You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Fix missing empty-string fallback for frontendApiProxy.path in Express middleware
When path is set to '/', stripTrailingSlashes returns '', causing pathname.startsWith('') to match every request as a proxy request
Adds || DEFAULT_PROXY_PATH guard to match the existing pattern in @clerk/hono and @clerk/fastify
Test plan
Verify pnpm build passes
Verify existing Express proxy tests pass
Summary by CodeRabbit
Bug Fixes
Resolved an issue where the express proxy could incorrectly intercept all requests when its configured path resolved to an empty string, restoring correct routing and preventing unintended interception.
Tests
Added tests to verify the proxy fallback behavior and ensure non-proxy routes remain unaffected when the configured path is empty.
Documentation
Added a changelog entry documenting the patch release.
When `frontendApiProxy.path` is set to '/', `stripTrailingSlashes`
returns an empty string, causing every request to be intercepted as
a proxy request. Add `|| DEFAULT_PROXY_PATH` fallback to match the
existing guard in the hono and fastify packages.
Adds a fallback for an empty frontend API proxy path: when the configured proxy path becomes an empty string after trimming, the code uses DEFAULT_PROXY_PATH instead of the empty value. Adds tests covering this behavior and a changeset entry documenting a patch release for the clerk/express package.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
frontendApiProxy.pathin Express middlewarepathis set to'/',stripTrailingSlashesreturns'', causingpathname.startsWith('')to match every request as a proxy request|| DEFAULT_PROXY_PATHguard to match the existing pattern in@clerk/honoand@clerk/fastifyTest plan
pnpm buildpassesSummary by CodeRabbit
Bug Fixes
Tests
Documentation