Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

ClerkAPIError drops meta.lockout_expires_in_seconds from user_locked errors

Offen Anfängerfreundlich
#10,026 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 1 Tag

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
2/5
Geschätzter Aufwand
1-3 Stunden
Anfängerfreundlichkeit
78/100
Issue-Typ
Bug
Klarheit
Klar beschrieben
Aktivitätsstatus
Aktiv
Tech-Stack
typescript
Bereich
authentication

Rechercherichtung

Beginne in packages/shared/src/errors/clerkApiError.ts bei der Metadatenanalyse um die Zeilen 21–38, wo ClerkAPIError meta aus bekannten Schlüsseln erstellt. Verfolge, wie die rohe user_locked-Antwort in den öffentlichen Fehler umgewandelt wird, und überprüfe anschließend, dass lockout_expires_in_seconds als lockoutExpiresInSeconds erhalten bleibt und für Aufrufer weiterhin verfügbar ist.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

Preliminary Checks
  • I have reviewed the documentation: https://clerk.com/docs
  • I have searched for existing issues: https://github.com/clerk/javascript/issues
  • I have not already reached out to Clerk support via email or Discord
  • This issue is not a question, general help request, or anything other than a bug report directly related to Clerk
Reproduction

The bug is visible in the source, no project needed: https://github.com/clerk/javascript/blob/main/packages/shared/src/errors/clerkApiError.ts#L21-L38

Publishable key

Not needed: the behavior does not depend on an instance, it is in the error parser.

Description

When an account reaches the user lockout threshold, the Frontend API answers the failed attempt with 403 user_locked and includes how long the lockout lasts in meta.lockout_expires_in_seconds. ClerkAPIError builds its meta from a fixed list of known keys (param_name, session_id, identifiers, zxcvbn, plan, …), so lockout_expires_in_seconds is dropped and the app cannot tell the user when they can try again.

Steps to reproduce:

  1. Enable user lockout on an instance (e.g. 10 attempts, 60 minutes).
  2. Sign in with a phone code and submit wrong codes until the attempt returns user_locked.
  3. Inspect the network response: errors[0].meta.lockout_expires_in_seconds is present (e.g. 3599).
  4. Inspect the thrown ClerkAPIResponseError: errors[0].meta has no lockout field.

Expected behavior:

ClerkAPIError.meta exposes the lockout duration (e.g. lockoutExpiresInSeconds), the same way ClerkAPIResponseError.retryAfter already exposes Retry-After for too_many_requests, so apps can show a countdown or hide "resend code" until the lockout ends.

Actual behavior:

The value is discarded during parsing. The only way to read it is to bypass the SDK and parse the raw response.

Environment
@clerk/shared 4.31.0 (also on main as of 2026-10-01)
@clerk/clerk-expo, React Native (Expo SDK), iOS and Android
Vorherrschende Sprache
TypeScript
Sterne
1.8k
Forks
477
Ø Merge
2 T. 25 Min.
Gemergte PRs (30 T.)
267

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus clerk/javascript

Alle Issues in clerk/javascript

Ähnliche Issues

Weitere Issues zu TypeScript

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.