Skip to content

fix(shared): exclude server runtimes from the worker navigator fallback - #8840

Merged
jacekradko merged 3 commits into
mainfrom
jacek/shared-worker-navigator-server-runtimes
Jun 12, 2026
Merged

fix(shared): exclude server runtimes from the worker navigator fallback#8840
jacekradko merged 3 commits into
mainfrom
jacek/shared-worker-navigator-server-runtimes

Conversation

@jacekradko

@jacekradkojacekradko commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Follow-up to #8827. While reviewing it we checked how the new worker-scope navigator fallback behaves on server runtimes with worker-like globals. Running the probe in real workerd (via miniflare, old and current compatibility dates) showed Cloudflare Workers expose the WorkerGlobalScope constructor but self instanceof WorkerGlobalScope evaluates to false, so the merged gate excludes them today only through that quirk of workerd's prototype chain. If workerd ever aligns with the spec (where ServiceWorkerGlobalScope inherits from WorkerGlobalScope), CF would pass the gate, and since it implements no navigator.onLine, isBrowserOnline would default to true.

Server worker runtimes self-identify in navigator.userAgent (Cloudflare-Workers, Node.js/24, Deno/2.5.0, Bun/1.3.9), so the fallback now rejects those before returning a worker navigator. Browser web/service workers (the MV3 case #8827 fixed) are unaffected; tests cover both today's workerd shape and a simulated spec-compliant one.

Summary by CodeRabbit

Bug Fixes

  • Fixed server-side worker environments (Cloudflare Workers, Node.js, Deno, Bun) from being incorrectly identified as valid browsers in runtime validation checks.

Tests

  • Added test coverage for browser detection in worker-like environments to verify server runtimes are properly excluded.

@vercel

vercelBot commented Jun 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 12, 2026 12:15pm
swingsetReadyReadyPreview, CommentJun 12, 2026 12:15pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 7c4cd878-b8c5-4426-99bf-2c4fc38c19aa

📥 Commits

Reviewing files that changed from the base of the PR and between c2ba971 and fd2dfcc.

📒 Files selected for processing (3)
  • .changeset/shared-worker-navigator-server-runtimes.md
  • packages/shared/src/__tests__/browser.spec.ts
  • packages/shared/src/browser.ts

📝 Walkthrough

Walkthrough

The PR tightens browser detection in @clerk/shared by preventing server-side worker environments from incorrectly passing as valid browsers. A new serverRuntimeUserAgentRegex pattern identifies server runtimes via navigator.userAgent, and getNavigator() now rejects those identifiers. Tests validate the exclusion for Cloudflare Workers, Node.js, Deno, and Bun runtimes.

Changes

Server-runtime exclusion from browser detection

Layer / File(s)Summary
Server runtime detection pattern and implementation
packages/shared/src/browser.ts
Introduces serverRuntimeUserAgentRegex constant documenting worker-like server runtimes (Cloudflare-Workers, Node.js, Deno, Bun) and extends getNavigator() to return null when self.navigator.userAgent matches a server runtime identifier, preventing those environments from being treated as valid browsers.
Test validation for browser and online detection
packages/shared/src/__tests__/browser.spec.ts
Extends isValidBrowser() test coverage with parameterized cases for server-runtime user agents, an explicit Cloudflare-Workers test, and a workerd edge case; adds isValidBrowserOnline() test asserting false for server-runtime workers where navigator.onLine is undefined.
Release documentation
.changeset/shared-worker-navigator-server-runtimes.md
Documents patch-level change to @clerk/shared describing the navigator fallback exclusion of self-identified server runtimes.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • clerk/javascript#8827: Both PRs modify browser/runtime detection around the global self.navigator fallback in worker-like environments, with this PR further tightening it by excluding server-identifying user agents.

Suggested labels

clerk-js

Suggested reviewers

  • tmilewski

Poem

🐰 A curious rabbit hops through runtimes,
Cloudflare Workers, Node, and Deno chimes,
"Not browsers!" it cries with delight,
Filtering server-side impostors right,
Now detection runs true, with regex just right!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the main change: excluding server runtimes from the worker navigator fallback, which matches the core objective of preventing server-side worker environments from incorrectly passing browser validation checks.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands and usage tips.

@changeset-bot

changeset-botBot commented Jun 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: d20b15b

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/sharedPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/reactPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch
@clerk/swingsetPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Jun 12, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8840

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8840

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8840

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8840

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8840

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8840

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8840

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8840

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8840

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8840

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8840

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8840

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8840

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8840

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8840

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8840

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8840

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8840

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8840

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8840

commit: d20b15b

@github-actions

github-actionsBot commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-12T12:17:52.406Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

Note
Break Check could not snapshot 1 subpath; the diff below excludes them.

  • @clerk/astro ./env: ambient declaration file (no top-level import or export): API Extractor can only analyze module entry points, so this global-augmentation surface cannot be snapshotted; add the subpath to ignoreSubpaths to acknowledge it (API Extractor: Unable to determine module for: /home/runner/_work/javascript/javascript/packages/astro/env.d.ts)

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on d20b15b.

@jacekradko
jacekradko marked this pull request as draft June 12, 2026 02:53

@tmilewskitmilewski left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch

@jacekradko
jacekradko marked this pull request as ready for review June 12, 2026 03:59
@jacekradko
jacekradko merged commit 8744728 into mainJun 12, 2026
47 checks passed
@jacekradko
jacekradko deleted the jacek/shared-worker-navigator-server-runtimes branch June 12, 2026 12:27
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@tmilewski
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(shared): exclude server runtimes from the worker navigator fallback by jacekradko · Pull Request #8840 · clerk/javascript · GitHub
Skip to content

fix(shared): exclude server runtimes from the worker navigator fallback - #8840

Merged
jacekradko merged 3 commits into
mainfrom
jacek/shared-worker-navigator-server-runtimes
Jun 12, 2026
Merged

fix(shared): exclude server runtimes from the worker navigator fallback#8840
jacekradko merged 3 commits into
mainfrom
jacek/shared-worker-navigator-server-runtimes

Conversation

@jacekradko

@jacekradkojacekradko commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Follow-up to #8827. While reviewing it we checked how the new worker-scope navigator fallback behaves on server runtimes with worker-like globals. Running the probe in real workerd (via miniflare, old and current compatibility dates) showed Cloudflare Workers expose the WorkerGlobalScope constructor but self instanceof WorkerGlobalScope evaluates to false, so the merged gate excludes them today only through that quirk of workerd's prototype chain. If workerd ever aligns with the spec (where ServiceWorkerGlobalScope inherits from WorkerGlobalScope), CF would pass the gate, and since it implements no navigator.onLine, isBrowserOnline would default to true.

Server worker runtimes self-identify in navigator.userAgent (Cloudflare-Workers, Node.js/24, Deno/2.5.0, Bun/1.3.9), so the fallback now rejects those before returning a worker navigator. Browser web/service workers (the MV3 case #8827 fixed) are unaffected; tests cover both today's workerd shape and a simulated spec-compliant one.

Summary by CodeRabbit

Bug Fixes

  • Fixed server-side worker environments (Cloudflare Workers, Node.js, Deno, Bun) from being incorrectly identified as valid browsers in runtime validation checks.

Tests

  • Added test coverage for browser detection in worker-like environments to verify server runtimes are properly excluded.

@vercel

vercelBot commented Jun 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 12, 2026 12:15pm
swingsetReadyReadyPreview, CommentJun 12, 2026 12:15pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 7c4cd878-b8c5-4426-99bf-2c4fc38c19aa

📥 Commits

Reviewing files that changed from the base of the PR and between c2ba971 and fd2dfcc.

📒 Files selected for processing (3)
  • .changeset/shared-worker-navigator-server-runtimes.md
  • packages/shared/src/__tests__/browser.spec.ts
  • packages/shared/src/browser.ts

📝 Walkthrough

Walkthrough

The PR tightens browser detection in @clerk/shared by preventing server-side worker environments from incorrectly passing as valid browsers. A new serverRuntimeUserAgentRegex pattern identifies server runtimes via navigator.userAgent, and getNavigator() now rejects those identifiers. Tests validate the exclusion for Cloudflare Workers, Node.js, Deno, and Bun runtimes.

Changes

Server-runtime exclusion from browser detection

Layer / File(s)Summary
Server runtime detection pattern and implementation
packages/shared/src/browser.ts
Introduces serverRuntimeUserAgentRegex constant documenting worker-like server runtimes (Cloudflare-Workers, Node.js, Deno, Bun) and extends getNavigator() to return null when self.navigator.userAgent matches a server runtime identifier, preventing those environments from being treated as valid browsers.
Test validation for browser and online detection
packages/shared/src/__tests__/browser.spec.ts
Extends isValidBrowser() test coverage with parameterized cases for server-runtime user agents, an explicit Cloudflare-Workers test, and a workerd edge case; adds isValidBrowserOnline() test asserting false for server-runtime workers where navigator.onLine is undefined.
Release documentation
.changeset/shared-worker-navigator-server-runtimes.md
Documents patch-level change to @clerk/shared describing the navigator fallback exclusion of self-identified server runtimes.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • clerk/javascript#8827: Both PRs modify browser/runtime detection around the global self.navigator fallback in worker-like environments, with this PR further tightening it by excluding server-identifying user agents.

Suggested labels

clerk-js

Suggested reviewers

  • tmilewski

Poem

🐰 A curious rabbit hops through runtimes,
Cloudflare Workers, Node, and Deno chimes,
"Not browsers!" it cries with delight,
Filtering server-side impostors right,
Now detection runs true, with regex just right!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the main change: excluding server runtimes from the worker navigator fallback, which matches the core objective of preventing server-side worker environments from incorrectly passing browser validation checks.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands and usage tips.

@changeset-bot

changeset-botBot commented Jun 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: d20b15b

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/sharedPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/reactPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch
@clerk/swingsetPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Jun 12, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8840

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8840

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8840

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8840

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8840

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8840

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8840

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8840

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8840

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8840

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8840

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8840

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8840

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8840

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8840

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8840

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8840

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8840

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8840

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8840

commit: d20b15b

@github-actions

github-actionsBot commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-12T12:17:52.406Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

Note
Break Check could not snapshot 1 subpath; the diff below excludes them.

  • @clerk/astro ./env: ambient declaration file (no top-level import or export): API Extractor can only analyze module entry points, so this global-augmentation surface cannot be snapshotted; add the subpath to ignoreSubpaths to acknowledge it (API Extractor: Unable to determine module for: /home/runner/_work/javascript/javascript/packages/astro/env.d.ts)

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on d20b15b.

@jacekradko
jacekradko marked this pull request as draft June 12, 2026 02:53

@tmilewskitmilewski left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch

@jacekradko
jacekradko marked this pull request as ready for review June 12, 2026 03:59
@jacekradko
jacekradko merged commit 8744728 into mainJun 12, 2026
47 checks passed
@jacekradko
jacekradko deleted the jacek/shared-worker-navigator-server-runtimes branch June 12, 2026 12:27
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@tmilewski
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(shared): exclude server runtimes from the worker navigator fallback by jacekradko · Pull Request #8840 · clerk/javascript · GitHub
Skip to content

fix(shared): exclude server runtimes from the worker navigator fallback - #8840

Merged
jacekradko merged 3 commits into
mainfrom
jacek/shared-worker-navigator-server-runtimes
Jun 12, 2026
Merged

fix(shared): exclude server runtimes from the worker navigator fallback#8840
jacekradko merged 3 commits into
mainfrom
jacek/shared-worker-navigator-server-runtimes

Conversation

@jacekradko

@jacekradkojacekradko commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Follow-up to #8827. While reviewing it we checked how the new worker-scope navigator fallback behaves on server runtimes with worker-like globals. Running the probe in real workerd (via miniflare, old and current compatibility dates) showed Cloudflare Workers expose the WorkerGlobalScope constructor but self instanceof WorkerGlobalScope evaluates to false, so the merged gate excludes them today only through that quirk of workerd's prototype chain. If workerd ever aligns with the spec (where ServiceWorkerGlobalScope inherits from WorkerGlobalScope), CF would pass the gate, and since it implements no navigator.onLine, isBrowserOnline would default to true.

Server worker runtimes self-identify in navigator.userAgent (Cloudflare-Workers, Node.js/24, Deno/2.5.0, Bun/1.3.9), so the fallback now rejects those before returning a worker navigator. Browser web/service workers (the MV3 case #8827 fixed) are unaffected; tests cover both today's workerd shape and a simulated spec-compliant one.

Summary by CodeRabbit

Bug Fixes

  • Fixed server-side worker environments (Cloudflare Workers, Node.js, Deno, Bun) from being incorrectly identified as valid browsers in runtime validation checks.

Tests

  • Added test coverage for browser detection in worker-like environments to verify server runtimes are properly excluded.

@vercel

vercelBot commented Jun 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 12, 2026 12:15pm
swingsetReadyReadyPreview, CommentJun 12, 2026 12:15pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 7c4cd878-b8c5-4426-99bf-2c4fc38c19aa

📥 Commits

Reviewing files that changed from the base of the PR and between c2ba971 and fd2dfcc.

📒 Files selected for processing (3)
  • .changeset/shared-worker-navigator-server-runtimes.md
  • packages/shared/src/__tests__/browser.spec.ts
  • packages/shared/src/browser.ts

📝 Walkthrough

Walkthrough

The PR tightens browser detection in @clerk/shared by preventing server-side worker environments from incorrectly passing as valid browsers. A new serverRuntimeUserAgentRegex pattern identifies server runtimes via navigator.userAgent, and getNavigator() now rejects those identifiers. Tests validate the exclusion for Cloudflare Workers, Node.js, Deno, and Bun runtimes.

Changes

Server-runtime exclusion from browser detection

Layer / File(s)Summary
Server runtime detection pattern and implementation
packages/shared/src/browser.ts
Introduces serverRuntimeUserAgentRegex constant documenting worker-like server runtimes (Cloudflare-Workers, Node.js, Deno, Bun) and extends getNavigator() to return null when self.navigator.userAgent matches a server runtime identifier, preventing those environments from being treated as valid browsers.
Test validation for browser and online detection
packages/shared/src/__tests__/browser.spec.ts
Extends isValidBrowser() test coverage with parameterized cases for server-runtime user agents, an explicit Cloudflare-Workers test, and a workerd edge case; adds isValidBrowserOnline() test asserting false for server-runtime workers where navigator.onLine is undefined.
Release documentation
.changeset/shared-worker-navigator-server-runtimes.md
Documents patch-level change to @clerk/shared describing the navigator fallback exclusion of self-identified server runtimes.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • clerk/javascript#8827: Both PRs modify browser/runtime detection around the global self.navigator fallback in worker-like environments, with this PR further tightening it by excluding server-identifying user agents.

Suggested labels

clerk-js

Suggested reviewers

  • tmilewski

Poem

🐰 A curious rabbit hops through runtimes,
Cloudflare Workers, Node, and Deno chimes,
"Not browsers!" it cries with delight,
Filtering server-side impostors right,
Now detection runs true, with regex just right!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the main change: excluding server runtimes from the worker navigator fallback, which matches the core objective of preventing server-side worker environments from incorrectly passing browser validation checks.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands and usage tips.

@changeset-bot

changeset-botBot commented Jun 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: d20b15b

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/sharedPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/reactPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch
@clerk/swingsetPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Jun 12, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8840

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8840

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8840

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8840

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8840

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8840

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8840

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8840

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8840

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8840

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8840

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8840

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8840

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8840

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8840

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8840

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8840

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8840

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8840

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8840

commit: d20b15b

@github-actions

github-actionsBot commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-12T12:17:52.406Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

Note
Break Check could not snapshot 1 subpath; the diff below excludes them.

  • @clerk/astro ./env: ambient declaration file (no top-level import or export): API Extractor can only analyze module entry points, so this global-augmentation surface cannot be snapshotted; add the subpath to ignoreSubpaths to acknowledge it (API Extractor: Unable to determine module for: /home/runner/_work/javascript/javascript/packages/astro/env.d.ts)

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on d20b15b.

@jacekradko
jacekradko marked this pull request as draft June 12, 2026 02:53

@tmilewskitmilewski left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch

@jacekradko
jacekradko marked this pull request as ready for review June 12, 2026 03:59
@jacekradko
jacekradko merged commit 8744728 into mainJun 12, 2026
47 checks passed
@jacekradko
jacekradko deleted the jacek/shared-worker-navigator-server-runtimes branch June 12, 2026 12:27
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@tmilewski
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(shared): exclude server runtimes from the worker navigator fallback by jacekradko · Pull Request #8840 · clerk/javascript · GitHub
Skip to content

fix(shared): exclude server runtimes from the worker navigator fallback - #8840

Merged
jacekradko merged 3 commits into
mainfrom
jacek/shared-worker-navigator-server-runtimes
Jun 12, 2026
Merged

fix(shared): exclude server runtimes from the worker navigator fallback#8840
jacekradko merged 3 commits into
mainfrom
jacek/shared-worker-navigator-server-runtimes

Conversation

@jacekradko

@jacekradkojacekradko commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Follow-up to #8827. While reviewing it we checked how the new worker-scope navigator fallback behaves on server runtimes with worker-like globals. Running the probe in real workerd (via miniflare, old and current compatibility dates) showed Cloudflare Workers expose the WorkerGlobalScope constructor but self instanceof WorkerGlobalScope evaluates to false, so the merged gate excludes them today only through that quirk of workerd's prototype chain. If workerd ever aligns with the spec (where ServiceWorkerGlobalScope inherits from WorkerGlobalScope), CF would pass the gate, and since it implements no navigator.onLine, isBrowserOnline would default to true.

Server worker runtimes self-identify in navigator.userAgent (Cloudflare-Workers, Node.js/24, Deno/2.5.0, Bun/1.3.9), so the fallback now rejects those before returning a worker navigator. Browser web/service workers (the MV3 case #8827 fixed) are unaffected; tests cover both today's workerd shape and a simulated spec-compliant one.

Summary by CodeRabbit

Bug Fixes

  • Fixed server-side worker environments (Cloudflare Workers, Node.js, Deno, Bun) from being incorrectly identified as valid browsers in runtime validation checks.

Tests

  • Added test coverage for browser detection in worker-like environments to verify server runtimes are properly excluded.

@vercel

vercelBot commented Jun 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 12, 2026 12:15pm
swingsetReadyReadyPreview, CommentJun 12, 2026 12:15pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 7c4cd878-b8c5-4426-99bf-2c4fc38c19aa

📥 Commits

Reviewing files that changed from the base of the PR and between c2ba971 and fd2dfcc.

📒 Files selected for processing (3)
  • .changeset/shared-worker-navigator-server-runtimes.md
  • packages/shared/src/__tests__/browser.spec.ts
  • packages/shared/src/browser.ts

📝 Walkthrough

Walkthrough

The PR tightens browser detection in @clerk/shared by preventing server-side worker environments from incorrectly passing as valid browsers. A new serverRuntimeUserAgentRegex pattern identifies server runtimes via navigator.userAgent, and getNavigator() now rejects those identifiers. Tests validate the exclusion for Cloudflare Workers, Node.js, Deno, and Bun runtimes.

Changes

Server-runtime exclusion from browser detection

Layer / File(s)Summary
Server runtime detection pattern and implementation
packages/shared/src/browser.ts
Introduces serverRuntimeUserAgentRegex constant documenting worker-like server runtimes (Cloudflare-Workers, Node.js, Deno, Bun) and extends getNavigator() to return null when self.navigator.userAgent matches a server runtime identifier, preventing those environments from being treated as valid browsers.
Test validation for browser and online detection
packages/shared/src/__tests__/browser.spec.ts
Extends isValidBrowser() test coverage with parameterized cases for server-runtime user agents, an explicit Cloudflare-Workers test, and a workerd edge case; adds isValidBrowserOnline() test asserting false for server-runtime workers where navigator.onLine is undefined.
Release documentation
.changeset/shared-worker-navigator-server-runtimes.md
Documents patch-level change to @clerk/shared describing the navigator fallback exclusion of self-identified server runtimes.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • clerk/javascript#8827: Both PRs modify browser/runtime detection around the global self.navigator fallback in worker-like environments, with this PR further tightening it by excluding server-identifying user agents.

Suggested labels

clerk-js

Suggested reviewers

  • tmilewski

Poem

🐰 A curious rabbit hops through runtimes,
Cloudflare Workers, Node, and Deno chimes,
"Not browsers!" it cries with delight,
Filtering server-side impostors right,
Now detection runs true, with regex just right!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the main change: excluding server runtimes from the worker navigator fallback, which matches the core objective of preventing server-side worker environments from incorrectly passing browser validation checks.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands and usage tips.

@changeset-bot

changeset-botBot commented Jun 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: d20b15b

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/sharedPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/reactPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch
@clerk/swingsetPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Jun 12, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8840

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8840

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8840

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8840

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8840

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8840

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8840

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8840

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8840

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8840

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8840

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8840

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8840

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8840

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8840

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8840

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8840

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8840

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8840

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8840

commit: d20b15b

@github-actions

github-actionsBot commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-12T12:17:52.406Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

Note
Break Check could not snapshot 1 subpath; the diff below excludes them.

  • @clerk/astro ./env: ambient declaration file (no top-level import or export): API Extractor can only analyze module entry points, so this global-augmentation surface cannot be snapshotted; add the subpath to ignoreSubpaths to acknowledge it (API Extractor: Unable to determine module for: /home/runner/_work/javascript/javascript/packages/astro/env.d.ts)

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on d20b15b.

@jacekradko
jacekradko marked this pull request as draft June 12, 2026 02:53

@tmilewskitmilewski left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch

@jacekradko
jacekradko marked this pull request as ready for review June 12, 2026 03:59
@jacekradko
jacekradko merged commit 8744728 into mainJun 12, 2026
47 checks passed
@jacekradko
jacekradko deleted the jacek/shared-worker-navigator-server-runtimes branch June 12, 2026 12:27
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@tmilewski
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(shared): exclude server runtimes from the worker navigator fallback by jacekradko · Pull Request #8840 · clerk/javascript · GitHub
Skip to content

fix(shared): exclude server runtimes from the worker navigator fallback - #8840

Merged
jacekradko merged 3 commits into
mainfrom
jacek/shared-worker-navigator-server-runtimes
Jun 12, 2026
Merged

fix(shared): exclude server runtimes from the worker navigator fallback#8840
jacekradko merged 3 commits into
mainfrom
jacek/shared-worker-navigator-server-runtimes

Conversation

@jacekradko

@jacekradkojacekradko commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Follow-up to #8827. While reviewing it we checked how the new worker-scope navigator fallback behaves on server runtimes with worker-like globals. Running the probe in real workerd (via miniflare, old and current compatibility dates) showed Cloudflare Workers expose the WorkerGlobalScope constructor but self instanceof WorkerGlobalScope evaluates to false, so the merged gate excludes them today only through that quirk of workerd's prototype chain. If workerd ever aligns with the spec (where ServiceWorkerGlobalScope inherits from WorkerGlobalScope), CF would pass the gate, and since it implements no navigator.onLine, isBrowserOnline would default to true.

Server worker runtimes self-identify in navigator.userAgent (Cloudflare-Workers, Node.js/24, Deno/2.5.0, Bun/1.3.9), so the fallback now rejects those before returning a worker navigator. Browser web/service workers (the MV3 case #8827 fixed) are unaffected; tests cover both today's workerd shape and a simulated spec-compliant one.

Summary by CodeRabbit

Bug Fixes

  • Fixed server-side worker environments (Cloudflare Workers, Node.js, Deno, Bun) from being incorrectly identified as valid browsers in runtime validation checks.

Tests

  • Added test coverage for browser detection in worker-like environments to verify server runtimes are properly excluded.

@vercel

vercelBot commented Jun 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 12, 2026 12:15pm
swingsetReadyReadyPreview, CommentJun 12, 2026 12:15pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 7c4cd878-b8c5-4426-99bf-2c4fc38c19aa

📥 Commits

Reviewing files that changed from the base of the PR and between c2ba971 and fd2dfcc.

