Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .changeset/keyless-leftover-cleanup.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
'@clerk/shared': minor
'@clerk/nextjs': patch
'@clerk/backend': minor
---

Remove leftover keyless-mode creation code now that no SDK mints keyless applications. `@clerk/shared/keyless` drops `resolveKeysWithKeylessFallback`, `getOrCreateKeys`, and related exports (internal APIs consumed only by Clerk SDKs); `@clerk/backend` removes the experimental `createAccountlessApplication` method; `@clerk/nextjs` deletes the unused keyless cookie reader and dead keyless middleware parameters, and logs a pointer to existing `.clerk/.tmp/keyless.json` keys when env keys are missing.
2 changes: 1 addition & 1 deletion integration/scripts/waitForServer.ts
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ type WaitForServerArgsType = {
acceptAnyResponse?: boolean;
};

// Poll a url until it returns a 200 status code
// Poll a url until it returns 2xx (or any HTTP response when acceptAnyResponse is set)
export const waitForServer = async (url: string, opts: WaitForServerArgsType) => {
const { log, delayInMs = 1000, maxAttempts = 20, shouldExit = () => false, acceptAnyResponse = false } = opts;
let attempts = 0;
Expand Down
100 changes: 1 addition & 99 deletions integration/testUtils/keylessHelpers.ts
Original file line number Diff line number Diff line change
@@ -1,8 +1,4 @@
import type { BrowserContext, Page } from '@playwright/test';
import { expect } from '@playwright/test';

import type { Application } from '../models/application';
import { createTestUtils } from './index';
import type { Page } from '@playwright/test';

/**
* Mocks the environment API call to return a claimed instance.
Expand All @@ -22,97 +18,3 @@ export const mockClaimedInstanceEnvironmentCall = async (page: Page): Promise<vo
await route.fulfill({ response, json: newJson });
});
};

/**
* Tests that the keyless popover can be toggled and the claim link opens the dashboard.
*/
export async function testToggleCollapsePopoverAndClaim({
page,
context,
app,
dashboardUrl,
framework,
}: {
page: Page;
context: BrowserContext;
app: Application;
dashboardUrl: string;
framework: string;
}): Promise<void> {
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();
await u.page.waitForClerkJsLoaded();
await u.po.expect.toBeSignedOut();

await u.po.keylessPopover.waitForMounted();

const claim = u.po.keylessPopover.promptsToClaim();

const href = await claim.getAttribute('href');
expect(href).toBeTruthy();

const claimUrl = new URL(href!);
expect(claimUrl.origin + '/').toBe(dashboardUrl);
expect(claimUrl.pathname).toBe('/apps/claim');
expect(claimUrl.searchParams.get('framework')).toBe(framework);
expect(claimUrl.searchParams.has('token')).toBe(true);
expect(claimUrl.searchParams.has('return_url')).toBe(true);
}

/**
* Tests that a claimed application with missing explicit keys shows the popover expanded
* with a prompt to get keys from the dashboard.
*/
export async function testClaimedAppWithMissingKeys({
page,
context,
app,
dashboardUrl,
}: {
page: Page;
context: BrowserContext;
app: Application;
dashboardUrl: string;
}): Promise<void> {
await mockClaimedInstanceEnvironmentCall(page);
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();
await u.page.waitForClerkJsLoaded();

await u.po.keylessPopover.waitForMounted();
expect(await u.po.keylessPopover.isExpanded()).toBe(true);
await expect(u.po.keylessPopover.promptToUseClaimedKeys()).toBeVisible();

const href = await u.po.keylessPopover.promptToUseClaimedKeys().getAttribute('href');
expect(href).toBeTruthy();
expect(href).toContain(dashboardUrl);
}

/**
* Tests that the keyless popover is removed after adding keys to .env and restarting the dev server.
*/
export async function testKeylessRemovedAfterEnvAndRestart({
page,
context,
app,
}: {
page: Page;
context: BrowserContext;
app: Application;
}): Promise<void> {
const u = createTestUtils({ app, page, context });
await u.page.goToAppHome();

await u.po.keylessPopover.waitForMounted();

// Copy keys from keyless.json to .env
await app.keylessToEnv();

// Restart the dev server to pick up new env vars (Vite doesn't hot-reload .env)
await app.restart();

await u.page.goToAppHome();

// Keyless popover should no longer be present since we now have explicit keys
await u.po.keylessPopover.waitForUnmounted();
}
Original file line number Diff line number Diff line change
Expand Up @@ -13,48 +13,6 @@ describe('AccountlessApplications', () => {
api_keys_url: 'https://dashboard.clerk.com/api-keys',
};

it('creates an accountless application with a source query parameter', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
});

server.use(
http.post('https://api.clerk.test/v1/accountless_applications', ({ request }) => {
const url = new URL(request.url);
expect(url.searchParams.get('source')).toBe('nextjs');
expect(request.headers.get('Clerk-API-Version')).toBeTruthy();
expect(request.headers.get('User-Agent')).toBe('@clerk/backend@0.0.0-test');

return HttpResponse.json(mockAccountlessApplication);
}),
);

