Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

ClerkAPIError drops meta.lockout_expires_in_seconds from user_locked errors

Aberta Para iniciantes
#10,026 1 comentário 0 reações 0 responsáveis Ver no GitHub

Mantenedores costumam responder em até 1 dia

Ninguém assumiu esta issue ainda.

Avaliação

Dificuldade
2/5
Tempo estimado
1-3 horas
Facilidade para iniciantes
78/100
Tipo de issue
Bug
Clareza
Claramente especificada
Status de atividade
Ativa
Stack de tecnologia
typescript
Domínio
authentication

Direção de pesquisa

Comece em packages/shared/src/errors/clerkApiError.ts, na análise de metadados em torno das linhas 21-38, onde ClerkAPIError constrói meta a partir de chaves conhecidas. Rastreie como a resposta bruta user_locked é convertida no erro público e, em seguida, verifique se lockout_expires_in_seconds é preservado como lockoutExpiresInSeconds e continua disponível para os chamadores.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

Preliminary Checks
  • I have reviewed the documentation: https://clerk.com/docs
  • I have searched for existing issues: https://github.com/clerk/javascript/issues
  • I have not already reached out to Clerk support via email or Discord
  • This issue is not a question, general help request, or anything other than a bug report directly related to Clerk
Reproduction

The bug is visible in the source, no project needed: https://github.com/clerk/javascript/blob/main/packages/shared/src/errors/clerkApiError.ts#L21-L38

Publishable key

Not needed: the behavior does not depend on an instance, it is in the error parser.

Description

When an account reaches the user lockout threshold, the Frontend API answers the failed attempt with 403 user_locked and includes how long the lockout lasts in meta.lockout_expires_in_seconds. ClerkAPIError builds its meta from a fixed list of known keys (param_name, session_id, identifiers, zxcvbn, plan, …), so lockout_expires_in_seconds is dropped and the app cannot tell the user when they can try again.

Steps to reproduce:

  1. Enable user lockout on an instance (e.g. 10 attempts, 60 minutes).
  2. Sign in with a phone code and submit wrong codes until the attempt returns user_locked.
  3. Inspect the network response: errors[0].meta.lockout_expires_in_seconds is present (e.g. 3599).
  4. Inspect the thrown ClerkAPIResponseError: errors[0].meta has no lockout field.

Expected behavior:

ClerkAPIError.meta exposes the lockout duration (e.g. lockoutExpiresInSeconds), the same way ClerkAPIResponseError.retryAfter already exposes Retry-After for too_many_requests, so apps can show a countdown or hide "resend code" until the lockout ends.

Actual behavior:

The value is discarded during parsing. The only way to read it is to bypass the SDK and parse the raw response.

Environment
@clerk/shared 4.31.0 (also on main as of 2026-10-01)
@clerk/clerk-expo, React Native (Expo SDK), iOS and Android
Linguagem predominante
TypeScript
Estrelas
1.8k
Forks
477
Merge médio
2d 25min
PRs com merge (30d)
267

Preparar o ambiente

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de clerk/javascript

Todas as issues de clerk/javascript

Issues semelhantes

Mais issues de TypeScript

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.