📒 Files selected for processing (3)
  • .changeset/shared-worker-navigator-server-runtimes.md
  • packages/shared/src/__tests__/browser.spec.ts
  • packages/shared/src/browser.ts

📝 Walkthrough

Walkthrough

The PR tightens browser detection in @clerk/shared by preventing server-side worker environments from incorrectly passing as valid browsers. A new serverRuntimeUserAgentRegex pattern identifies server runtimes via navigator.userAgent, and getNavigator() now rejects those identifiers. Tests validate the exclusion for Cloudflare Workers, Node.js, Deno, and Bun runtimes.

Changes

Server-runtime exclusion from browser detection

Layer / File(s)Summary
Server runtime detection pattern and implementation
packages/shared/src/browser.ts
Introduces serverRuntimeUserAgentRegex constant documenting worker-like server runtimes (Cloudflare-Workers, Node.js, Deno, Bun) and extends getNavigator() to return null when self.navigator.userAgent matches a server runtime identifier, preventing those environments from being treated as valid browsers.
Test validation for browser and online detection
packages/shared/src/__tests__/browser.spec.ts
Extends isValidBrowser() test coverage with parameterized cases for server-runtime user agents, an explicit Cloudflare-Workers test, and a workerd edge case; adds isValidBrowserOnline() test asserting false for server-runtime workers where navigator.onLine is undefined.
Release documentation
.changeset/shared-worker-navigator-server-runtimes.md
Documents patch-level change to @clerk/shared describing the navigator fallback exclusion of self-identified server runtimes.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • clerk/javascript#8827: Both PRs modify browser/runtime detection around the global self.navigator fallback in worker-like environments, with this PR further tightening it by excluding server-identifying user agents.

Suggested labels

clerk-js

Suggested reviewers

  • tmilewski

Poem

🐰 A curious rabbit hops through runtimes,
Cloudflare Workers, Node, and Deno chimes,
"Not browsers!" it cries with delight,
Filtering server-side impostors right,
Now detection runs true, with regex just right!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the main change: excluding server runtimes from the worker navigator fallback, which matches the core objective of preventing server-side worker environments from incorrectly passing browser validation checks.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands and usage tips.

@changeset-bot

changeset-botBot commented Jun 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: d20b15b

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/sharedPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/reactPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch
@clerk/swingsetPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Jun 12, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8840

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8840

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8840

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8840

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8840

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8840

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8840

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8840

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8840

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8840

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8840

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8840

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8840

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8840

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8840

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8840

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8840

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8840

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8840

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8840

commit: d20b15b

@github-actions

github-actionsBot commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-12T12:17:52.406Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

Note
Break Check could not snapshot 1 subpath; the diff below excludes them.

  • @clerk/astro ./env: ambient declaration file (no top-level import or export): API Extractor can only analyze module entry points, so this global-augmentation surface cannot be snapshotted; add the subpath to ignoreSubpaths to acknowledge it (API Extractor: Unable to determine module for: /home/runner/_work/javascript/javascript/packages/astro/env.d.ts)

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on d20b15b.

@jacekradko
jacekradko marked this pull request as draft June 12, 2026 02:53

@tmilewskitmilewski left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch

@jacekradko
jacekradko marked this pull request as ready for review June 12, 2026 03:59
@jacekradko
jacekradko merged commit 8744728 into mainJun 12, 2026
47 checks passed
@jacekradko
jacekradko deleted the jacek/shared-worker-navigator-server-runtimes branch June 12, 2026 12:27
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@tmilewski
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(shared): exclude server runtimes from the worker navigator fallback by jacekradko · Pull Request #8840 · clerk/javascript · GitHub
Skip to content

fix(shared): exclude server runtimes from the worker navigator fallback - #8840

Merged
jacekradko merged 3 commits into
mainfrom
jacek/shared-worker-navigator-server-runtimes
Jun 12, 2026
Merged

fix(shared): exclude server runtimes from the worker navigator fallback#8840
jacekradko merged 3 commits into
mainfrom
jacek/shared-worker-navigator-server-runtimes

Conversation

@jacekradko

@jacekradkojacekradko commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Follow-up to #8827. While reviewing it we checked how the new worker-scope navigator fallback behaves on server runtimes with worker-like globals. Running the probe in real workerd (via miniflare, old and current compatibility dates) showed Cloudflare Workers expose the WorkerGlobalScope constructor but self instanceof WorkerGlobalScope evaluates to false, so the merged gate excludes them today only through that quirk of workerd's prototype chain. If workerd ever aligns with the spec (where ServiceWorkerGlobalScope inherits from WorkerGlobalScope), CF would pass the gate, and since it implements no navigator.onLine, isBrowserOnline would default to true.

Server worker runtimes self-identify in navigator.userAgent (Cloudflare-Workers, Node.js/24, Deno/2.5.0, Bun/1.3.9), so the fallback now rejects those before returning a worker navigator. Browser web/service workers (the MV3 case #8827 fixed) are unaffected; tests cover both today's workerd shape and a simulated spec-compliant one.

Summary by CodeRabbit

Bug Fixes

  • Fixed server-side worker environments (Cloudflare Workers, Node.js, Deno, Bun) from being incorrectly identified as valid browsers in runtime validation checks.

