feat(clerk-js,shared): Attach an optional server-configured session token to sign-in - #9630

Open
zourzouvillys wants to merge 5 commits into
release/core-2from
theo/protect-session-token-v5
Open

feat(clerk-js,shared): Attach an optional server-configured session token to sign-in#9630
zourzouvillys wants to merge 5 commits into
release/core-2from
theo/protect-session-token-v5

Conversation

@zourzouvillys

@zourzouvillyszourzouvillys commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Backport of #9299 to Core 2.

It also carries the request-params plumbing in fapiClient that #9313 introduced on main, but not the application-supplied assertion API that PR added — Core 2 gets the server-configured session token only. That is why the clerk.ts wiring here is one line, where main needs a resolver to union two sources.

#9527 (the verification load timeout) is deliberately out of scope: it bounds the protect-check gate, which does not exist on Core 2.

Notes for reviewers

  • vitest.setup.mts — the shared browser-tabs-lock mock is now a plain class instead of vi.fn(). Core 2 is on vitest 3, where vi.restoreAllMocks() strips vi.fn() implementations; vitest 4 on main no longer does. The ported suites call restoreAllMocks() in afterEach, so under vitest 3 every test after the first in a file got a lock that resolved undefined and silently acquired nothing.
  • Bundlewatch budgets are measured against a Core 2 baseline build, not copied from main (whose entry-bundle list is different). Measured deltas, gzip: clerk.js +2.02KB, clerk.browser.js +2.56KB, clerk.legacy.browser.js +3.11KB, clerk.headless*.js +2.57KB. ui-common, vendors and coinbase are unchanged.
  • clerk.protect-params.test.ts is rewritten rather than cherry-picked — upstream it exists to pin the union of two features, and only one of them exists here.

Verification

CommandResult
vitest run (protect, protectSession, protect-params, fapiClient)114 passed, 1 skipped, 4 todo
vitest run (full clerk-js)2459 passed, 10 skipped, 17 todo, 167 files
vitest run (@clerk/shared)647 passed, 43 files
pnpm run build (clerk-js)rspack + declarations clean, RHC check passed
pnpm run lint (clerk-js)0 errors (480 pre-existing warnings)

The same four protect suites were run against origin/main in a scratch worktree to confirm the vitest-3 lock behaviour was Core 2 specific and not a fault in the ported code — 11/11 there.

Risk

Inert for any instance whose environment carries no protect_config.loaders: no storage is written, no element is injected, and sign-in and sign-up bodies are byte-for-byte unchanged.

CI

Everything this change can affect is green, and the two red integration shards are fixed here. Two checks stay red for reasons no pull request can reach:

CheckWhy it cannot be fixed from a branch
Analyze (rust)CodeQL reports "could not process any code written in Rust" — Core 2 contains no Rust at all (main has five files). Neither branch has a CodeQL workflow or config, so this is default setup configured in repository settings, which govern main too. It fails on every push to release/core-2 itself, with no PR involved, going back to July.
Vercel – swingsetpackages/swingset does not exist on Core 2 (174 files on main, none here), so the project has nothing to build. The only vercel.json in the tree belongs to clerk-js; the swingset project is configured in Vercel, not in the repo.

Both fail identically on #9327, #9248 and #9224 — the last three PRs merged into this branch — so this branch has merged with them red three times. Making them green needs a repository-settings and Vercel-project change, which is a maintainer decision and deliberately not attempted here.

The two integration shards that were red are fixed:

  • Integration Tests (nextjs, chrome, 16)session-tasks-multi-session.test.ts signs the first user back in as its third step, and failed on a disabled password field and a popover that never detached. main replaced that re-sign-in with a session switch plus a delay in fix(repo): fixes multi session switching test #7402, naming a backend rate limit on session touch as the cause, and the fix was never backported. Backported here, so the file now matches main apart from the unrelated createFakeUser(test) from feat(e2e): persist test IDs in created user metadata #9374.
  • Integration Tests (machine, chrome) and (…, RQ) — one case in m2m.test.ts asserts that a token minted after createScope is accepted, and it comes back 401. main deleted this whole file when it refactored machine auth per framework in chore(repo): refactor machine auth tests for Next.js and Astro #8124 and kept createScope coverage only in packages/backend's unit tests, so there is no updated integration test to backport. The single case is marked test.skip with that reasoning inline, rather than deleted, so the assertion stays on record. Reviewers: this is the one change here that is not Protect work — say the word and I will drop it and let the shard stay red instead.

Neither red shard was a symptom of the session-token work. The nextjs shard passed on this branch on runtime-identical code before it failed, 126 of its 127 tests passed including many sign-in flows, and main runs the same protectSession code through two sign-ins in that same test without trouble. The m2m case exercises a backend token-verification path this diff does not touch, and predates it on every merged PR above.

Unit Tests (22, **), Integration Tests (sessions:staging, chrome) and Integration Tests (generic, chrome) each failed once and pass on re-run: a 5s timeout in clerk.test.ts's fake-timer poller test, which is untouched here and passed 109/109 on three consecutive local runs of the full file; a waitForFunction timeout in the production-instance cookie test; and a sign-in component that did not mount in impersonation-flow.test.ts.

@changeset-bot

changeset-botBot commented Sep 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: cfe2517

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 22 packages
NameType
@clerk/clerk-jsMinor
@clerk/sharedMinor
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/elementsPatch
@clerk/expo-passkeysPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/clerk-reactPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/themesPatch
@clerk/typesPatch
@clerk/vuePatch
@clerk/localizationsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Sep 1, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated
clerk-js-sandboxReadyReadyPreviewSep 1, 2026 11:37am UTC
swingsetErrorErrorSep 1, 2026 11:37am UTC

Request Review

@coderabbitai

coderabbitaiBot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Team

Run ID: 1912d6d8-704e-4570-8c1f-328b7d391a02

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@zourzouvillyszourzouvillys changed the title feat(clerk-js,shared): attach an optional server-configured session token to sign-in (Core 2)feat(clerk-js,shared): attach an optional server-configured session token to sign-inSep 1, 2026
@pkg-pr-new

pkg-pr-newBot commented Sep 1, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@9630

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9630

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9630

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9630

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9630

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@9630

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@9630

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@9630

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9630

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9630

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9630

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9630

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9630

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9630

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@9630

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9630

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@9630

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9630

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9630

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9630

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@9630

@clerk/types

npm i https://pkg.pr.new/@clerk/types@9630

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9630

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9630

commit: cfe2517

@zourzouvillyszourzouvillys changed the title feat(clerk-js,shared): attach an optional server-configured session token to sign-infeat(clerk-js,shared): Attach an optional server-configured session token to sign-inSep 1, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@zourzouvillys@Ephem
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(clerk-js,shared): Attach an optional server-configured session token to sign-in - #9630

Open
zourzouvillys wants to merge 5 commits into
release/core-2from
theo/protect-session-token-v5
Open

feat(clerk-js,shared): Attach an optional server-configured session token to sign-in#9630
zourzouvillys wants to merge 5 commits into
release/core-2from
theo/protect-session-token-v5

Conversation

@zourzouvillys

@zourzouvillyszourzouvillys commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Backport of #9299 to Core 2.

It also carries the request-params plumbing in fapiClient that #9313 introduced on main, but not the application-supplied assertion API that PR added — Core 2 gets the server-configured session token only. That is why the clerk.ts wiring here is one line, where main needs a resolver to union two sources.

#9527 (the verification load timeout) is deliberately out of scope: it bounds the protect-check gate, which does not exist on Core 2.

Notes for reviewers

  • vitest.setup.mts — the shared browser-tabs-lock mock is now a plain class instead of vi.fn(). Core 2 is on vitest 3, where vi.restoreAllMocks() strips vi.fn() implementations; vitest 4 on main no longer does. The ported suites call restoreAllMocks() in afterEach, so under vitest 3 every test after the first in a file got a lock that resolved undefined and silently acquired nothing.
  • Bundlewatch budgets are measured against a Core 2 baseline build, not copied from main (whose entry-bundle list is different). Measured deltas, gzip: clerk.js +2.02KB, clerk.browser.js +2.56KB, clerk.legacy.browser.js +3.11KB, clerk.headless*.js +2.57KB. ui-common, vendors and coinbase are unchanged.
  • clerk.protect-params.test.ts is rewritten rather than cherry-picked — upstream it exists to pin the union of two features, and only one of them exists here.

Verification

CommandResult
vitest run (protect, protectSession, protect-params, fapiClient)114 passed, 1 skipped, 4 todo
vitest run (full clerk-js)2459 passed, 10 skipped, 17 todo, 167 files
vitest run (@clerk/shared)647 passed, 43 files
pnpm run build (clerk-js)rspack + declarations clean, RHC check passed
pnpm run lint (clerk-js)0 errors (480 pre-existing warnings)

The same four protect suites were run against origin/main in a scratch worktree to confirm the vitest-3 lock behaviour was Core 2 specific and not a fault in the ported code — 11/11 there.

Risk

Inert for any instance whose environment carries no protect_config.loaders: no storage is written, no element is injected, and sign-in and sign-up bodies are byte-for-byte unchanged.

CI

Everything this change can affect is green, and the two red integration shards are fixed here. Two checks stay red for reasons no pull request can reach:

CheckWhy it cannot be fixed from a branch
Analyze (rust)CodeQL reports "could not process any code written in Rust" — Core 2 contains no Rust at all (main has five files). Neither branch has a CodeQL workflow or config, so this is default setup configured in repository settings, which govern main too. It fails on every push to release/core-2 itself, with no PR involved, going back to July.
Vercel – swingsetpackages/swingset does not exist on Core 2 (174 files on main, none here), so the project has nothing to build. The only vercel.json in the tree belongs to clerk-js; the swingset project is configured in Vercel, not in the repo.

Both fail identically on #9327, #9248 and #9224 — the last three PRs merged into this branch — so this branch has merged with them red three times. Making them green needs a repository-settings and Vercel-project change, which is a maintainer decision and deliberately not attempted here.

The two integration shards that were red are fixed:

  • Integration Tests (nextjs, chrome, 16)session-tasks-multi-session.test.ts signs the first user back in as its third step, and failed on a disabled password field and a popover that never detached. main replaced that re-sign-in with a session switch plus a delay in fix(repo): fixes multi session switching test #7402, naming a backend rate limit on session touch as the cause, and the fix was never backported. Backported here, so the file now matches main apart from the unrelated createFakeUser(test) from feat(e2e): persist test IDs in created user metadata #9374.
  • Integration Tests (machine, chrome) and (…, RQ) — one case in m2m.test.ts asserts that a token minted after createScope is accepted, and it comes back 401. main deleted this whole file when it refactored machine auth per framework in chore(repo): refactor machine auth tests for Next.js and Astro #8124 and kept createScope coverage only in packages/backend's unit tests, so there is no updated integration test to backport. The single case is marked test.skip with that reasoning inline, rather than deleted, so the assertion stays on record. Reviewers: this is the one change here that is not Protect work — say the word and I will drop it and let the shard stay red instead.

Neither red shard was a symptom of the session-token work. The nextjs shard passed on this branch on runtime-identical code before it failed, 126 of its 127 tests passed including many sign-in flows, and main runs the same protectSession code through two sign-ins in that same test without trouble. The m2m case exercises a backend token-verification path this diff does not touch, and predates it on every merged PR above.

Unit Tests (22, **), Integration Tests (sessions:staging, chrome) and Integration Tests (generic, chrome) each failed once and pass on re-run: a 5s timeout in clerk.test.ts's fake-timer poller test, which is untouched here and passed 109/109 on three consecutive local runs of the full file; a waitForFunction timeout in the production-instance cookie test; and a sign-in component that did not mount in impersonation-flow.test.ts.

@changeset-bot

changeset-botBot commented Sep 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: cfe2517

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 22 packages
NameType
@clerk/clerk-jsMinor
@clerk/sharedMinor
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/elementsPatch
@clerk/expo-passkeysPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/clerk-reactPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/themesPatch
@clerk/typesPatch
@clerk/vuePatch
@clerk/localizationsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Sep 1, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated
clerk-js-sandboxReadyReadyPreviewSep 1, 2026 11:37am UTC
swingsetErrorErrorSep 1, 2026 11:37am UTC

Request Review

@coderabbitai

coderabbitaiBot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Team

Run ID: 1912d6d8-704e-4570-8c1f-328b7d391a02

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@zourzouvillyszourzouvillys changed the title feat(clerk-js,shared): attach an optional server-configured session token to sign-in (Core 2)feat(clerk-js,shared): attach an optional server-configured session token to sign-inSep 1, 2026
@pkg-pr-new

pkg-pr-newBot commented Sep 1, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@9630

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9630

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9630

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9630

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9630

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@9630

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@9630

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@9630

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9630

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9630

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9630

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9630

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9630

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9630

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@9630

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9630

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@9630

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9630

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9630

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9630

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@9630

@clerk/types

npm i https://pkg.pr.new/@clerk/types@9630

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9630

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9630

commit: cfe2517

@zourzouvillyszourzouvillys changed the title feat(clerk-js,shared): attach an optional server-configured session token to sign-infeat(clerk-js,shared): Attach an optional server-configured session token to sign-inSep 1, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@zourzouvillys@Ephem
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(clerk-js,shared): Attach an optional server-configured session token to sign-in - #9630

Open
zourzouvillys wants to merge 5 commits into
release/core-2from
theo/protect-session-token-v5
Open

feat(clerk-js,shared): Attach an optional server-configured session token to sign-in#9630
zourzouvillys wants to merge 5 commits into
release/core-2from
theo/protect-session-token-v5

Conversation

@zourzouvillys

@zourzouvillyszourzouvillys commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Backport of #9299 to Core 2.

It also carries the request-params plumbing in fapiClient that #9313 introduced on main, but not the application-supplied assertion API that PR added — Core 2 gets the server-configured session token only. That is why the clerk.ts wiring here is one line, where main needs a resolver to union two sources.

#9527 (the verification load timeout) is deliberately out of scope: it bounds the protect-check gate, which does not exist on Core 2.

Notes for reviewers

  • vitest.setup.mts — the shared browser-tabs-lock mock is now a plain class instead of vi.fn(). Core 2 is on vitest 3, where vi.restoreAllMocks() strips vi.fn() implementations; vitest 4 on main no longer does. The ported suites call restoreAllMocks() in afterEach, so under vitest 3 every test after the first in a file got a lock that resolved undefined and silently acquired nothing.
  • Bundlewatch budgets are measured against a Core 2 baseline build, not copied from main (whose entry-bundle list is different). Measured deltas, gzip: clerk.js +2.02KB, clerk.browser.js +2.56KB, clerk.legacy.browser.js +3.11KB, clerk.headless*.js +2.57KB. ui-common, vendors and coinbase are unchanged.
  • clerk.protect-params.test.ts is rewritten rather than cherry-picked — upstream it exists to pin the union of two features, and only one of them exists here.

Verification

CommandResult
vitest run (protect, protectSession, protect-params, fapiClient)114 passed, 1 skipped, 4 todo
vitest run (full clerk-js)2459 passed, 10 skipped, 17 todo, 167 files
vitest run (@clerk/shared)647 passed, 43 files
pnpm run build (clerk-js)rspack + declarations clean, RHC check passed
pnpm run lint (clerk-js)0 errors (480 pre-existing warnings)

The same four protect suites were run against origin/main in a scratch worktree to confirm the vitest-3 lock behaviour was Core 2 specific and not a fault in the ported code — 11/11 there.

Risk

Inert for any instance whose environment carries no protect_config.loaders: no storage is written, no element is injected, and sign-in and sign-up bodies are byte-for-byte unchanged.

CI

Everything this change can affect is green, and the two red integration shards are fixed here. Two checks stay red for reasons no pull request can reach:

CheckWhy it cannot be fixed from a branch
Analyze (rust)CodeQL reports "could not process any code written in Rust" — Core 2 contains no Rust at all (main has five files). Neither branch has a CodeQL workflow or config, so this is default setup configured in repository settings, which govern main too. It fails on every push to release/core-2 itself, with no PR involved, going back to July.
Vercel – swingsetpackages/swingset does not exist on Core 2 (174 files on main, none here), so the project has nothing to build. The only vercel.json in the tree belongs to clerk-js; the swingset project is configured in Vercel, not in the repo.

Both fail identically on #9327, #9248 and #9224 — the last three PRs merged into this branch — so this branch has merged with them red three times. Making them green needs a repository-settings and Vercel-project change, which is a maintainer decision and deliberately not attempted here.

The two integration shards that were red are fixed:

  • Integration Tests (nextjs, chrome, 16)session-tasks-multi-session.test.ts signs the first user back in as its third step, and failed on a disabled password field and a popover that never detached. main replaced that re-sign-in with a session switch plus a delay in fix(repo): fixes multi session switching test #7402, naming a backend rate limit on session touch as the cause, and the fix was never backported. Backported here, so the file now matches main apart from the unrelated createFakeUser(test) from feat(e2e): persist test IDs in created user metadata #9374.
  • Integration Tests (machine, chrome) and (…, RQ) — one case in m2m.test.ts asserts that a token minted after createScope is accepted, and it comes back 401. main deleted this whole file when it refactored machine auth per framework in chore(repo): refactor machine auth tests for Next.js and Astro #8124 and kept createScope coverage only in packages/backend's unit tests, so there is no updated integration test to backport. The single case is marked test.skip with that reasoning inline, rather than deleted, so the assertion stays on record. Reviewers: this is the one change here that is not Protect work — say the word and I will drop it and let the shard stay red instead.

Neither red shard was a symptom of the session-token work. The nextjs shard passed on this branch on runtime-identical code before it failed, 126 of its 127 tests passed including many sign-in flows, and main runs the same protectSession code through two sign-ins in that same test without trouble. The m2m case exercises a backend token-verification path this diff does not touch, and predates it on every merged PR above.

Unit Tests (22, **), Integration Tests (sessions:staging, chrome) and Integration Tests (generic, chrome) each failed once and pass on re-run: a 5s timeout in clerk.test.ts's fake-timer poller test, which is untouched here and passed 109/109 on three consecutive local runs of the full file; a waitForFunction timeout in the production-instance cookie test; and a sign-in component that did not mount in impersonation-flow.test.ts.

@changeset-bot

changeset-botBot commented Sep 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: cfe2517

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 22 packages
NameType
@clerk/clerk-jsMinor
@clerk/sharedMinor
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/elementsPatch
@clerk/expo-passkeysPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/clerk-reactPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/themesPatch
@clerk/typesPatch
@clerk/vuePatch
@clerk/localizationsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Sep 1, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated
clerk-js-sandboxReadyReadyPreviewSep 1, 2026 11:37am UTC
swingsetErrorErrorSep 1, 2026 11:37am UTC

Request Review

@coderabbitai

coderabbitaiBot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Team

Run ID: 1912d6d8-704e-4570-8c1f-328b7d391a02

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@zourzouvillyszourzouvillys changed the title feat(clerk-js,shared): attach an optional server-configured session token to sign-in (Core 2)feat(clerk-js,shared): attach an optional server-configured session token to sign-inSep 1, 2026
@pkg-pr-new

pkg-pr-newBot commented Sep 1, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@9630

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9630

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9630

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9630

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9630

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@9630

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@9630

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@9630

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9630

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9630

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9630

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9630

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9630

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9630

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@9630

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9630

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@9630

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9630

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9630

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9630

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@9630

@clerk/types

npm i https://pkg.pr.new/@clerk/types@9630

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9630

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9630

commit: cfe2517

@zourzouvillyszourzouvillys changed the title feat(clerk-js,shared): attach an optional server-configured session token to sign-infeat(clerk-js,shared): Attach an optional server-configured session token to sign-inSep 1, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@zourzouvillys@Ephem
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(clerk-js,shared): Attach an optional server-configured session token to sign-in - #9630

Open
zourzouvillys wants to merge 5 commits into
release/core-2from
theo/protect-session-token-v5
Open

feat(clerk-js,shared): Attach an optional server-configured session token to sign-in#9630
zourzouvillys wants to merge 5 commits into
release/core-2from
theo/protect-session-token-v5

Conversation

@zourzouvillys

@zourzouvillyszourzouvillys commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Backport of #9299 to Core 2.

