Skip to content

fix(ui): show user:org:read scope in OAuth Consent list - #8798

Merged
wobsoriano merged 1 commit into
mainfrom
jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent
Jun 10, 2026
Merged

fix(ui): show user:org:read scope in OAuth Consent list#8798
wobsoriano merged 1 commit into
mainfrom
jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent

Conversation

@jfoshee

@jfosheejfoshee commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

so that the user is made aware that they are sharing org information with 3rd party

Fixes USER-5442

The OAuth Consent dialog shows a list of scope descriptions so that the user is clearly informed about what they are granting access to. We were omitting the display of the user:org:read scope because we show an org selector in that case.

We determined that is not clear enough to users. Users should be explicitly informed that org information is being shared.

CleanShot 2026-06-10 at 09 50 06@2x

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes
    • Fixed OAuth consent scope display to show additional relevant scopes, including the user:org:read scope when available.

@changeset-bot

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 50f493e

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@vercel

vercelBot commented Jun 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 10, 2026 2:30pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

The OAuthConsent component's displayedScopes filter now excludes only offline_access, allowing user:org:read to be shown in the consent dialog; tests and a changeset entry were updated accordingly.

Changes

OAuth Consent Scope Display

Layer / File(s)Summary
Scope filtering logic
packages/ui/src/components/OAuthConsent/OAuthConsent.tsx
displayedScopes filter now excludes only OFFLINE_ACCESS_SCOPE, allowing USER_ORG_READ_SCOPE to be visible in the consent dialog when present.
Test expectation updates
packages/ui/src/components/OAuthConsent/__tests__/OAuthConsent.test.tsx
Org-selection scopes test updated to expect the Access your organizations description to be visible when user:org:read and memberships are present.
Release changeset
.changeset/brown-wolves-reply.md
Changeset updated to declare a patch release for @clerk/ui and note that the OAuth Consent dialog now shows the user:org:read scope description.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~5 minutes

Poem

A hop through the scopes, so clear and so bright,
The user can now see what's hidden from sight,
No user:org:read shall lurk in the shadows,
Transparency blooms through Clerk's UI meadows,
One little filter, one better display! 🐇✨

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately and concisely summarizes the main change: displaying the user:org:read scope in the OAuth Consent dialog. It directly reflects the primary modification across all changed files.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actionsBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-10T14:33:13.827Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

Note
Break Check could not snapshot 3 subpaths; the diff below excludes them.

  • @clerk/astro ./env: Internal Error: Unable to determine module for: /home/runner/_work/javascript/javascript/packages/astro/env.d.ts You have encountered a software defect. Please consider reporting the issue to the maintainers of this application.
  • @clerk/shared ./cookie: Internal Error: Unable to follow symbol for "Cookies" You have encountered a software defect. Please consider reporting the issue to the maintainers of this application.
  • @clerk/testing ./cypress: Symbol not found for identifier: Cypress

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 46a4622.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/ui/src/components/OAuthConsent/OAuthConsent.tsx`:
- Line 145: The test expectation is outdated because OAuthConsent now computes
displayedScopes by filtering only OFFLINE_ACCESS_SCOPE in the OAuthConsent
component (variable displayedScopes inside OAuthConsent), so the scope with
description "Access your organizations" (user:org:read) is rendered; update the
test named "does not display user:org:read in the scopes list" to assert that
the text 'Access your organizations' is present (e.g.,
expect(queryByText('Access your organizations')).not.toBeNull() or
toBeInTheDocument()) instead of asserting it is null, and remove any assertions
that assume user:org:read is hidden.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: fb7b4ea4-9e4d-4593-9e45-371b390c19eb

📥 Commits

Reviewing files that changed from the base of the PR and between 1028d82 and 50f493e.

📒 Files selected for processing (1)
  • packages/ui/src/components/OAuthConsent/OAuthConsent.tsx

Comment threadpackages/ui/src/components/OAuthConsent/OAuthConsent.tsx
@pkg-pr-new

pkg-pr-newBot commented Jun 10, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8798

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8798

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8798

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8798

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8798

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8798

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8798

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8798

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8798

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8798

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8798

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8798

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8798

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8798

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8798

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8798

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8798

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8798

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8798

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8798

commit: 46a4622

so that the user is made aware that they are sharing org information with 3rd party
Fixes USER-5442
The OAuth Consent dialog shows a list of scope descriptions so that the user is clearly informed about what they are granting access to. We were omitting the display of the `user:org:read` scope because we show an org selector in that case.
We determined that is not clear enough to users. Users should be explicitly informed that org information is being shared.
@jfoshee
jfosheeforce-pushed the jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent branch from 50f493e to 46a4622CompareJune 10, 2026 14:29
@jfoshee
jfoshee requested a review from wobsorianoJune 10, 2026 14:51

await waitFor(() => {
expect(queryByText('Access your organizations')).toBeNull();
expect(queryByText('Access your organizations')).toBeVisible();

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This isn't the description that was in the screenshot? But the test passes so I'm guessing this is some sort of internal description we also have.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah it's from a mock setup

@wobsoriano
wobsoriano merged commit df4619f into mainJun 10, 2026
56 checks passed
@wobsoriano
wobsoriano deleted the jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent branch June 10, 2026 15:03
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jfoshee@wobsoriano@dmoerner
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(ui): show user:org:read scope in OAuth Consent list by jfoshee · Pull Request #8798 · clerk/javascript · GitHub
Skip to content

fix(ui): show user:org:read scope in OAuth Consent list - #8798

Merged
wobsoriano merged 1 commit into
mainfrom
jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent
Jun 10, 2026
Merged

fix(ui): show user:org:read scope in OAuth Consent list#8798
wobsoriano merged 1 commit into
mainfrom
jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent

Conversation

@jfoshee

@jfosheejfoshee commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

so that the user is made aware that they are sharing org information with 3rd party

Fixes USER-5442

The OAuth Consent dialog shows a list of scope descriptions so that the user is clearly informed about what they are granting access to. We were omitting the display of the user:org:read scope because we show an org selector in that case.

