Skip to content

fix(expo): Sanitize stray hash fragment in SSO callback URL - #9272

Open
wobsoriano wants to merge 2 commits into
mainfrom
rob/remove-hash-rotating-token
Open

fix(expo): Sanitize stray hash fragment in SSO callback URL#9272
wobsoriano wants to merge 2 commits into
mainfrom
rob/remove-hash-rotating-token

Conversation

@wobsoriano

@wobsoriano wobsoriano commented Jul 29, 2026

Copy link
Copy Markdown
Member

Description

Native SSO sign-ins can fail with a 401 signed_out at the sign-in reload when the OAuth callback deep link carries a stray #. Some iOS redirect chains leave a fragment on the redirect URL, either literal or percent-encoded into the rotating_token_nonce value, so the nonce reaches FAPI as <nonce># and the exact-match check fails.

useSSO now extracts the nonce through a helper that strips fragments from the callback URL and trims a # and anything after it from the extracted value.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-bot Bot commented Jul 29, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: b0842c7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@clerk/expo Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercel Bot commented Jul 29, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
clerk-js-sandbox Ready Ready Preview, Comment Jul 29, 2026 6:10pm
swingset Ready Ready Preview, Comment Jul 29, 2026 6:10pm

Request Review

@github-actions

github-actions Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-29T18:10:40.235Z

Summary

Metric Count
Packages analyzed 19
Packages with changes 0
🔴 Breaking changes 0
🟡 Non-breaking changes 0
🟢 Additions 0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on b0842c7.

@pkg-pr-new

pkg-pr-new Bot commented Jul 29, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9272

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9272

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9272

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9272

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9272

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9272

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9272

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9272

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9272

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9272

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9272

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9272

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9272

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9272

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9272

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9272

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9272

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9272

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9272

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9272

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9272

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9272

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9272

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9272

commit: b0842c7

@coderabbitai

coderabbitai Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

Adds a shared callback URL parameter helper that removes stray or encoded hash fragments and handles invalid or missing parameters. Updates SSO, hosted authentication, and OAuth flows to use it for callback values, including rotating_token_nonce, while preserving existing validation and authentication handling. Adds tests for URL variants and failure cases, plus an Expo patch changeset.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • clerk/javascript#8960: Related hosted-auth callback parameter parsing changes in the same authentication flow.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main change: sanitizing stray hash fragments in Expo SSO callback URLs.
Description check ✅ Passed The description matches the changeset and accurately explains the SSO callback nonce sanitization fix.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Warning

Review ran into problems

🔥 Problems

Linked repositories: Couldn't analyze clerk/clerk-android - clone failed: Clone operation failed: Cloning into '/home/jailuser/git'...
From https://github.com/clerk/clerk-android

Errors logged to '/home/jailuser/git/.git/lfs/logs/20260729T181243.864989527.log'.
Use git lfs logs last to view the log.
error: external filter 'git-lfs filter-process' failed
fatal: config/bin/detekt-cli: smudge filter lfs failed
Downloading config/bin/detekt-cli (71 MB)
Error downloading object: config/bin/detekt-cli (2655f48): Smudge error: Error downloading config/bin/detekt-cli (2655f48c7c303a5f9bf920a33229408b8571bb1d29e4e57cf7be3e151bceecb1): LFS: Client error: https://github-cloud.githubusercontent.com/alambic/media/877189286/26/55/2655f48c7c303a5f9bf920a33229408b8571bb1d29e4e57cf7be3e151bceecb1?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIA5BA2674WPWWEFGQ5%2F20260729%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260729T181403Z&X-Amz-Expires=3600&X-Amz-Signature=351957cab6836ca5db3a8fa0653aea7de1c660144b2f664d014cb83c0f9e7d5d&X-Amz-SignedHeaders=host&actor_id=136622811&key_id=0&repo_id=980409545&token=1

Errors logged to '/home/jailuser/git/.git/lfs/logs/20260729T181403.276019622.log'.
Use git lfs logs last to view the log.
error: external filter 'git-lfs filter-process' failed
fatal: config/bin/detekt-cli: smudge filter lfs failed


Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/expo/src/hooks/useSSO.ts (1)

110-110: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add a hook-level regression test for nonce normalization.

The helper tests cover parsing, but they do not verify that useSSO passes the sanitized nonce to signIn.reload. Add a test in packages/expo/src/hooks/__tests__/useSSO.test.ts covering literal and encoded trailing # values and asserting rotatingTokenNonce: 'abc123'.

As per coding guidelines, tests should cover new functionality, error handling, and edge cases.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/expo/src/hooks/useSSO.ts` at line 110, Add a hook-level regression
test in useSSO tests that exercises the sign-in flow with both literal and
URL-encoded trailing # nonce values, then assert signIn.reload receives
rotatingTokenNonce: 'abc123'.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@packages/expo/src/hooks/useSSO.ts`:
- Line 110: Add a hook-level regression test in useSSO tests that exercises the
sign-in flow with both literal and URL-encoded trailing # nonce values, then
assert signIn.reload receives rotatingTokenNonce: 'abc123'.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: b9d360f3-c5be-4b18-868a-96298e535428

📥 Commits

Reviewing files that changed from the base of the PR and between a8f6e89 and 49b396e.

📒 Files selected for processing (4)
  • .changeset/expo-callback-nonce-hash.md
  • packages/expo/src/hooks/useSSO.ts
  • packages/expo/src/utils/__tests__/authSessionCallback.test.ts
  • packages/expo/src/utils/authSessionCallback.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go (manual)
  • clerk/dashboard (manual)
  • clerk/accounts (manual)
  • clerk/backoffice (manual)
  • clerk/clerk (manual)
  • clerk/clerk-docs (manual)
  • clerk/cloudflare-workers (manual)
  • clerk/cli (auto-detected)
  • clerk/clerk-ios (auto-detected)
  • clerk/clerk-android (auto-detected)

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@packages/expo/src/hooks/useOAuth.ts`:
- Around line 102-103: Update the OAuth callback flow around
getAuthSessionCallbackParam and signIn.reload to reject a null or otherwise
missing rotating token nonce before invoking reload. Remove the empty-string
fallback, fail locally using the existing error-handling behavior used for
invalid auth callback data, and only pass a validated nonce to signIn.reload.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 0a12bfbe-65d8-4461-a000-9c9267333518

📥 Commits

Reviewing files that changed from the base of the PR and between 49b396e and b0842c7.

📒 Files selected for processing (2)
  • packages/expo/src/hooks/useHostedAuth.ts
  • packages/expo/src/hooks/useOAuth.ts
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go (manual)
  • clerk/dashboard (manual)
  • clerk/accounts (manual)
  • clerk/backoffice (manual)
  • clerk/clerk (manual)
  • clerk/clerk-docs (manual)
  • clerk/cloudflare-workers (manual)
  • clerk/cli (auto-detected)
  • clerk/clerk-ios (auto-detected)
  • clerk/clerk-android (auto-detected)

Comment on lines +102 to 103
const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';
await signIn.reload({ rotatingTokenNonce });

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Reject missing or invalid nonces before reloading sign-in.

getAuthSessionCallbackParam returns null for malformed URLs or absent parameters, but || '' causes Line 103 to call signIn.reload({ rotatingTokenNonce: '' }). Fail locally, as hosted auth does, instead of forwarding an invalid nonce to FAPI.

Proposed fix
-    const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';
+    const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce');
+    if (!rotatingTokenNonce) {
+      return errorThrower.throw(
+        'OAuth callback did not include a rotating token nonce. Please restart the OAuth flow.',
+      );
+    }
     await signIn.reload({ rotatingTokenNonce });
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce') || '';
await signIn.reload({ rotatingTokenNonce });
const rotatingTokenNonce = getAuthSessionCallbackParam(url, 'rotating_token_nonce');
if (!rotatingTokenNonce) {
return errorThrower.throw(
'OAuth callback did not include a rotating token nonce. Please restart the OAuth flow.',
);
}
await signIn.reload({ rotatingTokenNonce });
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/expo/src/hooks/useOAuth.ts` around lines 102 - 103, Update the OAuth
callback flow around getAuthSessionCallbackParam and signIn.reload to reject a
null or otherwise missing rotating token nonce before invoking reload. Remove
the empty-string fallback, fail locally using the existing error-handling
behavior used for invalid auth callback data, and only pass a validated nonce to
signIn.reload.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants