[@clerk/react v6] <SignIn> sends duplicate email_code on second-factor (MFA) step, distinct from #8463
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 50/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- react, typescript
- Lĩnh vực
- authentication, frontend
Hướng nghiên cứu
Bắt đầu với flow dựng sẵn @clerk/react và quá trình chuyển tiếp từ needs_second_factor sau khi xác thực mật khẩu thành công. Theo dõi nơi prepareSecondFactor() được gọi và so sánh với quá trình xác minh được backend chuẩn bị, được hiển thị trong các sự kiện của dashboard. Tái hiện bằng password plus email_code MFA, sau đó xác nhận rằng chỉ Resend một cách rõ ràng mới gửi thêm mã.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Reproduction
- Instance has password as first factor,
email_codeas the (only) required second factor / MFA strategy. - Render prebuilt
<SignIn routing="path" path="/sign-in" signUpUrl="/sign-up" />(no custom flow). - Submit correct password. First factor passes cleanly (no duplicate here).
- Sign-in transitions to
needs_second_factor. Twoemail_codeverification emails arrive ~1 second apart; the first code is invalidated by the second.
Dashboard log evidence (single sign_in_id, single client)
sign_in.attempt_first_factor.passed strategy=password (T+0.0s)
sign_in.email_address.verification_code_sent (T+0.0s) <- code #1
sign_in.prepare_second_factor.passed strategy=email_code, new verification_id (T+0.0s)
sign_in.email_address.verification_code_sent (T+1.0s) <- code #2, invalidates #1
Same sign_in_id, same client_id, same IP across all four events — this is one browser tab, one attempt, not a remount/refresh or a second tab.
Why this looks like a sibling of #8463, not a duplicate report
#8463 (closed, "fixed in Core 3") and #8684/#4324 are about prepareFirstFactor / SignUp.create() re-sending a code on remount or because create() already prepares under the hood before an explicit prepare call fires again.
This reproduces on @clerk/[email protected] (Core 3, current latest), with no remount involved — it's the transition from first-factor success straight into the second-factor (MFA) step, in a single mount. It looks like the same class of bug (backend/widget both send a code for the same verification step) but on the prepareSecondFactor code path specifically, which doesn't appear to have been covered by the Core 3 fix for the first-factor case.
Expected behavior
When a sign-in transitions to needs_second_factor and email_code is the strategy, <SignIn> should resume on whatever verification the backend already prepared for that transition (if any) rather than unconditionally calling prepareSecondFactor() again. A second code should only be sent when the user explicitly clicks "Resend."
Environment
@clerk/react:6.12.9- React: 19, Vite 6
pk_test_*instance, password + email_code (as second factor/MFA) enabled- Reproduces in Chrome (desktop), consistently, every sign-in attempt requiring the second factor
Related
- #8463 (first-factor/remount case, closed as fixed in Core 3 — this is a different code path)
- #8684, #4324 (SignUp / prepareFirstFactor variants of the same "double prepare" pattern)
- Ngôn ngữ chính
- TypeScript
- Star
- 1.8k
- Fork
- 473
- Merge trung bình
- 2 ngày 3 giờ
- Pull request đã merge (30 ngày)
- 269
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của clerk/javascript
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
clerk/javascript#10033 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
clerk/javascript#10026 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
clerk/javascript#9987 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 65/100
clerk/javascript#10011 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 50/100
clerk/javascript#9984 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của clerk/javascript
Issue tương tự
-
keytrace logo svg?Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
cyclofinance/cyclo.site#448 ·
-
[sanity-plugin-media] Searching for a word with an apostrophe shows an error instead of resultsĐang mở@sanity-io/studio bug sanity-plugin-media Sieve-Agent
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
-
bug via-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
pingdotgg/t3code#15221 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày