Skip to content

fix(ui): Prompt reverification for SMS set-default and hide it when TOTP is enrolled - #10042

Open
alexcarpenter wants to merge 1 commit into
mainfrom
carp/debug-reverification
Open

alexcarpenter wants to merge 1 commit into
mainfrom
carp/debug-reverification

Conversation

@alexcarpenter

@alexcarpenter alexcarpenter commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Description

Fixes two problems with the SMS "Set as default" action in <UserProfile />'s MFA section, reported in #9984:

The third item in the issue (sign-in always starting with TOTP instead of honoring defaultSecondFactor) is intentional per determineStartingSignInSecondFactor and isn't changed here.

Screenshots

Set as default offered while an authenticator app is enrolled

Before After
before-1-menu-with-totp after-1-menu-with-totp

Reverification required

Before After
before-2-raw-error after-2-reverification-modal
after-3-retried-now-default

The "before" reverification shot uses a simulated session_reverification_required 403, since the session was still within the reverification window. After completing reverification, the action retries and the number becomes the default.

Refs #9984

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
clerk-js-sandbox Ready Ready Preview Oct 2, 2026 8:17pm UTC
swingset Ready Ready Preview Oct 2, 2026 8:17pm UTC

Request Review

@changeset-bot

changeset-bot Bot commented Oct 2, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 673a890

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
Name Type
@clerk/ui Patch
@clerk/chrome-extension Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions github-actions Bot added the ui label Oct 2, 2026
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Team

Run ID: d1ef9e41-2617-44a6-aace-a2d83cd0435b

📥 Commits

Reviewing files that changed from the base of the PR and between 43d21a2 and 673a890.

📒 Files selected for processing (3)
  • .changeset/mfa-set-default-reverification.md
  • packages/ui/src/components/UserProfile/MfaSection.tsx
  • packages/ui/src/components/UserProfile/__tests__/MfaPage.test.tsx
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

Included review availability: This review used your included allowance. 5 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 8 reviews per hour.


📝 Walkthrough

Walkthrough

Setting an SMS second factor as default now uses reverification when required. The SMS menu does not offer that action when TOTP is enabled or the phone is already the default. Tests cover the reverification retry and the menu state when an authenticator app is enrolled.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: ⚪ Minimal · up to 673a8

The SMS default action is hidden when TOTP is enabled, and no merge-blocking issue remains after normal checks.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly summarizes both main fixes: reverification for the SMS set-default action and hiding that action when TOTP is enrolled.
Description check ✅ Passed The description directly explains the two changes, their rationale, test coverage, scope, and intentional exclusions.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 2, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@10042

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@10042

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@10042

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@10042

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@10042

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@10042

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@10042

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@10042

@clerk/expo-biometrics

npm i https://pkg.pr.new/@clerk/expo-biometrics@10042

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@10042

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@10042

@clerk/express

npm i https://pkg.pr.new/@clerk/express@10042

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@10042

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@10042

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@10042

@clerk/mosaic

npm i https://pkg.pr.new/@clerk/mosaic@10042

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@10042

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@10042

@clerk/react

npm i https://pkg.pr.new/@clerk/react@10042

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@10042

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@10042

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@10042

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@10042

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@10042

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@10042

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@10042

commit: 673a890

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-10-02T20:19:35.648Z

Summary

Metric Count
Packages analyzed 19
Packages with changes 1
🔴 Breaking changes 1
🟡 Non-breaking changes 0
🟢 Additions 0

Warning
1 breaking change(s) detected - Major version bump required

🤖 This report was reviewed by claude-sonnet-4-6.

🔴 Breaking changes index (1)

Every breaking change, up front. Full diffs are in the package sections below.

Package Subpath Change
@clerk/ui ./themes/experimental createTheme

@clerk/ui

Current version: 1.38.1
Recommended bump: MAJOR → 2.0.0

Subpath ./themes/experimental

🔴 Breaking Changes (1)

Changed: createTheme
// ... 4 unchanged lines elided ...
      theme: InternalTheme;
    }) => Elements);
    theme?: (BaseTheme | BaseTheme[]) | undefined;
-   options?: Options | undefined;
-   variables?: Variables | undefined;
-   captcha?: CaptchaAppearanceOptions | undefined;
+   options?: import("@clerk/ui/internal").Options | undefined;
+   variables?: import("@clerk/ui/internal").Variables | undefined;
+   captcha?: import("@clerk/ui/internal").CaptchaAppearanceOptions | undefined;
    cssLayerName?: string | undefined;
  }

Static analyzer: Breaking change in function createTheme: Return type changed: {__type:"prebuilt_appearance";name?:string;elements?:((params:{theme:import("@clerk/ui").~InternalTheme;})=>import("@clerk/ui").~Elements)|import("@clerk/ui").~Elements;theme?:(import("@clerk/ui").~BaseTheme|import("@clerk/ui").~BaseTheme[])|undefined;options?:import("@clerk/ui").~Options|undefined;variables?:import("@clerk/ui").~Variables|undefined;captcha?:import("@clerk/ui").~CaptchaAppearanceOptions|undefined;cssLayerName?:string|undefined;} → {__type:"prebuilt_appearance";name?:string;elements?:!unknown|((params:{theme:import("@clerk/ui").~InternalTheme;})=>!unknown);theme?:(!unknown|!unknown[])|undefined;options?:import("@clerk/ui/internal").Options|undefined;variables?:import("@clerk/ui/internal").Variables|undefined;captcha?:import("@clerk/ui/internal").CaptchaAppearanceOptions|undefined;cssLayerName?:string|undefined;}

🤖 AI review (confirmed) (72%): The options, variables, and captcha fields in the return type now reference @clerk/ui/internal, which has "unknown" resolution (package not found), meaning consumers cannot resolve these types — per rule 12, structural equivalence cannot save this since the specifier is non-resolvable. This could degrade the types to any or cause compile errors for consumers depending on the type of those fields.

Migration: If you depend on Options, Variables, or CaptchaAppearanceOptions from the createTheme return type, update your imports to use @clerk/ui/internal once it is published as a resolvable entry point, or source those types from the package's public API surface.


Report generated by Break Check

Last ran on 673a890.

@wobsoriano wobsoriano left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks for the screenshots!

This branch was successfully deployed

2 active deployments
Preview – swingset — 673a8903 Deployed Oct 2, 2026 by vercel[bot]
Preview – clerk-js-sandbox — 673a8903 Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants