Skip to content

fix(expo): Sanitize stray hash fragment in SSO callback URL - #9272

Closed
wobsoriano wants to merge 2 commits into
mainfrom
rob/remove-hash-rotating-token
Closed

fix(expo): Sanitize stray hash fragment in SSO callback URL#9272
wobsoriano wants to merge 2 commits into
mainfrom
rob/remove-hash-rotating-token

Conversation

@wobsoriano

@wobsorianowobsoriano commented Jul 29, 2026

Copy link
Copy Markdown
Member

Description

Native SSO sign-ins can fail with a 401 signed_out at the sign-in reload when the OAuth callback deep link carries a stray #. Some iOS redirect chains leave a fragment on the redirect URL, either literal or percent-encoded into the rotating_token_nonce value, so the nonce reaches FAPI as <nonce># and the exact-match check fails.

useSSO now extracts the nonce through a helper that strips fragments from the callback URL and trims a # and anything after it from the extracted value.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-botBot commented Jul 29, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b0842c7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jul 29, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 29, 2026 6:10pm
swingsetReadyReadyPreview, CommentJul 29, 2026 6:10pm

Request Review

@github-actions

github-actionsBot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-29T18:10:40.235Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on b0842c7.

@pkg-pr-new

pkg-pr-newBot commented Jul 29, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9272

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9272

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9272

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9272

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9272

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9272

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9272

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9272

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9272

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9272

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9272

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9272

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9272

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9272

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9272

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9272

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9272

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9272

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9272

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9272

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9272

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9272

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9272

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9272

commit: b0842c7

@coderabbitai

coderabbitaiBot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

Adds a shared callback URL parameter helper that removes stray or encoded hash fragments and handles invalid or missing parameters. Updates SSO, hosted authentication, and OAuth flows to use it for callback values, including rotating_token_nonce, while preserving existing validation and authentication handling. Adds tests for URL variants and failure cases, plus an Expo patch changeset.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • clerk/javascript#8960: Related hosted-auth callback parameter parsing changes in the same authentication flow.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: sanitizing stray hash fragments in Expo SSO callback URLs.
Description check✅ PassedThe description matches the changeset and accurately explains the SSO callback nonce sanitization fix.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Warning

Review ran into problems

🔥 Problems

Linked repositories: Couldn't analyze clerk/clerk-android - clone failed: Clone operation failed: Cloning into '/home/jailuser/git'...
From https://github.com/clerk/clerk-android

Errors logged to '/home/jailuser/git/.git/lfs/logs/20260729T181243.864989527.log'.
Use git lfs logs last to view the log.
error: external filter 'git-lfs filter-process' failed
fatal: config/bin/detekt-cli: smudge filter lfs failed
Downloading config/bin/detekt-cli (71 MB)
Error downloading object: config/bin/detekt-cli (2655f48): Smudge error: Error downloading config/bin/detekt-cli (2655f48c7c303a5f9bf920a33229408b8571bb1d29e4e57cf7be3e151bceecb1): LFS: Client error: https://github-cloud.githubusercontent.com/alambic/media/877189286/26/55/2655f48c7c303a5f9bf920a33229408b8571bb1d29e4e57cf7be3e151bceecb1?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIA5BA2674WPWWEFGQ5%2F20260729%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260729T181403Z&X-Amz-Expires=3600&X-Amz-Signature=351957cab6836ca5db3a8fa0653aea7de1c660144b2f664d014cb83c0f9e7d5d&X-Amz-SignedHeaders=host&actor_id=136622811&key_id=0&repo_id=980409545&token=1

Errors logged to '/home/jailuser/git/.git/lfs/logs/20260729T181403.276019622.log'.
Use git lfs logs last to view the log.
error: external filter 'git-lfs filter-process' failed
fatal: config/bin/detekt-cli: smudge filter lfs failed


Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/expo/src/hooks/useSSO.ts (1)

110-110: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add a hook-level regression test for nonce normalization.

The helper tests cover parsing, but they do not verify that useSSO passes the sanitized nonce to signIn.reload. Add a test in packages/expo/src/hooks/__tests__/useSSO.test.ts covering literal and encoded trailing # values and asserting rotatingTokenNonce: 'abc123'.

As per coding guidelines, tests should cover new functionality, error handling, and edge cases.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/hooks/useSSO.ts` at line 110, Add a hook-level regression
test in useSSO tests that exercises the sign-in flow with both literal and
URL-encoded trailing # nonce values, then assert signIn.reload receives
rotatingTokenNonce: 'abc123'.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/expo/src/hooks/useSSO.ts`:
- Line 110: Add a hook-level regression test in useSSO tests that exercises the
sign-in flow with both literal and URL-encoded trailing # nonce values, then
assert signIn.reload receives rotatingTokenNonce: 'abc123'.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: b9d360f3-c5be-4b18-868a-96298e535428

📥 Commits

Reviewing files that changed from the base of the PR and between a8f6e89 and 49b396e.

📒 Files selected for processing (4)
  • .changeset/expo-callback-nonce-hash.md
  • packages/expo/src/hooks/useSSO.ts
  • packages/expo/src/utils/__tests__/authSessionCallback.test.ts
  • packages/expo/src/utils/authSessionCallback.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
  • clerk/cli(auto-detected)
  • clerk/clerk-ios(auto-detected)
  • clerk/clerk-android(auto-detected)

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/expo/src/hooks/useOAuth.ts`:
- Around line 102-103: Update the OAuth callback flow around
getAuthSessionCallbackParam and signIn.reload to reject a null or otherwise
missing rotating token nonce before invoking reload. Remove the empty-string
fallback, fail locally using the existing error-handling behavior used for
invalid auth callback data, and only pass a validated nonce to signIn.reload.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 0a12bfbe-65d8-4461-a000-9c9267333518

📥 Commits

Reviewing files that changed from the base of the PR and between 49b396e and b0842c7.

📒 Files selected for processing (2)
  • packages/expo/src/hooks/useHostedAuth.ts
  • packages/expo/src/hooks/useOAuth.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
  • clerk/cli(auto-detected)
  • clerk/clerk-ios(auto-detected)
  • clerk/clerk-android(auto-detected)

Comment on lines +102 to 103
const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';
await signIn.reload({ rotatingTokenNonce });

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Reject missing or invalid nonces before reloading sign-in.

getAuthSessionCallbackParam returns null for malformed URLs or absent parameters, but || '' causes Line 103 to call signIn.reload({ rotatingTokenNonce: '' }). Fail locally, as hosted auth does, instead of forwarding an invalid nonce to FAPI.

Proposed fix
- const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';+ const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce');+ if (!rotatingTokenNonce) {+ return errorThrower.throw(+ 'OAuth callback did not include a rotating token nonce. Please restart the OAuth flow.',+ );+ }
await signIn.reload({ rotatingTokenNonce });
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
constrotatingTokenNonce=getAuthSessionCallbackParam(url,'rotating_token_nonce')||'';
awaitsignIn.reload({ rotatingTokenNonce });
constrotatingTokenNonce=getAuthSessionCallbackParam(url,'rotating_token_nonce');
if(!rotatingTokenNonce){
returnerrorThrower.throw(
'OAuth callback did not include a rotating token nonce. Please restart the OAuth flow.',
);
}
awaitsignIn.reload({ rotatingTokenNonce });
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/hooks/useOAuth.ts` around lines 102 - 103, Update the OAuth
callback flow around getAuthSessionCallbackParam and signIn.reload to reject a
null or otherwise missing rotating token nonce before invoking reload. Remove
the empty-string fallback, fail locally using the existing error-handling
behavior used for invalid auth callback data, and only pass a validated nonce to
signIn.reload.

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

closed in favor of logging an error if the redirectUrl they pass in useSSO is missing a path

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@wobsoriano@mikepitre
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(expo): Sanitize stray hash fragment in SSO callback URL by wobsoriano · Pull Request #9272 · clerk/javascript · GitHub
Skip to content

fix(expo): Sanitize stray hash fragment in SSO callback URL - #9272

Closed
wobsoriano wants to merge 2 commits into
mainfrom
rob/remove-hash-rotating-token
Closed

fix(expo): Sanitize stray hash fragment in SSO callback URL#9272
wobsoriano wants to merge 2 commits into
mainfrom
rob/remove-hash-rotating-token

Conversation

@wobsoriano

@wobsorianowobsoriano commented Jul 29, 2026

Copy link
Copy Markdown
Member

Description

Native SSO sign-ins can fail with a 401 signed_out at the sign-in reload when the OAuth callback deep link carries a stray #. Some iOS redirect chains leave a fragment on the redirect URL, either literal or percent-encoded into the rotating_token_nonce value, so the nonce reaches FAPI as <nonce># and the exact-match check fails.

useSSO now extracts the nonce through a helper that strips fragments from the callback URL and trims a # and anything after it from the extracted value.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-botBot commented Jul 29, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b0842c7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jul 29, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 29, 2026 6:10pm
swingsetReadyReadyPreview, CommentJul 29, 2026 6:10pm

Request Review

@github-actions

github-actionsBot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-29T18:10:40.235Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on b0842c7.

@pkg-pr-new

pkg-pr-newBot commented Jul 29, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9272

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9272

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9272

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9272

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9272

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9272

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9272

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9272

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9272

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9272

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9272

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9272

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9272

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9272

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9272

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9272

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9272

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9272

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9272

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9272

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9272

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9272

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9272

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9272

commit: b0842c7

@coderabbitai

coderabbitaiBot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

Adds a shared callback URL parameter helper that removes stray or encoded hash fragments and handles invalid or missing parameters. Updates SSO, hosted authentication, and OAuth flows to use it for callback values, including rotating_token_nonce, while preserving existing validation and authentication handling. Adds tests for URL variants and failure cases, plus an Expo patch changeset.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • clerk/javascript#8960: Related hosted-auth callback parameter parsing changes in the same authentication flow.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: sanitizing stray hash fragments in Expo SSO callback URLs.
Description check✅ PassedThe description matches the changeset and accurately explains the SSO callback nonce sanitization fix.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Warning

Review ran into problems

🔥 Problems

Linked repositories: Couldn't analyze clerk/clerk-android - clone failed: Clone operation failed: Cloning into '/home/jailuser/git'...
From https://github.com/clerk/clerk-android

Errors logged to '/home/jailuser/git/.git/lfs/logs/20260729T181243.864989527.log'.
Use git lfs logs last to view the log.
error: external filter 'git-lfs filter-process' failed
fatal: config/bin/detekt-cli: smudge filter lfs failed
Downloading config/bin/detekt-cli (71 MB)
Error downloading object: config/bin/detekt-cli (2655f48): Smudge error: Error downloading config/bin/detekt-cli (2655f48c7c303a5f9bf920a33229408b8571bb1d29e4e57cf7be3e151bceecb1): LFS: Client error: https://github-cloud.githubusercontent.com/alambic/media/877189286/26/55/2655f48c7c303a5f9bf920a33229408b8571bb1d29e4e57cf7be3e151bceecb1?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIA5BA2674WPWWEFGQ5%2F20260729%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260729T181403Z&X-Amz-Expires=3600&X-Amz-Signature=351957cab6836ca5db3a8fa0653aea7de1c660144b2f664d014cb83c0f9e7d5d&X-Amz-SignedHeaders=host&actor_id=136622811&key_id=0&repo_id=980409545&token=1

Errors logged to '/home/jailuser/git/.git/lfs/logs/20260729T181403.276019622.log'.
Use git lfs logs last to view the log.
error: external filter 'git-lfs filter-process' failed
fatal: config/bin/detekt-cli: smudge filter lfs failed


Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/expo/src/hooks/useSSO.ts (1)

110-110: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add a hook-level regression test for nonce normalization.

The helper tests cover parsing, but they do not verify that useSSO passes the sanitized nonce to signIn.reload. Add a test in packages/expo/src/hooks/__tests__/useSSO.test.ts covering literal and encoded trailing # values and asserting rotatingTokenNonce: 'abc123'.

As per coding guidelines, tests should cover new functionality, error handling, and edge cases.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/hooks/useSSO.ts` at line 110, Add a hook-level regression
test in useSSO tests that exercises the sign-in flow with both literal and
URL-encoded trailing # nonce values, then assert signIn.reload receives
rotatingTokenNonce: 'abc123'.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/expo/src/hooks/useSSO.ts`:
- Line 110: Add a hook-level regression test in useSSO tests that exercises the
sign-in flow with both literal and URL-encoded trailing # nonce values, then
assert signIn.reload receives rotatingTokenNonce: 'abc123'.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: b9d360f3-c5be-4b18-868a-96298e535428

📥 Commits

Reviewing files that changed from the base of the PR and between a8f6e89 and 49b396e.

📒 Files selected for processing (4)
  • .changeset/expo-callback-nonce-hash.md
  • packages/expo/src/hooks/useSSO.ts
  • packages/expo/src/utils/__tests__/authSessionCallback.test.ts
  • packages/expo/src/utils/authSessionCallback.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
  • clerk/cli(auto-detected)
  • clerk/clerk-ios(auto-detected)
  • clerk/clerk-android(auto-detected)

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/expo/src/hooks/useOAuth.ts`:
- Around line 102-103: Update the OAuth callback flow around
getAuthSessionCallbackParam and signIn.reload to reject a null or otherwise
missing rotating token nonce before invoking reload. Remove the empty-string
fallback, fail locally using the existing error-handling behavior used for
invalid auth callback data, and only pass a validated nonce to signIn.reload.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 0a12bfbe-65d8-4461-a000-9c9267333518

📥 Commits

Reviewing files that changed from the base of the PR and between 49b396e and b0842c7.

📒 Files selected for processing (2)
  • packages/expo/src/hooks/useHostedAuth.ts
  • packages/expo/src/hooks/useOAuth.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
  • clerk/cli(auto-detected)
  • clerk/clerk-ios(auto-detected)
  • clerk/clerk-android(auto-detected)

Comment on lines +102 to 103
const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';
await signIn.reload({ rotatingTokenNonce });

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Reject missing or invalid nonces before reloading sign-in.

getAuthSessionCallbackParam returns null for malformed URLs or absent parameters, but || '' causes Line 103 to call signIn.reload({ rotatingTokenNonce: '' }). Fail locally, as hosted auth does, instead of forwarding an invalid nonce to FAPI.

Proposed fix
- const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';+ const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce');+ if (!rotatingTokenNonce) {+ return errorThrower.throw(+ 'OAuth callback did not include a rotating token nonce. Please restart the OAuth flow.',+ );+ }
await signIn.reload({ rotatingTokenNonce });
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
constrotatingTokenNonce=getAuthSessionCallbackParam(url,'rotating_token_nonce')||'';
awaitsignIn.reload({ rotatingTokenNonce });
constrotatingTokenNonce=getAuthSessionCallbackParam(url,'rotating_token_nonce');
if(!rotatingTokenNonce){
returnerrorThrower.throw(
'OAuth callback did not include a rotating token nonce. Please restart the OAuth flow.',
);
}
awaitsignIn.reload({ rotatingTokenNonce });
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/hooks/useOAuth.ts` around lines 102 - 103, Update the OAuth
callback flow around getAuthSessionCallbackParam and signIn.reload to reject a
null or otherwise missing rotating token nonce before invoking reload. Remove
the empty-string fallback, fail locally using the existing error-handling
behavior used for invalid auth callback data, and only pass a validated nonce to
signIn.reload.

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

closed in favor of logging an error if the redirectUrl they pass in useSSO is missing a path

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@wobsoriano@mikepitre
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(expo): Sanitize stray hash fragment in SSO callback URL by wobsoriano · Pull Request #9272 · clerk/javascript · GitHub
Skip to content

fix(expo): Sanitize stray hash fragment in SSO callback URL - #9272

Closed
wobsoriano wants to merge 2 commits into
mainfrom
rob/remove-hash-rotating-token
Closed

fix(expo): Sanitize stray hash fragment in SSO callback URL#9272
wobsoriano wants to merge 2 commits into
mainfrom
rob/remove-hash-rotating-token

Conversation

@wobsoriano

@wobsorianowobsoriano commented Jul 29, 2026

Copy link
Copy Markdown
Member

Description

Native SSO sign-ins can fail with a 401 signed_out at the sign-in reload when the OAuth callback deep link carries a stray #. Some iOS redirect chains leave a fragment on the redirect URL, either literal or percent-encoded into the rotating_token_nonce value, so the nonce reaches FAPI as <nonce># and the exact-match check fails.

useSSO now extracts the nonce through a helper that strips fragments from the callback URL and trims a # and anything after it from the extracted value.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-botBot commented Jul 29, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b0842c7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jul 29, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 29, 2026 6:10pm
swingsetReadyReadyPreview, CommentJul 29, 2026 6:10pm

Request Review

@github-actions

github-actionsBot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-29T18:10:40.235Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on b0842c7.

@pkg-pr-new

pkg-pr-newBot commented Jul 29, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9272

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9272

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9272

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9272

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9272

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9272

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9272

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9272

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9272

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9272

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9272

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9272

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9272

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9272

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9272

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9272

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9272

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9272

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9272

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9272

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9272

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9272

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9272

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9272

commit: b0842c7

@coderabbitai

coderabbitaiBot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

Adds a shared callback URL parameter helper that removes stray or encoded hash fragments and handles invalid or missing parameters. Updates SSO, hosted authentication, and OAuth flows to use it for callback values, including rotating_token_nonce, while preserving existing validation and authentication handling. Adds tests for URL variants and failure cases, plus an Expo patch changeset.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • clerk/javascript#8960: Related hosted-auth callback parameter parsing changes in the same authentication flow.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: sanitizing stray hash fragments in Expo SSO callback URLs.
Description check✅ PassedThe description matches the changeset and accurately explains the SSO callback nonce sanitization fix.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Warning

Review ran into problems

🔥 Problems

Linked repositories: Couldn't analyze clerk/clerk-android - clone failed: Clone operation failed: Cloning into '/home/jailuser/git'...
From https://github.com/clerk/clerk-android

Errors logged to '/home/jailuser/git/.git/lfs/logs/20260729T181243.864989527.log'.
Use git lfs logs last to view the log.
error: external filter 'git-lfs filter-process' failed
fatal: config/bin/detekt-cli: smudge filter lfs failed
Downloading config/bin/detekt-cli (71 MB)
Error downloading object: config/bin/detekt-cli (2655f48): Smudge error: Error downloading config/bin/detekt-cli (2655f48c7c303a5f9bf920a33229408b8571bb1d29e4e57cf7be3e151bceecb1): LFS: Client error: https://github-cloud.githubusercontent.com/alambic/media/877189286/26/55/2655f48c7c303a5f9bf920a33229408b8571bb1d29e4e57cf7be3e151bceecb1?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIA5BA2674WPWWEFGQ5%2F20260729%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260729T181403Z&X-Amz-Expires=3600&X-Amz-Signature=351957cab6836ca5db3a8fa0653aea7de1c660144b2f664d014cb83c0f9e7d5d&X-Amz-SignedHeaders=host&actor_id=136622811&key_id=0&repo_id=980409545&token=1

Errors logged to '/home/jailuser/git/.git/lfs/logs/20260729T181403.276019622.log'.
Use git lfs logs last to view the log.
error: external filter 'git-lfs filter-process' failed
fatal: config/bin/detekt-cli: smudge filter lfs failed


Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/expo/src/hooks/useSSO.ts (1)

110-110: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add a hook-level regression test for nonce normalization.

The helper tests cover parsing, but they do not verify that useSSO passes the sanitized nonce to signIn.reload. Add a test in packages/expo/src/hooks/__tests__/useSSO.test.ts covering literal and encoded trailing # values and asserting rotatingTokenNonce: 'abc123'.

As per coding guidelines, tests should cover new functionality, error handling, and edge cases.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/hooks/useSSO.ts` at line 110, Add a hook-level regression
test in useSSO tests that exercises the sign-in flow with both literal and
URL-encoded trailing # nonce values, then assert signIn.reload receives
rotatingTokenNonce: 'abc123'.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/expo/src/hooks/useSSO.ts`:
- Line 110: Add a hook-level regression test in useSSO tests that exercises the
sign-in flow with both literal and URL-encoded trailing # nonce values, then
assert signIn.reload receives rotatingTokenNonce: 'abc123'.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: b9d360f3-c5be-4b18-868a-96298e535428

📥 Commits

Reviewing files that changed from the base of the PR and between a8f6e89 and 49b396e.

📒 Files selected for processing (4)
  • .changeset/expo-callback-nonce-hash.md
  • packages/expo/src/hooks/useSSO.ts
  • packages/expo/src/utils/__tests__/authSessionCallback.test.ts
  • packages/expo/src/utils/authSessionCallback.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
  • clerk/cli(auto-detected)
  • clerk/clerk-ios(auto-detected)
  • clerk/clerk-android(auto-detected)

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/expo/src/hooks/useOAuth.ts`:
- Around line 102-103: Update the OAuth callback flow around
getAuthSessionCallbackParam and signIn.reload to reject a null or otherwise
missing rotating token nonce before invoking reload. Remove the empty-string
fallback, fail locally using the existing error-handling behavior used for
invalid auth callback data, and only pass a validated nonce to signIn.reload.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 0a12bfbe-65d8-4461-a000-9c9267333518

📥 Commits

Reviewing files that changed from the base of the PR and between 49b396e and b0842c7.

📒 Files selected for processing (2)
  • packages/expo/src/hooks/useHostedAuth.ts
  • packages/expo/src/hooks/useOAuth.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
  • clerk/cli(auto-detected)
  • clerk/clerk-ios(auto-detected)
  • clerk/clerk-android(auto-detected)

Comment on lines +102 to 103
const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';
await signIn.reload({ rotatingTokenNonce });

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Reject missing or invalid nonces before reloading sign-in.

getAuthSessionCallbackParam returns null for malformed URLs or absent parameters, but || '' causes Line 103 to call signIn.reload({ rotatingTokenNonce: '' }). Fail locally, as hosted auth does, instead of forwarding an invalid nonce to FAPI.

Proposed fix
- const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';+ const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce');+ if (!rotatingTokenNonce) {+ return errorThrower.throw(+ 'OAuth callback did not include a rotating token nonce. Please restart the OAuth flow.',+ );+ }
await signIn.reload({ rotatingTokenNonce });
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
constrotatingTokenNonce=getAuthSessionCallbackParam(url,'rotating_token_nonce')||'';
awaitsignIn.reload({ rotatingTokenNonce });
constrotatingTokenNonce=getAuthSessionCallbackParam(url,'rotating_token_nonce');
if(!rotatingTokenNonce){
returnerrorThrower.throw(
'OAuth callback did not include a rotating token nonce. Please restart the OAuth flow.',
);
}
awaitsignIn.reload({ rotatingTokenNonce });
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/hooks/useOAuth.ts` around lines 102 - 103, Update the OAuth
callback flow around getAuthSessionCallbackParam and signIn.reload to reject a
null or otherwise missing rotating token nonce before invoking reload. Remove
the empty-string fallback, fail locally using the existing error-handling
behavior used for invalid auth callback data, and only pass a validated nonce to
signIn.reload.

