test(e2e): improve integration test reliability - #8422

Merged
jacekradko merged 2 commits into
mainfrom
jacek/fix-e2e-compromised-password
May 1, 2026
Merged

test(e2e): improve integration test reliability#8422
jacekradko merged 2 commits into
mainfrom
jacek/fix-e2e-compromised-password

Conversation

@jacekradko

@jacekradkojacekradko commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Summary

Three small E2E reliability fixes uncovered while investigating consistent CI failures across multiple suites.

1. Strong random fake-user passwords

createFakeUser built passwords as ${email}${randomHash} (e.g. 76557538ea+clerk_test@clerkcookie.com76557538ea). FAPI's compromised-password check rejects these with form_password_compromised (HTTP 422), which broke any sign-in flow that wasn't intentionally testing the compromised-password path. Replaced with a fakerPassword() helper that emits a high-entropy base64url string with a fixed Aa1! prefix to satisfy default Clerk complexity rules (upper, lower, digit, symbol).

2. Defensive afterAll cleanup

When a test suite's beforeAll timed out or threw (BAPI hiccup, dev server slow to come up, etc.), afterAll would crash with a TypeError on the un-assigned fakeUser / fakeOrganization / network / fakeOAuth / fakeAPIKey, masking the real failure. Optional-chain the cleanup calls in:

  • integration/tests/components.test.ts
  • integration/testUtils/machineAuthHelpers.ts (apiKey, m2m, oauth describes)

3. Drop timer-dependent token-cache assertions

Two MemoryTokenCache cross-tab tests assumed JWT TTL = 60s and waited 50s of wall-clock time for the proactive-refresh setTimeout to fire. The dev test instance now issues 300s tokens, so the refresh fires at ~283s and the tests never reached it.

The BroadcastChannel-based deduplication these tests were checking is already covered elsewhere; the proactive-refresh timer scheduling itself is best validated by unit tests that mock setTimeout, not by real-time integration tests.

  • Deleteintegration/tests/session-token-cache/single-session.test.ts "multi-tab scheduled refreshes are deduped to a single request". The same broadcast-dedup path is exercised by the existing line-49 test ("multi-tab token sharing works when clearing the cache") via getToken({ skipCache: true }).
  • Rewriteintegration/tests/session-token-cache/multi-session.test.ts:249 (now "cross-session token refreshes do not deduplicate") to manually trigger getToken({ skipCache: true }) on each tab. Different sessions have different tokenIds, so BroadcastChannel doesn't dedupe — each tab is expected to make its own request. Unique coverage the single-session test doesn't provide.

Scoped to integration/ only and doesn't affect any published package — empty changeset.

Test plan

  • genericcomponents-component-smoke — real beforeAll failure surfaces instead of TypeError: ... 'delete'
  • machinetests-with-invalid-M2M-tokens / local-verification — real ClerkAPIResponseError surfaces instead of TypeError: ... 'cleanup'
  • genericmulti-tab token sharing works when clearing the cache — still green (covers the broadcast-dedup path the deleted timer test was duplicating)
  • nextjscross-session token refreshes do not deduplicate — green; runs in seconds and asserts the cross-session non-dedup case
  • No regression in nextjs session-tasks-sign-in-reset-password (test still calls setPasswordCompromised on purpose)

@changeset-bot

changeset-botBot commented Apr 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 6cf9d6c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Apr 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 1, 2026 0:11am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 30, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8422

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8422

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8422

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8422

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8422

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8422

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8422

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8422

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8422

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8422

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8422

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8422

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8422

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8422

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8422

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8422

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8422

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8422

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8422

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8422

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8422

commit: 6cf9d6c

@coderabbitai

coderabbitaiBot commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

A fix for e2e test reliability is introduced by adding a new fakerPassword helper function that generates strong test passwords using cryptographic randomness and base64 encoding, ensuring compliance with password complexity requirements. The createFakeUser function is updated to use this helper instead of simple email concatenation. Additionally, test teardown logic across multiple test files is made more defensive by applying optional chaining to safely handle cases where test fixtures may be uninitialized or missing.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe PR description comprehensively relates to the changeset, detailing the three reliability fixes with clear explanations of the problems and solutions.
Title check✅ PassedThe title 'test(e2e): improve integration test reliability' is partially related to the changeset. While it accurately describes one aspect of the changes (improving test reliability through defensive cleanup), it does not highlight the main change, which is fixing e2e failures caused by a compromised-password check by introducing a stronger fake password generator.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@jacekradkojacekradko changed the title test(integration): use strong random passwords and harden afterAlltest(e2e): use strong random passwords and harden afterAllApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): use strong random passwords and harden afterAlltest(e2e): addressing new e2e failuresApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): addressing new e2e failurestest(e2e): use strong fake-user passwords and harden afterAll cleanupApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): use strong fake-user passwords and harden afterAll cleanuptest(e2e): fake-user passwords, defensive afterAll, and virtual clock for token-cache testsApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): fake-user passwords, defensive afterAll, and virtual clock for token-cache teststest(e2e): fake-user passwords, defensive afterAll, and trim timer-dependent token-cache testsApr 30, 2026
…ent token-cache tests
Three small E2E reliability fixes uncovered while investigating
consistent CI failures across multiple suites.
1. Strong random fake-user passwords. createFakeUser built passwords
as `${email}${randomHash}`, which FAPI's compromised-password check
rejected with `form_password_compromised` (HTTP 422). Replaced with
a `fakerPassword()` helper that emits a high-entropy base64url
string with a fixed `Aa1!` prefix to satisfy default Clerk password
complexity rules.
2. Defensive afterAll cleanup. When a suite's beforeAll timed out or
threw, afterAll crashed with a TypeError on un-assigned fakeUser /
fakeOrganization / network / fakeOAuth / fakeAPIKey, masking the
real failure. Optional-chained the cleanup calls in:
- integration/tests/components.test.ts
- integration/testUtils/machineAuthHelpers.ts (apiKey, m2m, oauth)
3. Drop timer-dependent token-cache assertions. Two MemoryTokenCache
cross-tab tests assumed JWT TTL = 60s and waited 50s of wall-clock
time for the proactive-refresh setTimeout to fire. The dev test
instance now issues 300s tokens, so the timer fires at ~283s and
the tests never reached it.
- Deleted `multi-tab scheduled refreshes are deduped to a single
request` from single-session.test.ts. The same broadcast-dedup
path is exercised by the existing line-49 test via
`getToken({ skipCache: true })`.
- Rewrote multi-session.test.ts:249 (now `cross-session token
refreshes do not deduplicate`) to manually trigger
`getToken({ skipCache: true })` on each tab. Different sessions
have different tokenIds, so BroadcastChannel does NOT deduplicate
across them — unique coverage the single-session test doesn't
provide.
Proactive-refresh timer scheduling math is best validated by unit
tests that mock setTimeout, not by real-time integration tests
against a shared dev instance.
Scoped to integration/ only, no published package affected — empty
changeset.
@jacekradko
jacekradkoforce-pushed the jacek/fix-e2e-compromised-password branch from 6eebdd2 to ef5dd73CompareApril 30, 2026 21:29
@jacekradkojacekradko changed the title test(e2e): fake-user passwords, defensive afterAll, and trim timer-dependent token-cache teststest(e2e): improve integration test reliabilityApr 30, 2026
@jacekradko
jacekradko merged commit 1f804dc into mainMay 1, 2026
132 of 136 checks passed
@jacekradko
jacekradko deleted the jacek/fix-e2e-compromised-password branch May 1, 2026 01:19
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

test(e2e): improve integration test reliability - #8422

Merged
jacekradko merged 2 commits into
mainfrom
jacek/fix-e2e-compromised-password
May 1, 2026
Merged

test(e2e): improve integration test reliability#8422
jacekradko merged 2 commits into
mainfrom
jacek/fix-e2e-compromised-password

Conversation

@jacekradko

@jacekradkojacekradko commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Summary

Three small E2E reliability fixes uncovered while investigating consistent CI failures across multiple suites.

1. Strong random fake-user passwords

createFakeUser built passwords as ${email}${randomHash} (e.g. 76557538ea+clerk_test@clerkcookie.com76557538ea). FAPI's compromised-password check rejects these with form_password_compromised (HTTP 422), which broke any sign-in flow that wasn't intentionally testing the compromised-password path. Replaced with a fakerPassword() helper that emits a high-entropy base64url string with a fixed Aa1! prefix to satisfy default Clerk complexity rules (upper, lower, digit, symbol).

2. Defensive afterAll cleanup

When a test suite's beforeAll timed out or threw (BAPI hiccup, dev server slow to come up, etc.), afterAll would crash with a TypeError on the un-assigned fakeUser / fakeOrganization / network / fakeOAuth / fakeAPIKey, masking the real failure. Optional-chain the cleanup calls in:

  • integration/tests/components.test.ts
  • integration/testUtils/machineAuthHelpers.ts (apiKey, m2m, oauth describes)

3. Drop timer-dependent token-cache assertions

Two MemoryTokenCache cross-tab tests assumed JWT TTL = 60s and waited 50s of wall-clock time for the proactive-refresh setTimeout to fire. The dev test instance now issues 300s tokens, so the refresh fires at ~283s and the tests never reached it.

The BroadcastChannel-based deduplication these tests were checking is already covered elsewhere; the proactive-refresh timer scheduling itself is best validated by unit tests that mock setTimeout, not by real-time integration tests.

  • Deleteintegration/tests/session-token-cache/single-session.test.ts "multi-tab scheduled refreshes are deduped to a single request". The same broadcast-dedup path is exercised by the existing line-49 test ("multi-tab token sharing works when clearing the cache") via getToken({ skipCache: true }).
  • Rewriteintegration/tests/session-token-cache/multi-session.test.ts:249 (now "cross-session token refreshes do not deduplicate") to manually trigger getToken({ skipCache: true }) on each tab. Different sessions have different tokenIds, so BroadcastChannel doesn't dedupe — each tab is expected to make its own request. Unique coverage the single-session test doesn't provide.

Scoped to integration/ only and doesn't affect any published package — empty changeset.

Test plan

  • genericcomponents-component-smoke — real beforeAll failure surfaces instead of TypeError: ... 'delete'
  • machinetests-with-invalid-M2M-tokens / local-verification — real ClerkAPIResponseError surfaces instead of TypeError: ... 'cleanup'
  • genericmulti-tab token sharing works when clearing the cache — still green (covers the broadcast-dedup path the deleted timer test was duplicating)
  • nextjscross-session token refreshes do not deduplicate — green; runs in seconds and asserts the cross-session non-dedup case
  • No regression in nextjs session-tasks-sign-in-reset-password (test still calls setPasswordCompromised on purpose)

@changeset-bot

changeset-botBot commented Apr 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 6cf9d6c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Apr 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 1, 2026 0:11am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 30, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8422

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8422

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8422

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8422

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8422

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8422

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8422

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8422

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8422

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8422

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8422

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8422

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8422

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8422

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8422

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8422

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8422

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8422

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8422

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8422

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8422

commit: 6cf9d6c

@coderabbitai

coderabbitaiBot commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

A fix for e2e test reliability is introduced by adding a new fakerPassword helper function that generates strong test passwords using cryptographic randomness and base64 encoding, ensuring compliance with password complexity requirements. The createFakeUser function is updated to use this helper instead of simple email concatenation. Additionally, test teardown logic across multiple test files is made more defensive by applying optional chaining to safely handle cases where test fixtures may be uninitialized or missing.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe PR description comprehensively relates to the changeset, detailing the three reliability fixes with clear explanations of the problems and solutions.
Title check✅ PassedThe title 'test(e2e): improve integration test reliability' is partially related to the changeset. While it accurately describes one aspect of the changes (improving test reliability through defensive cleanup), it does not highlight the main change, which is fixing e2e failures caused by a compromised-password check by introducing a stronger fake password generator.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@jacekradkojacekradko changed the title test(integration): use strong random passwords and harden afterAlltest(e2e): use strong random passwords and harden afterAllApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): use strong random passwords and harden afterAlltest(e2e): addressing new e2e failuresApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): addressing new e2e failurestest(e2e): use strong fake-user passwords and harden afterAll cleanupApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): use strong fake-user passwords and harden afterAll cleanuptest(e2e): fake-user passwords, defensive afterAll, and virtual clock for token-cache testsApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): fake-user passwords, defensive afterAll, and virtual clock for token-cache teststest(e2e): fake-user passwords, defensive afterAll, and trim timer-dependent token-cache testsApr 30, 2026
…ent token-cache tests
Three small E2E reliability fixes uncovered while investigating
consistent CI failures across multiple suites.
1. Strong random fake-user passwords. createFakeUser built passwords
as `${email}${randomHash}`, which FAPI's compromised-password check
rejected with `form_password_compromised` (HTTP 422). Replaced with
a `fakerPassword()` helper that emits a high-entropy base64url
string with a fixed `Aa1!` prefix to satisfy default Clerk password
complexity rules.
2. Defensive afterAll cleanup. When a suite's beforeAll timed out or
threw, afterAll crashed with a TypeError on un-assigned fakeUser /
fakeOrganization / network / fakeOAuth / fakeAPIKey, masking the
real failure. Optional-chained the cleanup calls in:
- integration/tests/components.test.ts
- integration/testUtils/machineAuthHelpers.ts (apiKey, m2m, oauth)
3. Drop timer-dependent token-cache assertions. Two MemoryTokenCache
cross-tab tests assumed JWT TTL = 60s and waited 50s of wall-clock
time for the proactive-refresh setTimeout to fire. The dev test
instance now issues 300s tokens, so the timer fires at ~283s and
the tests never reached it.
- Deleted `multi-tab scheduled refreshes are deduped to a single
request` from single-session.test.ts. The same broadcast-dedup
path is exercised by the existing line-49 test via
`getToken({ skipCache: true })`.
- Rewrote multi-session.test.ts:249 (now `cross-session token
refreshes do not deduplicate`) to manually trigger
`getToken({ skipCache: true })` on each tab. Different sessions
have different tokenIds, so BroadcastChannel does NOT deduplicate
across them — unique coverage the single-session test doesn't
provide.
Proactive-refresh timer scheduling math is best validated by unit
tests that mock setTimeout, not by real-time integration tests
against a shared dev instance.
Scoped to integration/ only, no published package affected — empty
changeset.
@jacekradko
jacekradkoforce-pushed the jacek/fix-e2e-compromised-password branch from 6eebdd2 to ef5dd73CompareApril 30, 2026 21:29
@jacekradkojacekradko changed the title test(e2e): fake-user passwords, defensive afterAll, and trim timer-dependent token-cache teststest(e2e): improve integration test reliabilityApr 30, 2026
@jacekradko
jacekradko merged commit 1f804dc into mainMay 1, 2026
132 of 136 checks passed
@jacekradko
jacekradko deleted the jacek/fix-e2e-compromised-password branch May 1, 2026 01:19
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

test(e2e): improve integration test reliability - #8422

Merged
jacekradko merged 2 commits into
mainfrom
jacek/fix-e2e-compromised-password
May 1, 2026
Merged

test(e2e): improve integration test reliability#8422
jacekradko merged 2 commits into
mainfrom
jacek/fix-e2e-compromised-password

Conversation

@jacekradko

@jacekradkojacekradko commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Summary

Three small E2E reliability fixes uncovered while investigating consistent CI failures across multiple suites.

1. Strong random fake-user passwords

createFakeUser built passwords as ${email}${randomHash} (e.g. 76557538ea+clerk_test@clerkcookie.com76557538ea). FAPI's compromised-password check rejects these with form_password_compromised (HTTP 422), which broke any sign-in flow that wasn't intentionally testing the compromised-password path. Replaced with a fakerPassword() helper that emits a high-entropy base64url string with a fixed Aa1! prefix to satisfy default Clerk complexity rules (upper, lower, digit, symbol).

2. Defensive afterAll cleanup

When a test suite's beforeAll timed out or threw (BAPI hiccup, dev server slow to come up, etc.), afterAll would crash with a TypeError on the un-assigned fakeUser / fakeOrganization / network / fakeOAuth / fakeAPIKey, masking the real failure. Optional-chain the cleanup calls in:

  • integration/tests/components.test.ts
  • integration/testUtils/machineAuthHelpers.ts (apiKey, m2m, oauth describes)

3. Drop timer-dependent token-cache assertions

Two MemoryTokenCache cross-tab tests assumed JWT TTL = 60s and waited 50s of wall-clock time for the proactive-refresh setTimeout to fire. The dev test instance now issues 300s tokens, so the refresh fires at ~283s and the tests never reached it.

The BroadcastChannel-based deduplication these tests were checking is already covered elsewhere; the proactive-refresh timer scheduling itself is best validated by unit tests that mock setTimeout, not by real-time integration tests.

  • Deleteintegration/tests/session-token-cache/single-session.test.ts "multi-tab scheduled refreshes are deduped to a single request". The same broadcast-dedup path is exercised by the existing line-49 test ("multi-tab token sharing works when clearing the cache") via getToken({ skipCache: true }).
  • Rewriteintegration/tests/session-token-cache/multi-session.test.ts:249 (now "cross-session token refreshes do not deduplicate") to manually trigger getToken({ skipCache: true }) on each tab. Different sessions have different tokenIds, so BroadcastChannel doesn't dedupe — each tab is expected to make its own request. Unique coverage the single-session test doesn't provide.

Scoped to integration/ only and doesn't affect any published package — empty changeset.

Test plan

  • genericcomponents-component-smoke — real beforeAll failure surfaces instead of TypeError: ... 'delete'
  • machinetests-with-invalid-M2M-tokens / local-verification — real ClerkAPIResponseError surfaces instead of TypeError: ... 'cleanup'
  • genericmulti-tab token sharing works when clearing the cache — still green (covers the broadcast-dedup path the deleted timer test was duplicating)
  • nextjscross-session token refreshes do not deduplicate — green; runs in seconds and asserts the cross-session non-dedup case
  • No regression in nextjs session-tasks-sign-in-reset-password (test still calls setPasswordCompromised on purpose)

@changeset-bot

changeset-botBot commented Apr 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 6cf9d6c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Apr 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 1, 2026 0:11am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 30, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8422

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8422

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8422

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8422

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8422

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8422

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8422

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8422

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8422

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8422

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8422

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8422

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8422

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8422

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8422

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8422

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8422

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8422

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8422

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8422

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8422

commit: 6cf9d6c

@coderabbitai

coderabbitaiBot commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

A fix for e2e test reliability is introduced by adding a new fakerPassword helper function that generates strong test passwords using cryptographic randomness and base64 encoding, ensuring compliance with password complexity requirements. The createFakeUser function is updated to use this helper instead of simple email concatenation. Additionally, test teardown logic across multiple test files is made more defensive by applying optional chaining to safely handle cases where test fixtures may be uninitialized or missing.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe PR description comprehensively relates to the changeset, detailing the three reliability fixes with clear explanations of the problems and solutions.
Title check✅ PassedThe title 'test(e2e): improve integration test reliability' is partially related to the changeset. While it accurately describes one aspect of the changes (improving test reliability through defensive cleanup), it does not highlight the main change, which is fixing e2e failures caused by a compromised-password check by introducing a stronger fake password generator.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@jacekradkojacekradko changed the title test(integration): use strong random passwords and harden afterAlltest(e2e): use strong random passwords and harden afterAllApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): use strong random passwords and harden afterAlltest(e2e): addressing new e2e failuresApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): addressing new e2e failurestest(e2e): use strong fake-user passwords and harden afterAll cleanupApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): use strong fake-user passwords and harden afterAll cleanuptest(e2e): fake-user passwords, defensive afterAll, and virtual clock for token-cache testsApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): fake-user passwords, defensive afterAll, and virtual clock for token-cache teststest(e2e): fake-user passwords, defensive afterAll, and trim timer-dependent token-cache testsApr 30, 2026
…ent token-cache tests
Three small E2E reliability fixes uncovered while investigating
consistent CI failures across multiple suites.
1. Strong random fake-user passwords. createFakeUser built passwords
as `${email}${randomHash}`, which FAPI's compromised-password check
rejected with `form_password_compromised` (HTTP 422). Replaced with
a `fakerPassword()` helper that emits a high-entropy base64url
string with a fixed `Aa1!` prefix to satisfy default Clerk password
complexity rules.
2. Defensive afterAll cleanup. When a suite's beforeAll timed out or
threw, afterAll crashed with a TypeError on un-assigned fakeUser /
fakeOrganization / network / fakeOAuth / fakeAPIKey, masking the
real failure. Optional-chained the cleanup calls in:
- integration/tests/components.test.ts
- integration/testUtils/machineAuthHelpers.ts (apiKey, m2m, oauth)
3. Drop timer-dependent token-cache assertions. Two MemoryTokenCache
cross-tab tests assumed JWT TTL = 60s and waited 50s of wall-clock
time for the proactive-refresh setTimeout to fire. The dev test
instance now issues 300s tokens, so the timer fires at ~283s and
the tests never reached it.
- Deleted `multi-tab scheduled refreshes are deduped to a single
request` from single-session.test.ts. The same broadcast-dedup
path is exercised by the existing line-49 test via
`getToken({ skipCache: true })`.
- Rewrote multi-session.test.ts:249 (now `cross-session token
refreshes do not deduplicate`) to manually trigger
`getToken({ skipCache: true })` on each tab. Different sessions
have different tokenIds, so BroadcastChannel does NOT deduplicate
across them — unique coverage the single-session test doesn't
provide.
Proactive-refresh timer scheduling math is best validated by unit
tests that mock setTimeout, not by real-time integration tests
against a shared dev instance.
Scoped to integration/ only, no published package affected — empty
changeset.
@jacekradko
jacekradkoforce-pushed the jacek/fix-e2e-compromised-password branch from 6eebdd2 to ef5dd73CompareApril 30, 2026 21:29
@jacekradkojacekradko changed the title test(e2e): fake-user passwords, defensive afterAll, and trim timer-dependent token-cache teststest(e2e): improve integration test reliabilityApr 30, 2026
@jacekradko
jacekradko merged commit 1f804dc into mainMay 1, 2026
132 of 136 checks passed
@jacekradko
jacekradko deleted the jacek/fix-e2e-compromised-password branch May 1, 2026 01:19
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

test(e2e): improve integration test reliability - #8422

Merged
jacekradko merged 2 commits into
mainfrom
jacek/fix-e2e-compromised-password
May 1, 2026
Merged

test(e2e): improve integration test reliability#8422
jacekradko merged 2 commits into
mainfrom
jacek/fix-e2e-compromised-password

Conversation

@jacekradko

@jacekradkojacekradko commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Summary

Three small E2E reliability fixes uncovered while investigating consistent CI failures across multiple suites.

1. Strong random fake-user passwords

createFakeUser built passwords as ${email}${randomHash} (e.g. 76557538ea+clerk_test@clerkcookie.com76557538ea). FAPI's compromised-password check rejects these with form_password_compromised (HTTP 422), which broke any sign-in flow that wasn't intentionally testing the compromised-password path. Replaced with a fakerPassword() helper that emits a high-entropy base64url string with a fixed Aa1! prefix to satisfy default Clerk complexity rules (upper, lower, digit, symbol).

2. Defensive afterAll cleanup

When a test suite's beforeAll timed out or threw (BAPI hiccup, dev server slow to come up, etc.), afterAll would crash with a TypeError on the un-assigned fakeUser / fakeOrganization / network / fakeOAuth / fakeAPIKey, masking the real failure. Optional-chain the cleanup calls in:

  • integration/tests/components.test.ts
  • integration/testUtils/machineAuthHelpers.ts (apiKey, m2m, oauth describes)

3. Drop timer-dependent token-cache assertions

Two MemoryTokenCache cross-tab tests assumed JWT TTL = 60s and waited 50s of wall-clock time for the proactive-refresh setTimeout to fire. The dev test instance now issues 300s tokens, so the refresh fires at ~283s and the tests never reached it.

The BroadcastChannel-based deduplication these tests were checking is already covered elsewhere; the proactive-refresh timer scheduling itself is best validated by unit tests that mock setTimeout, not by real-time integration tests.

  • Deleteintegration/tests/session-token-cache/single-session.test.ts "multi-tab scheduled refreshes are deduped to a single request". The same broadcast-dedup path is exercised by the existing line-49 test ("multi-tab token sharing works when clearing the cache") via getToken({ skipCache: true }).
  • Rewriteintegration/tests/session-token-cache/multi-session.test.ts:249 (now "cross-session token refreshes do not deduplicate") to manually trigger getToken({ skipCache: true }) on each tab. Different sessions have different tokenIds, so BroadcastChannel doesn't dedupe — each tab is expected to make its own request. Unique coverage the single-session test doesn't provide.

Scoped to integration/ only and doesn't affect any published package — empty changeset.

Test plan

  • genericcomponents-component-smoke — real beforeAll failure surfaces instead of TypeError: ... 'delete'
  • machinetests-with-invalid-M2M-tokens / local-verification — real ClerkAPIResponseError surfaces instead of TypeError: ... 'cleanup'
  • genericmulti-tab token sharing works when clearing the cache — still green (covers the broadcast-dedup path the deleted timer test was duplicating)
  • nextjscross-session token refreshes do not deduplicate — green; runs in seconds and asserts the cross-session non-dedup case
  • No regression in nextjs session-tasks-sign-in-reset-password (test still calls setPasswordCompromised on purpose)

@changeset-bot

changeset-botBot commented Apr 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 6cf9d6c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Apr 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 1, 2026 0:11am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 30, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8422

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8422

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8422

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8422

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8422

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8422

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8422

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8422

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8422

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8422

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8422

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8422

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8422

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8422

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8422

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8422

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8422

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8422

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8422

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8422

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8422

commit: 6cf9d6c

@coderabbitai

coderabbitaiBot commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

A fix for e2e test reliability is introduced by adding a new fakerPassword helper function that generates strong test passwords using cryptographic randomness and base64 encoding, ensuring compliance with password complexity requirements. The createFakeUser function is updated to use this helper instead of simple email concatenation. Additionally, test teardown logic across multiple test files is made more defensive by applying optional chaining to safely handle cases where test fixtures may be uninitialized or missing.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe PR description comprehensively relates to the changeset, detailing the three reliability fixes with clear explanations of the problems and solutions.
Title check✅ PassedThe title 'test(e2e): improve integration test reliability' is partially related to the changeset. While it accurately describes one aspect of the changes (improving test reliability through defensive cleanup), it does not highlight the main change, which is fixing e2e failures caused by a compromised-password check by introducing a stronger fake password generator.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@jacekradkojacekradko changed the title test(integration): use strong random passwords and harden afterAlltest(e2e): use strong random passwords and harden afterAllApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): use strong random passwords and harden afterAlltest(e2e): addressing new e2e failuresApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): addressing new e2e failurestest(e2e): use strong fake-user passwords and harden afterAll cleanupApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): use strong fake-user passwords and harden afterAll cleanuptest(e2e): fake-user passwords, defensive afterAll, and virtual clock for token-cache testsApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): fake-user passwords, defensive afterAll, and virtual clock for token-cache teststest(e2e): fake-user passwords, defensive afterAll, and trim timer-dependent token-cache testsApr 30, 2026
…ent token-cache tests
Three small E2E reliability fixes uncovered while investigating
consistent CI failures across multiple suites.
1. Strong random fake-user passwords. createFakeUser built passwords
as `${email}${randomHash}`, which FAPI's compromised-password check
rejected with `form_password_compromised` (HTTP 422). Replaced with
a `fakerPassword()` helper that emits a high-entropy base64url
string with a fixed `Aa1!` prefix to satisfy default Clerk password
complexity rules.
2. Defensive afterAll cleanup. When a suite's beforeAll timed out or
threw, afterAll crashed with a TypeError on un-assigned fakeUser /
fakeOrganization / network / fakeOAuth / fakeAPIKey, masking the
real failure. Optional-chained the cleanup calls in:
- integration/tests/components.test.ts
- integration/testUtils/machineAuthHelpers.ts (apiKey, m2m, oauth)
3. Drop timer-dependent token-cache assertions. Two MemoryTokenCache
cross-tab tests assumed JWT TTL = 60s and waited 50s of wall-clock
time for the proactive-refresh setTimeout to fire. The dev test
instance now issues 300s tokens, so the timer fires at ~283s and
the tests never reached it.
- Deleted `multi-tab scheduled refreshes are deduped to a single
request` from single-session.test.ts. The same broadcast-dedup
path is exercised by the existing line-49 test via
`getToken({ skipCache: true })`.
- Rewrote multi-session.test.ts:249 (now `cross-session token
refreshes do not deduplicate`) to manually trigger
`getToken({ skipCache: true })` on each tab. Different sessions
have different tokenIds, so BroadcastChannel does NOT deduplicate
across them — unique coverage the single-session test doesn't
provide.
Proactive-refresh timer scheduling math is best validated by unit
tests that mock setTimeout, not by real-time integration tests
against a shared dev instance.
Scoped to integration/ only, no published package affected — empty
changeset.
@jacekradko
jacekradkoforce-pushed the jacek/fix-e2e-compromised-password branch from 6eebdd2 to ef5dd73CompareApril 30, 2026 21:29
@jacekradkojacekradko changed the title test(e2e): fake-user passwords, defensive afterAll, and trim timer-dependent token-cache teststest(e2e): improve integration test reliabilityApr 30, 2026
@jacekradko
jacekradko merged commit 1f804dc into mainMay 1, 2026
132 of 136 checks passed
@jacekradko
jacekradko deleted the jacek/fix-e2e-compromised-password branch May 1, 2026 01:19
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

test(e2e): improve integration test reliability - #8422

Merged
jacekradko merged 2 commits into
mainfrom
jacek/fix-e2e-compromised-password
May 1, 2026
Merged

test(e2e): improve integration test reliability#8422
jacekradko merged 2 commits into
mainfrom
jacek/fix-e2e-compromised-password

Conversation

@jacekradko

@jacekradkojacekradko commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Summary

Three small E2E reliability fixes uncovered while investigating consistent CI failures across multiple suites.

