fix(ui): remove back button from sign-in password compromised/pwned error screen - #8280

Merged
Ephem merged 3 commits into
mainfrom
fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button
May 6, 2026
Merged

fix(ui): remove back button from sign-in password compromised/pwned error screen#8280
Ephem merged 3 commits into
mainfrom
fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button

Conversation

@Ephem

@EphemEphem commented Apr 9, 2026

Copy link
Copy Markdown
Member

Description

These errors are not recoverable by re-entering the password, so the back button led to a confusing dead end that would always take you back to the same error.

Before:

CleanShot 2026-04-09 at 16 24 16

After:

CleanShot 2026-04-09 at 16 23 32

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Ephem added 2 commits April 9, 2026 16:02
This would take you back to re-enter the password, which never works so it was leading to a confusing dead end.
@changeset-bot

changeset-botBot commented Apr 9, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 18269d6

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
NameType
@clerk/uiPatch
@clerk/chrome-extensionPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Apr 9, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentApr 9, 2026 2:23pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 9, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8280

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8280

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8280

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8280

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8280

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8280

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8280

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8280

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8280

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8280

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8280

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8280

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8280

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8280

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8280

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8280

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8280

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8280

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8280

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8280

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8280

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8280

commit: 18269d6

@coderabbitai

coderabbitaiBot commented Apr 9, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 46e651b2-ee3b-43b2-b3ed-0a8454ff3b30

📥 Commits

Reviewing files that changed from the base of the PR and between 3a2b08b and 18269d6.

📒 Files selected for processing (1)
  • packages/ui/src/components/SignIn/__tests__/SignInFactorOne.test.tsx
💤 Files with no reviewable changes (1)
  • packages/ui/src/components/SignIn/tests/SignInFactorOne.test.tsx

📝 Walkthrough

Walkthrough

This PR adds a Changeset for a patch release and updates the sign-in flow in the @clerk/ui package. It changes the canGoBack computation in SignInFactorOne.tsx to require both factorHasLocalStrategy(currentFactor) and the absence of passwordErrorCode, preventing the back action when a password error is present. A test covering the pwned/password-compromised back-navigation flow was removed.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and concisely summarizes the main change: removing the back button from the password compromised/pwned error screen, which matches the primary objective across all modified files.
Description check✅ PassedThe description is directly related to the changeset, explaining the rationale for removing the back button and providing before/after screenshots demonstrating the UI change.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/ui/src/components/SignIn/SignInFactorOne.tsx (1)

158-173: ⚠️ Potential issue | 🟠 Major

Update/remove the test case that expects back navigation during pwned/compromised password flows.

The code change prevents back navigation when passwordErrorCode is present (line 159: const canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode;). However, the test at line 306 in SignInFactorOne.test.tsx ("entering a pwned password, then going back and clicking forgot password should result in the correct title") explicitly clicks the Back button during a pwned password scenario where passwordErrorCode will be set to 'pwned'. This test will fail because the Back button will no longer be clickable. Either remove this test or update it to validate that back navigation is intentionally disabled in error states.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/ui/src/components/SignIn/SignInFactorOne.tsx` around lines 158 -
173, The test expecting back navigation during a pwned/compromised password flow
must be updated because SignInFactorOne now sets canGoBack =
factorHasLocalStrategy(currentFactor) && !passwordErrorCode, which disables the
Back button when passwordErrorCode (e.g., 'pwned') is present; modify the test
"entering a pwned password, then going back and clicking forgot password should
result in the correct title" in SignInFactorOne.test.tsx to either remove the
Back click or assert that the backHandler is not invoked / the Back button is
not rendered/clickable (inspect canGoBack/AlternativeMethods props or presence
of onBackLinkClick) so the test reflects the new behavior. Ensure references to
canGoBack, passwordErrorCode, backHandler, and the AlternativeMethods
onBackLinkClick prop are used to drive the updated assertions.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Outside diff comments:
In `@packages/ui/src/components/SignIn/SignInFactorOne.tsx`:
- Around line 158-173: The test expecting back navigation during a
pwned/compromised password flow must be updated because SignInFactorOne now sets
canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode, which
disables the Back button when passwordErrorCode (e.g., 'pwned') is present;
modify the test "entering a pwned password, then going back and clicking forgot
password should result in the correct title" in SignInFactorOne.test.tsx to
either remove the Back click or assert that the backHandler is not invoked / the
Back button is not rendered/clickable (inspect canGoBack/AlternativeMethods
props or presence of onBackLinkClick) so the test reflects the new behavior.
Ensure references to canGoBack, passwordErrorCode, backHandler, and the
AlternativeMethods onBackLinkClick prop are used to drive the updated
assertions.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 1d132934-db90-44cb-b82d-11c32b6ab187

📥 Commits

Reviewing files that changed from the base of the PR and between fef9b68 and 3a2b08b.

📒 Files selected for processing (2)
  • .changeset/pink-taxes-do.md
  • packages/ui/src/components/SignIn/SignInFactorOne.tsx

if (showAllStrategies || showForgotPasswordStrategies) {
const canGoBack = factorHasLocalStrategy(currentFactor);
// Password errors are not recoverable by re-entering the password, so we hide the back button
const canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

passwordErrorCode is to me not a very clear name for this flag (it sounds more general than it is) but I confirmed that it is just a union of 'compromised' | 'pwned' so it's exactly what we want to check.