const response = await apiClient.__experimental_accountlessApplications.createAccountlessApplication({
source: 'nextjs',
});

expect(response.publishableKey).toBe('pk_test_keyless');
});

it('creates an accountless application without a source query parameter when source is omitted', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
});

server.use(
http.post('https://api.clerk.test/v1/accountless_applications', ({ request }) => {
const url = new URL(request.url);
expect(url.searchParams.has('source')).toBe(false);

return HttpResponse.json(mockAccountlessApplication);
}),
);

const response = await apiClient.__experimental_accountlessApplications.createAccountlessApplication();

expect(response.publishableKey).toBe('pk_test_keyless');
});

it('completes accountless application onboarding with a source query parameter', async () => {
const apiClient = createBackendApiClient({
apiUrl: 'https://api.clerk.test',
Expand Down
12 changes: 0 additions & 12 deletions packages/backend/src/api/endpoints/AccountlessApplicationsAPI.ts
Original file line number Diff line number Diff line change
Expand Up @@ -10,18 +10,6 @@ type AccountlessApplicationParams = {
};

export class AccountlessApplicationAPI extends AbstractAPI {
public async createAccountlessApplication(params?: AccountlessApplicationParams): Promise<AccountlessApplication> {
const headerParams = params?.requestHeaders ? Object.fromEntries(params.requestHeaders.entries()) : undefined;
return this.request<AccountlessApplication>({
method: 'POST',
path: basePath,
headerParams,
queryParams: {
source: params?.source,
},
});
}

public async completeAccountlessApplicationOnboarding(
params?: AccountlessApplicationParams,
): Promise<AccountlessApplication> {
Expand Down
13 changes: 7 additions & 6 deletions packages/nextjs/src/app-router/server/ClerkProvider.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ import React, { Suspense } from 'react';
import { getDynamicAuthData } from '../../server/buildClerkProps';
import { errorThrower } from '../../server/errorThrower';
import type { NextClerkProviderProps } from '../../types';
import { canUseKeyless } from '../../utils/feature-flags';
import { mergeNextClerkPropsWithEnv } from '../../utils/mergeNextClerkPropsWithEnv';
import { ClientClerkProvider } from '../client/ClerkProvider';
import { DynamicClerkScripts } from './DynamicClerkScripts';
Expand Down Expand Up @@ -32,7 +33,7 @@ export async function ClerkProvider<TUi extends Ui = Ui>(
initialState: statePromiseOrValue as InitialState | undefined,
});

const { shouldRunAsKeyless, runningWithClaimedKeys } = await getKeylessStatus(propsWithEnvs);
const { runningWithClaimedKeys } = await getKeylessStatus(propsWithEnvs);

// When dynamic mode is enabled, render scripts in a Suspense boundary to isolate
// the nonce fetching (which calls headers()) from the rest of the page.
Expand All @@ -52,14 +53,14 @@ export async function ClerkProvider<TUi extends Ui = Ui>(
</Suspense>
) : undefined;

if (shouldRunAsKeyless) {
if (!propsWithEnvs.publishableKey) {
errorThrower.throwMissingPublishableKeyError();
}
if (canUseKeyless && !propsWithEnvs.publishableKey) {
errorThrower.throwMissingPublishableKeyError();
}

if (runningWithClaimedKeys) {
return (
<KeylessProvider
rest={propsWithEnvs}
runningWithClaimedKeys={runningWithClaimedKeys}
__internal_scriptsSlot={scriptsSlot}
>
{children}
Expand Down
85 changes: 33 additions & 52 deletions packages/nextjs/src/app-router/server/keyless-provider.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -11,40 +11,42 @@ import { deleteKeylessAction } from '../keyless-actions';
export async function getKeylessStatus(
params: Without<NextClerkProviderProps, '__internal_invokeMiddlewareOnAuthStateChange' | 'children'>,
) {
let [shouldRunAsKeyless, runningWithClaimedKeys, locallyStoredPublishableKey] = [false, false, ''];
if (canUseKeyless) {
locallyStoredPublishableKey = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys()?.publishableKey || '')
.catch(() => '');
if (!canUseKeyless) {
return { runningWithClaimedKeys: false };
}

runningWithClaimedKeys = Boolean(params.publishableKey) && params.publishableKey === locallyStoredPublishableKey;
shouldRunAsKeyless = !params.publishableKey || runningWithClaimedKeys;
const storedKeys = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys() ?? null)
.catch(() => null);
if (!storedKeys) {
return { runningWithClaimedKeys: false };
}

return {
shouldRunAsKeyless,
runningWithClaimedKeys,
};
if (!params.publishableKey) {
const { clerkDevelopmentCache } = await import('../../server/keyless-log-cache.js');
clerkDevelopmentCache?.log({
cacheKey: `${storedKeys.publishableKey}_stored`,
msg: `[Clerk]: Found existing keyless-mode keys in .clerk/.tmp/keyless.json. Copy the publishableKey and secretKey into .env.local (NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY / CLERK_SECRET_KEY) to keep using that application, or claim it at ${storedKeys.claimUrl}`,
});
return { runningWithClaimedKeys: false };
}

return { runningWithClaimedKeys: params.publishableKey === storedKeys.publishableKey };
}

type KeylessProviderProps = PropsWithChildren<{
rest: Without<NextClerkProviderProps, '__internal_invokeMiddlewareOnAuthStateChange' | 'children'>;
runningWithClaimedKeys: boolean;
__internal_scriptsSlot?: React.ReactNode;
}>;

export const KeylessProvider = async (props: KeylessProviderProps) => {
const { rest, runningWithClaimedKeys, __internal_scriptsSlot, children } = props;
const { rest, __internal_scriptsSlot, children } = props;