1. Strong random fake-user passwords

createFakeUser built passwords as ${email}${randomHash} (e.g. 76557538ea+clerk_test@clerkcookie.com76557538ea). FAPI's compromised-password check rejects these with form_password_compromised (HTTP 422), which broke any sign-in flow that wasn't intentionally testing the compromised-password path. Replaced with a fakerPassword() helper that emits a high-entropy base64url string with a fixed Aa1! prefix to satisfy default Clerk complexity rules (upper, lower, digit, symbol).

2. Defensive afterAll cleanup

When a test suite's beforeAll timed out or threw (BAPI hiccup, dev server slow to come up, etc.), afterAll would crash with a TypeError on the un-assigned fakeUser / fakeOrganization / network / fakeOAuth / fakeAPIKey, masking the real failure. Optional-chain the cleanup calls in:

  • integration/tests/components.test.ts
  • integration/testUtils/machineAuthHelpers.ts (apiKey, m2m, oauth describes)

3. Drop timer-dependent token-cache assertions

Two MemoryTokenCache cross-tab tests assumed JWT TTL = 60s and waited 50s of wall-clock time for the proactive-refresh setTimeout to fire. The dev test instance now issues 300s tokens, so the refresh fires at ~283s and the tests never reached it.

The BroadcastChannel-based deduplication these tests were checking is already covered elsewhere; the proactive-refresh timer scheduling itself is best validated by unit tests that mock setTimeout, not by real-time integration tests.

  • Deleteintegration/tests/session-token-cache/single-session.test.ts "multi-tab scheduled refreshes are deduped to a single request". The same broadcast-dedup path is exercised by the existing line-49 test ("multi-tab token sharing works when clearing the cache") via getToken({ skipCache: true }).
  • Rewriteintegration/tests/session-token-cache/multi-session.test.ts:249 (now "cross-session token refreshes do not deduplicate") to manually trigger getToken({ skipCache: true }) on each tab. Different sessions have different tokenIds, so BroadcastChannel doesn't dedupe — each tab is expected to make its own request. Unique coverage the single-session test doesn't provide.

Scoped to integration/ only and doesn't affect any published package — empty changeset.

Test plan

  • genericcomponents-component-smoke — real beforeAll failure surfaces instead of TypeError: ... 'delete'
  • machinetests-with-invalid-M2M-tokens / local-verification — real ClerkAPIResponseError surfaces instead of TypeError: ... 'cleanup'
  • genericmulti-tab token sharing works when clearing the cache — still green (covers the broadcast-dedup path the deleted timer test was duplicating)
  • nextjscross-session token refreshes do not deduplicate — green; runs in seconds and asserts the cross-session non-dedup case
  • No regression in nextjs session-tasks-sign-in-reset-password (test still calls setPasswordCompromised on purpose)

@changeset-bot

changeset-botBot commented Apr 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 6cf9d6c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Apr 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 1, 2026 0:11am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 30, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8422

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8422

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8422

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8422

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8422

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8422

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8422

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8422

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8422

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8422

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8422

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8422

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8422

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8422

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8422

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8422

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8422

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8422

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8422

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8422

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8422

commit: 6cf9d6c

@coderabbitai

coderabbitaiBot commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

A fix for e2e test reliability is introduced by adding a new fakerPassword helper function that generates strong test passwords using cryptographic randomness and base64 encoding, ensuring compliance with password complexity requirements. The createFakeUser function is updated to use this helper instead of simple email concatenation. Additionally, test teardown logic across multiple test files is made more defensive by applying optional chaining to safely handle cases where test fixtures may be uninitialized or missing.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe PR description comprehensively relates to the changeset, detailing the three reliability fixes with clear explanations of the problems and solutions.
Title check✅ PassedThe title 'test(e2e): improve integration test reliability' is partially related to the changeset. While it accurately describes one aspect of the changes (improving test reliability through defensive cleanup), it does not highlight the main change, which is fixing e2e failures caused by a compromised-password check by introducing a stronger fake password generator.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@jacekradkojacekradko changed the title test(integration): use strong random passwords and harden afterAlltest(e2e): use strong random passwords and harden afterAllApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): use strong random passwords and harden afterAlltest(e2e): addressing new e2e failuresApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): addressing new e2e failurestest(e2e): use strong fake-user passwords and harden afterAll cleanupApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): use strong fake-user passwords and harden afterAll cleanuptest(e2e): fake-user passwords, defensive afterAll, and virtual clock for token-cache testsApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): fake-user passwords, defensive afterAll, and virtual clock for token-cache teststest(e2e): fake-user passwords, defensive afterAll, and trim timer-dependent token-cache testsApr 30, 2026
…ent token-cache tests
Three small E2E reliability fixes uncovered while investigating
consistent CI failures across multiple suites.
1. Strong random fake-user passwords. createFakeUser built passwords
as `${email}${randomHash}`, which FAPI's compromised-password check
rejected with `form_password_compromised` (HTTP 422). Replaced with
a `fakerPassword()` helper that emits a high-entropy base64url
string with a fixed `Aa1!` prefix to satisfy default Clerk password
complexity rules.
2. Defensive afterAll cleanup. When a suite's beforeAll timed out or
threw, afterAll crashed with a TypeError on un-assigned fakeUser /
fakeOrganization / network / fakeOAuth / fakeAPIKey, masking the
real failure. Optional-chained the cleanup calls in:
- integration/tests/components.test.ts
- integration/testUtils/machineAuthHelpers.ts (apiKey, m2m, oauth)
3. Drop timer-dependent token-cache assertions. Two MemoryTokenCache
cross-tab tests assumed JWT TTL = 60s and waited 50s of wall-clock
time for the proactive-refresh setTimeout to fire. The dev test
instance now issues 300s tokens, so the timer fires at ~283s and
the tests never reached it.
- Deleted `multi-tab scheduled refreshes are deduped to a single
request` from single-session.test.ts. The same broadcast-dedup
path is exercised by the existing line-49 test via
`getToken({ skipCache: true })`.
- Rewrote multi-session.test.ts:249 (now `cross-session token
refreshes do not deduplicate`) to manually trigger
`getToken({ skipCache: true })` on each tab. Different sessions
have different tokenIds, so BroadcastChannel does NOT deduplicate
across them — unique coverage the single-session test doesn't
provide.
Proactive-refresh timer scheduling math is best validated by unit
tests that mock setTimeout, not by real-time integration tests
against a shared dev instance.
Scoped to integration/ only, no published package affected — empty
changeset.
@jacekradko
jacekradkoforce-pushed the jacek/fix-e2e-compromised-password branch from 6eebdd2 to ef5dd73CompareApril 30, 2026 21:29
@jacekradkojacekradko changed the title test(e2e): fake-user passwords, defensive afterAll, and trim timer-dependent token-cache teststest(e2e): improve integration test reliabilityApr 30, 2026
@jacekradko
jacekradko merged commit 1f804dc into mainMay 1, 2026
132 of 136 checks passed
@jacekradko
jacekradko deleted the jacek/fix-e2e-compromised-password branch May 1, 2026 01:19
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

test(e2e): improve integration test reliability - #8422

Merged
jacekradko merged 2 commits into
mainfrom
jacek/fix-e2e-compromised-password
May 1, 2026
Merged

test(e2e): improve integration test reliability#8422
jacekradko merged 2 commits into
mainfrom
jacek/fix-e2e-compromised-password

Conversation

@jacekradko

@jacekradkojacekradko commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Summary

Three small E2E reliability fixes uncovered while investigating consistent CI failures across multiple suites.