We determined that is not clear enough to users. Users should be explicitly informed that org information is being shared.

CleanShot 2026-06-10 at 09 50 06@2x

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes
    • Fixed OAuth consent scope display to show additional relevant scopes, including the user:org:read scope when available.

@changeset-bot

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 50f493e

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@vercel

vercelBot commented Jun 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 10, 2026 2:30pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

The OAuthConsent component's displayedScopes filter now excludes only offline_access, allowing user:org:read to be shown in the consent dialog; tests and a changeset entry were updated accordingly.

Changes

OAuth Consent Scope Display

Layer / File(s)Summary
Scope filtering logic
packages/ui/src/components/OAuthConsent/OAuthConsent.tsx
displayedScopes filter now excludes only OFFLINE_ACCESS_SCOPE, allowing USER_ORG_READ_SCOPE to be visible in the consent dialog when present.
Test expectation updates
packages/ui/src/components/OAuthConsent/__tests__/OAuthConsent.test.tsx
Org-selection scopes test updated to expect the Access your organizations description to be visible when user:org:read and memberships are present.
Release changeset
.changeset/brown-wolves-reply.md
Changeset updated to declare a patch release for @clerk/ui and note that the OAuth Consent dialog now shows the user:org:read scope description.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~5 minutes

Poem

A hop through the scopes, so clear and so bright,
The user can now see what's hidden from sight,
No user:org:read shall lurk in the shadows,
Transparency blooms through Clerk's UI meadows,
One little filter, one better display! 🐇✨

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately and concisely summarizes the main change: displaying the user:org:read scope in the OAuth Consent dialog. It directly reflects the primary modification across all changed files.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actionsBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-10T14:33:13.827Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

Note
Break Check could not snapshot 3 subpaths; the diff below excludes them.

  • @clerk/astro ./env: Internal Error: Unable to determine module for: /home/runner/_work/javascript/javascript/packages/astro/env.d.ts You have encountered a software defect. Please consider reporting the issue to the maintainers of this application.
  • @clerk/shared ./cookie: Internal Error: Unable to follow symbol for "Cookies" You have encountered a software defect. Please consider reporting the issue to the maintainers of this application.
  • @clerk/testing ./cypress: Symbol not found for identifier: Cypress

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 46a4622.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/ui/src/components/OAuthConsent/OAuthConsent.tsx`:
- Line 145: The test expectation is outdated because OAuthConsent now computes
displayedScopes by filtering only OFFLINE_ACCESS_SCOPE in the OAuthConsent
component (variable displayedScopes inside OAuthConsent), so the scope with
description "Access your organizations" (user:org:read) is rendered; update the
test named "does not display user:org:read in the scopes list" to assert that
the text 'Access your organizations' is present (e.g.,
expect(queryByText('Access your organizations')).not.toBeNull() or
toBeInTheDocument()) instead of asserting it is null, and remove any assertions
that assume user:org:read is hidden.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: fb7b4ea4-9e4d-4593-9e45-371b390c19eb

📥 Commits

Reviewing files that changed from the base of the PR and between 1028d82 and 50f493e.

📒 Files selected for processing (1)
  • packages/ui/src/components/OAuthConsent/OAuthConsent.tsx

Comment threadpackages/ui/src/components/OAuthConsent/OAuthConsent.tsx
@pkg-pr-new

pkg-pr-newBot commented Jun 10, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8798

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8798

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8798

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8798

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8798

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8798

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8798

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8798

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8798

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8798

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8798

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8798

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8798

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8798

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8798

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8798

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8798

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8798

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8798

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8798

commit: 46a4622

so that the user is made aware that they are sharing org information with 3rd party
Fixes USER-5442
The OAuth Consent dialog shows a list of scope descriptions so that the user is clearly informed about what they are granting access to. We were omitting the display of the `user:org:read` scope because we show an org selector in that case.
We determined that is not clear enough to users. Users should be explicitly informed that org information is being shared.
@jfoshee
jfosheeforce-pushed the jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent branch from 50f493e to 46a4622CompareJune 10, 2026 14:29
@jfoshee
jfoshee requested a review from wobsorianoJune 10, 2026 14:51

await waitFor(() => {
expect(queryByText('Access your organizations')).toBeNull();
expect(queryByText('Access your organizations')).toBeVisible();

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This isn't the description that was in the screenshot? But the test passes so I'm guessing this is some sort of internal description we also have.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah it's from a mock setup

@wobsoriano
wobsoriano merged commit df4619f into mainJun 10, 2026
56 checks passed
@wobsoriano
wobsoriano deleted the jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent branch June 10, 2026 15:03
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jfoshee@wobsoriano@dmoerner
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(ui): show user:org:read scope in OAuth Consent list by jfoshee · Pull Request #8798 · clerk/javascript · GitHub
Skip to content

fix(ui): show user:org:read scope in OAuth Consent list - #8798

Merged
wobsoriano merged 1 commit into
mainfrom
jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent
Jun 10, 2026
Merged

fix(ui): show user:org:read scope in OAuth Consent list#8798
wobsoriano merged 1 commit into
mainfrom
jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent

Conversation

@jfoshee

@jfosheejfoshee commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

so that the user is made aware that they are sharing org information with 3rd party

Fixes USER-5442

The OAuth Consent dialog shows a list of scope descriptions so that the user is clearly informed about what they are granting access to. We were omitting the display of the user:org:read scope because we show an org selector in that case.

We determined that is not clear enough to users. Users should be explicitly informed that org information is being shared.

CleanShot 2026-06-10 at 09 50 06@2x

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes
    • Fixed OAuth consent scope display to show additional relevant scopes, including the user:org:read scope when available.

@changeset-bot

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 50f493e

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@vercel

vercelBot commented Jun 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 10, 2026 2:30pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

The OAuthConsent component's displayedScopes filter now excludes only offline_access, allowing user:org:read to be shown in the consent dialog; tests and a changeset entry were updated accordingly.

Changes

OAuth Consent Scope Display

Layer / File(s)Summary
Scope filtering logic
packages/ui/src/components/OAuthConsent/OAuthConsent.tsx
displayedScopes filter now excludes only OFFLINE_ACCESS_SCOPE, allowing USER_ORG_READ_SCOPE to be visible in the consent dialog when present.
Test expectation updates
packages/ui/src/components/OAuthConsent/__tests__/OAuthConsent.test.tsx
Org-selection scopes test updated to expect the Access your organizations description to be visible when user:org:read and memberships are present.
Release changeset
.changeset/brown-wolves-reply.md
Changeset updated to declare a patch release for @clerk/ui and note that the OAuth Consent dialog now shows the user:org:read scope description.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~5 minutes

Poem

A hop through the scopes, so clear and so bright,
The user can now see what's hidden from sight,
No user:org:read shall lurk in the shadows,
Transparency blooms through Clerk's UI meadows,
One little filter, one better display! 🐇✨

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately and concisely summarizes the main change: displaying the user:org:read scope in the OAuth Consent dialog. It directly reflects the primary modification across all changed files.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actionsBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-10T14:33:13.827Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

Note
Break Check could not snapshot 3 subpaths; the diff below excludes them.

  • @clerk/astro ./env: Internal Error: Unable to determine module for: /home/runner/_work/javascript/javascript/packages/astro/env.d.ts You have encountered a software defect. Please consider reporting the issue to the maintainers of this application.
  • @clerk/shared ./cookie: Internal Error: Unable to follow symbol for "Cookies" You have encountered a software defect. Please consider reporting the issue to the maintainers of this application.
  • @clerk/testing ./cypress: Symbol not found for identifier: Cypress

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 46a4622.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/ui/src/components/OAuthConsent/OAuthConsent.tsx`:
- Line 145: The test expectation is outdated because OAuthConsent now computes
displayedScopes by filtering only OFFLINE_ACCESS_SCOPE in the OAuthConsent
component (variable displayedScopes inside OAuthConsent), so the scope with
description "Access your organizations" (user:org:read) is rendered; update the
test named "does not display user:org:read in the scopes list" to assert that
the text 'Access your organizations' is present (e.g.,
expect(queryByText('Access your organizations')).not.toBeNull() or
toBeInTheDocument()) instead of asserting it is null, and remove any assertions
that assume user:org:read is hidden.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: fb7b4ea4-9e4d-4593-9e45-371b390c19eb

📥 Commits

Reviewing files that changed from the base of the PR and between 1028d82 and 50f493e.

📒 Files selected for processing (1)
  • packages/ui/src/components/OAuthConsent/OAuthConsent.tsx

Comment threadpackages/ui/src/components/OAuthConsent/OAuthConsent.tsx
@pkg-pr-new

pkg-pr-newBot commented Jun 10, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8798

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8798

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8798

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8798

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8798

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8798

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8798

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8798

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8798

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8798

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8798

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8798

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8798

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8798

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8798

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8798

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8798

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8798

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8798

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8798

commit: 46a4622

so that the user is made aware that they are sharing org information with 3rd party
Fixes USER-5442
The OAuth Consent dialog shows a list of scope descriptions so that the user is clearly informed about what they are granting access to. We were omitting the display of the `user:org:read` scope because we show an org selector in that case.
We determined that is not clear enough to users. Users should be explicitly informed that org information is being shared.
@jfoshee
jfosheeforce-pushed the jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent branch from 50f493e to 46a4622CompareJune 10, 2026 14:29
@jfoshee
jfoshee requested a review from wobsorianoJune 10, 2026 14:51

await waitFor(() => {
expect(queryByText('Access your organizations')).toBeNull();
expect(queryByText('Access your organizations')).toBeVisible();

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This isn't the description that was in the screenshot? But the test passes so I'm guessing this is some sort of internal description we also have.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah it's from a mock setup

@wobsoriano
wobsoriano merged commit df4619f into mainJun 10, 2026
56 checks passed
@wobsoriano
wobsoriano deleted the jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent branch June 10, 2026 15:03
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jfoshee@wobsoriano@dmoerner
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(ui): show user:org:read scope in OAuth Consent list by jfoshee · Pull Request #8798 · clerk/javascript · GitHub
Skip to content

fix(ui): show user:org:read scope in OAuth Consent list - #8798

Merged
wobsoriano merged 1 commit into
mainfrom
jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent
Jun 10, 2026
Merged

fix(ui): show user:org:read scope in OAuth Consent list#8798
wobsoriano merged 1 commit into
mainfrom
jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent

Conversation

@jfoshee

@jfosheejfoshee commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

so that the user is made aware that they are sharing org information with 3rd party

Fixes USER-5442

The OAuth Consent dialog shows a list of scope descriptions so that the user is clearly informed about what they are granting access to. We were omitting the display of the user:org:read scope because we show an org selector in that case.