// Read-only: the SDK no longer mints keyless applications, it only reads claimed keys from disk.
const newOrReadKeys = await import('../../server/keyless-node.js')
const storedKeys = await import('../../server/keyless-node.js')
.then(mod => mod.keyless().readKeys() ?? null)
.catch(() => null);

const { clerkDevelopmentCache, createConfirmationMessage } = await import('../../server/keyless-log-cache.js');

if (!newOrReadKeys) {
// When case keyless should run, but keys are not available, then fallback to throwing for missing keys
if (!storedKeys) {
return (
<ClientClerkProvider
{...mergeNextClerkPropsWithEnv(rest)}
Expand All @@ -56,46 +58,25 @@ export const KeylessProvider = async (props: KeylessProviderProps) => {
);
}

const clientProvider = (
try {
const keylessService = await import('../../server/keyless-node.js').then(mod => mod.keyless());
const { completeClaimedOnboarding } = await import('@clerk/shared/keyless');
await completeClaimedOnboarding(storedKeys.publishableKey, keylessService);
} catch {
// noop
}

return (
<ClientClerkProvider
{...mergeNextClerkPropsWithEnv({
...rest,
publishableKey: newOrReadKeys.publishableKey,
__internal_keyless_claimKeylessApplicationUrl: newOrReadKeys.claimUrl,
__internal_keyless_copyInstanceKeysUrl: newOrReadKeys.apiKeysUrl,
// Explicitly use `null` instead of `undefined` here to avoid persisting `deleteKeylessAction` during merging of options.
__internal_keyless_dismissPrompt: runningWithClaimedKeys ? deleteKeylessAction : null,
__internal_keyless_claimKeylessApplicationUrl: storedKeys.claimUrl,
__internal_keyless_copyInstanceKeysUrl: storedKeys.apiKeysUrl,
__internal_keyless_dismissPrompt: deleteKeylessAction,
})}
__internal_scriptsSlot={__internal_scriptsSlot}
>
{children}
</ClientClerkProvider>
);

if (runningWithClaimedKeys) {
try {
const keylessService = await import('../../server/keyless-node.js').then(mod => mod.keyless());

/**
* Notifying the dashboard should run once. We are controlling this behaviour by caching the result of the request.
* If the request fails, it will be considered stale after 10 minutes, otherwise it is cached for 24 hours.
*/
await clerkDevelopmentCache?.run(() => keylessService.completeOnboarding(), {
cacheKey: `${newOrReadKeys.publishableKey}_complete`,
onSuccessStale: 24 * 60 * 60 * 1000, // 24 hours
});
} catch {
// noop
}

/**
* Notify developers.
*/
clerkDevelopmentCache?.log({
cacheKey: `${newOrReadKeys.publishableKey}_claimed`,
msg: createConfirmationMessage(),
});
}

return clientProvider;
};
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,7 @@ import type { NextFetchEvent } from 'next/server';
import { NextRequest } from 'next/server';
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest';

// The mock SHOULD exist before the imports: unlike clerkMiddleware.test.ts, keys are empty so the
// missing-key error path is reachable.
// The mock SHOULD exist before the imports. Keys are intentionally empty so the missing-key error path is reachable.
vi.mock(import('../constants.js'), async importOriginal => {
const actual = await importOriginal();
return {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,6 @@ const mockRequest = (params: MockRequestParams) => {
if (machineAuthObject) {
const encryptedData = encryptClerkRequestData(
{}, // requestData
{}, // keylessModeKeys
// @ts-expect-error - mock machine auth object
machineAuthObject,
);
Expand Down
1 change: 0 additions & 1 deletion packages/nextjs/src/server/clerkMiddleware.ts
Original file line number Diff line number Diff line change
Expand Up @@ -389,7 +389,6 @@ async function runHandlerWithRequestState({
handlerResult,
requestState,
resolvedParams,
{},
authObject.tokenType === 'session_token' ? null : makeAuthObjectSerializable(authObject),
);

Expand Down
9 changes: 2 additions & 7 deletions packages/nextjs/src/server/keyless-log-cache.ts
Original file line number Diff line number Diff line change
@@ -1,10 +1,5 @@
/**
* Re-export keyless development cache utilities from shared.
* Re-export the keyless development cache from shared.
* This maintains backward compatibility with existing imports.
*/
export {
clerkDevelopmentCache,
createClerkDevCache,
createConfirmationMessage,
createKeylessModeMessage,
} from '@clerk/shared/keyless';
export { clerkDevelopmentCache } from '@clerk/shared/keyless';
Loading
Loading