Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .changeset/full-horses-repair.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
'@clerk/tanstack-react-start': patch
---

Fixed a bug where the `clerkMiddleware()` helper would consume the body of the request
9 changes: 5 additions & 4 deletions packages/tanstack-react-start/src/server/clerkMiddleware.ts
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
import type { RequestState } from '@clerk/backend/internal';
import { AuthStatus, constants } from '@clerk/backend/internal';
import { AuthStatus, constants, createClerkRequest } from '@clerk/backend/internal';
import { handleNetlifyCacheInDevInstance } from '@clerk/shared/netlifyCacheHandler';
import type { PendingSessionOptions } from '@clerk/types';
import type { AnyRequestMiddleware } from '@tanstack/react-start';
Expand All @@ -8,12 +8,13 @@ import { createMiddleware, json } from '@tanstack/react-start';
import { clerkClient } from './clerkClient';
import { loadOptions } from './loadOptions';
import type { ClerkMiddlewareOptions } from './types';
import { getResponseClerkState } from './utils';
import { getResponseClerkState, patchRequest } from './utils';

export const clerkMiddleware = (options?: ClerkMiddlewareOptions): AnyRequestMiddleware => {
return createMiddleware().server(async args => {
const loadedOptions = loadOptions(args.request, options);
const requestState = await clerkClient().authenticateRequest(args.request, {
const clerkRequest = createClerkRequest(patchRequest(args.request));
const loadedOptions = loadOptions(clerkRequest, options);
const requestState = await clerkClient().authenticateRequest(clerkRequest, {
...loadedOptions,
acceptsToken: 'any',
});
Expand Down
10 changes: 4 additions & 6 deletions packages/tanstack-react-start/src/server/loadOptions.ts
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
import { createClerkRequest } from '@clerk/backend/internal';
import type { ClerkRequest } from '@clerk/backend/internal';
import { apiUrlFromPublishableKey } from '@clerk/shared/apiUrlFromPublishableKey';
import { getEnvVariable } from '@clerk/shared/getEnvVariable';
import { isDevelopmentFromSecretKey } from '@clerk/shared/keys';
Expand All @@ -9,10 +9,8 @@ import { errorThrower } from '../utils';
import { getPublicEnvVariables } from '../utils/env';
import { commonEnvs } from './constants';
import type { LoaderOptions } from './types';
import { patchRequest } from './utils';

export const loadOptions = (request: Request, overrides: LoaderOptions = {}) => {
const clerkRequest = createClerkRequest(patchRequest(request));
export const loadOptions = (request: ClerkRequest, overrides: LoaderOptions = {}) => {
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion | 🟠 Major

Add explicit return type annotation.

The function signature lacks an explicit return type. Per coding guidelines, public APIs should have explicit return types for clarity and to prevent unintended type widening.

As per coding guidelines.

Apply this diff:

-export const loadOptions = (request: ClerkRequest, overrides: LoaderOptions = {}) => {
+export const loadOptions = (request: ClerkRequest, overrides: LoaderOptions = {}): ReturnType<typeof loadOptions> => {

Alternatively, define an explicit interface for the return type:

interface LoadOptionsResult {
  secretKey: string;
  machineSecretKey?: string;
  publishableKey: string;
  jwtKey?: string;
  apiUrl: string;
  domain: string;
  isSatellite: boolean;
  proxyUrl?: string;
  signInUrl: string;
  signUpUrl: string;
  afterSignInUrl: string;
  afterSignUpUrl: string;
  // ... other properties from overrides
}

export const loadOptions = (request: ClerkRequest, overrides: LoaderOptions = {}): LoadOptionsResult => {

Note: This change from Request to ClerkRequest is a breaking API change. Ensure this is documented in the changeset.

const commonEnv = commonEnvs();
const secretKey = overrides.secretKey || commonEnv.SECRET_KEY;
const machineSecretKey = overrides.machineSecretKey || commonEnv.MACHINE_SECRET_KEY;
Expand All @@ -21,15 +19,15 @@ export const loadOptions = (request: Request, overrides: LoaderOptions = {}) =>
const apiUrl = getEnvVariable('CLERK_API_URL') || apiUrlFromPublishableKey(publishableKey);
const domain = handleValueOrFn(overrides.domain, new URL(request.url)) || commonEnv.DOMAIN;
const isSatellite = handleValueOrFn(overrides.isSatellite, new URL(request.url)) || commonEnv.IS_SATELLITE;
const relativeOrAbsoluteProxyUrl = handleValueOrFn(overrides?.proxyUrl, clerkRequest.clerkUrl, commonEnv.PROXY_URL);
const relativeOrAbsoluteProxyUrl = handleValueOrFn(overrides?.proxyUrl, request.clerkUrl, commonEnv.PROXY_URL);
const signInUrl = overrides.signInUrl || commonEnv.SIGN_IN_URL;
const signUpUrl = overrides.signUpUrl || commonEnv.SIGN_UP_URL;
const afterSignInUrl = overrides.afterSignInUrl || getPublicEnvVariables().afterSignInUrl;
const afterSignUpUrl = overrides.afterSignUpUrl || getPublicEnvVariables().afterSignUpUrl;

let proxyUrl;
if (!!relativeOrAbsoluteProxyUrl && isProxyUrlRelative(relativeOrAbsoluteProxyUrl)) {
proxyUrl = new URL(relativeOrAbsoluteProxyUrl, clerkRequest.clerkUrl).toString();
proxyUrl = new URL(relativeOrAbsoluteProxyUrl, request.clerkUrl).toString();
} else {
proxyUrl = relativeOrAbsoluteProxyUrl;
}
Expand Down
Loading