We determined that is not clear enough to users. Users should be explicitly informed that org information is being shared.

CleanShot 2026-06-10 at 09 50 06@2x

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes
    • Fixed OAuth consent scope display to show additional relevant scopes, including the user:org:read scope when available.

@changeset-bot

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 50f493e

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@vercel

vercelBot commented Jun 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 10, 2026 2:30pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

The OAuthConsent component's displayedScopes filter now excludes only offline_access, allowing user:org:read to be shown in the consent dialog; tests and a changeset entry were updated accordingly.

Changes

OAuth Consent Scope Display

Layer / File(s)Summary
Scope filtering logic
packages/ui/src/components/OAuthConsent/OAuthConsent.tsx
displayedScopes filter now excludes only OFFLINE_ACCESS_SCOPE, allowing USER_ORG_READ_SCOPE to be visible in the consent dialog when present.
Test expectation updates
packages/ui/src/components/OAuthConsent/__tests__/OAuthConsent.test.tsx
Org-selection scopes test updated to expect the Access your organizations description to be visible when user:org:read and memberships are present.
Release changeset
.changeset/brown-wolves-reply.md
Changeset updated to declare a patch release for @clerk/ui and note that the OAuth Consent dialog now shows the user:org:read scope description.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~5 minutes

Poem

A hop through the scopes, so clear and so bright,
The user can now see what's hidden from sight,
No user:org:read shall lurk in the shadows,
Transparency blooms through Clerk's UI meadows,
One little filter, one better display! 🐇✨

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately and concisely summarizes the main change: displaying the user:org:read scope in the OAuth Consent dialog. It directly reflects the primary modification across all changed files.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actionsBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-10T14:33:13.827Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

Note
Break Check could not snapshot 3 subpaths; the diff below excludes them.

  • @clerk/astro ./env: Internal Error: Unable to determine module for: /home/runner/_work/javascript/javascript/packages/astro/env.d.ts You have encountered a software defect. Please consider reporting the issue to the maintainers of this application.
  • @clerk/shared ./cookie: Internal Error: Unable to follow symbol for "Cookies" You have encountered a software defect. Please consider reporting the issue to the maintainers of this application.
  • @clerk/testing ./cypress: Symbol not found for identifier: Cypress

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 46a4622.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/ui/src/components/OAuthConsent/OAuthConsent.tsx`:
- Line 145: The test expectation is outdated because OAuthConsent now computes
displayedScopes by filtering only OFFLINE_ACCESS_SCOPE in the OAuthConsent
component (variable displayedScopes inside OAuthConsent), so the scope with
description "Access your organizations" (user:org:read) is rendered; update the
test named "does not display user:org:read in the scopes list" to assert that
the text 'Access your organizations' is present (e.g.,
expect(queryByText('Access your organizations')).not.toBeNull() or
toBeInTheDocument()) instead of asserting it is null, and remove any assertions
that assume user:org:read is hidden.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: fb7b4ea4-9e4d-4593-9e45-371b390c19eb

📥 Commits

Reviewing files that changed from the base of the PR and between 1028d82 and 50f493e.

📒 Files selected for processing (1)
  • packages/ui/src/components/OAuthConsent/OAuthConsent.tsx

Comment threadpackages/ui/src/components/OAuthConsent/OAuthConsent.tsx
@pkg-pr-new

pkg-pr-newBot commented Jun 10, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8798

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8798

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8798

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8798

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8798

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8798

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8798

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8798

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8798

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8798

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8798

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8798

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8798

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8798

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8798

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8798

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8798

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8798

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8798

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8798

commit: 46a4622

so that the user is made aware that they are sharing org information with 3rd party
Fixes USER-5442
The OAuth Consent dialog shows a list of scope descriptions so that the user is clearly informed about what they are granting access to. We were omitting the display of the `user:org:read` scope because we show an org selector in that case.
We determined that is not clear enough to users. Users should be explicitly informed that org information is being shared.
@jfoshee
jfosheeforce-pushed the jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent branch from 50f493e to 46a4622CompareJune 10, 2026 14:29
@jfoshee
jfoshee requested a review from wobsorianoJune 10, 2026 14:51

await waitFor(() => {
expect(queryByText('Access your organizations')).toBeNull();
expect(queryByText('Access your organizations')).toBeVisible();

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This isn't the description that was in the screenshot? But the test passes so I'm guessing this is some sort of internal description we also have.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah it's from a mock setup

@wobsoriano
wobsoriano merged commit df4619f into mainJun 10, 2026
56 checks passed
@wobsoriano
wobsoriano deleted the jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent branch June 10, 2026 15:03
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jfoshee@wobsoriano@dmoerner
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(ui): show user:org:read scope in OAuth Consent list by jfoshee · Pull Request #8798 · clerk/javascript · GitHub
Skip to content

fix(ui): show user:org:read scope in OAuth Consent list - #8798

Merged
wobsoriano merged 1 commit into
mainfrom
jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent
Jun 10, 2026
Merged

fix(ui): show user:org:read scope in OAuth Consent list#8798
wobsoriano merged 1 commit into
mainfrom
jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent

Conversation

@jfoshee

@jfosheejfoshee commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

so that the user is made aware that they are sharing org information with 3rd party

Fixes USER-5442

The OAuth Consent dialog shows a list of scope descriptions so that the user is clearly informed about what they are granting access to. We were omitting the display of the user:org:read scope because we show an org selector in that case.

We determined that is not clear enough to users. Users should be explicitly informed that org information is being shared.

CleanShot 2026-06-10 at 09 50 06@2x

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes
    • Fixed OAuth consent scope display to show additional relevant scopes, including the user:org:read scope when available.

@changeset-bot

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 50f493e

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@vercel

vercelBot commented Jun 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 10, 2026 2:30pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

The OAuthConsent component's displayedScopes filter now excludes only offline_access, allowing user:org:read to be shown in the consent dialog; tests and a changeset entry were updated accordingly.

Changes

OAuth Consent Scope Display

Layer / File(s)Summary
Scope filtering logic
packages/ui/src/components/OAuthConsent/OAuthConsent.tsx
displayedScopes filter now excludes only OFFLINE_ACCESS_SCOPE, allowing USER_ORG_READ_SCOPE to be visible in the consent dialog when present.
Test expectation updates
packages/ui/src/components/OAuthConsent/__tests__/OAuthConsent.test.tsx
Org-selection scopes test updated to expect the Access your organizations description to be visible when user:org:read and memberships are present.
Release changeset
.changeset/brown-wolves-reply.md
Changeset updated to declare a patch release for @clerk/ui and note that the OAuth Consent dialog now shows the user:org:read scope description.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~5 minutes

Poem

A hop through the scopes, so clear and so bright,
The user can now see what's hidden from sight,
No user:org:read shall lurk in the shadows,
Transparency blooms through Clerk's UI meadows,
One little filter, one better display! 🐇✨

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately and concisely summarizes the main change: displaying the user:org:read scope in the OAuth Consent dialog. It directly reflects the primary modification across all changed files.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actionsBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-10T14:33:13.827Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

Note
Break Check could not snapshot 3 subpaths; the diff below excludes them.

  • @clerk/astro ./env: Internal Error: Unable to determine module for: /home/runner/_work/javascript/javascript/packages/astro/env.d.ts You have encountered a software defect. Please consider reporting the issue to the maintainers of this application.
  • @clerk/shared ./cookie: Internal Error: Unable to follow symbol for "Cookies" You have encountered a software defect. Please consider reporting the issue to the maintainers of this application.
  • @clerk/testing ./cypress: Symbol not found for identifier: Cypress

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 46a4622.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/ui/src/components/OAuthConsent/OAuthConsent.tsx`:
- Line 145: The test expectation is outdated because OAuthConsent now computes
displayedScopes by filtering only OFFLINE_ACCESS_SCOPE in the OAuthConsent
component (variable displayedScopes inside OAuthConsent), so the scope with
description "Access your organizations" (user:org:read) is rendered; update the
test named "does not display user:org:read in the scopes list" to assert that
the text 'Access your organizations' is present (e.g.,
expect(queryByText('Access your organizations')).not.toBeNull() or
toBeInTheDocument()) instead of asserting it is null, and remove any assertions
that assume user:org:read is hidden.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: fb7b4ea4-9e4d-4593-9e45-371b390c19eb

📥 Commits

Reviewing files that changed from the base of the PR and between 1028d82 and 50f493e.

📒 Files selected for processing (1)
  • packages/ui/src/components/OAuthConsent/OAuthConsent.tsx

Comment threadpackages/ui/src/components/OAuthConsent/OAuthConsent.tsx
@pkg-pr-new

pkg-pr-newBot commented Jun 10, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8798

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8798

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8798

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8798

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8798

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8798

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8798

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8798

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8798

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8798

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8798

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8798

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8798

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8798

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8798

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8798

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8798

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8798

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8798

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8798

commit: 46a4622

so that the user is made aware that they are sharing org information with 3rd party
Fixes USER-5442
The OAuth Consent dialog shows a list of scope descriptions so that the user is clearly informed about what they are granting access to. We were omitting the display of the `user:org:read` scope because we show an org selector in that case.
We determined that is not clear enough to users. Users should be explicitly informed that org information is being shared.
@jfoshee
jfosheeforce-pushed the jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent branch from 50f493e to 46a4622CompareJune 10, 2026 14:29
@jfoshee
jfoshee requested a review from wobsorianoJune 10, 2026 14:51

await waitFor(() => {
expect(queryByText('Access your organizations')).toBeNull();
expect(queryByText('Access your organizations')).toBeVisible();

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This isn't the description that was in the screenshot? But the test passes so I'm guessing this is some sort of internal description we also have.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah it's from a mock setup

@wobsoriano
wobsoriano merged commit df4619f into mainJun 10, 2026
56 checks passed
@wobsoriano
wobsoriano deleted the jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent branch June 10, 2026 15:03
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jfoshee@wobsoriano@dmoerner
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(ui): show user:org:read scope in OAuth Consent list by jfoshee · Pull Request #8798 · clerk/javascript · GitHub
Skip to content

fix(ui): show user:org:read scope in OAuth Consent list - #8798

Merged
wobsoriano merged 1 commit into
mainfrom
jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent
Jun 10, 2026
Merged

fix(ui): show user:org:read scope in OAuth Consent list#8798
wobsoriano merged 1 commit into
mainfrom
jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent

Conversation

@jfoshee

@jfosheejfoshee commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

so that the user is made aware that they are sharing org information with 3rd party

Fixes USER-5442

The OAuth Consent dialog shows a list of scope descriptions so that the user is clearly informed about what they are granting access to. We were omitting the display of the user:org:read scope because we show an org selector in that case.

We determined that is not clear enough to users. Users should be explicitly informed that org information is being shared.

CleanShot 2026-06-10 at 09 50 06@2x

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes
    • Fixed OAuth consent scope display to show additional relevant scopes, including the user:org:read scope when available.

@changeset-bot

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 50f493e

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@vercel

vercelBot commented Jun 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 10, 2026 2:30pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

The OAuthConsent component's displayedScopes filter now excludes only offline_access, allowing user:org:read to be shown in the consent dialog; tests and a changeset entry were updated accordingly.

Changes

OAuth Consent Scope Display

Layer / File(s)Summary
Scope filtering logic
packages/ui/src/components/OAuthConsent/OAuthConsent.tsx
displayedScopes filter now excludes only OFFLINE_ACCESS_SCOPE, allowing USER_ORG_READ_SCOPE to be visible in the consent dialog when present.
Test expectation updates
packages/ui/src/components/OAuthConsent/__tests__/OAuthConsent.test.tsx
Org-selection scopes test updated to expect the Access your organizations description to be visible when user:org:read and memberships are present.
Release changeset
.changeset/brown-wolves-reply.md
Changeset updated to declare a patch release for @clerk/ui and note that the OAuth Consent dialog now shows the user:org:read scope description.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~5 minutes

Poem

A hop through the scopes, so clear and so bright,
The user can now see what's hidden from sight,
No user:org:read shall lurk in the shadows,
Transparency blooms through Clerk's UI meadows,
One little filter, one better display! 🐇✨

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately and concisely summarizes the main change: displaying the user:org:read scope in the OAuth Consent dialog. It directly reflects the primary modification across all changed files.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actionsBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-10T14:33:13.827Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

Note
Break Check could not snapshot 3 subpaths; the diff below excludes them.

  • @clerk/astro ./env: Internal Error: Unable to determine module for: /home/runner/_work/javascript/javascript/packages/astro/env.d.ts You have encountered a software defect. Please consider reporting the issue to the maintainers of this application.
  • @clerk/shared ./cookie: Internal Error: Unable to follow symbol for "Cookies" You have encountered a software defect. Please consider reporting the issue to the maintainers of this application.
  • @clerk/testing ./cypress: Symbol not found for identifier: Cypress

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 46a4622.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/ui/src/components/OAuthConsent/OAuthConsent.tsx`:
- Line 145: The test expectation is outdated because OAuthConsent now computes
displayedScopes by filtering only OFFLINE_ACCESS_SCOPE in the OAuthConsent
component (variable displayedScopes inside OAuthConsent), so the scope with
description "Access your organizations" (user:org:read) is rendered; update the
test named "does not display user:org:read in the scopes list" to assert that
the text 'Access your organizations' is present (e.g.,
expect(queryByText('Access your organizations')).not.toBeNull() or
toBeInTheDocument()) instead of asserting it is null, and remove any assertions
that assume user:org:read is hidden.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: fb7b4ea4-9e4d-4593-9e45-371b390c19eb

📥 Commits

Reviewing files that changed from the base of the PR and between 1028d82 and 50f493e.

📒 Files selected for processing (1)
  • packages/ui/src/components/OAuthConsent/OAuthConsent.tsx

Comment threadpackages/ui/src/components/OAuthConsent/OAuthConsent.tsx
@pkg-pr-new

pkg-pr-newBot commented Jun 10, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8798

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8798

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8798

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8798

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8798

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8798

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8798

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8798

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8798

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8798

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8798

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8798

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8798

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8798

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8798

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8798

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8798

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8798

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8798

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8798

commit: 46a4622

so that the user is made aware that they are sharing org information with 3rd party
Fixes USER-5442
The OAuth Consent dialog shows a list of scope descriptions so that the user is clearly informed about what they are granting access to. We were omitting the display of the `user:org:read` scope because we show an org selector in that case.
We determined that is not clear enough to users. Users should be explicitly informed that org information is being shared.
@jfoshee
jfosheeforce-pushed the jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent branch from 50f493e to 46a4622CompareJune 10, 2026 14:29
@jfoshee
jfoshee requested a review from wobsorianoJune 10, 2026 14:51

await waitFor(() => {
expect(queryByText('Access your organizations')).toBeNull();
expect(queryByText('Access your organizations')).toBeVisible();

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This isn't the description that was in the screenshot? But the test passes so I'm guessing this is some sort of internal description we also have.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah it's from a mock setup

@wobsoriano
wobsoriano merged commit df4619f into mainJun 10, 2026
56 checks passed
@wobsoriano
wobsoriano deleted the jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent branch June 10, 2026 15:03
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jfoshee@wobsoriano@dmoerner
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(ui): show user:org:read scope in OAuth Consent list by jfoshee · Pull Request #8798 · clerk/javascript · GitHub
Skip to content

fix(ui): show user:org:read scope in OAuth Consent list - #8798

Merged
wobsoriano merged 1 commit into
mainfrom
jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent
Jun 10, 2026
Merged

fix(ui): show user:org:read scope in OAuth Consent list#8798
wobsoriano merged 1 commit into
mainfrom
jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent

Conversation

@jfoshee

@jfosheejfoshee commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

so that the user is made aware that they are sharing org information with 3rd party

Fixes USER-5442

The OAuth Consent dialog shows a list of scope descriptions so that the user is clearly informed about what they are granting access to. We were omitting the display of the user:org:read scope because we show an org selector in that case.

We determined that is not clear enough to users. Users should be explicitly informed that org information is being shared.

CleanShot 2026-06-10 at 09 50 06@2x

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes
    • Fixed OAuth consent scope display to show additional relevant scopes, including the user:org:read scope when available.

@changeset-bot

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 50f493e

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@vercel

vercelBot commented Jun 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 10, 2026 2:30pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

The OAuthConsent component's displayedScopes filter now excludes only offline_access, allowing user:org:read to be shown in the consent dialog; tests and a changeset entry were updated accordingly.

Changes

OAuth Consent Scope Display

Layer / File(s)Summary
Scope filtering logic
packages/ui/src/components/OAuthConsent/OAuthConsent.tsx
displayedScopes filter now excludes only OFFLINE_ACCESS_SCOPE, allowing USER_ORG_READ_SCOPE to be visible in the consent dialog when present.
Test expectation updates
packages/ui/src/components/OAuthConsent/__tests__/OAuthConsent.test.tsx
Org-selection scopes test updated to expect the Access your organizations description to be visible when user:org:read and memberships are present.
Release changeset
.changeset/brown-wolves-reply.md
Changeset updated to declare a patch release for @clerk/ui and note that the OAuth Consent dialog now shows the user:org:read scope description.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~5 minutes

Poem

A hop through the scopes, so clear and so bright,
The user can now see what's hidden from sight,
No user:org:read shall lurk in the shadows,
Transparency blooms through Clerk's UI meadows,
One little filter, one better display! 🐇✨

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately and concisely summarizes the main change: displaying the user:org:read scope in the OAuth Consent dialog. It directly reflects the primary modification across all changed files.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actionsBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-10T14:33:13.827Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

Note
Break Check could not snapshot 3 subpaths; the diff below excludes them.

  • @clerk/astro ./env: Internal Error: Unable to determine module for: /home/runner/_work/javascript/javascript/packages/astro/env.d.ts You have encountered a software defect. Please consider reporting the issue to the maintainers of this application.
  • @clerk/shared ./cookie: Internal Error: Unable to follow symbol for "Cookies" You have encountered a software defect. Please consider reporting the issue to the maintainers of this application.
  • @clerk/testing ./cypress: Symbol not found for identifier: Cypress

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 46a4622.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/ui/src/components/OAuthConsent/OAuthConsent.tsx`:
- Line 145: The test expectation is outdated because OAuthConsent now computes
displayedScopes by filtering only OFFLINE_ACCESS_SCOPE in the OAuthConsent
component (variable displayedScopes inside OAuthConsent), so the scope with
description "Access your organizations" (user:org:read) is rendered; update the
test named "does not display user:org:read in the scopes list" to assert that
the text 'Access your organizations' is present (e.g.,
expect(queryByText('Access your organizations')).not.toBeNull() or
toBeInTheDocument()) instead of asserting it is null, and remove any assertions
that assume user:org:read is hidden.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: fb7b4ea4-9e4d-4593-9e45-371b390c19eb

📥 Commits

Reviewing files that changed from the base of the PR and between 1028d82 and 50f493e.

📒 Files selected for processing (1)
  • packages/ui/src/components/OAuthConsent/OAuthConsent.tsx

Comment threadpackages/ui/src/components/OAuthConsent/OAuthConsent.tsx
@pkg-pr-new

pkg-pr-newBot commented Jun 10, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8798

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8798

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8798

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8798

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8798

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8798

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8798

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8798

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8798

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8798

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8798

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8798

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8798

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8798

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8798

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8798

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8798

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8798

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8798

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8798

commit: 46a4622

so that the user is made aware that they are sharing org information with 3rd party
Fixes USER-5442
The OAuth Consent dialog shows a list of scope descriptions so that the user is clearly informed about what they are granting access to. We were omitting the display of the `user:org:read` scope because we show an org selector in that case.
We determined that is not clear enough to users. Users should be explicitly informed that org information is being shared.
@jfoshee
jfosheeforce-pushed the jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent branch from 50f493e to 46a4622CompareJune 10, 2026 14:29
@jfoshee
jfoshee requested a review from wobsorianoJune 10, 2026 14:51

await waitFor(() => {
expect(queryByText('Access your organizations')).toBeNull();
expect(queryByText('Access your organizations')).toBeVisible();

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This isn't the description that was in the screenshot? But the test passes so I'm guessing this is some sort of internal description we also have.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah it's from a mock setup

@wobsoriano
wobsoriano merged commit df4619f into mainJun 10, 2026
56 checks passed
@wobsoriano
wobsoriano deleted the jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent branch June 10, 2026 15:03
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jfoshee@wobsoriano@dmoerner
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix(ui): show user:org:read scope in OAuth Consent list by jfoshee · Pull Request #8798 · clerk/javascript · GitHub
Skip to content

fix(ui): show user:org:read scope in OAuth Consent list - #8798

Merged
wobsoriano merged 1 commit into
mainfrom
jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent
Jun 10, 2026
Merged

fix(ui): show user:org:read scope in OAuth Consent list#8798
wobsoriano merged 1 commit into
mainfrom
jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent

Conversation

@jfoshee

@jfosheejfoshee commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

so that the user is made aware that they are sharing org information with 3rd party

Fixes USER-5442

The OAuth Consent dialog shows a list of scope descriptions so that the user is clearly informed about what they are granting access to. We were omitting the display of the user:org:read scope because we show an org selector in that case.

We determined that is not clear enough to users. Users should be explicitly informed that org information is being shared.

CleanShot 2026-06-10 at 09 50 06@2x

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

Summary by CodeRabbit

  • Bug Fixes
    • Fixed OAuth consent scope display to show additional relevant scopes, including the user:org:read scope when available.

@changeset-bot

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 50f493e

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@vercel

vercelBot commented Jun 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 10, 2026 2:30pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

The OAuthConsent component's displayedScopes filter now excludes only offline_access, allowing user:org:read to be shown in the consent dialog; tests and a changeset entry were updated accordingly.

Changes

OAuth Consent Scope Display

Layer / File(s)Summary
Scope filtering logic
packages/ui/src/components/OAuthConsent/OAuthConsent.tsx
displayedScopes filter now excludes only OFFLINE_ACCESS_SCOPE, allowing USER_ORG_READ_SCOPE to be visible in the consent dialog when present.
Test expectation updates
packages/ui/src/components/OAuthConsent/__tests__/OAuthConsent.test.tsx
Org-selection scopes test updated to expect the Access your organizations description to be visible when user:org:read and memberships are present.
Release changeset
.changeset/brown-wolves-reply.md
Changeset updated to declare a patch release for @clerk/ui and note that the OAuth Consent dialog now shows the user:org:read scope description.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~5 minutes

Poem

A hop through the scopes, so clear and so bright,
The user can now see what's hidden from sight,
No user:org:read shall lurk in the shadows,
Transparency blooms through Clerk's UI meadows,
One little filter, one better display! 🐇✨

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check nameStatusExplanationResolution
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately and concisely summarizes the main change: displaying the user:org:read scope in the OAuth Consent dialog. It directly reflects the primary modification across all changed files.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actionsBot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-10T14:33:13.827Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

Note
Break Check could not snapshot 3 subpaths; the diff below excludes them.

  • @clerk/astro ./env: Internal Error: Unable to determine module for: /home/runner/_work/javascript/javascript/packages/astro/env.d.ts You have encountered a software defect. Please consider reporting the issue to the maintainers of this application.
  • @clerk/shared ./cookie: Internal Error: Unable to follow symbol for "Cookies" You have encountered a software defect. Please consider reporting the issue to the maintainers of this application.
  • @clerk/testing ./cypress: Symbol not found for identifier: Cypress

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 46a4622.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/ui/src/components/OAuthConsent/OAuthConsent.tsx`:
- Line 145: The test expectation is outdated because OAuthConsent now computes
displayedScopes by filtering only OFFLINE_ACCESS_SCOPE in the OAuthConsent
component (variable displayedScopes inside OAuthConsent), so the scope with
description "Access your organizations" (user:org:read) is rendered; update the
test named "does not display user:org:read in the scopes list" to assert that
the text 'Access your organizations' is present (e.g.,
expect(queryByText('Access your organizations')).not.toBeNull() or
toBeInTheDocument()) instead of asserting it is null, and remove any assertions
that assume user:org:read is hidden.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: fb7b4ea4-9e4d-4593-9e45-371b390c19eb

📥 Commits

Reviewing files that changed from the base of the PR and between 1028d82 and 50f493e.

📒 Files selected for processing (1)
  • packages/ui/src/components/OAuthConsent/OAuthConsent.tsx

Comment threadpackages/ui/src/components/OAuthConsent/OAuthConsent.tsx
@pkg-pr-new

pkg-pr-newBot commented Jun 10, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8798

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8798

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8798

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8798

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8798

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8798

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8798

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8798

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8798

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8798

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8798

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8798

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8798

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8798

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8798

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8798

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8798

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8798

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8798

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8798

commit: 46a4622

so that the user is made aware that they are sharing org information with 3rd party
Fixes USER-5442
The OAuth Consent dialog shows a list of scope descriptions so that the user is clearly informed about what they are granting access to. We were omitting the display of the `user:org:read` scope because we show an org selector in that case.
We determined that is not clear enough to users. Users should be explicitly informed that org information is being shared.
@jfoshee
jfosheeforce-pushed the jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent branch from 50f493e to 46a4622CompareJune 10, 2026 14:29
@jfoshee
jfoshee requested a review from wobsorianoJune 10, 2026 14:51

await waitFor(() => {
expect(queryByText('Access your organizations')).toBeNull();
expect(queryByText('Access your organizations')).toBeVisible();

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This isn't the description that was in the screenshot? But the test passes so I'm guessing this is some sort of internal description we also have.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah it's from a mock setup

@wobsoriano
wobsoriano merged commit df4619f into mainJun 10, 2026
56 checks passed
@wobsoriano
wobsoriano deleted the jacobfoshee/user-5442-organization-read-scope-is-hidden-from-the-oauth-consent branch June 10, 2026 15:03
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jfoshee@wobsoriano@dmoerner