001
nikosdouvlis merged 6 commits into
mainfrom
nikos/fix-satellite-auto-sync-default

Conversation

@nikosdouvlis

@nikosdouvlisnikosdouvlis commented Mar 5, 2026

Copy link
Copy Markdown
Member

Why

Users upgrading to Core 3 expect satelliteAutoSync to default to false as documented in the JSDoc (@default false) and as the Core 3 upgrade codemod implies (it adds satelliteAutoSync={true} to existing satellite configs to preserve Core 2 behavior).

However, the runtime check used === false (strict equality), so undefined (not passing the prop) behaved identically to true, preserving Core 2 auto-sync-on-every-page-load behavior. A customer reported that their satellite domain was redirecting on every page load despite not opting into auto-sync.

What changed

  • Changed the satellite auto-sync gate from === false to !== true in both @clerk/backend (SSR middleware path in request.ts) and @clerk/clerk-js (CSR initialization in clerk.ts)
  • undefined and false now both skip automatic satellite handshake, matching the documented Core 3 default
  • true must be explicitly passed to enable auto-sync (opt-in)
  • __clerk_synced=false (post sign-in redirect) still triggers handshake regardless of the setting

Test coverage

  • Updated existing unit tests that relied on implicit auto-sync to explicitly pass satelliteAutoSync: true
  • Added new unit tests for undefined default behavior (prod + dev, with and without __clerk_synced=false)
  • Updated integration test that expected 307 redirect with unset satelliteAutoSync to expect 200
  • Added integration test verifying __clerk_synced=false still triggers handshake when satelliteAutoSync is unset

Packages affected

  • @clerk/backend: satellite handshake decision logic in request.ts
  • @clerk/clerk-js: #shouldSyncWithPrimary in clerk.ts

Summary by CodeRabbit

  • Bug Fixes

    • satelliteAutoSync now defaults to false (opt-in); automatic cross-domain satellite sync runs only when explicitly enabled.
    • Sign-out detection corrected so signed-out state is reported accurately.
  • Tests

    • Updated and added tests to cover auto-sync opt-in behavior and handshake/redirect expectations.
  • Documentation

    • Added changelog entry documenting the satelliteAutoSync default fix.

…re 3 default)
The JSDoc on satelliteAutoSync says @default false, and the Core 3
upgrade codemod adds satelliteAutoSync={true} to existing satellite
configs, but the runtime check used === false (strict equality).
This meant undefined (not passing the prop) behaved like true,
preserving Core 2 auto-sync behavior instead of the intended Core 3
default of no auto-sync.
Change the check from === false to !== true so that undefined is
treated the same as false, matching the documented default.
@changeset-bot

changeset-botBot commented Mar 5, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: e664eb1

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 14 packages
NameType
@clerk/backendPatch
@clerk/clerk-jsPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/chrome-extensionPatch
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Mar 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxSkippedSkippedMar 6, 2026 7:45am

Request Review

@coderabbitai

coderabbitaiBot commented Mar 5, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 81066520-9770-48b6-b559-61ad633ea590

📥 Commits

Reviewing files that changed from the base of the PR and between 90fed2d and e664eb1.

📒 Files selected for processing (1)
  • packages/clerk-js/src/core/__tests__/clerk.test.ts

📝 Walkthrough

Walkthrough

The PR changes satellite auto-sync behavior: satelliteAutoSync now enables auto-sync only when explicitly true; undefined or false skip auto-sync. Backend and client checks were updated to use the stricter condition. Tests were added/updated and a changelog entry added to document the default change. AuthCookieService.isSignedOut() was corrected to return true when no user is present.

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely summarizes the main change: treating undefined satelliteAutoSync as false, which is the primary fix across backend and clerk-js packages.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

The post-load branch of isSignedOut() returned !!this.clerk.user,
which is true when the user IS signed in. This is inverted from
what the method name implies. Currently dead code (the only caller
runs before clerk.loaded is true), but fixing it prevents a latent
bug where signed-in satellite users with satelliteAutoSync=true
would get bounced to primary unnecessarily if this method were
ever called post-load.
@nikosdouvlisnikosdouvlis changed the title fix(backend,clerk-js): treat undefined satelliteAutoSync as false (Core 3 default)fix(backend,clerk-js): treat undefined satelliteAutoSync as falseMar 5, 2026
@nikosdouvlis
nikosdouvlis marked this pull request as draft March 5, 2026 23:24
@pkg-pr-new

pkg-pr-newBot commented Mar 6, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8001

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8001

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8001

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8001

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8001

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8001

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8001

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8001

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8001

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8001

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8001

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8001

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8001

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8001

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8001

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8001

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8001

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8001

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8001

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8001

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8001

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8001

commit: e664eb1

These tests reset mockClientFetch in their beforeEach but didn't
set up a return value. Previously this was fine because
#shouldSyncWithPrimary() returned true and the code never reached
Client.fetch(). Now that satelliteAutoSync defaults to false, the
code falls through to the client fetch, so a mock is needed.
@nikosdouvlis
nikosdouvlis marked this pull request as ready for review March 6, 2026 07:44
return this.clientUat.get() <= 0;
}
return !!this.clerk.user;
return !this.clerk.user;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems to be outside of the scope of this PR. Should we split this out into its own change so it has a changelog entry?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the change is small enough to not warrant a new PR, I also dont think a changeset is needed as its internal behavior

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The change looks good. Just wondering how we want to communicate this to users that already upgraded to Core 3

@nikosdouvlis
nikosdouvlis merged commit 3efdd2c into mainMar 23, 2026
41 checks passed
@nikosdouvlis
nikosdouvlis deleted the nikos/fix-satellite-auto-sync-default branch March 23, 2026 09:37
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nikosdouvlis@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(backend,clerk-js): treat undefined satelliteAutoSync as false by nikosdouvlis · Pull Request #8001 · clerk/javascript · GitHub
Skip to content

fix(backend,clerk-js): treat undefined satelliteAutoSync as false - #8001

Merged
nikosdouvlis merged 6 commits into
mainfrom
nikos/fix-satellite-auto-sync-default
Mar 23, 2026
Merged

fix(backend,clerk-js): treat undefined satelliteAutoSync as false#8001
nikosdouvlis merged 6 commits into
mainfrom
nikos/fix-satellite-auto-sync-default

Conversation

@nikosdouvlis

@nikosdouvlisnikosdouvlis commented Mar 5, 2026

Copy link
Copy Markdown
Member

Why

Users upgrading to Core 3 expect satelliteAutoSync to default to false as documented in the JSDoc (@default false) and as the Core 3 upgrade codemod implies (it adds satelliteAutoSync={true} to existing satellite configs to preserve Core 2 behavior).

However, the runtime check used === false (strict equality), so undefined (not passing the prop) behaved identically to true, preserving Core 2 auto-sync-on-every-page-load behavior. A customer reported that their satellite domain was redirecting on every page load despite not opting into auto-sync.

What changed

  • Changed the satellite auto-sync gate from === false to !== true in both @clerk/backend (SSR middleware path in request.ts) and @clerk/clerk-js (CSR initialization in clerk.ts)
  • undefined and false now both skip automatic satellite handshake, matching the documented Core 3 default
  • true must be explicitly passed to enable auto-sync (opt-in)
  • __clerk_synced=false (post sign-in redirect) still triggers handshake regardless of the setting

Test coverage

  • Updated existing unit tests that relied on implicit auto-sync to explicitly pass satelliteAutoSync: true
  • Added new unit tests for undefined default behavior (prod + dev, with and without __clerk_synced=false)
  • Updated integration test that expected 307 redirect with unset satelliteAutoSync to expect 200
  • Added integration test verifying __clerk_synced=false still triggers handshake when satelliteAutoSync is unset

Packages affected

  • @clerk/backend: satellite handshake decision logic in request.ts
  • @clerk/clerk-js: #shouldSyncWithPrimary in clerk.ts

Summary by CodeRabbit

  • Bug Fixes

    • satelliteAutoSync now defaults to false (opt-in); automatic cross-domain satellite sync runs only when explicitly enabled.
    • Sign-out detection corrected so signed-out state is reported accurately.
  • Tests

    • Updated and added tests to cover auto-sync opt-in behavior and handshake/redirect expectations.
  • Documentation

    • Added changelog entry documenting the satelliteAutoSync default fix.

…re 3 default)
The JSDoc on satelliteAutoSync says @default false, and the Core 3
upgrade codemod adds satelliteAutoSync={true} to existing satellite
configs, but the runtime check used === false (strict equality).
This meant undefined (not passing the prop) behaved like true,
preserving Core 2 auto-sync behavior instead of the intended Core 3
default of no auto-sync.
Change the check from === false to !== true so that undefined is
treated the same as false, matching the documented default.
@changeset-bot

changeset-botBot commented Mar 5, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: e664eb1

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 14 packages
NameType
@clerk/backendPatch
@clerk/clerk-jsPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/chrome-extensionPatch
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Mar 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxSkippedSkippedMar 6, 2026 7:45am

Request Review

@coderabbitai

coderabbitaiBot commented Mar 5, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 81066520-9770-48b6-b559-61ad633ea590

📥 Commits

Reviewing files that changed from the base of the PR and between 90fed2d and e664eb1.

📒 Files selected for processing (1)
  • packages/clerk-js/src/core/__tests__/clerk.test.ts

📝 Walkthrough

Walkthrough

The PR changes satellite auto-sync behavior: satelliteAutoSync now enables auto-sync only when explicitly true; undefined or false skip auto-sync. Backend and client checks were updated to use the stricter condition. Tests were added/updated and a changelog entry added to document the default change. AuthCookieService.isSignedOut() was corrected to return true when no user is present.

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely summarizes the main change: treating undefined satelliteAutoSync as false, which is the primary fix across backend and clerk-js packages.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

The post-load branch of isSignedOut() returned !!this.clerk.user,
which is true when the user IS signed in. This is inverted from
what the method name implies. Currently dead code (the only caller
runs before clerk.loaded is true), but fixing it prevents a latent
bug where signed-in satellite users with satelliteAutoSync=true
would get bounced to primary unnecessarily if this method were
ever called post-load.
@nikosdouvlisnikosdouvlis changed the title fix(backend,clerk-js): treat undefined satelliteAutoSync as false (Core 3 default)fix(backend,clerk-js): treat undefined satelliteAutoSync as falseMar 5, 2026
@nikosdouvlis
nikosdouvlis marked this pull request as draft March 5, 2026 23:24
@pkg-pr-new

pkg-pr-newBot commented Mar 6, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8001

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8001

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8001

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8001

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8001

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8001

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8001

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8001

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8001

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8001

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8001

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8001

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8001

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8001

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8001

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8001

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8001

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8001

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8001

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8001

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8001

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8001

commit: e664eb1

These tests reset mockClientFetch in their beforeEach but didn't
set up a return value. Previously this was fine because
#shouldSyncWithPrimary() returned true and the code never reached
Client.fetch(). Now that satelliteAutoSync defaults to false, the
code falls through to the client fetch, so a mock is needed.
@nikosdouvlis
nikosdouvlis marked this pull request as ready for review March 6, 2026 07:44
return this.clientUat.get() <= 0;
}
return !!this.clerk.user;
return !this.clerk.user;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems to be outside of the scope of this PR. Should we split this out into its own change so it has a changelog entry?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the change is small enough to not warrant a new PR, I also dont think a changeset is needed as its internal behavior

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The change looks good. Just wondering how we want to communicate this to users that already upgraded to Core 3

@nikosdouvlis
nikosdouvlis merged commit 3efdd2c into mainMar 23, 2026
41 checks passed
@nikosdouvlis
nikosdouvlis deleted the nikos/fix-satellite-auto-sync-default branch March 23, 2026 09:37
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nikosdouvlis@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(backend,clerk-js): treat undefined satelliteAutoSync as false by nikosdouvlis · Pull Request #8001 · clerk/javascript · GitHub
Skip to content

fix(backend,clerk-js): treat undefined satelliteAutoSync as false - #8001

Merged
nikosdouvlis merged 6 commits into
mainfrom
nikos/fix-satellite-auto-sync-default
Mar 23, 2026
Merged

fix(backend,clerk-js): treat undefined satelliteAutoSync as false#8001
nikosdouvlis merged 6 commits into
mainfrom
nikos/fix-satellite-auto-sync-default

Conversation

@nikosdouvlis

@nikosdouvlisnikosdouvlis commented Mar 5, 2026

Copy link
Copy Markdown
Member

Why

Users upgrading to Core 3 expect satelliteAutoSync to default to false as documented in the JSDoc (@default false) and as the Core 3 upgrade codemod implies (it adds satelliteAutoSync={true} to existing satellite configs to preserve Core 2 behavior).

However, the runtime check used === false (strict equality), so undefined (not passing the prop) behaved identically to true, preserving Core 2 auto-sync-on-every-page-load behavior. A customer reported that their satellite domain was redirecting on every page load despite not opting into auto-sync.

What changed

  • Changed the satellite auto-sync gate from === false to !== true in both @clerk/backend (SSR middleware path in request.ts) and @clerk/clerk-js (CSR initialization in clerk.ts)
  • undefined and false now both skip automatic satellite handshake, matching the documented Core 3 default
  • true must be explicitly passed to enable auto-sync (opt-in)
  • __clerk_synced=false (post sign-in redirect) still triggers handshake regardless of the setting

Test coverage

  • Updated existing unit tests that relied on implicit auto-sync to explicitly pass satelliteAutoSync: true
  • Added new unit tests for undefined default behavior (prod + dev, with and without __clerk_synced=false)
  • Updated integration test that expected 307 redirect with unset satelliteAutoSync to expect 200
  • Added integration test verifying __clerk_synced=false still triggers handshake when satelliteAutoSync is unset

Packages affected

  • @clerk/backend: satellite handshake decision logic in request.ts
  • @clerk/clerk-js: #shouldSyncWithPrimary in clerk.ts

Summary by CodeRabbit

  • Bug Fixes

    • satelliteAutoSync now defaults to false (opt-in); automatic cross-domain satellite sync runs only when explicitly enabled.
    • Sign-out detection corrected so signed-out state is reported accurately.
  • Tests

    • Updated and added tests to cover auto-sync opt-in behavior and handshake/redirect expectations.
  • Documentation

    • Added changelog entry documenting the satelliteAutoSync default fix.

…re 3 default)
The JSDoc on satelliteAutoSync says @default false, and the Core 3
upgrade codemod adds satelliteAutoSync={true} to existing satellite
configs, but the runtime check used === false (strict equality).
This meant undefined (not passing the prop) behaved like true,
preserving Core 2 auto-sync behavior instead of the intended Core 3
default of no auto-sync.
Change the check from === false to !== true so that undefined is
treated the same as false, matching the documented default.
@changeset-bot

changeset-botBot commented Mar 5, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: e664eb1

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 14 packages
NameType
@clerk/backendPatch
@clerk/clerk-jsPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/chrome-extensionPatch
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Mar 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxSkippedSkippedMar 6, 2026 7:45am

Request Review

@coderabbitai

coderabbitaiBot commented Mar 5, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 81066520-9770-48b6-b559-61ad633ea590

📥 Commits

Reviewing files that changed from the base of the PR and between 90fed2d and e664eb1.

📒 Files selected for processing (1)
  • packages/clerk-js/src/core/__tests__/clerk.test.ts

📝 Walkthrough

Walkthrough

The PR changes satellite auto-sync behavior: satelliteAutoSync now enables auto-sync only when explicitly true; undefined or false skip auto-sync. Backend and client checks were updated to use the stricter condition. Tests were added/updated and a changelog entry added to document the default change. AuthCookieService.isSignedOut() was corrected to return true when no user is present.

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely summarizes the main change: treating undefined satelliteAutoSync as false, which is the primary fix across backend and clerk-js packages.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

The post-load branch of isSignedOut() returned !!this.clerk.user,
which is true when the user IS signed in. This is inverted from
what the method name implies. Currently dead code (the only caller
runs before clerk.loaded is true), but fixing it prevents a latent
bug where signed-in satellite users with satelliteAutoSync=true
would get bounced to primary unnecessarily if this method were
ever called post-load.
@nikosdouvlisnikosdouvlis changed the title fix(backend,clerk-js): treat undefined satelliteAutoSync as false (Core 3 default)fix(backend,clerk-js): treat undefined satelliteAutoSync as falseMar 5, 2026
@nikosdouvlis
nikosdouvlis marked this pull request as draft March 5, 2026 23:24
@pkg-pr-new

pkg-pr-newBot commented Mar 6, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8001

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8001

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8001

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8001

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8001

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8001

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8001

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8001

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8001

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8001

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8001

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8001

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8001

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8001

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8001

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8001

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8001

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8001

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8001

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8001

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8001

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8001

commit: e664eb1

These tests reset mockClientFetch in their beforeEach but didn't
set up a return value. Previously this was fine because
#shouldSyncWithPrimary() returned true and the code never reached
Client.fetch(). Now that satelliteAutoSync defaults to false, the
code falls through to the client fetch, so a mock is needed.
@nikosdouvlis
nikosdouvlis marked this pull request as ready for review March 6, 2026 07:44
return this.clientUat.get() <= 0;
}
return !!this.clerk.user;
return !this.clerk.user;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems to be outside of the scope of this PR. Should we split this out into its own change so it has a changelog entry?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the change is small enough to not warrant a new PR, I also dont think a changeset is needed as its internal behavior

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The change looks good. Just wondering how we want to communicate this to users that already upgraded to Core 3

@nikosdouvlis
nikosdouvlis merged commit 3efdd2c into mainMar 23, 2026
41 checks passed
@nikosdouvlis
nikosdouvlis deleted the nikos/fix-satellite-auto-sync-default branch March 23, 2026 09:37
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nikosdouvlis@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(backend,clerk-js): treat undefined satelliteAutoSync as false by nikosdouvlis · Pull Request #8001 · clerk/javascript · GitHub
Skip to content

fix(backend,clerk-js): treat undefined satelliteAutoSync as false - #8001

Merged
nikosdouvlis merged 6 commits into
mainfrom
nikos/fix-satellite-auto-sync-default
Mar 23, 2026
Merged

fix(backend,clerk-js): treat undefined satelliteAutoSync as false#8001
nikosdouvlis merged 6 commits into
mainfrom
nikos/fix-satellite-auto-sync-default

Conversation

@nikosdouvlis

@nikosdouvlisnikosdouvlis commented Mar 5, 2026

Copy link
Copy Markdown
Member

Why

Users upgrading to Core 3 expect satelliteAutoSync to default to false as documented in the JSDoc (@default false) and as the Core 3 upgrade codemod implies (it adds satelliteAutoSync={true} to existing satellite configs to preserve Core 2 behavior).

However, the runtime check used === false (strict equality), so undefined (not passing the prop) behaved identically to true, preserving Core 2 auto-sync-on-every-page-load behavior. A customer reported that their satellite domain was redirecting on every page load despite not opting into auto-sync.

What changed

  • Changed the satellite auto-sync gate from === false to !== true in both @clerk/backend (SSR middleware path in request.ts) and @clerk/clerk-js (CSR initialization in clerk.ts)
  • undefined and false now both skip automatic satellite handshake, matching the documented Core 3 default
  • true must be explicitly passed to enable auto-sync (opt-in)
  • __clerk_synced=false (post sign-in redirect) still triggers handshake regardless of the setting

Test coverage

  • Updated existing unit tests that relied on implicit auto-sync to explicitly pass satelliteAutoSync: true
  • Added new unit tests for undefined default behavior (prod + dev, with and without __clerk_synced=false)
  • Updated integration test that expected 307 redirect with unset satelliteAutoSync to expect 200
  • Added integration test verifying __clerk_synced=false still triggers handshake when satelliteAutoSync is unset

Packages affected

  • @clerk/backend: satellite handshake decision logic in request.ts
  • @clerk/clerk-js: #shouldSyncWithPrimary in clerk.ts

Summary by CodeRabbit

  • Bug Fixes

    • satelliteAutoSync now defaults to false (opt-in); automatic cross-domain satellite sync runs only when explicitly enabled.
    • Sign-out detection corrected so signed-out state is reported accurately.
  • Tests

    • Updated and added tests to cover auto-sync opt-in behavior and handshake/redirect expectations.
  • Documentation

    • Added changelog entry documenting the satelliteAutoSync default fix.

…re 3 default)
The JSDoc on satelliteAutoSync says @default false, and the Core 3
upgrade codemod adds satelliteAutoSync={true} to existing satellite
configs, but the runtime check used === false (strict equality).
This meant undefined (not passing the prop) behaved like true,
preserving Core 2 auto-sync behavior instead of the intended Core 3
default of no auto-sync.
Change the check from === false to !== true so that undefined is
treated the same as false, matching the documented default.
@changeset-bot

changeset-botBot commented Mar 5, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: e664eb1

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 14 packages
NameType
@clerk/backendPatch
@clerk/clerk-jsPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/chrome-extensionPatch
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Mar 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxSkippedSkippedMar 6, 2026 7:45am

Request Review

@coderabbitai

coderabbitaiBot commented Mar 5, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 81066520-9770-48b6-b559-61ad633ea590

📥 Commits

Reviewing files that changed from the base of the PR and between 90fed2d and e664eb1.

📒 Files selected for processing (1)
  • packages/clerk-js/src/core/__tests__/clerk.test.ts

📝 Walkthrough

Walkthrough

The PR changes satellite auto-sync behavior: satelliteAutoSync now enables auto-sync only when explicitly true; undefined or false skip auto-sync. Backend and client checks were updated to use the stricter condition. Tests were added/updated and a changelog entry added to document the default change. AuthCookieService.isSignedOut() was corrected to return true when no user is present.

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely summarizes the main change: treating undefined satelliteAutoSync as false, which is the primary fix across backend and clerk-js packages.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

The post-load branch of isSignedOut() returned !!this.clerk.user,
which is true when the user IS signed in. This is inverted from
what the method name implies. Currently dead code (the only caller
runs before clerk.loaded is true), but fixing it prevents a latent
bug where signed-in satellite users with satelliteAutoSync=true
would get bounced to primary unnecessarily if this method were
ever called post-load.
@nikosdouvlisnikosdouvlis changed the title fix(backend,clerk-js): treat undefined satelliteAutoSync as false (Core 3 default)fix(backend,clerk-js): treat undefined satelliteAutoSync as falseMar 5, 2026
@nikosdouvlis
nikosdouvlis marked this pull request as draft March 5, 2026 23:24
@pkg-pr-new

pkg-pr-newBot commented Mar 6, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8001

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8001

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8001

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8001

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8001

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8001

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8001

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8001

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8001

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8001

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8001

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8001

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8001

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8001

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8001

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8001

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8001

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8001

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8001

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8001

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8001

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8001

commit: e664eb1

These tests reset mockClientFetch in their beforeEach but didn't
set up a return value. Previously this was fine because
#shouldSyncWithPrimary() returned true and the code never reached
Client.fetch(). Now that satelliteAutoSync defaults to false, the
code falls through to the client fetch, so a mock is needed.
@nikosdouvlis
nikosdouvlis marked this pull request as ready for review March 6, 2026 07:44
return this.clientUat.get() <= 0;
}
return !!this.clerk.user;
return !this.clerk.user;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems to be outside of the scope of this PR. Should we split this out into its own change so it has a changelog entry?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the change is small enough to not warrant a new PR, I also dont think a changeset is needed as its internal behavior

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The change looks good. Just wondering how we want to communicate this to users that already upgraded to Core 3

@nikosdouvlis
nikosdouvlis merged commit 3efdd2c into mainMar 23, 2026
41 checks passed
@nikosdouvlis
nikosdouvlis deleted the nikos/fix-satellite-auto-sync-default branch March 23, 2026 09:37
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nikosdouvlis@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(backend,clerk-js): treat undefined satelliteAutoSync as false by nikosdouvlis · Pull Request #8001 · clerk/javascript · GitHub
Skip to content

fix(backend,clerk-js): treat undefined satelliteAutoSync as false - #8001

Merged
nikosdouvlis merged 6 commits into
mainfrom
nikos/fix-satellite-auto-sync-default
Mar 23, 2026
Merged

fix(backend,clerk-js): treat undefined satelliteAutoSync as false#8001
nikosdouvlis merged 6 commits into
mainfrom
nikos/fix-satellite-auto-sync-default

Conversation

@nikosdouvlis

@nikosdouvlisnikosdouvlis commented Mar 5, 2026

Copy link
Copy Markdown
Member

Why

Users upgrading to Core 3 expect satelliteAutoSync to default to false as documented in the JSDoc (@default false) and as the Core 3 upgrade codemod implies (it adds satelliteAutoSync={true} to existing satellite configs to preserve Core 2 behavior).

However, the runtime check used === false (strict equality), so undefined (not passing the prop) behaved identically to true, preserving Core 2 auto-sync-on-every-page-load behavior. A customer reported that their satellite domain was redirecting on every page load despite not opting into auto-sync.

What changed

  • Changed the satellite auto-sync gate from === false to !== true in both @clerk/backend (SSR middleware path in request.ts) and @clerk/clerk-js (CSR initialization in clerk.ts)
  • undefined and false now both skip automatic satellite handshake, matching the documented Core 3 default
  • true must be explicitly passed to enable auto-sync (opt-in)
  • __clerk_synced=false (post sign-in redirect) still triggers handshake regardless of the setting

Test coverage

  • Updated existing unit tests that relied on implicit auto-sync to explicitly pass satelliteAutoSync: true
  • Added new unit tests for undefined default behavior (prod + dev, with and without __clerk_synced=false)
  • Updated integration test that expected 307 redirect with unset satelliteAutoSync to expect 200
  • Added integration test verifying __clerk_synced=false still triggers handshake when satelliteAutoSync is unset

Packages affected

  • @clerk/backend: satellite handshake decision logic in request.ts
  • @clerk/clerk-js: #shouldSyncWithPrimary in clerk.ts

Summary by CodeRabbit

  • Bug Fixes

    • satelliteAutoSync now defaults to false (opt-in); automatic cross-domain satellite sync runs only when explicitly enabled.
    • Sign-out detection corrected so signed-out state is reported accurately.
  • Tests

    • Updated and added tests to cover auto-sync opt-in behavior and handshake/redirect expectations.
  • Documentation

    • Added changelog entry documenting the satelliteAutoSync default fix.

…re 3 default)
The JSDoc on satelliteAutoSync says @default false, and the Core 3
upgrade codemod adds satelliteAutoSync={true} to existing satellite
configs, but the runtime check used === false (strict equality).
This meant undefined (not passing the prop) behaved like true,
preserving Core 2 auto-sync behavior instead of the intended Core 3
default of no auto-sync.
Change the check from === false to !== true so that undefined is
treated the same as false, matching the documented default.
@changeset-bot

changeset-botBot commented Mar 5, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: e664eb1

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 14 packages
NameType
@clerk/backendPatch
@clerk/clerk-jsPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/chrome-extensionPatch
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Mar 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxSkippedSkippedMar 6, 2026 7:45am

Request Review

@coderabbitai

coderabbitaiBot commented Mar 5, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 81066520-9770-48b6-b559-61ad633ea590

📥 Commits

Reviewing files that changed from the base of the PR and between 90fed2d and e664eb1.

📒 Files selected for processing (1)
  • packages/clerk-js/src/core/__tests__/clerk.test.ts

📝 Walkthrough

Walkthrough

The PR changes satellite auto-sync behavior: satelliteAutoSync now enables auto-sync only when explicitly true; undefined or false skip auto-sync. Backend and client checks were updated to use the stricter condition. Tests were added/updated and a changelog entry added to document the default change. AuthCookieService.isSignedOut() was corrected to return true when no user is present.

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely summarizes the main change: treating undefined satelliteAutoSync as false, which is the primary fix across backend and clerk-js packages.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

The post-load branch of isSignedOut() returned !!this.clerk.user,
which is true when the user IS signed in. This is inverted from
what the method name implies. Currently dead code (the only caller
runs before clerk.loaded is true), but fixing it prevents a latent
bug where signed-in satellite users with satelliteAutoSync=true
would get bounced to primary unnecessarily if this method were
ever called post-load.
@nikosdouvlisnikosdouvlis changed the title fix(backend,clerk-js): treat undefined satelliteAutoSync as false (Core 3 default)fix(backend,clerk-js): treat undefined satelliteAutoSync as falseMar 5, 2026
@nikosdouvlis
nikosdouvlis marked this pull request as draft March 5, 2026 23:24
@pkg-pr-new

pkg-pr-newBot commented Mar 6, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8001

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8001

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8001

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8001

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8001

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8001

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8001

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8001

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8001

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8001

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8001

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8001

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8001

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8001

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8001

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8001

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8001

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8001

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8001

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8001

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8001

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8001

commit: e664eb1

These tests reset mockClientFetch in their beforeEach but didn't
set up a return value. Previously this was fine because
#shouldSyncWithPrimary() returned true and the code never reached
Client.fetch(). Now that satelliteAutoSync defaults to false, the
code falls through to the client fetch, so a mock is needed.
@nikosdouvlis
nikosdouvlis marked this pull request as ready for review March 6, 2026 07:44
return this.clientUat.get() <= 0;
}
return !!this.clerk.user;
return !this.clerk.user;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems to be outside of the scope of this PR. Should we split this out into its own change so it has a changelog entry?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the change is small enough to not warrant a new PR, I also dont think a changeset is needed as its internal behavior

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The change looks good. Just wondering how we want to communicate this to users that already upgraded to Core 3

@nikosdouvlis
nikosdouvlis merged commit 3efdd2c into mainMar 23, 2026
41 checks passed
@nikosdouvlis
nikosdouvlis deleted the nikos/fix-satellite-auto-sync-default branch March 23, 2026 09:37
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nikosdouvlis@jacekradko
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix(backend,clerk-js): treat undefined satelliteAutoSync as false by nikosdouvlis · Pull Request #8001 · clerk/javascript · GitHub
Skip to content

fix(backend,clerk-js): treat undefined satelliteAutoSync as false - #8001

Merged
nikosdouvlis merged 6 commits into
mainfrom
nikos/fix-satellite-auto-sync-default
Mar 23, 2026
Merged

fix(backend,clerk-js): treat undefined satelliteAutoSync as false#8001
nikosdouvlis merged 6 commits into
mainfrom
nikos/fix-satellite-auto-sync-default

Conversation

@nikosdouvlis

@nikosdouvlisnikosdouvlis commented Mar 5, 2026

Copy link
Copy Markdown
Member

Why

Users upgrading to Core 3 expect satelliteAutoSync to default to false as documented in the JSDoc (@default false) and as the Core 3 upgrade codemod implies (it adds satelliteAutoSync={true} to existing satellite configs to preserve Core 2 behavior).

However, the runtime check used === false (strict equality), so undefined (not passing the prop) behaved identically to true, preserving Core 2 auto-sync-on-every-page-load behavior. A customer reported that their satellite domain was redirecting on every page load despite not opting into auto-sync.

What changed

  • Changed the satellite auto-sync gate from === false to !== true in both @clerk/backend (SSR middleware path in request.ts) and @clerk/clerk-js (CSR initialization in clerk.ts)
  • undefined and false now both skip automatic satellite handshake, matching the documented Core 3 default
  • true must be explicitly passed to enable auto-sync (opt-in)
  • __clerk_synced=false (post sign-in redirect) still triggers handshake regardless of the setting

Test coverage

  • Updated existing unit tests that relied on implicit auto-sync to explicitly pass satelliteAutoSync: true
  • Added new unit tests for undefined default behavior (prod + dev, with and without __clerk_synced=false)
  • Updated integration test that expected 307 redirect with unset satelliteAutoSync to expect 200
  • Added integration test verifying __clerk_synced=false still triggers handshake when satelliteAutoSync is unset

Packages affected

  • @clerk/backend: satellite handshake decision logic in request.ts
  • @clerk/clerk-js: #shouldSyncWithPrimary in clerk.ts

Summary by CodeRabbit

  • Bug Fixes

    • satelliteAutoSync now defaults to false (opt-in); automatic cross-domain satellite sync runs only when explicitly enabled.
    • Sign-out detection corrected so signed-out state is reported accurately.
  • Tests

    • Updated and added tests to cover auto-sync opt-in behavior and handshake/redirect expectations.
  • Documentation

    • Added changelog entry documenting the satelliteAutoSync default fix.

…re 3 default)
The JSDoc on satelliteAutoSync says @default false, and the Core 3
upgrade codemod adds satelliteAutoSync={true} to existing satellite
configs, but the runtime check used === false (strict equality).
This meant undefined (not passing the prop) behaved like true,
preserving Core 2 auto-sync behavior instead of the intended Core 3
default of no auto-sync.
Change the check from === false to !== true so that undefined is
treated the same as false, matching the documented default.
@changeset-bot

changeset-botBot commented Mar 5, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: e664eb1

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 14 packages
NameType
@clerk/backendPatch
@clerk/clerk-jsPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/chrome-extensionPatch
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Mar 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxSkippedSkippedMar 6, 2026 7:45am

Request Review

@coderabbitai

coderabbitaiBot commented Mar 5, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 81066520-9770-48b6-b559-61ad633ea590

📥 Commits

Reviewing files that changed from the base of the PR and between 90fed2d and e664eb1.

📒 Files selected for processing (1)
  • packages/clerk-js/src/core/__tests__/clerk.test.ts

📝 Walkthrough

Walkthrough

The PR changes satellite auto-sync behavior: satelliteAutoSync now enables auto-sync only when explicitly true; undefined or false skip auto-sync. Backend and client checks were updated to use the stricter condition. Tests were added/updated and a changelog entry added to document the default change. AuthCookieService.isSignedOut() was corrected to return true when no user is present.

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and concisely summarizes the main change: treating undefined satelliteAutoSync as false, which is the primary fix across backend and clerk-js packages.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

The post-load branch of isSignedOut() returned !!this.clerk.user,
which is true when the user IS signed in. This is inverted from
what the method name implies. Currently dead code (the only caller
runs before clerk.loaded is true), but fixing it prevents a latent
bug where signed-in satellite users with satelliteAutoSync=true
would get bounced to primary unnecessarily if this method were
ever called post-load.
@nikosdouvlisnikosdouvlis changed the title fix(backend,clerk-js): treat undefined satelliteAutoSync as false (Core 3 default)fix(backend,clerk-js): treat undefined satelliteAutoSync as falseMar 5, 2026
@nikosdouvlis
nikosdouvlis marked this pull request as draft March 5, 2026 23:24
@pkg-pr-new

pkg-pr-newBot commented Mar 6, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8001

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8001

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8001

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8001

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8001

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8001

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8001

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8001

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8001

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8001

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8001

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8001

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8001

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8001

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8001

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8001

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8001

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8001

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8001

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8001

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8001

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8001

commit: e664eb1

These tests reset mockClientFetch in their beforeEach but didn't
set up a return value. Previously this was fine because
#shouldSyncWithPrimary() returned true and the code never reached
Client.fetch(). Now that satelliteAutoSync defaults to false, the
code falls through to the client fetch, so a mock is needed.
@nikosdouvlis
nikosdouvlis marked this pull request as ready for review March 6, 2026 07:44
return this.clientUat.get() <= 0;
}
return !!this.clerk.user;
return !this.clerk.user;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems to be outside of the scope of this PR. Should we split this out into its own change so it has a changelog entry?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the change is small enough to not warrant a new PR, I also dont think a changeset is needed as its internal behavior

@jacekradkojacekradko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The change looks good. Just wondering how we want to communicate this to users that already upgraded to Core 3

@nikosdouvlis
nikosdouvlis merged commit 3efdd2c into mainMar 23, 2026
41 checks passed
@nikosdouvlis
nikosdouvlis deleted the nikos/fix-satellite-auto-sync-default branch March 23, 2026 09:37
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@nikosdouvlis@jacekradko