Skip to content

feat(ui): remove experimental gate from self-serve OIDC flow - #9288

Merged
NicolasLopes7 merged 5 commits into
mainfrom
nicolas/remove-oidc-self-serve-flag
Jul 31, 2026
Merged

feat(ui): remove experimental gate from self-serve OIDC flow#9288
NicolasLopes7 merged 5 commits into
mainfrom
nicolas/remove-oidc-self-serve-flag

Conversation

@NicolasLopes7

Copy link
Copy Markdown
Contributor

Description

Removes the experimental.oidcSelfServe gate now that the self-serve OIDC flow is complete.

Behaviour changes for applications that never set the option:

  • The OpenID Connect (OIDC) group appears in the <OrganizationProfile /> Security tab provider picker.
  • An existing OIDC connection (oauth_custom_<slug> / oidc_*) resolves to OidcCustomConfigureSteps instead of degrading to the unsupported-provider state.

resolveConfigureSteps drops its second parameter, ConfigureSSOData drops isOIDCFlowEnabled, and ClerkOptions['experimental'] drops oidcSelfServe. The option was declared inside an Autocomplete<..., Record<string, any>>, so applications still passing it keep type-checking; it is now inert.

The unsupported-provider fallback stays for provider families a given SDK version doesn't recognise.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@vercel

vercel Bot commented Jul 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
clerk-js-sandbox Ready Ready Preview Jul 30, 2026 11:41pm
swingset Ready Ready Preview Jul 30, 2026 11:41pm

Request Review

@pkg-pr-new

pkg-pr-new Bot commented Jul 30, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9288

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9288

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9288

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9288

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9288

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9288

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9288

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9288

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9288

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9288

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9288

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9288

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9288

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9288

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9288

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9288

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9288

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9288

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9288

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9288

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9288

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9288

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9288

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9288

commit: abfbac2

@NicolasLopes7
NicolasLopes7 marked this pull request as ready for review July 30, 2026 16:18
@changeset-bot

changeset-bot Bot commented Jul 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: abfbac2

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 23 packages
Name Type
@clerk/clerk-js Patch
@clerk/shared Patch
@clerk/ui Patch
@clerk/chrome-extension Patch
@clerk/electron Patch
@clerk/expo Patch
@clerk/astro Patch
@clerk/backend Patch
@clerk/expo-passkeys Patch
@clerk/express Patch
@clerk/fastify Patch
@clerk/headless Patch
@clerk/hono Patch
@clerk/localizations Patch
@clerk/msw Patch
@clerk/nextjs Patch
@clerk/nuxt Patch
@clerk/react-router Patch
@clerk/react Patch
@clerk/tanstack-react-start Patch
@clerk/testing Patch
@clerk/vue Patch
@clerk/swingset Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitai Bot commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 4f7aad20-eb01-430a-a060-0ad97f306bfe

📥 Commits

Reviewing files that changed from the base of the PR and between b32efd1 and 558c427.

📒 Files selected for processing (1)
  • packages/ui/src/components/ConfigureSSO/steps/__tests__/SelectProviderStep.test.tsx
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go (manual)
  • clerk/dashboard (manual)
  • clerk/accounts (manual)
  • clerk/backoffice (manual)
  • clerk/clerk (manual)
  • clerk/clerk-docs (manual)
  • clerk/cloudflare-workers (manual)
  • clerk/clerk-ios (auto-detected)
  • clerk/clerk-android (auto-detected)
  • clerk/cli (auto-detected)

📝 Walkthrough

Walkthrough

Self-serve OIDC configuration is enabled for all applications. The experimental oidcSelfServe option and context flag were removed, OIDC provider selection is unconditional, and OIDC connections route directly to configuration steps. Tests and changeset documentation were updated, and the experimental options type now includes runtimeEnvironment: 'headless'.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers: gabrielmeloc22, iagodahlem, laurabeatris

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly matches the main change: removing the experimental gate from the self-serve OIDC flow.
Description check ✅ Passed The description is directly aligned with the PR changes and accurately summarizes the OIDC flow gate removal.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-30T23:41:51.674Z

Summary

Metric Count
Packages analyzed 19
Packages with changes 1
🔴 Breaking changes 0
🟡 Non-breaking changes 1
🟢 Additions 0

🤖 This report was reviewed by claude-sonnet-4-6.


@clerk/shared

Current version: 4.25.9
Recommended bump: MINOR → 4.26.0

Subpath ./types

🟡 Non-breaking Changes (1)

Modified: ClerkOptions
// ... 26 unchanged lines elided ...
      rethrowOfflineNetworkErrors: boolean;
      commerce: boolean;
      runtimeEnvironment: 'headless';
-     oidcSelfServe: boolean;
    }, Record<string, any>>;
    __internal_keyless_claimKeylessApplicationUrl?: string;
    __internal_keyless_copyInstanceKeysUrl?: string;
// ... 4 unchanged lines elided ...

Static analyzer: Breaking change in type alias ClerkOptions: Type changed: import("@clerk/shared").AfterMultiSessionSingleSignOutUrl&import("@clerk/shared").AfterSignOutUrl&import("@clerk/shared…import("@clerk/shared").AfterMultiSessionSingleSignOutUrl&import("@clerk/shared").AfterSignOutUrl&import("@clerk/shared…

🤖 AI review (reclassified as non-breaking) (85%): The only difference is the removal of oidcSelfServe: boolean from the experimental property's Autocomplete<{...}, Record<string, any>> type. Per rule 14, Autocomplete<X, Record<string, any>> is a LiteralUnion-style type where Record<string, any> (an absorbing arm) already accepts every object value including one with oidcSelfServe; removing a named key from the literal-hint arm does not change the assignable set for callers constructing or reading this value.


Report generated by Break Check

Last ran on abfbac2.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/ui/src/components/ConfigureSSO/steps/__tests__/SelectProviderStep.test.tsx (1)

108-114: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Use an accessible Testing Library query for the OIDC option.

container.querySelector('input[value="oidc_custom"]') couples the test to the DOM implementation and can pass even if the option is not exposed as an operable radio. Query the OIDC option by accessible role/name or label, matching the existing Okta assertion.

Suggested assertion
-    const { container } = renderStep(wrapper);
+    renderStep(wrapper);

-    expect(container.querySelector('input[value="oidc_custom"]')).toBeInTheDocument();
+    expect(screen.getByRole('radio', { name: /OIDC/i })).toBeInTheDocument();

As per coding guidelines, React Testing Library tests should use proper test queries.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@packages/ui/src/components/ConfigureSSO/steps/__tests__/SelectProviderStep.test.tsx`
around lines 108 - 114, Update the OIDC assertion in the renders OIDC provider
tile test to use an accessible Testing Library query, such as the radio role
with the option’s accessible name or its associated label, instead of
container.querySelector. Keep the existing Okta Workforce radio assertion
pattern and continue verifying the OIDC option is present and operable.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In
`@packages/ui/src/components/ConfigureSSO/steps/__tests__/SelectProviderStep.test.tsx`:
- Around line 108-114: Update the OIDC assertion in the renders OIDC provider
tile test to use an accessible Testing Library query, such as the radio role
with the option’s accessible name or its associated label, instead of
container.querySelector. Keep the existing Okta Workforce radio assertion
pattern and continue verifying the OIDC option is present and operable.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: d286f553-20da-46bb-b667-e73ccbaec498

📥 Commits

Reviewing files that changed from the base of the PR and between 9c51d74 and b32efd1.

📒 Files selected for processing (7)
  • .changeset/quiet-moons-shine.md
  • packages/shared/src/types/clerk.ts
  • packages/ui/src/components/ConfigureSSO/ConfigureSSOContext.tsx
  • packages/ui/src/components/ConfigureSSO/steps/ConfigureStep/__tests__/ConfigureStep.test.tsx
  • packages/ui/src/components/ConfigureSSO/steps/ConfigureStep/index.tsx
  • packages/ui/src/components/ConfigureSSO/steps/SelectProviderStep.tsx
  • packages/ui/src/components/ConfigureSSO/steps/__tests__/SelectProviderStep.test.tsx
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go (manual)
  • clerk/dashboard (manual)
  • clerk/accounts (manual)
  • clerk/backoffice (manual)
  • clerk/clerk (manual)
  • clerk/clerk-docs (manual)
  • clerk/cloudflare-workers (manual)
  • clerk/clerk-ios (auto-detected)
  • clerk/clerk-android (auto-detected)
  • clerk/cli (auto-detected)
💤 Files with no reviewable changes (2)
  • packages/ui/src/components/ConfigureSSO/ConfigureSSOContext.tsx
  • packages/shared/src/types/clerk.ts
🚧 Files skipped from review as they are similar to previous changes (3)
  • .changeset/quiet-moons-shine.md
  • packages/ui/src/components/ConfigureSSO/steps/SelectProviderStep.tsx
  • packages/ui/src/components/ConfigureSSO/steps/ConfigureStep/index.tsx

The OIDC group now always renders, so the step shows 5 provider cards
instead of 4.
@NicolasLopes7
NicolasLopes7 merged commit aaea141 into main Jul 31, 2026
52 checks passed
@NicolasLopes7
NicolasLopes7 deleted the nicolas/remove-oidc-self-serve-flag branch July 31, 2026 00:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants