@clerk/nextjs: onBeforeSetActive never settles when invalidateCacheAction rejects (e.g. after a redeploy), so setActive and signOut hang forever
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 78/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Lĩnh vực
- authentication, frontend
Hướng nghiên cứu
Bắt đầu trong dist/esm/app-router/client/ClerkProvider.js tại window.__internal_onBeforeSetActive và kiểm tra cách invalidateCacheAction() xử lý việc bị từ chối. Tái hiện bằng các bước stale-tab redeploy được cung cấp, sau đó xác minh rằng hook hoàn tất và việc đăng nhập, đăng xuất cũng như xác minh lại hoàn tất sau khi hành động vô hiệu hóa cache thất bại.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Preliminary Checks
- I have reviewed the documentation: https://clerk.com/docs
- I have searched for existing issues: https://github.com/clerk/javascript/issues
- I have not already reached out to Clerk support via email or Discord
- This issue is not a question, general help request, or anything other than a bug report directly related to Clerk.
Reproduction
No public repo: the steps below reproduce it in any App Router app using @clerk/nextjs, and the faulty code path is two lines, quoted below.
Publishable key
pk_test_YnJpZWYtc2N1bHBpbi00NS5jbGVyay5hY2NvdW50cy5kZXYk (a development instance; the bug does not depend on the instance, and we hit it in production first)
Description
The App Router client ClerkProvider sets (@clerk/nextjs 7.4.1, dist/esm/app-router/client/ClerkProvider.js; the same code is in 7.9.7):
window.__internal_onBeforeSetActive = (intent) => {
return new Promise((resolve) => {
const nextVersion = window?.next?.version || "";
if ((nextVersion.startsWith("15") || nextVersion.startsWith("16")) && intent === "sign-out") {
resolve();
} else {
void invalidateCacheAction().then(() => resolve());
}
});
};
If invalidateCacheAction() rejects, resolve is never called and the promise never settles. clerk-js awaits this hook inside setActive and signOut, so they hang forever.
The rejection is routine on any self-hosted Next 15/16 app. Server action IDs are salted with a per-build encryption key, so after every redeploy a tab loaded from the previous build calls an action ID the new server does not know. The server answers 404 with x-nextjs-action-not-found: 1 and logs Failed to find Server Action "…". This request might be from an older or newer deployment., and Next rejects the call with UnrecognizedActionError. A network failure has the same effect.
What we measured, in tabs opened before a deploy:
- Sign-in and reverification (a password change in
<UserProfile />) spin forever. signOut()calls the hook with no intent, so the Next 15/16"sign-out"fast path does not apply, and it awaits the hook beforeremoveSessions(). A stale-tab sign-out therefore leaves the user signed in.
Steps to reproduce:
- A fresh
create-next-app(App Router) with@clerk/nextjsand a<UserButton />on a page. NEXT_SERVER_ACTIONS_ENCRYPTION_KEY=$(openssl rand -base64 32) next build && next start, open the page and sign in.- Stop the server and rebuild with a different
NEXT_SERVER_ACTIONS_ENCRYPTION_KEY(two plain local builds reuse the key cached in.next/cache/.rscinfoand keep the same IDs), thennext startagain. Do not reload the tab. - In that tab, sign out from the
<UserButton />, or runawait window.__internal_onBeforeSetActive()in the console.
Expected behavior:
The hook settles even when the cache-invalidation action fails (__internal_onAfterSetActive already calls router.refresh()), and sign-out, sign-in and reverification complete.
Actual behavior:
The promise never settles, the UI spins, and on sign-out the session is not removed. The console shows Uncaught (in promise) UnrecognizedActionError: Server Action "…" was not found on the server.
Suggested fix: invalidateCacheAction().then(() => resolve(), () => resolve()), or skip the action on Next ≥ 15 as #7873 proposed. Related prior art: #5084 and #7873 (closed unmerged), and #8122 (a never-settling variant with cacheComponents).
Our app-side workaround re-points window.__internal_onBeforeSetActive, from a descendant useEffect, to a wrapper that races Clerk's promise against an unhandledrejection listener for UnrecognizedActionError and a timeout.
Environment
next: 16.2.6 (webpack build, output: standalone, self-hosted)
@clerk/nextjs: 7.4.1 (the hook is identical in 7.9.7)
@clerk/clerk-js: 6.x (loaded from the CDN by major version)
react / react-dom: 19.2.4
node: 22 (production image)
browser: Chrome
- Ngôn ngữ chính
- TypeScript
- Star
- 1.8k
- Fork
- 477
- Merge trung bình
- 2 ngày 3 giờ
- Pull request đã merge (30 ngày)
- 269
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của clerk/javascript
-
[expo] useLocalCredentials throws "Invalid key provided to SecureStore" during render when the publishable key has base64 padding (=)Có thể đã có người làm @RaphaelFakhri đã nhận 3 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
clerk/javascript#10033 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
clerk/javascript#10026 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 65/100
clerk/javascript#10011 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
<UserProfile />: SMS "Set as default" shows the raw reverification error instead of launching reverification, and has no effect while an authenticator app is enrolledCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 50/100
clerk/javascript#9984 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
M2M Token only authentication in Clerk MiddlewareCó thể đã có người làm @wobsoriano đã nhận 5 ngày trước. Đang mởneeds-triage
clerk/javascript#9981 · 1 người được giao ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của clerk/javascript
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
bug:new
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
callstackincubator/simlock#350 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
openwatersio/maritime-zones#33 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Booking email verification fails for plus aliases with impersonation protection enabledCó thể đã có người làm @kankadev đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
calcom/cal.diy#30293 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 5 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
AOSSIE-Org/DebateAI#611 ·
Maintainer thường phản hồi trong vòng 3 ngày