@clerk/nextjs: onBeforeSetActive never settles when invalidateCacheAction rejects (e.g. after a redeploy), so setActive and signOut hang forever
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 2/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 78/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
调研方向
从 dist/esm/app-router/client/ClerkProvider.js 中的 window.__internal_onBeforeSetActive 开始,检查 invalidateCacheAction() 如何处理拒绝。按照提供的 stale-tab redeploy 步骤重现,然后验证 cache-invalidation action 失败后 hook 能够结束,并且登录、登出和重新验证都能完成。
由索引模型根据 Issue 内容生成。
描述
Preliminary Checks
- I have reviewed the documentation: https://clerk.com/docs
- I have searched for existing issues: https://github.com/clerk/javascript/issues
- I have not already reached out to Clerk support via email or Discord
- This issue is not a question, general help request, or anything other than a bug report directly related to Clerk.
Reproduction
No public repo: the steps below reproduce it in any App Router app using @clerk/nextjs, and the faulty code path is two lines, quoted below.
Publishable key
pk_test_YnJpZWYtc2N1bHBpbi00NS5jbGVyay5hY2NvdW50cy5kZXYk (a development instance; the bug does not depend on the instance, and we hit it in production first)
Description
The App Router client ClerkProvider sets (@clerk/nextjs 7.4.1, dist/esm/app-router/client/ClerkProvider.js; the same code is in 7.9.7):
window.__internal_onBeforeSetActive = (intent) => {
return new Promise((resolve) => {
const nextVersion = window?.next?.version || "";
if ((nextVersion.startsWith("15") || nextVersion.startsWith("16")) && intent === "sign-out") {
resolve();
} else {
void invalidateCacheAction().then(() => resolve());
}
});
};
If invalidateCacheAction() rejects, resolve is never called and the promise never settles. clerk-js awaits this hook inside setActive and signOut, so they hang forever.
The rejection is routine on any self-hosted Next 15/16 app. Server action IDs are salted with a per-build encryption key, so after every redeploy a tab loaded from the previous build calls an action ID the new server does not know. The server answers 404 with x-nextjs-action-not-found: 1 and logs Failed to find Server Action "…". This request might be from an older or newer deployment., and Next rejects the call with UnrecognizedActionError. A network failure has the same effect.
What we measured, in tabs opened before a deploy:
- Sign-in and reverification (a password change in
<UserProfile />) spin forever. signOut()calls the hook with no intent, so the Next 15/16"sign-out"fast path does not apply, and it awaits the hook beforeremoveSessions(). A stale-tab sign-out therefore leaves the user signed in.
Steps to reproduce:
- A fresh
create-next-app(App Router) with@clerk/nextjsand a<UserButton />on a page. NEXT_SERVER_ACTIONS_ENCRYPTION_KEY=$(openssl rand -base64 32) next build && next start, open the page and sign in.- Stop the server and rebuild with a different
NEXT_SERVER_ACTIONS_ENCRYPTION_KEY(two plain local builds reuse the key cached in.next/cache/.rscinfoand keep the same IDs), thennext startagain. Do not reload the tab. - In that tab, sign out from the
<UserButton />, or runawait window.__internal_onBeforeSetActive()in the console.
Expected behavior:
The hook settles even when the cache-invalidation action fails (__internal_onAfterSetActive already calls router.refresh()), and sign-out, sign-in and reverification complete.
Actual behavior:
The promise never settles, the UI spins, and on sign-out the session is not removed. The console shows Uncaught (in promise) UnrecognizedActionError: Server Action "…" was not found on the server.
Suggested fix: invalidateCacheAction().then(() => resolve(), () => resolve()), or skip the action on Next ≥ 15 as #7873 proposed. Related prior art: #5084 and #7873 (closed unmerged), and #8122 (a never-settling variant with cacheComponents).
Our app-side workaround re-points window.__internal_onBeforeSetActive, from a descendant useEffect, to a wrapper that races Clerk's promise against an unhandledrejection listener for UnrecognizedActionError and a timeout.
Environment
next: 16.2.6 (webpack build, output: standalone, self-hosted)
@clerk/nextjs: 7.4.1 (the hook is identical in 7.9.7)
@clerk/clerk-js: 6.x (loaded from the CDN by major version)
react / react-dom: 19.2.4
node: 22 (production image)
browser: Chrome
- 主要语言
- TypeScript
- 星标
- 1.8k
- 派生
- 473
- 平均合并
- 2 天 3 小时
- 30 天内合并 PR
- 269
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
clerk/javascript 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 88/100
clerk/javascript#10033 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 78/100
clerk/javascript#10026 ·
维护者通常 1 天内回复
-
难度 3/5 1-2 天 新手友好度 65/100
clerk/javascript#10011 ·
维护者通常 1 天内回复
-
难度 4/5 3-5 天 新手友好度 50/100
clerk/javascript#9984 ·
维护者通常 1 天内回复
-
M2M Token only authentication in Clerk Middleware可能已有人在做 @wobsoriano 于 3 天前认领。 未关闭needs-triage
clerk/javascript#9981 · 已指派 1 人 ·
维护者通常 1 天内回复
相似的 Issue
-
bug
难度 2/5 1-3 小时 新手友好度 88/100
MystenLabs/MemWal#1085 · 1 条评论 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复
-
📕documentation
难度 2/5 1-3 小时 新手友好度 72/100
db-ux-design-system/core-web#8343 ·
维护者通常 1 天内回复
-
enhancement triage/needs-triage
难度 2/5 1-3 小时 新手友好度 88/100
heygen-com/hyperframes#4944 ·
维护者通常 1 天内回复
-
ai-driven-qa bug claude
难度 2/5 1-3 小时 新手友好度 82/100
linagora/twake-calendar-frontend#1493 · 1 条评论 ·
维护者通常 1 天内回复