Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .changeset/keyless-leftover-cleanup.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
---
'@clerk/shared': minor
'@clerk/nextjs': patch
'@clerk/backend': minor
---

Remove leftover keyless-mode creation code now that no SDK mints keyless applications. `@clerk/shared/keyless` drops `resolveKeysWithKeylessFallback`, `getOrCreateKeys`, and related exports (internal APIs consumed only by Clerk SDKs); `@clerk/backend` removes the experimental `createAccountlessApplication` method; `@clerk/nextjs` deletes the unused keyless cookie reader and dead keyless middleware parameters, and logs a pointer to existing `.clerk/.tmp/keyless.json` keys when env keys are missing.
2 changes: 1 addition & 1 deletion integration/scripts/waitForServer.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,7 +6,7 @@ type WaitForServerArgsType = {
acceptAnyResponse?: boolean;
};

// Poll a url until it returns a 200 status code
// Poll a url until it returns 2xx (or any HTTP response when acceptAnyResponse is set)
export const waitForServer = async (url: string, opts: WaitForServerArgsType) => {
const { log, delayInMs = 1000, maxAttempts = 20, shouldExit = () => false, acceptAnyResponse = false } = opts;
let attempts = 0;
Expand Down
100 changes: 1 addition & 99 deletions integration/testUtils/keylessHelpers.ts
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,4 @@
import type { BrowserContext, Page } from '@playwright/test';
import { expect } from '@playwright/test';

import type { Application } from '../models/application';
import { createTestUtils } from './index';
import type { Page } from '@playwright/test';

/**
* Mocks the environment API call to return a claimed instance.
Expand All@@ -22,97 +18,3 @@ export const mockClaimedInstanceEnvironmentCall = async (page: Page): Promise<vo
await route.fulfill({ response, json: newJson });
});
};

/**
* Tests that the keyless popover can be toggled and the claim link opens the dashboard.
*/
export async function testToggleCollapsePopoverAndClaim({
page,
context,
app,
dashboardUrl,
framework,
}: {
page: Page;
context: BrowserContext;
app: Application;
dashboardUrl: string;
framework: string;
}): Promise<void> {
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();
await u.page.waitForClerkJsLoaded();
await u.po.expect.toBeSignedOut();

await u.po.keylessPopover.waitForMounted();

const claim = u.po.keylessPopover.promptsToClaim();

const href = await claim.getAttribute('href');
expect(href).toBeTruthy();

const claimUrl = new URL(href!);
expect(claimUrl.origin + '/').toBe(dashboardUrl);
expect(claimUrl.pathname).toBe('/apps/claim');
expect(claimUrl.searchParams.get('framework')).toBe(framework);
expect(claimUrl.searchParams.has('token')).toBe(true);
expect(claimUrl.searchParams.has('return_url')).toBe(true);
}

/**
* Tests that a claimed application with missing explicit keys shows the popover expanded
* with a prompt to get keys from the dashboard.
*/
export async function testClaimedAppWithMissingKeys({
page,
context,
app,
dashboardUrl,
}: {
page: Page;
context: BrowserContext;
app: Application;
dashboardUrl: string;
}): Promise<void> {
await mockClaimedInstanceEnvironmentCall(page);
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();
await u.page.waitForClerkJsLoaded();

await u.po.keylessPopover.waitForMounted();
expect(await u.po.keylessPopover.isExpanded()).toBe(true);
await expect(u.po.keylessPopover.promptToUseClaimedKeys()).toBeVisible();

const href = await u.po.keylessPopover.promptToUseClaimedKeys().getAttribute('href');
expect(href).toBeTruthy();
expect(href).toContain(dashboardUrl);
}

/**
* Tests that the keyless popover is removed after adding keys to .env and restarting the dev server.
*/
export async function testKeylessRemovedAfterEnvAndRestart({
page,
context,
app,
}: {
page: Page;
context: BrowserContext;
app: Application;
}): Promise<void> {
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();

await u.po.keylessPopover.waitForMounted();

// Copy keys from keyless.json to .env
await app.keylessToEnv();

// Restart the dev server to pick up new env vars (Vite doesn't hot-reload .env)
await app.restart();

await u.page.goToAppHome();

// Keyless popover should no longer be present since we now have explicit keys
await u.po.keylessPopover.waitForUnmounted();
}
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,48 +13,6 @@ describe('AccountlessApplications', () => {
api_keys_url: 'https://dashboard.clerk.com/api-keys',
};

it('creates an accountless application with a source query parameter', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
});

server.use(
http.post('https://api.clerk.test/v1/accountless_applications', ({ request }) => {
const url = new URL(request.url);
expect(url.searchParams.get('source')).toBe('nextjs');
expect(request.headers.get('Clerk-API-Version')).toBeTruthy();
expect(request.headers.get('User-Agent')).toBe('@clerk/backend@0.0.0-test');

return HttpResponse.json(mockAccountlessApplication);
}),
);

const response = await apiClient.__experimental_accountlessApplications.createAccountlessApplication({
source: 'nextjs',
});

expect(response.publishableKey).toBe('pk_test_keyless');
});

it('creates an accountless application without a source query parameter when source is omitted', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
});

server.use(
http.post('https://api.clerk.test/v1/accountless_applications', ({ request }) => {
const url = new URL(request.url);
expect(url.searchParams.has('source')).toBe(false);

return HttpResponse.json(mockAccountlessApplication);
}),
);

const response = await apiClient.__experimental_accountlessApplications.createAccountlessApplication();

expect(response.publishableKey).toBe('pk_test_keyless');
});

it('completes accountless application onboarding with a source query parameter', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
Expand Down
12 changes: 0 additions & 12 deletions packages/backend/src/api/endpoints/AccountlessApplicationsAPI.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,18 +10,6 @@ type AccountlessApplicationParams = {
};

export class AccountlessApplicationAPI extends AbstractAPI {
public async createAccountlessApplication(params?: AccountlessApplicationParams): Promise<AccountlessApplication> {
const headerParams = params?.requestHeaders ? Object.fromEntries(params.requestHeaders.entries()) : undefined;
return this.request<AccountlessApplication>({
method: 'POST',
path: basePath,
headerParams,
queryParams: {
source: params?.source,
},
});
}

public async completeAccountlessApplicationOnboarding(
params?: AccountlessApplicationParams,
): Promise<AccountlessApplication> {
Expand Down
13 changes: 7 additions & 6 deletions packages/nextjs/src/app-router/server/ClerkProvider.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@ import React, { Suspense } from 'react';
import { getDynamicAuthData } from '../../server/buildClerkProps';
import { errorThrower } from '../../server/errorThrower';
import type { NextClerkProviderProps } from '../../types';
import { canUseKeyless } from '../../utils/feature-flags';
import { mergeNextClerkPropsWithEnv } from '../../utils/mergeNextClerkPropsWithEnv';
import { ClientClerkProvider } from '../client/ClerkProvider';
import { DynamicClerkScripts } from './DynamicClerkScripts';
Expand DownExpand Up@@ -32,7 +33,7 @@ export async function ClerkProvider<TUi extends Ui = Ui>(
initialState: statePromiseOrValue as InitialState | undefined,
});

const { shouldRunAsKeyless, runningWithClaimedKeys } = await getKeylessStatus(propsWithEnvs);
const { runningWithClaimedKeys } = await getKeylessStatus(propsWithEnvs);

// When dynamic mode is enabled, render scripts in a Suspense boundary to isolate
// the nonce fetching (which calls headers()) from the rest of the page.
Expand All@@ -52,14 +53,14 @@ export async function ClerkProvider<TUi extends Ui = Ui>(
</Suspense>
) : undefined;

if (shouldRunAsKeyless) {
if (!propsWithEnvs.publishableKey) {
errorThrower.throwMissingPublishableKeyError();
}
if (canUseKeyless && !propsWithEnvs.publishableKey) {
errorThrower.throwMissingPublishableKeyError();
}

if (runningWithClaimedKeys) {
return (
<KeylessProvider
rest={propsWithEnvs}
runningWithClaimedKeys={runningWithClaimedKeys}
__internal_scriptsSlot={scriptsSlot}
>
{children}
Expand Down
85 changes: 33 additions & 52 deletions packages/nextjs/src/app-router/server/keyless-provider.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -11,40 +11,42 @@ import { deleteKeylessAction } from '../keyless-actions';
export async function getKeylessStatus(
params: Without<NextClerkProviderProps, '__internal_invokeMiddlewareOnAuthStateChange' | 'children'>,
) {
let [shouldRunAsKeyless, runningWithClaimedKeys, locallyStoredPublishableKey] = [false, false, ''];
if (canUseKeyless) {
locallyStoredPublishableKey = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys()?.publishableKey || '')
.catch(() => '');
if (!canUseKeyless) {
return { runningWithClaimedKeys: false };
}

runningWithClaimedKeys = Boolean(params.publishableKey) && params.publishableKey === locallyStoredPublishableKey;
shouldRunAsKeyless = !params.publishableKey || runningWithClaimedKeys;
const storedKeys = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys() ?? null)
.catch(() => null);
if (!storedKeys) {
return { runningWithClaimedKeys: false };
}

return {
shouldRunAsKeyless,
runningWithClaimedKeys,
};
if (!params.publishableKey) {
const { clerkDevelopmentCache } = await import('../../server/keyless-log-cache.js');
clerkDevelopmentCache?.log({
cacheKey: `${storedKeys.publishableKey}_stored`,
msg: `[Clerk]: Found existing keyless-mode keys in .clerk/.tmp/keyless.json. Copy the publishableKey and secretKey into .env.local (NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY / CLERK_SECRET_KEY) to keep using that application, or claim it at ${storedKeys.claimUrl}`,
});
return { runningWithClaimedKeys: false };
}

return { runningWithClaimedKeys: params.publishableKey === storedKeys.publishableKey };
}

type KeylessProviderProps = PropsWithChildren<{
rest: Without<NextClerkProviderProps, '__internal_invokeMiddlewareOnAuthStateChange' | 'children'>;
runningWithClaimedKeys: boolean;
__internal_scriptsSlot?: React.ReactNode;
}>;

export const KeylessProvider = async (props: KeylessProviderProps) => {
const { rest, runningWithClaimedKeys, __internal_scriptsSlot, children } = props;
const { rest, __internal_scriptsSlot, children } = props;

// Read-only: the SDK no longer mints keyless applications, it only reads claimed keys from disk.
const newOrReadKeys = await import('../../server/keyless-node.js')
const storedKeys = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys() ?? null)
.catch(() => null);

const { clerkDevelopmentCache, createConfirmationMessage } = await import('../../server/keyless-log-cache.js');

if (!newOrReadKeys) {
// When case keyless should run, but keys are not available, then fallback to throwing for missing keys
if (!storedKeys) {
return (
<ClientClerkProvider
{...mergeNextClerkPropsWithEnv(rest)}
Expand All@@ -56,46 +58,25 @@ export const KeylessProvider = async (props: KeylessProviderProps) => {
);
}

const clientProvider = (
try {
const keylessService = await import('../../server/keyless-node.js').then(mod => mod.keyless());
const { completeClaimedOnboarding } = await import('@clerk/shared/keyless');
await completeClaimedOnboarding(storedKeys.publishableKey, keylessService);
} catch {
// noop
}

return (
<ClientClerkProvider
{...mergeNextClerkPropsWithEnv({
...rest,
publishableKey: newOrReadKeys.publishableKey,
__internal_keyless_claimKeylessApplicationUrl: newOrReadKeys.claimUrl,
__internal_keyless_copyInstanceKeysUrl: newOrReadKeys.apiKeysUrl,
// Explicitly use `null` instead of `undefined` here to avoid persisting `deleteKeylessAction` during merging of options.
__internal_keyless_dismissPrompt: runningWithClaimedKeys ? deleteKeylessAction : null,
__internal_keyless_claimKeylessApplicationUrl: storedKeys.claimUrl,
__internal_keyless_copyInstanceKeysUrl: storedKeys.apiKeysUrl,
__internal_keyless_dismissPrompt: deleteKeylessAction,
})}
__internal_scriptsSlot={__internal_scriptsSlot}
>
{children}
</ClientClerkProvider>
);

if (runningWithClaimedKeys) {
try {
const keylessService = await import('../../server/keyless-node.js').then(mod => mod.keyless());

/**
* Notifying the dashboard should run once. We are controlling this behaviour by caching the result of the request.
* If the request fails, it will be considered stale after 10 minutes, otherwise it is cached for 24 hours.
*/
await clerkDevelopmentCache?.run(() => keylessService.completeOnboarding(), {
cacheKey: `${newOrReadKeys.publishableKey}_complete`,
onSuccessStale: 24 * 60 * 60 * 1000, // 24 hours
});
} catch {
// noop
}

/**
* Notify developers.
*/
clerkDevelopmentCache?.log({
cacheKey: `${newOrReadKeys.publishableKey}_claimed`,
msg: createConfirmationMessage(),
});
}

return clientProvider;
};
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,8 +3,7 @@ import type { NextFetchEvent } from 'next/server';
import { NextRequest } from 'next/server';
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest';

// The mock SHOULD exist before the imports: unlike clerkMiddleware.test.ts, keys are empty so the
// missing-key error path is reachable.
// The mock SHOULD exist before the imports. Keys are intentionally empty so the missing-key error path is reachable.
vi.mock(import('../constants.js'), async importOriginal => {
const actual = await importOriginal();
return {
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -37,7 +37,6 @@ const mockRequest = (params: MockRequestParams) => {
if (machineAuthObject) {
const encryptedData = encryptClerkRequestData(
{}, // requestData
{}, // keylessModeKeys
// @ts-expect-error - mock machine auth object
machineAuthObject,
);
Expand Down
1 change: 0 additions & 1 deletion packages/nextjs/src/server/clerkMiddleware.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -389,7 +389,6 @@ async function runHandlerWithRequestState({
handlerResult,
requestState,
resolvedParams,
{},
authObject.tokenType === 'session_token' ? null : makeAuthObjectSerializable(authObject),
);

Expand Down
9 changes: 2 additions & 7 deletions packages/nextjs/src/server/keyless-log-cache.ts
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,5 @@
/**
* Re-export keyless development cache utilities from shared.
* Re-export the keyless development cache from shared.
* This maintains backward compatibility with existing imports.
*/
export {
clerkDevelopmentCache,
createClerkDevCache,
createConfirmationMessage,
createKeylessModeMessage,
} from '@clerk/shared/keyless';
export { clerkDevelopmentCache } from '@clerk/shared/keyless';
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .changeset/keyless-leftover-cleanup.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
---
'@clerk/shared': minor
'@clerk/nextjs': patch
'@clerk/backend': minor
---

Remove leftover keyless-mode creation code now that no SDK mints keyless applications. `@clerk/shared/keyless` drops `resolveKeysWithKeylessFallback`, `getOrCreateKeys`, and related exports (internal APIs consumed only by Clerk SDKs); `@clerk/backend` removes the experimental `createAccountlessApplication` method; `@clerk/nextjs` deletes the unused keyless cookie reader and dead keyless middleware parameters, and logs a pointer to existing `.clerk/.tmp/keyless.json` keys when env keys are missing.
2 changes: 1 addition & 1 deletion integration/scripts/waitForServer.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,7 +6,7 @@ type WaitForServerArgsType = {
acceptAnyResponse?: boolean;
};

// Poll a url until it returns a 200 status code
// Poll a url until it returns 2xx (or any HTTP response when acceptAnyResponse is set)
export const waitForServer = async (url: string, opts: WaitForServerArgsType) => {
const { log, delayInMs = 1000, maxAttempts = 20, shouldExit = () => false, acceptAnyResponse = false } = opts;
let attempts = 0;
Expand Down
100 changes: 1 addition & 99 deletions integration/testUtils/keylessHelpers.ts
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,4 @@
import type { BrowserContext, Page } from '@playwright/test';
import { expect } from '@playwright/test';

import type { Application } from '../models/application';
import { createTestUtils } from './index';
import type { Page } from '@playwright/test';

/**
* Mocks the environment API call to return a claimed instance.
Expand All@@ -22,97 +18,3 @@ export const mockClaimedInstanceEnvironmentCall = async (page: Page): Promise<vo
await route.fulfill({ response, json: newJson });
});
};

/**
* Tests that the keyless popover can be toggled and the claim link opens the dashboard.
*/
export async function testToggleCollapsePopoverAndClaim({
page,
context,
app,
dashboardUrl,
framework,
}: {
page: Page;
context: BrowserContext;
app: Application;
dashboardUrl: string;
framework: string;
}): Promise<void> {
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();
await u.page.waitForClerkJsLoaded();
await u.po.expect.toBeSignedOut();

await u.po.keylessPopover.waitForMounted();

const claim = u.po.keylessPopover.promptsToClaim();

const href = await claim.getAttribute('href');
expect(href).toBeTruthy();

const claimUrl = new URL(href!);
expect(claimUrl.origin + '/').toBe(dashboardUrl);
expect(claimUrl.pathname).toBe('/apps/claim');
expect(claimUrl.searchParams.get('framework')).toBe(framework);
expect(claimUrl.searchParams.has('token')).toBe(true);
expect(claimUrl.searchParams.has('return_url')).toBe(true);
}

/**
* Tests that a claimed application with missing explicit keys shows the popover expanded
* with a prompt to get keys from the dashboard.
*/
export async function testClaimedAppWithMissingKeys({
page,
context,
app,
dashboardUrl,
}: {
page: Page;
context: BrowserContext;
app: Application;
dashboardUrl: string;
}): Promise<void> {
await mockClaimedInstanceEnvironmentCall(page);
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();
await u.page.waitForClerkJsLoaded();

await u.po.keylessPopover.waitForMounted();
expect(await u.po.keylessPopover.isExpanded()).toBe(true);
await expect(u.po.keylessPopover.promptToUseClaimedKeys()).toBeVisible();

const href = await u.po.keylessPopover.promptToUseClaimedKeys().getAttribute('href');
expect(href).toBeTruthy();
expect(href).toContain(dashboardUrl);
}

/**
* Tests that the keyless popover is removed after adding keys to .env and restarting the dev server.
*/
export async function testKeylessRemovedAfterEnvAndRestart({
page,
context,
app,
}: {
page: Page;
context: BrowserContext;
app: Application;
}): Promise<void> {
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();

await u.po.keylessPopover.waitForMounted();

// Copy keys from keyless.json to .env
await app.keylessToEnv();

// Restart the dev server to pick up new env vars (Vite doesn't hot-reload .env)
await app.restart();

await u.page.goToAppHome();

// Keyless popover should no longer be present since we now have explicit keys
await u.po.keylessPopover.waitForUnmounted();
}
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,48 +13,6 @@ describe('AccountlessApplications', () => {
api_keys_url: 'https://dashboard.clerk.com/api-keys',
};

it('creates an accountless application with a source query parameter', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
});

server.use(
http.post('https://api.clerk.test/v1/accountless_applications', ({ request }) => {
const url = new URL(request.url);
expect(url.searchParams.get('source')).toBe('nextjs');
expect(request.headers.get('Clerk-API-Version')).toBeTruthy();
expect(request.headers.get('User-Agent')).toBe('@clerk/backend@0.0.0-test');

return HttpResponse.json(mockAccountlessApplication);
}),
);

const response = await apiClient.__experimental_accountlessApplications.createAccountlessApplication({
source: 'nextjs',
});

expect(response.publishableKey).toBe('pk_test_keyless');
});

it('creates an accountless application without a source query parameter when source is omitted', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
});

server.use(
http.post('https://api.clerk.test/v1/accountless_applications', ({ request }) => {
const url = new URL(request.url);
expect(url.searchParams.has('source')).toBe(false);

return HttpResponse.json(mockAccountlessApplication);
}),
);

const response = await apiClient.__experimental_accountlessApplications.createAccountlessApplication();

expect(response.publishableKey).toBe('pk_test_keyless');
});

it('completes accountless application onboarding with a source query parameter', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
Expand Down
12 changes: 0 additions & 12 deletions packages/backend/src/api/endpoints/AccountlessApplicationsAPI.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,18 +10,6 @@ type AccountlessApplicationParams = {
};

export class AccountlessApplicationAPI extends AbstractAPI {
public async createAccountlessApplication(params?: AccountlessApplicationParams): Promise<AccountlessApplication> {
const headerParams = params?.requestHeaders ? Object.fromEntries(params.requestHeaders.entries()) : undefined;
return this.request<AccountlessApplication>({
method: 'POST',
path: basePath,
headerParams,
queryParams: {
source: params?.source,
},
});
}

public async completeAccountlessApplicationOnboarding(
params?: AccountlessApplicationParams,
): Promise<AccountlessApplication> {
Expand Down
13 changes: 7 additions & 6 deletions packages/nextjs/src/app-router/server/ClerkProvider.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@ import React, { Suspense } from 'react';
import { getDynamicAuthData } from '../../server/buildClerkProps';
import { errorThrower } from '../../server/errorThrower';
import type { NextClerkProviderProps } from '../../types';
import { canUseKeyless } from '../../utils/feature-flags';
import { mergeNextClerkPropsWithEnv } from '../../utils/mergeNextClerkPropsWithEnv';
import { ClientClerkProvider } from '../client/ClerkProvider';
import { DynamicClerkScripts } from './DynamicClerkScripts';
Expand DownExpand Up@@ -32,7 +33,7 @@ export async function ClerkProvider<TUi extends Ui = Ui>(
initialState: statePromiseOrValue as InitialState | undefined,
});

const { shouldRunAsKeyless, runningWithClaimedKeys } = await getKeylessStatus(propsWithEnvs);
const { runningWithClaimedKeys } = await getKeylessStatus(propsWithEnvs);

// When dynamic mode is enabled, render scripts in a Suspense boundary to isolate
// the nonce fetching (which calls headers()) from the rest of the page.
Expand All@@ -52,14 +53,14 @@ export async function ClerkProvider<TUi extends Ui = Ui>(
</Suspense>
) : undefined;

if (shouldRunAsKeyless) {
if (!propsWithEnvs.publishableKey) {
errorThrower.throwMissingPublishableKeyError();
}
if (canUseKeyless && !propsWithEnvs.publishableKey) {
errorThrower.throwMissingPublishableKeyError();
}

if (runningWithClaimedKeys) {
return (
<KeylessProvider
rest={propsWithEnvs}
runningWithClaimedKeys={runningWithClaimedKeys}
__internal_scriptsSlot={scriptsSlot}
>
{children}
Expand Down
85 changes: 33 additions & 52 deletions packages/nextjs/src/app-router/server/keyless-provider.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -11,40 +11,42 @@ import { deleteKeylessAction } from '../keyless-actions';
export async function getKeylessStatus(
params: Without<NextClerkProviderProps, '__internal_invokeMiddlewareOnAuthStateChange' | 'children'>,
) {
let [shouldRunAsKeyless, runningWithClaimedKeys, locallyStoredPublishableKey] = [false, false, ''];
if (canUseKeyless) {
locallyStoredPublishableKey = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys()?.publishableKey || '')
.catch(() => '');
if (!canUseKeyless) {
return { runningWithClaimedKeys: false };
}

runningWithClaimedKeys = Boolean(params.publishableKey) && params.publishableKey === locallyStoredPublishableKey;
shouldRunAsKeyless = !params.publishableKey || runningWithClaimedKeys;
const storedKeys = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys() ?? null)
.catch(() => null);
if (!storedKeys) {
return { runningWithClaimedKeys: false };
}

return {
shouldRunAsKeyless,
runningWithClaimedKeys,
};
if (!params.publishableKey) {
const { clerkDevelopmentCache } = await import('../../server/keyless-log-cache.js');
clerkDevelopmentCache?.log({
cacheKey: `${storedKeys.publishableKey}_stored`,
msg: `[Clerk]: Found existing keyless-mode keys in .clerk/.tmp/keyless.json. Copy the publishableKey and secretKey into .env.local (NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY / CLERK_SECRET_KEY) to keep using that application, or claim it at ${storedKeys.claimUrl}`,
});
return { runningWithClaimedKeys: false };
}

return { runningWithClaimedKeys: params.publishableKey === storedKeys.publishableKey };
}

type KeylessProviderProps = PropsWithChildren<{
rest: Without<NextClerkProviderProps, '__internal_invokeMiddlewareOnAuthStateChange' | 'children'>;
runningWithClaimedKeys: boolean;
__internal_scriptsSlot?: React.ReactNode;
}>;

export const KeylessProvider = async (props: KeylessProviderProps) => {
const { rest, runningWithClaimedKeys, __internal_scriptsSlot, children } = props;
const { rest, __internal_scriptsSlot, children } = props;

// Read-only: the SDK no longer mints keyless applications, it only reads claimed keys from disk.
const newOrReadKeys = await import('../../server/keyless-node.js')
const storedKeys = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys() ?? null)
.catch(() => null);

const { clerkDevelopmentCache, createConfirmationMessage } = await import('../../server/keyless-log-cache.js');

if (!newOrReadKeys) {
// When case keyless should run, but keys are not available, then fallback to throwing for missing keys
if (!storedKeys) {
return (
<ClientClerkProvider
{...mergeNextClerkPropsWithEnv(rest)}
Expand All@@ -56,46 +58,25 @@ export const KeylessProvider = async (props: KeylessProviderProps) => {
);
}

const clientProvider = (
try {
const keylessService = await import('../../server/keyless-node.js').then(mod => mod.keyless());
const { completeClaimedOnboarding } = await import('@clerk/shared/keyless');
await completeClaimedOnboarding(storedKeys.publishableKey, keylessService);
} catch {
// noop
}

return (
<ClientClerkProvider
{...mergeNextClerkPropsWithEnv({
...rest,
publishableKey: newOrReadKeys.publishableKey,
__internal_keyless_claimKeylessApplicationUrl: newOrReadKeys.claimUrl,
__internal_keyless_copyInstanceKeysUrl: newOrReadKeys.apiKeysUrl,
// Explicitly use `null` instead of `undefined` here to avoid persisting `deleteKeylessAction` during merging of options.
__internal_keyless_dismissPrompt: runningWithClaimedKeys ? deleteKeylessAction : null,
__internal_keyless_claimKeylessApplicationUrl: storedKeys.claimUrl,
__internal_keyless_copyInstanceKeysUrl: storedKeys.apiKeysUrl,
__internal_keyless_dismissPrompt: deleteKeylessAction,
})}
__internal_scriptsSlot={__internal_scriptsSlot}
>
{children}
</ClientClerkProvider>
);

if (runningWithClaimedKeys) {
try {
const keylessService = await import('../../server/keyless-node.js').then(mod => mod.keyless());

/**
* Notifying the dashboard should run once. We are controlling this behaviour by caching the result of the request.
* If the request fails, it will be considered stale after 10 minutes, otherwise it is cached for 24 hours.
*/
await clerkDevelopmentCache?.run(() => keylessService.completeOnboarding(), {
cacheKey: `${newOrReadKeys.publishableKey}_complete`,
onSuccessStale: 24 * 60 * 60 * 1000, // 24 hours
});
} catch {
// noop
}

/**
* Notify developers.
*/
clerkDevelopmentCache?.log({
cacheKey: `${newOrReadKeys.publishableKey}_claimed`,
msg: createConfirmationMessage(),
});
}

return clientProvider;
};
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,8 +3,7 @@ import type { NextFetchEvent } from 'next/server';
import { NextRequest } from 'next/server';
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest';

// The mock SHOULD exist before the imports: unlike clerkMiddleware.test.ts, keys are empty so the
// missing-key error path is reachable.
// The mock SHOULD exist before the imports. Keys are intentionally empty so the missing-key error path is reachable.
vi.mock(import('../constants.js'), async importOriginal => {
const actual = await importOriginal();
return {
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -37,7 +37,6 @@ const mockRequest = (params: MockRequestParams) => {
if (machineAuthObject) {
const encryptedData = encryptClerkRequestData(
{}, // requestData
{}, // keylessModeKeys
// @ts-expect-error - mock machine auth object
machineAuthObject,
);
Expand Down
1 change: 0 additions & 1 deletion packages/nextjs/src/server/clerkMiddleware.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -389,7 +389,6 @@ async function runHandlerWithRequestState({
handlerResult,
requestState,
resolvedParams,
{},
authObject.tokenType === 'session_token' ? null : makeAuthObjectSerializable(authObject),
);

Expand Down
9 changes: 2 additions & 7 deletions packages/nextjs/src/server/keyless-log-cache.ts
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,5 @@
/**
* Re-export keyless development cache utilities from shared.
* Re-export the keyless development cache from shared.
* This maintains backward compatibility with existing imports.
*/
export {
clerkDevelopmentCache,
createClerkDevCache,
createConfirmationMessage,
createKeylessModeMessage,
} from '@clerk/shared/keyless';
export { clerkDevelopmentCache } from '@clerk/shared/keyless';
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .changeset/keyless-leftover-cleanup.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
---
'@clerk/shared': minor
'@clerk/nextjs': patch
'@clerk/backend': minor
---