@Ephem
Ephem merged commit 3ffbe1f into mainMay 6, 2026
44 checks passed
@Ephem
Ephem deleted the fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button branch May 6, 2026 07:09
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Ephem@wobsoriano@dmoerner
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(ui): remove back button from sign-in password compromised/pwned error screen - #8280

Merged
Ephem merged 3 commits into
mainfrom
fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button
May 6, 2026
Merged

fix(ui): remove back button from sign-in password compromised/pwned error screen#8280
Ephem merged 3 commits into
mainfrom
fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button

Conversation

@Ephem

@EphemEphem commented Apr 9, 2026

Copy link
Copy Markdown
Member

Description

These errors are not recoverable by re-entering the password, so the back button led to a confusing dead end that would always take you back to the same error.

Before:

CleanShot 2026-04-09 at 16 24 16

After:

CleanShot 2026-04-09 at 16 23 32

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Ephem added 2 commits April 9, 2026 16:02
This would take you back to re-enter the password, which never works so it was leading to a confusing dead end.
@changeset-bot

changeset-botBot commented Apr 9, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 18269d6

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
NameType
@clerk/uiPatch
@clerk/chrome-extensionPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Apr 9, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentApr 9, 2026 2:23pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 9, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8280

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8280

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8280

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8280

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8280

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8280

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8280

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8280

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8280

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8280

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8280

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8280

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8280

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8280

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8280

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8280

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8280

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8280

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8280

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8280

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8280

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8280

commit: 18269d6

@coderabbitai

coderabbitaiBot commented Apr 9, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 46e651b2-ee3b-43b2-b3ed-0a8454ff3b30

📥 Commits

Reviewing files that changed from the base of the PR and between 3a2b08b and 18269d6.

📒 Files selected for processing (1)
  • packages/ui/src/components/SignIn/__tests__/SignInFactorOne.test.tsx
💤 Files with no reviewable changes (1)
  • packages/ui/src/components/SignIn/tests/SignInFactorOne.test.tsx

📝 Walkthrough

Walkthrough

This PR adds a Changeset for a patch release and updates the sign-in flow in the @clerk/ui package. It changes the canGoBack computation in SignInFactorOne.tsx to require both factorHasLocalStrategy(currentFactor) and the absence of passwordErrorCode, preventing the back action when a password error is present. A test covering the pwned/password-compromised back-navigation flow was removed.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and concisely summarizes the main change: removing the back button from the password compromised/pwned error screen, which matches the primary objective across all modified files.
Description check✅ PassedThe description is directly related to the changeset, explaining the rationale for removing the back button and providing before/after screenshots demonstrating the UI change.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/ui/src/components/SignIn/SignInFactorOne.tsx (1)

158-173: ⚠️ Potential issue | 🟠 Major

Update/remove the test case that expects back navigation during pwned/compromised password flows.

The code change prevents back navigation when passwordErrorCode is present (line 159: const canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode;). However, the test at line 306 in SignInFactorOne.test.tsx ("entering a pwned password, then going back and clicking forgot password should result in the correct title") explicitly clicks the Back button during a pwned password scenario where passwordErrorCode will be set to 'pwned'. This test will fail because the Back button will no longer be clickable. Either remove this test or update it to validate that back navigation is intentionally disabled in error states.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/ui/src/components/SignIn/SignInFactorOne.tsx` around lines 158 -
173, The test expecting back navigation during a pwned/compromised password flow
must be updated because SignInFactorOne now sets canGoBack =
factorHasLocalStrategy(currentFactor) && !passwordErrorCode, which disables the
Back button when passwordErrorCode (e.g., 'pwned') is present; modify the test
"entering a pwned password, then going back and clicking forgot password should
result in the correct title" in SignInFactorOne.test.tsx to either remove the
Back click or assert that the backHandler is not invoked / the Back button is
not rendered/clickable (inspect canGoBack/AlternativeMethods props or presence
of onBackLinkClick) so the test reflects the new behavior. Ensure references to
canGoBack, passwordErrorCode, backHandler, and the AlternativeMethods
onBackLinkClick prop are used to drive the updated assertions.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Outside diff comments:
In `@packages/ui/src/components/SignIn/SignInFactorOne.tsx`:
- Around line 158-173: The test expecting back navigation during a
pwned/compromised password flow must be updated because SignInFactorOne now sets
canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode, which
disables the Back button when passwordErrorCode (e.g., 'pwned') is present;
modify the test "entering a pwned password, then going back and clicking forgot
password should result in the correct title" in SignInFactorOne.test.tsx to
either remove the Back click or assert that the backHandler is not invoked / the
Back button is not rendered/clickable (inspect canGoBack/AlternativeMethods
props or presence of onBackLinkClick) so the test reflects the new behavior.
Ensure references to canGoBack, passwordErrorCode, backHandler, and the
AlternativeMethods onBackLinkClick prop are used to drive the updated
assertions.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 1d132934-db90-44cb-b82d-11c32b6ab187

📥 Commits

Reviewing files that changed from the base of the PR and between fef9b68 and 3a2b08b.

📒 Files selected for processing (2)
  • .changeset/pink-taxes-do.md
  • packages/ui/src/components/SignIn/SignInFactorOne.tsx

if (showAllStrategies || showForgotPasswordStrategies) {
const canGoBack = factorHasLocalStrategy(currentFactor);
// Password errors are not recoverable by re-entering the password, so we hide the back button
const canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

passwordErrorCode is to me not a very clear name for this flag (it sounds more general than it is) but I confirmed that it is just a union of 'compromised' | 'pwned' so it's exactly what we want to check.

@Ephem
Ephem merged commit 3ffbe1f into mainMay 6, 2026
44 checks passed
@Ephem
Ephem deleted the fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button branch May 6, 2026 07:09
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Ephem@wobsoriano@dmoerner
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(ui): remove back button from sign-in password compromised/pwned error screen - #8280

Merged
Ephem merged 3 commits into
mainfrom
fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button
May 6, 2026
Merged

fix(ui): remove back button from sign-in password compromised/pwned error screen#8280
Ephem merged 3 commits into
mainfrom
fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button

Conversation

@Ephem

@EphemEphem commented Apr 9, 2026

Copy link
Copy Markdown
Member

Description

These errors are not recoverable by re-entering the password, so the back button led to a confusing dead end that would always take you back to the same error.

Before:

CleanShot 2026-04-09 at 16 24 16

After:

CleanShot 2026-04-09 at 16 23 32

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Ephem added 2 commits April 9, 2026 16:02
This would take you back to re-enter the password, which never works so it was leading to a confusing dead end.
@changeset-bot

changeset-botBot commented Apr 9, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 18269d6

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
NameType
@clerk/uiPatch
@clerk/chrome-extensionPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Apr 9, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentApr 9, 2026 2:23pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 9, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8280

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8280

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8280

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8280

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8280

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8280

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8280

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8280

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8280

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8280

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8280

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8280

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8280

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8280

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8280

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8280

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8280

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8280

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8280

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8280

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8280

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8280

commit: 18269d6

@coderabbitai

coderabbitaiBot commented Apr 9, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 46e651b2-ee3b-43b2-b3ed-0a8454ff3b30

📥 Commits

Reviewing files that changed from the base of the PR and between 3a2b08b and 18269d6.

📒 Files selected for processing (1)
  • packages/ui/src/components/SignIn/__tests__/SignInFactorOne.test.tsx
💤 Files with no reviewable changes (1)
  • packages/ui/src/components/SignIn/tests/SignInFactorOne.test.tsx

📝 Walkthrough

Walkthrough

This PR adds a Changeset for a patch release and updates the sign-in flow in the @clerk/ui package. It changes the canGoBack computation in SignInFactorOne.tsx to require both factorHasLocalStrategy(currentFactor) and the absence of passwordErrorCode, preventing the back action when a password error is present. A test covering the pwned/password-compromised back-navigation flow was removed.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and concisely summarizes the main change: removing the back button from the password compromised/pwned error screen, which matches the primary objective across all modified files.
Description check✅ PassedThe description is directly related to the changeset, explaining the rationale for removing the back button and providing before/after screenshots demonstrating the UI change.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/ui/src/components/SignIn/SignInFactorOne.tsx (1)

158-173: ⚠️ Potential issue | 🟠 Major

Update/remove the test case that expects back navigation during pwned/compromised password flows.

The code change prevents back navigation when passwordErrorCode is present (line 159: const canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode;). However, the test at line 306 in SignInFactorOne.test.tsx ("entering a pwned password, then going back and clicking forgot password should result in the correct title") explicitly clicks the Back button during a pwned password scenario where passwordErrorCode will be set to 'pwned'. This test will fail because the Back button will no longer be clickable. Either remove this test or update it to validate that back navigation is intentionally disabled in error states.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/ui/src/components/SignIn/SignInFactorOne.tsx` around lines 158 -
173, The test expecting back navigation during a pwned/compromised password flow
must be updated because SignInFactorOne now sets canGoBack =
factorHasLocalStrategy(currentFactor) && !passwordErrorCode, which disables the
Back button when passwordErrorCode (e.g., 'pwned') is present; modify the test
"entering a pwned password, then going back and clicking forgot password should
result in the correct title" in SignInFactorOne.test.tsx to either remove the
Back click or assert that the backHandler is not invoked / the Back button is
not rendered/clickable (inspect canGoBack/AlternativeMethods props or presence
of onBackLinkClick) so the test reflects the new behavior. Ensure references to
canGoBack, passwordErrorCode, backHandler, and the AlternativeMethods
onBackLinkClick prop are used to drive the updated assertions.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Outside diff comments:
In `@packages/ui/src/components/SignIn/SignInFactorOne.tsx`:
- Around line 158-173: The test expecting back navigation during a
pwned/compromised password flow must be updated because SignInFactorOne now sets
canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode, which
disables the Back button when passwordErrorCode (e.g., 'pwned') is present;
modify the test "entering a pwned password, then going back and clicking forgot
password should result in the correct title" in SignInFactorOne.test.tsx to
either remove the Back click or assert that the backHandler is not invoked / the
Back button is not rendered/clickable (inspect canGoBack/AlternativeMethods
props or presence of onBackLinkClick) so the test reflects the new behavior.
Ensure references to canGoBack, passwordErrorCode, backHandler, and the
AlternativeMethods onBackLinkClick prop are used to drive the updated
assertions.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 1d132934-db90-44cb-b82d-11c32b6ab187

📥 Commits

Reviewing files that changed from the base of the PR and between fef9b68 and 3a2b08b.

📒 Files selected for processing (2)
  • .changeset/pink-taxes-do.md
  • packages/ui/src/components/SignIn/SignInFactorOne.tsx

if (showAllStrategies || showForgotPasswordStrategies) {
const canGoBack = factorHasLocalStrategy(currentFactor);
// Password errors are not recoverable by re-entering the password, so we hide the back button
const canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

passwordErrorCode is to me not a very clear name for this flag (it sounds more general than it is) but I confirmed that it is just a union of 'compromised' | 'pwned' so it's exactly what we want to check.

