ClerkAPIError drops meta.lockout_expires_in_seconds from user_locked errors
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 2/5
- Tempo estimado
- 1-3 horas
- Facilidade para iniciantes
- 78/100
- Tipo de issue
- Bug
- Clareza
- Claramente especificada
- Status de atividade
- Ativa
- Stack de tecnologia
- typescript
- Domínio
- authentication
Direção de pesquisa
Comece em packages/shared/src/errors/clerkApiError.ts, na análise de metadados em torno das linhas 21-38, onde ClerkAPIError constrói meta a partir de chaves conhecidas. Rastreie como a resposta bruta user_locked é convertida no erro público e, em seguida, verifique se lockout_expires_in_seconds é preservado como lockoutExpiresInSeconds e continua disponível para os chamadores.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Preliminary Checks
- I have reviewed the documentation: https://clerk.com/docs
- I have searched for existing issues: https://github.com/clerk/javascript/issues
- I have not already reached out to Clerk support via email or Discord
- This issue is not a question, general help request, or anything other than a bug report directly related to Clerk
Reproduction
The bug is visible in the source, no project needed: https://github.com/clerk/javascript/blob/main/packages/shared/src/errors/clerkApiError.ts#L21-L38
Publishable key
Not needed: the behavior does not depend on an instance, it is in the error parser.
Description
When an account reaches the user lockout threshold, the Frontend API answers the failed attempt with 403 user_locked and includes how long the lockout lasts in meta.lockout_expires_in_seconds. ClerkAPIError builds its meta from a fixed list of known keys (param_name, session_id, identifiers, zxcvbn, plan, …), so lockout_expires_in_seconds is dropped and the app cannot tell the user when they can try again.
Steps to reproduce:
- Enable user lockout on an instance (e.g. 10 attempts, 60 minutes).
- Sign in with a phone code and submit wrong codes until the attempt returns
user_locked. - Inspect the network response:
errors[0].meta.lockout_expires_in_secondsis present (e.g.3599). - Inspect the thrown
ClerkAPIResponseError:errors[0].metahas no lockout field.
Expected behavior:
ClerkAPIError.meta exposes the lockout duration (e.g. lockoutExpiresInSeconds), the same way ClerkAPIResponseError.retryAfter already exposes Retry-After for too_many_requests, so apps can show a countdown or hide "resend code" until the lockout ends.
Actual behavior:
The value is discarded during parsing. The only way to read it is to bypass the SDK and parse the raw response.
Environment
@clerk/shared 4.31.0 (also on main as of 2026-10-01)
@clerk/clerk-expo, React Native (Expo SDK), iOS and Android
- Linguagem predominante
- TypeScript
- Estrelas
- 1.8k
- Forks
- 477
- Merge médio
- 2d 25min
- PRs com merge (30d)
- 267
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Tem um modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de clerk/javascript
-
@clerk/nextjs: onBeforeSetActive never settles when invalidateCacheAction rejects (e.g. after a redeploy), so setActive and signOut hang foreverTalvez já em andamento Um pull request vinculado a esta issue está aberto ou já foi mesclado. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
clerk/javascript#9987 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 3/5 1-2 dias Facilidade para iniciantes 65/100
clerk/javascript#10011 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 50/100
clerk/javascript#9984 ·
Mantenedores costumam responder em até 1 dia
-
M2M Token only authentication in Clerk MiddlewareTalvez já em andamento @wobsoriano assumiu há 6 dias. Abertaneeds-triage
clerk/javascript#9981 · 1 responsável ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 3/5 1-2 dias Facilidade para iniciantes 72/100
clerk/javascript#9972 ·
Mantenedores costumam responder em até 1 dia
Todas as issues de clerk/javascript
Issues semelhantes
-
fix(data-lake): wizard source step still previews the local slug, not the server-disambiguated oneAbertadata-lake
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 82/100
Mantenedores costumam responder em até 1 dia
-
enhancement good first issue priority: low size: XS
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 82/100
Mantenedores costumam responder em até 1 dia
-
Empty label or headline exports the editor hint ("LABEL" / "Headline goes here") into the PNGAberta
Dificuldade 1/5 1-3 horas Facilidade para iniciantes 88/100
-
Spray wall wizard: Done button on the hold review step sits under the navigation header (iOS)Abertabug ios mobile priority:P1
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 76/100
Mantenedores costumam responder em até 1 dia
-
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 90/100
streamplace/streamplace#1351 ·
Mantenedores costumam responder em até 2 dias