Repository navigation
Conversation
🦋 Changeset detectedLatest commit: df8ab46 The changes in this PR will be included in the next version bump. This PR includes changesets to release 0 packagesWhen changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueNote Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (1)
🔗 Linked repositories identifiedCodeRabbit considers these linked repositories for cross-repo context during reviews:
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 3 remain after this review. 📝 WalkthroughWalkthroughAdds the Priority: ➖ Normal Estimated code review effort: 5 (Critical) | ~120 minutes Merge Risk: 🔵 Low · up to The verification tool can lose run evidence or encounter cleanup, duplicate-runner, and proxy-check failures in specific conditions. These are bounded workflow risks; merge is possible with owner awareness and follow-up. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)✅ Passed checks (4 passed)
Comment |
160b44a to
729ecd1
Compare
729ecd1 to
2d05137
Compare
2d05137 to
43ca8cc
Compare
43ca8cc to
e31b477
Compare
b0d1508 to
249bffc
Compare
9b925c9 to
e0f90bd
Compare
…nd repo wiring Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…API stand-in, secrets, and evidence Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…on per worktree Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Description
Adds end-to-end tests that prove a
@clerk/expochange on an iOS simulator or an Android emulator, and a CLI that runs them, as the Node packageintegration/expo-native/.The tests are an ordinary e2e project.
npx e2e run <test file>runs one when the environment names the platform, a booted simulator or a running emulator by its id, a build of theexpo-nativefixture, and the publishable key and secret key of a Clerk development instance.integration/expo-native/README.mdhas the commands. The tests launch the fixture with the inputs from #10052.The CLI sits on top of the tests. It builds the fixture, runs the tests against a Clerk application that it creates and deletes, and keeps a video and screenshots of each run. The device is on the machine that runs the CLI. Under the CLI the test process never holds the application's secret key. The
verify-clerk-exposkill is the instructions an agent or a developer reads, and they point at the package.It sits on #10052. #10090, on top of this, runs these tests in CI and deletes the older tests in
integration/tests/expo-native/, which this pull request leaves as they are. #10131, on top of #10090, lets a machine that cannot run a device borrow one on a CI runner.The seven commits are in dependency order, and each adds one part. Paths below that begin
src/,specs/, or.verify/are insideintegration/expo-native/.package-lock.jsonintegration/expo-native/up as a small Node package: its dependencies, thecontrol-clerk-expocommand, the five-linee2e.config.ts, the packageREADME.md, and the.prettierignoreandeslint.config.mjsentries that keep the repo's formatter and linter off its files.specs/support/reads a run's settings from the environment, starts the app, and creates test users and sign-in tickets through Clerk's Backend API.expo-nativefixture and install it on the simulator or emulator, and inspecs/app.tshow a test launches it.hostfixture they use, and one short page per feature that says how a user reaches it and what on screen proves it works.test/seam.test.tsfails whene2e.config.tsor a file underspecs/imports anything outsidespecs/.Commits 2 and 3,
e2e.config.tsin commit 1,specs/fixtures.tsin commit 5, and most of commit 6 are the same files, byte for byte, in clerk/clerk-ios#629 and clerk/clerk-android#1046.src/core/MANIFESTlists every shared file with its hash, and a unit test fails when one drifts. Review them once. The unit tests for all of the code arrive together in commit 6, so the commits before it do not pass a test run by themselves.The skill is
SKILL.md,references/, and one page per feature infeatures/, all in.claude/skills/verify-clerk-expo/, and.cursor/skills/verify-clerk-expois a symlink to that directory. To review what is this repository's own, readSKILL.md, thensrc/host.tsandsrc/fixture.ts, thenspecs/app.tsandspecs/golden/.To try it on a Mac with Xcode, Node 24.8 or newer, and the team's Clerk Platform API key:
doctoronly reads, and prints a fix for each thing the machine lacks.runbuilds the fixture as a Debug dev client, creates the application, takes a simulator that the CLI cloned for itself, starts Metro andtsdown --watchinpackages/expo, and runs the tests. A later JS edit reaches the app on the nextrunwith no native build.downreleases the device and deletes the application. The evidence stays in.verify/runs/<run-id>/.The 17 end-to-end tests are in
specs/golden/, in seven groups. Two are for iOS only, so Android runs 15.native-auth-viewAuthView, its React Native logo, and a sign-in through ituser-button-and-profileUserButton, the profile it opens, the home's sign-out, and an inlineUserProfileViewwithonHostBackand a custom pagecustom-flow-sign-inuseSignIncustom-flow-sign-upuseSignUptoken-cache-persistencenative-js-syncuseAuth,useUser, anduseSessionnative-modulesuseSignInWithGoogleopening the native Google sign-in and, on iOS, reporting a cancel, anduseBiometricCredentialsgiving the native module's answerEvery test starts at the fixture's home and taps to the screen it needs, as a user would. The options of
host.launchchoose who is signed in, the mode ofAuthView, and whether storage is kept from the last launch.specs/native.tsholds the locators of the home's buttons, and a unit test fails when they differ from the fixture's.The tests assert on what a user sees, in the prebuilt views first and on the fixture's home for the outcome of a flow. Android tests find the prebuilt views by text, because the clerk-android release that
@clerk/expopins has no test tags. iOS tests use theclerk.*accessibility identifiers. Tests type only+clerk_testaddresses and the test code424242.The two
native-modulestests sign no one in. The Google test proves that the hook reads the fixture's placeholder client IDs and that the native module opens Google's sign-in. On iOS it also proves that a cancel comes back asGoogle sign-in was cancelled. On Android it stops once a page of Google Play services is on screen, because what that page is and whether Back closes it differ from run to run on an emulator with no Google account. It does not prove that a Google account can sign in. The biometrics test turns biometric sign-in on for the instance through the settings file beside it and expects the answer the native module gives on a simulator or an emulator. It does not prove enrolling or signing in with a biometric.Each worktree gets one Clerk application in a workspace that holds nothing else, with the settings in
src/core/instances/base.json. The CLI creates it with the Platform API key, which comes from the environment, a file, or a 1Password reference kept outside the repository. No file holds the application's secret key. Under the CLI the tests reach Clerk's Backend API through a stand-in on the same machine, insrc/core/broker.ts, which forwards only the three kinds of request they make, for test users of that run. After a run, the CLI searches the run directory for every secret the run used, andattachrefuses to post a run that holds one.The tests' config also sets up e2e's built-in agent, with
anthropic/claude-haiku-5.5andopenai/gpt-6-luna-fastas its backup, only when the environment has a Vercel AI Gateway key. No committed test uses the agent, and no workflow passes a key.The package installs its dependencies with
npm cifrom its own lockfile, outside the pnpm workspace. TheExpo Native Runner Testsjob added toci.ymlruns the package's 498 unit tests andtscon Linux, with no device and no secret, when a pull request changes the package or a path its tests read.Nothing in this pull request runs a test on a device in CI. The workflow in #10090 runs the 17 tests on a commit that contains this one.
Checklist
pnpm testruns as expected.pnpm buildruns as expected.Type of change
🤖 Generated with Claude Code