Tests

  • Added test coverage for browser detection in worker-like environments to verify server runtimes are properly excluded.

@vercel

vercelBot commented Jun 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 12, 2026 12:15pm
swingsetReadyReadyPreview, CommentJun 12, 2026 12:15pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 7c4cd878-b8c5-4426-99bf-2c4fc38c19aa

📥 Commits

Reviewing files that changed from the base of the PR and between c2ba971 and fd2dfcc.

📒 Files selected for processing (3)
  • .changeset/shared-worker-navigator-server-runtimes.md
  • packages/shared/src/__tests__/browser.spec.ts
  • packages/shared/src/browser.ts

📝 Walkthrough

Walkthrough

The PR tightens browser detection in @clerk/shared by preventing server-side worker environments from incorrectly passing as valid browsers. A new serverRuntimeUserAgentRegex pattern identifies server runtimes via navigator.userAgent, and getNavigator() now rejects those identifiers. Tests validate the exclusion for Cloudflare Workers, Node.js, Deno, and Bun runtimes.

Changes

Server-runtime exclusion from browser detection

Layer / File(s)Summary
Server runtime detection pattern and implementation
packages/shared/src/browser.ts
Introduces serverRuntimeUserAgentRegex constant documenting worker-like server runtimes (Cloudflare-Workers, Node.js, Deno, Bun) and extends getNavigator() to return null when self.navigator.userAgent matches a server runtime identifier, preventing those environments from being treated as valid browsers.
Test validation for browser and online detection
packages/shared/src/__tests__/browser.spec.ts
Extends isValidBrowser() test coverage with parameterized cases for server-runtime user agents, an explicit Cloudflare-Workers test, and a workerd edge case; adds isValidBrowserOnline() test asserting false for server-runtime workers where navigator.onLine is undefined.
Release documentation
.changeset/shared-worker-navigator-server-runtimes.md
Documents patch-level change to @clerk/shared describing the navigator fallback exclusion of self-identified server runtimes.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • clerk/javascript#8827: Both PRs modify browser/runtime detection around the global self.navigator fallback in worker-like environments, with this PR further tightening it by excluding server-identifying user agents.

Suggested labels

clerk-js

Suggested reviewers

  • tmilewski

Poem

🐰 A curious rabbit hops through runtimes,
Cloudflare Workers, Node, and Deno chimes,
"Not browsers!" it cries with delight,
Filtering server-side impostors right,
Now detection runs true, with regex just right!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the main change: excluding server runtimes from the worker navigator fallback, which matches the core objective of preventing server-side worker environments from incorrectly passing browser validation checks.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands and usage tips.

@changeset-bot

changeset-botBot commented Jun 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: d20b15b

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/sharedPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/reactPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch
@clerk/swingsetPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Jun 12, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8840

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8840

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8840

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8840

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8840

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8840

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8840

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8840

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8840

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8840

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8840

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8840

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8840

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8840

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8840

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8840

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8840

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8840

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8840

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8840

commit: d20b15b

@github-actions

github-actionsBot commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-12T12:17:52.406Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

Note
Break Check could not snapshot 1 subpath; the diff below excludes them.

  • @clerk/astro ./env: ambient declaration file (no top-level import or export): API Extractor can only analyze module entry points, so this global-augmentation surface cannot be snapshotted; add the subpath to ignoreSubpaths to acknowledge it (API Extractor: Unable to determine module for: /home/runner/_work/javascript/javascript/packages/astro/env.d.ts)

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on d20b15b.

@jacekradko
jacekradko marked this pull request as draft June 12, 2026 02:53

@tmilewskitmilewski left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch

@jacekradko
jacekradko marked this pull request as ready for review June 12, 2026 03:59
@jacekradko
jacekradko merged commit 8744728 into mainJun 12, 2026
47 checks passed
@jacekradko
jacekradko deleted the jacek/shared-worker-navigator-server-runtimes branch June 12, 2026 12:27
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@tmilewski
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); fix(shared): exclude server runtimes from the worker navigator fallback by jacekradko · Pull Request #8840 · clerk/javascript · GitHub
Skip to content

fix(shared): exclude server runtimes from the worker navigator fallback - #8840

Merged
jacekradko merged 3 commits into
mainfrom
jacek/shared-worker-navigator-server-runtimes
Jun 12, 2026
Merged

fix(shared): exclude server runtimes from the worker navigator fallback#8840
jacekradko merged 3 commits into
mainfrom
jacek/shared-worker-navigator-server-runtimes

Conversation

@jacekradko

@jacekradkojacekradko commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Follow-up to #8827. While reviewing it we checked how the new worker-scope navigator fallback behaves on server runtimes with worker-like globals. Running the probe in real workerd (via miniflare, old and current compatibility dates) showed Cloudflare Workers expose the WorkerGlobalScope constructor but self instanceof WorkerGlobalScope evaluates to false, so the merged gate excludes them today only through that quirk of workerd's prototype chain. If workerd ever aligns with the spec (where ServiceWorkerGlobalScope inherits from WorkerGlobalScope), CF would pass the gate, and since it implements no navigator.onLine, isBrowserOnline would default to true.

Server worker runtimes self-identify in navigator.userAgent (Cloudflare-Workers, Node.js/24, Deno/2.5.0, Bun/1.3.9), so the fallback now rejects those before returning a worker navigator. Browser web/service workers (the MV3 case #8827 fixed) are unaffected; tests cover both today's workerd shape and a simulated spec-compliant one.

Summary by CodeRabbit

Bug Fixes

  • Fixed server-side worker environments (Cloudflare Workers, Node.js, Deno, Bun) from being incorrectly identified as valid browsers in runtime validation checks.

Tests

  • Added test coverage for browser detection in worker-like environments to verify server runtimes are properly excluded.

@vercel

vercelBot commented Jun 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 12, 2026 12:15pm
swingsetReadyReadyPreview, CommentJun 12, 2026 12:15pm

Request Review

@coderabbitai

coderabbitaiBot commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 7c4cd878-b8c5-4426-99bf-2c4fc38c19aa

📥 Commits

Reviewing files that changed from the base of the PR and between c2ba971 and fd2dfcc.

📒 Files selected for processing (3)
  • .changeset/shared-worker-navigator-server-runtimes.md
  • packages/shared/src/__tests__/browser.spec.ts
  • packages/shared/src/browser.ts

📝 Walkthrough

Walkthrough

The PR tightens browser detection in @clerk/shared by preventing server-side worker environments from incorrectly passing as valid browsers. A new serverRuntimeUserAgentRegex pattern identifies server runtimes via navigator.userAgent, and getNavigator() now rejects those identifiers. Tests validate the exclusion for Cloudflare Workers, Node.js, Deno, and Bun runtimes.

Changes

Server-runtime exclusion from browser detection

Layer / File(s)Summary
Server runtime detection pattern and implementation
packages/shared/src/browser.ts
Introduces serverRuntimeUserAgentRegex constant documenting worker-like server runtimes (Cloudflare-Workers, Node.js, Deno, Bun) and extends getNavigator() to return null when self.navigator.userAgent matches a server runtime identifier, preventing those environments from being treated as valid browsers.
Test validation for browser and online detection
packages/shared/src/__tests__/browser.spec.ts
Extends isValidBrowser() test coverage with parameterized cases for server-runtime user agents, an explicit Cloudflare-Workers test, and a workerd edge case; adds isValidBrowserOnline() test asserting false for server-runtime workers where navigator.onLine is undefined.
Release documentation
.changeset/shared-worker-navigator-server-runtimes.md
Documents patch-level change to @clerk/shared describing the navigator fallback exclusion of self-identified server runtimes.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

  • clerk/javascript#8827: Both PRs modify browser/runtime detection around the global self.navigator fallback in worker-like environments, with this PR further tightening it by excluding server-identifying user agents.

Suggested labels

clerk-js

Suggested reviewers

  • tmilewski

Poem

🐰 A curious rabbit hops through runtimes,
Cloudflare Workers, Node, and Deno chimes,
"Not browsers!" it cries with delight,
Filtering server-side impostors right,
Now detection runs true, with regex just right!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly summarizes the main change: excluding server runtimes from the worker navigator fallback, which matches the core objective of preventing server-side worker environments from incorrectly passing browser validation checks.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Comment @coderabbitai help to get the list of available commands and usage tips.

@changeset-bot

changeset-botBot commented Jun 12, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: d20b15b

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
NameType
@clerk/sharedPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/chrome-extensionPatch
@clerk/clerk-jsPatch
@clerk/expo-passkeysPatch
@clerk/expoPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/localizationsPatch
@clerk/mswPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/reactPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/uiPatch
@clerk/vuePatch
@clerk/swingsetPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-newBot commented Jun 12, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8840

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8840

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8840

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8840

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8840

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8840

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8840

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8840

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8840

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8840

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8840

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8840

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8840

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8840

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8840

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8840

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8840

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8840

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8840

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8840

commit: d20b15b

@github-actions

github-actionsBot commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-12T12:17:52.406Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

Note
Break Check could not snapshot 1 subpath; the diff below excludes them.

  • @clerk/astro ./env: ambient declaration file (no top-level import or export): API Extractor can only analyze module entry points, so this global-augmentation surface cannot be snapshotted; add the subpath to ignoreSubpaths to acknowledge it (API Extractor: Unable to determine module for: /home/runner/_work/javascript/javascript/packages/astro/env.d.ts)

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on d20b15b.

@jacekradko
jacekradko marked this pull request as draft June 12, 2026 02:53

@tmilewskitmilewski left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch

@jacekradko
jacekradko marked this pull request as ready for review June 12, 2026 03:59
@jacekradko
jacekradko merged commit 8744728 into mainJun 12, 2026
47 checks passed
@jacekradko
jacekradko deleted the jacek/shared-worker-navigator-server-runtimes branch June 12, 2026 12:27
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@tmilewski