Skip to content

fix(electron,ui): Don't run passkey autofill as a modal prompt - #9500

Merged
jeremy-clerk merged 1 commit into
mainfrom
jw/fix-native-passkey-conditional
Aug 19, 2026
Merged

fix(electron,ui): Don't run passkey autofill as a modal prompt#9500
jeremy-clerk merged 1 commit into
mainfrom
jw/fix-native-passkey-conditional

Conversation

@jeremy-clerk

Copy link
Copy Markdown
Contributor

Description

The Electron passkey provider reported autofill as supported but serviced the request as a modal ceremony, so an OS passkey sheet opened as soon as the sign-in form mounted, before user intent. On custom-scheme windows the same probe would fail with passkey_not_supported.

  • get() honors conditionalUI instead of hardcoding to false, so the renderer path performs conditional mediation. A conditional request that would resolve to the native or unsupported path is aborted and doesn't fall back to the native path.
  • isSupported() and isAutoFillSupported() go through the same routing rules as decidePath() & they stop advertising capabilities the resolved path cannot deliver.
  • SignInStart resolves both WebAuthn predicates against the Clerk instance before falling back to the shared helpers, so a host-provided passkey provider can influence whether the autofill flow starts at all.

Signing in with the “Use passkey” button/action is unchanged.

@clerk/electron alone does not fix the reported behaviour, the gate that starts the flow lives in @clerk/ui.

Fixes #9496

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

The Electron passkey provider reported autofill as supported but serviced the
request as a modal ceremony, so an OS passkey sheet opened as soon as the sign-in
form mounted, before any user intent.

- `get()` now honours `conditionalUI` instead of hardcoding it to `false`, so the
  renderer path performs real conditional mediation. When a conditional request
  would resolve to the native or unsupported path it is quietly aborted rather
  than prompting, and it no longer falls back to the native path on error.
- `isSupported()` and `isAutoFillSupported()` now answer through the same routing
  rules as `decidePath()`, so they stop advertising capabilities the resolved path
  cannot deliver.
- `SignInStart` resolves both WebAuthn predicates against the Clerk instance
  before falling back to the shared helpers, so a host-provided passkey provider
  can influence whether the autofill flow starts at all.

Closes #9496
@vercel

vercel Bot commented Aug 19, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
clerk-js-sandbox Ready Ready Preview Aug 19, 2026 4:44am
swingset Ready Ready Preview Aug 19, 2026 4:44am

Request Review

@changeset-bot

changeset-bot Bot commented Aug 19, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 70a6432

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 4 packages
Name Type
@clerk/electron Patch
@clerk/ui Patch
@clerk/chrome-extension Patch
@clerk/swingset Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions github-actions Bot added the ui label Aug 19, 2026
@pkg-pr-new

pkg-pr-new Bot commented Aug 19, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9500

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9500

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9500

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9500

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9500

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9500

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9500

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9500

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9500

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9500

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9500

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9500

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9500

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9500

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9500

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9500

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9500

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9500

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9500

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9500

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9500

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9500

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9500

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9500

commit: 70a6432

@coderabbitai

coderabbitai Bot commented Aug 19, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 82aa3ae6-9c4a-44ee-b7d8-a0c507adb29d

📥 Commits

Reviewing files that changed from the base of the PR and between 72ffc81 and 70a6432.

📒 Files selected for processing (8)
  • .changeset/rude-pianos-smoke.md
  • packages/electron/README.md
  • packages/electron/src/passkeys/__tests__/index.test.ts
  • packages/electron/src/passkeys/__tests__/strategy.test.ts
  • packages/electron/src/passkeys/index.ts
  • packages/electron/src/passkeys/renderer/strategy.ts
  • packages/ui/src/components/SignIn/SignInStart.tsx
  • packages/ui/src/components/SignIn/__tests__/SignInStart.test.tsx
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go (manual)
  • clerk/dashboard (manual)
  • clerk/accounts (manual)
  • clerk/backoffice (manual)
  • clerk/clerk (manual)
  • clerk/clerk-docs (manual)
  • clerk/cloudflare-workers (manual)
  • clerk/clerk-ios (auto-detected)
  • clerk/cli (auto-detected)
  • clerk/clerk-android (auto-detected)

Included review availability: 5 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 6 reviews per hour.


📝 Walkthrough

Walkthrough

Electron passkey routing now supports conditional renderer requests and aborts conditional requests when only native routing is available. Renderer eligibility accounts for mode, origin, WebAuthn support, and legacy macOS Electron versions. Autofill support checks are asynchronous and require an eligible renderer path. Sign-in detection uses Clerk’s internal WebAuthn support APIs when available. Tests and documentation cover the updated behavior.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Merge Risk: ⚪ Minimal · up to 70a64

The change updates passkey autofill routing so it waits for user intent while preserving explicit passkey sign-in behavior. No actionable merge-blocking risk remains beyond normal checks and review.

Possibly related issues

  • clerk/javascript issue 9265 — Both changes update SignInStart passkey autofill handling and prevent unsupported autofill attempts.

Suggested reviewers: wobsoriano

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the Electron and UI fix that prevents passkey autofill from opening a modal prompt.
Description check ✅ Passed The description accurately explains the modal autofill bug, routing changes, capability checks, UI changes, and preserved explicit sign-in behavior.
Linked Issues check ✅ Passed The changes address issue #9496 by enabling conditional mediation, preventing invalid fallbacks, aligning capability checks, and preserving explicit passkey sign-in.
Out of Scope Changes check ✅ Passed The changes remain within scope and include related implementation, tests, documentation, and release metadata for the passkey autofill fix.

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-08-19T04:49:30.290Z

Summary

Metric Count
Packages analyzed 19
Packages with changes 0
🔴 Breaking changes 0
🟡 Non-breaking changes 0
🟢 Additions 0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 70a6432.

@jeremy-clerk
jeremy-clerk merged commit a52d486 into main Aug 19, 2026
84 of 85 checks passed
@jeremy-clerk
jeremy-clerk deleted the jw/fix-native-passkey-conditional branch August 19, 2026 05:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[@clerk/electron] Passkey autofill runs as a modal prompt: OS passkey dialog opens as soon as sign-in mounts

2 participants