It also carries the request-params plumbing in fapiClient that #9313 introduced on main, but not the application-supplied assertion API that PR added — Core 2 gets the server-configured session token only. That is why the clerk.ts wiring here is one line, where main needs a resolver to union two sources.

#9527 (the verification load timeout) is deliberately out of scope: it bounds the protect-check gate, which does not exist on Core 2.

Notes for reviewers

  • vitest.setup.mts — the shared browser-tabs-lock mock is now a plain class instead of vi.fn(). Core 2 is on vitest 3, where vi.restoreAllMocks() strips vi.fn() implementations; vitest 4 on main no longer does. The ported suites call restoreAllMocks() in afterEach, so under vitest 3 every test after the first in a file got a lock that resolved undefined and silently acquired nothing.
  • Bundlewatch budgets are measured against a Core 2 baseline build, not copied from main (whose entry-bundle list is different). Measured deltas, gzip: clerk.js +2.02KB, clerk.browser.js +2.56KB, clerk.legacy.browser.js +3.11KB, clerk.headless*.js +2.57KB. ui-common, vendors and coinbase are unchanged.
  • clerk.protect-params.test.ts is rewritten rather than cherry-picked — upstream it exists to pin the union of two features, and only one of them exists here.

Verification

CommandResult
vitest run (protect, protectSession, protect-params, fapiClient)114 passed, 1 skipped, 4 todo
vitest run (full clerk-js)2459 passed, 10 skipped, 17 todo, 167 files
vitest run (@clerk/shared)647 passed, 43 files
pnpm run build (clerk-js)rspack + declarations clean, RHC check passed
pnpm run lint (clerk-js)0 errors (480 pre-existing warnings)

The same four protect suites were run against origin/main in a scratch worktree to confirm the vitest-3 lock behaviour was Core 2 specific and not a fault in the ported code — 11/11 there.

Risk

Inert for any instance whose environment carries no protect_config.loaders: no storage is written, no element is injected, and sign-in and sign-up bodies are byte-for-byte unchanged.

CI

Everything this change can affect is green, and the two red integration shards are fixed here. Two checks stay red for reasons no pull request can reach:

CheckWhy it cannot be fixed from a branch
Analyze (rust)CodeQL reports "could not process any code written in Rust" — Core 2 contains no Rust at all (main has five files). Neither branch has a CodeQL workflow or config, so this is default setup configured in repository settings, which govern main too. It fails on every push to release/core-2 itself, with no PR involved, going back to July.
Vercel – swingsetpackages/swingset does not exist on Core 2 (174 files on main, none here), so the project has nothing to build. The only vercel.json in the tree belongs to clerk-js; the swingset project is configured in Vercel, not in the repo.

Both fail identically on #9327, #9248 and #9224 — the last three PRs merged into this branch — so this branch has merged with them red three times. Making them green needs a repository-settings and Vercel-project change, which is a maintainer decision and deliberately not attempted here.

The two integration shards that were red are fixed:

  • Integration Tests (nextjs, chrome, 16)session-tasks-multi-session.test.ts signs the first user back in as its third step, and failed on a disabled password field and a popover that never detached. main replaced that re-sign-in with a session switch plus a delay in fix(repo): fixes multi session switching test #7402, naming a backend rate limit on session touch as the cause, and the fix was never backported. Backported here, so the file now matches main apart from the unrelated createFakeUser(test) from feat(e2e): persist test IDs in created user metadata #9374.
  • Integration Tests (machine, chrome) and (…, RQ) — one case in m2m.test.ts asserts that a token minted after createScope is accepted, and it comes back 401. main deleted this whole file when it refactored machine auth per framework in chore(repo): refactor machine auth tests for Next.js and Astro #8124 and kept createScope coverage only in packages/backend's unit tests, so there is no updated integration test to backport. The single case is marked test.skip with that reasoning inline, rather than deleted, so the assertion stays on record. Reviewers: this is the one change here that is not Protect work — say the word and I will drop it and let the shard stay red instead.

Neither red shard was a symptom of the session-token work. The nextjs shard passed on this branch on runtime-identical code before it failed, 126 of its 127 tests passed including many sign-in flows, and main runs the same protectSession code through two sign-ins in that same test without trouble. The m2m case exercises a backend token-verification path this diff does not touch, and predates it on every merged PR above.

Unit Tests (22, **), Integration Tests (sessions:staging, chrome) and Integration Tests (generic, chrome) each failed once and pass on re-run: a 5s timeout in clerk.test.ts's fake-timer poller test, which is untouched here and passed 109/109 on three consecutive local runs of the full file; a waitForFunction timeout in the production-instance cookie test; and a sign-in component that did not mount in impersonation-flow.test.ts.

@changeset-bot

changeset-botBot commented Sep 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: cfe2517

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 22 packages
NameType
@clerk/clerk-jsMinor
@clerk/sharedMinor
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/elementsPatch
@clerk/expo-passkeysPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/clerk-reactPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/themesPatch
@clerk/typesPatch
@clerk/vuePatch
@clerk/localizationsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Sep 1, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated
clerk-js-sandboxReadyReadyPreviewSep 1, 2026 11:37am UTC
swingsetErrorErrorSep 1, 2026 11:37am UTC

Request Review

@coderabbitai

coderabbitaiBot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Team

Run ID: 1912d6d8-704e-4570-8c1f-328b7d391a02

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@zourzouvillyszourzouvillys changed the title feat(clerk-js,shared): attach an optional server-configured session token to sign-in (Core 2)feat(clerk-js,shared): attach an optional server-configured session token to sign-inSep 1, 2026
@pkg-pr-new

pkg-pr-newBot commented Sep 1, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@9630

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9630

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9630

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9630

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9630

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@9630

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@9630

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@9630

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9630

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9630

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9630

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9630

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9630

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9630

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@9630

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9630

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@9630

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9630

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9630

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9630

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@9630

@clerk/types

npm i https://pkg.pr.new/@clerk/types@9630

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9630

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9630

commit: cfe2517

@zourzouvillyszourzouvillys changed the title feat(clerk-js,shared): attach an optional server-configured session token to sign-infeat(clerk-js,shared): Attach an optional server-configured session token to sign-inSep 1, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@zourzouvillys@Ephem
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(clerk-js,shared): Attach an optional server-configured session token to sign-in - #9630

Open
zourzouvillys wants to merge 5 commits into
release/core-2from
theo/protect-session-token-v5
Open

feat(clerk-js,shared): Attach an optional server-configured session token to sign-in#9630
zourzouvillys wants to merge 5 commits into
release/core-2from
theo/protect-session-token-v5

Conversation

@zourzouvillys

@zourzouvillyszourzouvillys commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Backport of #9299 to Core 2.

