Skip to content

fix(expo): Fix expo-auth-session import leak and env var detection - #8607

Merged
wobsoriano merged 3 commits into
mainfrom
chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection
Jun 3, 2026
Merged

fix(expo): Fix expo-auth-session import leak and env var detection#8607
wobsoriano merged 3 commits into
mainfrom
chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection

Conversation

@chriscanin

@chriscaninchriscanin commented May 20, 2026

Copy link
Copy Markdown
Contributor

Summary

This PR fixes an optional-dependency leak in @clerk/expo's ClerkProvider.

Previously, ClerkProvider synchronously referenced expo-web-browser behind an isWeb() runtime check in order to call maybeCompleteAuthSession() for OAuth/SSO flows on web. In Expo/Metro, that pattern can still cause expo-web-browser to be picked up during native bundling even though it is only needed on web and is declared as an optional peer dependency.

This change moves that logic into a platform-specific helper:

  • maybeCompleteAuthSession.web.ts contains the web implementation
  • maybeCompleteAuthSession.ts is a native no-op

That keeps web behavior unchanged while ensuring native bundles no longer reference expo-web-browser through ClerkProvider.

Note: this is distinct from the useSSO / expo-auth-session issue fixed separately #8720. This PR only addresses the ClerkProviderexpo-web-browser leak.

`ClerkProvider` previously called `require('expo-web-browser')` synchronously
inside an `isWeb()` runtime gate. Metro's static analyzer resolves literal-string
`require()` calls regardless of runtime gates or try/catch, so production
bundling failed for native consumers who don't install `expo-web-browser` (an
optional peer dependency).
Splits the web-only `maybeCompleteAuthSession()` call into a platform-specific
helper. Metro/Expo's platform resolver picks `maybeCompleteAuthSession.web.ts`
for web bundles and the no-op `maybeCompleteAuthSession.ts` for native — so
native dist no longer references `expo-web-browser`.
Behavior is unchanged at runtime on both platforms; the fix is purely at bundle
time.
The "env var detection" half of MOBILE-402 was already resolved in #7655
(publishableKey made a required prop, env-var fallback removed). No further
change needed there.
MOBILE-402
@changeset-bot

changeset-botBot commented May 20, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: bbf9e1e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 3, 2026 8:43pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Jun 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8607

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8607

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8607

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8607

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8607

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8607

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8607

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8607

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8607

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8607

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8607

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8607

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8607

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8607

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8607

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8607

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8607

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8607

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8607

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8607

commit: bbf9e1e

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tested this locally 👍🏼

@github-actions

Copy link
Copy Markdown
Contributor

Break Check: no API changes detected across the tracked packages.

Last ran on bbf9e1e. Pushes that change no tracked declarations (no API surface change vs. base) are skipped and don't update this comment.

@coderabbitai

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR refactors the Expo package's OAuth/SSO completion logic to prevent Metro bundler from statically resolving the optional expo-web-browser peer during native builds. A new maybeCompleteAuthSession module with platform-specific implementations (native no-op and web-specific) replaces inline try/catch logic in ClerkProvider.tsx, eliminating native build failures when expo-web-browser is not installed.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Title check⚠️ WarningThe title mentions 'expo-auth-session import leak' but the PR primarily fixes the 'expo-web-browser' leak in ClerkProvider; 'expo-auth-session' is a separate issue handled elsewhere.Update the title to accurately reflect the main change: 'fix(expo): Prevent expo-web-browser from leaking into native bundles' or similar.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description check✅ PassedThe description clearly explains the optional-dependency leak issue, the solution with platform-specific helpers, and distinguishes this from the separate expo-auth-session issue.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/expo/src/provider/ClerkProvider.tsx (1)

379-381: ⚡ Quick win

Add test coverage for the platform-split maybeCompleteAuthSession.

This PR introduces a new platform-resolved module (native no-op vs. web require of expo-web-browser) but ships no tests. Given the bug being fixed (Metro statically resolving the optional peer on native), a regression here would be silent. Consider tests that assert: the web implementation invokes WebBrowser.maybeCompleteAuthSession() and swallows errors with a __DEV__ warning when the peer is missing, and that the native variant is a no-op that never references expo-web-browser.

Want me to draft the Vitest cases for both maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts?

As per coding guidelines: "If there are no tests added or modified as part of the PR, please suggest that tests be added to cover the changes."

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/provider/ClerkProvider.tsx` around lines 379 - 381, Add
unit tests covering the platform-split maybeCompleteAuthSession behavior: create
Vitest cases for maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts
that (1) on web mock expo-web-browser and assert maybeCompleteAuthSession()
calls WebBrowser.maybeCompleteAuthSession() and that when the peer is missing it
swallows the error and emits a __DEV__ warning, and (2) on native assert the
native maybeCompleteAuthSession implementation is a no-op and does not import or
reference expo-web-browser (i.e., calling it does not attempt to require
WebBrowser). Target the exported function maybeCompleteAuthSession to locate the
implementations.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/expo/src/provider/ClerkProvider.tsx`:
- Around line 379-381: Add unit tests covering the platform-split
maybeCompleteAuthSession behavior: create Vitest cases for
maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts that (1) on web
mock expo-web-browser and assert maybeCompleteAuthSession() calls
WebBrowser.maybeCompleteAuthSession() and that when the peer is missing it
swallows the error and emits a __DEV__ warning, and (2) on native assert the
native maybeCompleteAuthSession implementation is a no-op and does not import or
reference expo-web-browser (i.e., calling it does not attempt to require
WebBrowser). Target the exported function maybeCompleteAuthSession to locate the
implementations.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: a5705a5a-f1e8-4a53-bf20-3a1eb4b567dd

📥 Commits

Reviewing files that changed from the base of the PR and between 03e2bba and bbf9e1e.

📒 Files selected for processing (4)
  • .changeset/expo_avoid_web_browser_static_require.md
  • packages/expo/src/provider/ClerkProvider.tsx
  • packages/expo/src/provider/maybeCompleteAuthSession.ts
  • packages/expo/src/provider/maybeCompleteAuthSession.web.ts

@wobsoriano

Copy link
Copy Markdown
Member

!snapshot

@github-actions

Copy link
Copy Markdown
Contributor

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/astro3.3.4-snapshot.v20260603205452
@clerk/backend3.5.1-snapshot.v20260603205452
@clerk/chrome-extension3.1.33-snapshot.v20260603205452
@clerk/clerk-js6.14.1-snapshot.v20260603205452
@clerk/expo3.3.2-snapshot.v20260603205452
@clerk/expo-passkeys1.1.2-snapshot.v20260603205452
@clerk/express2.1.24-snapshot.v20260603205452
@clerk/fastify3.1.34-snapshot.v20260603205452
@clerk/hono0.1.34-snapshot.v20260603205452
@clerk/localizations4.7.2-snapshot.v20260603205452
@clerk/msw0.0.32-snapshot.v20260603205452
@clerk/nextjs7.4.4-snapshot.v20260603205452
@clerk/nuxt2.5.4-snapshot.v20260603205452
@clerk/react6.7.4-snapshot.v20260603205452
@clerk/react-router3.3.4-snapshot.v20260603205452
@clerk/shared4.15.1-snapshot.v20260603205452
@clerk/tanstack-react-start1.3.4-snapshot.v20260603205452
@clerk/testing2.0.36-snapshot.v20260603205452
@clerk/ui1.15.1-snapshot.v20260603205452
@clerk/upgrade2.0.4-snapshot.v20260603205452
@clerk/vue2.3.4-snapshot.v20260603205452

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/astro

npm i @clerk/astro@3.3.4-snapshot.v20260603205452 --save-exact

@clerk/backend

npm i @clerk/backend@3.5.1-snapshot.v20260603205452 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@3.1.33-snapshot.v20260603205452 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@6.14.1-snapshot.v20260603205452 --save-exact

@clerk/expo

npm i @clerk/expo@3.3.2-snapshot.v20260603205452 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@1.1.2-snapshot.v20260603205452 --save-exact

@clerk/express

npm i @clerk/express@2.1.24-snapshot.v20260603205452 --save-exact

@clerk/fastify

npm i @clerk/fastify@3.1.34-snapshot.v20260603205452 --save-exact

@clerk/hono

npm i @clerk/hono@0.1.34-snapshot.v20260603205452 --save-exact

@clerk/localizations

npm i @clerk/localizations@4.7.2-snapshot.v20260603205452 --save-exact

@clerk/msw

npm i @clerk/msw@0.0.32-snapshot.v20260603205452 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@7.4.4-snapshot.v20260603205452 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@2.5.4-snapshot.v20260603205452 --save-exact

@clerk/react

npm i @clerk/react@6.7.4-snapshot.v20260603205452 --save-exact

@clerk/react-router

npm i @clerk/react-router@3.3.4-snapshot.v20260603205452 --save-exact

@clerk/shared

npm i @clerk/shared@4.15.1-snapshot.v20260603205452 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@1.3.4-snapshot.v20260603205452 --save-exact

@clerk/testing

npm i @clerk/testing@2.0.36-snapshot.v20260603205452 --save-exact

@clerk/ui

npm i @clerk/ui@1.15.1-snapshot.v20260603205452 --save-exact

@clerk/upgrade

npm i @clerk/upgrade@2.0.4-snapshot.v20260603205452 --save-exact

@clerk/vue

npm i @clerk/vue@2.3.4-snapshot.v20260603205452 --save-exact

@wobsoriano
wobsoriano merged commit c0bfb9d into mainJun 3, 2026
75 of 80 checks passed
@wobsoriano
wobsoriano deleted the chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection branch June 3, 2026 21:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@chriscanin@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(expo): Fix expo-auth-session import leak and env var detection by chriscanin · Pull Request #8607 · clerk/javascript · GitHub
Skip to content

fix(expo): Fix expo-auth-session import leak and env var detection - #8607

Merged
wobsoriano merged 3 commits into
mainfrom
chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection
Jun 3, 2026
Merged

fix(expo): Fix expo-auth-session import leak and env var detection#8607
wobsoriano merged 3 commits into
mainfrom
chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection

Conversation

@chriscanin

@chriscaninchriscanin commented May 20, 2026

Copy link
Copy Markdown
Contributor

Summary

This PR fixes an optional-dependency leak in @clerk/expo's ClerkProvider.

Previously, ClerkProvider synchronously referenced expo-web-browser behind an isWeb() runtime check in order to call maybeCompleteAuthSession() for OAuth/SSO flows on web. In Expo/Metro, that pattern can still cause expo-web-browser to be picked up during native bundling even though it is only needed on web and is declared as an optional peer dependency.

This change moves that logic into a platform-specific helper:

  • maybeCompleteAuthSession.web.ts contains the web implementation
  • maybeCompleteAuthSession.ts is a native no-op

That keeps web behavior unchanged while ensuring native bundles no longer reference expo-web-browser through ClerkProvider.

Note: this is distinct from the useSSO / expo-auth-session issue fixed separately #8720. This PR only addresses the ClerkProviderexpo-web-browser leak.

`ClerkProvider` previously called `require('expo-web-browser')` synchronously
inside an `isWeb()` runtime gate. Metro's static analyzer resolves literal-string
`require()` calls regardless of runtime gates or try/catch, so production
bundling failed for native consumers who don't install `expo-web-browser` (an
optional peer dependency).
Splits the web-only `maybeCompleteAuthSession()` call into a platform-specific
helper. Metro/Expo's platform resolver picks `maybeCompleteAuthSession.web.ts`
for web bundles and the no-op `maybeCompleteAuthSession.ts` for native — so
native dist no longer references `expo-web-browser`.
Behavior is unchanged at runtime on both platforms; the fix is purely at bundle
time.
The "env var detection" half of MOBILE-402 was already resolved in #7655
(publishableKey made a required prop, env-var fallback removed). No further
change needed there.
MOBILE-402
@changeset-bot

changeset-botBot commented May 20, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: bbf9e1e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 3, 2026 8:43pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Jun 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8607

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8607

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8607

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8607

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8607

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8607

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8607

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8607

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8607

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8607

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8607

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8607

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8607

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8607

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8607

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8607

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8607

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8607

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8607

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8607

commit: bbf9e1e

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tested this locally 👍🏼

@github-actions

Copy link
Copy Markdown
Contributor

Break Check: no API changes detected across the tracked packages.

Last ran on bbf9e1e. Pushes that change no tracked declarations (no API surface change vs. base) are skipped and don't update this comment.

@coderabbitai

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR refactors the Expo package's OAuth/SSO completion logic to prevent Metro bundler from statically resolving the optional expo-web-browser peer during native builds. A new maybeCompleteAuthSession module with platform-specific implementations (native no-op and web-specific) replaces inline try/catch logic in ClerkProvider.tsx, eliminating native build failures when expo-web-browser is not installed.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Title check⚠️ WarningThe title mentions 'expo-auth-session import leak' but the PR primarily fixes the 'expo-web-browser' leak in ClerkProvider; 'expo-auth-session' is a separate issue handled elsewhere.Update the title to accurately reflect the main change: 'fix(expo): Prevent expo-web-browser from leaking into native bundles' or similar.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description check✅ PassedThe description clearly explains the optional-dependency leak issue, the solution with platform-specific helpers, and distinguishes this from the separate expo-auth-session issue.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/expo/src/provider/ClerkProvider.tsx (1)

379-381: ⚡ Quick win

Add test coverage for the platform-split maybeCompleteAuthSession.

This PR introduces a new platform-resolved module (native no-op vs. web require of expo-web-browser) but ships no tests. Given the bug being fixed (Metro statically resolving the optional peer on native), a regression here would be silent. Consider tests that assert: the web implementation invokes WebBrowser.maybeCompleteAuthSession() and swallows errors with a __DEV__ warning when the peer is missing, and that the native variant is a no-op that never references expo-web-browser.

Want me to draft the Vitest cases for both maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts?

As per coding guidelines: "If there are no tests added or modified as part of the PR, please suggest that tests be added to cover the changes."

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/provider/ClerkProvider.tsx` around lines 379 - 381, Add
unit tests covering the platform-split maybeCompleteAuthSession behavior: create
Vitest cases for maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts
that (1) on web mock expo-web-browser and assert maybeCompleteAuthSession()
calls WebBrowser.maybeCompleteAuthSession() and that when the peer is missing it
swallows the error and emits a __DEV__ warning, and (2) on native assert the
native maybeCompleteAuthSession implementation is a no-op and does not import or
reference expo-web-browser (i.e., calling it does not attempt to require
WebBrowser). Target the exported function maybeCompleteAuthSession to locate the
implementations.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/expo/src/provider/ClerkProvider.tsx`:
- Around line 379-381: Add unit tests covering the platform-split
maybeCompleteAuthSession behavior: create Vitest cases for
maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts that (1) on web
mock expo-web-browser and assert maybeCompleteAuthSession() calls
WebBrowser.maybeCompleteAuthSession() and that when the peer is missing it
swallows the error and emits a __DEV__ warning, and (2) on native assert the
native maybeCompleteAuthSession implementation is a no-op and does not import or
reference expo-web-browser (i.e., calling it does not attempt to require
WebBrowser). Target the exported function maybeCompleteAuthSession to locate the
implementations.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: a5705a5a-f1e8-4a53-bf20-3a1eb4b567dd

📥 Commits

Reviewing files that changed from the base of the PR and between 03e2bba and bbf9e1e.

📒 Files selected for processing (4)
  • .changeset/expo_avoid_web_browser_static_require.md
  • packages/expo/src/provider/ClerkProvider.tsx
  • packages/expo/src/provider/maybeCompleteAuthSession.ts
  • packages/expo/src/provider/maybeCompleteAuthSession.web.ts

@wobsoriano

Copy link
Copy Markdown
Member

!snapshot

@github-actions

Copy link
Copy Markdown
Contributor

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/astro3.3.4-snapshot.v20260603205452
@clerk/backend3.5.1-snapshot.v20260603205452
@clerk/chrome-extension3.1.33-snapshot.v20260603205452
@clerk/clerk-js6.14.1-snapshot.v20260603205452
@clerk/expo3.3.2-snapshot.v20260603205452
@clerk/expo-passkeys1.1.2-snapshot.v20260603205452
@clerk/express2.1.24-snapshot.v20260603205452
@clerk/fastify3.1.34-snapshot.v20260603205452
@clerk/hono0.1.34-snapshot.v20260603205452
@clerk/localizations4.7.2-snapshot.v20260603205452
@clerk/msw0.0.32-snapshot.v20260603205452
@clerk/nextjs7.4.4-snapshot.v20260603205452
@clerk/nuxt2.5.4-snapshot.v20260603205452
@clerk/react6.7.4-snapshot.v20260603205452
@clerk/react-router3.3.4-snapshot.v20260603205452
@clerk/shared4.15.1-snapshot.v20260603205452
@clerk/tanstack-react-start1.3.4-snapshot.v20260603205452
@clerk/testing2.0.36-snapshot.v20260603205452
@clerk/ui1.15.1-snapshot.v20260603205452
@clerk/upgrade2.0.4-snapshot.v20260603205452
@clerk/vue2.3.4-snapshot.v20260603205452

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/astro

npm i @clerk/astro@3.3.4-snapshot.v20260603205452 --save-exact

@clerk/backend

npm i @clerk/backend@3.5.1-snapshot.v20260603205452 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@3.1.33-snapshot.v20260603205452 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@6.14.1-snapshot.v20260603205452 --save-exact

@clerk/expo

npm i @clerk/expo@3.3.2-snapshot.v20260603205452 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@1.1.2-snapshot.v20260603205452 --save-exact

@clerk/express

npm i @clerk/express@2.1.24-snapshot.v20260603205452 --save-exact

@clerk/fastify

npm i @clerk/fastify@3.1.34-snapshot.v20260603205452 --save-exact

@clerk/hono

npm i @clerk/hono@0.1.34-snapshot.v20260603205452 --save-exact

@clerk/localizations

npm i @clerk/localizations@4.7.2-snapshot.v20260603205452 --save-exact

@clerk/msw

npm i @clerk/msw@0.0.32-snapshot.v20260603205452 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@7.4.4-snapshot.v20260603205452 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@2.5.4-snapshot.v20260603205452 --save-exact

@clerk/react

npm i @clerk/react@6.7.4-snapshot.v20260603205452 --save-exact

@clerk/react-router

npm i @clerk/react-router@3.3.4-snapshot.v20260603205452 --save-exact

@clerk/shared

npm i @clerk/shared@4.15.1-snapshot.v20260603205452 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@1.3.4-snapshot.v20260603205452 --save-exact

@clerk/testing

npm i @clerk/testing@2.0.36-snapshot.v20260603205452 --save-exact

@clerk/ui

npm i @clerk/ui@1.15.1-snapshot.v20260603205452 --save-exact

@clerk/upgrade

npm i @clerk/upgrade@2.0.4-snapshot.v20260603205452 --save-exact

@clerk/vue

npm i @clerk/vue@2.3.4-snapshot.v20260603205452 --save-exact

@wobsoriano
wobsoriano merged commit c0bfb9d into mainJun 3, 2026
75 of 80 checks passed
@wobsoriano
wobsoriano deleted the chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection branch June 3, 2026 21:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@chriscanin@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(expo): Fix expo-auth-session import leak and env var detection by chriscanin · Pull Request #8607 · clerk/javascript · GitHub
Skip to content

fix(expo): Fix expo-auth-session import leak and env var detection - #8607

Merged
wobsoriano merged 3 commits into
mainfrom
chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection
Jun 3, 2026
Merged

fix(expo): Fix expo-auth-session import leak and env var detection#8607
wobsoriano merged 3 commits into
mainfrom
chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection

Conversation

@chriscanin

@chriscaninchriscanin commented May 20, 2026

Copy link
Copy Markdown
Contributor

Summary

This PR fixes an optional-dependency leak in @clerk/expo's ClerkProvider.

Previously, ClerkProvider synchronously referenced expo-web-browser behind an isWeb() runtime check in order to call maybeCompleteAuthSession() for OAuth/SSO flows on web. In Expo/Metro, that pattern can still cause expo-web-browser to be picked up during native bundling even though it is only needed on web and is declared as an optional peer dependency.

This change moves that logic into a platform-specific helper:

  • maybeCompleteAuthSession.web.ts contains the web implementation
  • maybeCompleteAuthSession.ts is a native no-op

That keeps web behavior unchanged while ensuring native bundles no longer reference expo-web-browser through ClerkProvider.

Note: this is distinct from the useSSO / expo-auth-session issue fixed separately #8720. This PR only addresses the ClerkProviderexpo-web-browser leak.

`ClerkProvider` previously called `require('expo-web-browser')` synchronously
inside an `isWeb()` runtime gate. Metro's static analyzer resolves literal-string
`require()` calls regardless of runtime gates or try/catch, so production
bundling failed for native consumers who don't install `expo-web-browser` (an
optional peer dependency).
Splits the web-only `maybeCompleteAuthSession()` call into a platform-specific
helper. Metro/Expo's platform resolver picks `maybeCompleteAuthSession.web.ts`
for web bundles and the no-op `maybeCompleteAuthSession.ts` for native — so
native dist no longer references `expo-web-browser`.
Behavior is unchanged at runtime on both platforms; the fix is purely at bundle
time.
The "env var detection" half of MOBILE-402 was already resolved in #7655
(publishableKey made a required prop, env-var fallback removed). No further
change needed there.
MOBILE-402
@changeset-bot

changeset-botBot commented May 20, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: bbf9e1e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 3, 2026 8:43pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Jun 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8607

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8607

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8607

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8607

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8607

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8607

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8607

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8607

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8607

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8607

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8607

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8607

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8607

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8607

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8607

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8607

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8607

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8607

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8607

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8607

commit: bbf9e1e

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tested this locally 👍🏼

@github-actions

Copy link
Copy Markdown
Contributor

Break Check: no API changes detected across the tracked packages.

Last ran on bbf9e1e. Pushes that change no tracked declarations (no API surface change vs. base) are skipped and don't update this comment.

@coderabbitai

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR refactors the Expo package's OAuth/SSO completion logic to prevent Metro bundler from statically resolving the optional expo-web-browser peer during native builds. A new maybeCompleteAuthSession module with platform-specific implementations (native no-op and web-specific) replaces inline try/catch logic in ClerkProvider.tsx, eliminating native build failures when expo-web-browser is not installed.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Title check⚠️ WarningThe title mentions 'expo-auth-session import leak' but the PR primarily fixes the 'expo-web-browser' leak in ClerkProvider; 'expo-auth-session' is a separate issue handled elsewhere.Update the title to accurately reflect the main change: 'fix(expo): Prevent expo-web-browser from leaking into native bundles' or similar.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description check✅ PassedThe description clearly explains the optional-dependency leak issue, the solution with platform-specific helpers, and distinguishes this from the separate expo-auth-session issue.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/expo/src/provider/ClerkProvider.tsx (1)

379-381: ⚡ Quick win

Add test coverage for the platform-split maybeCompleteAuthSession.

This PR introduces a new platform-resolved module (native no-op vs. web require of expo-web-browser) but ships no tests. Given the bug being fixed (Metro statically resolving the optional peer on native), a regression here would be silent. Consider tests that assert: the web implementation invokes WebBrowser.maybeCompleteAuthSession() and swallows errors with a __DEV__ warning when the peer is missing, and that the native variant is a no-op that never references expo-web-browser.

Want me to draft the Vitest cases for both maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts?

As per coding guidelines: "If there are no tests added or modified as part of the PR, please suggest that tests be added to cover the changes."

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/provider/ClerkProvider.tsx` around lines 379 - 381, Add
unit tests covering the platform-split maybeCompleteAuthSession behavior: create
Vitest cases for maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts
that (1) on web mock expo-web-browser and assert maybeCompleteAuthSession()
calls WebBrowser.maybeCompleteAuthSession() and that when the peer is missing it
swallows the error and emits a __DEV__ warning, and (2) on native assert the
native maybeCompleteAuthSession implementation is a no-op and does not import or
reference expo-web-browser (i.e., calling it does not attempt to require
WebBrowser). Target the exported function maybeCompleteAuthSession to locate the
implementations.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/expo/src/provider/ClerkProvider.tsx`:
- Around line 379-381: Add unit tests covering the platform-split
maybeCompleteAuthSession behavior: create Vitest cases for
maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts that (1) on web
mock expo-web-browser and assert maybeCompleteAuthSession() calls
WebBrowser.maybeCompleteAuthSession() and that when the peer is missing it
swallows the error and emits a __DEV__ warning, and (2) on native assert the
native maybeCompleteAuthSession implementation is a no-op and does not import or
reference expo-web-browser (i.e., calling it does not attempt to require
WebBrowser). Target the exported function maybeCompleteAuthSession to locate the
implementations.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: a5705a5a-f1e8-4a53-bf20-3a1eb4b567dd

📥 Commits

Reviewing files that changed from the base of the PR and between 03e2bba and bbf9e1e.

📒 Files selected for processing (4)
  • .changeset/expo_avoid_web_browser_static_require.md
  • packages/expo/src/provider/ClerkProvider.tsx
  • packages/expo/src/provider/maybeCompleteAuthSession.ts
  • packages/expo/src/provider/maybeCompleteAuthSession.web.ts

@wobsoriano

Copy link
Copy Markdown
Member

!snapshot

@github-actions

Copy link
Copy Markdown
Contributor

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/astro3.3.4-snapshot.v20260603205452
@clerk/backend3.5.1-snapshot.v20260603205452
@clerk/chrome-extension3.1.33-snapshot.v20260603205452
@clerk/clerk-js6.14.1-snapshot.v20260603205452
@clerk/expo3.3.2-snapshot.v20260603205452
@clerk/expo-passkeys1.1.2-snapshot.v20260603205452
@clerk/express2.1.24-snapshot.v20260603205452
@clerk/fastify3.1.34-snapshot.v20260603205452
@clerk/hono0.1.34-snapshot.v20260603205452
@clerk/localizations4.7.2-snapshot.v20260603205452
@clerk/msw0.0.32-snapshot.v20260603205452
@clerk/nextjs7.4.4-snapshot.v20260603205452
@clerk/nuxt2.5.4-snapshot.v20260603205452
@clerk/react6.7.4-snapshot.v20260603205452
@clerk/react-router3.3.4-snapshot.v20260603205452
@clerk/shared4.15.1-snapshot.v20260603205452
@clerk/tanstack-react-start1.3.4-snapshot.v20260603205452
@clerk/testing2.0.36-snapshot.v20260603205452
@clerk/ui1.15.1-snapshot.v20260603205452
@clerk/upgrade2.0.4-snapshot.v20260603205452
@clerk/vue2.3.4-snapshot.v20260603205452

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/astro

npm i @clerk/astro@3.3.4-snapshot.v20260603205452 --save-exact

@clerk/backend

npm i @clerk/backend@3.5.1-snapshot.v20260603205452 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@3.1.33-snapshot.v20260603205452 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@6.14.1-snapshot.v20260603205452 --save-exact

@clerk/expo

npm i @clerk/expo@3.3.2-snapshot.v20260603205452 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@1.1.2-snapshot.v20260603205452 --save-exact

@clerk/express

npm i @clerk/express@2.1.24-snapshot.v20260603205452 --save-exact

@clerk/fastify

npm i @clerk/fastify@3.1.34-snapshot.v20260603205452 --save-exact

@clerk/hono

npm i @clerk/hono@0.1.34-snapshot.v20260603205452 --save-exact

@clerk/localizations

npm i @clerk/localizations@4.7.2-snapshot.v20260603205452 --save-exact

@clerk/msw

npm i @clerk/msw@0.0.32-snapshot.v20260603205452 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@7.4.4-snapshot.v20260603205452 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@2.5.4-snapshot.v20260603205452 --save-exact

@clerk/react

npm i @clerk/react@6.7.4-snapshot.v20260603205452 --save-exact

@clerk/react-router

npm i @clerk/react-router@3.3.4-snapshot.v20260603205452 --save-exact

@clerk/shared

npm i @clerk/shared@4.15.1-snapshot.v20260603205452 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@1.3.4-snapshot.v20260603205452 --save-exact

@clerk/testing

npm i @clerk/testing@2.0.36-snapshot.v20260603205452 --save-exact

@clerk/ui

npm i @clerk/ui@1.15.1-snapshot.v20260603205452 --save-exact

@clerk/upgrade

npm i @clerk/upgrade@2.0.4-snapshot.v20260603205452 --save-exact

@clerk/vue

npm i @clerk/vue@2.3.4-snapshot.v20260603205452 --save-exact

@wobsoriano
wobsoriano merged commit c0bfb9d into mainJun 3, 2026
75 of 80 checks passed
@wobsoriano
wobsoriano deleted the chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection branch June 3, 2026 21:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@chriscanin@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(expo): Fix expo-auth-session import leak and env var detection by chriscanin · Pull Request #8607 · clerk/javascript · GitHub
Skip to content

fix(expo): Fix expo-auth-session import leak and env var detection - #8607

Merged
wobsoriano merged 3 commits into
mainfrom
chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection
Jun 3, 2026
Merged

fix(expo): Fix expo-auth-session import leak and env var detection#8607
wobsoriano merged 3 commits into
mainfrom
chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection

Conversation

@chriscanin

@chriscaninchriscanin commented May 20, 2026

Copy link
Copy Markdown
Contributor

Summary

This PR fixes an optional-dependency leak in @clerk/expo's ClerkProvider.

Previously, ClerkProvider synchronously referenced expo-web-browser behind an isWeb() runtime check in order to call maybeCompleteAuthSession() for OAuth/SSO flows on web. In Expo/Metro, that pattern can still cause expo-web-browser to be picked up during native bundling even though it is only needed on web and is declared as an optional peer dependency.

This change moves that logic into a platform-specific helper:

  • maybeCompleteAuthSession.web.ts contains the web implementation
  • maybeCompleteAuthSession.ts is a native no-op

That keeps web behavior unchanged while ensuring native bundles no longer reference expo-web-browser through ClerkProvider.

Note: this is distinct from the useSSO / expo-auth-session issue fixed separately #8720. This PR only addresses the ClerkProviderexpo-web-browser leak.

`ClerkProvider` previously called `require('expo-web-browser')` synchronously
inside an `isWeb()` runtime gate. Metro's static analyzer resolves literal-string
`require()` calls regardless of runtime gates or try/catch, so production
bundling failed for native consumers who don't install `expo-web-browser` (an
optional peer dependency).
Splits the web-only `maybeCompleteAuthSession()` call into a platform-specific
helper. Metro/Expo's platform resolver picks `maybeCompleteAuthSession.web.ts`
for web bundles and the no-op `maybeCompleteAuthSession.ts` for native — so
native dist no longer references `expo-web-browser`.
Behavior is unchanged at runtime on both platforms; the fix is purely at bundle
time.
The "env var detection" half of MOBILE-402 was already resolved in #7655
(publishableKey made a required prop, env-var fallback removed). No further
change needed there.
MOBILE-402
@changeset-bot

changeset-botBot commented May 20, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: bbf9e1e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 3, 2026 8:43pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Jun 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8607

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8607

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8607

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8607

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8607

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8607

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8607

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8607

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8607

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8607

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8607

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8607

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8607

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8607

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8607

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8607

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8607

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8607

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8607

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8607

commit: bbf9e1e

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tested this locally 👍🏼

@github-actions

Copy link
Copy Markdown
Contributor

Break Check: no API changes detected across the tracked packages.

Last ran on bbf9e1e. Pushes that change no tracked declarations (no API surface change vs. base) are skipped and don't update this comment.

@coderabbitai

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR refactors the Expo package's OAuth/SSO completion logic to prevent Metro bundler from statically resolving the optional expo-web-browser peer during native builds. A new maybeCompleteAuthSession module with platform-specific implementations (native no-op and web-specific) replaces inline try/catch logic in ClerkProvider.tsx, eliminating native build failures when expo-web-browser is not installed.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Title check⚠️ WarningThe title mentions 'expo-auth-session import leak' but the PR primarily fixes the 'expo-web-browser' leak in ClerkProvider; 'expo-auth-session' is a separate issue handled elsewhere.Update the title to accurately reflect the main change: 'fix(expo): Prevent expo-web-browser from leaking into native bundles' or similar.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description check✅ PassedThe description clearly explains the optional-dependency leak issue, the solution with platform-specific helpers, and distinguishes this from the separate expo-auth-session issue.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/expo/src/provider/ClerkProvider.tsx (1)

379-381: ⚡ Quick win

Add test coverage for the platform-split maybeCompleteAuthSession.

This PR introduces a new platform-resolved module (native no-op vs. web require of expo-web-browser) but ships no tests. Given the bug being fixed (Metro statically resolving the optional peer on native), a regression here would be silent. Consider tests that assert: the web implementation invokes WebBrowser.maybeCompleteAuthSession() and swallows errors with a __DEV__ warning when the peer is missing, and that the native variant is a no-op that never references expo-web-browser.

Want me to draft the Vitest cases for both maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts?

As per coding guidelines: "If there are no tests added or modified as part of the PR, please suggest that tests be added to cover the changes."

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/provider/ClerkProvider.tsx` around lines 379 - 381, Add
unit tests covering the platform-split maybeCompleteAuthSession behavior: create
Vitest cases for maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts
that (1) on web mock expo-web-browser and assert maybeCompleteAuthSession()
calls WebBrowser.maybeCompleteAuthSession() and that when the peer is missing it
swallows the error and emits a __DEV__ warning, and (2) on native assert the
native maybeCompleteAuthSession implementation is a no-op and does not import or
reference expo-web-browser (i.e., calling it does not attempt to require
WebBrowser). Target the exported function maybeCompleteAuthSession to locate the
implementations.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/expo/src/provider/ClerkProvider.tsx`:
- Around line 379-381: Add unit tests covering the platform-split
maybeCompleteAuthSession behavior: create Vitest cases for
maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts that (1) on web
mock expo-web-browser and assert maybeCompleteAuthSession() calls
WebBrowser.maybeCompleteAuthSession() and that when the peer is missing it
swallows the error and emits a __DEV__ warning, and (2) on native assert the
native maybeCompleteAuthSession implementation is a no-op and does not import or
reference expo-web-browser (i.e., calling it does not attempt to require
WebBrowser). Target the exported function maybeCompleteAuthSession to locate the
implementations.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: a5705a5a-f1e8-4a53-bf20-3a1eb4b567dd

📥 Commits

Reviewing files that changed from the base of the PR and between 03e2bba and bbf9e1e.

📒 Files selected for processing (4)
  • .changeset/expo_avoid_web_browser_static_require.md
  • packages/expo/src/provider/ClerkProvider.tsx
  • packages/expo/src/provider/maybeCompleteAuthSession.ts
  • packages/expo/src/provider/maybeCompleteAuthSession.web.ts

@wobsoriano

Copy link
Copy Markdown
Member

!snapshot

@github-actions

Copy link
Copy Markdown
Contributor

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/astro3.3.4-snapshot.v20260603205452
@clerk/backend3.5.1-snapshot.v20260603205452
@clerk/chrome-extension3.1.33-snapshot.v20260603205452
@clerk/clerk-js6.14.1-snapshot.v20260603205452
@clerk/expo3.3.2-snapshot.v20260603205452
@clerk/expo-passkeys1.1.2-snapshot.v20260603205452
@clerk/express2.1.24-snapshot.v20260603205452
@clerk/fastify3.1.34-snapshot.v20260603205452
@clerk/hono0.1.34-snapshot.v20260603205452
@clerk/localizations4.7.2-snapshot.v20260603205452
@clerk/msw0.0.32-snapshot.v20260603205452
@clerk/nextjs7.4.4-snapshot.v20260603205452
@clerk/nuxt2.5.4-snapshot.v20260603205452
@clerk/react6.7.4-snapshot.v20260603205452
@clerk/react-router3.3.4-snapshot.v20260603205452
@clerk/shared4.15.1-snapshot.v20260603205452
@clerk/tanstack-react-start1.3.4-snapshot.v20260603205452
@clerk/testing2.0.36-snapshot.v20260603205452
@clerk/ui1.15.1-snapshot.v20260603205452
@clerk/upgrade2.0.4-snapshot.v20260603205452
@clerk/vue2.3.4-snapshot.v20260603205452

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/astro

npm i @clerk/astro@3.3.4-snapshot.v20260603205452 --save-exact

@clerk/backend

npm i @clerk/backend@3.5.1-snapshot.v20260603205452 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@3.1.33-snapshot.v20260603205452 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@6.14.1-snapshot.v20260603205452 --save-exact

@clerk/expo

npm i @clerk/expo@3.3.2-snapshot.v20260603205452 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@1.1.2-snapshot.v20260603205452 --save-exact

@clerk/express

npm i @clerk/express@2.1.24-snapshot.v20260603205452 --save-exact

@clerk/fastify

npm i @clerk/fastify@3.1.34-snapshot.v20260603205452 --save-exact

@clerk/hono

npm i @clerk/hono@0.1.34-snapshot.v20260603205452 --save-exact

@clerk/localizations

npm i @clerk/localizations@4.7.2-snapshot.v20260603205452 --save-exact

@clerk/msw

npm i @clerk/msw@0.0.32-snapshot.v20260603205452 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@7.4.4-snapshot.v20260603205452 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@2.5.4-snapshot.v20260603205452 --save-exact

@clerk/react

npm i @clerk/react@6.7.4-snapshot.v20260603205452 --save-exact

@clerk/react-router

npm i @clerk/react-router@3.3.4-snapshot.v20260603205452 --save-exact

@clerk/shared

npm i @clerk/shared@4.15.1-snapshot.v20260603205452 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@1.3.4-snapshot.v20260603205452 --save-exact

@clerk/testing

npm i @clerk/testing@2.0.36-snapshot.v20260603205452 --save-exact

@clerk/ui

npm i @clerk/ui@1.15.1-snapshot.v20260603205452 --save-exact

@clerk/upgrade

npm i @clerk/upgrade@2.0.4-snapshot.v20260603205452 --save-exact

@clerk/vue

npm i @clerk/vue@2.3.4-snapshot.v20260603205452 --save-exact

@wobsoriano
wobsoriano merged commit c0bfb9d into mainJun 3, 2026
75 of 80 checks passed
@wobsoriano
wobsoriano deleted the chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection branch June 3, 2026 21:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@chriscanin@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(expo): Fix expo-auth-session import leak and env var detection by chriscanin · Pull Request #8607 · clerk/javascript · GitHub
Skip to content

fix(expo): Fix expo-auth-session import leak and env var detection - #8607

Merged
wobsoriano merged 3 commits into
mainfrom
chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection
Jun 3, 2026
Merged

fix(expo): Fix expo-auth-session import leak and env var detection#8607
wobsoriano merged 3 commits into
mainfrom
chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection

Conversation

@chriscanin

@chriscaninchriscanin commented May 20, 2026

Copy link
Copy Markdown
Contributor

Summary

This PR fixes an optional-dependency leak in @clerk/expo's ClerkProvider.

Previously, ClerkProvider synchronously referenced expo-web-browser behind an isWeb() runtime check in order to call maybeCompleteAuthSession() for OAuth/SSO flows on web. In Expo/Metro, that pattern can still cause expo-web-browser to be picked up during native bundling even though it is only needed on web and is declared as an optional peer dependency.

This change moves that logic into a platform-specific helper:

  • maybeCompleteAuthSession.web.ts contains the web implementation
  • maybeCompleteAuthSession.ts is a native no-op

That keeps web behavior unchanged while ensuring native bundles no longer reference expo-web-browser through ClerkProvider.

Note: this is distinct from the useSSO / expo-auth-session issue fixed separately #8720. This PR only addresses the ClerkProviderexpo-web-browser leak.

`ClerkProvider` previously called `require('expo-web-browser')` synchronously
inside an `isWeb()` runtime gate. Metro's static analyzer resolves literal-string
`require()` calls regardless of runtime gates or try/catch, so production
bundling failed for native consumers who don't install `expo-web-browser` (an
optional peer dependency).
Splits the web-only `maybeCompleteAuthSession()` call into a platform-specific
helper. Metro/Expo's platform resolver picks `maybeCompleteAuthSession.web.ts`
for web bundles and the no-op `maybeCompleteAuthSession.ts` for native — so
native dist no longer references `expo-web-browser`.
Behavior is unchanged at runtime on both platforms; the fix is purely at bundle
time.
The "env var detection" half of MOBILE-402 was already resolved in #7655
(publishableKey made a required prop, env-var fallback removed). No further
change needed there.
MOBILE-402
@changeset-bot

changeset-botBot commented May 20, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: bbf9e1e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 3, 2026 8:43pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Jun 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8607

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8607

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8607

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8607

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8607

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8607

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8607

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8607

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8607

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8607

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8607

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8607

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8607

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8607

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8607

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8607

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8607

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8607

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8607

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8607

commit: bbf9e1e

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tested this locally 👍🏼

@github-actions

Copy link
Copy Markdown
Contributor

Break Check: no API changes detected across the tracked packages.

Last ran on bbf9e1e. Pushes that change no tracked declarations (no API surface change vs. base) are skipped and don't update this comment.

@coderabbitai

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR refactors the Expo package's OAuth/SSO completion logic to prevent Metro bundler from statically resolving the optional expo-web-browser peer during native builds. A new maybeCompleteAuthSession module with platform-specific implementations (native no-op and web-specific) replaces inline try/catch logic in ClerkProvider.tsx, eliminating native build failures when expo-web-browser is not installed.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Title check⚠️ WarningThe title mentions 'expo-auth-session import leak' but the PR primarily fixes the 'expo-web-browser' leak in ClerkProvider; 'expo-auth-session' is a separate issue handled elsewhere.Update the title to accurately reflect the main change: 'fix(expo): Prevent expo-web-browser from leaking into native bundles' or similar.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description check✅ PassedThe description clearly explains the optional-dependency leak issue, the solution with platform-specific helpers, and distinguishes this from the separate expo-auth-session issue.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/expo/src/provider/ClerkProvider.tsx (1)

379-381: ⚡ Quick win

Add test coverage for the platform-split maybeCompleteAuthSession.

This PR introduces a new platform-resolved module (native no-op vs. web require of expo-web-browser) but ships no tests. Given the bug being fixed (Metro statically resolving the optional peer on native), a regression here would be silent. Consider tests that assert: the web implementation invokes WebBrowser.maybeCompleteAuthSession() and swallows errors with a __DEV__ warning when the peer is missing, and that the native variant is a no-op that never references expo-web-browser.

Want me to draft the Vitest cases for both maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts?

As per coding guidelines: "If there are no tests added or modified as part of the PR, please suggest that tests be added to cover the changes."

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/provider/ClerkProvider.tsx` around lines 379 - 381, Add
unit tests covering the platform-split maybeCompleteAuthSession behavior: create
Vitest cases for maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts
that (1) on web mock expo-web-browser and assert maybeCompleteAuthSession()
calls WebBrowser.maybeCompleteAuthSession() and that when the peer is missing it
swallows the error and emits a __DEV__ warning, and (2) on native assert the
native maybeCompleteAuthSession implementation is a no-op and does not import or
reference expo-web-browser (i.e., calling it does not attempt to require
WebBrowser). Target the exported function maybeCompleteAuthSession to locate the
implementations.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/expo/src/provider/ClerkProvider.tsx`:
- Around line 379-381: Add unit tests covering the platform-split
maybeCompleteAuthSession behavior: create Vitest cases for
maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts that (1) on web
mock expo-web-browser and assert maybeCompleteAuthSession() calls
WebBrowser.maybeCompleteAuthSession() and that when the peer is missing it
swallows the error and emits a __DEV__ warning, and (2) on native assert the
native maybeCompleteAuthSession implementation is a no-op and does not import or
reference expo-web-browser (i.e., calling it does not attempt to require
WebBrowser). Target the exported function maybeCompleteAuthSession to locate the
implementations.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: a5705a5a-f1e8-4a53-bf20-3a1eb4b567dd

📥 Commits

Reviewing files that changed from the base of the PR and between 03e2bba and bbf9e1e.

📒 Files selected for processing (4)
  • .changeset/expo_avoid_web_browser_static_require.md
  • packages/expo/src/provider/ClerkProvider.tsx
  • packages/expo/src/provider/maybeCompleteAuthSession.ts
  • packages/expo/src/provider/maybeCompleteAuthSession.web.ts

@wobsoriano

Copy link
Copy Markdown
Member

!snapshot

@github-actions

Copy link
Copy Markdown
Contributor

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/astro3.3.4-snapshot.v20260603205452
@clerk/backend3.5.1-snapshot.v20260603205452
@clerk/chrome-extension3.1.33-snapshot.v20260603205452
@clerk/clerk-js6.14.1-snapshot.v20260603205452
@clerk/expo3.3.2-snapshot.v20260603205452
@clerk/expo-passkeys1.1.2-snapshot.v20260603205452
@clerk/express2.1.24-snapshot.v20260603205452
@clerk/fastify3.1.34-snapshot.v20260603205452
@clerk/hono0.1.34-snapshot.v20260603205452
@clerk/localizations4.7.2-snapshot.v20260603205452
@clerk/msw0.0.32-snapshot.v20260603205452
@clerk/nextjs7.4.4-snapshot.v20260603205452
@clerk/nuxt2.5.4-snapshot.v20260603205452
@clerk/react6.7.4-snapshot.v20260603205452
@clerk/react-router3.3.4-snapshot.v20260603205452
@clerk/shared4.15.1-snapshot.v20260603205452
@clerk/tanstack-react-start1.3.4-snapshot.v20260603205452
@clerk/testing2.0.36-snapshot.v20260603205452
@clerk/ui1.15.1-snapshot.v20260603205452
@clerk/upgrade2.0.4-snapshot.v20260603205452
@clerk/vue2.3.4-snapshot.v20260603205452

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/astro

npm i @clerk/astro@3.3.4-snapshot.v20260603205452 --save-exact

@clerk/backend

npm i @clerk/backend@3.5.1-snapshot.v20260603205452 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@3.1.33-snapshot.v20260603205452 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@6.14.1-snapshot.v20260603205452 --save-exact

@clerk/expo

npm i @clerk/expo@3.3.2-snapshot.v20260603205452 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@1.1.2-snapshot.v20260603205452 --save-exact

@clerk/express

npm i @clerk/express@2.1.24-snapshot.v20260603205452 --save-exact

@clerk/fastify

npm i @clerk/fastify@3.1.34-snapshot.v20260603205452 --save-exact

@clerk/hono

npm i @clerk/hono@0.1.34-snapshot.v20260603205452 --save-exact

@clerk/localizations

npm i @clerk/localizations@4.7.2-snapshot.v20260603205452 --save-exact

@clerk/msw

npm i @clerk/msw@0.0.32-snapshot.v20260603205452 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@7.4.4-snapshot.v20260603205452 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@2.5.4-snapshot.v20260603205452 --save-exact

@clerk/react

npm i @clerk/react@6.7.4-snapshot.v20260603205452 --save-exact

@clerk/react-router

npm i @clerk/react-router@3.3.4-snapshot.v20260603205452 --save-exact

@clerk/shared

npm i @clerk/shared@4.15.1-snapshot.v20260603205452 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@1.3.4-snapshot.v20260603205452 --save-exact

@clerk/testing

npm i @clerk/testing@2.0.36-snapshot.v20260603205452 --save-exact

@clerk/ui

npm i @clerk/ui@1.15.1-snapshot.v20260603205452 --save-exact

@clerk/upgrade

npm i @clerk/upgrade@2.0.4-snapshot.v20260603205452 --save-exact

@clerk/vue

npm i @clerk/vue@2.3.4-snapshot.v20260603205452 --save-exact

@wobsoriano
wobsoriano merged commit c0bfb9d into mainJun 3, 2026
75 of 80 checks passed
@wobsoriano
wobsoriano deleted the chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection branch June 3, 2026 21:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@chriscanin@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(expo): Fix expo-auth-session import leak and env var detection by chriscanin · Pull Request #8607 · clerk/javascript · GitHub
Skip to content

fix(expo): Fix expo-auth-session import leak and env var detection - #8607

Merged
wobsoriano merged 3 commits into
mainfrom
chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection
Jun 3, 2026
Merged

fix(expo): Fix expo-auth-session import leak and env var detection#8607
wobsoriano merged 3 commits into
mainfrom
chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection

Conversation

@chriscanin

@chriscaninchriscanin commented May 20, 2026

Copy link
Copy Markdown
Contributor

Summary

This PR fixes an optional-dependency leak in @clerk/expo's ClerkProvider.

Previously, ClerkProvider synchronously referenced expo-web-browser behind an isWeb() runtime check in order to call maybeCompleteAuthSession() for OAuth/SSO flows on web. In Expo/Metro, that pattern can still cause expo-web-browser to be picked up during native bundling even though it is only needed on web and is declared as an optional peer dependency.

This change moves that logic into a platform-specific helper:

  • maybeCompleteAuthSession.web.ts contains the web implementation
  • maybeCompleteAuthSession.ts is a native no-op

That keeps web behavior unchanged while ensuring native bundles no longer reference expo-web-browser through ClerkProvider.

Note: this is distinct from the useSSO / expo-auth-session issue fixed separately #8720. This PR only addresses the ClerkProviderexpo-web-browser leak.

`ClerkProvider` previously called `require('expo-web-browser')` synchronously
inside an `isWeb()` runtime gate. Metro's static analyzer resolves literal-string
`require()` calls regardless of runtime gates or try/catch, so production
bundling failed for native consumers who don't install `expo-web-browser` (an
optional peer dependency).
Splits the web-only `maybeCompleteAuthSession()` call into a platform-specific
helper. Metro/Expo's platform resolver picks `maybeCompleteAuthSession.web.ts`
for web bundles and the no-op `maybeCompleteAuthSession.ts` for native — so
native dist no longer references `expo-web-browser`.
Behavior is unchanged at runtime on both platforms; the fix is purely at bundle
time.
The "env var detection" half of MOBILE-402 was already resolved in #7655
(publishableKey made a required prop, env-var fallback removed). No further
change needed there.
MOBILE-402
@changeset-bot

changeset-botBot commented May 20, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: bbf9e1e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 3, 2026 8:43pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Jun 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8607

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8607

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8607

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8607

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8607

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8607

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8607

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8607

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8607

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8607

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8607

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8607

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8607

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8607

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8607

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8607

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8607

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8607

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8607

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8607

commit: bbf9e1e

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tested this locally 👍🏼

@github-actions

Copy link
Copy Markdown
Contributor

Break Check: no API changes detected across the tracked packages.

Last ran on bbf9e1e. Pushes that change no tracked declarations (no API surface change vs. base) are skipped and don't update this comment.

@coderabbitai

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR refactors the Expo package's OAuth/SSO completion logic to prevent Metro bundler from statically resolving the optional expo-web-browser peer during native builds. A new maybeCompleteAuthSession module with platform-specific implementations (native no-op and web-specific) replaces inline try/catch logic in ClerkProvider.tsx, eliminating native build failures when expo-web-browser is not installed.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Title check⚠️ WarningThe title mentions 'expo-auth-session import leak' but the PR primarily fixes the 'expo-web-browser' leak in ClerkProvider; 'expo-auth-session' is a separate issue handled elsewhere.Update the title to accurately reflect the main change: 'fix(expo): Prevent expo-web-browser from leaking into native bundles' or similar.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description check✅ PassedThe description clearly explains the optional-dependency leak issue, the solution with platform-specific helpers, and distinguishes this from the separate expo-auth-session issue.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/expo/src/provider/ClerkProvider.tsx (1)

379-381: ⚡ Quick win

Add test coverage for the platform-split maybeCompleteAuthSession.

This PR introduces a new platform-resolved module (native no-op vs. web require of expo-web-browser) but ships no tests. Given the bug being fixed (Metro statically resolving the optional peer on native), a regression here would be silent. Consider tests that assert: the web implementation invokes WebBrowser.maybeCompleteAuthSession() and swallows errors with a __DEV__ warning when the peer is missing, and that the native variant is a no-op that never references expo-web-browser.

Want me to draft the Vitest cases for both maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts?

As per coding guidelines: "If there are no tests added or modified as part of the PR, please suggest that tests be added to cover the changes."

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/provider/ClerkProvider.tsx` around lines 379 - 381, Add
unit tests covering the platform-split maybeCompleteAuthSession behavior: create
Vitest cases for maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts
that (1) on web mock expo-web-browser and assert maybeCompleteAuthSession()
calls WebBrowser.maybeCompleteAuthSession() and that when the peer is missing it
swallows the error and emits a __DEV__ warning, and (2) on native assert the
native maybeCompleteAuthSession implementation is a no-op and does not import or
reference expo-web-browser (i.e., calling it does not attempt to require
WebBrowser). Target the exported function maybeCompleteAuthSession to locate the
implementations.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/expo/src/provider/ClerkProvider.tsx`:
- Around line 379-381: Add unit tests covering the platform-split
maybeCompleteAuthSession behavior: create Vitest cases for
maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts that (1) on web
mock expo-web-browser and assert maybeCompleteAuthSession() calls
WebBrowser.maybeCompleteAuthSession() and that when the peer is missing it
swallows the error and emits a __DEV__ warning, and (2) on native assert the
native maybeCompleteAuthSession implementation is a no-op and does not import or
reference expo-web-browser (i.e., calling it does not attempt to require
WebBrowser). Target the exported function maybeCompleteAuthSession to locate the
implementations.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: a5705a5a-f1e8-4a53-bf20-3a1eb4b567dd

📥 Commits

Reviewing files that changed from the base of the PR and between 03e2bba and bbf9e1e.

📒 Files selected for processing (4)
  • .changeset/expo_avoid_web_browser_static_require.md
  • packages/expo/src/provider/ClerkProvider.tsx
  • packages/expo/src/provider/maybeCompleteAuthSession.ts
  • packages/expo/src/provider/maybeCompleteAuthSession.web.ts

@wobsoriano

Copy link
Copy Markdown
Member

!snapshot

@github-actions

Copy link
Copy Markdown
Contributor

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/astro3.3.4-snapshot.v20260603205452
@clerk/backend3.5.1-snapshot.v20260603205452
@clerk/chrome-extension3.1.33-snapshot.v20260603205452
@clerk/clerk-js6.14.1-snapshot.v20260603205452
@clerk/expo3.3.2-snapshot.v20260603205452
@clerk/expo-passkeys1.1.2-snapshot.v20260603205452
@clerk/express2.1.24-snapshot.v20260603205452
@clerk/fastify3.1.34-snapshot.v20260603205452
@clerk/hono0.1.34-snapshot.v20260603205452
@clerk/localizations4.7.2-snapshot.v20260603205452
@clerk/msw0.0.32-snapshot.v20260603205452
@clerk/nextjs7.4.4-snapshot.v20260603205452
@clerk/nuxt2.5.4-snapshot.v20260603205452
@clerk/react6.7.4-snapshot.v20260603205452
@clerk/react-router3.3.4-snapshot.v20260603205452
@clerk/shared4.15.1-snapshot.v20260603205452
@clerk/tanstack-react-start1.3.4-snapshot.v20260603205452
@clerk/testing2.0.36-snapshot.v20260603205452
@clerk/ui1.15.1-snapshot.v20260603205452
@clerk/upgrade2.0.4-snapshot.v20260603205452
@clerk/vue2.3.4-snapshot.v20260603205452

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/astro

npm i @clerk/astro@3.3.4-snapshot.v20260603205452 --save-exact

@clerk/backend

npm i @clerk/backend@3.5.1-snapshot.v20260603205452 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@3.1.33-snapshot.v20260603205452 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@6.14.1-snapshot.v20260603205452 --save-exact

@clerk/expo

npm i @clerk/expo@3.3.2-snapshot.v20260603205452 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@1.1.2-snapshot.v20260603205452 --save-exact

@clerk/express

npm i @clerk/express@2.1.24-snapshot.v20260603205452 --save-exact

@clerk/fastify

npm i @clerk/fastify@3.1.34-snapshot.v20260603205452 --save-exact

@clerk/hono

npm i @clerk/hono@0.1.34-snapshot.v20260603205452 --save-exact

@clerk/localizations

npm i @clerk/localizations@4.7.2-snapshot.v20260603205452 --save-exact

@clerk/msw

npm i @clerk/msw@0.0.32-snapshot.v20260603205452 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@7.4.4-snapshot.v20260603205452 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@2.5.4-snapshot.v20260603205452 --save-exact

@clerk/react

npm i @clerk/react@6.7.4-snapshot.v20260603205452 --save-exact

@clerk/react-router

npm i @clerk/react-router@3.3.4-snapshot.v20260603205452 --save-exact

@clerk/shared

npm i @clerk/shared@4.15.1-snapshot.v20260603205452 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@1.3.4-snapshot.v20260603205452 --save-exact

@clerk/testing

npm i @clerk/testing@2.0.36-snapshot.v20260603205452 --save-exact

@clerk/ui

npm i @clerk/ui@1.15.1-snapshot.v20260603205452 --save-exact

@clerk/upgrade

npm i @clerk/upgrade@2.0.4-snapshot.v20260603205452 --save-exact

@clerk/vue

npm i @clerk/vue@2.3.4-snapshot.v20260603205452 --save-exact

@wobsoriano
wobsoriano merged commit c0bfb9d into mainJun 3, 2026
75 of 80 checks passed
@wobsoriano
wobsoriano deleted the chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection branch June 3, 2026 21:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@chriscanin@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(expo): Fix expo-auth-session import leak and env var detection by chriscanin · Pull Request #8607 · clerk/javascript · GitHub
Skip to content

fix(expo): Fix expo-auth-session import leak and env var detection - #8607

Merged
wobsoriano merged 3 commits into
mainfrom
chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection
Jun 3, 2026
Merged

fix(expo): Fix expo-auth-session import leak and env var detection#8607
wobsoriano merged 3 commits into
mainfrom
chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection

Conversation

@chriscanin

@chriscaninchriscanin commented May 20, 2026

Copy link
Copy Markdown
Contributor

Summary

This PR fixes an optional-dependency leak in @clerk/expo's ClerkProvider.

Previously, ClerkProvider synchronously referenced expo-web-browser behind an isWeb() runtime check in order to call maybeCompleteAuthSession() for OAuth/SSO flows on web. In Expo/Metro, that pattern can still cause expo-web-browser to be picked up during native bundling even though it is only needed on web and is declared as an optional peer dependency.

This change moves that logic into a platform-specific helper:

  • maybeCompleteAuthSession.web.ts contains the web implementation
  • maybeCompleteAuthSession.ts is a native no-op

That keeps web behavior unchanged while ensuring native bundles no longer reference expo-web-browser through ClerkProvider.

Note: this is distinct from the useSSO / expo-auth-session issue fixed separately #8720. This PR only addresses the ClerkProviderexpo-web-browser leak.

`ClerkProvider` previously called `require('expo-web-browser')` synchronously
inside an `isWeb()` runtime gate. Metro's static analyzer resolves literal-string
`require()` calls regardless of runtime gates or try/catch, so production
bundling failed for native consumers who don't install `expo-web-browser` (an
optional peer dependency).
Splits the web-only `maybeCompleteAuthSession()` call into a platform-specific
helper. Metro/Expo's platform resolver picks `maybeCompleteAuthSession.web.ts`
for web bundles and the no-op `maybeCompleteAuthSession.ts` for native — so
native dist no longer references `expo-web-browser`.
Behavior is unchanged at runtime on both platforms; the fix is purely at bundle
time.
The "env var detection" half of MOBILE-402 was already resolved in #7655
(publishableKey made a required prop, env-var fallback removed). No further
change needed there.
MOBILE-402
@changeset-bot

changeset-botBot commented May 20, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: bbf9e1e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 3, 2026 8:43pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Jun 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8607

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8607

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8607

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8607

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8607

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8607

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8607

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8607

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8607

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8607

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8607

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8607

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8607

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8607

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8607

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8607

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8607

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8607

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8607

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8607

commit: bbf9e1e

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tested this locally 👍🏼

@github-actions

Copy link
Copy Markdown
Contributor

Break Check: no API changes detected across the tracked packages.

Last ran on bbf9e1e. Pushes that change no tracked declarations (no API surface change vs. base) are skipped and don't update this comment.

@coderabbitai

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR refactors the Expo package's OAuth/SSO completion logic to prevent Metro bundler from statically resolving the optional expo-web-browser peer during native builds. A new maybeCompleteAuthSession module with platform-specific implementations (native no-op and web-specific) replaces inline try/catch logic in ClerkProvider.tsx, eliminating native build failures when expo-web-browser is not installed.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Title check⚠️ WarningThe title mentions 'expo-auth-session import leak' but the PR primarily fixes the 'expo-web-browser' leak in ClerkProvider; 'expo-auth-session' is a separate issue handled elsewhere.Update the title to accurately reflect the main change: 'fix(expo): Prevent expo-web-browser from leaking into native bundles' or similar.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description check✅ PassedThe description clearly explains the optional-dependency leak issue, the solution with platform-specific helpers, and distinguishes this from the separate expo-auth-session issue.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/expo/src/provider/ClerkProvider.tsx (1)

379-381: ⚡ Quick win

Add test coverage for the platform-split maybeCompleteAuthSession.

This PR introduces a new platform-resolved module (native no-op vs. web require of expo-web-browser) but ships no tests. Given the bug being fixed (Metro statically resolving the optional peer on native), a regression here would be silent. Consider tests that assert: the web implementation invokes WebBrowser.maybeCompleteAuthSession() and swallows errors with a __DEV__ warning when the peer is missing, and that the native variant is a no-op that never references expo-web-browser.

Want me to draft the Vitest cases for both maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts?

As per coding guidelines: "If there are no tests added or modified as part of the PR, please suggest that tests be added to cover the changes."

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/provider/ClerkProvider.tsx` around lines 379 - 381, Add
unit tests covering the platform-split maybeCompleteAuthSession behavior: create
Vitest cases for maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts
that (1) on web mock expo-web-browser and assert maybeCompleteAuthSession()
calls WebBrowser.maybeCompleteAuthSession() and that when the peer is missing it
swallows the error and emits a __DEV__ warning, and (2) on native assert the
native maybeCompleteAuthSession implementation is a no-op and does not import or
reference expo-web-browser (i.e., calling it does not attempt to require
WebBrowser). Target the exported function maybeCompleteAuthSession to locate the
implementations.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/expo/src/provider/ClerkProvider.tsx`:
- Around line 379-381: Add unit tests covering the platform-split
maybeCompleteAuthSession behavior: create Vitest cases for
maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts that (1) on web
mock expo-web-browser and assert maybeCompleteAuthSession() calls
WebBrowser.maybeCompleteAuthSession() and that when the peer is missing it
swallows the error and emits a __DEV__ warning, and (2) on native assert the
native maybeCompleteAuthSession implementation is a no-op and does not import or
reference expo-web-browser (i.e., calling it does not attempt to require
WebBrowser). Target the exported function maybeCompleteAuthSession to locate the
implementations.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: a5705a5a-f1e8-4a53-bf20-3a1eb4b567dd

📥 Commits

Reviewing files that changed from the base of the PR and between 03e2bba and bbf9e1e.

📒 Files selected for processing (4)
  • .changeset/expo_avoid_web_browser_static_require.md
  • packages/expo/src/provider/ClerkProvider.tsx
  • packages/expo/src/provider/maybeCompleteAuthSession.ts
  • packages/expo/src/provider/maybeCompleteAuthSession.web.ts

@wobsoriano

Copy link
Copy Markdown
Member

!snapshot

@github-actions

Copy link
Copy Markdown
Contributor

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/astro3.3.4-snapshot.v20260603205452
@clerk/backend3.5.1-snapshot.v20260603205452
@clerk/chrome-extension3.1.33-snapshot.v20260603205452
@clerk/clerk-js6.14.1-snapshot.v20260603205452
@clerk/expo3.3.2-snapshot.v20260603205452
@clerk/expo-passkeys1.1.2-snapshot.v20260603205452
@clerk/express2.1.24-snapshot.v20260603205452
@clerk/fastify3.1.34-snapshot.v20260603205452
@clerk/hono0.1.34-snapshot.v20260603205452
@clerk/localizations4.7.2-snapshot.v20260603205452
@clerk/msw0.0.32-snapshot.v20260603205452
@clerk/nextjs7.4.4-snapshot.v20260603205452
@clerk/nuxt2.5.4-snapshot.v20260603205452
@clerk/react6.7.4-snapshot.v20260603205452
@clerk/react-router3.3.4-snapshot.v20260603205452
@clerk/shared4.15.1-snapshot.v20260603205452
@clerk/tanstack-react-start1.3.4-snapshot.v20260603205452
@clerk/testing2.0.36-snapshot.v20260603205452
@clerk/ui1.15.1-snapshot.v20260603205452
@clerk/upgrade2.0.4-snapshot.v20260603205452
@clerk/vue2.3.4-snapshot.v20260603205452

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/astro

npm i @clerk/astro@3.3.4-snapshot.v20260603205452 --save-exact

@clerk/backend

npm i @clerk/backend@3.5.1-snapshot.v20260603205452 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@3.1.33-snapshot.v20260603205452 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@6.14.1-snapshot.v20260603205452 --save-exact

@clerk/expo

npm i @clerk/expo@3.3.2-snapshot.v20260603205452 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@1.1.2-snapshot.v20260603205452 --save-exact

@clerk/express

npm i @clerk/express@2.1.24-snapshot.v20260603205452 --save-exact

@clerk/fastify

npm i @clerk/fastify@3.1.34-snapshot.v20260603205452 --save-exact

@clerk/hono

npm i @clerk/hono@0.1.34-snapshot.v20260603205452 --save-exact

@clerk/localizations

npm i @clerk/localizations@4.7.2-snapshot.v20260603205452 --save-exact

@clerk/msw

npm i @clerk/msw@0.0.32-snapshot.v20260603205452 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@7.4.4-snapshot.v20260603205452 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@2.5.4-snapshot.v20260603205452 --save-exact

@clerk/react

npm i @clerk/react@6.7.4-snapshot.v20260603205452 --save-exact

@clerk/react-router

npm i @clerk/react-router@3.3.4-snapshot.v20260603205452 --save-exact

@clerk/shared

npm i @clerk/shared@4.15.1-snapshot.v20260603205452 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@1.3.4-snapshot.v20260603205452 --save-exact

@clerk/testing

npm i @clerk/testing@2.0.36-snapshot.v20260603205452 --save-exact

@clerk/ui

npm i @clerk/ui@1.15.1-snapshot.v20260603205452 --save-exact

@clerk/upgrade

npm i @clerk/upgrade@2.0.4-snapshot.v20260603205452 --save-exact

@clerk/vue

npm i @clerk/vue@2.3.4-snapshot.v20260603205452 --save-exact

@wobsoriano
wobsoriano merged commit c0bfb9d into mainJun 3, 2026
75 of 80 checks passed
@wobsoriano
wobsoriano deleted the chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection branch June 3, 2026 21:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@chriscanin@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix(expo): Fix expo-auth-session import leak and env var detection by chriscanin · Pull Request #8607 · clerk/javascript · GitHub
Skip to content

fix(expo): Fix expo-auth-session import leak and env var detection - #8607

Merged
wobsoriano merged 3 commits into
mainfrom
chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection
Jun 3, 2026
Merged

fix(expo): Fix expo-auth-session import leak and env var detection#8607
wobsoriano merged 3 commits into
mainfrom
chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection

Conversation

@chriscanin

@chriscaninchriscanin commented May 20, 2026

Copy link
Copy Markdown
Contributor

Summary

This PR fixes an optional-dependency leak in @clerk/expo's ClerkProvider.

Previously, ClerkProvider synchronously referenced expo-web-browser behind an isWeb() runtime check in order to call maybeCompleteAuthSession() for OAuth/SSO flows on web. In Expo/Metro, that pattern can still cause expo-web-browser to be picked up during native bundling even though it is only needed on web and is declared as an optional peer dependency.

This change moves that logic into a platform-specific helper:

  • maybeCompleteAuthSession.web.ts contains the web implementation
  • maybeCompleteAuthSession.ts is a native no-op

That keeps web behavior unchanged while ensuring native bundles no longer reference expo-web-browser through ClerkProvider.

Note: this is distinct from the useSSO / expo-auth-session issue fixed separately #8720. This PR only addresses the ClerkProviderexpo-web-browser leak.

`ClerkProvider` previously called `require('expo-web-browser')` synchronously
inside an `isWeb()` runtime gate. Metro's static analyzer resolves literal-string
`require()` calls regardless of runtime gates or try/catch, so production
bundling failed for native consumers who don't install `expo-web-browser` (an
optional peer dependency).
Splits the web-only `maybeCompleteAuthSession()` call into a platform-specific
helper. Metro/Expo's platform resolver picks `maybeCompleteAuthSession.web.ts`
for web bundles and the no-op `maybeCompleteAuthSession.ts` for native — so
native dist no longer references `expo-web-browser`.
Behavior is unchanged at runtime on both platforms; the fix is purely at bundle
time.
The "env var detection" half of MOBILE-402 was already resolved in #7655
(publishableKey made a required prop, env-var fallback removed). No further
change needed there.
MOBILE-402
@changeset-bot

changeset-botBot commented May 20, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: bbf9e1e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 3, 2026 8:43pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Jun 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8607

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8607

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8607

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8607

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8607

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8607

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8607

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8607

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8607

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8607

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8607

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8607

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8607

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8607

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8607

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8607

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8607

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8607

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8607

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8607

commit: bbf9e1e

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tested this locally 👍🏼

@github-actions

Copy link
Copy Markdown
Contributor

Break Check: no API changes detected across the tracked packages.

Last ran on bbf9e1e. Pushes that change no tracked declarations (no API surface change vs. base) are skipped and don't update this comment.

@coderabbitai

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR refactors the Expo package's OAuth/SSO completion logic to prevent Metro bundler from statically resolving the optional expo-web-browser peer during native builds. A new maybeCompleteAuthSession module with platform-specific implementations (native no-op and web-specific) replaces inline try/catch logic in ClerkProvider.tsx, eliminating native build failures when expo-web-browser is not installed.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Title check⚠️ WarningThe title mentions 'expo-auth-session import leak' but the PR primarily fixes the 'expo-web-browser' leak in ClerkProvider; 'expo-auth-session' is a separate issue handled elsewhere.Update the title to accurately reflect the main change: 'fix(expo): Prevent expo-web-browser from leaking into native bundles' or similar.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Description check✅ PassedThe description clearly explains the optional-dependency leak issue, the solution with platform-specific helpers, and distinguishes this from the separate expo-auth-session issue.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/expo/src/provider/ClerkProvider.tsx (1)

379-381: ⚡ Quick win

Add test coverage for the platform-split maybeCompleteAuthSession.

This PR introduces a new platform-resolved module (native no-op vs. web require of expo-web-browser) but ships no tests. Given the bug being fixed (Metro statically resolving the optional peer on native), a regression here would be silent. Consider tests that assert: the web implementation invokes WebBrowser.maybeCompleteAuthSession() and swallows errors with a __DEV__ warning when the peer is missing, and that the native variant is a no-op that never references expo-web-browser.

Want me to draft the Vitest cases for both maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts?

As per coding guidelines: "If there are no tests added or modified as part of the PR, please suggest that tests be added to cover the changes."

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/provider/ClerkProvider.tsx` around lines 379 - 381, Add
unit tests covering the platform-split maybeCompleteAuthSession behavior: create
Vitest cases for maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts
that (1) on web mock expo-web-browser and assert maybeCompleteAuthSession()
calls WebBrowser.maybeCompleteAuthSession() and that when the peer is missing it
swallows the error and emits a __DEV__ warning, and (2) on native assert the
native maybeCompleteAuthSession implementation is a no-op and does not import or
reference expo-web-browser (i.e., calling it does not attempt to require
WebBrowser). Target the exported function maybeCompleteAuthSession to locate the
implementations.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/expo/src/provider/ClerkProvider.tsx`:
- Around line 379-381: Add unit tests covering the platform-split
maybeCompleteAuthSession behavior: create Vitest cases for
maybeCompleteAuthSession.ts and maybeCompleteAuthSession.web.ts that (1) on web
mock expo-web-browser and assert maybeCompleteAuthSession() calls
WebBrowser.maybeCompleteAuthSession() and that when the peer is missing it
swallows the error and emits a __DEV__ warning, and (2) on native assert the
native maybeCompleteAuthSession implementation is a no-op and does not import or
reference expo-web-browser (i.e., calling it does not attempt to require
WebBrowser). Target the exported function maybeCompleteAuthSession to locate the
implementations.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: a5705a5a-f1e8-4a53-bf20-3a1eb4b567dd

📥 Commits

Reviewing files that changed from the base of the PR and between 03e2bba and bbf9e1e.

📒 Files selected for processing (4)
  • .changeset/expo_avoid_web_browser_static_require.md
  • packages/expo/src/provider/ClerkProvider.tsx
  • packages/expo/src/provider/maybeCompleteAuthSession.ts
  • packages/expo/src/provider/maybeCompleteAuthSession.web.ts

@wobsoriano

Copy link
Copy Markdown
Member

!snapshot

@github-actions

Copy link
Copy Markdown
Contributor

Hey @wobsoriano - the snapshot version command generated the following package versions:

PackageVersion
@clerk/astro3.3.4-snapshot.v20260603205452
@clerk/backend3.5.1-snapshot.v20260603205452
@clerk/chrome-extension3.1.33-snapshot.v20260603205452
@clerk/clerk-js6.14.1-snapshot.v20260603205452
@clerk/expo3.3.2-snapshot.v20260603205452
@clerk/expo-passkeys1.1.2-snapshot.v20260603205452
@clerk/express2.1.24-snapshot.v20260603205452
@clerk/fastify3.1.34-snapshot.v20260603205452
@clerk/hono0.1.34-snapshot.v20260603205452
@clerk/localizations4.7.2-snapshot.v20260603205452
@clerk/msw0.0.32-snapshot.v20260603205452
@clerk/nextjs7.4.4-snapshot.v20260603205452
@clerk/nuxt2.5.4-snapshot.v20260603205452
@clerk/react6.7.4-snapshot.v20260603205452
@clerk/react-router3.3.4-snapshot.v20260603205452
@clerk/shared4.15.1-snapshot.v20260603205452
@clerk/tanstack-react-start1.3.4-snapshot.v20260603205452
@clerk/testing2.0.36-snapshot.v20260603205452
@clerk/ui1.15.1-snapshot.v20260603205452
@clerk/upgrade2.0.4-snapshot.v20260603205452
@clerk/vue2.3.4-snapshot.v20260603205452

Tip: Use the snippet copy button below to quickly install the required packages.
@clerk/astro

npm i @clerk/astro@3.3.4-snapshot.v20260603205452 --save-exact

@clerk/backend

npm i @clerk/backend@3.5.1-snapshot.v20260603205452 --save-exact

@clerk/chrome-extension

npm i @clerk/chrome-extension@3.1.33-snapshot.v20260603205452 --save-exact

@clerk/clerk-js

npm i @clerk/clerk-js@6.14.1-snapshot.v20260603205452 --save-exact

@clerk/expo

npm i @clerk/expo@3.3.2-snapshot.v20260603205452 --save-exact

@clerk/expo-passkeys

npm i @clerk/expo-passkeys@1.1.2-snapshot.v20260603205452 --save-exact

@clerk/express

npm i @clerk/express@2.1.24-snapshot.v20260603205452 --save-exact

@clerk/fastify

npm i @clerk/fastify@3.1.34-snapshot.v20260603205452 --save-exact

@clerk/hono

npm i @clerk/hono@0.1.34-snapshot.v20260603205452 --save-exact

@clerk/localizations

npm i @clerk/localizations@4.7.2-snapshot.v20260603205452 --save-exact

@clerk/msw

npm i @clerk/msw@0.0.32-snapshot.v20260603205452 --save-exact

@clerk/nextjs

npm i @clerk/nextjs@7.4.4-snapshot.v20260603205452 --save-exact

@clerk/nuxt

npm i @clerk/nuxt@2.5.4-snapshot.v20260603205452 --save-exact

@clerk/react

npm i @clerk/react@6.7.4-snapshot.v20260603205452 --save-exact

@clerk/react-router

npm i @clerk/react-router@3.3.4-snapshot.v20260603205452 --save-exact

@clerk/shared

npm i @clerk/shared@4.15.1-snapshot.v20260603205452 --save-exact

@clerk/tanstack-react-start

npm i @clerk/tanstack-react-start@1.3.4-snapshot.v20260603205452 --save-exact

@clerk/testing

npm i @clerk/testing@2.0.36-snapshot.v20260603205452 --save-exact

@clerk/ui

npm i @clerk/ui@1.15.1-snapshot.v20260603205452 --save-exact

@clerk/upgrade

npm i @clerk/upgrade@2.0.4-snapshot.v20260603205452 --save-exact

@clerk/vue

npm i @clerk/vue@2.3.4-snapshot.v20260603205452 --save-exact

@wobsoriano
wobsoriano merged commit c0bfb9d into mainJun 3, 2026
75 of 80 checks passed
@wobsoriano
wobsoriano deleted the chris/mobile-402-fix-expo-auth-session-import-leak-and-env-var-detection branch June 3, 2026 21:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@chriscanin@wobsoriano