1. Strong random fake-user passwords

createFakeUser built passwords as ${email}${randomHash} (e.g. 76557538ea+clerk_test@clerkcookie.com76557538ea). FAPI's compromised-password check rejects these with form_password_compromised (HTTP 422), which broke any sign-in flow that wasn't intentionally testing the compromised-password path. Replaced with a fakerPassword() helper that emits a high-entropy base64url string with a fixed Aa1! prefix to satisfy default Clerk complexity rules (upper, lower, digit, symbol).

2. Defensive afterAll cleanup

When a test suite's beforeAll timed out or threw (BAPI hiccup, dev server slow to come up, etc.), afterAll would crash with a TypeError on the un-assigned fakeUser / fakeOrganization / network / fakeOAuth / fakeAPIKey, masking the real failure. Optional-chain the cleanup calls in:

  • integration/tests/components.test.ts
  • integration/testUtils/machineAuthHelpers.ts (apiKey, m2m, oauth describes)

3. Drop timer-dependent token-cache assertions

Two MemoryTokenCache cross-tab tests assumed JWT TTL = 60s and waited 50s of wall-clock time for the proactive-refresh setTimeout to fire. The dev test instance now issues 300s tokens, so the refresh fires at ~283s and the tests never reached it.

The BroadcastChannel-based deduplication these tests were checking is already covered elsewhere; the proactive-refresh timer scheduling itself is best validated by unit tests that mock setTimeout, not by real-time integration tests.

  • Deleteintegration/tests/session-token-cache/single-session.test.ts "multi-tab scheduled refreshes are deduped to a single request". The same broadcast-dedup path is exercised by the existing line-49 test ("multi-tab token sharing works when clearing the cache") via getToken({ skipCache: true }).
  • Rewriteintegration/tests/session-token-cache/multi-session.test.ts:249 (now "cross-session token refreshes do not deduplicate") to manually trigger getToken({ skipCache: true }) on each tab. Different sessions have different tokenIds, so BroadcastChannel doesn't dedupe — each tab is expected to make its own request. Unique coverage the single-session test doesn't provide.

Scoped to integration/ only and doesn't affect any published package — empty changeset.

Test plan

  • genericcomponents-component-smoke — real beforeAll failure surfaces instead of TypeError: ... 'delete'
  • machinetests-with-invalid-M2M-tokens / local-verification — real ClerkAPIResponseError surfaces instead of TypeError: ... 'cleanup'
  • genericmulti-tab token sharing works when clearing the cache — still green (covers the broadcast-dedup path the deleted timer test was duplicating)
  • nextjscross-session token refreshes do not deduplicate — green; runs in seconds and asserts the cross-session non-dedup case
  • No regression in nextjs session-tasks-sign-in-reset-password (test still calls setPasswordCompromised on purpose)

@changeset-bot

changeset-botBot commented Apr 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 6cf9d6c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Apr 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 1, 2026 0:11am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 30, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8422

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8422

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8422

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8422

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8422

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8422

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8422

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8422

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8422

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8422

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8422

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8422

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8422

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8422

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8422

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8422

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8422

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8422

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8422

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8422

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8422

commit: 6cf9d6c

@coderabbitai

coderabbitaiBot commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

A fix for e2e test reliability is introduced by adding a new fakerPassword helper function that generates strong test passwords using cryptographic randomness and base64 encoding, ensuring compliance with password complexity requirements. The createFakeUser function is updated to use this helper instead of simple email concatenation. Additionally, test teardown logic across multiple test files is made more defensive by applying optional chaining to safely handle cases where test fixtures may be uninitialized or missing.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe PR description comprehensively relates to the changeset, detailing the three reliability fixes with clear explanations of the problems and solutions.
Title check✅ PassedThe title 'test(e2e): improve integration test reliability' is partially related to the changeset. While it accurately describes one aspect of the changes (improving test reliability through defensive cleanup), it does not highlight the main change, which is fixing e2e failures caused by a compromised-password check by introducing a stronger fake password generator.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@jacekradkojacekradko changed the title test(integration): use strong random passwords and harden afterAlltest(e2e): use strong random passwords and harden afterAllApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): use strong random passwords and harden afterAlltest(e2e): addressing new e2e failuresApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): addressing new e2e failurestest(e2e): use strong fake-user passwords and harden afterAll cleanupApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): use strong fake-user passwords and harden afterAll cleanuptest(e2e): fake-user passwords, defensive afterAll, and virtual clock for token-cache testsApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): fake-user passwords, defensive afterAll, and virtual clock for token-cache teststest(e2e): fake-user passwords, defensive afterAll, and trim timer-dependent token-cache testsApr 30, 2026
…ent token-cache tests
Three small E2E reliability fixes uncovered while investigating
consistent CI failures across multiple suites.
1. Strong random fake-user passwords. createFakeUser built passwords
as `${email}${randomHash}`, which FAPI's compromised-password check
rejected with `form_password_compromised` (HTTP 422). Replaced with
a `fakerPassword()` helper that emits a high-entropy base64url
string with a fixed `Aa1!` prefix to satisfy default Clerk password
complexity rules.
2. Defensive afterAll cleanup. When a suite's beforeAll timed out or
threw, afterAll crashed with a TypeError on un-assigned fakeUser /
fakeOrganization / network / fakeOAuth / fakeAPIKey, masking the
real failure. Optional-chained the cleanup calls in:
- integration/tests/components.test.ts
- integration/testUtils/machineAuthHelpers.ts (apiKey, m2m, oauth)
3. Drop timer-dependent token-cache assertions. Two MemoryTokenCache
cross-tab tests assumed JWT TTL = 60s and waited 50s of wall-clock
time for the proactive-refresh setTimeout to fire. The dev test
instance now issues 300s tokens, so the timer fires at ~283s and
the tests never reached it.
- Deleted `multi-tab scheduled refreshes are deduped to a single
request` from single-session.test.ts. The same broadcast-dedup
path is exercised by the existing line-49 test via
`getToken({ skipCache: true })`.
- Rewrote multi-session.test.ts:249 (now `cross-session token
refreshes do not deduplicate`) to manually trigger
`getToken({ skipCache: true })` on each tab. Different sessions
have different tokenIds, so BroadcastChannel does NOT deduplicate
across them — unique coverage the single-session test doesn't
provide.
Proactive-refresh timer scheduling math is best validated by unit
tests that mock setTimeout, not by real-time integration tests
against a shared dev instance.
Scoped to integration/ only, no published package affected — empty
changeset.
@jacekradko
jacekradkoforce-pushed the jacek/fix-e2e-compromised-password branch from 6eebdd2 to ef5dd73CompareApril 30, 2026 21:29
@jacekradkojacekradko changed the title test(e2e): fake-user passwords, defensive afterAll, and trim timer-dependent token-cache teststest(e2e): improve integration test reliabilityApr 30, 2026
@jacekradko
jacekradko merged commit 1f804dc into mainMay 1, 2026
132 of 136 checks passed
@jacekradko
jacekradko deleted the jacek/fix-e2e-compromised-password branch May 1, 2026 01:19
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

test(e2e): improve integration test reliability - #8422

Merged
jacekradko merged 2 commits into
mainfrom
jacek/fix-e2e-compromised-password
May 1, 2026
Merged

test(e2e): improve integration test reliability#8422
jacekradko merged 2 commits into
mainfrom
jacek/fix-e2e-compromised-password

Conversation

@jacekradko

@jacekradkojacekradko commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Summary

Three small E2E reliability fixes uncovered while investigating consistent CI failures across multiple suites.

1. Strong random fake-user passwords

createFakeUser built passwords as ${email}${randomHash} (e.g. 76557538ea+clerk_test@clerkcookie.com76557538ea). FAPI's compromised-password check rejects these with form_password_compromised (HTTP 422), which broke any sign-in flow that wasn't intentionally testing the compromised-password path. Replaced with a fakerPassword() helper that emits a high-entropy base64url string with a fixed Aa1! prefix to satisfy default Clerk complexity rules (upper, lower, digit, symbol).

2. Defensive afterAll cleanup

When a test suite's beforeAll timed out or threw (BAPI hiccup, dev server slow to come up, etc.), afterAll would crash with a TypeError on the un-assigned fakeUser / fakeOrganization / network / fakeOAuth / fakeAPIKey, masking the real failure. Optional-chain the cleanup calls in:

  • integration/tests/components.test.ts
  • integration/testUtils/machineAuthHelpers.ts (apiKey, m2m, oauth describes)

3. Drop timer-dependent token-cache assertions

Two MemoryTokenCache cross-tab tests assumed JWT TTL = 60s and waited 50s of wall-clock time for the proactive-refresh setTimeout to fire. The dev test instance now issues 300s tokens, so the refresh fires at ~283s and the tests never reached it.

The BroadcastChannel-based deduplication these tests were checking is already covered elsewhere; the proactive-refresh timer scheduling itself is best validated by unit tests that mock setTimeout, not by real-time integration tests.

  • Deleteintegration/tests/session-token-cache/single-session.test.ts "multi-tab scheduled refreshes are deduped to a single request". The same broadcast-dedup path is exercised by the existing line-49 test ("multi-tab token sharing works when clearing the cache") via getToken({ skipCache: true }).
  • Rewriteintegration/tests/session-token-cache/multi-session.test.ts:249 (now "cross-session token refreshes do not deduplicate") to manually trigger getToken({ skipCache: true }) on each tab. Different sessions have different tokenIds, so BroadcastChannel doesn't dedupe — each tab is expected to make its own request. Unique coverage the single-session test doesn't provide.

Scoped to integration/ only and doesn't affect any published package — empty changeset.

Test plan

  • genericcomponents-component-smoke — real beforeAll failure surfaces instead of TypeError: ... 'delete'
  • machinetests-with-invalid-M2M-tokens / local-verification — real ClerkAPIResponseError surfaces instead of TypeError: ... 'cleanup'
  • genericmulti-tab token sharing works when clearing the cache — still green (covers the broadcast-dedup path the deleted timer test was duplicating)
  • nextjscross-session token refreshes do not deduplicate — green; runs in seconds and asserts the cross-session non-dedup case
  • No regression in nextjs session-tasks-sign-in-reset-password (test still calls setPasswordCompromised on purpose)

@changeset-bot

changeset-botBot commented Apr 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 6cf9d6c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Apr 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 1, 2026 0:11am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 30, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8422

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8422

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8422

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8422

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8422

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8422

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8422

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8422

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8422

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8422

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8422

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8422

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8422

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8422

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8422

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8422

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8422

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8422

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8422

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8422

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8422

commit: 6cf9d6c

@coderabbitai

coderabbitaiBot commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

A fix for e2e test reliability is introduced by adding a new fakerPassword helper function that generates strong test passwords using cryptographic randomness and base64 encoding, ensuring compliance with password complexity requirements. The createFakeUser function is updated to use this helper instead of simple email concatenation. Additionally, test teardown logic across multiple test files is made more defensive by applying optional chaining to safely handle cases where test fixtures may be uninitialized or missing.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe PR description comprehensively relates to the changeset, detailing the three reliability fixes with clear explanations of the problems and solutions.
Title check✅ PassedThe title 'test(e2e): improve integration test reliability' is partially related to the changeset. While it accurately describes one aspect of the changes (improving test reliability through defensive cleanup), it does not highlight the main change, which is fixing e2e failures caused by a compromised-password check by introducing a stronger fake password generator.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@jacekradkojacekradko changed the title test(integration): use strong random passwords and harden afterAlltest(e2e): use strong random passwords and harden afterAllApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): use strong random passwords and harden afterAlltest(e2e): addressing new e2e failuresApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): addressing new e2e failurestest(e2e): use strong fake-user passwords and harden afterAll cleanupApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): use strong fake-user passwords and harden afterAll cleanuptest(e2e): fake-user passwords, defensive afterAll, and virtual clock for token-cache testsApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): fake-user passwords, defensive afterAll, and virtual clock for token-cache teststest(e2e): fake-user passwords, defensive afterAll, and trim timer-dependent token-cache testsApr 30, 2026
…ent token-cache tests
Three small E2E reliability fixes uncovered while investigating
consistent CI failures across multiple suites.
1. Strong random fake-user passwords. createFakeUser built passwords
as `${email}${randomHash}`, which FAPI's compromised-password check
rejected with `form_password_compromised` (HTTP 422). Replaced with
a `fakerPassword()` helper that emits a high-entropy base64url
string with a fixed `Aa1!` prefix to satisfy default Clerk password
complexity rules.
2. Defensive afterAll cleanup. When a suite's beforeAll timed out or
threw, afterAll crashed with a TypeError on un-assigned fakeUser /
fakeOrganization / network / fakeOAuth / fakeAPIKey, masking the
real failure. Optional-chained the cleanup calls in:
- integration/tests/components.test.ts
- integration/testUtils/machineAuthHelpers.ts (apiKey, m2m, oauth)
3. Drop timer-dependent token-cache assertions. Two MemoryTokenCache
cross-tab tests assumed JWT TTL = 60s and waited 50s of wall-clock
time for the proactive-refresh setTimeout to fire. The dev test
instance now issues 300s tokens, so the timer fires at ~283s and
the tests never reached it.
- Deleted `multi-tab scheduled refreshes are deduped to a single
request` from single-session.test.ts. The same broadcast-dedup
path is exercised by the existing line-49 test via
`getToken({ skipCache: true })`.
- Rewrote multi-session.test.ts:249 (now `cross-session token
refreshes do not deduplicate`) to manually trigger
`getToken({ skipCache: true })` on each tab. Different sessions
have different tokenIds, so BroadcastChannel does NOT deduplicate
across them — unique coverage the single-session test doesn't
provide.
Proactive-refresh timer scheduling math is best validated by unit
tests that mock setTimeout, not by real-time integration tests
against a shared dev instance.
Scoped to integration/ only, no published package affected — empty
changeset.
@jacekradko
jacekradkoforce-pushed the jacek/fix-e2e-compromised-password branch from 6eebdd2 to ef5dd73CompareApril 30, 2026 21:29
@jacekradkojacekradko changed the title test(e2e): fake-user passwords, defensive afterAll, and trim timer-dependent token-cache teststest(e2e): improve integration test reliabilityApr 30, 2026
@jacekradko
jacekradko merged commit 1f804dc into mainMay 1, 2026
132 of 136 checks passed
@jacekradko
jacekradko deleted the jacek/fix-e2e-compromised-password branch May 1, 2026 01:19
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

test(e2e): improve integration test reliability - #8422

Merged
jacekradko merged 2 commits into
mainfrom
jacek/fix-e2e-compromised-password
May 1, 2026
Merged

test(e2e): improve integration test reliability#8422
jacekradko merged 2 commits into
mainfrom
jacek/fix-e2e-compromised-password

Conversation

@jacekradko

@jacekradkojacekradko commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Summary

Three small E2E reliability fixes uncovered while investigating consistent CI failures across multiple suites.

1. Strong random fake-user passwords

createFakeUser built passwords as ${email}${randomHash} (e.g. 76557538ea+clerk_test@clerkcookie.com76557538ea). FAPI's compromised-password check rejects these with form_password_compromised (HTTP 422), which broke any sign-in flow that wasn't intentionally testing the compromised-password path. Replaced with a fakerPassword() helper that emits a high-entropy base64url string with a fixed Aa1! prefix to satisfy default Clerk complexity rules (upper, lower, digit, symbol).

2. Defensive afterAll cleanup

When a test suite's beforeAll timed out or threw (BAPI hiccup, dev server slow to come up, etc.), afterAll would crash with a TypeError on the un-assigned fakeUser / fakeOrganization / network / fakeOAuth / fakeAPIKey, masking the real failure. Optional-chain the cleanup calls in:

  • integration/tests/components.test.ts
  • integration/testUtils/machineAuthHelpers.ts (apiKey, m2m, oauth describes)

3. Drop timer-dependent token-cache assertions

Two MemoryTokenCache cross-tab tests assumed JWT TTL = 60s and waited 50s of wall-clock time for the proactive-refresh setTimeout to fire. The dev test instance now issues 300s tokens, so the refresh fires at ~283s and the tests never reached it.

The BroadcastChannel-based deduplication these tests were checking is already covered elsewhere; the proactive-refresh timer scheduling itself is best validated by unit tests that mock setTimeout, not by real-time integration tests.

  • Deleteintegration/tests/session-token-cache/single-session.test.ts "multi-tab scheduled refreshes are deduped to a single request". The same broadcast-dedup path is exercised by the existing line-49 test ("multi-tab token sharing works when clearing the cache") via getToken({ skipCache: true }).
  • Rewriteintegration/tests/session-token-cache/multi-session.test.ts:249 (now "cross-session token refreshes do not deduplicate") to manually trigger getToken({ skipCache: true }) on each tab. Different sessions have different tokenIds, so BroadcastChannel doesn't dedupe — each tab is expected to make its own request. Unique coverage the single-session test doesn't provide.

Scoped to integration/ only and doesn't affect any published package — empty changeset.

Test plan

  • genericcomponents-component-smoke — real beforeAll failure surfaces instead of TypeError: ... 'delete'
  • machinetests-with-invalid-M2M-tokens / local-verification — real ClerkAPIResponseError surfaces instead of TypeError: ... 'cleanup'
  • genericmulti-tab token sharing works when clearing the cache — still green (covers the broadcast-dedup path the deleted timer test was duplicating)
  • nextjscross-session token refreshes do not deduplicate — green; runs in seconds and asserts the cross-session non-dedup case
  • No regression in nextjs session-tasks-sign-in-reset-password (test still calls setPasswordCompromised on purpose)

@changeset-bot

changeset-botBot commented Apr 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 6cf9d6c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Apr 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 1, 2026 0:11am

Request Review

@pkg-pr-new

pkg-pr-newBot commented Apr 30, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8422

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8422

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8422

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8422

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8422

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8422

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8422

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8422

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8422

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8422

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8422

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8422

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8422

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8422

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8422

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8422

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8422

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8422

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8422

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8422

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8422

commit: 6cf9d6c

@coderabbitai

coderabbitaiBot commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

A fix for e2e test reliability is introduced by adding a new fakerPassword helper function that generates strong test passwords using cryptographic randomness and base64 encoding, ensuring compliance with password complexity requirements. The createFakeUser function is updated to use this helper instead of simple email concatenation. Additionally, test teardown logic across multiple test files is made more defensive by applying optional chaining to safely handle cases where test fixtures may be uninitialized or missing.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe PR description comprehensively relates to the changeset, detailing the three reliability fixes with clear explanations of the problems and solutions.
Title check✅ PassedThe title 'test(e2e): improve integration test reliability' is partially related to the changeset. While it accurately describes one aspect of the changes (improving test reliability through defensive cleanup), it does not highlight the main change, which is fixing e2e failures caused by a compromised-password check by introducing a stronger fake password generator.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@jacekradkojacekradko changed the title test(integration): use strong random passwords and harden afterAlltest(e2e): use strong random passwords and harden afterAllApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): use strong random passwords and harden afterAlltest(e2e): addressing new e2e failuresApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): addressing new e2e failurestest(e2e): use strong fake-user passwords and harden afterAll cleanupApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): use strong fake-user passwords and harden afterAll cleanuptest(e2e): fake-user passwords, defensive afterAll, and virtual clock for token-cache testsApr 30, 2026
@jacekradkojacekradko changed the title test(e2e): fake-user passwords, defensive afterAll, and virtual clock for token-cache teststest(e2e): fake-user passwords, defensive afterAll, and trim timer-dependent token-cache testsApr 30, 2026
…ent token-cache tests
Three small E2E reliability fixes uncovered while investigating
consistent CI failures across multiple suites.
1. Strong random fake-user passwords. createFakeUser built passwords
as `${email}${randomHash}`, which FAPI's compromised-password check
rejected with `form_password_compromised` (HTTP 422). Replaced with
a `fakerPassword()` helper that emits a high-entropy base64url
string with a fixed `Aa1!` prefix to satisfy default Clerk password
complexity rules.
2. Defensive afterAll cleanup. When a suite's beforeAll timed out or
threw, afterAll crashed with a TypeError on un-assigned fakeUser /
fakeOrganization / network / fakeOAuth / fakeAPIKey, masking the
real failure. Optional-chained the cleanup calls in:
- integration/tests/components.test.ts
- integration/testUtils/machineAuthHelpers.ts (apiKey, m2m, oauth)
3. Drop timer-dependent token-cache assertions. Two MemoryTokenCache
cross-tab tests assumed JWT TTL = 60s and waited 50s of wall-clock
time for the proactive-refresh setTimeout to fire. The dev test
instance now issues 300s tokens, so the timer fires at ~283s and
the tests never reached it.
- Deleted `multi-tab scheduled refreshes are deduped to a single
request` from single-session.test.ts. The same broadcast-dedup
path is exercised by the existing line-49 test via
`getToken({ skipCache: true })`.
- Rewrote multi-session.test.ts:249 (now `cross-session token
refreshes do not deduplicate`) to manually trigger
`getToken({ skipCache: true })` on each tab. Different sessions
have different tokenIds, so BroadcastChannel does NOT deduplicate
across them — unique coverage the single-session test doesn't
provide.
Proactive-refresh timer scheduling math is best validated by unit
tests that mock setTimeout, not by real-time integration tests
against a shared dev instance.
Scoped to integration/ only, no published package affected — empty
changeset.
@jacekradko
jacekradkoforce-pushed the jacek/fix-e2e-compromised-password branch from 6eebdd2 to ef5dd73CompareApril 30, 2026 21:29
@jacekradkojacekradko changed the title test(e2e): fake-user passwords, defensive afterAll, and trim timer-dependent token-cache teststest(e2e): improve integration test reliabilityApr 30, 2026
@jacekradko
jacekradko merged commit 1f804dc into mainMay 1, 2026
132 of 136 checks passed
@jacekradko
jacekradko deleted the jacek/fix-e2e-compromised-password branch May 1, 2026 01:19
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@wobsoriano