Remove leftover keyless-mode creation code now that no SDK mints keyless applications. `@clerk/shared/keyless` drops `resolveKeysWithKeylessFallback`, `getOrCreateKeys`, and related exports (internal APIs consumed only by Clerk SDKs); `@clerk/backend` removes the experimental `createAccountlessApplication` method; `@clerk/nextjs` deletes the unused keyless cookie reader and dead keyless middleware parameters, and logs a pointer to existing `.clerk/.tmp/keyless.json` keys when env keys are missing.
2 changes: 1 addition & 1 deletion integration/scripts/waitForServer.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,7 +6,7 @@ type WaitForServerArgsType = {
acceptAnyResponse?: boolean;
};

// Poll a url until it returns a 200 status code
// Poll a url until it returns 2xx (or any HTTP response when acceptAnyResponse is set)
export const waitForServer = async (url: string, opts: WaitForServerArgsType) => {
const { log, delayInMs = 1000, maxAttempts = 20, shouldExit = () => false, acceptAnyResponse = false } = opts;
let attempts = 0;
Expand Down
100 changes: 1 addition & 99 deletions integration/testUtils/keylessHelpers.ts
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,4 @@
import type { BrowserContext, Page } from '@playwright/test';
import { expect } from '@playwright/test';

import type { Application } from '../models/application';
import { createTestUtils } from './index';
import type { Page } from '@playwright/test';

/**
* Mocks the environment API call to return a claimed instance.
Expand All@@ -22,97 +18,3 @@ export const mockClaimedInstanceEnvironmentCall = async (page: Page): Promise<vo
await route.fulfill({ response, json: newJson });
});
};

/**
* Tests that the keyless popover can be toggled and the claim link opens the dashboard.
*/
export async function testToggleCollapsePopoverAndClaim({
page,
context,
app,
dashboardUrl,
framework,
}: {
page: Page;
context: BrowserContext;
app: Application;
dashboardUrl: string;
framework: string;
}): Promise<void> {
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();
await u.page.waitForClerkJsLoaded();
await u.po.expect.toBeSignedOut();

await u.po.keylessPopover.waitForMounted();

const claim = u.po.keylessPopover.promptsToClaim();

const href = await claim.getAttribute('href');
expect(href).toBeTruthy();

const claimUrl = new URL(href!);
expect(claimUrl.origin + '/').toBe(dashboardUrl);
expect(claimUrl.pathname).toBe('/apps/claim');
expect(claimUrl.searchParams.get('framework')).toBe(framework);
expect(claimUrl.searchParams.has('token')).toBe(true);
expect(claimUrl.searchParams.has('return_url')).toBe(true);
}

/**
* Tests that a claimed application with missing explicit keys shows the popover expanded
* with a prompt to get keys from the dashboard.
*/
export async function testClaimedAppWithMissingKeys({
page,
context,
app,
dashboardUrl,
}: {
page: Page;
context: BrowserContext;
app: Application;
dashboardUrl: string;
}): Promise<void> {
await mockClaimedInstanceEnvironmentCall(page);
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();
await u.page.waitForClerkJsLoaded();

await u.po.keylessPopover.waitForMounted();
expect(await u.po.keylessPopover.isExpanded()).toBe(true);
await expect(u.po.keylessPopover.promptToUseClaimedKeys()).toBeVisible();

const href = await u.po.keylessPopover.promptToUseClaimedKeys().getAttribute('href');
expect(href).toBeTruthy();
expect(href).toContain(dashboardUrl);
}

/**
* Tests that the keyless popover is removed after adding keys to .env and restarting the dev server.
*/
export async function testKeylessRemovedAfterEnvAndRestart({
page,
context,
app,
}: {
page: Page;
context: BrowserContext;
app: Application;
}): Promise<void> {
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();

await u.po.keylessPopover.waitForMounted();

// Copy keys from keyless.json to .env
await app.keylessToEnv();

// Restart the dev server to pick up new env vars (Vite doesn't hot-reload .env)
await app.restart();

await u.page.goToAppHome();

// Keyless popover should no longer be present since we now have explicit keys
await u.po.keylessPopover.waitForUnmounted();
}
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,48 +13,6 @@ describe('AccountlessApplications', () => {
api_keys_url: 'https://dashboard.clerk.com/api-keys',
};

it('creates an accountless application with a source query parameter', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
});

server.use(
http.post('https://api.clerk.test/v1/accountless_applications', ({ request }) => {
const url = new URL(request.url);
expect(url.searchParams.get('source')).toBe('nextjs');
expect(request.headers.get('Clerk-API-Version')).toBeTruthy();
expect(request.headers.get('User-Agent')).toBe('@clerk/backend@0.0.0-test');

return HttpResponse.json(mockAccountlessApplication);
}),
);

const response = await apiClient.__experimental_accountlessApplications.createAccountlessApplication({
source: 'nextjs',
});

expect(response.publishableKey).toBe('pk_test_keyless');
});

it('creates an accountless application without a source query parameter when source is omitted', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
});

server.use(
http.post('https://api.clerk.test/v1/accountless_applications', ({ request }) => {
const url = new URL(request.url);
expect(url.searchParams.has('source')).toBe(false);

return HttpResponse.json(mockAccountlessApplication);
}),
);

const response = await apiClient.__experimental_accountlessApplications.createAccountlessApplication();

expect(response.publishableKey).toBe('pk_test_keyless');
});

it('completes accountless application onboarding with a source query parameter', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
Expand Down
12 changes: 0 additions & 12 deletions packages/backend/src/api/endpoints/AccountlessApplicationsAPI.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,18 +10,6 @@ type AccountlessApplicationParams = {
};

export class AccountlessApplicationAPI extends AbstractAPI {
public async createAccountlessApplication(params?: AccountlessApplicationParams): Promise<AccountlessApplication> {
const headerParams = params?.requestHeaders ? Object.fromEntries(params.requestHeaders.entries()) : undefined;
return this.request<AccountlessApplication>({
method: 'POST',
path: basePath,
headerParams,
queryParams: {
source: params?.source,
},
});
}

public async completeAccountlessApplicationOnboarding(
params?: AccountlessApplicationParams,
): Promise<AccountlessApplication> {
Expand Down
13 changes: 7 additions & 6 deletions packages/nextjs/src/app-router/server/ClerkProvider.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@ import React, { Suspense } from 'react';
import { getDynamicAuthData } from '../../server/buildClerkProps';
import { errorThrower } from '../../server/errorThrower';
import type { NextClerkProviderProps } from '../../types';
import { canUseKeyless } from '../../utils/feature-flags';
import { mergeNextClerkPropsWithEnv } from '../../utils/mergeNextClerkPropsWithEnv';
import { ClientClerkProvider } from '../client/ClerkProvider';
import { DynamicClerkScripts } from './DynamicClerkScripts';
Expand DownExpand Up@@ -32,7 +33,7 @@ export async function ClerkProvider<TUi extends Ui = Ui>(
initialState: statePromiseOrValue as InitialState | undefined,
});

const { shouldRunAsKeyless, runningWithClaimedKeys } = await getKeylessStatus(propsWithEnvs);
const { runningWithClaimedKeys } = await getKeylessStatus(propsWithEnvs);

// When dynamic mode is enabled, render scripts in a Suspense boundary to isolate
// the nonce fetching (which calls headers()) from the rest of the page.
Expand All@@ -52,14 +53,14 @@ export async function ClerkProvider<TUi extends Ui = Ui>(
</Suspense>
) : undefined;

if (shouldRunAsKeyless) {
if (!propsWithEnvs.publishableKey) {
errorThrower.throwMissingPublishableKeyError();
}
if (canUseKeyless && !propsWithEnvs.publishableKey) {
errorThrower.throwMissingPublishableKeyError();
}

if (runningWithClaimedKeys) {
return (
<KeylessProvider
rest={propsWithEnvs}
runningWithClaimedKeys={runningWithClaimedKeys}
__internal_scriptsSlot={scriptsSlot}
>
{children}
Expand Down
85 changes: 33 additions & 52 deletions packages/nextjs/src/app-router/server/keyless-provider.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -11,40 +11,42 @@ import { deleteKeylessAction } from '../keyless-actions';
export async function getKeylessStatus(
params: Without<NextClerkProviderProps, '__internal_invokeMiddlewareOnAuthStateChange' | 'children'>,
) {
let [shouldRunAsKeyless, runningWithClaimedKeys, locallyStoredPublishableKey] = [false, false, ''];
if (canUseKeyless) {
locallyStoredPublishableKey = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys()?.publishableKey || '')
.catch(() => '');
if (!canUseKeyless) {
return { runningWithClaimedKeys: false };
}

runningWithClaimedKeys = Boolean(params.publishableKey) && params.publishableKey === locallyStoredPublishableKey;
shouldRunAsKeyless = !params.publishableKey || runningWithClaimedKeys;
const storedKeys = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys() ?? null)
.catch(() => null);
if (!storedKeys) {
return { runningWithClaimedKeys: false };
}

return {
shouldRunAsKeyless,
runningWithClaimedKeys,
};
if (!params.publishableKey) {
const { clerkDevelopmentCache } = await import('../../server/keyless-log-cache.js');
clerkDevelopmentCache?.log({
cacheKey: `${storedKeys.publishableKey}_stored`,
msg: `[Clerk]: Found existing keyless-mode keys in .clerk/.tmp/keyless.json. Copy the publishableKey and secretKey into .env.local (NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY / CLERK_SECRET_KEY) to keep using that application, or claim it at ${storedKeys.claimUrl}`,
});
return { runningWithClaimedKeys: false };
}

return { runningWithClaimedKeys: params.publishableKey === storedKeys.publishableKey };
}

type KeylessProviderProps = PropsWithChildren<{
rest: Without<NextClerkProviderProps, '__internal_invokeMiddlewareOnAuthStateChange' | 'children'>;
runningWithClaimedKeys: boolean;
__internal_scriptsSlot?: React.ReactNode;
}>;

export const KeylessProvider = async (props: KeylessProviderProps) => {
const { rest, runningWithClaimedKeys, __internal_scriptsSlot, children } = props;
const { rest, __internal_scriptsSlot, children } = props;

// Read-only: the SDK no longer mints keyless applications, it only reads claimed keys from disk.
const newOrReadKeys = await import('../../server/keyless-node.js')
const storedKeys = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys() ?? null)
.catch(() => null);

const { clerkDevelopmentCache, createConfirmationMessage } = await import('../../server/keyless-log-cache.js');

if (!newOrReadKeys) {
// When case keyless should run, but keys are not available, then fallback to throwing for missing keys
if (!storedKeys) {
return (
<ClientClerkProvider
{...mergeNextClerkPropsWithEnv(rest)}
Expand All@@ -56,46 +58,25 @@ export const KeylessProvider = async (props: KeylessProviderProps) => {
);
}

const clientProvider = (
try {
const keylessService = await import('../../server/keyless-node.js').then(mod => mod.keyless());
const { completeClaimedOnboarding } = await import('@clerk/shared/keyless');
await completeClaimedOnboarding(storedKeys.publishableKey, keylessService);
} catch {
// noop
}

return (
<ClientClerkProvider
{...mergeNextClerkPropsWithEnv({
...rest,
publishableKey: newOrReadKeys.publishableKey,
__internal_keyless_claimKeylessApplicationUrl: newOrReadKeys.claimUrl,
__internal_keyless_copyInstanceKeysUrl: newOrReadKeys.apiKeysUrl,
// Explicitly use `null` instead of `undefined` here to avoid persisting `deleteKeylessAction` during merging of options.
__internal_keyless_dismissPrompt: runningWithClaimedKeys ? deleteKeylessAction : null,
__internal_keyless_claimKeylessApplicationUrl: storedKeys.claimUrl,
__internal_keyless_copyInstanceKeysUrl: storedKeys.apiKeysUrl,
__internal_keyless_dismissPrompt: deleteKeylessAction,
})}
__internal_scriptsSlot={__internal_scriptsSlot}
>
{children}
</ClientClerkProvider>
);

if (runningWithClaimedKeys) {
try {
const keylessService = await import('../../server/keyless-node.js').then(mod => mod.keyless());

/**
* Notifying the dashboard should run once. We are controlling this behaviour by caching the result of the request.
* If the request fails, it will be considered stale after 10 minutes, otherwise it is cached for 24 hours.
*/
await clerkDevelopmentCache?.run(() => keylessService.completeOnboarding(), {
cacheKey: `${newOrReadKeys.publishableKey}_complete`,
onSuccessStale: 24 * 60 * 60 * 1000, // 24 hours
});
} catch {
// noop
}

/**
* Notify developers.
*/
clerkDevelopmentCache?.log({
cacheKey: `${newOrReadKeys.publishableKey}_claimed`,
msg: createConfirmationMessage(),
});
}

return clientProvider;
};
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,8 +3,7 @@ import type { NextFetchEvent } from 'next/server';
import { NextRequest } from 'next/server';
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest';

// The mock SHOULD exist before the imports: unlike clerkMiddleware.test.ts, keys are empty so the
// missing-key error path is reachable.
// The mock SHOULD exist before the imports. Keys are intentionally empty so the missing-key error path is reachable.
vi.mock(import('../constants.js'), async importOriginal => {
const actual = await importOriginal();
return {
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -37,7 +37,6 @@ const mockRequest = (params: MockRequestParams) => {
if (machineAuthObject) {
const encryptedData = encryptClerkRequestData(
{}, // requestData
{}, // keylessModeKeys
// @ts-expect-error - mock machine auth object
machineAuthObject,
);
Expand Down
1 change: 0 additions & 1 deletion packages/nextjs/src/server/clerkMiddleware.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -389,7 +389,6 @@ async function runHandlerWithRequestState({
handlerResult,
requestState,
resolvedParams,
{},
authObject.tokenType === 'session_token' ? null : makeAuthObjectSerializable(authObject),
);

Expand Down
9 changes: 2 additions & 7 deletions packages/nextjs/src/server/keyless-log-cache.ts
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,5 @@
/**
* Re-export keyless development cache utilities from shared.
* Re-export the keyless development cache from shared.
* This maintains backward compatibility with existing imports.
*/
export {
clerkDevelopmentCache,
createClerkDevCache,
createConfirmationMessage,
createKeylessModeMessage,
} from '@clerk/shared/keyless';
export { clerkDevelopmentCache } from '@clerk/shared/keyless';
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .changeset/keyless-leftover-cleanup.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
---
'@clerk/shared': minor
'@clerk/nextjs': patch
'@clerk/backend': minor
---

Remove leftover keyless-mode creation code now that no SDK mints keyless applications. `@clerk/shared/keyless` drops `resolveKeysWithKeylessFallback`, `getOrCreateKeys`, and related exports (internal APIs consumed only by Clerk SDKs); `@clerk/backend` removes the experimental `createAccountlessApplication` method; `@clerk/nextjs` deletes the unused keyless cookie reader and dead keyless middleware parameters, and logs a pointer to existing `.clerk/.tmp/keyless.json` keys when env keys are missing.
2 changes: 1 addition & 1 deletion integration/scripts/waitForServer.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,7 +6,7 @@ type WaitForServerArgsType = {
acceptAnyResponse?: boolean;
};

// Poll a url until it returns a 200 status code
// Poll a url until it returns 2xx (or any HTTP response when acceptAnyResponse is set)
export const waitForServer = async (url: string, opts: WaitForServerArgsType) => {
const { log, delayInMs = 1000, maxAttempts = 20, shouldExit = () => false, acceptAnyResponse = false } = opts;
let attempts = 0;
Expand Down
100 changes: 1 addition & 99 deletions integration/testUtils/keylessHelpers.ts
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,4 @@
import type { BrowserContext, Page } from '@playwright/test';
import { expect } from '@playwright/test';

import type { Application } from '../models/application';
import { createTestUtils } from './index';
import type { Page } from '@playwright/test';

/**
* Mocks the environment API call to return a claimed instance.
Expand All@@ -22,97 +18,3 @@ export const mockClaimedInstanceEnvironmentCall = async (page: Page): Promise<vo
await route.fulfill({ response, json: newJson });
});
};

/**
* Tests that the keyless popover can be toggled and the claim link opens the dashboard.
*/
export async function testToggleCollapsePopoverAndClaim({
page,
context,
app,
dashboardUrl,
framework,
}: {
page: Page;
context: BrowserContext;
app: Application;
dashboardUrl: string;
framework: string;
}): Promise<void> {
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();
await u.page.waitForClerkJsLoaded();
await u.po.expect.toBeSignedOut();

await u.po.keylessPopover.waitForMounted();

const claim = u.po.keylessPopover.promptsToClaim();

const href = await claim.getAttribute('href');
expect(href).toBeTruthy();

const claimUrl = new URL(href!);
expect(claimUrl.origin + '/').toBe(dashboardUrl);
expect(claimUrl.pathname).toBe('/apps/claim');
expect(claimUrl.searchParams.get('framework')).toBe(framework);
expect(claimUrl.searchParams.has('token')).toBe(true);
expect(claimUrl.searchParams.has('return_url')).toBe(true);
}

/**
* Tests that a claimed application with missing explicit keys shows the popover expanded
* with a prompt to get keys from the dashboard.
*/
export async function testClaimedAppWithMissingKeys({
page,
context,
app,
dashboardUrl,
}: {
page: Page;
context: BrowserContext;
app: Application;
dashboardUrl: string;
}): Promise<void> {
await mockClaimedInstanceEnvironmentCall(page);
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();
await u.page.waitForClerkJsLoaded();

await u.po.keylessPopover.waitForMounted();
expect(await u.po.keylessPopover.isExpanded()).toBe(true);
await expect(u.po.keylessPopover.promptToUseClaimedKeys()).toBeVisible();

const href = await u.po.keylessPopover.promptToUseClaimedKeys().getAttribute('href');
expect(href).toBeTruthy();
expect(href).toContain(dashboardUrl);
}

/**
* Tests that the keyless popover is removed after adding keys to .env and restarting the dev server.
*/
export async function testKeylessRemovedAfterEnvAndRestart({
page,
context,
app,
}: {
page: Page;
context: BrowserContext;
app: Application;
}): Promise<void> {
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();

await u.po.keylessPopover.waitForMounted();

// Copy keys from keyless.json to .env
await app.keylessToEnv();

// Restart the dev server to pick up new env vars (Vite doesn't hot-reload .env)
await app.restart();

await u.page.goToAppHome();

// Keyless popover should no longer be present since we now have explicit keys
await u.po.keylessPopover.waitForUnmounted();
}
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,48 +13,6 @@ describe('AccountlessApplications', () => {
api_keys_url: 'https://dashboard.clerk.com/api-keys',
};

it('creates an accountless application with a source query parameter', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
});

server.use(
http.post('https://api.clerk.test/v1/accountless_applications', ({ request }) => {
const url = new URL(request.url);
expect(url.searchParams.get('source')).toBe('nextjs');
expect(request.headers.get('Clerk-API-Version')).toBeTruthy();
expect(request.headers.get('User-Agent')).toBe('@clerk/backend@0.0.0-test');

return HttpResponse.json(mockAccountlessApplication);
}),
);

const response = await apiClient.__experimental_accountlessApplications.createAccountlessApplication({
source: 'nextjs',
});

expect(response.publishableKey).toBe('pk_test_keyless');
});

it('creates an accountless application without a source query parameter when source is omitted', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
});

server.use(
http.post('https://api.clerk.test/v1/accountless_applications', ({ request }) => {
const url = new URL(request.url);
expect(url.searchParams.has('source')).toBe(false);

return HttpResponse.json(mockAccountlessApplication);
}),
);

const response = await apiClient.__experimental_accountlessApplications.createAccountlessApplication();

expect(response.publishableKey).toBe('pk_test_keyless');
});

it('completes accountless application onboarding with a source query parameter', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
Expand Down
12 changes: 0 additions & 12 deletions packages/backend/src/api/endpoints/AccountlessApplicationsAPI.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,18 +10,6 @@ type AccountlessApplicationParams = {
};

export class AccountlessApplicationAPI extends AbstractAPI {
public async createAccountlessApplication(params?: AccountlessApplicationParams): Promise<AccountlessApplication> {
const headerParams = params?.requestHeaders ? Object.fromEntries(params.requestHeaders.entries()) : undefined;
return this.request<AccountlessApplication>({
method: 'POST',
path: basePath,
headerParams,
queryParams: {
source: params?.source,
},
});
}

public async completeAccountlessApplicationOnboarding(
params?: AccountlessApplicationParams,
): Promise<AccountlessApplication> {
Expand Down
13 changes: 7 additions & 6 deletions packages/nextjs/src/app-router/server/ClerkProvider.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@ import React, { Suspense } from 'react';
import { getDynamicAuthData } from '../../server/buildClerkProps';
import { errorThrower } from '../../server/errorThrower';
import type { NextClerkProviderProps } from '../../types';
import { canUseKeyless } from '../../utils/feature-flags';
import { mergeNextClerkPropsWithEnv } from '../../utils/mergeNextClerkPropsWithEnv';
import { ClientClerkProvider } from '../client/ClerkProvider';
import { DynamicClerkScripts } from './DynamicClerkScripts';
Expand DownExpand Up@@ -32,7 +33,7 @@ export async function ClerkProvider<TUi extends Ui = Ui>(
initialState: statePromiseOrValue as InitialState | undefined,
});

const { shouldRunAsKeyless, runningWithClaimedKeys } = await getKeylessStatus(propsWithEnvs);
const { runningWithClaimedKeys } = await getKeylessStatus(propsWithEnvs);

// When dynamic mode is enabled, render scripts in a Suspense boundary to isolate
// the nonce fetching (which calls headers()) from the rest of the page.
Expand All@@ -52,14 +53,14 @@ export async function ClerkProvider<TUi extends Ui = Ui>(
</Suspense>
) : undefined;

if (shouldRunAsKeyless) {
if (!propsWithEnvs.publishableKey) {
errorThrower.throwMissingPublishableKeyError();
}
if (canUseKeyless && !propsWithEnvs.publishableKey) {
errorThrower.throwMissingPublishableKeyError();
}

if (runningWithClaimedKeys) {
return (
<KeylessProvider
rest={propsWithEnvs}
runningWithClaimedKeys={runningWithClaimedKeys}
__internal_scriptsSlot={scriptsSlot}
>
{children}
Expand Down
85 changes: 33 additions & 52 deletions packages/nextjs/src/app-router/server/keyless-provider.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -11,40 +11,42 @@ import { deleteKeylessAction } from '../keyless-actions';
export async function getKeylessStatus(
params: Without<NextClerkProviderProps, '__internal_invokeMiddlewareOnAuthStateChange' | 'children'>,
) {
let [shouldRunAsKeyless, runningWithClaimedKeys, locallyStoredPublishableKey] = [false, false, ''];
if (canUseKeyless) {
locallyStoredPublishableKey = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys()?.publishableKey || '')
.catch(() => '');
if (!canUseKeyless) {
return { runningWithClaimedKeys: false };
}

runningWithClaimedKeys = Boolean(params.publishableKey) && params.publishableKey === locallyStoredPublishableKey;
shouldRunAsKeyless = !params.publishableKey || runningWithClaimedKeys;
const storedKeys = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys() ?? null)
.catch(() => null);
if (!storedKeys) {
return { runningWithClaimedKeys: false };
}

return {
shouldRunAsKeyless,
runningWithClaimedKeys,
};
if (!params.publishableKey) {
const { clerkDevelopmentCache } = await import('../../server/keyless-log-cache.js');
clerkDevelopmentCache?.log({
cacheKey: `${storedKeys.publishableKey}_stored`,
msg: `[Clerk]: Found existing keyless-mode keys in .clerk/.tmp/keyless.json. Copy the publishableKey and secretKey into .env.local (NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY / CLERK_SECRET_KEY) to keep using that application, or claim it at ${storedKeys.claimUrl}`,
});
return { runningWithClaimedKeys: false };
}

return { runningWithClaimedKeys: params.publishableKey === storedKeys.publishableKey };
}

type KeylessProviderProps = PropsWithChildren<{
rest: Without<NextClerkProviderProps, '__internal_invokeMiddlewareOnAuthStateChange' | 'children'>;
runningWithClaimedKeys: boolean;
__internal_scriptsSlot?: React.ReactNode;
}>;

export const KeylessProvider = async (props: KeylessProviderProps) => {
const { rest, runningWithClaimedKeys, __internal_scriptsSlot, children } = props;
const { rest, __internal_scriptsSlot, children } = props;

// Read-only: the SDK no longer mints keyless applications, it only reads claimed keys from disk.
const newOrReadKeys = await import('../../server/keyless-node.js')
const storedKeys = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys() ?? null)
.catch(() => null);

const { clerkDevelopmentCache, createConfirmationMessage } = await import('../../server/keyless-log-cache.js');

if (!newOrReadKeys) {
// When case keyless should run, but keys are not available, then fallback to throwing for missing keys
if (!storedKeys) {
return (
<ClientClerkProvider
{...mergeNextClerkPropsWithEnv(rest)}
Expand All@@ -56,46 +58,25 @@ export const KeylessProvider = async (props: KeylessProviderProps) => {
);
}

const clientProvider = (
try {
const keylessService = await import('../../server/keyless-node.js').then(mod => mod.keyless());
const { completeClaimedOnboarding } = await import('@clerk/shared/keyless');
await completeClaimedOnboarding(storedKeys.publishableKey, keylessService);
} catch {
// noop
}

return (
<ClientClerkProvider
{...mergeNextClerkPropsWithEnv({
...rest,
publishableKey: newOrReadKeys.publishableKey,
__internal_keyless_claimKeylessApplicationUrl: newOrReadKeys.claimUrl,
__internal_keyless_copyInstanceKeysUrl: newOrReadKeys.apiKeysUrl,
// Explicitly use `null` instead of `undefined` here to avoid persisting `deleteKeylessAction` during merging of options.
__internal_keyless_dismissPrompt: runningWithClaimedKeys ? deleteKeylessAction : null,
__internal_keyless_claimKeylessApplicationUrl: storedKeys.claimUrl,
__internal_keyless_copyInstanceKeysUrl: storedKeys.apiKeysUrl,
__internal_keyless_dismissPrompt: deleteKeylessAction,
})}
__internal_scriptsSlot={__internal_scriptsSlot}
>
{children}
</ClientClerkProvider>
);

if (runningWithClaimedKeys) {
try {
const keylessService = await import('../../server/keyless-node.js').then(mod => mod.keyless());

/**
* Notifying the dashboard should run once. We are controlling this behaviour by caching the result of the request.
* If the request fails, it will be considered stale after 10 minutes, otherwise it is cached for 24 hours.
*/
await clerkDevelopmentCache?.run(() => keylessService.completeOnboarding(), {
cacheKey: `${newOrReadKeys.publishableKey}_complete`,
onSuccessStale: 24 * 60 * 60 * 1000, // 24 hours
});
} catch {
// noop
}

/**
* Notify developers.
*/
clerkDevelopmentCache?.log({
cacheKey: `${newOrReadKeys.publishableKey}_claimed`,
msg: createConfirmationMessage(),
});
}

return clientProvider;
};
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,8 +3,7 @@ import type { NextFetchEvent } from 'next/server';
import { NextRequest } from 'next/server';
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest';

// The mock SHOULD exist before the imports: unlike clerkMiddleware.test.ts, keys are empty so the
// missing-key error path is reachable.
// The mock SHOULD exist before the imports. Keys are intentionally empty so the missing-key error path is reachable.
vi.mock(import('../constants.js'), async importOriginal => {
const actual = await importOriginal();
return {
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -37,7 +37,6 @@ const mockRequest = (params: MockRequestParams) => {
if (machineAuthObject) {
const encryptedData = encryptClerkRequestData(
{}, // requestData
{}, // keylessModeKeys
// @ts-expect-error - mock machine auth object
machineAuthObject,
);
Expand Down
1 change: 0 additions & 1 deletion packages/nextjs/src/server/clerkMiddleware.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -389,7 +389,6 @@ async function runHandlerWithRequestState({
handlerResult,
requestState,
resolvedParams,
{},
authObject.tokenType === 'session_token' ? null : makeAuthObjectSerializable(authObject),
);

Expand Down
9 changes: 2 additions & 7 deletions packages/nextjs/src/server/keyless-log-cache.ts
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,5 @@
/**
* Re-export keyless development cache utilities from shared.
* Re-export the keyless development cache from shared.
* This maintains backward compatibility with existing imports.
*/
export {
clerkDevelopmentCache,
createClerkDevCache,
createConfirmationMessage,
createKeylessModeMessage,
} from '@clerk/shared/keyless';
export { clerkDevelopmentCache } from '@clerk/shared/keyless';
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .changeset/keyless-leftover-cleanup.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
---
'@clerk/shared': minor
'@clerk/nextjs': patch
'@clerk/backend': minor
---

Remove leftover keyless-mode creation code now that no SDK mints keyless applications. `@clerk/shared/keyless` drops `resolveKeysWithKeylessFallback`, `getOrCreateKeys`, and related exports (internal APIs consumed only by Clerk SDKs); `@clerk/backend` removes the experimental `createAccountlessApplication` method; `@clerk/nextjs` deletes the unused keyless cookie reader and dead keyless middleware parameters, and logs a pointer to existing `.clerk/.tmp/keyless.json` keys when env keys are missing.
2 changes: 1 addition & 1 deletion integration/scripts/waitForServer.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,7 +6,7 @@ type WaitForServerArgsType = {
acceptAnyResponse?: boolean;
};

// Poll a url until it returns a 200 status code
// Poll a url until it returns 2xx (or any HTTP response when acceptAnyResponse is set)
export const waitForServer = async (url: string, opts: WaitForServerArgsType) => {
const { log, delayInMs = 1000, maxAttempts = 20, shouldExit = () => false, acceptAnyResponse = false } = opts;
let attempts = 0;
Expand Down
100 changes: 1 addition & 99 deletions integration/testUtils/keylessHelpers.ts
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,4 @@
import type { BrowserContext, Page } from '@playwright/test';
import { expect } from '@playwright/test';

import type { Application } from '../models/application';
import { createTestUtils } from './index';
import type { Page } from '@playwright/test';

/**
* Mocks the environment API call to return a claimed instance.
Expand All@@ -22,97 +18,3 @@ export const mockClaimedInstanceEnvironmentCall = async (page: Page): Promise<vo
await route.fulfill({ response, json: newJson });
});
};

/**
* Tests that the keyless popover can be toggled and the claim link opens the dashboard.
*/
export async function testToggleCollapsePopoverAndClaim({
page,
context,
app,
dashboardUrl,
framework,
}: {
page: Page;
context: BrowserContext;
app: Application;
dashboardUrl: string;
framework: string;
}): Promise<void> {
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();
await u.page.waitForClerkJsLoaded();
await u.po.expect.toBeSignedOut();

await u.po.keylessPopover.waitForMounted();

const claim = u.po.keylessPopover.promptsToClaim();

const href = await claim.getAttribute('href');
expect(href).toBeTruthy();

const claimUrl = new URL(href!);
expect(claimUrl.origin + '/').toBe(dashboardUrl);
expect(claimUrl.pathname).toBe('/apps/claim');
expect(claimUrl.searchParams.get('framework')).toBe(framework);
expect(claimUrl.searchParams.has('token')).toBe(true);
expect(claimUrl.searchParams.has('return_url')).toBe(true);
}

/**
* Tests that a claimed application with missing explicit keys shows the popover expanded
* with a prompt to get keys from the dashboard.
*/
export async function testClaimedAppWithMissingKeys({
page,
context,
app,
dashboardUrl,
}: {
page: Page;
context: BrowserContext;
app: Application;
dashboardUrl: string;
}): Promise<void> {
await mockClaimedInstanceEnvironmentCall(page);
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();
await u.page.waitForClerkJsLoaded();

await u.po.keylessPopover.waitForMounted();
expect(await u.po.keylessPopover.isExpanded()).toBe(true);
await expect(u.po.keylessPopover.promptToUseClaimedKeys()).toBeVisible();

const href = await u.po.keylessPopover.promptToUseClaimedKeys().getAttribute('href');
expect(href).toBeTruthy();
expect(href).toContain(dashboardUrl);
}

/**
* Tests that the keyless popover is removed after adding keys to .env and restarting the dev server.
*/
export async function testKeylessRemovedAfterEnvAndRestart({
page,
context,
app,
}: {
page: Page;
context: BrowserContext;
app: Application;
}): Promise<void> {
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();

await u.po.keylessPopover.waitForMounted();

// Copy keys from keyless.json to .env
await app.keylessToEnv();

// Restart the dev server to pick up new env vars (Vite doesn't hot-reload .env)
await app.restart();

await u.page.goToAppHome();

// Keyless popover should no longer be present since we now have explicit keys
await u.po.keylessPopover.waitForUnmounted();
}
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,48 +13,6 @@ describe('AccountlessApplications', () => {
api_keys_url: 'https://dashboard.clerk.com/api-keys',
};

it('creates an accountless application with a source query parameter', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
});

server.use(
http.post('https://api.clerk.test/v1/accountless_applications', ({ request }) => {
const url = new URL(request.url);
expect(url.searchParams.get('source')).toBe('nextjs');
expect(request.headers.get('Clerk-API-Version')).toBeTruthy();
expect(request.headers.get('User-Agent')).toBe('@clerk/backend@0.0.0-test');

return HttpResponse.json(mockAccountlessApplication);
}),
);

const response = await apiClient.__experimental_accountlessApplications.createAccountlessApplication({
source: 'nextjs',
});

expect(response.publishableKey).toBe('pk_test_keyless');
});

it('creates an accountless application without a source query parameter when source is omitted', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
});

server.use(
http.post('https://api.clerk.test/v1/accountless_applications', ({ request }) => {
const url = new URL(request.url);
expect(url.searchParams.has('source')).toBe(false);

return HttpResponse.json(mockAccountlessApplication);
}),
);

const response = await apiClient.__experimental_accountlessApplications.createAccountlessApplication();

expect(response.publishableKey).toBe('pk_test_keyless');
});

it('completes accountless application onboarding with a source query parameter', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
Expand Down
12 changes: 0 additions & 12 deletions packages/backend/src/api/endpoints/AccountlessApplicationsAPI.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,18 +10,6 @@ type AccountlessApplicationParams = {
};

export class AccountlessApplicationAPI extends AbstractAPI {
public async createAccountlessApplication(params?: AccountlessApplicationParams): Promise<AccountlessApplication> {
const headerParams = params?.requestHeaders ? Object.fromEntries(params.requestHeaders.entries()) : undefined;
return this.request<AccountlessApplication>({
method: 'POST',
path: basePath,
headerParams,
queryParams: {
source: params?.source,
},
});
}

public async completeAccountlessApplicationOnboarding(
params?: AccountlessApplicationParams,
): Promise<AccountlessApplication> {
Expand Down
13 changes: 7 additions & 6 deletions packages/nextjs/src/app-router/server/ClerkProvider.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@ import React, { Suspense } from 'react';
import { getDynamicAuthData } from '../../server/buildClerkProps';
import { errorThrower } from '../../server/errorThrower';
import type { NextClerkProviderProps } from '../../types';
import { canUseKeyless } from '../../utils/feature-flags';
import { mergeNextClerkPropsWithEnv } from '../../utils/mergeNextClerkPropsWithEnv';
import { ClientClerkProvider } from '../client/ClerkProvider';
import { DynamicClerkScripts } from './DynamicClerkScripts';
Expand DownExpand Up@@ -32,7 +33,7 @@ export async function ClerkProvider<TUi extends Ui = Ui>(
initialState: statePromiseOrValue as InitialState | undefined,
});

const { shouldRunAsKeyless, runningWithClaimedKeys } = await getKeylessStatus(propsWithEnvs);
const { runningWithClaimedKeys } = await getKeylessStatus(propsWithEnvs);

// When dynamic mode is enabled, render scripts in a Suspense boundary to isolate
// the nonce fetching (which calls headers()) from the rest of the page.
Expand All@@ -52,14 +53,14 @@ export async function ClerkProvider<TUi extends Ui = Ui>(
</Suspense>
) : undefined;

if (shouldRunAsKeyless) {
if (!propsWithEnvs.publishableKey) {
errorThrower.throwMissingPublishableKeyError();
}
if (canUseKeyless && !propsWithEnvs.publishableKey) {
errorThrower.throwMissingPublishableKeyError();
}

if (runningWithClaimedKeys) {
return (
<KeylessProvider
rest={propsWithEnvs}
runningWithClaimedKeys={runningWithClaimedKeys}
__internal_scriptsSlot={scriptsSlot}
>
{children}
Expand Down
85 changes: 33 additions & 52 deletions packages/nextjs/src/app-router/server/keyless-provider.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -11,40 +11,42 @@ import { deleteKeylessAction } from '../keyless-actions';
export async function getKeylessStatus(
params: Without<NextClerkProviderProps, '__internal_invokeMiddlewareOnAuthStateChange' | 'children'>,
) {
let [shouldRunAsKeyless, runningWithClaimedKeys, locallyStoredPublishableKey] = [false, false, ''];
if (canUseKeyless) {
locallyStoredPublishableKey = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys()?.publishableKey || '')
.catch(() => '');
if (!canUseKeyless) {
return { runningWithClaimedKeys: false };
}

runningWithClaimedKeys = Boolean(params.publishableKey) && params.publishableKey === locallyStoredPublishableKey;
shouldRunAsKeyless = !params.publishableKey || runningWithClaimedKeys;
const storedKeys = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys() ?? null)
.catch(() => null);
if (!storedKeys) {
return { runningWithClaimedKeys: false };
}

return {
shouldRunAsKeyless,
runningWithClaimedKeys,
};
if (!params.publishableKey) {
const { clerkDevelopmentCache } = await import('../../server/keyless-log-cache.js');
clerkDevelopmentCache?.log({
cacheKey: `${storedKeys.publishableKey}_stored`,
msg: `[Clerk]: Found existing keyless-mode keys in .clerk/.tmp/keyless.json. Copy the publishableKey and secretKey into .env.local (NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY / CLERK_SECRET_KEY) to keep using that application, or claim it at ${storedKeys.claimUrl}`,
});
return { runningWithClaimedKeys: false };
}

return { runningWithClaimedKeys: params.publishableKey === storedKeys.publishableKey };
}

type KeylessProviderProps = PropsWithChildren<{
rest: Without<NextClerkProviderProps, '__internal_invokeMiddlewareOnAuthStateChange' | 'children'>;
runningWithClaimedKeys: boolean;
__internal_scriptsSlot?: React.ReactNode;
}>;

export const KeylessProvider = async (props: KeylessProviderProps) => {
const { rest, runningWithClaimedKeys, __internal_scriptsSlot, children } = props;
const { rest, __internal_scriptsSlot, children } = props;

// Read-only: the SDK no longer mints keyless applications, it only reads claimed keys from disk.
const newOrReadKeys = await import('../../server/keyless-node.js')
const storedKeys = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys() ?? null)
.catch(() => null);

const { clerkDevelopmentCache, createConfirmationMessage } = await import('../../server/keyless-log-cache.js');

if (!newOrReadKeys) {
// When case keyless should run, but keys are not available, then fallback to throwing for missing keys
if (!storedKeys) {
return (
<ClientClerkProvider
{...mergeNextClerkPropsWithEnv(rest)}
Expand All@@ -56,46 +58,25 @@ export const KeylessProvider = async (props: KeylessProviderProps) => {
);
}

const clientProvider = (
try {
const keylessService = await import('../../server/keyless-node.js').then(mod => mod.keyless());
const { completeClaimedOnboarding } = await import('@clerk/shared/keyless');
await completeClaimedOnboarding(storedKeys.publishableKey, keylessService);
} catch {
// noop
}

return (
<ClientClerkProvider
{...mergeNextClerkPropsWithEnv({
...rest,
publishableKey: newOrReadKeys.publishableKey,
__internal_keyless_claimKeylessApplicationUrl: newOrReadKeys.claimUrl,
__internal_keyless_copyInstanceKeysUrl: newOrReadKeys.apiKeysUrl,
// Explicitly use `null` instead of `undefined` here to avoid persisting `deleteKeylessAction` during merging of options.
__internal_keyless_dismissPrompt: runningWithClaimedKeys ? deleteKeylessAction : null,
__internal_keyless_claimKeylessApplicationUrl: storedKeys.claimUrl,
__internal_keyless_copyInstanceKeysUrl: storedKeys.apiKeysUrl,
__internal_keyless_dismissPrompt: deleteKeylessAction,
})}
__internal_scriptsSlot={__internal_scriptsSlot}
>
{children}
</ClientClerkProvider>
);

if (runningWithClaimedKeys) {
try {
const keylessService = await import('../../server/keyless-node.js').then(mod => mod.keyless());

/**
* Notifying the dashboard should run once. We are controlling this behaviour by caching the result of the request.
* If the request fails, it will be considered stale after 10 minutes, otherwise it is cached for 24 hours.
*/
await clerkDevelopmentCache?.run(() => keylessService.completeOnboarding(), {
cacheKey: `${newOrReadKeys.publishableKey}_complete`,
onSuccessStale: 24 * 60 * 60 * 1000, // 24 hours
});
} catch {
// noop
}

/**
* Notify developers.
*/
clerkDevelopmentCache?.log({
cacheKey: `${newOrReadKeys.publishableKey}_claimed`,
msg: createConfirmationMessage(),
});
}

return clientProvider;
};
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,8 +3,7 @@ import type { NextFetchEvent } from 'next/server';
import { NextRequest } from 'next/server';
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest';

// The mock SHOULD exist before the imports: unlike clerkMiddleware.test.ts, keys are empty so the
// missing-key error path is reachable.
// The mock SHOULD exist before the imports. Keys are intentionally empty so the missing-key error path is reachable.
vi.mock(import('../constants.js'), async importOriginal => {
const actual = await importOriginal();
return {
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -37,7 +37,6 @@ const mockRequest = (params: MockRequestParams) => {
if (machineAuthObject) {
const encryptedData = encryptClerkRequestData(
{}, // requestData
{}, // keylessModeKeys
// @ts-expect-error - mock machine auth object
machineAuthObject,
);
Expand Down
1 change: 0 additions & 1 deletion packages/nextjs/src/server/clerkMiddleware.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -389,7 +389,6 @@ async function runHandlerWithRequestState({
handlerResult,
requestState,
resolvedParams,
{},
authObject.tokenType === 'session_token' ? null : makeAuthObjectSerializable(authObject),
);

Expand Down
9 changes: 2 additions & 7 deletions packages/nextjs/src/server/keyless-log-cache.ts
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,5 @@
/**
* Re-export keyless development cache utilities from shared.
* Re-export the keyless development cache from shared.
* This maintains backward compatibility with existing imports.
*/
export {
clerkDevelopmentCache,
createClerkDevCache,
createConfirmationMessage,
createKeylessModeMessage,
} from '@clerk/shared/keyless';
export { clerkDevelopmentCache } from '@clerk/shared/keyless';
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .changeset/keyless-leftover-cleanup.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
---
'@clerk/shared': minor
'@clerk/nextjs': patch
'@clerk/backend': minor
---

Remove leftover keyless-mode creation code now that no SDK mints keyless applications. `@clerk/shared/keyless` drops `resolveKeysWithKeylessFallback`, `getOrCreateKeys`, and related exports (internal APIs consumed only by Clerk SDKs); `@clerk/backend` removes the experimental `createAccountlessApplication` method; `@clerk/nextjs` deletes the unused keyless cookie reader and dead keyless middleware parameters, and logs a pointer to existing `.clerk/.tmp/keyless.json` keys when env keys are missing.
2 changes: 1 addition & 1 deletion integration/scripts/waitForServer.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,7 +6,7 @@ type WaitForServerArgsType = {
acceptAnyResponse?: boolean;
};

// Poll a url until it returns a 200 status code
// Poll a url until it returns 2xx (or any HTTP response when acceptAnyResponse is set)
export const waitForServer = async (url: string, opts: WaitForServerArgsType) => {
const { log, delayInMs = 1000, maxAttempts = 20, shouldExit = () => false, acceptAnyResponse = false } = opts;
let attempts = 0;
Expand Down
100 changes: 1 addition & 99 deletions integration/testUtils/keylessHelpers.ts
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,4 @@
import type { BrowserContext, Page } from '@playwright/test';
import { expect } from '@playwright/test';

import type { Application } from '../models/application';
import { createTestUtils } from './index';
import type { Page } from '@playwright/test';

/**
* Mocks the environment API call to return a claimed instance.
Expand All@@ -22,97 +18,3 @@ export const mockClaimedInstanceEnvironmentCall = async (page: Page): Promise<vo
await route.fulfill({ response, json: newJson });
});
};

/**
* Tests that the keyless popover can be toggled and the claim link opens the dashboard.
*/
export async function testToggleCollapsePopoverAndClaim({
page,
context,
app,
dashboardUrl,
framework,
}: {
page: Page;
context: BrowserContext;
app: Application;
dashboardUrl: string;
framework: string;
}): Promise<void> {
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();
await u.page.waitForClerkJsLoaded();
await u.po.expect.toBeSignedOut();

await u.po.keylessPopover.waitForMounted();

const claim = u.po.keylessPopover.promptsToClaim();

const href = await claim.getAttribute('href');
expect(href).toBeTruthy();

const claimUrl = new URL(href!);
expect(claimUrl.origin + '/').toBe(dashboardUrl);
expect(claimUrl.pathname).toBe('/apps/claim');
expect(claimUrl.searchParams.get('framework')).toBe(framework);
expect(claimUrl.searchParams.has('token')).toBe(true);
expect(claimUrl.searchParams.has('return_url')).toBe(true);
}

/**
* Tests that a claimed application with missing explicit keys shows the popover expanded
* with a prompt to get keys from the dashboard.
*/
export async function testClaimedAppWithMissingKeys({
page,
context,
app,
dashboardUrl,
}: {
page: Page;
context: BrowserContext;
app: Application;
dashboardUrl: string;
}): Promise<void> {
await mockClaimedInstanceEnvironmentCall(page);
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();
await u.page.waitForClerkJsLoaded();

await u.po.keylessPopover.waitForMounted();
expect(await u.po.keylessPopover.isExpanded()).toBe(true);
await expect(u.po.keylessPopover.promptToUseClaimedKeys()).toBeVisible();

const href = await u.po.keylessPopover.promptToUseClaimedKeys().getAttribute('href');
expect(href).toBeTruthy();
expect(href).toContain(dashboardUrl);
}

/**
* Tests that the keyless popover is removed after adding keys to .env and restarting the dev server.
*/
export async function testKeylessRemovedAfterEnvAndRestart({
page,
context,
app,
}: {
page: Page;
context: BrowserContext;
app: Application;
}): Promise<void> {
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();

await u.po.keylessPopover.waitForMounted();

// Copy keys from keyless.json to .env
await app.keylessToEnv();

// Restart the dev server to pick up new env vars (Vite doesn't hot-reload .env)
await app.restart();

await u.page.goToAppHome();

// Keyless popover should no longer be present since we now have explicit keys
await u.po.keylessPopover.waitForUnmounted();
}
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,48 +13,6 @@ describe('AccountlessApplications', () => {
api_keys_url: 'https://dashboard.clerk.com/api-keys',
};

it('creates an accountless application with a source query parameter', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
});

server.use(
http.post('https://api.clerk.test/v1/accountless_applications', ({ request }) => {
const url = new URL(request.url);
expect(url.searchParams.get('source')).toBe('nextjs');
expect(request.headers.get('Clerk-API-Version')).toBeTruthy();
expect(request.headers.get('User-Agent')).toBe('@clerk/backend@0.0.0-test');

return HttpResponse.json(mockAccountlessApplication);
}),
);

const response = await apiClient.__experimental_accountlessApplications.createAccountlessApplication({
source: 'nextjs',
});

expect(response.publishableKey).toBe('pk_test_keyless');
});

it('creates an accountless application without a source query parameter when source is omitted', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
});

server.use(
http.post('https://api.clerk.test/v1/accountless_applications', ({ request }) => {
const url = new URL(request.url);
expect(url.searchParams.has('source')).toBe(false);

return HttpResponse.json(mockAccountlessApplication);
}),
);

const response = await apiClient.__experimental_accountlessApplications.createAccountlessApplication();

expect(response.publishableKey).toBe('pk_test_keyless');
});

it('completes accountless application onboarding with a source query parameter', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
Expand Down
12 changes: 0 additions & 12 deletions packages/backend/src/api/endpoints/AccountlessApplicationsAPI.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,18 +10,6 @@ type AccountlessApplicationParams = {
};

export class AccountlessApplicationAPI extends AbstractAPI {
public async createAccountlessApplication(params?: AccountlessApplicationParams): Promise<AccountlessApplication> {
const headerParams = params?.requestHeaders ? Object.fromEntries(params.requestHeaders.entries()) : undefined;
return this.request<AccountlessApplication>({
method: 'POST',
path: basePath,
headerParams,
queryParams: {
source: params?.source,
},
});
}

public async completeAccountlessApplicationOnboarding(
params?: AccountlessApplicationParams,
): Promise<AccountlessApplication> {
Expand Down
13 changes: 7 additions & 6 deletions packages/nextjs/src/app-router/server/ClerkProvider.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@ import React, { Suspense } from 'react';
import { getDynamicAuthData } from '../../server/buildClerkProps';
import { errorThrower } from '../../server/errorThrower';
import type { NextClerkProviderProps } from '../../types';
import { canUseKeyless } from '../../utils/feature-flags';
import { mergeNextClerkPropsWithEnv } from '../../utils/mergeNextClerkPropsWithEnv';
import { ClientClerkProvider } from '../client/ClerkProvider';
import { DynamicClerkScripts } from './DynamicClerkScripts';
Expand DownExpand Up@@ -32,7 +33,7 @@ export async function ClerkProvider<TUi extends Ui = Ui>(
initialState: statePromiseOrValue as InitialState | undefined,
});

const { shouldRunAsKeyless, runningWithClaimedKeys } = await getKeylessStatus(propsWithEnvs);
const { runningWithClaimedKeys } = await getKeylessStatus(propsWithEnvs);

// When dynamic mode is enabled, render scripts in a Suspense boundary to isolate
// the nonce fetching (which calls headers()) from the rest of the page.
Expand All@@ -52,14 +53,14 @@ export async function ClerkProvider<TUi extends Ui = Ui>(
</Suspense>
) : undefined;

if (shouldRunAsKeyless) {
if (!propsWithEnvs.publishableKey) {
errorThrower.throwMissingPublishableKeyError();
}
if (canUseKeyless && !propsWithEnvs.publishableKey) {
errorThrower.throwMissingPublishableKeyError();
}

if (runningWithClaimedKeys) {
return (
<KeylessProvider
rest={propsWithEnvs}
runningWithClaimedKeys={runningWithClaimedKeys}
__internal_scriptsSlot={scriptsSlot}
>
{children}
Expand Down
85 changes: 33 additions & 52 deletions packages/nextjs/src/app-router/server/keyless-provider.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -11,40 +11,42 @@ import { deleteKeylessAction } from '../keyless-actions';
export async function getKeylessStatus(
params: Without<NextClerkProviderProps, '__internal_invokeMiddlewareOnAuthStateChange' | 'children'>,
) {
let [shouldRunAsKeyless, runningWithClaimedKeys, locallyStoredPublishableKey] = [false, false, ''];
if (canUseKeyless) {
locallyStoredPublishableKey = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys()?.publishableKey || '')
.catch(() => '');
if (!canUseKeyless) {
return { runningWithClaimedKeys: false };
}

runningWithClaimedKeys = Boolean(params.publishableKey) && params.publishableKey === locallyStoredPublishableKey;
shouldRunAsKeyless = !params.publishableKey || runningWithClaimedKeys;
const storedKeys = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys() ?? null)
.catch(() => null);
if (!storedKeys) {
return { runningWithClaimedKeys: false };
}

return {
shouldRunAsKeyless,
runningWithClaimedKeys,
};
if (!params.publishableKey) {
const { clerkDevelopmentCache } = await import('../../server/keyless-log-cache.js');
clerkDevelopmentCache?.log({
cacheKey: `${storedKeys.publishableKey}_stored`,
msg: `[Clerk]: Found existing keyless-mode keys in .clerk/.tmp/keyless.json. Copy the publishableKey and secretKey into .env.local (NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY / CLERK_SECRET_KEY) to keep using that application, or claim it at ${storedKeys.claimUrl}`,
});
return { runningWithClaimedKeys: false };
}

return { runningWithClaimedKeys: params.publishableKey === storedKeys.publishableKey };
}

type KeylessProviderProps = PropsWithChildren<{
rest: Without<NextClerkProviderProps, '__internal_invokeMiddlewareOnAuthStateChange' | 'children'>;
runningWithClaimedKeys: boolean;
__internal_scriptsSlot?: React.ReactNode;
}>;

export const KeylessProvider = async (props: KeylessProviderProps) => {
const { rest, runningWithClaimedKeys, __internal_scriptsSlot, children } = props;
const { rest, __internal_scriptsSlot, children } = props;

// Read-only: the SDK no longer mints keyless applications, it only reads claimed keys from disk.
const newOrReadKeys = await import('../../server/keyless-node.js')
const storedKeys = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys() ?? null)
.catch(() => null);

const { clerkDevelopmentCache, createConfirmationMessage } = await import('../../server/keyless-log-cache.js');

if (!newOrReadKeys) {
// When case keyless should run, but keys are not available, then fallback to throwing for missing keys
if (!storedKeys) {
return (
<ClientClerkProvider
{...mergeNextClerkPropsWithEnv(rest)}
Expand All@@ -56,46 +58,25 @@ export const KeylessProvider = async (props: KeylessProviderProps) => {
);
}

const clientProvider = (
try {
const keylessService = await import('../../server/keyless-node.js').then(mod => mod.keyless());
const { completeClaimedOnboarding } = await import('@clerk/shared/keyless');
await completeClaimedOnboarding(storedKeys.publishableKey, keylessService);
} catch {
// noop
}

return (
<ClientClerkProvider
{...mergeNextClerkPropsWithEnv({
...rest,
publishableKey: newOrReadKeys.publishableKey,
__internal_keyless_claimKeylessApplicationUrl: newOrReadKeys.claimUrl,
__internal_keyless_copyInstanceKeysUrl: newOrReadKeys.apiKeysUrl,
// Explicitly use `null` instead of `undefined` here to avoid persisting `deleteKeylessAction` during merging of options.
__internal_keyless_dismissPrompt: runningWithClaimedKeys ? deleteKeylessAction : null,
__internal_keyless_claimKeylessApplicationUrl: storedKeys.claimUrl,
__internal_keyless_copyInstanceKeysUrl: storedKeys.apiKeysUrl,
__internal_keyless_dismissPrompt: deleteKeylessAction,
})}
__internal_scriptsSlot={__internal_scriptsSlot}
>
{children}
</ClientClerkProvider>
);

if (runningWithClaimedKeys) {
try {
const keylessService = await import('../../server/keyless-node.js').then(mod => mod.keyless());

/**
* Notifying the dashboard should run once. We are controlling this behaviour by caching the result of the request.
* If the request fails, it will be considered stale after 10 minutes, otherwise it is cached for 24 hours.
*/
await clerkDevelopmentCache?.run(() => keylessService.completeOnboarding(), {
cacheKey: `${newOrReadKeys.publishableKey}_complete`,
onSuccessStale: 24 * 60 * 60 * 1000, // 24 hours
});
} catch {
// noop
}

/**
* Notify developers.
*/
clerkDevelopmentCache?.log({
cacheKey: `${newOrReadKeys.publishableKey}_claimed`,
msg: createConfirmationMessage(),
});
}

return clientProvider;
};
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,8 +3,7 @@ import type { NextFetchEvent } from 'next/server';
import { NextRequest } from 'next/server';
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest';

// The mock SHOULD exist before the imports: unlike clerkMiddleware.test.ts, keys are empty so the
// missing-key error path is reachable.
// The mock SHOULD exist before the imports. Keys are intentionally empty so the missing-key error path is reachable.
vi.mock(import('../constants.js'), async importOriginal => {
const actual = await importOriginal();
return {
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -37,7 +37,6 @@ const mockRequest = (params: MockRequestParams) => {
if (machineAuthObject) {
const encryptedData = encryptClerkRequestData(
{}, // requestData
{}, // keylessModeKeys
// @ts-expect-error - mock machine auth object
machineAuthObject,
);
Expand Down
1 change: 0 additions & 1 deletion packages/nextjs/src/server/clerkMiddleware.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -389,7 +389,6 @@ async function runHandlerWithRequestState({
handlerResult,
requestState,
resolvedParams,
{},
authObject.tokenType === 'session_token' ? null : makeAuthObjectSerializable(authObject),
);

Expand Down
9 changes: 2 additions & 7 deletions packages/nextjs/src/server/keyless-log-cache.ts
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,5 @@
/**
* Re-export keyless development cache utilities from shared.
* Re-export the keyless development cache from shared.
* This maintains backward compatibility with existing imports.
*/
export {
clerkDevelopmentCache,
createClerkDevCache,
createConfirmationMessage,
createKeylessModeMessage,
} from '@clerk/shared/keyless';
export { clerkDevelopmentCache } from '@clerk/shared/keyless';
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .changeset/keyless-leftover-cleanup.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
---
'@clerk/shared': minor
'@clerk/nextjs': patch
'@clerk/backend': minor
---

