Skip to content

fix(ui): continue combined-flow SSO callbacks to sign-in steps - #10014

Merged
mwickett merged 5 commits into
mainfrom
mwickett/combined-flow-sso-callback-protect-check
Oct 1, 2026
Merged

mwickett merged 5 commits into
mainfrom
mwickett/combined-flow-sso-callback-protect-check

Conversation

@mwickett

@mwickett mwickett commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Description

In the combined sign-in-or-up flow, the OAuth/SAML callback navigated to URLs the component's own router could not reach. That sent users back to the start card mid-flow.

  • create/sso-callback, where combined-flow OAuth redirects land under path/hash routing, was built with buildSignUpOAuthCallbackParams. That builder carries no sign-in step URLs, so a callback resolving into needs_protect_check, needs_first_factor, needs_second_factor or needs_new_password fell back to displayConfig.signInUrl#/<step>.
  • When a sign-in turned into a sign-up, the root-level routes used the context's signUpContinueUrl / signUpProtectCheckUrl, which in the combined flow are <signInUrl>#/create/*. Those routes are sso-callback, where an OAuth redirect started from the modal lands on the sign-in page, and protect-check, when it resumes an OAuth transfer.

The SSO callback hands the component router's navigate to the handler, so a hash-form URL becomes an internal navigation to the SignIn index: BaseRouter installs the pathname and ignores the fragment, and PathRouter converts hashes only in its own effect. The start card mounts and can replace the in-flight sign-in before the intended step renders. With passkey autofill it immediately creates a new passkey sign-in, and its OAuth-error handling resets the attempt with signIn.create({}).

This shows up when a Protect check gates an OAuth sign-in. The challenged create still returns the provider redirect, so the user completes Google and lands back on the callback. They are then sent to the start card, solve a check for a new passkey sign-in, tap Google again, and loop. The OAuth sign-in's own check never runs. FAPI logs for an affected session show a new POST /v1/client/sign_ins (strategy passkey) about 1.4s after each oauth_callback 303, and no protect_check PATCH on the OAuth sign-in.

Changes:

  • One place builds the combined-flow sign-up step URLs. signUpStepUrls(prefix) produces continue / verify-email-address / verify-phone-number / protect-check for a route depth. It is used by buildSignInOAuthCallbackParams (../create/), the transport builder (create/), buildSignUpOAuthCallbackParams (../), buildSignUpOAuthTransportCallbackParams ('') and handleSignUpIfMissingTransfer (../create/).
  • buildSignInOAuthCallbackParams branches on isCombinedFlow. sso-callback and protect-check are siblings at the SignIn root, so the same ../create/* URLs serve the root callback route and SignInProtectCheck's transfer resume. Separate sign-in/sign-up setups are unchanged.
  • create/sso-callback uses buildCombinedFlowOAuthCallbackParams. It takes the sign-up step URLs plus the sign-in steps one level further up: ../../protect-check, ../../factor-one, ../../factor-two, ../../reset-password.
  • Two comments that described the hash-form context URLs as depth-independent are corrected.

The web3 callers (SignInSocialButtons, SignInFactorOneSolanaWalletsCard) still pick their own create/* URLs, because authenticateWithWeb3 takes a differently named parameter set. The root cause is that the context's combined-flow URLs are hash-form. Fixing that at the context level would remove every override, but is larger than this PR.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-bot Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: a879076

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
Name Type
@clerk/ui Patch
@clerk/chrome-extension Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
clerk-js-sandbox Ready Ready Preview Oct 1, 2026 7:46pm UTC
swingset Ready Ready Preview Oct 1, 2026 7:46pm UTC

Request Review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T14:12:05.354512Z b422e2e PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions github-actions Bot added the ui label Oct 1, 2026
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Team

Run ID: 20cf5e40-0228-4dc3-a568-7d4cee7b75c7

📥 Commits

Reviewing files that changed from the base of the PR and between d3e0d06 and a879076.

📒 Files selected for processing (1)
  • .changeset/combined-flow-sso-callback-sign-in-steps.md
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

Included review availability: This review used your included allowance. 8 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 10 reviews per hour.


📝 Walkthrough

Walkthrough

The combined-flow SSO callback now uses callback parameters with relative sign-in and sign-up step URLs. The transfer handler uses a shared helper to build sign-up step URLs. Tests cover callback navigation across routing modes and Protect-check outcomes, including session activation, second-factor navigation, and continuation to an embedded sign-up route.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Merge Risk: ⚪ Minimal · up to a8790

The callback destinations resolve to the intended combined-flow steps within the mounted SignIn component. No actionable merge-blocking issue is identified.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 12.50% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 8 functions across 9 files. (1 skipped: 1… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly and concisely identifies the main change: continuing combined-flow SSO callbacks to the correct sign-in steps.
Description check ✅ Passed The description directly explains the combined-flow SSO callback routing bug, its user impact, and the implemented routing changes.
Full details: Docstring Coverage

Explanation

Docstring coverage is 12.50% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 8 functions across 9 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@10014

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@10014

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@10014

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@10014

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@10014

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@10014

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@10014

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@10014

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@10014

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@10014

@clerk/express

npm i https://pkg.pr.new/@clerk/express@10014

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@10014

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@10014

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@10014

@clerk/mosaic

npm i https://pkg.pr.new/@clerk/mosaic@10014

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@10014

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@10014

@clerk/react

npm i https://pkg.pr.new/@clerk/react@10014

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@10014

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@10014

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@10014

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@10014

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@10014

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@10014

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@10014

commit: a879076

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-10-01T19:47:34.167Z

Summary

Metric Count
Packages analyzed 19
Packages with changes 0
🔴 Breaking changes 0
🟡 Non-breaking changes 0
🟢 Additions 0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on a879076.

@mwickett
mwickett merged commit 7412289 into main Oct 1, 2026
53 checks passed
@mwickett
mwickett deleted the mwickett/combined-flow-sso-callback-protect-check branch October 1, 2026 20:53

This branch was successfully deployed

2 active deployments
Preview – swingset — a879076a Deployed Oct 1, 2026 by vercel[bot]
Preview – clerk-js-sandbox — a879076a Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants