Skip to content

refactor(mosaic): simplify password section composition and coverage - #10075

Open
austincalvelage wants to merge 8 commits into
mainfrom
austin/password-wire-up-feedback
Open

austincalvelage wants to merge 8 commits into
mainfrom
austin/password-wire-up-feedback

Conversation

@austincalvelage

@austincalvelage austincalvelage commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Description

Follow up on the review of #9930. Simplify the Mosaic password section composition while preserving password editing, loading fallbacks, and hiding empty Authentication sections.

  • Replace the typed slot hook and { content } wrapper with a shared rendering function. The password slot carries the resolved content or null, without a separate visibility flag.
  • Keep the ready-only controller boundary. Require a typed set/change password policy with requiresCurrentPassword: false for a first password. Swingset forwards the controller's display values to the dialog.
  • Consolidate model coverage into feature tests, including current-password API errors, blank enterprise names, and policy changes while a dialog remains open. Colocate the password-section test and give the security panel its own feature test.
  • Resolve the enterprise-name fallback in the model and remove the intermediate content component. Track password skeleton integration after feat(mosaic): section skeletons with a page-wide loading wave #10029 at the loading branch.

The connected UserProfileSecurityPanel is groundwork for future integration and is currently used only in tests. The controller pass-through remains local to this feature; this change does not introduce a repo-wide architecture rule.

The empty changeset is intentional. These are internal composition and test changes with no public package export changes.

Checklist

  • pnpm test runs as expected. Targeted password and security-panel suites passed locally with 63 tests and 2 existing TODOs.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@vercel

vercel Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
clerk-js-sandbox Ready Ready Preview Oct 5, 2026 9:12pm UTC
swingset Ready Ready Preview Oct 5, 2026 9:12pm UTC

Request Review

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (2)
packages/swingset/CLAUDE.md — auto-discovered
.cursor/rules/typescript.mdc — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository YAML (base), Organization UI (inherited)
  • Review profile: ASSERTIVE
  • Plan: Team
  • Run ID: a4328a61-c290-471a-be95-76e1432a7925
📥 Commits

Reviewing files that changed from the base of the PR and between dc8fa62 and e3ce9d0.

📒 Files selected for processing (13)
  • packages/mosaic/src/features/user-profile/__tests__/user-profile-security-panel.view.test.tsx
  • packages/mosaic/src/features/user-profile/user-profile-password-section/user-profile-edit-password.controller.test.ts
  • packages/mosaic/src/features/user-profile/user-profile-password-section/user-profile-edit-password.controller.ts
  • packages/mosaic/src/features/user-profile/user-profile-password-section/user-profile-password-section.feature.test.tsx
  • packages/mosaic/src/features/user-profile/user-profile-password-section/user-profile-password-section.model.ts
  • packages/mosaic/src/features/user-profile/user-profile-password-section/user-profile-password-section.tsx
  • packages/mosaic/src/features/user-profile/user-profile-password-section/user-profile-password-section.types.ts
  • packages/mosaic/src/features/user-profile/user-profile-security-panel.feature.test.tsx
  • packages/mosaic/src/features/user-profile/user-profile-security-panel.tsx
  • packages/mosaic/src/features/user-profile/user-profile-security-panel.view.tsx
  • packages/swingset/src/stories/fixtures/user-profile-edit-password.tsx
  • packages/swingset/src/stories/fixtures/user-profile.tsx
  • packages/swingset/src/stories/user-profile-security-panel.mdx
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

Included review availability: This review used your included allowance. 4 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 6 reviews per hour.


📝 Walkthrough

Walkthrough

The password controller now accepts a shared policy and identifier, and exposes password state and current-password requirements. The password section uses that state and renders model-specific content. The security panel now obtains password content and includes the Authentication region when password content, passkeys, or MFA methods are present. Tests, fixtures, and guidance reflect these changes.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~25 minutes

Possibly related PRs

  • clerk/javascript#9750: Introduced the password section, edit controller, dialog, and security-panel password handling that this PR revises.

Suggested reviewers: alexcarpenter

Merge Risk: ⚪ Minimal · up to e3ce9

The password-section and security-panel changes are mergeable after normal checks; no specific behavior requiring a fix before merge is established.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 7.14% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 14 functions across 13 files. (1 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the password-section refactor and its test coverage.
Description check ✅ Passed The description explains the composition changes, preserved behavior, and added test coverage.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 7.14% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 14 functions across 13 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@10075

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@10075

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@10075

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@10075

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@10075

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@10075

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@10075

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@10075

@clerk/expo-biometrics

npm i https://pkg.pr.new/@clerk/expo-biometrics@10075

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@10075

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@10075

@clerk/express

npm i https://pkg.pr.new/@clerk/express@10075

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@10075

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@10075

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@10075

@clerk/mosaic

npm i https://pkg.pr.new/@clerk/mosaic@10075

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@10075

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@10075

@clerk/react

npm i https://pkg.pr.new/@clerk/react@10075

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@10075

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@10075

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@10075

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@10075

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@10075

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@10075

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@10075

commit: e3ce9d0

@austincalvelage
austincalvelage force-pushed the austin/password-wire-up-feedback branch from f3522c6 to dc8fa62 Compare October 5, 2026 20:44
@changeset-bot

changeset-bot Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: e3ce9d0

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

This branch was successfully deployed

2 active deployments
Preview – swingset — e3ce9d08 Deployed Oct 5, 2026 by vercel[bot]
Preview – clerk-js-sandbox — e3ce9d08 Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant