Skip to content

fix(backend): stop authenticateRequest from consuming the request body - #8708

Merged
jacekradko merged 1 commit into
mainfrom
jacek/fix-clerkrequest-body-consume
Jun 1, 2026
Merged

fix(backend): stop authenticateRequest from consuming the request body#8708
jacekradko merged 1 commit into
mainfrom
jacek/fix-clerkrequest-body-consume

Conversation

@jacekradko

Copy link
Copy Markdown
Contributor

ClerkRequest clones the incoming request to read headers, cookies, and URL, but the clone was also forwarding the body. On Node/undici that body is a single-use stream shared with the original, so once anything reads the clone the original throws "Body is unusable" downstream (#8305, e.g. a Hono POST handler calling c.req.json()).

The clone now hides body next to signal in the existing Proxy. I kept the Proxy rather than an explicit RequestInit on purpose: that shape was reverted in e9f8d1a because eagerly reading cache breaks Cloudflare Workers. Auth never touches the body, so dropping it from the clone is safe. The retains the body test asserted the old behavior and is now a streaming-body regression test.

Closes#8305.

@changeset-bot

changeset-botBot commented May 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b21dca3

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 10 packages
NameType
@clerk/backendPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 30, 2026 2:26am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

Snapi: no API changes detected in @clerk/backend, @clerk/clerk-js, @clerk/nextjs, @clerk/react, @clerk/shared, @clerk/ui.

@pkg-pr-new

pkg-pr-newBot commented May 30, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8708

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8708

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8708

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8708

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8708

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8708

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8708

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8708

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8708

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8708

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8708

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8708

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8708

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8708

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8708

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8708

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8708

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8708

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8708

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8708

commit: b21dca3

@coderabbitai

coderabbitaiBot commented May 30, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR fixes a bug where ClerkRequest was consuming the incoming HTTP request body stream, preventing downstream handlers from reading it in Node.js environments. The implementation expands inline documentation explaining the Proxy-based approach to lazy property access that preserves the body. The test is updated to verify the original request remains readable after constructing a Clerk request, and a changeset entry documents the fix for @clerk/backend.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and specifically describes the main change: stopping authenticateRequest from consuming the request body, which matches the core objective of the PR.
Description check✅ PassedThe description is directly related to the changeset, explaining the problem (body consumption), the solution (hiding body in the Proxy), and referencing issue #8305.
Linked Issues check✅ PassedThe PR fully addresses issue #8305 by preventing body transfer in ClerkRequest's constructor via Proxy-based hiding, avoiding downstream body read failures (#8305).
Out of Scope Changes check✅ PassedAll changes are directly scoped to fixing the body consumption issue: test updates, implementation comment clarification, and changeset entry.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/backend/src/tokens/__tests__/clerkRequest.test.ts (1)

7-18: 💤 Low value

Consider adding an explicit return type annotation for clarity.

While the return type is easily inferred as boolean, adding an explicit annotation would improve readability and document the intent.

📝 Optional enhancement
-const supportsStreamConstruction = (() => {+const supportsStreamConstruction = ((): boolean => {
try {
new ReadableStream({
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/backend/src/tokens/__tests__/clerkRequest.test.ts` around lines 7 -
18, The IIFE assigned to supportsStreamConstruction should have an explicit
boolean return type for clarity; update the constant declaration for
supportsStreamConstruction (the immediately-invoked function expression that
constructs a ReadableStream) to include a : boolean return type annotation so
the intent is documented and the inferred type is explicit.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/backend/src/tokens/__tests__/clerkRequest.test.ts`:
- Around line 7-18: The IIFE assigned to supportsStreamConstruction should have
an explicit boolean return type for clarity; update the constant declaration for
supportsStreamConstruction (the immediately-invoked function expression that
constructs a ReadableStream) to include a : boolean return type annotation so
the intent is documented and the inferred type is explicit.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 1cd5ed60-34a6-444e-b621-8de615e4db09

📥 Commits

Reviewing files that changed from the base of the PR and between 87212c5 and b21dca3.

📒 Files selected for processing (3)
  • .changeset/clerkrequest-omit-body.md
  • packages/backend/src/tokens/__tests__/clerkRequest.test.ts
  • packages/backend/src/tokens/clerkRequest.ts
🚧 Files skipped from review as they are similar to previous changes (2)
  • packages/backend/src/tokens/clerkRequest.ts
  • .changeset/clerkrequest-omit-body.md

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good! thanks for fixing 🫡

@jacekradko
jacekradko merged commit ff0cfef into mainJun 1, 2026
45 checks passed
@jacekradko
jacekradko deleted the jacek/fix-clerkrequest-body-consume branch June 1, 2026 16:31
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ClerkRequest constructor consumes request body, breaking downstream body reads in non-native Request environments

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(backend): stop authenticateRequest from consuming the request body by jacekradko · Pull Request #8708 · clerk/javascript · GitHub
Skip to content

fix(backend): stop authenticateRequest from consuming the request body - #8708

Merged
jacekradko merged 1 commit into
mainfrom
jacek/fix-clerkrequest-body-consume
Jun 1, 2026
Merged

fix(backend): stop authenticateRequest from consuming the request body#8708
jacekradko merged 1 commit into
mainfrom
jacek/fix-clerkrequest-body-consume

Conversation

@jacekradko

Copy link
Copy Markdown
Contributor

ClerkRequest clones the incoming request to read headers, cookies, and URL, but the clone was also forwarding the body. On Node/undici that body is a single-use stream shared with the original, so once anything reads the clone the original throws "Body is unusable" downstream (#8305, e.g. a Hono POST handler calling c.req.json()).

The clone now hides body next to signal in the existing Proxy. I kept the Proxy rather than an explicit RequestInit on purpose: that shape was reverted in e9f8d1a because eagerly reading cache breaks Cloudflare Workers. Auth never touches the body, so dropping it from the clone is safe. The retains the body test asserted the old behavior and is now a streaming-body regression test.

Closes#8305.

@changeset-bot

changeset-botBot commented May 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b21dca3

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 10 packages
NameType
@clerk/backendPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 30, 2026 2:26am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

Snapi: no API changes detected in @clerk/backend, @clerk/clerk-js, @clerk/nextjs, @clerk/react, @clerk/shared, @clerk/ui.

@pkg-pr-new

pkg-pr-newBot commented May 30, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8708

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8708

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8708

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8708

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8708

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8708

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8708

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8708

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8708

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8708

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8708

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8708

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8708

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8708

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8708

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8708

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8708

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8708

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8708

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8708

commit: b21dca3

@coderabbitai

coderabbitaiBot commented May 30, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR fixes a bug where ClerkRequest was consuming the incoming HTTP request body stream, preventing downstream handlers from reading it in Node.js environments. The implementation expands inline documentation explaining the Proxy-based approach to lazy property access that preserves the body. The test is updated to verify the original request remains readable after constructing a Clerk request, and a changeset entry documents the fix for @clerk/backend.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and specifically describes the main change: stopping authenticateRequest from consuming the request body, which matches the core objective of the PR.
Description check✅ PassedThe description is directly related to the changeset, explaining the problem (body consumption), the solution (hiding body in the Proxy), and referencing issue #8305.
Linked Issues check✅ PassedThe PR fully addresses issue #8305 by preventing body transfer in ClerkRequest's constructor via Proxy-based hiding, avoiding downstream body read failures (#8305).
Out of Scope Changes check✅ PassedAll changes are directly scoped to fixing the body consumption issue: test updates, implementation comment clarification, and changeset entry.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/backend/src/tokens/__tests__/clerkRequest.test.ts (1)

7-18: 💤 Low value

Consider adding an explicit return type annotation for clarity.

While the return type is easily inferred as boolean, adding an explicit annotation would improve readability and document the intent.

📝 Optional enhancement
-const supportsStreamConstruction = (() => {+const supportsStreamConstruction = ((): boolean => {
try {
new ReadableStream({
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/backend/src/tokens/__tests__/clerkRequest.test.ts` around lines 7 -
18, The IIFE assigned to supportsStreamConstruction should have an explicit
boolean return type for clarity; update the constant declaration for
supportsStreamConstruction (the immediately-invoked function expression that
constructs a ReadableStream) to include a : boolean return type annotation so
the intent is documented and the inferred type is explicit.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/backend/src/tokens/__tests__/clerkRequest.test.ts`:
- Around line 7-18: The IIFE assigned to supportsStreamConstruction should have
an explicit boolean return type for clarity; update the constant declaration for
supportsStreamConstruction (the immediately-invoked function expression that
constructs a ReadableStream) to include a : boolean return type annotation so
the intent is documented and the inferred type is explicit.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 1cd5ed60-34a6-444e-b621-8de615e4db09

📥 Commits

Reviewing files that changed from the base of the PR and between 87212c5 and b21dca3.

📒 Files selected for processing (3)
  • .changeset/clerkrequest-omit-body.md
  • packages/backend/src/tokens/__tests__/clerkRequest.test.ts
  • packages/backend/src/tokens/clerkRequest.ts
🚧 Files skipped from review as they are similar to previous changes (2)
  • packages/backend/src/tokens/clerkRequest.ts
  • .changeset/clerkrequest-omit-body.md

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good! thanks for fixing 🫡

@jacekradko
jacekradko merged commit ff0cfef into mainJun 1, 2026
45 checks passed
@jacekradko
jacekradko deleted the jacek/fix-clerkrequest-body-consume branch June 1, 2026 16:31
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ClerkRequest constructor consumes request body, breaking downstream body reads in non-native Request environments

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(backend): stop authenticateRequest from consuming the request body by jacekradko · Pull Request #8708 · clerk/javascript · GitHub
Skip to content

fix(backend): stop authenticateRequest from consuming the request body - #8708

Merged
jacekradko merged 1 commit into
mainfrom
jacek/fix-clerkrequest-body-consume
Jun 1, 2026
Merged

fix(backend): stop authenticateRequest from consuming the request body#8708
jacekradko merged 1 commit into
mainfrom
jacek/fix-clerkrequest-body-consume

Conversation

@jacekradko

Copy link
Copy Markdown
Contributor

ClerkRequest clones the incoming request to read headers, cookies, and URL, but the clone was also forwarding the body. On Node/undici that body is a single-use stream shared with the original, so once anything reads the clone the original throws "Body is unusable" downstream (#8305, e.g. a Hono POST handler calling c.req.json()).

The clone now hides body next to signal in the existing Proxy. I kept the Proxy rather than an explicit RequestInit on purpose: that shape was reverted in e9f8d1a because eagerly reading cache breaks Cloudflare Workers. Auth never touches the body, so dropping it from the clone is safe. The retains the body test asserted the old behavior and is now a streaming-body regression test.

Closes#8305.

@changeset-bot

changeset-botBot commented May 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b21dca3

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 10 packages
NameType
@clerk/backendPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 30, 2026 2:26am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

Snapi: no API changes detected in @clerk/backend, @clerk/clerk-js, @clerk/nextjs, @clerk/react, @clerk/shared, @clerk/ui.

@pkg-pr-new

pkg-pr-newBot commented May 30, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8708

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8708

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8708

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8708

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8708

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8708

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8708

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8708

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8708

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8708

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8708

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8708

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8708

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8708

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8708

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8708

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8708

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8708

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8708

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8708

commit: b21dca3

@coderabbitai

coderabbitaiBot commented May 30, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR fixes a bug where ClerkRequest was consuming the incoming HTTP request body stream, preventing downstream handlers from reading it in Node.js environments. The implementation expands inline documentation explaining the Proxy-based approach to lazy property access that preserves the body. The test is updated to verify the original request remains readable after constructing a Clerk request, and a changeset entry documents the fix for @clerk/backend.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and specifically describes the main change: stopping authenticateRequest from consuming the request body, which matches the core objective of the PR.
Description check✅ PassedThe description is directly related to the changeset, explaining the problem (body consumption), the solution (hiding body in the Proxy), and referencing issue #8305.
Linked Issues check✅ PassedThe PR fully addresses issue #8305 by preventing body transfer in ClerkRequest's constructor via Proxy-based hiding, avoiding downstream body read failures (#8305).
Out of Scope Changes check✅ PassedAll changes are directly scoped to fixing the body consumption issue: test updates, implementation comment clarification, and changeset entry.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/backend/src/tokens/__tests__/clerkRequest.test.ts (1)

7-18: 💤 Low value

Consider adding an explicit return type annotation for clarity.

While the return type is easily inferred as boolean, adding an explicit annotation would improve readability and document the intent.

📝 Optional enhancement
-const supportsStreamConstruction = (() => {+const supportsStreamConstruction = ((): boolean => {
try {
new ReadableStream({
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/backend/src/tokens/__tests__/clerkRequest.test.ts` around lines 7 -
18, The IIFE assigned to supportsStreamConstruction should have an explicit
boolean return type for clarity; update the constant declaration for
supportsStreamConstruction (the immediately-invoked function expression that
constructs a ReadableStream) to include a : boolean return type annotation so
the intent is documented and the inferred type is explicit.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/backend/src/tokens/__tests__/clerkRequest.test.ts`:
- Around line 7-18: The IIFE assigned to supportsStreamConstruction should have
an explicit boolean return type for clarity; update the constant declaration for
supportsStreamConstruction (the immediately-invoked function expression that
constructs a ReadableStream) to include a : boolean return type annotation so
the intent is documented and the inferred type is explicit.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 1cd5ed60-34a6-444e-b621-8de615e4db09

📥 Commits

Reviewing files that changed from the base of the PR and between 87212c5 and b21dca3.

📒 Files selected for processing (3)
  • .changeset/clerkrequest-omit-body.md
  • packages/backend/src/tokens/__tests__/clerkRequest.test.ts
  • packages/backend/src/tokens/clerkRequest.ts
🚧 Files skipped from review as they are similar to previous changes (2)
  • packages/backend/src/tokens/clerkRequest.ts
  • .changeset/clerkrequest-omit-body.md

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good! thanks for fixing 🫡

@jacekradko
jacekradko merged commit ff0cfef into mainJun 1, 2026
45 checks passed
@jacekradko
jacekradko deleted the jacek/fix-clerkrequest-body-consume branch June 1, 2026 16:31
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ClerkRequest constructor consumes request body, breaking downstream body reads in non-native Request environments

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(backend): stop authenticateRequest from consuming the request body by jacekradko · Pull Request #8708 · clerk/javascript · GitHub
Skip to content

fix(backend): stop authenticateRequest from consuming the request body - #8708

Merged
jacekradko merged 1 commit into
mainfrom
jacek/fix-clerkrequest-body-consume
Jun 1, 2026
Merged

fix(backend): stop authenticateRequest from consuming the request body#8708
jacekradko merged 1 commit into
mainfrom
jacek/fix-clerkrequest-body-consume

Conversation

@jacekradko

Copy link
Copy Markdown
Contributor

ClerkRequest clones the incoming request to read headers, cookies, and URL, but the clone was also forwarding the body. On Node/undici that body is a single-use stream shared with the original, so once anything reads the clone the original throws "Body is unusable" downstream (#8305, e.g. a Hono POST handler calling c.req.json()).

The clone now hides body next to signal in the existing Proxy. I kept the Proxy rather than an explicit RequestInit on purpose: that shape was reverted in e9f8d1a because eagerly reading cache breaks Cloudflare Workers. Auth never touches the body, so dropping it from the clone is safe. The retains the body test asserted the old behavior and is now a streaming-body regression test.

Closes#8305.

@changeset-bot

changeset-botBot commented May 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b21dca3

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 10 packages
NameType
@clerk/backendPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 30, 2026 2:26am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

Snapi: no API changes detected in @clerk/backend, @clerk/clerk-js, @clerk/nextjs, @clerk/react, @clerk/shared, @clerk/ui.

@pkg-pr-new

pkg-pr-newBot commented May 30, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8708

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8708

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8708

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8708

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8708

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8708

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8708

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8708

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8708

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8708

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8708

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8708

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8708

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8708

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8708

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8708

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8708

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8708

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8708

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8708

commit: b21dca3

@coderabbitai

coderabbitaiBot commented May 30, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR fixes a bug where ClerkRequest was consuming the incoming HTTP request body stream, preventing downstream handlers from reading it in Node.js environments. The implementation expands inline documentation explaining the Proxy-based approach to lazy property access that preserves the body. The test is updated to verify the original request remains readable after constructing a Clerk request, and a changeset entry documents the fix for @clerk/backend.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and specifically describes the main change: stopping authenticateRequest from consuming the request body, which matches the core objective of the PR.
Description check✅ PassedThe description is directly related to the changeset, explaining the problem (body consumption), the solution (hiding body in the Proxy), and referencing issue #8305.
Linked Issues check✅ PassedThe PR fully addresses issue #8305 by preventing body transfer in ClerkRequest's constructor via Proxy-based hiding, avoiding downstream body read failures (#8305).
Out of Scope Changes check✅ PassedAll changes are directly scoped to fixing the body consumption issue: test updates, implementation comment clarification, and changeset entry.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/backend/src/tokens/__tests__/clerkRequest.test.ts (1)

7-18: 💤 Low value

Consider adding an explicit return type annotation for clarity.

While the return type is easily inferred as boolean, adding an explicit annotation would improve readability and document the intent.

📝 Optional enhancement
-const supportsStreamConstruction = (() => {+const supportsStreamConstruction = ((): boolean => {
try {
new ReadableStream({
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/backend/src/tokens/__tests__/clerkRequest.test.ts` around lines 7 -
18, The IIFE assigned to supportsStreamConstruction should have an explicit
boolean return type for clarity; update the constant declaration for
supportsStreamConstruction (the immediately-invoked function expression that
constructs a ReadableStream) to include a : boolean return type annotation so
the intent is documented and the inferred type is explicit.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/backend/src/tokens/__tests__/clerkRequest.test.ts`:
- Around line 7-18: The IIFE assigned to supportsStreamConstruction should have
an explicit boolean return type for clarity; update the constant declaration for
supportsStreamConstruction (the immediately-invoked function expression that
constructs a ReadableStream) to include a : boolean return type annotation so
the intent is documented and the inferred type is explicit.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 1cd5ed60-34a6-444e-b621-8de615e4db09

📥 Commits

Reviewing files that changed from the base of the PR and between 87212c5 and b21dca3.

📒 Files selected for processing (3)
  • .changeset/clerkrequest-omit-body.md
  • packages/backend/src/tokens/__tests__/clerkRequest.test.ts
  • packages/backend/src/tokens/clerkRequest.ts
🚧 Files skipped from review as they are similar to previous changes (2)
  • packages/backend/src/tokens/clerkRequest.ts
  • .changeset/clerkrequest-omit-body.md

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good! thanks for fixing 🫡

@jacekradko
jacekradko merged commit ff0cfef into mainJun 1, 2026
45 checks passed
@jacekradko
jacekradko deleted the jacek/fix-clerkrequest-body-consume branch June 1, 2026 16:31
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ClerkRequest constructor consumes request body, breaking downstream body reads in non-native Request environments

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(backend): stop authenticateRequest from consuming the request body by jacekradko · Pull Request #8708 · clerk/javascript · GitHub
Skip to content

fix(backend): stop authenticateRequest from consuming the request body - #8708

Merged
jacekradko merged 1 commit into
mainfrom
jacek/fix-clerkrequest-body-consume
Jun 1, 2026
Merged

fix(backend): stop authenticateRequest from consuming the request body#8708
jacekradko merged 1 commit into
mainfrom
jacek/fix-clerkrequest-body-consume

Conversation

@jacekradko

Copy link
Copy Markdown
Contributor

ClerkRequest clones the incoming request to read headers, cookies, and URL, but the clone was also forwarding the body. On Node/undici that body is a single-use stream shared with the original, so once anything reads the clone the original throws "Body is unusable" downstream (#8305, e.g. a Hono POST handler calling c.req.json()).

The clone now hides body next to signal in the existing Proxy. I kept the Proxy rather than an explicit RequestInit on purpose: that shape was reverted in e9f8d1a because eagerly reading cache breaks Cloudflare Workers. Auth never touches the body, so dropping it from the clone is safe. The retains the body test asserted the old behavior and is now a streaming-body regression test.

Closes#8305.

@changeset-bot

changeset-botBot commented May 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b21dca3

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 10 packages
NameType
@clerk/backendPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 30, 2026 2:26am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

Snapi: no API changes detected in @clerk/backend, @clerk/clerk-js, @clerk/nextjs, @clerk/react, @clerk/shared, @clerk/ui.

@pkg-pr-new

pkg-pr-newBot commented May 30, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8708

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8708

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8708

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8708

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8708

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8708

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8708

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8708

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8708

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8708

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8708

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8708

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8708

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8708

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8708

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8708

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8708

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8708

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8708

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8708

commit: b21dca3

@coderabbitai

coderabbitaiBot commented May 30, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR fixes a bug where ClerkRequest was consuming the incoming HTTP request body stream, preventing downstream handlers from reading it in Node.js environments. The implementation expands inline documentation explaining the Proxy-based approach to lazy property access that preserves the body. The test is updated to verify the original request remains readable after constructing a Clerk request, and a changeset entry documents the fix for @clerk/backend.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and specifically describes the main change: stopping authenticateRequest from consuming the request body, which matches the core objective of the PR.
Description check✅ PassedThe description is directly related to the changeset, explaining the problem (body consumption), the solution (hiding body in the Proxy), and referencing issue #8305.
Linked Issues check✅ PassedThe PR fully addresses issue #8305 by preventing body transfer in ClerkRequest's constructor via Proxy-based hiding, avoiding downstream body read failures (#8305).
Out of Scope Changes check✅ PassedAll changes are directly scoped to fixing the body consumption issue: test updates, implementation comment clarification, and changeset entry.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/backend/src/tokens/__tests__/clerkRequest.test.ts (1)

7-18: 💤 Low value

Consider adding an explicit return type annotation for clarity.

While the return type is easily inferred as boolean, adding an explicit annotation would improve readability and document the intent.

📝 Optional enhancement
-const supportsStreamConstruction = (() => {+const supportsStreamConstruction = ((): boolean => {
try {
new ReadableStream({
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/backend/src/tokens/__tests__/clerkRequest.test.ts` around lines 7 -
18, The IIFE assigned to supportsStreamConstruction should have an explicit
boolean return type for clarity; update the constant declaration for
supportsStreamConstruction (the immediately-invoked function expression that
constructs a ReadableStream) to include a : boolean return type annotation so
the intent is documented and the inferred type is explicit.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/backend/src/tokens/__tests__/clerkRequest.test.ts`:
- Around line 7-18: The IIFE assigned to supportsStreamConstruction should have
an explicit boolean return type for clarity; update the constant declaration for
supportsStreamConstruction (the immediately-invoked function expression that
constructs a ReadableStream) to include a : boolean return type annotation so
the intent is documented and the inferred type is explicit.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 1cd5ed60-34a6-444e-b621-8de615e4db09

📥 Commits

Reviewing files that changed from the base of the PR and between 87212c5 and b21dca3.

📒 Files selected for processing (3)
  • .changeset/clerkrequest-omit-body.md
  • packages/backend/src/tokens/__tests__/clerkRequest.test.ts
  • packages/backend/src/tokens/clerkRequest.ts
🚧 Files skipped from review as they are similar to previous changes (2)
  • packages/backend/src/tokens/clerkRequest.ts
  • .changeset/clerkrequest-omit-body.md

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good! thanks for fixing 🫡

@jacekradko
jacekradko merged commit ff0cfef into mainJun 1, 2026
45 checks passed
@jacekradko
jacekradko deleted the jacek/fix-clerkrequest-body-consume branch June 1, 2026 16:31
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ClerkRequest constructor consumes request body, breaking downstream body reads in non-native Request environments

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(backend): stop authenticateRequest from consuming the request body by jacekradko · Pull Request #8708 · clerk/javascript · GitHub
Skip to content

fix(backend): stop authenticateRequest from consuming the request body - #8708

Merged
jacekradko merged 1 commit into
mainfrom
jacek/fix-clerkrequest-body-consume
Jun 1, 2026
Merged

fix(backend): stop authenticateRequest from consuming the request body#8708
jacekradko merged 1 commit into
mainfrom
jacek/fix-clerkrequest-body-consume

Conversation

@jacekradko

Copy link
Copy Markdown
Contributor

ClerkRequest clones the incoming request to read headers, cookies, and URL, but the clone was also forwarding the body. On Node/undici that body is a single-use stream shared with the original, so once anything reads the clone the original throws "Body is unusable" downstream (#8305, e.g. a Hono POST handler calling c.req.json()).

The clone now hides body next to signal in the existing Proxy. I kept the Proxy rather than an explicit RequestInit on purpose: that shape was reverted in e9f8d1a because eagerly reading cache breaks Cloudflare Workers. Auth never touches the body, so dropping it from the clone is safe. The retains the body test asserted the old behavior and is now a streaming-body regression test.

Closes#8305.

@changeset-bot

changeset-botBot commented May 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b21dca3

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 10 packages
NameType
@clerk/backendPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 30, 2026 2:26am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

Snapi: no API changes detected in @clerk/backend, @clerk/clerk-js, @clerk/nextjs, @clerk/react, @clerk/shared, @clerk/ui.

@pkg-pr-new

pkg-pr-newBot commented May 30, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8708

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8708

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8708

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8708

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8708

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8708

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8708

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8708

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8708

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8708

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8708

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8708

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8708

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8708

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8708

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8708

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8708

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8708

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8708

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8708

commit: b21dca3

@coderabbitai

coderabbitaiBot commented May 30, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR fixes a bug where ClerkRequest was consuming the incoming HTTP request body stream, preventing downstream handlers from reading it in Node.js environments. The implementation expands inline documentation explaining the Proxy-based approach to lazy property access that preserves the body. The test is updated to verify the original request remains readable after constructing a Clerk request, and a changeset entry documents the fix for @clerk/backend.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and specifically describes the main change: stopping authenticateRequest from consuming the request body, which matches the core objective of the PR.
Description check✅ PassedThe description is directly related to the changeset, explaining the problem (body consumption), the solution (hiding body in the Proxy), and referencing issue #8305.
Linked Issues check✅ PassedThe PR fully addresses issue #8305 by preventing body transfer in ClerkRequest's constructor via Proxy-based hiding, avoiding downstream body read failures (#8305).
Out of Scope Changes check✅ PassedAll changes are directly scoped to fixing the body consumption issue: test updates, implementation comment clarification, and changeset entry.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/backend/src/tokens/__tests__/clerkRequest.test.ts (1)

7-18: 💤 Low value

Consider adding an explicit return type annotation for clarity.

While the return type is easily inferred as boolean, adding an explicit annotation would improve readability and document the intent.

📝 Optional enhancement
-const supportsStreamConstruction = (() => {+const supportsStreamConstruction = ((): boolean => {
try {
new ReadableStream({
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/backend/src/tokens/__tests__/clerkRequest.test.ts` around lines 7 -
18, The IIFE assigned to supportsStreamConstruction should have an explicit
boolean return type for clarity; update the constant declaration for
supportsStreamConstruction (the immediately-invoked function expression that
constructs a ReadableStream) to include a : boolean return type annotation so
the intent is documented and the inferred type is explicit.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/backend/src/tokens/__tests__/clerkRequest.test.ts`:
- Around line 7-18: The IIFE assigned to supportsStreamConstruction should have
an explicit boolean return type for clarity; update the constant declaration for
supportsStreamConstruction (the immediately-invoked function expression that
constructs a ReadableStream) to include a : boolean return type annotation so
the intent is documented and the inferred type is explicit.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 1cd5ed60-34a6-444e-b621-8de615e4db09

📥 Commits

Reviewing files that changed from the base of the PR and between 87212c5 and b21dca3.

📒 Files selected for processing (3)
  • .changeset/clerkrequest-omit-body.md
  • packages/backend/src/tokens/__tests__/clerkRequest.test.ts
  • packages/backend/src/tokens/clerkRequest.ts
🚧 Files skipped from review as they are similar to previous changes (2)
  • packages/backend/src/tokens/clerkRequest.ts
  • .changeset/clerkrequest-omit-body.md

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good! thanks for fixing 🫡

@jacekradko
jacekradko merged commit ff0cfef into mainJun 1, 2026
45 checks passed
@jacekradko
jacekradko deleted the jacek/fix-clerkrequest-body-consume branch June 1, 2026 16:31
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ClerkRequest constructor consumes request body, breaking downstream body reads in non-native Request environments

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(backend): stop authenticateRequest from consuming the request body by jacekradko · Pull Request #8708 · clerk/javascript · GitHub
Skip to content

fix(backend): stop authenticateRequest from consuming the request body - #8708

Merged
jacekradko merged 1 commit into
mainfrom
jacek/fix-clerkrequest-body-consume
Jun 1, 2026
Merged

fix(backend): stop authenticateRequest from consuming the request body#8708
jacekradko merged 1 commit into
mainfrom
jacek/fix-clerkrequest-body-consume

Conversation

@jacekradko

Copy link
Copy Markdown
Contributor

ClerkRequest clones the incoming request to read headers, cookies, and URL, but the clone was also forwarding the body. On Node/undici that body is a single-use stream shared with the original, so once anything reads the clone the original throws "Body is unusable" downstream (#8305, e.g. a Hono POST handler calling c.req.json()).

The clone now hides body next to signal in the existing Proxy. I kept the Proxy rather than an explicit RequestInit on purpose: that shape was reverted in e9f8d1a because eagerly reading cache breaks Cloudflare Workers. Auth never touches the body, so dropping it from the clone is safe. The retains the body test asserted the old behavior and is now a streaming-body regression test.

Closes#8305.

@changeset-bot

changeset-botBot commented May 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b21dca3

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 10 packages
NameType
@clerk/backendPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 30, 2026 2:26am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

Snapi: no API changes detected in @clerk/backend, @clerk/clerk-js, @clerk/nextjs, @clerk/react, @clerk/shared, @clerk/ui.

@pkg-pr-new

pkg-pr-newBot commented May 30, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8708

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8708

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8708

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8708

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8708

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8708

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8708

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8708

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8708

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8708

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8708

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8708

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8708

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8708

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8708

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8708

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8708

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8708

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8708

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8708

commit: b21dca3

@coderabbitai

coderabbitaiBot commented May 30, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR fixes a bug where ClerkRequest was consuming the incoming HTTP request body stream, preventing downstream handlers from reading it in Node.js environments. The implementation expands inline documentation explaining the Proxy-based approach to lazy property access that preserves the body. The test is updated to verify the original request remains readable after constructing a Clerk request, and a changeset entry documents the fix for @clerk/backend.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and specifically describes the main change: stopping authenticateRequest from consuming the request body, which matches the core objective of the PR.
Description check✅ PassedThe description is directly related to the changeset, explaining the problem (body consumption), the solution (hiding body in the Proxy), and referencing issue #8305.
Linked Issues check✅ PassedThe PR fully addresses issue #8305 by preventing body transfer in ClerkRequest's constructor via Proxy-based hiding, avoiding downstream body read failures (#8305).
Out of Scope Changes check✅ PassedAll changes are directly scoped to fixing the body consumption issue: test updates, implementation comment clarification, and changeset entry.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/backend/src/tokens/__tests__/clerkRequest.test.ts (1)

7-18: 💤 Low value

Consider adding an explicit return type annotation for clarity.

While the return type is easily inferred as boolean, adding an explicit annotation would improve readability and document the intent.

📝 Optional enhancement
-const supportsStreamConstruction = (() => {+const supportsStreamConstruction = ((): boolean => {
try {
new ReadableStream({
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/backend/src/tokens/__tests__/clerkRequest.test.ts` around lines 7 -
18, The IIFE assigned to supportsStreamConstruction should have an explicit
boolean return type for clarity; update the constant declaration for
supportsStreamConstruction (the immediately-invoked function expression that
constructs a ReadableStream) to include a : boolean return type annotation so
the intent is documented and the inferred type is explicit.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/backend/src/tokens/__tests__/clerkRequest.test.ts`:
- Around line 7-18: The IIFE assigned to supportsStreamConstruction should have
an explicit boolean return type for clarity; update the constant declaration for
supportsStreamConstruction (the immediately-invoked function expression that
constructs a ReadableStream) to include a : boolean return type annotation so
the intent is documented and the inferred type is explicit.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 1cd5ed60-34a6-444e-b621-8de615e4db09

📥 Commits

Reviewing files that changed from the base of the PR and between 87212c5 and b21dca3.

📒 Files selected for processing (3)
  • .changeset/clerkrequest-omit-body.md
  • packages/backend/src/tokens/__tests__/clerkRequest.test.ts
  • packages/backend/src/tokens/clerkRequest.ts
🚧 Files skipped from review as they are similar to previous changes (2)
  • packages/backend/src/tokens/clerkRequest.ts
  • .changeset/clerkrequest-omit-body.md

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good! thanks for fixing 🫡

@jacekradko
jacekradko merged commit ff0cfef into mainJun 1, 2026
45 checks passed
@jacekradko
jacekradko deleted the jacek/fix-clerkrequest-body-consume branch June 1, 2026 16:31
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ClerkRequest constructor consumes request body, breaking downstream body reads in non-native Request environments

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix(backend): stop authenticateRequest from consuming the request body by jacekradko · Pull Request #8708 · clerk/javascript · GitHub
Skip to content

fix(backend): stop authenticateRequest from consuming the request body - #8708

Merged
jacekradko merged 1 commit into
mainfrom
jacek/fix-clerkrequest-body-consume
Jun 1, 2026
Merged

fix(backend): stop authenticateRequest from consuming the request body#8708
jacekradko merged 1 commit into
mainfrom
jacek/fix-clerkrequest-body-consume

Conversation

@jacekradko

Copy link
Copy Markdown
Contributor

ClerkRequest clones the incoming request to read headers, cookies, and URL, but the clone was also forwarding the body. On Node/undici that body is a single-use stream shared with the original, so once anything reads the clone the original throws "Body is unusable" downstream (#8305, e.g. a Hono POST handler calling c.req.json()).

The clone now hides body next to signal in the existing Proxy. I kept the Proxy rather than an explicit RequestInit on purpose: that shape was reverted in e9f8d1a because eagerly reading cache breaks Cloudflare Workers. Auth never touches the body, so dropping it from the clone is safe. The retains the body test asserted the old behavior and is now a streaming-body regression test.

Closes#8305.

@changeset-bot

changeset-botBot commented May 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b21dca3

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 10 packages
NameType
@clerk/backendPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 30, 2026 2:26am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

Snapi: no API changes detected in @clerk/backend, @clerk/clerk-js, @clerk/nextjs, @clerk/react, @clerk/shared, @clerk/ui.

@pkg-pr-new

pkg-pr-newBot commented May 30, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8708

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8708

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8708

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8708

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8708

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8708

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8708

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8708

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8708

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8708

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8708

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8708

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8708

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8708

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8708

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8708

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8708

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8708

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8708

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8708

commit: b21dca3

@coderabbitai

coderabbitaiBot commented May 30, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR fixes a bug where ClerkRequest was consuming the incoming HTTP request body stream, preventing downstream handlers from reading it in Node.js environments. The implementation expands inline documentation explaining the Proxy-based approach to lazy property access that preserves the body. The test is updated to verify the original request remains readable after constructing a Clerk request, and a changeset entry documents the fix for @clerk/backend.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly and specifically describes the main change: stopping authenticateRequest from consuming the request body, which matches the core objective of the PR.
Description check✅ PassedThe description is directly related to the changeset, explaining the problem (body consumption), the solution (hiding body in the Proxy), and referencing issue #8305.
Linked Issues check✅ PassedThe PR fully addresses issue #8305 by preventing body transfer in ClerkRequest's constructor via Proxy-based hiding, avoiding downstream body read failures (#8305).
Out of Scope Changes check✅ PassedAll changes are directly scoped to fixing the body consumption issue: test updates, implementation comment clarification, and changeset entry.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/backend/src/tokens/__tests__/clerkRequest.test.ts (1)

7-18: 💤 Low value

Consider adding an explicit return type annotation for clarity.

While the return type is easily inferred as boolean, adding an explicit annotation would improve readability and document the intent.

📝 Optional enhancement
-const supportsStreamConstruction = (() => {+const supportsStreamConstruction = ((): boolean => {
try {
new ReadableStream({
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/backend/src/tokens/__tests__/clerkRequest.test.ts` around lines 7 -
18, The IIFE assigned to supportsStreamConstruction should have an explicit
boolean return type for clarity; update the constant declaration for
supportsStreamConstruction (the immediately-invoked function expression that
constructs a ReadableStream) to include a : boolean return type annotation so
the intent is documented and the inferred type is explicit.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/backend/src/tokens/__tests__/clerkRequest.test.ts`:
- Around line 7-18: The IIFE assigned to supportsStreamConstruction should have
an explicit boolean return type for clarity; update the constant declaration for
supportsStreamConstruction (the immediately-invoked function expression that
constructs a ReadableStream) to include a : boolean return type annotation so
the intent is documented and the inferred type is explicit.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 1cd5ed60-34a6-444e-b621-8de615e4db09

📥 Commits

Reviewing files that changed from the base of the PR and between 87212c5 and b21dca3.

📒 Files selected for processing (3)
  • .changeset/clerkrequest-omit-body.md
  • packages/backend/src/tokens/__tests__/clerkRequest.test.ts
  • packages/backend/src/tokens/clerkRequest.ts
🚧 Files skipped from review as they are similar to previous changes (2)
  • packages/backend/src/tokens/clerkRequest.ts
  • .changeset/clerkrequest-omit-body.md

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good! thanks for fixing 🫡

@jacekradko
jacekradko merged commit ff0cfef into mainJun 1, 2026
45 checks passed
@jacekradko
jacekradko deleted the jacek/fix-clerkrequest-body-consume branch June 1, 2026 16:31
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ClerkRequest constructor consumes request body, breaking downstream body reads in non-native Request environments

2 participants

@jacekradko@wobsoriano