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

closed in favor of logging an error if the redirectUrl they pass in useSSO is missing a path

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@wobsoriano@mikepitre
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(expo): Sanitize stray hash fragment in SSO callback URL by wobsoriano · Pull Request #9272 · clerk/javascript · GitHub
Skip to content

fix(expo): Sanitize stray hash fragment in SSO callback URL - #9272

Closed
wobsoriano wants to merge 2 commits into
mainfrom
rob/remove-hash-rotating-token
Closed

fix(expo): Sanitize stray hash fragment in SSO callback URL#9272
wobsoriano wants to merge 2 commits into
mainfrom
rob/remove-hash-rotating-token

Conversation

@wobsoriano

@wobsorianowobsoriano commented Jul 29, 2026

Copy link
Copy Markdown
Member

Description

Native SSO sign-ins can fail with a 401 signed_out at the sign-in reload when the OAuth callback deep link carries a stray #. Some iOS redirect chains leave a fragment on the redirect URL, either literal or percent-encoded into the rotating_token_nonce value, so the nonce reaches FAPI as <nonce># and the exact-match check fails.

useSSO now extracts the nonce through a helper that strips fragments from the callback URL and trims a # and anything after it from the extracted value.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-botBot commented Jul 29, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b0842c7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jul 29, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 29, 2026 6:10pm
swingsetReadyReadyPreview, CommentJul 29, 2026 6:10pm

Request Review

@github-actions

github-actionsBot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-29T18:10:40.235Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on b0842c7.

@pkg-pr-new

pkg-pr-newBot commented Jul 29, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9272

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9272

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9272

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9272

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9272

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9272

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9272

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9272

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9272

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9272

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9272

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9272

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9272

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9272

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9272

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9272

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9272

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9272

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9272

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9272

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9272

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9272

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9272

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9272

commit: b0842c7

@coderabbitai

coderabbitaiBot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

Adds a shared callback URL parameter helper that removes stray or encoded hash fragments and handles invalid or missing parameters. Updates SSO, hosted authentication, and OAuth flows to use it for callback values, including rotating_token_nonce, while preserving existing validation and authentication handling. Adds tests for URL variants and failure cases, plus an Expo patch changeset.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • clerk/javascript#8960: Related hosted-auth callback parameter parsing changes in the same authentication flow.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: sanitizing stray hash fragments in Expo SSO callback URLs.
Description check✅ PassedThe description matches the changeset and accurately explains the SSO callback nonce sanitization fix.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Warning

Review ran into problems

🔥 Problems

Linked repositories: Couldn't analyze clerk/clerk-android - clone failed: Clone operation failed: Cloning into '/home/jailuser/git'...
From https://github.com/clerk/clerk-android

Errors logged to '/home/jailuser/git/.git/lfs/logs/20260729T181243.864989527.log'.
Use git lfs logs last to view the log.
error: external filter 'git-lfs filter-process' failed
fatal: config/bin/detekt-cli: smudge filter lfs failed
Downloading config/bin/detekt-cli (71 MB)
Error downloading object: config/bin/detekt-cli (2655f48): Smudge error: Error downloading config/bin/detekt-cli (2655f48c7c303a5f9bf920a33229408b8571bb1d29e4e57cf7be3e151bceecb1): LFS: Client error: https://github-cloud.githubusercontent.com/alambic/media/877189286/26/55/2655f48c7c303a5f9bf920a33229408b8571bb1d29e4e57cf7be3e151bceecb1?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIA5BA2674WPWWEFGQ5%2F20260729%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260729T181403Z&X-Amz-Expires=3600&X-Amz-Signature=351957cab6836ca5db3a8fa0653aea7de1c660144b2f664d014cb83c0f9e7d5d&X-Amz-SignedHeaders=host&actor_id=136622811&key_id=0&repo_id=980409545&token=1

Errors logged to '/home/jailuser/git/.git/lfs/logs/20260729T181403.276019622.log'.
Use git lfs logs last to view the log.
error: external filter 'git-lfs filter-process' failed
fatal: config/bin/detekt-cli: smudge filter lfs failed


Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/expo/src/hooks/useSSO.ts (1)

110-110: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add a hook-level regression test for nonce normalization.

The helper tests cover parsing, but they do not verify that useSSO passes the sanitized nonce to signIn.reload. Add a test in packages/expo/src/hooks/__tests__/useSSO.test.ts covering literal and encoded trailing # values and asserting rotatingTokenNonce: 'abc123'.

As per coding guidelines, tests should cover new functionality, error handling, and edge cases.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/hooks/useSSO.ts` at line 110, Add a hook-level regression
test in useSSO tests that exercises the sign-in flow with both literal and
URL-encoded trailing # nonce values, then assert signIn.reload receives
rotatingTokenNonce: 'abc123'.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/expo/src/hooks/useSSO.ts`:
- Line 110: Add a hook-level regression test in useSSO tests that exercises the
sign-in flow with both literal and URL-encoded trailing # nonce values, then
assert signIn.reload receives rotatingTokenNonce: 'abc123'.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: b9d360f3-c5be-4b18-868a-96298e535428

📥 Commits

Reviewing files that changed from the base of the PR and between a8f6e89 and 49b396e.

📒 Files selected for processing (4)
  • .changeset/expo-callback-nonce-hash.md
  • packages/expo/src/hooks/useSSO.ts
  • packages/expo/src/utils/__tests__/authSessionCallback.test.ts
  • packages/expo/src/utils/authSessionCallback.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
  • clerk/cli(auto-detected)
  • clerk/clerk-ios(auto-detected)
  • clerk/clerk-android(auto-detected)

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/expo/src/hooks/useOAuth.ts`:
- Around line 102-103: Update the OAuth callback flow around
getAuthSessionCallbackParam and signIn.reload to reject a null or otherwise
missing rotating token nonce before invoking reload. Remove the empty-string
fallback, fail locally using the existing error-handling behavior used for
invalid auth callback data, and only pass a validated nonce to signIn.reload.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 0a12bfbe-65d8-4461-a000-9c9267333518

📥 Commits

Reviewing files that changed from the base of the PR and between 49b396e and b0842c7.

📒 Files selected for processing (2)
  • packages/expo/src/hooks/useHostedAuth.ts
  • packages/expo/src/hooks/useOAuth.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
  • clerk/cli(auto-detected)
  • clerk/clerk-ios(auto-detected)
  • clerk/clerk-android(auto-detected)

Comment on lines +102 to 103
const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';
await signIn.reload({ rotatingTokenNonce });

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Reject missing or invalid nonces before reloading sign-in.

getAuthSessionCallbackParam returns null for malformed URLs or absent parameters, but || '' causes Line 103 to call signIn.reload({ rotatingTokenNonce: '' }). Fail locally, as hosted auth does, instead of forwarding an invalid nonce to FAPI.

Proposed fix
- const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';+ const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce');+ if (!rotatingTokenNonce) {+ return errorThrower.throw(+ 'OAuth callback did not include a rotating token nonce. Please restart the OAuth flow.',+ );+ }
await signIn.reload({ rotatingTokenNonce });
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
constrotatingTokenNonce=getAuthSessionCallbackParam(url,'rotating_token_nonce')||'';
awaitsignIn.reload({ rotatingTokenNonce });
constrotatingTokenNonce=getAuthSessionCallbackParam(url,'rotating_token_nonce');
if(!rotatingTokenNonce){
returnerrorThrower.throw(
'OAuth callback did not include a rotating token nonce. Please restart the OAuth flow.',
);
}
awaitsignIn.reload({ rotatingTokenNonce });
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/hooks/useOAuth.ts` around lines 102 - 103, Update the OAuth
callback flow around getAuthSessionCallbackParam and signIn.reload to reject a
null or otherwise missing rotating token nonce before invoking reload. Remove
the empty-string fallback, fail locally using the existing error-handling
behavior used for invalid auth callback data, and only pass a validated nonce to
signIn.reload.

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

closed in favor of logging an error if the redirectUrl they pass in useSSO is missing a path

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@wobsoriano@mikepitre
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(expo): Sanitize stray hash fragment in SSO callback URL by wobsoriano · Pull Request #9272 · clerk/javascript · GitHub
Skip to content

fix(expo): Sanitize stray hash fragment in SSO callback URL - #9272

Closed
wobsoriano wants to merge 2 commits into
mainfrom
rob/remove-hash-rotating-token
Closed

fix(expo): Sanitize stray hash fragment in SSO callback URL#9272
wobsoriano wants to merge 2 commits into
mainfrom
rob/remove-hash-rotating-token

Conversation

@wobsoriano

@wobsorianowobsoriano commented Jul 29, 2026

Copy link
Copy Markdown
Member

Description

Native SSO sign-ins can fail with a 401 signed_out at the sign-in reload when the OAuth callback deep link carries a stray #. Some iOS redirect chains leave a fragment on the redirect URL, either literal or percent-encoded into the rotating_token_nonce value, so the nonce reaches FAPI as <nonce># and the exact-match check fails.

useSSO now extracts the nonce through a helper that strips fragments from the callback URL and trims a # and anything after it from the extracted value.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-botBot commented Jul 29, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b0842c7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jul 29, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 29, 2026 6:10pm
swingsetReadyReadyPreview, CommentJul 29, 2026 6:10pm

Request Review

@github-actions

github-actionsBot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-29T18:10:40.235Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on b0842c7.

@pkg-pr-new

pkg-pr-newBot commented Jul 29, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9272

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9272

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9272

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9272

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9272

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9272

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9272

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9272

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9272

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9272

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9272

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9272

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9272

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9272

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9272

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9272

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9272

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9272

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9272

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9272

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9272

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9272

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9272

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9272

commit: b0842c7

@coderabbitai

coderabbitaiBot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

Adds a shared callback URL parameter helper that removes stray or encoded hash fragments and handles invalid or missing parameters. Updates SSO, hosted authentication, and OAuth flows to use it for callback values, including rotating_token_nonce, while preserving existing validation and authentication handling. Adds tests for URL variants and failure cases, plus an Expo patch changeset.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • clerk/javascript#8960: Related hosted-auth callback parameter parsing changes in the same authentication flow.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: sanitizing stray hash fragments in Expo SSO callback URLs.
Description check✅ PassedThe description matches the changeset and accurately explains the SSO callback nonce sanitization fix.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Warning

Review ran into problems

🔥 Problems

Linked repositories: Couldn't analyze clerk/clerk-android - clone failed: Clone operation failed: Cloning into '/home/jailuser/git'...
From https://github.com/clerk/clerk-android

Errors logged to '/home/jailuser/git/.git/lfs/logs/20260729T181243.864989527.log'.
Use git lfs logs last to view the log.
error: external filter 'git-lfs filter-process' failed
fatal: config/bin/detekt-cli: smudge filter lfs failed
Downloading config/bin/detekt-cli (71 MB)
Error downloading object: config/bin/detekt-cli (2655f48): Smudge error: Error downloading config/bin/detekt-cli (2655f48c7c303a5f9bf920a33229408b8571bb1d29e4e57cf7be3e151bceecb1): LFS: Client error: https://github-cloud.githubusercontent.com/alambic/media/877189286/26/55/2655f48c7c303a5f9bf920a33229408b8571bb1d29e4e57cf7be3e151bceecb1?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIA5BA2674WPWWEFGQ5%2F20260729%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260729T181403Z&X-Amz-Expires=3600&X-Amz-Signature=351957cab6836ca5db3a8fa0653aea7de1c660144b2f664d014cb83c0f9e7d5d&X-Amz-SignedHeaders=host&actor_id=136622811&key_id=0&repo_id=980409545&token=1

Errors logged to '/home/jailuser/git/.git/lfs/logs/20260729T181403.276019622.log'.
Use git lfs logs last to view the log.
error: external filter 'git-lfs filter-process' failed
fatal: config/bin/detekt-cli: smudge filter lfs failed


Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/expo/src/hooks/useSSO.ts (1)

110-110: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add a hook-level regression test for nonce normalization.

The helper tests cover parsing, but they do not verify that useSSO passes the sanitized nonce to signIn.reload. Add a test in packages/expo/src/hooks/__tests__/useSSO.test.ts covering literal and encoded trailing # values and asserting rotatingTokenNonce: 'abc123'.

As per coding guidelines, tests should cover new functionality, error handling, and edge cases.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/hooks/useSSO.ts` at line 110, Add a hook-level regression
test in useSSO tests that exercises the sign-in flow with both literal and
URL-encoded trailing # nonce values, then assert signIn.reload receives
rotatingTokenNonce: 'abc123'.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/expo/src/hooks/useSSO.ts`:
- Line 110: Add a hook-level regression test in useSSO tests that exercises the
sign-in flow with both literal and URL-encoded trailing # nonce values, then
assert signIn.reload receives rotatingTokenNonce: 'abc123'.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: b9d360f3-c5be-4b18-868a-96298e535428

📥 Commits

Reviewing files that changed from the base of the PR and between a8f6e89 and 49b396e.

📒 Files selected for processing (4)
  • .changeset/expo-callback-nonce-hash.md
  • packages/expo/src/hooks/useSSO.ts
  • packages/expo/src/utils/__tests__/authSessionCallback.test.ts
  • packages/expo/src/utils/authSessionCallback.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
  • clerk/cli(auto-detected)
  • clerk/clerk-ios(auto-detected)
  • clerk/clerk-android(auto-detected)

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/expo/src/hooks/useOAuth.ts`:
- Around line 102-103: Update the OAuth callback flow around
getAuthSessionCallbackParam and signIn.reload to reject a null or otherwise
missing rotating token nonce before invoking reload. Remove the empty-string
fallback, fail locally using the existing error-handling behavior used for
invalid auth callback data, and only pass a validated nonce to signIn.reload.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 0a12bfbe-65d8-4461-a000-9c9267333518

📥 Commits

Reviewing files that changed from the base of the PR and between 49b396e and b0842c7.

📒 Files selected for processing (2)
  • packages/expo/src/hooks/useHostedAuth.ts
  • packages/expo/src/hooks/useOAuth.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
  • clerk/cli(auto-detected)
  • clerk/clerk-ios(auto-detected)
  • clerk/clerk-android(auto-detected)

Comment on lines +102 to 103
const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';
await signIn.reload({ rotatingTokenNonce });

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Reject missing or invalid nonces before reloading sign-in.

getAuthSessionCallbackParam returns null for malformed URLs or absent parameters, but || '' causes Line 103 to call signIn.reload({ rotatingTokenNonce: '' }). Fail locally, as hosted auth does, instead of forwarding an invalid nonce to FAPI.

Proposed fix
- const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';+ const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce');+ if (!rotatingTokenNonce) {+ return errorThrower.throw(+ 'OAuth callback did not include a rotating token nonce. Please restart the OAuth flow.',+ );+ }
await signIn.reload({ rotatingTokenNonce });
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
constrotatingTokenNonce=getAuthSessionCallbackParam(url,'rotating_token_nonce')||'';
awaitsignIn.reload({ rotatingTokenNonce });
constrotatingTokenNonce=getAuthSessionCallbackParam(url,'rotating_token_nonce');
if(!rotatingTokenNonce){
returnerrorThrower.throw(
'OAuth callback did not include a rotating token nonce. Please restart the OAuth flow.',
);
}
awaitsignIn.reload({ rotatingTokenNonce });
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/hooks/useOAuth.ts` around lines 102 - 103, Update the OAuth
callback flow around getAuthSessionCallbackParam and signIn.reload to reject a
null or otherwise missing rotating token nonce before invoking reload. Remove
the empty-string fallback, fail locally using the existing error-handling
behavior used for invalid auth callback data, and only pass a validated nonce to
signIn.reload.

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

closed in favor of logging an error if the redirectUrl they pass in useSSO is missing a path

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@wobsoriano@mikepitre
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(expo): Sanitize stray hash fragment in SSO callback URL by wobsoriano · Pull Request #9272 · clerk/javascript · GitHub
Skip to content

fix(expo): Sanitize stray hash fragment in SSO callback URL - #9272

Closed
wobsoriano wants to merge 2 commits into
mainfrom
rob/remove-hash-rotating-token
Closed

fix(expo): Sanitize stray hash fragment in SSO callback URL#9272
wobsoriano wants to merge 2 commits into
mainfrom
rob/remove-hash-rotating-token

Conversation

@wobsoriano

@wobsorianowobsoriano commented Jul 29, 2026

Copy link
Copy Markdown
Member

Description

Native SSO sign-ins can fail with a 401 signed_out at the sign-in reload when the OAuth callback deep link carries a stray #. Some iOS redirect chains leave a fragment on the redirect URL, either literal or percent-encoded into the rotating_token_nonce value, so the nonce reaches FAPI as <nonce># and the exact-match check fails.

useSSO now extracts the nonce through a helper that strips fragments from the callback URL and trims a # and anything after it from the extracted value.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-botBot commented Jul 29, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b0842c7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jul 29, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 29, 2026 6:10pm
swingsetReadyReadyPreview, CommentJul 29, 2026 6:10pm

Request Review

@github-actions

github-actionsBot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-29T18:10:40.235Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on b0842c7.

@pkg-pr-new

pkg-pr-newBot commented Jul 29, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9272

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9272

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9272

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9272

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9272

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9272

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9272

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9272

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9272

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9272

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9272

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9272

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9272

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9272

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9272

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9272

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9272

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9272

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9272

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9272

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9272

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9272

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9272

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9272

commit: b0842c7

@coderabbitai

coderabbitaiBot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

Adds a shared callback URL parameter helper that removes stray or encoded hash fragments and handles invalid or missing parameters. Updates SSO, hosted authentication, and OAuth flows to use it for callback values, including rotating_token_nonce, while preserving existing validation and authentication handling. Adds tests for URL variants and failure cases, plus an Expo patch changeset.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • clerk/javascript#8960: Related hosted-auth callback parameter parsing changes in the same authentication flow.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: sanitizing stray hash fragments in Expo SSO callback URLs.
Description check✅ PassedThe description matches the changeset and accurately explains the SSO callback nonce sanitization fix.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Warning

Review ran into problems

🔥 Problems

Linked repositories: Couldn't analyze clerk/clerk-android - clone failed: Clone operation failed: Cloning into '/home/jailuser/git'...
From https://github.com/clerk/clerk-android

Errors logged to '/home/jailuser/git/.git/lfs/logs/20260729T181243.864989527.log'.
Use git lfs logs last to view the log.
error: external filter 'git-lfs filter-process' failed
fatal: config/bin/detekt-cli: smudge filter lfs failed
Downloading config/bin/detekt-cli (71 MB)
Error downloading object: config/bin/detekt-cli (2655f48): Smudge error: Error downloading config/bin/detekt-cli (2655f48c7c303a5f9bf920a33229408b8571bb1d29e4e57cf7be3e151bceecb1): LFS: Client error: https://github-cloud.githubusercontent.com/alambic/media/877189286/26/55/2655f48c7c303a5f9bf920a33229408b8571bb1d29e4e57cf7be3e151bceecb1?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIA5BA2674WPWWEFGQ5%2F20260729%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260729T181403Z&X-Amz-Expires=3600&X-Amz-Signature=351957cab6836ca5db3a8fa0653aea7de1c660144b2f664d014cb83c0f9e7d5d&X-Amz-SignedHeaders=host&actor_id=136622811&key_id=0&repo_id=980409545&token=1

Errors logged to '/home/jailuser/git/.git/lfs/logs/20260729T181403.276019622.log'.
Use git lfs logs last to view the log.
error: external filter 'git-lfs filter-process' failed
fatal: config/bin/detekt-cli: smudge filter lfs failed


Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/expo/src/hooks/useSSO.ts (1)

110-110: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add a hook-level regression test for nonce normalization.

The helper tests cover parsing, but they do not verify that useSSO passes the sanitized nonce to signIn.reload. Add a test in packages/expo/src/hooks/__tests__/useSSO.test.ts covering literal and encoded trailing # values and asserting rotatingTokenNonce: 'abc123'.

As per coding guidelines, tests should cover new functionality, error handling, and edge cases.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/hooks/useSSO.ts` at line 110, Add a hook-level regression
test in useSSO tests that exercises the sign-in flow with both literal and
URL-encoded trailing # nonce values, then assert signIn.reload receives
rotatingTokenNonce: 'abc123'.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/expo/src/hooks/useSSO.ts`:
- Line 110: Add a hook-level regression test in useSSO tests that exercises the
sign-in flow with both literal and URL-encoded trailing # nonce values, then
assert signIn.reload receives rotatingTokenNonce: 'abc123'.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: b9d360f3-c5be-4b18-868a-96298e535428

📥 Commits

Reviewing files that changed from the base of the PR and between a8f6e89 and 49b396e.

📒 Files selected for processing (4)
  • .changeset/expo-callback-nonce-hash.md
  • packages/expo/src/hooks/useSSO.ts
  • packages/expo/src/utils/__tests__/authSessionCallback.test.ts
  • packages/expo/src/utils/authSessionCallback.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
  • clerk/cli(auto-detected)
  • clerk/clerk-ios(auto-detected)
  • clerk/clerk-android(auto-detected)

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/expo/src/hooks/useOAuth.ts`:
- Around line 102-103: Update the OAuth callback flow around
getAuthSessionCallbackParam and signIn.reload to reject a null or otherwise
missing rotating token nonce before invoking reload. Remove the empty-string
fallback, fail locally using the existing error-handling behavior used for
invalid auth callback data, and only pass a validated nonce to signIn.reload.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 0a12bfbe-65d8-4461-a000-9c9267333518

📥 Commits

Reviewing files that changed from the base of the PR and between 49b396e and b0842c7.

📒 Files selected for processing (2)
  • packages/expo/src/hooks/useHostedAuth.ts
  • packages/expo/src/hooks/useOAuth.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
  • clerk/cli(auto-detected)
  • clerk/clerk-ios(auto-detected)
  • clerk/clerk-android(auto-detected)

Comment on lines +102 to 103
const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';
await signIn.reload({ rotatingTokenNonce });

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Reject missing or invalid nonces before reloading sign-in.

getAuthSessionCallbackParam returns null for malformed URLs or absent parameters, but || '' causes Line 103 to call signIn.reload({ rotatingTokenNonce: '' }). Fail locally, as hosted auth does, instead of forwarding an invalid nonce to FAPI.

Proposed fix
- const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';+ const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce');+ if (!rotatingTokenNonce) {+ return errorThrower.throw(+ 'OAuth callback did not include a rotating token nonce. Please restart the OAuth flow.',+ );+ }
await signIn.reload({ rotatingTokenNonce });
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
constrotatingTokenNonce=getAuthSessionCallbackParam(url,'rotating_token_nonce')||'';
awaitsignIn.reload({ rotatingTokenNonce });
constrotatingTokenNonce=getAuthSessionCallbackParam(url,'rotating_token_nonce');
if(!rotatingTokenNonce){
returnerrorThrower.throw(
'OAuth callback did not include a rotating token nonce. Please restart the OAuth flow.',
);
}
awaitsignIn.reload({ rotatingTokenNonce });
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/hooks/useOAuth.ts` around lines 102 - 103, Update the OAuth
callback flow around getAuthSessionCallbackParam and signIn.reload to reject a
null or otherwise missing rotating token nonce before invoking reload. Remove
the empty-string fallback, fail locally using the existing error-handling
behavior used for invalid auth callback data, and only pass a validated nonce to
signIn.reload.

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

closed in favor of logging an error if the redirectUrl they pass in useSSO is missing a path

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@wobsoriano@mikepitre
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(expo): Sanitize stray hash fragment in SSO callback URL by wobsoriano · Pull Request #9272 · clerk/javascript · GitHub
Skip to content

fix(expo): Sanitize stray hash fragment in SSO callback URL - #9272

Closed
wobsoriano wants to merge 2 commits into
mainfrom
rob/remove-hash-rotating-token
Closed

fix(expo): Sanitize stray hash fragment in SSO callback URL#9272
wobsoriano wants to merge 2 commits into
mainfrom
rob/remove-hash-rotating-token

Conversation

@wobsoriano

@wobsorianowobsoriano commented Jul 29, 2026

Copy link
Copy Markdown
Member

Description

Native SSO sign-ins can fail with a 401 signed_out at the sign-in reload when the OAuth callback deep link carries a stray #. Some iOS redirect chains leave a fragment on the redirect URL, either literal or percent-encoded into the rotating_token_nonce value, so the nonce reaches FAPI as <nonce># and the exact-match check fails.

useSSO now extracts the nonce through a helper that strips fragments from the callback URL and trims a # and anything after it from the extracted value.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-botBot commented Jul 29, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b0842c7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jul 29, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 29, 2026 6:10pm
swingsetReadyReadyPreview, CommentJul 29, 2026 6:10pm

Request Review

@github-actions

github-actionsBot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-29T18:10:40.235Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on b0842c7.

@pkg-pr-new

pkg-pr-newBot commented Jul 29, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9272

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9272

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9272

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9272

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9272

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9272

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9272

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9272

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9272

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9272

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9272

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9272

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9272

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9272

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9272

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9272

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9272

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9272

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9272

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9272

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9272

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9272

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9272

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9272

commit: b0842c7

@coderabbitai

coderabbitaiBot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

Adds a shared callback URL parameter helper that removes stray or encoded hash fragments and handles invalid or missing parameters. Updates SSO, hosted authentication, and OAuth flows to use it for callback values, including rotating_token_nonce, while preserving existing validation and authentication handling. Adds tests for URL variants and failure cases, plus an Expo patch changeset.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • clerk/javascript#8960: Related hosted-auth callback parameter parsing changes in the same authentication flow.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: sanitizing stray hash fragments in Expo SSO callback URLs.
Description check✅ PassedThe description matches the changeset and accurately explains the SSO callback nonce sanitization fix.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Warning

Review ran into problems

🔥 Problems

Linked repositories: Couldn't analyze clerk/clerk-android - clone failed: Clone operation failed: Cloning into '/home/jailuser/git'...
From https://github.com/clerk/clerk-android

Errors logged to '/home/jailuser/git/.git/lfs/logs/20260729T181243.864989527.log'.
Use git lfs logs last to view the log.
error: external filter 'git-lfs filter-process' failed
fatal: config/bin/detekt-cli: smudge filter lfs failed
Downloading config/bin/detekt-cli (71 MB)
Error downloading object: config/bin/detekt-cli (2655f48): Smudge error: Error downloading config/bin/detekt-cli (2655f48c7c303a5f9bf920a33229408b8571bb1d29e4e57cf7be3e151bceecb1): LFS: Client error: https://github-cloud.githubusercontent.com/alambic/media/877189286/26/55/2655f48c7c303a5f9bf920a33229408b8571bb1d29e4e57cf7be3e151bceecb1?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIA5BA2674WPWWEFGQ5%2F20260729%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260729T181403Z&X-Amz-Expires=3600&X-Amz-Signature=351957cab6836ca5db3a8fa0653aea7de1c660144b2f664d014cb83c0f9e7d5d&X-Amz-SignedHeaders=host&actor_id=136622811&key_id=0&repo_id=980409545&token=1

Errors logged to '/home/jailuser/git/.git/lfs/logs/20260729T181403.276019622.log'.
Use git lfs logs last to view the log.
error: external filter 'git-lfs filter-process' failed
fatal: config/bin/detekt-cli: smudge filter lfs failed


Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/expo/src/hooks/useSSO.ts (1)

110-110: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add a hook-level regression test for nonce normalization.

The helper tests cover parsing, but they do not verify that useSSO passes the sanitized nonce to signIn.reload. Add a test in packages/expo/src/hooks/__tests__/useSSO.test.ts covering literal and encoded trailing # values and asserting rotatingTokenNonce: 'abc123'.

As per coding guidelines, tests should cover new functionality, error handling, and edge cases.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/hooks/useSSO.ts` at line 110, Add a hook-level regression
test in useSSO tests that exercises the sign-in flow with both literal and
URL-encoded trailing # nonce values, then assert signIn.reload receives
rotatingTokenNonce: 'abc123'.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/expo/src/hooks/useSSO.ts`:
- Line 110: Add a hook-level regression test in useSSO tests that exercises the
sign-in flow with both literal and URL-encoded trailing # nonce values, then
assert signIn.reload receives rotatingTokenNonce: 'abc123'.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: b9d360f3-c5be-4b18-868a-96298e535428

📥 Commits

Reviewing files that changed from the base of the PR and between a8f6e89 and 49b396e.

📒 Files selected for processing (4)
  • .changeset/expo-callback-nonce-hash.md
  • packages/expo/src/hooks/useSSO.ts
  • packages/expo/src/utils/__tests__/authSessionCallback.test.ts
  • packages/expo/src/utils/authSessionCallback.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
  • clerk/cli(auto-detected)
  • clerk/clerk-ios(auto-detected)
  • clerk/clerk-android(auto-detected)

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/expo/src/hooks/useOAuth.ts`:
- Around line 102-103: Update the OAuth callback flow around
getAuthSessionCallbackParam and signIn.reload to reject a null or otherwise
missing rotating token nonce before invoking reload. Remove the empty-string
fallback, fail locally using the existing error-handling behavior used for
invalid auth callback data, and only pass a validated nonce to signIn.reload.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 0a12bfbe-65d8-4461-a000-9c9267333518

📥 Commits

Reviewing files that changed from the base of the PR and between 49b396e and b0842c7.

📒 Files selected for processing (2)
  • packages/expo/src/hooks/useHostedAuth.ts
  • packages/expo/src/hooks/useOAuth.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
  • clerk/cli(auto-detected)
  • clerk/clerk-ios(auto-detected)
  • clerk/clerk-android(auto-detected)

Comment on lines +102 to 103
const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';
await signIn.reload({ rotatingTokenNonce });

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Reject missing or invalid nonces before reloading sign-in.

getAuthSessionCallbackParam returns null for malformed URLs or absent parameters, but || '' causes Line 103 to call signIn.reload({ rotatingTokenNonce: '' }). Fail locally, as hosted auth does, instead of forwarding an invalid nonce to FAPI.

Proposed fix
- const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';+ const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce');+ if (!rotatingTokenNonce) {+ return errorThrower.throw(+ 'OAuth callback did not include a rotating token nonce. Please restart the OAuth flow.',+ );+ }
await signIn.reload({ rotatingTokenNonce });
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
constrotatingTokenNonce=getAuthSessionCallbackParam(url,'rotating_token_nonce')||'';
awaitsignIn.reload({ rotatingTokenNonce });
constrotatingTokenNonce=getAuthSessionCallbackParam(url,'rotating_token_nonce');
if(!rotatingTokenNonce){
returnerrorThrower.throw(
'OAuth callback did not include a rotating token nonce. Please restart the OAuth flow.',
);
}
awaitsignIn.reload({ rotatingTokenNonce });
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/hooks/useOAuth.ts` around lines 102 - 103, Update the OAuth
callback flow around getAuthSessionCallbackParam and signIn.reload to reject a
null or otherwise missing rotating token nonce before invoking reload. Remove
the empty-string fallback, fail locally using the existing error-handling
behavior used for invalid auth callback data, and only pass a validated nonce to
signIn.reload.