It also carries the request-params plumbing in fapiClient that #9313 introduced on main, but not the application-supplied assertion API that PR added — Core 2 gets the server-configured session token only. That is why the clerk.ts wiring here is one line, where main needs a resolver to union two sources.

#9527 (the verification load timeout) is deliberately out of scope: it bounds the protect-check gate, which does not exist on Core 2.

Notes for reviewers

  • vitest.setup.mts — the shared browser-tabs-lock mock is now a plain class instead of vi.fn(). Core 2 is on vitest 3, where vi.restoreAllMocks() strips vi.fn() implementations; vitest 4 on main no longer does. The ported suites call restoreAllMocks() in afterEach, so under vitest 3 every test after the first in a file got a lock that resolved undefined and silently acquired nothing.
  • Bundlewatch budgets are measured against a Core 2 baseline build, not copied from main (whose entry-bundle list is different). Measured deltas, gzip: clerk.js +2.02KB, clerk.browser.js +2.56KB, clerk.legacy.browser.js +3.11KB, clerk.headless*.js +2.57KB. ui-common, vendors and coinbase are unchanged.
  • clerk.protect-params.test.ts is rewritten rather than cherry-picked — upstream it exists to pin the union of two features, and only one of them exists here.

Verification

CommandResult
vitest run (protect, protectSession, protect-params, fapiClient)114 passed, 1 skipped, 4 todo
vitest run (full clerk-js)2459 passed, 10 skipped, 17 todo, 167 files
vitest run (@clerk/shared)647 passed, 43 files
pnpm run build (clerk-js)rspack + declarations clean, RHC check passed
pnpm run lint (clerk-js)0 errors (480 pre-existing warnings)

The same four protect suites were run against origin/main in a scratch worktree to confirm the vitest-3 lock behaviour was Core 2 specific and not a fault in the ported code — 11/11 there.

Risk

Inert for any instance whose environment carries no protect_config.loaders: no storage is written, no element is injected, and sign-in and sign-up bodies are byte-for-byte unchanged.

CI

Everything this change can affect is green, and the two red integration shards are fixed here. Two checks stay red for reasons no pull request can reach:

CheckWhy it cannot be fixed from a branch
Analyze (rust)CodeQL reports "could not process any code written in Rust" — Core 2 contains no Rust at all (main has five files). Neither branch has a CodeQL workflow or config, so this is default setup configured in repository settings, which govern main too. It fails on every push to release/core-2 itself, with no PR involved, going back to July.
Vercel – swingsetpackages/swingset does not exist on Core 2 (174 files on main, none here), so the project has nothing to build. The only vercel.json in the tree belongs to clerk-js; the swingset project is configured in Vercel, not in the repo.

Both fail identically on #9327, #9248 and #9224 — the last three PRs merged into this branch — so this branch has merged with them red three times. Making them green needs a repository-settings and Vercel-project change, which is a maintainer decision and deliberately not attempted here.

The two integration shards that were red are fixed:

  • Integration Tests (nextjs, chrome, 16)session-tasks-multi-session.test.ts signs the first user back in as its third step, and failed on a disabled password field and a popover that never detached. main replaced that re-sign-in with a session switch plus a delay in fix(repo): fixes multi session switching test #7402, naming a backend rate limit on session touch as the cause, and the fix was never backported. Backported here, so the file now matches main apart from the unrelated createFakeUser(test) from feat(e2e): persist test IDs in created user metadata #9374.
  • Integration Tests (machine, chrome) and (…, RQ) — one case in m2m.test.ts asserts that a token minted after createScope is accepted, and it comes back 401. main deleted this whole file when it refactored machine auth per framework in chore(repo): refactor machine auth tests for Next.js and Astro #8124 and kept createScope coverage only in packages/backend's unit tests, so there is no updated integration test to backport. The single case is marked test.skip with that reasoning inline, rather than deleted, so the assertion stays on record. Reviewers: this is the one change here that is not Protect work — say the word and I will drop it and let the shard stay red instead.

Neither red shard was a symptom of the session-token work. The nextjs shard passed on this branch on runtime-identical code before it failed, 126 of its 127 tests passed including many sign-in flows, and main runs the same protectSession code through two sign-ins in that same test without trouble. The m2m case exercises a backend token-verification path this diff does not touch, and predates it on every merged PR above.

Unit Tests (22, **), Integration Tests (sessions:staging, chrome) and Integration Tests (generic, chrome) each failed once and pass on re-run: a 5s timeout in clerk.test.ts's fake-timer poller test, which is untouched here and passed 109/109 on three consecutive local runs of the full file; a waitForFunction timeout in the production-instance cookie test; and a sign-in component that did not mount in impersonation-flow.test.ts.

@changeset-bot

changeset-botBot commented Sep 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: cfe2517

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 22 packages
NameType
@clerk/clerk-jsMinor
@clerk/sharedMinor
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/elementsPatch
@clerk/expo-passkeysPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/clerk-reactPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/themesPatch
@clerk/typesPatch
@clerk/vuePatch
@clerk/localizationsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Sep 1, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated
clerk-js-sandboxReadyReadyPreviewSep 1, 2026 11:37am UTC
swingsetErrorErrorSep 1, 2026 11:37am UTC

Request Review

@coderabbitai

coderabbitaiBot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Team

Run ID: 1912d6d8-704e-4570-8c1f-328b7d391a02

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@zourzouvillyszourzouvillys changed the title feat(clerk-js,shared): attach an optional server-configured session token to sign-in (Core 2)feat(clerk-js,shared): attach an optional server-configured session token to sign-inSep 1, 2026
@pkg-pr-new

pkg-pr-newBot commented Sep 1, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@9630

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9630

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9630

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9630

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9630

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@9630

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@9630

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@9630

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9630

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9630

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9630

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9630

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9630

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9630

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@9630

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9630

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@9630

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9630

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9630

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9630

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@9630

@clerk/types

npm i https://pkg.pr.new/@clerk/types@9630

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9630

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9630

commit: cfe2517

@zourzouvillyszourzouvillys changed the title feat(clerk-js,shared): attach an optional server-configured session token to sign-infeat(clerk-js,shared): Attach an optional server-configured session token to sign-inSep 1, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@zourzouvillys@Ephem
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(clerk-js,shared): Attach an optional server-configured session token to sign-in - #9630

Open
zourzouvillys wants to merge 5 commits into
release/core-2from
theo/protect-session-token-v5
Open

feat(clerk-js,shared): Attach an optional server-configured session token to sign-in#9630
zourzouvillys wants to merge 5 commits into
release/core-2from
theo/protect-session-token-v5

Conversation

@zourzouvillys

@zourzouvillyszourzouvillys commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Backport of #9299 to Core 2.