Remove leftover keyless-mode creation code now that no SDK mints keyless applications. `@clerk/shared/keyless` drops `resolveKeysWithKeylessFallback`, `getOrCreateKeys`, and related exports (internal APIs consumed only by Clerk SDKs); `@clerk/backend` removes the experimental `createAccountlessApplication` method; `@clerk/nextjs` deletes the unused keyless cookie reader and dead keyless middleware parameters, and logs a pointer to existing `.clerk/.tmp/keyless.json` keys when env keys are missing.
2 changes: 1 addition & 1 deletion integration/scripts/waitForServer.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,7 +6,7 @@ type WaitForServerArgsType = {
acceptAnyResponse?: boolean;
};

// Poll a url until it returns a 200 status code
// Poll a url until it returns 2xx (or any HTTP response when acceptAnyResponse is set)
export const waitForServer = async (url: string, opts: WaitForServerArgsType) => {
const { log, delayInMs = 1000, maxAttempts = 20, shouldExit = () => false, acceptAnyResponse = false } = opts;
let attempts = 0;
Expand Down
100 changes: 1 addition & 99 deletions integration/testUtils/keylessHelpers.ts
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,4 @@
import type { BrowserContext, Page } from '@playwright/test';
import { expect } from '@playwright/test';

import type { Application } from '../models/application';
import { createTestUtils } from './index';
import type { Page } from '@playwright/test';

/**
* Mocks the environment API call to return a claimed instance.
Expand All@@ -22,97 +18,3 @@ export const mockClaimedInstanceEnvironmentCall = async (page: Page): Promise<vo
await route.fulfill({ response, json: newJson });
});
};

/**
* Tests that the keyless popover can be toggled and the claim link opens the dashboard.
*/
export async function testToggleCollapsePopoverAndClaim({
page,
context,
app,
dashboardUrl,
framework,
}: {
page: Page;
context: BrowserContext;
app: Application;
dashboardUrl: string;
framework: string;
}): Promise<void> {
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();
await u.page.waitForClerkJsLoaded();
await u.po.expect.toBeSignedOut();

await u.po.keylessPopover.waitForMounted();

const claim = u.po.keylessPopover.promptsToClaim();

const href = await claim.getAttribute('href');
expect(href).toBeTruthy();

const claimUrl = new URL(href!);
expect(claimUrl.origin + '/').toBe(dashboardUrl);
expect(claimUrl.pathname).toBe('/apps/claim');
expect(claimUrl.searchParams.get('framework')).toBe(framework);
expect(claimUrl.searchParams.has('token')).toBe(true);
expect(claimUrl.searchParams.has('return_url')).toBe(true);
}

/**
* Tests that a claimed application with missing explicit keys shows the popover expanded
* with a prompt to get keys from the dashboard.
*/
export async function testClaimedAppWithMissingKeys({
page,
context,
app,
dashboardUrl,
}: {
page: Page;
context: BrowserContext;
app: Application;
dashboardUrl: string;
}): Promise<void> {
await mockClaimedInstanceEnvironmentCall(page);
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();
await u.page.waitForClerkJsLoaded();

await u.po.keylessPopover.waitForMounted();
expect(await u.po.keylessPopover.isExpanded()).toBe(true);
await expect(u.po.keylessPopover.promptToUseClaimedKeys()).toBeVisible();

const href = await u.po.keylessPopover.promptToUseClaimedKeys().getAttribute('href');
expect(href).toBeTruthy();
expect(href).toContain(dashboardUrl);
}

/**
* Tests that the keyless popover is removed after adding keys to .env and restarting the dev server.
*/
export async function testKeylessRemovedAfterEnvAndRestart({
page,
context,
app,
}: {
page: Page;
context: BrowserContext;
app: Application;
}): Promise<void> {
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();

await u.po.keylessPopover.waitForMounted();

// Copy keys from keyless.json to .env
await app.keylessToEnv();

// Restart the dev server to pick up new env vars (Vite doesn't hot-reload .env)
await app.restart();

await u.page.goToAppHome();

// Keyless popover should no longer be present since we now have explicit keys
await u.po.keylessPopover.waitForUnmounted();
}
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,48 +13,6 @@ describe('AccountlessApplications', () => {
api_keys_url: 'https://dashboard.clerk.com/api-keys',
};

it('creates an accountless application with a source query parameter', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
});

server.use(
http.post('https://api.clerk.test/v1/accountless_applications', ({ request }) => {
const url = new URL(request.url);
expect(url.searchParams.get('source')).toBe('nextjs');
expect(request.headers.get('Clerk-API-Version')).toBeTruthy();
expect(request.headers.get('User-Agent')).toBe('@clerk/backend@0.0.0-test');

return HttpResponse.json(mockAccountlessApplication);
}),
);

const response = await apiClient.__experimental_accountlessApplications.createAccountlessApplication({
source: 'nextjs',
});

expect(response.publishableKey).toBe('pk_test_keyless');
});

it('creates an accountless application without a source query parameter when source is omitted', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
});

server.use(
http.post('https://api.clerk.test/v1/accountless_applications', ({ request }) => {
const url = new URL(request.url);
expect(url.searchParams.has('source')).toBe(false);

return HttpResponse.json(mockAccountlessApplication);
}),
);

const response = await apiClient.__experimental_accountlessApplications.createAccountlessApplication();

expect(response.publishableKey).toBe('pk_test_keyless');
});

it('completes accountless application onboarding with a source query parameter', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
Expand Down
12 changes: 0 additions & 12 deletions packages/backend/src/api/endpoints/AccountlessApplicationsAPI.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,18 +10,6 @@ type AccountlessApplicationParams = {
};

export class AccountlessApplicationAPI extends AbstractAPI {
public async createAccountlessApplication(params?: AccountlessApplicationParams): Promise<AccountlessApplication> {
const headerParams = params?.requestHeaders ? Object.fromEntries(params.requestHeaders.entries()) : undefined;
return this.request<AccountlessApplication>({
method: 'POST',
path: basePath,
headerParams,
queryParams: {
source: params?.source,
},
});
}

public async completeAccountlessApplicationOnboarding(
params?: AccountlessApplicationParams,
): Promise<AccountlessApplication> {
Expand Down
13 changes: 7 additions & 6 deletions packages/nextjs/src/app-router/server/ClerkProvider.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@ import React, { Suspense } from 'react';
import { getDynamicAuthData } from '../../server/buildClerkProps';
import { errorThrower } from '../../server/errorThrower';
import type { NextClerkProviderProps } from '../../types';
import { canUseKeyless } from '../../utils/feature-flags';
import { mergeNextClerkPropsWithEnv } from '../../utils/mergeNextClerkPropsWithEnv';
import { ClientClerkProvider } from '../client/ClerkProvider';
import { DynamicClerkScripts } from './DynamicClerkScripts';
Expand DownExpand Up@@ -32,7 +33,7 @@ export async function ClerkProvider<TUi extends Ui = Ui>(
initialState: statePromiseOrValue as InitialState | undefined,
});

const { shouldRunAsKeyless, runningWithClaimedKeys } = await getKeylessStatus(propsWithEnvs);
const { runningWithClaimedKeys } = await getKeylessStatus(propsWithEnvs);

// When dynamic mode is enabled, render scripts in a Suspense boundary to isolate
// the nonce fetching (which calls headers()) from the rest of the page.
Expand All@@ -52,14 +53,14 @@ export async function ClerkProvider<TUi extends Ui = Ui>(
</Suspense>
) : undefined;

if (shouldRunAsKeyless) {
if (!propsWithEnvs.publishableKey) {
errorThrower.throwMissingPublishableKeyError();
}
if (canUseKeyless && !propsWithEnvs.publishableKey) {
errorThrower.throwMissingPublishableKeyError();
}

if (runningWithClaimedKeys) {
return (
<KeylessProvider
rest={propsWithEnvs}
runningWithClaimedKeys={runningWithClaimedKeys}
__internal_scriptsSlot={scriptsSlot}
>
{children}
Expand Down
85 changes: 33 additions & 52 deletions packages/nextjs/src/app-router/server/keyless-provider.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -11,40 +11,42 @@ import { deleteKeylessAction } from '../keyless-actions';
export async function getKeylessStatus(
params: Without<NextClerkProviderProps, '__internal_invokeMiddlewareOnAuthStateChange' | 'children'>,
) {
let [shouldRunAsKeyless, runningWithClaimedKeys, locallyStoredPublishableKey] = [false, false, ''];
if (canUseKeyless) {
locallyStoredPublishableKey = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys()?.publishableKey || '')
.catch(() => '');
if (!canUseKeyless) {
return { runningWithClaimedKeys: false };
}

runningWithClaimedKeys = Boolean(params.publishableKey) && params.publishableKey === locallyStoredPublishableKey;
shouldRunAsKeyless = !params.publishableKey || runningWithClaimedKeys;
const storedKeys = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys() ?? null)
.catch(() => null);
if (!storedKeys) {
return { runningWithClaimedKeys: false };
}

return {
shouldRunAsKeyless,
runningWithClaimedKeys,
};
if (!params.publishableKey) {
const { clerkDevelopmentCache } = await import('../../server/keyless-log-cache.js');
clerkDevelopmentCache?.log({
cacheKey: `${storedKeys.publishableKey}_stored`,
msg: `[Clerk]: Found existing keyless-mode keys in .clerk/.tmp/keyless.json. Copy the publishableKey and secretKey into .env.local (NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY / CLERK_SECRET_KEY) to keep using that application, or claim it at ${storedKeys.claimUrl}`,
});
return { runningWithClaimedKeys: false };
}

return { runningWithClaimedKeys: params.publishableKey === storedKeys.publishableKey };
}

type KeylessProviderProps = PropsWithChildren<{
rest: Without<NextClerkProviderProps, '__internal_invokeMiddlewareOnAuthStateChange' | 'children'>;
runningWithClaimedKeys: boolean;
__internal_scriptsSlot?: React.ReactNode;
}>;

export const KeylessProvider = async (props: KeylessProviderProps) => {
const { rest, runningWithClaimedKeys, __internal_scriptsSlot, children } = props;
const { rest, __internal_scriptsSlot, children } = props;

// Read-only: the SDK no longer mints keyless applications, it only reads claimed keys from disk.
const newOrReadKeys = await import('../../server/keyless-node.js')
const storedKeys = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys() ?? null)
.catch(() => null);

const { clerkDevelopmentCache, createConfirmationMessage } = await import('../../server/keyless-log-cache.js');

if (!newOrReadKeys) {
// When case keyless should run, but keys are not available, then fallback to throwing for missing keys
if (!storedKeys) {
return (
<ClientClerkProvider
{...mergeNextClerkPropsWithEnv(rest)}
Expand All@@ -56,46 +58,25 @@ export const KeylessProvider = async (props: KeylessProviderProps) => {
);
}

const clientProvider = (
try {
const keylessService = await import('../../server/keyless-node.js').then(mod => mod.keyless());
const { completeClaimedOnboarding } = await import('@clerk/shared/keyless');
await completeClaimedOnboarding(storedKeys.publishableKey, keylessService);
} catch {
// noop
}

return (
<ClientClerkProvider
{...mergeNextClerkPropsWithEnv({
...rest,
publishableKey: newOrReadKeys.publishableKey,
__internal_keyless_claimKeylessApplicationUrl: newOrReadKeys.claimUrl,
__internal_keyless_copyInstanceKeysUrl: newOrReadKeys.apiKeysUrl,
// Explicitly use `null` instead of `undefined` here to avoid persisting `deleteKeylessAction` during merging of options.
__internal_keyless_dismissPrompt: runningWithClaimedKeys ? deleteKeylessAction : null,
__internal_keyless_claimKeylessApplicationUrl: storedKeys.claimUrl,
__internal_keyless_copyInstanceKeysUrl: storedKeys.apiKeysUrl,
__internal_keyless_dismissPrompt: deleteKeylessAction,
})}
__internal_scriptsSlot={__internal_scriptsSlot}
>
{children}
</ClientClerkProvider>
);

if (runningWithClaimedKeys) {
try {
const keylessService = await import('../../server/keyless-node.js').then(mod => mod.keyless());

/**
* Notifying the dashboard should run once. We are controlling this behaviour by caching the result of the request.
* If the request fails, it will be considered stale after 10 minutes, otherwise it is cached for 24 hours.
*/
await clerkDevelopmentCache?.run(() => keylessService.completeOnboarding(), {
cacheKey: `${newOrReadKeys.publishableKey}_complete`,
onSuccessStale: 24 * 60 * 60 * 1000, // 24 hours
});
} catch {
// noop
}

/**
* Notify developers.
*/
clerkDevelopmentCache?.log({
cacheKey: `${newOrReadKeys.publishableKey}_claimed`,
msg: createConfirmationMessage(),
});
}

return clientProvider;
};
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,8 +3,7 @@ import type { NextFetchEvent } from 'next/server';
import { NextRequest } from 'next/server';
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest';

// The mock SHOULD exist before the imports: unlike clerkMiddleware.test.ts, keys are empty so the
// missing-key error path is reachable.
// The mock SHOULD exist before the imports. Keys are intentionally empty so the missing-key error path is reachable.
vi.mock(import('../constants.js'), async importOriginal => {
const actual = await importOriginal();
return {
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -37,7 +37,6 @@ const mockRequest = (params: MockRequestParams) => {
if (machineAuthObject) {
const encryptedData = encryptClerkRequestData(
{}, // requestData
{}, // keylessModeKeys
// @ts-expect-error - mock machine auth object
machineAuthObject,
);
Expand Down
1 change: 0 additions & 1 deletion packages/nextjs/src/server/clerkMiddleware.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -389,7 +389,6 @@ async function runHandlerWithRequestState({
handlerResult,
requestState,
resolvedParams,
{},
authObject.tokenType === 'session_token' ? null : makeAuthObjectSerializable(authObject),
);

Expand Down
9 changes: 2 additions & 7 deletions packages/nextjs/src/server/keyless-log-cache.ts
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,5 @@
/**
* Re-export keyless development cache utilities from shared.
* Re-export the keyless development cache from shared.
* This maintains backward compatibility with existing imports.
*/
export {
clerkDevelopmentCache,
createClerkDevCache,
createConfirmationMessage,
createKeylessModeMessage,
} from '@clerk/shared/keyless';
export { clerkDevelopmentCache } from '@clerk/shared/keyless';
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .changeset/keyless-leftover-cleanup.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
---
'@clerk/shared': minor
'@clerk/nextjs': patch
'@clerk/backend': minor
---

