bug(nuxt): repeated Set-Cookie headers are overwritten by clerkMiddleware
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 86/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- nuxtjs, typescript
- Domain
- authentication, backend
Research direction
Start with packages/nuxt/src/runtime/server/tests/clerkMiddleware.test.ts, especially the reproduction around lines 116-143, and inspect the clerkMiddleware path exercised by the H3 handler. Run the focused test with mocked authentication headers; done means both appended Set-Cookie directives remain available in the Nuxt response.
Written by the indexing model from the issue text.
Description
Preliminary Checks
- I have reviewed the documentation: https://clerk.com/docs
- I have searched for existing issues: https://github.com/clerk/javascript/issues
- I have not already reached out to Clerk support via email or Discord
- This is a bug report directly related to Clerk
Reproduction
The package's existing clerkMiddleware.test.ts can reproduce this without a Clerk instance: mock authenticateRequest() with a Headers object containing two appended Set-Cookie values, run the H3 handler, then inspect response.headers.getSetCookie(). Only the last value remains.
Publishable key
Not applicable. This is a unit-level server middleware reproduction and does not make a request to Clerk.
Description
Steps to reproduce:
- Create a
Headersinstance and append twoSet-Cookievalues, such as an expired__clerk_handshakecookie and a refreshed__sessioncookie. - Return those headers from the mocked
authenticateRequest()result used byclerkMiddleware. - Send a request through the H3 handler and inspect
response.headers.getSetCookie().
Expected behavior:
Both cookie directives are present in the Nuxt response. Set-Cookie is a repeatable response header, and Clerk can return several cookie mutations from one authentication or handshake result.
Actual behavior:
Only the last cookie directive is present. clerkMiddleware iterates over the authentication headers and calls H3's setResponseHeader() for every value. That API replaces a previous value with the same name, so each Set-Cookie overwrites the preceding one.
This can leave an expired or stale Clerk handshake cookie in the browser when its deletion directive is followed by another cookie directive. Subsequent server requests can then continue entering the handshake path until that short-lived cookie expires.
Environment
System:
OS: Linux 6.16 Pop!_OS 24.04 LTS
CPU: (16) x64 11th Gen Intel(R) Core(TM) i9-11900K @ 3.50GHz
Binaries:
Node: 25.0.0
npm: 11.6.2
pnpm: 10.33.0
Browsers:
Chrome: 150.0.7871.46
npmPackages:
@clerk/nuxt: 3.0.15
h3: 1.15.11
- Dominant language
- TypeScript
- Stars
- 1.8k
- Forks
- 472
- Avg merge
- 2d 15h
- Merged PRs (30d)
- 193
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from clerk/javascript
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
clerk/javascript#9852 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
clerk/javascript#9611 · 1 comment ·
-
Difficulty 4/5 3-5 days Newbie friendliness 64/100
clerk/javascript#9775 · 1 comment ·
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
clerk/javascript#9770 · 3 comments ·
-
Difficulty 3/5 1-2 days Newbie friendliness 68/100
clerk/javascript#9667 · 1 comment ·
All issues in clerk/javascript
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
ontola/atomic-server#1625 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
melgarafael/DeskcommCRM#1451 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 82/100
-
bug via-triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
bot:ai-assisted component:compact-js status:untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
midnightntwrk/midnight-sdk#403 ·