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

closed in favor of logging an error if the redirectUrl they pass in useSSO is missing a path

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@wobsoriano@mikepitre
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix(expo): Sanitize stray hash fragment in SSO callback URL by wobsoriano · Pull Request #9272 · clerk/javascript · GitHub
Skip to content

fix(expo): Sanitize stray hash fragment in SSO callback URL - #9272

Closed
wobsoriano wants to merge 2 commits into
mainfrom
rob/remove-hash-rotating-token
Closed

fix(expo): Sanitize stray hash fragment in SSO callback URL#9272
wobsoriano wants to merge 2 commits into
mainfrom
rob/remove-hash-rotating-token

Conversation

@wobsoriano

@wobsorianowobsoriano commented Jul 29, 2026

Copy link
Copy Markdown
Member

Description

Native SSO sign-ins can fail with a 401 signed_out at the sign-in reload when the OAuth callback deep link carries a stray #. Some iOS redirect chains leave a fragment on the redirect URL, either literal or percent-encoded into the rotating_token_nonce value, so the nonce reaches FAPI as <nonce># and the exact-match check fails.

useSSO now extracts the nonce through a helper that strips fragments from the callback URL and trims a # and anything after it from the extracted value.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-botBot commented Jul 29, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b0842c7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jul 29, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJul 29, 2026 6:10pm
swingsetReadyReadyPreview, CommentJul 29, 2026 6:10pm

Request Review

@github-actions

github-actionsBot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-29T18:10:40.235Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on b0842c7.

@pkg-pr-new

pkg-pr-newBot commented Jul 29, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9272

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9272

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9272

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9272

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9272

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9272

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9272

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9272

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9272

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9272

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9272

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9272

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9272

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9272

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9272

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9272

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9272

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9272

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9272

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9272

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9272

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9272

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9272

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9272

commit: b0842c7

@coderabbitai

coderabbitaiBot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

Adds a shared callback URL parameter helper that removes stray or encoded hash fragments and handles invalid or missing parameters. Updates SSO, hosted authentication, and OAuth flows to use it for callback values, including rotating_token_nonce, while preserving existing validation and authentication handling. Adds tests for URL variants and failure cases, plus an Expo patch changeset.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • clerk/javascript#8960: Related hosted-auth callback parameter parsing changes in the same authentication flow.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: sanitizing stray hash fragments in Expo SSO callback URLs.
Description check✅ PassedThe description matches the changeset and accurately explains the SSO callback nonce sanitization fix.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

Warning

Review ran into problems

🔥 Problems

Linked repositories: Couldn't analyze clerk/clerk-android - clone failed: Clone operation failed: Cloning into '/home/jailuser/git'...
From https://github.com/clerk/clerk-android

Errors logged to '/home/jailuser/git/.git/lfs/logs/20260729T181243.864989527.log'.
Use git lfs logs last to view the log.
error: external filter 'git-lfs filter-process' failed
fatal: config/bin/detekt-cli: smudge filter lfs failed
Downloading config/bin/detekt-cli (71 MB)
Error downloading object: config/bin/detekt-cli (2655f48): Smudge error: Error downloading config/bin/detekt-cli (2655f48c7c303a5f9bf920a33229408b8571bb1d29e4e57cf7be3e151bceecb1): LFS: Client error: https://github-cloud.githubusercontent.com/alambic/media/877189286/26/55/2655f48c7c303a5f9bf920a33229408b8571bb1d29e4e57cf7be3e151bceecb1?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIA5BA2674WPWWEFGQ5%2F20260729%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260729T181403Z&X-Amz-Expires=3600&X-Amz-Signature=351957cab6836ca5db3a8fa0653aea7de1c660144b2f664d014cb83c0f9e7d5d&X-Amz-SignedHeaders=host&actor_id=136622811&key_id=0&repo_id=980409545&token=1

Errors logged to '/home/jailuser/git/.git/lfs/logs/20260729T181403.276019622.log'.
Use git lfs logs last to view the log.
error: external filter 'git-lfs filter-process' failed
fatal: config/bin/detekt-cli: smudge filter lfs failed


Comment @coderabbitai help to get the list of available commands.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/expo/src/hooks/useSSO.ts (1)

110-110: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add a hook-level regression test for nonce normalization.

The helper tests cover parsing, but they do not verify that useSSO passes the sanitized nonce to signIn.reload. Add a test in packages/expo/src/hooks/__tests__/useSSO.test.ts covering literal and encoded trailing # values and asserting rotatingTokenNonce: 'abc123'.

As per coding guidelines, tests should cover new functionality, error handling, and edge cases.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/hooks/useSSO.ts` at line 110, Add a hook-level regression
test in useSSO tests that exercises the sign-in flow with both literal and
URL-encoded trailing # nonce values, then assert signIn.reload receives
rotatingTokenNonce: 'abc123'.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/expo/src/hooks/useSSO.ts`:
- Line 110: Add a hook-level regression test in useSSO tests that exercises the
sign-in flow with both literal and URL-encoded trailing # nonce values, then
assert signIn.reload receives rotatingTokenNonce: 'abc123'.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: b9d360f3-c5be-4b18-868a-96298e535428

📥 Commits

Reviewing files that changed from the base of the PR and between a8f6e89 and 49b396e.

📒 Files selected for processing (4)
  • .changeset/expo-callback-nonce-hash.md
  • packages/expo/src/hooks/useSSO.ts
  • packages/expo/src/utils/__tests__/authSessionCallback.test.ts
  • packages/expo/src/utils/authSessionCallback.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
  • clerk/cli(auto-detected)
  • clerk/clerk-ios(auto-detected)
  • clerk/clerk-android(auto-detected)

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/expo/src/hooks/useOAuth.ts`:
- Around line 102-103: Update the OAuth callback flow around
getAuthSessionCallbackParam and signIn.reload to reject a null or otherwise
missing rotating token nonce before invoking reload. Remove the empty-string
fallback, fail locally using the existing error-handling behavior used for
invalid auth callback data, and only pass a validated nonce to signIn.reload.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 0a12bfbe-65d8-4461-a000-9c9267333518

📥 Commits

Reviewing files that changed from the base of the PR and between 49b396e and b0842c7.

📒 Files selected for processing (2)
  • packages/expo/src/hooks/useHostedAuth.ts
  • packages/expo/src/hooks/useOAuth.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go(manual)
  • clerk/dashboard(manual)
  • clerk/accounts(manual)
  • clerk/backoffice(manual)
  • clerk/clerk(manual)
  • clerk/clerk-docs(manual)
  • clerk/cloudflare-workers(manual)
  • clerk/cli(auto-detected)
  • clerk/clerk-ios(auto-detected)
  • clerk/clerk-android(auto-detected)

Comment on lines +102 to 103
const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';
await signIn.reload({ rotatingTokenNonce });

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Reject missing or invalid nonces before reloading sign-in.

getAuthSessionCallbackParam returns null for malformed URLs or absent parameters, but || '' causes Line 103 to call signIn.reload({ rotatingTokenNonce: '' }). Fail locally, as hosted auth does, instead of forwarding an invalid nonce to FAPI.

Proposed fix
- const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';+ const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce');+ if (!rotatingTokenNonce) {+ return errorThrower.throw(+ 'OAuth callback did not include a rotating token nonce. Please restart the OAuth flow.',+ );+ }
await signIn.reload({ rotatingTokenNonce });
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
constrotatingTokenNonce=getAuthSessionCallbackParam(url,'rotating_token_nonce')||'';
awaitsignIn.reload({ rotatingTokenNonce });
constrotatingTokenNonce=getAuthSessionCallbackParam(url,'rotating_token_nonce');
if(!rotatingTokenNonce){
returnerrorThrower.throw(
'OAuth callback did not include a rotating token nonce. Please restart the OAuth flow.',
);
}
awaitsignIn.reload({ rotatingTokenNonce });
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/expo/src/hooks/useOAuth.ts` around lines 102 - 103, Update the OAuth
callback flow around getAuthSessionCallbackParam and signIn.reload to reject a
null or otherwise missing rotating token nonce before invoking reload. Remove
the empty-string fallback, fail locally using the existing error-handling
behavior used for invalid auth callback data, and only pass a validated nonce to
signIn.reload.

@wobsoriano

Copy link
Copy Markdown
MemberAuthor

closed in favor of logging an error if the redirectUrl they pass in useSSO is missing a path

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@wobsoriano@mikepitre