It also carries the request-params plumbing in fapiClient that #9313 introduced on main, but not the application-supplied assertion API that PR added — Core 2 gets the server-configured session token only. That is why the clerk.ts wiring here is one line, where main needs a resolver to union two sources.

#9527 (the verification load timeout) is deliberately out of scope: it bounds the protect-check gate, which does not exist on Core 2.

Notes for reviewers

  • vitest.setup.mts — the shared browser-tabs-lock mock is now a plain class instead of vi.fn(). Core 2 is on vitest 3, where vi.restoreAllMocks() strips vi.fn() implementations; vitest 4 on main no longer does. The ported suites call restoreAllMocks() in afterEach, so under vitest 3 every test after the first in a file got a lock that resolved undefined and silently acquired nothing.
  • Bundlewatch budgets are measured against a Core 2 baseline build, not copied from main (whose entry-bundle list is different). Measured deltas, gzip: clerk.js +2.02KB, clerk.browser.js +2.56KB, clerk.legacy.browser.js +3.11KB, clerk.headless*.js +2.57KB. ui-common, vendors and coinbase are unchanged.
  • clerk.protect-params.test.ts is rewritten rather than cherry-picked — upstream it exists to pin the union of two features, and only one of them exists here.

Verification

CommandResult
vitest run (protect, protectSession, protect-params, fapiClient)114 passed, 1 skipped, 4 todo
vitest run (full clerk-js)2459 passed, 10 skipped, 17 todo, 167 files
vitest run (@clerk/shared)647 passed, 43 files
pnpm run build (clerk-js)rspack + declarations clean, RHC check passed
pnpm run lint (clerk-js)0 errors (480 pre-existing warnings)

The same four protect suites were run against origin/main in a scratch worktree to confirm the vitest-3 lock behaviour was Core 2 specific and not a fault in the ported code — 11/11 there.

Risk

Inert for any instance whose environment carries no protect_config.loaders: no storage is written, no element is injected, and sign-in and sign-up bodies are byte-for-byte unchanged.

CI

Everything this change can affect is green, and the two red integration shards are fixed here. Two checks stay red for reasons no pull request can reach:

CheckWhy it cannot be fixed from a branch
Analyze (rust)CodeQL reports "could not process any code written in Rust" — Core 2 contains no Rust at all (main has five files). Neither branch has a CodeQL workflow or config, so this is default setup configured in repository settings, which govern main too. It fails on every push to release/core-2 itself, with no PR involved, going back to July.
Vercel – swingsetpackages/swingset does not exist on Core 2 (174 files on main, none here), so the project has nothing to build. The only vercel.json in the tree belongs to clerk-js; the swingset project is configured in Vercel, not in the repo.

Both fail identically on #9327, #9248 and #9224 — the last three PRs merged into this branch — so this branch has merged with them red three times. Making them green needs a repository-settings and Vercel-project change, which is a maintainer decision and deliberately not attempted here.

The two integration shards that were red are fixed:

  • Integration Tests (nextjs, chrome, 16)session-tasks-multi-session.test.ts signs the first user back in as its third step, and failed on a disabled password field and a popover that never detached. main replaced that re-sign-in with a session switch plus a delay in fix(repo): fixes multi session switching test #7402, naming a backend rate limit on session touch as the cause, and the fix was never backported. Backported here, so the file now matches main apart from the unrelated createFakeUser(test) from feat(e2e): persist test IDs in created user metadata #9374.
  • Integration Tests (machine, chrome) and (…, RQ) — one case in m2m.test.ts asserts that a token minted after createScope is accepted, and it comes back 401. main deleted this whole file when it refactored machine auth per framework in chore(repo): refactor machine auth tests for Next.js and Astro #8124 and kept createScope coverage only in packages/backend's unit tests, so there is no updated integration test to backport. The single case is marked test.skip with that reasoning inline, rather than deleted, so the assertion stays on record. Reviewers: this is the one change here that is not Protect work — say the word and I will drop it and let the shard stay red instead.

Neither red shard was a symptom of the session-token work. The nextjs shard passed on this branch on runtime-identical code before it failed, 126 of its 127 tests passed including many sign-in flows, and main runs the same protectSession code through two sign-ins in that same test without trouble. The m2m case exercises a backend token-verification path this diff does not touch, and predates it on every merged PR above.

Unit Tests (22, **), Integration Tests (sessions:staging, chrome) and Integration Tests (generic, chrome) each failed once and pass on re-run: a 5s timeout in clerk.test.ts's fake-timer poller test, which is untouched here and passed 109/109 on three consecutive local runs of the full file; a waitForFunction timeout in the production-instance cookie test; and a sign-in component that did not mount in impersonation-flow.test.ts.

@changeset-bot

changeset-botBot commented Sep 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: cfe2517

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 22 packages
NameType
@clerk/clerk-jsMinor
@clerk/sharedMinor
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/elementsPatch
@clerk/expo-passkeysPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/clerk-reactPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/themesPatch
@clerk/typesPatch
@clerk/vuePatch
@clerk/localizationsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Sep 1, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated
clerk-js-sandboxReadyReadyPreviewSep 1, 2026 11:37am UTC
swingsetErrorErrorSep 1, 2026 11:37am UTC

Request Review

@coderabbitai

coderabbitaiBot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Team

Run ID: 1912d6d8-704e-4570-8c1f-328b7d391a02

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@zourzouvillyszourzouvillys changed the title feat(clerk-js,shared): attach an optional server-configured session token to sign-in (Core 2)feat(clerk-js,shared): attach an optional server-configured session token to sign-inSep 1, 2026
@pkg-pr-new

pkg-pr-newBot commented Sep 1, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@9630

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9630

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9630

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9630

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9630

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@9630

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@9630

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@9630

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9630

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9630

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9630

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9630

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9630

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9630

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@9630

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9630

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@9630

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9630

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9630

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9630

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@9630

@clerk/types

npm i https://pkg.pr.new/@clerk/types@9630

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9630

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9630

commit: cfe2517

@zourzouvillyszourzouvillys changed the title feat(clerk-js,shared): attach an optional server-configured session token to sign-infeat(clerk-js,shared): Attach an optional server-configured session token to sign-inSep 1, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@zourzouvillys@Ephem
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(clerk-js,shared): Attach an optional server-configured session token to sign-in - #9630

Open
zourzouvillys wants to merge 5 commits into
release/core-2from
theo/protect-session-token-v5
Open

feat(clerk-js,shared): Attach an optional server-configured session token to sign-in#9630
zourzouvillys wants to merge 5 commits into
release/core-2from
theo/protect-session-token-v5

Conversation

@zourzouvillys

@zourzouvillyszourzouvillys commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Backport of #9299 to Core 2.

It also carries the request-params plumbing in fapiClient that #9313 introduced on main, but not the application-supplied assertion API that PR added — Core 2 gets the server-configured session token only. That is why the clerk.ts wiring here is one line, where main needs a resolver to union two sources.

