fix(backend): Align enterprise connection create and update params with the Backend API - #9155

Merged
manovotny merged 6 commits into
mainfrom
manovotny/amazing-lalande-e031c2
Jul 18, 2026
Merged

fix(backend): Align enterprise connection create and update params with the Backend API#9155
manovotny merged 6 commits into
mainfrom
manovotny/amazing-lalande-e031c2

Conversation

@manovotny

@manovotnymanovotny commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Description

Aligns CreateEnterpriseConnectionParams and UpdateEnterpriseConnectionParams with the Backend API contract (clerk_goapi/bapi/v1/enterprise_connections/service.go). Folds in #9153 — the provider fix and this work are one thought: the create/update params didn't match what BAPI accepts. Every claim was verified against the Go source.

Discovered while reviewing clerk/clerk#2887, where a docs code sample calling createEnterpriseConnection without provider would fail BAPI validation despite type-checking.

Required provider field (from #9153)

  • CreateEnterpriseConnectionParams was missing provider, which BAPI validates as required. Calls without it type-checked and failed at runtime. The field is typed as the OrganizationEnterpriseConnectionProvider union from @clerk/shared/types (matching the sibling SamlConnectionApi pattern), with type-level tests so it can't silently become optional or widen back to string.
  • The tanstack-start enterprise SSO integration test was already passing provider behind an as cast to work around the missing field. The cast is removed.

Required name and domains, plus deprecations

  • name and domains are now required on create. BAPI validates both (validate:"required", min=1 on domains), so calls without them already failed at runtime — the types now catch it at compile time. Type-level tests lock each field individually.
  • syncUserAttributes on create is deprecated. BAPI's CreateParams has no sync_user_attributes field; the JSON decoder drops it silently. It works on update, and the deprecation notice points there.
  • provider on update is deprecated. BAPI's UpdateParams has no provider field — the provider can't be changed after creation.

Missing optional params

  • Adds the optional fields BAPI accepts that the SDK types omitted: allowOrganizationAccountLinking, customAttributes, authenticatable, disableJitProvisioning (create and update), disableAdditionalIdentifications (update only), and saml.loginHint.
  • loginHint is a discriminated union: source is required exactly when mode is 'custom_attribute' and rejected otherwise, matching BAPI's validation. Custom attribute shapes (name and key required) match the Go structs, and all camelCase names were confirmed to snake-case to the exact wire keys.

Making previously-optional fields required is a compile-time change, but only for calls that already failed BAPI validation at runtime — it converts a runtime failure into a type error. Ships as a patch for that reason.

To test: pnpm --filter @clerk/backend test:node EnterpriseConnectionApi.test.ts — wire-format tests assert every field reaches the request body in snake_case, alongside the type-level assertions.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

🤖 Generated with Claude Code

manovotnyand others added 2 commits July 13, 2026 22:55
…onParams
The Backend API validates provider as required on enterprise connection
creation, so calls without it type-checked but failed at runtime.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ntract
Reuses the OrganizationEnterpriseConnectionProvider union from
@clerk/shared/types (matching the sibling SamlConnectionApi pattern) and
adds type-level tests so provider can't silently become optional or widen
back to string.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@changeset-bot

changeset-botBot commented Jul 14, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 95db01e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 10 packages
NameType
@clerk/backendPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jul 14, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 17, 2026 10:59pm
swingsetReadyReadyPreview, CommentJul 17, 2026 10:59pm

Request Review

@coderabbitai

coderabbitaiBot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: f0c02279-170f-45ba-abd2-93fd1233299e

📥 Commits

Reviewing files that changed from the base of the PR and between 774304d and 95db01e.

📒 Files selected for processing (6)
  • .changeset/heavy-melons-argue.md
  • .changeset/tidy-donuts-attend.md
  • .changeset/violet-planes-repeat.md
  • integration/tests/tanstack-start/enterprise-sso.test.ts
  • packages/backend/src/api/__tests__/EnterpriseConnectionApi.test.ts
  • packages/backend/src/api/endpoints/EnterpriseConnectionApi.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:


📝 Walkthrough

Walkthrough

Enterprise connection API types now require supported creation providers, names, and domains, and add provisioning, custom attribute, and SAML login-hint parameters. Update types add additional-identification control and deprecate changing providers. Tests cover compile-time constraints, provider payloads, and camelCase-to-snake_case serialization. The integration helper now passes typed parameters directly. Changesets document the backend patch release.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: aligning enterprise connection create and update params with the Backend API.
Description check✅ PassedThe description is directly about the same API contract alignment and matches the changeset details.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

manovotnyand others added 2 commits July 13, 2026 23:25
…ctions
Stacked on #9153 (required provider field). Aligns the remaining
CreateEnterpriseConnectionParams gaps with the Backend API contract,
which validates name and domains (min 1) as required. Deprecates
syncUserAttributes on create and provider on update, since the
Backend API ignores both.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Adds the optional create/update params the Backend API supports but
the SDK types omitted: allowOrganizationAccountLinking,
customAttributes, authenticatable, disableJitProvisioning,
disableAdditionalIdentifications (update only), and saml.loginHint.
Verified against BAPI's CreateParams/UpdateParams/SAMLParams in
clerk_go.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Codex review: BAPI requires login_hint.source exactly when mode is
custom_attribute and rejects it otherwise; model as a discriminated
union. Also lock name/domains as required with type-level tests.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this looks legit to me

@pkg-pr-new

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9155

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9155

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9155

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9155

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9155

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9155

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9155

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9155

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9155

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9155

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9155

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9155

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9155

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9155

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9155

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9155

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9155

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9155

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9155

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9155

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9155

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9155

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9155

commit: 95db01e

@github-actions

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-17T23:00:47.781Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 95db01e.

@manovotny
manovotny merged commit a009d91 into mainJul 18, 2026
51 checks passed
@manovotny
manovotny deleted the manovotny/amazing-lalande-e031c2 branch July 18, 2026 03:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@manovotny@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(backend): Align enterprise connection create and update params with the Backend API - #9155

Merged
manovotny merged 6 commits into
mainfrom
manovotny/amazing-lalande-e031c2
Jul 18, 2026
Merged

fix(backend): Align enterprise connection create and update params with the Backend API#9155
manovotny merged 6 commits into
mainfrom
manovotny/amazing-lalande-e031c2

Conversation

@manovotny

@manovotnymanovotny commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Description

Aligns CreateEnterpriseConnectionParams and UpdateEnterpriseConnectionParams with the Backend API contract (clerk_goapi/bapi/v1/enterprise_connections/service.go). Folds in #9153 — the provider fix and this work are one thought: the create/update params didn't match what BAPI accepts. Every claim was verified against the Go source.

Discovered while reviewing clerk/clerk#2887, where a docs code sample calling createEnterpriseConnection without provider would fail BAPI validation despite type-checking.

Required provider field (from #9153)

  • CreateEnterpriseConnectionParams was missing provider, which BAPI validates as required. Calls without it type-checked and failed at runtime. The field is typed as the OrganizationEnterpriseConnectionProvider union from @clerk/shared/types (matching the sibling SamlConnectionApi pattern), with type-level tests so it can't silently become optional or widen back to string.
  • The tanstack-start enterprise SSO integration test was already passing provider behind an as cast to work around the missing field. The cast is removed.

Required name and domains, plus deprecations

  • name and domains are now required on create. BAPI validates both (validate:"required", min=1 on domains), so calls without them already failed at runtime — the types now catch it at compile time. Type-level tests lock each field individually.
  • syncUserAttributes on create is deprecated. BAPI's CreateParams has no sync_user_attributes field; the JSON decoder drops it silently. It works on update, and the deprecation notice points there.
  • provider on update is deprecated. BAPI's UpdateParams has no provider field — the provider can't be changed after creation.

Missing optional params

  • Adds the optional fields BAPI accepts that the SDK types omitted: allowOrganizationAccountLinking, customAttributes, authenticatable, disableJitProvisioning (create and update), disableAdditionalIdentifications (update only), and saml.loginHint.
  • loginHint is a discriminated union: source is required exactly when mode is 'custom_attribute' and rejected otherwise, matching BAPI's validation. Custom attribute shapes (name and key required) match the Go structs, and all camelCase names were confirmed to snake-case to the exact wire keys.

Making previously-optional fields required is a compile-time change, but only for calls that already failed BAPI validation at runtime — it converts a runtime failure into a type error. Ships as a patch for that reason.

To test: pnpm --filter @clerk/backend test:node EnterpriseConnectionApi.test.ts — wire-format tests assert every field reaches the request body in snake_case, alongside the type-level assertions.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

🤖 Generated with Claude Code

manovotnyand others added 2 commits July 13, 2026 22:55
…onParams
The Backend API validates provider as required on enterprise connection
creation, so calls without it type-checked but failed at runtime.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ntract
Reuses the OrganizationEnterpriseConnectionProvider union from
@clerk/shared/types (matching the sibling SamlConnectionApi pattern) and
adds type-level tests so provider can't silently become optional or widen
back to string.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@changeset-bot

changeset-botBot commented Jul 14, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 95db01e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 10 packages
NameType
@clerk/backendPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jul 14, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 17, 2026 10:59pm
swingsetReadyReadyPreview, CommentJul 17, 2026 10:59pm

Request Review

@coderabbitai

coderabbitaiBot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: f0c02279-170f-45ba-abd2-93fd1233299e

📥 Commits

Reviewing files that changed from the base of the PR and between 774304d and 95db01e.

📒 Files selected for processing (6)
  • .changeset/heavy-melons-argue.md
  • .changeset/tidy-donuts-attend.md
  • .changeset/violet-planes-repeat.md
  • integration/tests/tanstack-start/enterprise-sso.test.ts
  • packages/backend/src/api/__tests__/EnterpriseConnectionApi.test.ts
  • packages/backend/src/api/endpoints/EnterpriseConnectionApi.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:


📝 Walkthrough

Walkthrough

Enterprise connection API types now require supported creation providers, names, and domains, and add provisioning, custom attribute, and SAML login-hint parameters. Update types add additional-identification control and deprecate changing providers. Tests cover compile-time constraints, provider payloads, and camelCase-to-snake_case serialization. The integration helper now passes typed parameters directly. Changesets document the backend patch release.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: aligning enterprise connection create and update params with the Backend API.
Description check✅ PassedThe description is directly about the same API contract alignment and matches the changeset details.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

manovotnyand others added 2 commits July 13, 2026 23:25
…ctions
Stacked on #9153 (required provider field). Aligns the remaining
CreateEnterpriseConnectionParams gaps with the Backend API contract,
which validates name and domains (min 1) as required. Deprecates
syncUserAttributes on create and provider on update, since the
Backend API ignores both.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Adds the optional create/update params the Backend API supports but
the SDK types omitted: allowOrganizationAccountLinking,
customAttributes, authenticatable, disableJitProvisioning,
disableAdditionalIdentifications (update only), and saml.loginHint.
Verified against BAPI's CreateParams/UpdateParams/SAMLParams in
clerk_go.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Codex review: BAPI requires login_hint.source exactly when mode is
custom_attribute and rejects it otherwise; model as a discriminated
union. Also lock name/domains as required with type-level tests.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this looks legit to me

@pkg-pr-new

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9155

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9155

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9155

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9155

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9155

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9155

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9155

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9155

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9155

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9155

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9155

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9155

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9155

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9155

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9155

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9155

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9155

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9155

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9155

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9155

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9155

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9155

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9155

commit: 95db01e

@github-actions

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-17T23:00:47.781Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 95db01e.

@manovotny
manovotny merged commit a009d91 into mainJul 18, 2026
51 checks passed
@manovotny
manovotny deleted the manovotny/amazing-lalande-e031c2 branch July 18, 2026 03:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@manovotny@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(backend): Align enterprise connection create and update params with the Backend API - #9155

Merged
manovotny merged 6 commits into
mainfrom
manovotny/amazing-lalande-e031c2
Jul 18, 2026
Merged

fix(backend): Align enterprise connection create and update params with the Backend API#9155
manovotny merged 6 commits into
mainfrom
manovotny/amazing-lalande-e031c2

Conversation

@manovotny

@manovotnymanovotny commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Description

Aligns CreateEnterpriseConnectionParams and UpdateEnterpriseConnectionParams with the Backend API contract (clerk_goapi/bapi/v1/enterprise_connections/service.go). Folds in #9153 — the provider fix and this work are one thought: the create/update params didn't match what BAPI accepts. Every claim was verified against the Go source.

Discovered while reviewing clerk/clerk#2887, where a docs code sample calling createEnterpriseConnection without provider would fail BAPI validation despite type-checking.

Required provider field (from #9153)

  • CreateEnterpriseConnectionParams was missing provider, which BAPI validates as required. Calls without it type-checked and failed at runtime. The field is typed as the OrganizationEnterpriseConnectionProvider union from @clerk/shared/types (matching the sibling SamlConnectionApi pattern), with type-level tests so it can't silently become optional or widen back to string.
  • The tanstack-start enterprise SSO integration test was already passing provider behind an as cast to work around the missing field. The cast is removed.

Required name and domains, plus deprecations

  • name and domains are now required on create. BAPI validates both (validate:"required", min=1 on domains), so calls without them already failed at runtime — the types now catch it at compile time. Type-level tests lock each field individually.
  • syncUserAttributes on create is deprecated. BAPI's CreateParams has no sync_user_attributes field; the JSON decoder drops it silently. It works on update, and the deprecation notice points there.
  • provider on update is deprecated. BAPI's UpdateParams has no provider field — the provider can't be changed after creation.

Missing optional params

  • Adds the optional fields BAPI accepts that the SDK types omitted: allowOrganizationAccountLinking, customAttributes, authenticatable, disableJitProvisioning (create and update), disableAdditionalIdentifications (update only), and saml.loginHint.
  • loginHint is a discriminated union: source is required exactly when mode is 'custom_attribute' and rejected otherwise, matching BAPI's validation. Custom attribute shapes (name and key required) match the Go structs, and all camelCase names were confirmed to snake-case to the exact wire keys.

Making previously-optional fields required is a compile-time change, but only for calls that already failed BAPI validation at runtime — it converts a runtime failure into a type error. Ships as a patch for that reason.

To test: pnpm --filter @clerk/backend test:node EnterpriseConnectionApi.test.ts — wire-format tests assert every field reaches the request body in snake_case, alongside the type-level assertions.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

🤖 Generated with Claude Code

manovotnyand others added 2 commits July 13, 2026 22:55
…onParams
The Backend API validates provider as required on enterprise connection
creation, so calls without it type-checked but failed at runtime.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ntract
Reuses the OrganizationEnterpriseConnectionProvider union from
@clerk/shared/types (matching the sibling SamlConnectionApi pattern) and
adds type-level tests so provider can't silently become optional or widen
back to string.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@changeset-bot

changeset-botBot commented Jul 14, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 95db01e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 10 packages
NameType
@clerk/backendPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jul 14, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 17, 2026 10:59pm
swingsetReadyReadyPreview, CommentJul 17, 2026 10:59pm

Request Review

@coderabbitai

coderabbitaiBot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: f0c02279-170f-45ba-abd2-93fd1233299e

📥 Commits

Reviewing files that changed from the base of the PR and between 774304d and 95db01e.

📒 Files selected for processing (6)
  • .changeset/heavy-melons-argue.md
  • .changeset/tidy-donuts-attend.md
  • .changeset/violet-planes-repeat.md
  • integration/tests/tanstack-start/enterprise-sso.test.ts
  • packages/backend/src/api/__tests__/EnterpriseConnectionApi.test.ts
  • packages/backend/src/api/endpoints/EnterpriseConnectionApi.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:


📝 Walkthrough

Walkthrough

Enterprise connection API types now require supported creation providers, names, and domains, and add provisioning, custom attribute, and SAML login-hint parameters. Update types add additional-identification control and deprecate changing providers. Tests cover compile-time constraints, provider payloads, and camelCase-to-snake_case serialization. The integration helper now passes typed parameters directly. Changesets document the backend patch release.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: aligning enterprise connection create and update params with the Backend API.
Description check✅ PassedThe description is directly about the same API contract alignment and matches the changeset details.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

manovotnyand others added 2 commits July 13, 2026 23:25
…ctions
Stacked on #9153 (required provider field). Aligns the remaining
CreateEnterpriseConnectionParams gaps with the Backend API contract,
which validates name and domains (min 1) as required. Deprecates
syncUserAttributes on create and provider on update, since the
Backend API ignores both.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Adds the optional create/update params the Backend API supports but
the SDK types omitted: allowOrganizationAccountLinking,
customAttributes, authenticatable, disableJitProvisioning,
disableAdditionalIdentifications (update only), and saml.loginHint.
Verified against BAPI's CreateParams/UpdateParams/SAMLParams in
clerk_go.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Codex review: BAPI requires login_hint.source exactly when mode is
custom_attribute and rejects it otherwise; model as a discriminated
union. Also lock name/domains as required with type-level tests.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this looks legit to me

@pkg-pr-new

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9155

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9155

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9155

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9155

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9155

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9155

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9155

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9155

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9155

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9155

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9155

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9155

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9155

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9155

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9155

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9155

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9155

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9155

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9155

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9155

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9155

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9155

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9155

commit: 95db01e

@github-actions

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-17T23:00:47.781Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 95db01e.

@manovotny
manovotny merged commit a009d91 into mainJul 18, 2026
51 checks passed
@manovotny
manovotny deleted the manovotny/amazing-lalande-e031c2 branch July 18, 2026 03:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@manovotny@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(backend): Align enterprise connection create and update params with the Backend API - #9155

Merged
manovotny merged 6 commits into
mainfrom
manovotny/amazing-lalande-e031c2
Jul 18, 2026
Merged

fix(backend): Align enterprise connection create and update params with the Backend API#9155
manovotny merged 6 commits into
mainfrom
manovotny/amazing-lalande-e031c2

Conversation

@manovotny

@manovotnymanovotny commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Description

Aligns CreateEnterpriseConnectionParams and UpdateEnterpriseConnectionParams with the Backend API contract (clerk_goapi/bapi/v1/enterprise_connections/service.go). Folds in #9153 — the provider fix and this work are one thought: the create/update params didn't match what BAPI accepts. Every claim was verified against the Go source.

Discovered while reviewing clerk/clerk#2887, where a docs code sample calling createEnterpriseConnection without provider would fail BAPI validation despite type-checking.

Required provider field (from #9153)

  • CreateEnterpriseConnectionParams was missing provider, which BAPI validates as required. Calls without it type-checked and failed at runtime. The field is typed as the OrganizationEnterpriseConnectionProvider union from @clerk/shared/types (matching the sibling SamlConnectionApi pattern), with type-level tests so it can't silently become optional or widen back to string.
  • The tanstack-start enterprise SSO integration test was already passing provider behind an as cast to work around the missing field. The cast is removed.

Required name and domains, plus deprecations

  • name and domains are now required on create. BAPI validates both (validate:"required", min=1 on domains), so calls without them already failed at runtime — the types now catch it at compile time. Type-level tests lock each field individually.
  • syncUserAttributes on create is deprecated. BAPI's CreateParams has no sync_user_attributes field; the JSON decoder drops it silently. It works on update, and the deprecation notice points there.
  • provider on update is deprecated. BAPI's UpdateParams has no provider field — the provider can't be changed after creation.

Missing optional params

  • Adds the optional fields BAPI accepts that the SDK types omitted: allowOrganizationAccountLinking, customAttributes, authenticatable, disableJitProvisioning (create and update), disableAdditionalIdentifications (update only), and saml.loginHint.
  • loginHint is a discriminated union: source is required exactly when mode is 'custom_attribute' and rejected otherwise, matching BAPI's validation. Custom attribute shapes (name and key required) match the Go structs, and all camelCase names were confirmed to snake-case to the exact wire keys.

Making previously-optional fields required is a compile-time change, but only for calls that already failed BAPI validation at runtime — it converts a runtime failure into a type error. Ships as a patch for that reason.

To test: pnpm --filter @clerk/backend test:node EnterpriseConnectionApi.test.ts — wire-format tests assert every field reaches the request body in snake_case, alongside the type-level assertions.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

🤖 Generated with Claude Code

manovotnyand others added 2 commits July 13, 2026 22:55
…onParams
The Backend API validates provider as required on enterprise connection
creation, so calls without it type-checked but failed at runtime.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ntract
Reuses the OrganizationEnterpriseConnectionProvider union from
@clerk/shared/types (matching the sibling SamlConnectionApi pattern) and
adds type-level tests so provider can't silently become optional or widen
back to string.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@changeset-bot

changeset-botBot commented Jul 14, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 95db01e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 10 packages
NameType
@clerk/backendPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jul 14, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 17, 2026 10:59pm
swingsetReadyReadyPreview, CommentJul 17, 2026 10:59pm

Request Review

@coderabbitai

coderabbitaiBot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: f0c02279-170f-45ba-abd2-93fd1233299e

📥 Commits

Reviewing files that changed from the base of the PR and between 774304d and 95db01e.

📒 Files selected for processing (6)
  • .changeset/heavy-melons-argue.md
  • .changeset/tidy-donuts-attend.md
  • .changeset/violet-planes-repeat.md
  • integration/tests/tanstack-start/enterprise-sso.test.ts
  • packages/backend/src/api/__tests__/EnterpriseConnectionApi.test.ts
  • packages/backend/src/api/endpoints/EnterpriseConnectionApi.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:


📝 Walkthrough

Walkthrough

Enterprise connection API types now require supported creation providers, names, and domains, and add provisioning, custom attribute, and SAML login-hint parameters. Update types add additional-identification control and deprecate changing providers. Tests cover compile-time constraints, provider payloads, and camelCase-to-snake_case serialization. The integration helper now passes typed parameters directly. Changesets document the backend patch release.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: aligning enterprise connection create and update params with the Backend API.
Description check✅ PassedThe description is directly about the same API contract alignment and matches the changeset details.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

manovotnyand others added 2 commits July 13, 2026 23:25
…ctions
Stacked on #9153 (required provider field). Aligns the remaining
CreateEnterpriseConnectionParams gaps with the Backend API contract,
which validates name and domains (min 1) as required. Deprecates
syncUserAttributes on create and provider on update, since the
Backend API ignores both.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Adds the optional create/update params the Backend API supports but
the SDK types omitted: allowOrganizationAccountLinking,
customAttributes, authenticatable, disableJitProvisioning,
disableAdditionalIdentifications (update only), and saml.loginHint.
Verified against BAPI's CreateParams/UpdateParams/SAMLParams in
clerk_go.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Codex review: BAPI requires login_hint.source exactly when mode is
custom_attribute and rejects it otherwise; model as a discriminated
union. Also lock name/domains as required with type-level tests.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this looks legit to me

@pkg-pr-new

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9155

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9155

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9155

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9155

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9155

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9155

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9155

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9155

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9155

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9155

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9155

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9155

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9155

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9155

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9155

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9155

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9155

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9155

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9155

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9155

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9155

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9155

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9155

commit: 95db01e

@github-actions

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-17T23:00:47.781Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 95db01e.

@manovotny
manovotny merged commit a009d91 into mainJul 18, 2026
51 checks passed
@manovotny
manovotny deleted the manovotny/amazing-lalande-e031c2 branch July 18, 2026 03:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@manovotny@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(backend): Align enterprise connection create and update params with the Backend API - #9155

Merged
manovotny merged 6 commits into
mainfrom
manovotny/amazing-lalande-e031c2
Jul 18, 2026
Merged

fix(backend): Align enterprise connection create and update params with the Backend API#9155
manovotny merged 6 commits into
mainfrom
manovotny/amazing-lalande-e031c2

Conversation

@manovotny

@manovotnymanovotny commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Description

Aligns CreateEnterpriseConnectionParams and UpdateEnterpriseConnectionParams with the Backend API contract (clerk_goapi/bapi/v1/enterprise_connections/service.go). Folds in #9153 — the provider fix and this work are one thought: the create/update params didn't match what BAPI accepts. Every claim was verified against the Go source.

Discovered while reviewing clerk/clerk#2887, where a docs code sample calling createEnterpriseConnection without provider would fail BAPI validation despite type-checking.

Required provider field (from #9153)

  • CreateEnterpriseConnectionParams was missing provider, which BAPI validates as required. Calls without it type-checked and failed at runtime. The field is typed as the OrganizationEnterpriseConnectionProvider union from @clerk/shared/types (matching the sibling SamlConnectionApi pattern), with type-level tests so it can't silently become optional or widen back to string.
  • The tanstack-start enterprise SSO integration test was already passing provider behind an as cast to work around the missing field. The cast is removed.

Required name and domains, plus deprecations

  • name and domains are now required on create. BAPI validates both (validate:"required", min=1 on domains), so calls without them already failed at runtime — the types now catch it at compile time. Type-level tests lock each field individually.
  • syncUserAttributes on create is deprecated. BAPI's CreateParams has no sync_user_attributes field; the JSON decoder drops it silently. It works on update, and the deprecation notice points there.
  • provider on update is deprecated. BAPI's UpdateParams has no provider field — the provider can't be changed after creation.

Missing optional params

  • Adds the optional fields BAPI accepts that the SDK types omitted: allowOrganizationAccountLinking, customAttributes, authenticatable, disableJitProvisioning (create and update), disableAdditionalIdentifications (update only), and saml.loginHint.
  • loginHint is a discriminated union: source is required exactly when mode is 'custom_attribute' and rejected otherwise, matching BAPI's validation. Custom attribute shapes (name and key required) match the Go structs, and all camelCase names were confirmed to snake-case to the exact wire keys.

Making previously-optional fields required is a compile-time change, but only for calls that already failed BAPI validation at runtime — it converts a runtime failure into a type error. Ships as a patch for that reason.

To test: pnpm --filter @clerk/backend test:node EnterpriseConnectionApi.test.ts — wire-format tests assert every field reaches the request body in snake_case, alongside the type-level assertions.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

🤖 Generated with Claude Code

manovotnyand others added 2 commits July 13, 2026 22:55
…onParams
The Backend API validates provider as required on enterprise connection
creation, so calls without it type-checked but failed at runtime.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ntract
Reuses the OrganizationEnterpriseConnectionProvider union from
@clerk/shared/types (matching the sibling SamlConnectionApi pattern) and
adds type-level tests so provider can't silently become optional or widen
back to string.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@changeset-bot

changeset-botBot commented Jul 14, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 95db01e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 10 packages
NameType
@clerk/backendPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jul 14, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 17, 2026 10:59pm
swingsetReadyReadyPreview, CommentJul 17, 2026 10:59pm

Request Review

@coderabbitai

coderabbitaiBot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: f0c02279-170f-45ba-abd2-93fd1233299e

📥 Commits

Reviewing files that changed from the base of the PR and between 774304d and 95db01e.

📒 Files selected for processing (6)
  • .changeset/heavy-melons-argue.md
  • .changeset/tidy-donuts-attend.md
  • .changeset/violet-planes-repeat.md
  • integration/tests/tanstack-start/enterprise-sso.test.ts
  • packages/backend/src/api/__tests__/EnterpriseConnectionApi.test.ts
  • packages/backend/src/api/endpoints/EnterpriseConnectionApi.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:


📝 Walkthrough

Walkthrough

Enterprise connection API types now require supported creation providers, names, and domains, and add provisioning, custom attribute, and SAML login-hint parameters. Update types add additional-identification control and deprecate changing providers. Tests cover compile-time constraints, provider payloads, and camelCase-to-snake_case serialization. The integration helper now passes typed parameters directly. Changesets document the backend patch release.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: aligning enterprise connection create and update params with the Backend API.
Description check✅ PassedThe description is directly about the same API contract alignment and matches the changeset details.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

manovotnyand others added 2 commits July 13, 2026 23:25
…ctions
Stacked on #9153 (required provider field). Aligns the remaining
CreateEnterpriseConnectionParams gaps with the Backend API contract,
which validates name and domains (min 1) as required. Deprecates
syncUserAttributes on create and provider on update, since the
Backend API ignores both.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Adds the optional create/update params the Backend API supports but
the SDK types omitted: allowOrganizationAccountLinking,
customAttributes, authenticatable, disableJitProvisioning,
disableAdditionalIdentifications (update only), and saml.loginHint.
Verified against BAPI's CreateParams/UpdateParams/SAMLParams in
clerk_go.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Codex review: BAPI requires login_hint.source exactly when mode is
custom_attribute and rejects it otherwise; model as a discriminated
union. Also lock name/domains as required with type-level tests.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this looks legit to me

@pkg-pr-new

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9155

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9155

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9155

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9155

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9155

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9155

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9155

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9155

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9155

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9155

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9155

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9155

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9155

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9155

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9155

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9155

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9155

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9155

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9155

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9155

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9155

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9155

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9155

commit: 95db01e

@github-actions

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-17T23:00:47.781Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 95db01e.

@manovotny
manovotny merged commit a009d91 into mainJul 18, 2026
51 checks passed
@manovotny
manovotny deleted the manovotny/amazing-lalande-e031c2 branch July 18, 2026 03:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@manovotny@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(backend): Align enterprise connection create and update params with the Backend API - #9155

Merged
manovotny merged 6 commits into
mainfrom
manovotny/amazing-lalande-e031c2
Jul 18, 2026
Merged

fix(backend): Align enterprise connection create and update params with the Backend API#9155
manovotny merged 6 commits into
mainfrom
manovotny/amazing-lalande-e031c2

Conversation

@manovotny

@manovotnymanovotny commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Description

Aligns CreateEnterpriseConnectionParams and UpdateEnterpriseConnectionParams with the Backend API contract (clerk_goapi/bapi/v1/enterprise_connections/service.go). Folds in #9153 — the provider fix and this work are one thought: the create/update params didn't match what BAPI accepts. Every claim was verified against the Go source.

Discovered while reviewing clerk/clerk#2887, where a docs code sample calling createEnterpriseConnection without provider would fail BAPI validation despite type-checking.

Required provider field (from #9153)

  • CreateEnterpriseConnectionParams was missing provider, which BAPI validates as required. Calls without it type-checked and failed at runtime. The field is typed as the OrganizationEnterpriseConnectionProvider union from @clerk/shared/types (matching the sibling SamlConnectionApi pattern), with type-level tests so it can't silently become optional or widen back to string.
  • The tanstack-start enterprise SSO integration test was already passing provider behind an as cast to work around the missing field. The cast is removed.

Required name and domains, plus deprecations

  • name and domains are now required on create. BAPI validates both (validate:"required", min=1 on domains), so calls without them already failed at runtime — the types now catch it at compile time. Type-level tests lock each field individually.
  • syncUserAttributes on create is deprecated. BAPI's CreateParams has no sync_user_attributes field; the JSON decoder drops it silently. It works on update, and the deprecation notice points there.
  • provider on update is deprecated. BAPI's UpdateParams has no provider field — the provider can't be changed after creation.

Missing optional params

  • Adds the optional fields BAPI accepts that the SDK types omitted: allowOrganizationAccountLinking, customAttributes, authenticatable, disableJitProvisioning (create and update), disableAdditionalIdentifications (update only), and saml.loginHint.
  • loginHint is a discriminated union: source is required exactly when mode is 'custom_attribute' and rejected otherwise, matching BAPI's validation. Custom attribute shapes (name and key required) match the Go structs, and all camelCase names were confirmed to snake-case to the exact wire keys.

Making previously-optional fields required is a compile-time change, but only for calls that already failed BAPI validation at runtime — it converts a runtime failure into a type error. Ships as a patch for that reason.

To test: pnpm --filter @clerk/backend test:node EnterpriseConnectionApi.test.ts — wire-format tests assert every field reaches the request body in snake_case, alongside the type-level assertions.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

🤖 Generated with Claude Code

manovotnyand others added 2 commits July 13, 2026 22:55
…onParams
The Backend API validates provider as required on enterprise connection
creation, so calls without it type-checked but failed at runtime.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ntract
Reuses the OrganizationEnterpriseConnectionProvider union from
@clerk/shared/types (matching the sibling SamlConnectionApi pattern) and
adds type-level tests so provider can't silently become optional or widen
back to string.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@changeset-bot

changeset-botBot commented Jul 14, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 95db01e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 10 packages
NameType
@clerk/backendPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jul 14, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 17, 2026 10:59pm
swingsetReadyReadyPreview, CommentJul 17, 2026 10:59pm

Request Review

@coderabbitai

coderabbitaiBot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: f0c02279-170f-45ba-abd2-93fd1233299e

📥 Commits

Reviewing files that changed from the base of the PR and between 774304d and 95db01e.

📒 Files selected for processing (6)
  • .changeset/heavy-melons-argue.md
  • .changeset/tidy-donuts-attend.md
  • .changeset/violet-planes-repeat.md
  • integration/tests/tanstack-start/enterprise-sso.test.ts
  • packages/backend/src/api/__tests__/EnterpriseConnectionApi.test.ts
  • packages/backend/src/api/endpoints/EnterpriseConnectionApi.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:


📝 Walkthrough

Walkthrough

Enterprise connection API types now require supported creation providers, names, and domains, and add provisioning, custom attribute, and SAML login-hint parameters. Update types add additional-identification control and deprecate changing providers. Tests cover compile-time constraints, provider payloads, and camelCase-to-snake_case serialization. The integration helper now passes typed parameters directly. Changesets document the backend patch release.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: aligning enterprise connection create and update params with the Backend API.
Description check✅ PassedThe description is directly about the same API contract alignment and matches the changeset details.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

manovotnyand others added 2 commits July 13, 2026 23:25
…ctions
Stacked on #9153 (required provider field). Aligns the remaining
CreateEnterpriseConnectionParams gaps with the Backend API contract,
which validates name and domains (min 1) as required. Deprecates
syncUserAttributes on create and provider on update, since the
Backend API ignores both.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Adds the optional create/update params the Backend API supports but
the SDK types omitted: allowOrganizationAccountLinking,
customAttributes, authenticatable, disableJitProvisioning,
disableAdditionalIdentifications (update only), and saml.loginHint.
Verified against BAPI's CreateParams/UpdateParams/SAMLParams in
clerk_go.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Codex review: BAPI requires login_hint.source exactly when mode is
custom_attribute and rejects it otherwise; model as a discriminated
union. Also lock name/domains as required with type-level tests.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this looks legit to me

@pkg-pr-new

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9155

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9155

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9155

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9155

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9155

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9155

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9155

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9155

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9155

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9155

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9155

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9155

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9155

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9155

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9155

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9155

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9155

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9155

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9155

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9155

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9155

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9155

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9155

commit: 95db01e

@github-actions

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-17T23:00:47.781Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 95db01e.

@manovotny
manovotny merged commit a009d91 into mainJul 18, 2026
51 checks passed
@manovotny
manovotny deleted the manovotny/amazing-lalande-e031c2 branch July 18, 2026 03:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@manovotny@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(backend): Align enterprise connection create and update params with the Backend API - #9155

Merged
manovotny merged 6 commits into
mainfrom
manovotny/amazing-lalande-e031c2
Jul 18, 2026
Merged

fix(backend): Align enterprise connection create and update params with the Backend API#9155
manovotny merged 6 commits into
mainfrom
manovotny/amazing-lalande-e031c2

Conversation

@manovotny

@manovotnymanovotny commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Description

Aligns CreateEnterpriseConnectionParams and UpdateEnterpriseConnectionParams with the Backend API contract (clerk_goapi/bapi/v1/enterprise_connections/service.go). Folds in #9153 — the provider fix and this work are one thought: the create/update params didn't match what BAPI accepts. Every claim was verified against the Go source.

Discovered while reviewing clerk/clerk#2887, where a docs code sample calling createEnterpriseConnection without provider would fail BAPI validation despite type-checking.

Required provider field (from #9153)

  • CreateEnterpriseConnectionParams was missing provider, which BAPI validates as required. Calls without it type-checked and failed at runtime. The field is typed as the OrganizationEnterpriseConnectionProvider union from @clerk/shared/types (matching the sibling SamlConnectionApi pattern), with type-level tests so it can't silently become optional or widen back to string.
  • The tanstack-start enterprise SSO integration test was already passing provider behind an as cast to work around the missing field. The cast is removed.

Required name and domains, plus deprecations

  • name and domains are now required on create. BAPI validates both (validate:"required", min=1 on domains), so calls without them already failed at runtime — the types now catch it at compile time. Type-level tests lock each field individually.
  • syncUserAttributes on create is deprecated. BAPI's CreateParams has no sync_user_attributes field; the JSON decoder drops it silently. It works on update, and the deprecation notice points there.
  • provider on update is deprecated. BAPI's UpdateParams has no provider field — the provider can't be changed after creation.

Missing optional params

  • Adds the optional fields BAPI accepts that the SDK types omitted: allowOrganizationAccountLinking, customAttributes, authenticatable, disableJitProvisioning (create and update), disableAdditionalIdentifications (update only), and saml.loginHint.
  • loginHint is a discriminated union: source is required exactly when mode is 'custom_attribute' and rejected otherwise, matching BAPI's validation. Custom attribute shapes (name and key required) match the Go structs, and all camelCase names were confirmed to snake-case to the exact wire keys.

Making previously-optional fields required is a compile-time change, but only for calls that already failed BAPI validation at runtime — it converts a runtime failure into a type error. Ships as a patch for that reason.

To test: pnpm --filter @clerk/backend test:node EnterpriseConnectionApi.test.ts — wire-format tests assert every field reaches the request body in snake_case, alongside the type-level assertions.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

🤖 Generated with Claude Code

manovotnyand others added 2 commits July 13, 2026 22:55
…onParams
The Backend API validates provider as required on enterprise connection
creation, so calls without it type-checked but failed at runtime.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ntract
Reuses the OrganizationEnterpriseConnectionProvider union from
@clerk/shared/types (matching the sibling SamlConnectionApi pattern) and
adds type-level tests so provider can't silently become optional or widen
back to string.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@changeset-bot

changeset-botBot commented Jul 14, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 95db01e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 10 packages
NameType
@clerk/backendPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jul 14, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 17, 2026 10:59pm
swingsetReadyReadyPreview, CommentJul 17, 2026 10:59pm

Request Review

@coderabbitai

coderabbitaiBot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: f0c02279-170f-45ba-abd2-93fd1233299e

📥 Commits

Reviewing files that changed from the base of the PR and between 774304d and 95db01e.

📒 Files selected for processing (6)
  • .changeset/heavy-melons-argue.md
  • .changeset/tidy-donuts-attend.md
  • .changeset/violet-planes-repeat.md
  • integration/tests/tanstack-start/enterprise-sso.test.ts
  • packages/backend/src/api/__tests__/EnterpriseConnectionApi.test.ts
  • packages/backend/src/api/endpoints/EnterpriseConnectionApi.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:


📝 Walkthrough

Walkthrough

Enterprise connection API types now require supported creation providers, names, and domains, and add provisioning, custom attribute, and SAML login-hint parameters. Update types add additional-identification control and deprecate changing providers. Tests cover compile-time constraints, provider payloads, and camelCase-to-snake_case serialization. The integration helper now passes typed parameters directly. Changesets document the backend patch release.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: aligning enterprise connection create and update params with the Backend API.
Description check✅ PassedThe description is directly about the same API contract alignment and matches the changeset details.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

manovotnyand others added 2 commits July 13, 2026 23:25
…ctions
Stacked on #9153 (required provider field). Aligns the remaining
CreateEnterpriseConnectionParams gaps with the Backend API contract,
which validates name and domains (min 1) as required. Deprecates
syncUserAttributes on create and provider on update, since the
Backend API ignores both.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Adds the optional create/update params the Backend API supports but
the SDK types omitted: allowOrganizationAccountLinking,
customAttributes, authenticatable, disableJitProvisioning,
disableAdditionalIdentifications (update only), and saml.loginHint.
Verified against BAPI's CreateParams/UpdateParams/SAMLParams in
clerk_go.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Codex review: BAPI requires login_hint.source exactly when mode is
custom_attribute and rejects it otherwise; model as a discriminated
union. Also lock name/domains as required with type-level tests.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this looks legit to me

@pkg-pr-new

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9155

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9155

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9155

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9155

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9155

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9155

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9155

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9155

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9155

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9155

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9155

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9155

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9155

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9155

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9155

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9155

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9155

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9155

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9155

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9155

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9155

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9155

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9155

commit: 95db01e

@github-actions

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-17T23:00:47.781Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 95db01e.

@manovotny
manovotny merged commit a009d91 into mainJul 18, 2026
51 checks passed
@manovotny
manovotny deleted the manovotny/amazing-lalande-e031c2 branch July 18, 2026 03:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@manovotny@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(backend): Align enterprise connection create and update params with the Backend API - #9155

Merged
manovotny merged 6 commits into
mainfrom
manovotny/amazing-lalande-e031c2
Jul 18, 2026
Merged

fix(backend): Align enterprise connection create and update params with the Backend API#9155
manovotny merged 6 commits into
mainfrom
manovotny/amazing-lalande-e031c2

Conversation

@manovotny

@manovotnymanovotny commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Description

Aligns CreateEnterpriseConnectionParams and UpdateEnterpriseConnectionParams with the Backend API contract (clerk_goapi/bapi/v1/enterprise_connections/service.go). Folds in #9153 — the provider fix and this work are one thought: the create/update params didn't match what BAPI accepts. Every claim was verified against the Go source.

Discovered while reviewing clerk/clerk#2887, where a docs code sample calling createEnterpriseConnection without provider would fail BAPI validation despite type-checking.

Required provider field (from #9153)

  • CreateEnterpriseConnectionParams was missing provider, which BAPI validates as required. Calls without it type-checked and failed at runtime. The field is typed as the OrganizationEnterpriseConnectionProvider union from @clerk/shared/types (matching the sibling SamlConnectionApi pattern), with type-level tests so it can't silently become optional or widen back to string.
  • The tanstack-start enterprise SSO integration test was already passing provider behind an as cast to work around the missing field. The cast is removed.

Required name and domains, plus deprecations

  • name and domains are now required on create. BAPI validates both (validate:"required", min=1 on domains), so calls without them already failed at runtime — the types now catch it at compile time. Type-level tests lock each field individually.
  • syncUserAttributes on create is deprecated. BAPI's CreateParams has no sync_user_attributes field; the JSON decoder drops it silently. It works on update, and the deprecation notice points there.
  • provider on update is deprecated. BAPI's UpdateParams has no provider field — the provider can't be changed after creation.

Missing optional params

  • Adds the optional fields BAPI accepts that the SDK types omitted: allowOrganizationAccountLinking, customAttributes, authenticatable, disableJitProvisioning (create and update), disableAdditionalIdentifications (update only), and saml.loginHint.
  • loginHint is a discriminated union: source is required exactly when mode is 'custom_attribute' and rejected otherwise, matching BAPI's validation. Custom attribute shapes (name and key required) match the Go structs, and all camelCase names were confirmed to snake-case to the exact wire keys.

Making previously-optional fields required is a compile-time change, but only for calls that already failed BAPI validation at runtime — it converts a runtime failure into a type error. Ships as a patch for that reason.

To test: pnpm --filter @clerk/backend test:node EnterpriseConnectionApi.test.ts — wire-format tests assert every field reaches the request body in snake_case, alongside the type-level assertions.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

🤖 Generated with Claude Code

manovotnyand others added 2 commits July 13, 2026 22:55
…onParams
The Backend API validates provider as required on enterprise connection
creation, so calls without it type-checked but failed at runtime.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ntract
Reuses the OrganizationEnterpriseConnectionProvider union from
@clerk/shared/types (matching the sibling SamlConnectionApi pattern) and
adds type-level tests so provider can't silently become optional or widen
back to string.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@changeset-bot

changeset-botBot commented Jul 14, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 95db01e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 10 packages
NameType
@clerk/backendPatch
@clerk/astroPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/honoPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jul 14, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 17, 2026 10:59pm
swingsetReadyReadyPreview, CommentJul 17, 2026 10:59pm

Request Review

@coderabbitai

coderabbitaiBot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: f0c02279-170f-45ba-abd2-93fd1233299e

📥 Commits

Reviewing files that changed from the base of the PR and between 774304d and 95db01e.

📒 Files selected for processing (6)
  • .changeset/heavy-melons-argue.md
  • .changeset/tidy-donuts-attend.md
  • .changeset/violet-planes-repeat.md
  • integration/tests/tanstack-start/enterprise-sso.test.ts
  • packages/backend/src/api/__tests__/EnterpriseConnectionApi.test.ts
  • packages/backend/src/api/endpoints/EnterpriseConnectionApi.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:


📝 Walkthrough

Walkthrough

Enterprise connection API types now require supported creation providers, names, and domains, and add provisioning, custom attribute, and SAML login-hint parameters. Update types add additional-identification control and deprecate changing providers. Tests cover compile-time constraints, provider payloads, and camelCase-to-snake_case serialization. The integration helper now passes typed parameters directly. Changesets document the backend patch release.

Estimated code review effort: 3 (Moderate) | ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: aligning enterprise connection create and update params with the Backend API.
Description check✅ PassedThe description is directly about the same API contract alignment and matches the changeset details.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

manovotnyand others added 2 commits July 13, 2026 23:25
…ctions
Stacked on #9153 (required provider field). Aligns the remaining
CreateEnterpriseConnectionParams gaps with the Backend API contract,
which validates name and domains (min 1) as required. Deprecates
syncUserAttributes on create and provider on update, since the
Backend API ignores both.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Adds the optional create/update params the Backend API supports but
the SDK types omitted: allowOrganizationAccountLinking,
customAttributes, authenticatable, disableJitProvisioning,
disableAdditionalIdentifications (update only), and saml.loginHint.
Verified against BAPI's CreateParams/UpdateParams/SAMLParams in
clerk_go.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Codex review: BAPI requires login_hint.source exactly when mode is
custom_attribute and rejects it otherwise; model as a discriminated
union. Also lock name/domains as required with type-level tests.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@wobsorianowobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this looks legit to me

@pkg-pr-new

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9155

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9155

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9155

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9155

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9155

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9155

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9155

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9155

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9155

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9155

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9155

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9155

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9155

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9155

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9155

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9155

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9155

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9155

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9155

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9155

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9155

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9155

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9155

commit: 95db01e

@github-actions

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-17T23:00:47.781Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 95db01e.

@manovotny
manovotny merged commit a009d91 into mainJul 18, 2026
51 checks passed
@manovotny
manovotny deleted the manovotny/amazing-lalande-e031c2 branch July 18, 2026 03:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@manovotny@wobsoriano