Skip to content
Merged
22 changes: 22 additions & 0 deletions .changeset/tanstack-start-csrf-minimum.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
---
'@clerk/tanstack-react-start': minor
---

Raise the minimum supported peer dependencies to `@tanstack/react-start@^1.168.10` and `@tanstack/react-router@^1.170.7`. Start 1.168.10 is the first version where importing `createCsrfMiddleware()` works reliably during Vite SSR.

TanStack Start skips its default CSRF protection for server functions when your app has a `src/start.ts`, which `clerkMiddleware()` requires. Register `createCsrfMiddleware()` before `clerkMiddleware()` to restore it:

```ts
import { clerkMiddleware } from '@clerk/tanstack-react-start/server';
import { createCsrfMiddleware, createStart } from '@tanstack/react-start';

const csrfMiddleware = createCsrfMiddleware({
filter: (ctx) => ctx.handlerType === 'serverFn',
});

export const startInstance = createStart(() => {
return {
requestMiddleware: [csrfMiddleware, clerkMiddleware()],
};
});
```
4 changes: 2 additions & 2 deletions packages/tanstack-react-start/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,8 +31,8 @@

### Prerequisites

- TanStack Start `^1.157.0` or later
- TanStack Router `^1.157.0` or later
- TanStack Start `^1.168.10` or later
- TanStack Router `^1.170.7` or later
- React 18 or later
- Node.js `>=20.9.0` or later
- An existing Clerk application. [Create your account for free](https://dashboard.clerk.com/sign-up?utm_source=github&utm_medium=clerk_tanstack_react_start).
Expand Down
4 changes: 2 additions & 2 deletions packages/tanstack-react-start/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -90,8 +90,8 @@
"esbuild-plugin-file-path-extensions": "^2.1.4"
},
"peerDependencies": {
"@tanstack/react-router": "^1.168.10",
"@tanstack/react-start": "^1.167.17",
"@tanstack/react-router": "^1.170.7",
"@tanstack/react-start": "^1.168.10",
Comment thread
coderabbitai[bot] marked this conversation as resolved.
"react": "catalog:peer-react",
"react-dom": "catalog:peer-react"
},
Expand Down
Loading