#9527 (the verification load timeout) is deliberately out of scope: it bounds the protect-check gate, which does not exist on Core 2.

Notes for reviewers

  • vitest.setup.mts — the shared browser-tabs-lock mock is now a plain class instead of vi.fn(). Core 2 is on vitest 3, where vi.restoreAllMocks() strips vi.fn() implementations; vitest 4 on main no longer does. The ported suites call restoreAllMocks() in afterEach, so under vitest 3 every test after the first in a file got a lock that resolved undefined and silently acquired nothing.
  • Bundlewatch budgets are measured against a Core 2 baseline build, not copied from main (whose entry-bundle list is different). Measured deltas, gzip: clerk.js +2.02KB, clerk.browser.js +2.56KB, clerk.legacy.browser.js +3.11KB, clerk.headless*.js +2.57KB. ui-common, vendors and coinbase are unchanged.
  • clerk.protect-params.test.ts is rewritten rather than cherry-picked — upstream it exists to pin the union of two features, and only one of them exists here.

Verification

CommandResult
vitest run (protect, protectSession, protect-params, fapiClient)114 passed, 1 skipped, 4 todo
vitest run (full clerk-js)2459 passed, 10 skipped, 17 todo, 167 files
vitest run (@clerk/shared)647 passed, 43 files
pnpm run build (clerk-js)rspack + declarations clean, RHC check passed
pnpm run lint (clerk-js)0 errors (480 pre-existing warnings)

The same four protect suites were run against origin/main in a scratch worktree to confirm the vitest-3 lock behaviour was Core 2 specific and not a fault in the ported code — 11/11 there.

Risk

Inert for any instance whose environment carries no protect_config.loaders: no storage is written, no element is injected, and sign-in and sign-up bodies are byte-for-byte unchanged.

CI

Everything this change can affect is green, and the two red integration shards are fixed here. Two checks stay red for reasons no pull request can reach:

CheckWhy it cannot be fixed from a branch
Analyze (rust)CodeQL reports "could not process any code written in Rust" — Core 2 contains no Rust at all (main has five files). Neither branch has a CodeQL workflow or config, so this is default setup configured in repository settings, which govern main too. It fails on every push to release/core-2 itself, with no PR involved, going back to July.
Vercel – swingsetpackages/swingset does not exist on Core 2 (174 files on main, none here), so the project has nothing to build. The only vercel.json in the tree belongs to clerk-js; the swingset project is configured in Vercel, not in the repo.

Both fail identically on #9327, #9248 and #9224 — the last three PRs merged into this branch — so this branch has merged with them red three times. Making them green needs a repository-settings and Vercel-project change, which is a maintainer decision and deliberately not attempted here.

The two integration shards that were red are fixed:

  • Integration Tests (nextjs, chrome, 16)session-tasks-multi-session.test.ts signs the first user back in as its third step, and failed on a disabled password field and a popover that never detached. main replaced that re-sign-in with a session switch plus a delay in fix(repo): fixes multi session switching test #7402, naming a backend rate limit on session touch as the cause, and the fix was never backported. Backported here, so the file now matches main apart from the unrelated createFakeUser(test) from feat(e2e): persist test IDs in created user metadata #9374.
  • Integration Tests (machine, chrome) and (…, RQ) — one case in m2m.test.ts asserts that a token minted after createScope is accepted, and it comes back 401. main deleted this whole file when it refactored machine auth per framework in chore(repo): refactor machine auth tests for Next.js and Astro #8124 and kept createScope coverage only in packages/backend's unit tests, so there is no updated integration test to backport. The single case is marked test.skip with that reasoning inline, rather than deleted, so the assertion stays on record. Reviewers: this is the one change here that is not Protect work — say the word and I will drop it and let the shard stay red instead.

Neither red shard was a symptom of the session-token work. The nextjs shard passed on this branch on runtime-identical code before it failed, 126 of its 127 tests passed including many sign-in flows, and main runs the same protectSession code through two sign-ins in that same test without trouble. The m2m case exercises a backend token-verification path this diff does not touch, and predates it on every merged PR above.

Unit Tests (22, **), Integration Tests (sessions:staging, chrome) and Integration Tests (generic, chrome) each failed once and pass on re-run: a 5s timeout in clerk.test.ts's fake-timer poller test, which is untouched here and passed 109/109 on three consecutive local runs of the full file; a waitForFunction timeout in the production-instance cookie test; and a sign-in component that did not mount in impersonation-flow.test.ts.

@changeset-bot

changeset-botBot commented Sep 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: cfe2517

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 22 packages
NameType
@clerk/clerk-jsMinor
@clerk/sharedMinor
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/elementsPatch
@clerk/expo-passkeysPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/clerk-reactPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/themesPatch
@clerk/typesPatch
@clerk/vuePatch
@clerk/localizationsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Sep 1, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated
clerk-js-sandboxReadyReadyPreviewSep 1, 2026 11:37am UTC
swingsetErrorErrorSep 1, 2026 11:37am UTC

Request Review

@coderabbitai

coderabbitaiBot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Team

Run ID: 1912d6d8-704e-4570-8c1f-328b7d391a02

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@zourzouvillyszourzouvillys changed the title feat(clerk-js,shared): attach an optional server-configured session token to sign-in (Core 2)feat(clerk-js,shared): attach an optional server-configured session token to sign-inSep 1, 2026
@pkg-pr-new

pkg-pr-newBot commented Sep 1, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@9630

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9630

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9630

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9630

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9630

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@9630

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@9630

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@9630

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9630

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9630

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9630

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9630

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9630

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9630

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@9630

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9630

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@9630

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9630

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9630

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9630

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@9630

@clerk/types

npm i https://pkg.pr.new/@clerk/types@9630

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9630

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9630

commit: cfe2517

@zourzouvillyszourzouvillys changed the title feat(clerk-js,shared): attach an optional server-configured session token to sign-infeat(clerk-js,shared): Attach an optional server-configured session token to sign-inSep 1, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@zourzouvillys@Ephem
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(clerk-js,shared): Attach an optional server-configured session token to sign-in - #9630

Open
zourzouvillys wants to merge 5 commits into
release/core-2from
theo/protect-session-token-v5
Open

feat(clerk-js,shared): Attach an optional server-configured session token to sign-in#9630
zourzouvillys wants to merge 5 commits into
release/core-2from
theo/protect-session-token-v5

Conversation

@zourzouvillys

@zourzouvillyszourzouvillys commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Backport of #9299 to Core 2.

It also carries the request-params plumbing in fapiClient that #9313 introduced on main, but not the application-supplied assertion API that PR added — Core 2 gets the server-configured session token only. That is why the clerk.ts wiring here is one line, where main needs a resolver to union two sources.

#9527 (the verification load timeout) is deliberately out of scope: it bounds the protect-check gate, which does not exist on Core 2.