Remove leftover keyless-mode creation code now that no SDK mints keyless applications. `@clerk/shared/keyless` drops `resolveKeysWithKeylessFallback`, `getOrCreateKeys`, and related exports (internal APIs consumed only by Clerk SDKs); `@clerk/backend` removes the experimental `createAccountlessApplication` method; `@clerk/nextjs` deletes the unused keyless cookie reader and dead keyless middleware parameters, and logs a pointer to existing `.clerk/.tmp/keyless.json` keys when env keys are missing.
2 changes: 1 addition & 1 deletion integration/scripts/waitForServer.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -6,7 +6,7 @@ type WaitForServerArgsType = {
acceptAnyResponse?: boolean;
};

// Poll a url until it returns a 200 status code
// Poll a url until it returns 2xx (or any HTTP response when acceptAnyResponse is set)
export const waitForServer = async (url: string, opts: WaitForServerArgsType) => {
const { log, delayInMs = 1000, maxAttempts = 20, shouldExit = () => false, acceptAnyResponse = false } = opts;
let attempts = 0;
Expand Down
100 changes: 1 addition & 99 deletions integration/testUtils/keylessHelpers.ts
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,4 @@
import type { BrowserContext, Page } from '@playwright/test';
import { expect } from '@playwright/test';

import type { Application } from '../models/application';
import { createTestUtils } from './index';
import type { Page } from '@playwright/test';

/**
* Mocks the environment API call to return a claimed instance.
Expand All@@ -22,97 +18,3 @@ export const mockClaimedInstanceEnvironmentCall = async (page: Page): Promise<vo
await route.fulfill({ response, json: newJson });
});
};

/**
* Tests that the keyless popover can be toggled and the claim link opens the dashboard.
*/
export async function testToggleCollapsePopoverAndClaim({
page,
context,
app,
dashboardUrl,
framework,
}: {
page: Page;
context: BrowserContext;
app: Application;
dashboardUrl: string;
framework: string;
}): Promise<void> {
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();
await u.page.waitForClerkJsLoaded();
await u.po.expect.toBeSignedOut();

await u.po.keylessPopover.waitForMounted();

const claim = u.po.keylessPopover.promptsToClaim();

const href = await claim.getAttribute('href');
expect(href).toBeTruthy();

const claimUrl = new URL(href!);
expect(claimUrl.origin + '/').toBe(dashboardUrl);
expect(claimUrl.pathname).toBe('/apps/claim');
expect(claimUrl.searchParams.get('framework')).toBe(framework);
expect(claimUrl.searchParams.has('token')).toBe(true);
expect(claimUrl.searchParams.has('return_url')).toBe(true);
}

/**
* Tests that a claimed application with missing explicit keys shows the popover expanded
* with a prompt to get keys from the dashboard.
*/
export async function testClaimedAppWithMissingKeys({
page,
context,
app,
dashboardUrl,
}: {
page: Page;
context: BrowserContext;
app: Application;
dashboardUrl: string;
}): Promise<void> {
await mockClaimedInstanceEnvironmentCall(page);
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();
await u.page.waitForClerkJsLoaded();

await u.po.keylessPopover.waitForMounted();
expect(await u.po.keylessPopover.isExpanded()).toBe(true);
await expect(u.po.keylessPopover.promptToUseClaimedKeys()).toBeVisible();

const href = await u.po.keylessPopover.promptToUseClaimedKeys().getAttribute('href');
expect(href).toBeTruthy();
expect(href).toContain(dashboardUrl);
}

/**
* Tests that the keyless popover is removed after adding keys to .env and restarting the dev server.
*/
export async function testKeylessRemovedAfterEnvAndRestart({
page,
context,
app,
}: {
page: Page;
context: BrowserContext;
app: Application;
}): Promise<void> {
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();

await u.po.keylessPopover.waitForMounted();

// Copy keys from keyless.json to .env
await app.keylessToEnv();

// Restart the dev server to pick up new env vars (Vite doesn't hot-reload .env)
await app.restart();

await u.page.goToAppHome();

// Keyless popover should no longer be present since we now have explicit keys
await u.po.keylessPopover.waitForUnmounted();
}
Original file line numberDiff line numberDiff line change
Expand Up@@ -13,48 +13,6 @@ describe('AccountlessApplications', () => {
api_keys_url: 'https://dashboard.clerk.com/api-keys',
};

it('creates an accountless application with a source query parameter', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
});

server.use(
http.post('https://api.clerk.test/v1/accountless_applications', ({ request }) => {
const url = new URL(request.url);
expect(url.searchParams.get('source')).toBe('nextjs');
expect(request.headers.get('Clerk-API-Version')).toBeTruthy();
expect(request.headers.get('User-Agent')).toBe('@clerk/backend@0.0.0-test');

return HttpResponse.json(mockAccountlessApplication);
}),
);

const response = await apiClient.__experimental_accountlessApplications.createAccountlessApplication({
source: 'nextjs',
});

expect(response.publishableKey).toBe('pk_test_keyless');
});

it('creates an accountless application without a source query parameter when source is omitted', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
});

server.use(
http.post('https://api.clerk.test/v1/accountless_applications', ({ request }) => {
const url = new URL(request.url);
expect(url.searchParams.has('source')).toBe(false);

return HttpResponse.json(mockAccountlessApplication);
}),
);

const response = await apiClient.__experimental_accountlessApplications.createAccountlessApplication();

expect(response.publishableKey).toBe('pk_test_keyless');
});

it('completes accountless application onboarding with a source query parameter', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
Expand Down
12 changes: 0 additions & 12 deletions packages/backend/src/api/endpoints/AccountlessApplicationsAPI.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,18 +10,6 @@ type AccountlessApplicationParams = {
};

export class AccountlessApplicationAPI extends AbstractAPI {
public async createAccountlessApplication(params?: AccountlessApplicationParams): Promise<AccountlessApplication> {
const headerParams = params?.requestHeaders ? Object.fromEntries(params.requestHeaders.entries()) : undefined;
return this.request<AccountlessApplication>({
method: 'POST',
path: basePath,
headerParams,
queryParams: {
source: params?.source,
},
});
}

public async completeAccountlessApplicationOnboarding(
params?: AccountlessApplicationParams,
): Promise<AccountlessApplication> {
Expand Down
13 changes: 7 additions & 6 deletions packages/nextjs/src/app-router/server/ClerkProvider.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -5,6 +5,7 @@ import React, { Suspense } from 'react';
import { getDynamicAuthData } from '../../server/buildClerkProps';
import { errorThrower } from '../../server/errorThrower';
import type { NextClerkProviderProps } from '../../types';
import { canUseKeyless } from '../../utils/feature-flags';
import { mergeNextClerkPropsWithEnv } from '../../utils/mergeNextClerkPropsWithEnv';
import { ClientClerkProvider } from '../client/ClerkProvider';
import { DynamicClerkScripts } from './DynamicClerkScripts';
Expand DownExpand Up@@ -32,7 +33,7 @@ export async function ClerkProvider<TUi extends Ui = Ui>(
initialState: statePromiseOrValue as InitialState | undefined,
});

const { shouldRunAsKeyless, runningWithClaimedKeys } = await getKeylessStatus(propsWithEnvs);
const { runningWithClaimedKeys } = await getKeylessStatus(propsWithEnvs);

// When dynamic mode is enabled, render scripts in a Suspense boundary to isolate
// the nonce fetching (which calls headers()) from the rest of the page.
Expand All@@ -52,14 +53,14 @@ export async function ClerkProvider<TUi extends Ui = Ui>(
</Suspense>
) : undefined;

if (shouldRunAsKeyless) {
if (!propsWithEnvs.publishableKey) {
errorThrower.throwMissingPublishableKeyError();
}
if (canUseKeyless && !propsWithEnvs.publishableKey) {
errorThrower.throwMissingPublishableKeyError();
}

if (runningWithClaimedKeys) {
return (
<KeylessProvider
rest={propsWithEnvs}
runningWithClaimedKeys={runningWithClaimedKeys}
__internal_scriptsSlot={scriptsSlot}
>
{children}
Expand Down
85 changes: 33 additions & 52 deletions packages/nextjs/src/app-router/server/keyless-provider.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -11,40 +11,42 @@ import { deleteKeylessAction } from '../keyless-actions';
export async function getKeylessStatus(
params: Without<NextClerkProviderProps, '__internal_invokeMiddlewareOnAuthStateChange' | 'children'>,
) {
let [shouldRunAsKeyless, runningWithClaimedKeys, locallyStoredPublishableKey] = [false, false, ''];
if (canUseKeyless) {
locallyStoredPublishableKey = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys()?.publishableKey || '')
.catch(() => '');
if (!canUseKeyless) {
return { runningWithClaimedKeys: false };
}

runningWithClaimedKeys = Boolean(params.publishableKey) && params.publishableKey === locallyStoredPublishableKey;
shouldRunAsKeyless = !params.publishableKey || runningWithClaimedKeys;
const storedKeys = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys() ?? null)
.catch(() => null);
if (!storedKeys) {
return { runningWithClaimedKeys: false };
}

return {
shouldRunAsKeyless,
runningWithClaimedKeys,
};
if (!params.publishableKey) {
const { clerkDevelopmentCache } = await import('../../server/keyless-log-cache.js');
clerkDevelopmentCache?.log({
cacheKey: `${storedKeys.publishableKey}_stored`,
msg: `[Clerk]: Found existing keyless-mode keys in .clerk/.tmp/keyless.json. Copy the publishableKey and secretKey into .env.local (NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY / CLERK_SECRET_KEY) to keep using that application, or claim it at ${storedKeys.claimUrl}`,
});
return { runningWithClaimedKeys: false };
}

return { runningWithClaimedKeys: params.publishableKey === storedKeys.publishableKey };
}

type KeylessProviderProps = PropsWithChildren<{
rest: Without<NextClerkProviderProps, '__internal_invokeMiddlewareOnAuthStateChange' | 'children'>;
runningWithClaimedKeys: boolean;
__internal_scriptsSlot?: React.ReactNode;
}>;

export const KeylessProvider = async (props: KeylessProviderProps) => {
const { rest, runningWithClaimedKeys, __internal_scriptsSlot, children } = props;
const { rest, __internal_scriptsSlot, children } = props;

// Read-only: the SDK no longer mints keyless applications, it only reads claimed keys from disk.
const newOrReadKeys = await import('../../server/keyless-node.js')
const storedKeys = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys() ?? null)
.catch(() => null);

const { clerkDevelopmentCache, createConfirmationMessage } = await import('../../server/keyless-log-cache.js');

if (!newOrReadKeys) {
// When case keyless should run, but keys are not available, then fallback to throwing for missing keys
if (!storedKeys) {
return (
<ClientClerkProvider
{...mergeNextClerkPropsWithEnv(rest)}
Expand All@@ -56,46 +58,25 @@ export const KeylessProvider = async (props: KeylessProviderProps) => {
);
}

const clientProvider = (
try {
const keylessService = await import('../../server/keyless-node.js').then(mod => mod.keyless());
const { completeClaimedOnboarding } = await import('@clerk/shared/keyless');
await completeClaimedOnboarding(storedKeys.publishableKey, keylessService);
} catch {
// noop
}

return (
<ClientClerkProvider
{...mergeNextClerkPropsWithEnv({
...rest,
publishableKey: newOrReadKeys.publishableKey,
__internal_keyless_claimKeylessApplicationUrl: newOrReadKeys.claimUrl,
__internal_keyless_copyInstanceKeysUrl: newOrReadKeys.apiKeysUrl,
// Explicitly use `null` instead of `undefined` here to avoid persisting `deleteKeylessAction` during merging of options.
__internal_keyless_dismissPrompt: runningWithClaimedKeys ? deleteKeylessAction : null,
__internal_keyless_claimKeylessApplicationUrl: storedKeys.claimUrl,
__internal_keyless_copyInstanceKeysUrl: storedKeys.apiKeysUrl,
__internal_keyless_dismissPrompt: deleteKeylessAction,
})}
__internal_scriptsSlot={__internal_scriptsSlot}
>
{children}
</ClientClerkProvider>
);

if (runningWithClaimedKeys) {
try {
const keylessService = await import('../../server/keyless-node.js').then(mod => mod.keyless());

/**
* Notifying the dashboard should run once. We are controlling this behaviour by caching the result of the request.
* If the request fails, it will be considered stale after 10 minutes, otherwise it is cached for 24 hours.
*/
await clerkDevelopmentCache?.run(() => keylessService.completeOnboarding(), {
cacheKey: `${newOrReadKeys.publishableKey}_complete`,
onSuccessStale: 24 * 60 * 60 * 1000, // 24 hours
});
} catch {
// noop
}

/**
* Notify developers.
*/
clerkDevelopmentCache?.log({
cacheKey: `${newOrReadKeys.publishableKey}_claimed`,
msg: createConfirmationMessage(),
});
}

return clientProvider;
};
Original file line numberDiff line numberDiff line change
Expand Up@@ -3,8 +3,7 @@ import type { NextFetchEvent } from 'next/server';
import { NextRequest } from 'next/server';
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest';

// The mock SHOULD exist before the imports: unlike clerkMiddleware.test.ts, keys are empty so the
// missing-key error path is reachable.
// The mock SHOULD exist before the imports. Keys are intentionally empty so the missing-key error path is reachable.
vi.mock(import('../constants.js'), async importOriginal => {
const actual = await importOriginal();
return {
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -37,7 +37,6 @@ const mockRequest = (params: MockRequestParams) => {
if (machineAuthObject) {
const encryptedData = encryptClerkRequestData(
{}, // requestData
{}, // keylessModeKeys
// @ts-expect-error - mock machine auth object
machineAuthObject,
);
Expand Down
1 change: 0 additions & 1 deletion packages/nextjs/src/server/clerkMiddleware.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -389,7 +389,6 @@ async function runHandlerWithRequestState({
handlerResult,
requestState,
resolvedParams,
{},
authObject.tokenType === 'session_token' ? null : makeAuthObjectSerializable(authObject),
);

Expand Down
9 changes: 2 additions & 7 deletions packages/nextjs/src/server/keyless-log-cache.ts
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,5 @@
/**
* Re-export keyless development cache utilities from shared.
* Re-export the keyless development cache from shared.
* This maintains backward compatibility with existing imports.
*/
export {
clerkDevelopmentCache,
createClerkDevCache,
createConfirmationMessage,
createKeylessModeMessage,
} from '@clerk/shared/keyless';
export { clerkDevelopmentCache } from '@clerk/shared/keyless';
Loading
Loading