@Ephem
Ephem merged commit 3ffbe1f into mainMay 6, 2026
44 checks passed
@Ephem
Ephem deleted the fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button branch May 6, 2026 07:09
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Ephem@wobsoriano@dmoerner
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(ui): remove back button from sign-in password compromised/pwned error screen - #8280

Merged
Ephem merged 3 commits into
mainfrom
fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button
May 6, 2026
Merged

fix(ui): remove back button from sign-in password compromised/pwned error screen#8280
Ephem merged 3 commits into
mainfrom
fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button

Conversation

@Ephem

@EphemEphem commented Apr 9, 2026

Copy link
Copy Markdown
Member

Description

These errors are not recoverable by re-entering the password, so the back button led to a confusing dead end that would always take you back to the same error.

Before:

CleanShot 2026-04-09 at 16 24 16

After:

CleanShot 2026-04-09 at 16 23 32

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Ephem added 2 commits April 9, 2026 16:02
This would take you back to re-enter the password, which never works so it was leading to a confusing dead end.
@changeset-bot

changeset-botBot commented Apr 9, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 18269d6

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
NameType
@clerk/uiPatch
@clerk/chrome-extensionPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Apr 9, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentApr 9, 2026 2:23pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 9, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8280

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8280

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8280

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8280

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8280

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8280

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8280

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8280

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8280

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8280

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8280

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8280

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8280

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8280

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8280

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8280

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8280

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8280

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8280

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8280

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8280

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8280

commit: 18269d6

@coderabbitai

coderabbitaiBot commented Apr 9, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 46e651b2-ee3b-43b2-b3ed-0a8454ff3b30

📥 Commits

Reviewing files that changed from the base of the PR and between 3a2b08b and 18269d6.

📒 Files selected for processing (1)
  • packages/ui/src/components/SignIn/__tests__/SignInFactorOne.test.tsx
💤 Files with no reviewable changes (1)
  • packages/ui/src/components/SignIn/tests/SignInFactorOne.test.tsx

📝 Walkthrough

Walkthrough

This PR adds a Changeset for a patch release and updates the sign-in flow in the @clerk/ui package. It changes the canGoBack computation in SignInFactorOne.tsx to require both factorHasLocalStrategy(currentFactor) and the absence of passwordErrorCode, preventing the back action when a password error is present. A test covering the pwned/password-compromised back-navigation flow was removed.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and concisely summarizes the main change: removing the back button from the password compromised/pwned error screen, which matches the primary objective across all modified files.
Description check✅ PassedThe description is directly related to the changeset, explaining the rationale for removing the back button and providing before/after screenshots demonstrating the UI change.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/ui/src/components/SignIn/SignInFactorOne.tsx (1)

158-173: ⚠️ Potential issue | 🟠 Major

Update/remove the test case that expects back navigation during pwned/compromised password flows.

The code change prevents back navigation when passwordErrorCode is present (line 159: const canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode;). However, the test at line 306 in SignInFactorOne.test.tsx ("entering a pwned password, then going back and clicking forgot password should result in the correct title") explicitly clicks the Back button during a pwned password scenario where passwordErrorCode will be set to 'pwned'. This test will fail because the Back button will no longer be clickable. Either remove this test or update it to validate that back navigation is intentionally disabled in error states.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/ui/src/components/SignIn/SignInFactorOne.tsx` around lines 158 -
173, The test expecting back navigation during a pwned/compromised password flow
must be updated because SignInFactorOne now sets canGoBack =
factorHasLocalStrategy(currentFactor) && !passwordErrorCode, which disables the
Back button when passwordErrorCode (e.g., 'pwned') is present; modify the test
"entering a pwned password, then going back and clicking forgot password should
result in the correct title" in SignInFactorOne.test.tsx to either remove the
Back click or assert that the backHandler is not invoked / the Back button is
not rendered/clickable (inspect canGoBack/AlternativeMethods props or presence
of onBackLinkClick) so the test reflects the new behavior. Ensure references to
canGoBack, passwordErrorCode, backHandler, and the AlternativeMethods
onBackLinkClick prop are used to drive the updated assertions.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Outside diff comments:
In `@packages/ui/src/components/SignIn/SignInFactorOne.tsx`:
- Around line 158-173: The test expecting back navigation during a
pwned/compromised password flow must be updated because SignInFactorOne now sets
canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode, which
disables the Back button when passwordErrorCode (e.g., 'pwned') is present;
modify the test "entering a pwned password, then going back and clicking forgot
password should result in the correct title" in SignInFactorOne.test.tsx to
either remove the Back click or assert that the backHandler is not invoked / the
Back button is not rendered/clickable (inspect canGoBack/AlternativeMethods
props or presence of onBackLinkClick) so the test reflects the new behavior.
Ensure references to canGoBack, passwordErrorCode, backHandler, and the
AlternativeMethods onBackLinkClick prop are used to drive the updated
assertions.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 1d132934-db90-44cb-b82d-11c32b6ab187

📥 Commits

Reviewing files that changed from the base of the PR and between fef9b68 and 3a2b08b.

📒 Files selected for processing (2)
  • .changeset/pink-taxes-do.md
  • packages/ui/src/components/SignIn/SignInFactorOne.tsx

if (showAllStrategies || showForgotPasswordStrategies) {
const canGoBack = factorHasLocalStrategy(currentFactor);
// Password errors are not recoverable by re-entering the password, so we hide the back button
const canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

passwordErrorCode is to me not a very clear name for this flag (it sounds more general than it is) but I confirmed that it is just a union of 'compromised' | 'pwned' so it's exactly what we want to check.

@Ephem
Ephem merged commit 3ffbe1f into mainMay 6, 2026
44 checks passed
@Ephem
Ephem deleted the fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button branch May 6, 2026 07:09
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Ephem@wobsoriano@dmoerner
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(ui): remove back button from sign-in password compromised/pwned error screen - #8280

Merged
Ephem merged 3 commits into
mainfrom
fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button
May 6, 2026
Merged

fix(ui): remove back button from sign-in password compromised/pwned error screen#8280
Ephem merged 3 commits into
mainfrom
fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button

Conversation

@Ephem

@EphemEphem commented Apr 9, 2026

Copy link
Copy Markdown
Member

Description

These errors are not recoverable by re-entering the password, so the back button led to a confusing dead end that would always take you back to the same error.

Before:

CleanShot 2026-04-09 at 16 24 16

After:

CleanShot 2026-04-09 at 16 23 32

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Ephem added 2 commits April 9, 2026 16:02
This would take you back to re-enter the password, which never works so it was leading to a confusing dead end.
@changeset-bot

changeset-botBot commented Apr 9, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 18269d6

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
NameType
@clerk/uiPatch
@clerk/chrome-extensionPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Apr 9, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentApr 9, 2026 2:23pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 9, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8280

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8280

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8280

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8280

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8280

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8280

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8280

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8280

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8280

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8280

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8280

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8280

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8280

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8280

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8280

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8280

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8280

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8280

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8280

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8280

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8280

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8280

commit: 18269d6

@coderabbitai

coderabbitaiBot commented Apr 9, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 46e651b2-ee3b-43b2-b3ed-0a8454ff3b30

📥 Commits

Reviewing files that changed from the base of the PR and between 3a2b08b and 18269d6.

📒 Files selected for processing (1)
  • packages/ui/src/components/SignIn/__tests__/SignInFactorOne.test.tsx
💤 Files with no reviewable changes (1)
  • packages/ui/src/components/SignIn/tests/SignInFactorOne.test.tsx

📝 Walkthrough

Walkthrough

This PR adds a Changeset for a patch release and updates the sign-in flow in the @clerk/ui package. It changes the canGoBack computation in SignInFactorOne.tsx to require both factorHasLocalStrategy(currentFactor) and the absence of passwordErrorCode, preventing the back action when a password error is present. A test covering the pwned/password-compromised back-navigation flow was removed.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and concisely summarizes the main change: removing the back button from the password compromised/pwned error screen, which matches the primary objective across all modified files.
Description check✅ PassedThe description is directly related to the changeset, explaining the rationale for removing the back button and providing before/after screenshots demonstrating the UI change.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/ui/src/components/SignIn/SignInFactorOne.tsx (1)

158-173: ⚠️ Potential issue | 🟠 Major

Update/remove the test case that expects back navigation during pwned/compromised password flows.

The code change prevents back navigation when passwordErrorCode is present (line 159: const canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode;). However, the test at line 306 in SignInFactorOne.test.tsx ("entering a pwned password, then going back and clicking forgot password should result in the correct title") explicitly clicks the Back button during a pwned password scenario where passwordErrorCode will be set to 'pwned'. This test will fail because the Back button will no longer be clickable. Either remove this test or update it to validate that back navigation is intentionally disabled in error states.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/ui/src/components/SignIn/SignInFactorOne.tsx` around lines 158 -
173, The test expecting back navigation during a pwned/compromised password flow
must be updated because SignInFactorOne now sets canGoBack =
factorHasLocalStrategy(currentFactor) && !passwordErrorCode, which disables the
Back button when passwordErrorCode (e.g., 'pwned') is present; modify the test
"entering a pwned password, then going back and clicking forgot password should
result in the correct title" in SignInFactorOne.test.tsx to either remove the
Back click or assert that the backHandler is not invoked / the Back button is
not rendered/clickable (inspect canGoBack/AlternativeMethods props or presence
of onBackLinkClick) so the test reflects the new behavior. Ensure references to
canGoBack, passwordErrorCode, backHandler, and the AlternativeMethods
onBackLinkClick prop are used to drive the updated assertions.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Outside diff comments:
In `@packages/ui/src/components/SignIn/SignInFactorOne.tsx`:
- Around line 158-173: The test expecting back navigation during a
pwned/compromised password flow must be updated because SignInFactorOne now sets
canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode, which
disables the Back button when passwordErrorCode (e.g., 'pwned') is present;
modify the test "entering a pwned password, then going back and clicking forgot
password should result in the correct title" in SignInFactorOne.test.tsx to
either remove the Back click or assert that the backHandler is not invoked / the
Back button is not rendered/clickable (inspect canGoBack/AlternativeMethods
props or presence of onBackLinkClick) so the test reflects the new behavior.
Ensure references to canGoBack, passwordErrorCode, backHandler, and the
AlternativeMethods onBackLinkClick prop are used to drive the updated
assertions.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 1d132934-db90-44cb-b82d-11c32b6ab187

📥 Commits

Reviewing files that changed from the base of the PR and between fef9b68 and 3a2b08b.

📒 Files selected for processing (2)
  • .changeset/pink-taxes-do.md
  • packages/ui/src/components/SignIn/SignInFactorOne.tsx

if (showAllStrategies || showForgotPasswordStrategies) {
const canGoBack = factorHasLocalStrategy(currentFactor);
// Password errors are not recoverable by re-entering the password, so we hide the back button
const canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

passwordErrorCode is to me not a very clear name for this flag (it sounds more general than it is) but I confirmed that it is just a union of 'compromised' | 'pwned' so it's exactly what we want to check.

@Ephem
Ephem merged commit 3ffbe1f into mainMay 6, 2026
44 checks passed
@Ephem
Ephem deleted the fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button branch May 6, 2026 07:09
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Ephem@wobsoriano@dmoerner
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(ui): remove back button from sign-in password compromised/pwned error screen - #8280

Merged
Ephem merged 3 commits into
mainfrom
fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button
May 6, 2026
Merged

fix(ui): remove back button from sign-in password compromised/pwned error screen#8280
Ephem merged 3 commits into
mainfrom
fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button

Conversation

@Ephem

@EphemEphem commented Apr 9, 2026

Copy link
Copy Markdown
Member

Description

These errors are not recoverable by re-entering the password, so the back button led to a confusing dead end that would always take you back to the same error.

Before:

CleanShot 2026-04-09 at 16 24 16

After:

CleanShot 2026-04-09 at 16 23 32

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Ephem added 2 commits April 9, 2026 16:02
This would take you back to re-enter the password, which never works so it was leading to a confusing dead end.
@changeset-bot

changeset-botBot commented Apr 9, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 18269d6

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
NameType
@clerk/uiPatch
@clerk/chrome-extensionPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Apr 9, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentApr 9, 2026 2:23pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 9, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8280

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8280

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8280

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8280

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8280

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8280

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8280

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8280

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8280

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8280

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8280

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8280

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8280

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8280

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8280

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8280

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8280

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8280

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8280

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8280

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8280

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8280

commit: 18269d6

@coderabbitai

coderabbitaiBot commented Apr 9, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 46e651b2-ee3b-43b2-b3ed-0a8454ff3b30

📥 Commits

Reviewing files that changed from the base of the PR and between 3a2b08b and 18269d6.

📒 Files selected for processing (1)
  • packages/ui/src/components/SignIn/__tests__/SignInFactorOne.test.tsx
💤 Files with no reviewable changes (1)
  • packages/ui/src/components/SignIn/tests/SignInFactorOne.test.tsx

📝 Walkthrough

Walkthrough

This PR adds a Changeset for a patch release and updates the sign-in flow in the @clerk/ui package. It changes the canGoBack computation in SignInFactorOne.tsx to require both factorHasLocalStrategy(currentFactor) and the absence of passwordErrorCode, preventing the back action when a password error is present. A test covering the pwned/password-compromised back-navigation flow was removed.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and concisely summarizes the main change: removing the back button from the password compromised/pwned error screen, which matches the primary objective across all modified files.
Description check✅ PassedThe description is directly related to the changeset, explaining the rationale for removing the back button and providing before/after screenshots demonstrating the UI change.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/ui/src/components/SignIn/SignInFactorOne.tsx (1)

158-173: ⚠️ Potential issue | 🟠 Major

Update/remove the test case that expects back navigation during pwned/compromised password flows.

The code change prevents back navigation when passwordErrorCode is present (line 159: const canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode;). However, the test at line 306 in SignInFactorOne.test.tsx ("entering a pwned password, then going back and clicking forgot password should result in the correct title") explicitly clicks the Back button during a pwned password scenario where passwordErrorCode will be set to 'pwned'. This test will fail because the Back button will no longer be clickable. Either remove this test or update it to validate that back navigation is intentionally disabled in error states.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/ui/src/components/SignIn/SignInFactorOne.tsx` around lines 158 -
173, The test expecting back navigation during a pwned/compromised password flow
must be updated because SignInFactorOne now sets canGoBack =
factorHasLocalStrategy(currentFactor) && !passwordErrorCode, which disables the
Back button when passwordErrorCode (e.g., 'pwned') is present; modify the test
"entering a pwned password, then going back and clicking forgot password should
result in the correct title" in SignInFactorOne.test.tsx to either remove the
Back click or assert that the backHandler is not invoked / the Back button is
not rendered/clickable (inspect canGoBack/AlternativeMethods props or presence
of onBackLinkClick) so the test reflects the new behavior. Ensure references to
canGoBack, passwordErrorCode, backHandler, and the AlternativeMethods
onBackLinkClick prop are used to drive the updated assertions.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Outside diff comments:
In `@packages/ui/src/components/SignIn/SignInFactorOne.tsx`:
- Around line 158-173: The test expecting back navigation during a
pwned/compromised password flow must be updated because SignInFactorOne now sets
canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode, which
disables the Back button when passwordErrorCode (e.g., 'pwned') is present;
modify the test "entering a pwned password, then going back and clicking forgot
password should result in the correct title" in SignInFactorOne.test.tsx to
either remove the Back click or assert that the backHandler is not invoked / the
Back button is not rendered/clickable (inspect canGoBack/AlternativeMethods
props or presence of onBackLinkClick) so the test reflects the new behavior.
Ensure references to canGoBack, passwordErrorCode, backHandler, and the
AlternativeMethods onBackLinkClick prop are used to drive the updated
assertions.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 1d132934-db90-44cb-b82d-11c32b6ab187

📥 Commits

Reviewing files that changed from the base of the PR and between fef9b68 and 3a2b08b.

📒 Files selected for processing (2)
  • .changeset/pink-taxes-do.md
  • packages/ui/src/components/SignIn/SignInFactorOne.tsx

if (showAllStrategies || showForgotPasswordStrategies) {
const canGoBack = factorHasLocalStrategy(currentFactor);
// Password errors are not recoverable by re-entering the password, so we hide the back button
const canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

passwordErrorCode is to me not a very clear name for this flag (it sounds more general than it is) but I confirmed that it is just a union of 'compromised' | 'pwned' so it's exactly what we want to check.

@Ephem
Ephem merged commit 3ffbe1f into mainMay 6, 2026
44 checks passed
@Ephem
Ephem deleted the fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button branch May 6, 2026 07:09
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Ephem@wobsoriano@dmoerner
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(ui): remove back button from sign-in password compromised/pwned error screen - #8280

Merged
Ephem merged 3 commits into
mainfrom
fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button
May 6, 2026
Merged

fix(ui): remove back button from sign-in password compromised/pwned error screen#8280
Ephem merged 3 commits into
mainfrom
fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button

Conversation

@Ephem

@EphemEphem commented Apr 9, 2026

Copy link
Copy Markdown
Member

Description

These errors are not recoverable by re-entering the password, so the back button led to a confusing dead end that would always take you back to the same error.

Before:

CleanShot 2026-04-09 at 16 24 16

After:

CleanShot 2026-04-09 at 16 23 32

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Ephem added 2 commits April 9, 2026 16:02
This would take you back to re-enter the password, which never works so it was leading to a confusing dead end.
@changeset-bot

changeset-botBot commented Apr 9, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 18269d6

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
NameType
@clerk/uiPatch
@clerk/chrome-extensionPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Apr 9, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentApr 9, 2026 2:23pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 9, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8280

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8280

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8280

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8280

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8280

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8280

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8280

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8280

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8280

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8280

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8280

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8280

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8280

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8280

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8280

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8280

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8280

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8280

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8280

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8280

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8280

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8280

commit: 18269d6

@coderabbitai

coderabbitaiBot commented Apr 9, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 46e651b2-ee3b-43b2-b3ed-0a8454ff3b30

📥 Commits

Reviewing files that changed from the base of the PR and between 3a2b08b and 18269d6.

📒 Files selected for processing (1)
  • packages/ui/src/components/SignIn/__tests__/SignInFactorOne.test.tsx
💤 Files with no reviewable changes (1)
  • packages/ui/src/components/SignIn/tests/SignInFactorOne.test.tsx

📝 Walkthrough

Walkthrough

This PR adds a Changeset for a patch release and updates the sign-in flow in the @clerk/ui package. It changes the canGoBack computation in SignInFactorOne.tsx to require both factorHasLocalStrategy(currentFactor) and the absence of passwordErrorCode, preventing the back action when a password error is present. A test covering the pwned/password-compromised back-navigation flow was removed.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and concisely summarizes the main change: removing the back button from the password compromised/pwned error screen, which matches the primary objective across all modified files.
Description check✅ PassedThe description is directly related to the changeset, explaining the rationale for removing the back button and providing before/after screenshots demonstrating the UI change.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/ui/src/components/SignIn/SignInFactorOne.tsx (1)

158-173: ⚠️ Potential issue | 🟠 Major

Update/remove the test case that expects back navigation during pwned/compromised password flows.

The code change prevents back navigation when passwordErrorCode is present (line 159: const canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode;). However, the test at line 306 in SignInFactorOne.test.tsx ("entering a pwned password, then going back and clicking forgot password should result in the correct title") explicitly clicks the Back button during a pwned password scenario where passwordErrorCode will be set to 'pwned'. This test will fail because the Back button will no longer be clickable. Either remove this test or update it to validate that back navigation is intentionally disabled in error states.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/ui/src/components/SignIn/SignInFactorOne.tsx` around lines 158 -
173, The test expecting back navigation during a pwned/compromised password flow
must be updated because SignInFactorOne now sets canGoBack =
factorHasLocalStrategy(currentFactor) && !passwordErrorCode, which disables the
Back button when passwordErrorCode (e.g., 'pwned') is present; modify the test
"entering a pwned password, then going back and clicking forgot password should
result in the correct title" in SignInFactorOne.test.tsx to either remove the
Back click or assert that the backHandler is not invoked / the Back button is
not rendered/clickable (inspect canGoBack/AlternativeMethods props or presence
of onBackLinkClick) so the test reflects the new behavior. Ensure references to
canGoBack, passwordErrorCode, backHandler, and the AlternativeMethods
onBackLinkClick prop are used to drive the updated assertions.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Outside diff comments:
In `@packages/ui/src/components/SignIn/SignInFactorOne.tsx`:
- Around line 158-173: The test expecting back navigation during a
pwned/compromised password flow must be updated because SignInFactorOne now sets
canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode, which
disables the Back button when passwordErrorCode (e.g., 'pwned') is present;
modify the test "entering a pwned password, then going back and clicking forgot
password should result in the correct title" in SignInFactorOne.test.tsx to
either remove the Back click or assert that the backHandler is not invoked / the
Back button is not rendered/clickable (inspect canGoBack/AlternativeMethods
props or presence of onBackLinkClick) so the test reflects the new behavior.
Ensure references to canGoBack, passwordErrorCode, backHandler, and the
AlternativeMethods onBackLinkClick prop are used to drive the updated
assertions.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 1d132934-db90-44cb-b82d-11c32b6ab187

📥 Commits

Reviewing files that changed from the base of the PR and between fef9b68 and 3a2b08b.

📒 Files selected for processing (2)
  • .changeset/pink-taxes-do.md
  • packages/ui/src/components/SignIn/SignInFactorOne.tsx

if (showAllStrategies || showForgotPasswordStrategies) {
const canGoBack = factorHasLocalStrategy(currentFactor);
// Password errors are not recoverable by re-entering the password, so we hide the back button
const canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

passwordErrorCode is to me not a very clear name for this flag (it sounds more general than it is) but I confirmed that it is just a union of 'compromised' | 'pwned' so it's exactly what we want to check.

@Ephem
Ephem merged commit 3ffbe1f into mainMay 6, 2026
44 checks passed
@Ephem
Ephem deleted the fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button branch May 6, 2026 07:09
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Ephem@wobsoriano@dmoerner
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(ui): remove back button from sign-in password compromised/pwned error screen - #8280

Merged
Ephem merged 3 commits into
mainfrom
fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button
May 6, 2026
Merged

fix(ui): remove back button from sign-in password compromised/pwned error screen#8280
Ephem merged 3 commits into
mainfrom
fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button

Conversation

@Ephem

@EphemEphem commented Apr 9, 2026

Copy link
Copy Markdown
Member

Description

These errors are not recoverable by re-entering the password, so the back button led to a confusing dead end that would always take you back to the same error.

Before:

CleanShot 2026-04-09 at 16 24 16

After:

CleanShot 2026-04-09 at 16 23 32

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Ephem added 2 commits April 9, 2026 16:02
This would take you back to re-enter the password, which never works so it was leading to a confusing dead end.
@changeset-bot

changeset-botBot commented Apr 9, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 18269d6

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
NameType
@clerk/uiPatch
@clerk/chrome-extensionPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Apr 9, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentApr 9, 2026 2:23pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 9, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@8280

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8280

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8280

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8280

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8280

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8280

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8280

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8280

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8280

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8280

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8280

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8280

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8280

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8280

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8280

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8280

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8280

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8280

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8280

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8280

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8280

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8280

commit: 18269d6

@coderabbitai

coderabbitaiBot commented Apr 9, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 46e651b2-ee3b-43b2-b3ed-0a8454ff3b30

📥 Commits

Reviewing files that changed from the base of the PR and between 3a2b08b and 18269d6.

📒 Files selected for processing (1)
  • packages/ui/src/components/SignIn/__tests__/SignInFactorOne.test.tsx
💤 Files with no reviewable changes (1)
  • packages/ui/src/components/SignIn/tests/SignInFactorOne.test.tsx

📝 Walkthrough

Walkthrough

This PR adds a Changeset for a patch release and updates the sign-in flow in the @clerk/ui package. It changes the canGoBack computation in SignInFactorOne.tsx to require both factorHasLocalStrategy(currentFactor) and the absence of passwordErrorCode, preventing the back action when a password error is present. A test covering the pwned/password-compromised back-navigation flow was removed.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and concisely summarizes the main change: removing the back button from the password compromised/pwned error screen, which matches the primary objective across all modified files.
Description check✅ PassedThe description is directly related to the changeset, explaining the rationale for removing the back button and providing before/after screenshots demonstrating the UI change.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/ui/src/components/SignIn/SignInFactorOne.tsx (1)

158-173: ⚠️ Potential issue | 🟠 Major

Update/remove the test case that expects back navigation during pwned/compromised password flows.

The code change prevents back navigation when passwordErrorCode is present (line 159: const canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode;). However, the test at line 306 in SignInFactorOne.test.tsx ("entering a pwned password, then going back and clicking forgot password should result in the correct title") explicitly clicks the Back button during a pwned password scenario where passwordErrorCode will be set to 'pwned'. This test will fail because the Back button will no longer be clickable. Either remove this test or update it to validate that back navigation is intentionally disabled in error states.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@packages/ui/src/components/SignIn/SignInFactorOne.tsx` around lines 158 -
173, The test expecting back navigation during a pwned/compromised password flow
must be updated because SignInFactorOne now sets canGoBack =
factorHasLocalStrategy(currentFactor) && !passwordErrorCode, which disables the
Back button when passwordErrorCode (e.g., 'pwned') is present; modify the test
"entering a pwned password, then going back and clicking forgot password should
result in the correct title" in SignInFactorOne.test.tsx to either remove the
Back click or assert that the backHandler is not invoked / the Back button is
not rendered/clickable (inspect canGoBack/AlternativeMethods props or presence
of onBackLinkClick) so the test reflects the new behavior. Ensure references to
canGoBack, passwordErrorCode, backHandler, and the AlternativeMethods
onBackLinkClick prop are used to drive the updated assertions.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Outside diff comments:
In `@packages/ui/src/components/SignIn/SignInFactorOne.tsx`:
- Around line 158-173: The test expecting back navigation during a
pwned/compromised password flow must be updated because SignInFactorOne now sets
canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode, which
disables the Back button when passwordErrorCode (e.g., 'pwned') is present;
modify the test "entering a pwned password, then going back and clicking forgot
password should result in the correct title" in SignInFactorOne.test.tsx to
either remove the Back click or assert that the backHandler is not invoked / the
Back button is not rendered/clickable (inspect canGoBack/AlternativeMethods
props or presence of onBackLinkClick) so the test reflects the new behavior.
Ensure references to canGoBack, passwordErrorCode, backHandler, and the
AlternativeMethods onBackLinkClick prop are used to drive the updated
assertions.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 1d132934-db90-44cb-b82d-11c32b6ab187

📥 Commits

Reviewing files that changed from the base of the PR and between fef9b68 and 3a2b08b.

📒 Files selected for processing (2)
  • .changeset/pink-taxes-do.md
  • packages/ui/src/components/SignIn/SignInFactorOne.tsx

if (showAllStrategies || showForgotPasswordStrategies) {
const canGoBack = factorHasLocalStrategy(currentFactor);
// Password errors are not recoverable by re-entering the password, so we hide the back button
const canGoBack = factorHasLocalStrategy(currentFactor) && !passwordErrorCode;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

passwordErrorCode is to me not a very clear name for this flag (it sounds more general than it is) but I confirmed that it is just a union of 'compromised' | 'pwned' so it's exactly what we want to check.

@Ephem
Ephem merged commit 3ffbe1f into mainMay 6, 2026
44 checks passed
@Ephem
Ephem deleted the fredrik/sdk-44-breached-password-error-allows-resubmission-via-back-button branch May 6, 2026 07:09
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Ephem@wobsoriano@dmoerner