Notes for reviewers

  • vitest.setup.mts — the shared browser-tabs-lock mock is now a plain class instead of vi.fn(). Core 2 is on vitest 3, where vi.restoreAllMocks() strips vi.fn() implementations; vitest 4 on main no longer does. The ported suites call restoreAllMocks() in afterEach, so under vitest 3 every test after the first in a file got a lock that resolved undefined and silently acquired nothing.
  • Bundlewatch budgets are measured against a Core 2 baseline build, not copied from main (whose entry-bundle list is different). Measured deltas, gzip: clerk.js +2.02KB, clerk.browser.js +2.56KB, clerk.legacy.browser.js +3.11KB, clerk.headless*.js +2.57KB. ui-common, vendors and coinbase are unchanged.
  • clerk.protect-params.test.ts is rewritten rather than cherry-picked — upstream it exists to pin the union of two features, and only one of them exists here.

Verification

CommandResult
vitest run (protect, protectSession, protect-params, fapiClient)114 passed, 1 skipped, 4 todo
vitest run (full clerk-js)2459 passed, 10 skipped, 17 todo, 167 files
vitest run (@clerk/shared)647 passed, 43 files
pnpm run build (clerk-js)rspack + declarations clean, RHC check passed
pnpm run lint (clerk-js)0 errors (480 pre-existing warnings)

The same four protect suites were run against origin/main in a scratch worktree to confirm the vitest-3 lock behaviour was Core 2 specific and not a fault in the ported code — 11/11 there.

Risk

Inert for any instance whose environment carries no protect_config.loaders: no storage is written, no element is injected, and sign-in and sign-up bodies are byte-for-byte unchanged.

CI

Everything this change can affect is green, and the two red integration shards are fixed here. Two checks stay red for reasons no pull request can reach:

CheckWhy it cannot be fixed from a branch
Analyze (rust)CodeQL reports "could not process any code written in Rust" — Core 2 contains no Rust at all (main has five files). Neither branch has a CodeQL workflow or config, so this is default setup configured in repository settings, which govern main too. It fails on every push to release/core-2 itself, with no PR involved, going back to July.
Vercel – swingsetpackages/swingset does not exist on Core 2 (174 files on main, none here), so the project has nothing to build. The only vercel.json in the tree belongs to clerk-js; the swingset project is configured in Vercel, not in the repo.

Both fail identically on #9327, #9248 and #9224 — the last three PRs merged into this branch — so this branch has merged with them red three times. Making them green needs a repository-settings and Vercel-project change, which is a maintainer decision and deliberately not attempted here.

The two integration shards that were red are fixed:

  • Integration Tests (nextjs, chrome, 16)session-tasks-multi-session.test.ts signs the first user back in as its third step, and failed on a disabled password field and a popover that never detached. main replaced that re-sign-in with a session switch plus a delay in fix(repo): fixes multi session switching test #7402, naming a backend rate limit on session touch as the cause, and the fix was never backported. Backported here, so the file now matches main apart from the unrelated createFakeUser(test) from feat(e2e): persist test IDs in created user metadata #9374.
  • Integration Tests (machine, chrome) and (…, RQ) — one case in m2m.test.ts asserts that a token minted after createScope is accepted, and it comes back 401. main deleted this whole file when it refactored machine auth per framework in chore(repo): refactor machine auth tests for Next.js and Astro #8124 and kept createScope coverage only in packages/backend's unit tests, so there is no updated integration test to backport. The single case is marked test.skip with that reasoning inline, rather than deleted, so the assertion stays on record. Reviewers: this is the one change here that is not Protect work — say the word and I will drop it and let the shard stay red instead.

Neither red shard was a symptom of the session-token work. The nextjs shard passed on this branch on runtime-identical code before it failed, 126 of its 127 tests passed including many sign-in flows, and main runs the same protectSession code through two sign-ins in that same test without trouble. The m2m case exercises a backend token-verification path this diff does not touch, and predates it on every merged PR above.

Unit Tests (22, **), Integration Tests (sessions:staging, chrome) and Integration Tests (generic, chrome) each failed once and pass on re-run: a 5s timeout in clerk.test.ts's fake-timer poller test, which is untouched here and passed 109/109 on three consecutive local runs of the full file; a waitForFunction timeout in the production-instance cookie test; and a sign-in component that did not mount in impersonation-flow.test.ts.

@changeset-bot

changeset-botBot commented Sep 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: cfe2517

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 22 packages
NameType
@clerk/clerk-jsMinor
@clerk/sharedMinor
@clerk/chrome-extensionPatch
@clerk/clerk-expoPatch
@clerk/agent-toolkitPatch
@clerk/astroPatch
@clerk/backendPatch
@clerk/elementsPatch
@clerk/expo-passkeysPatch
@clerk/expressPatch
@clerk/fastifyPatch
@clerk/nextjsPatch
@clerk/nuxtPatch
@clerk/react-routerPatch
@clerk/clerk-reactPatch
@clerk/remixPatch
@clerk/tanstack-react-startPatch
@clerk/testingPatch
@clerk/themesPatch
@clerk/typesPatch
@clerk/vuePatch
@clerk/localizationsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Sep 1, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated
clerk-js-sandboxReadyReadyPreviewSep 1, 2026 11:37am UTC
swingsetErrorErrorSep 1, 2026 11:37am UTC

Request Review

@coderabbitai

coderabbitaiBot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Team

Run ID: 1912d6d8-704e-4570-8c1f-328b7d391a02

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@zourzouvillyszourzouvillys changed the title feat(clerk-js,shared): attach an optional server-configured session token to sign-in (Core 2)feat(clerk-js,shared): attach an optional server-configured session token to sign-inSep 1, 2026
@pkg-pr-new

pkg-pr-newBot commented Sep 1, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/agent-toolkit

npm i https://pkg.pr.new/@clerk/agent-toolkit@9630

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9630

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9630

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9630

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9630

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@9630

@clerk/elements

npm i https://pkg.pr.new/@clerk/elements@9630

@clerk/clerk-expo

npm i https://pkg.pr.new/@clerk/clerk-expo@9630

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9630

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9630

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9630

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9630

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9630

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9630

@clerk/clerk-react

npm i https://pkg.pr.new/@clerk/clerk-react@9630

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9630

@clerk/remix

npm i https://pkg.pr.new/@clerk/remix@9630

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9630

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9630

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9630

@clerk/themes

npm i https://pkg.pr.new/@clerk/themes@9630

@clerk/types

npm i https://pkg.pr.new/@clerk/types@9630

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9630

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9630

commit: cfe2517

@zourzouvillyszourzouvillys changed the title feat(clerk-js,shared): attach an optional server-configured session token to sign-infeat(clerk-js,shared): Attach an optional server-configured session token to sign-inSep 1, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@zourzouvillys@Ephem