Skip to content

feat(ui,clerk-js,shared,localizations): Add all members of a role to the SSO allow list - #9826

Merged
mauricioabreu merged 2 commits into
mainfrom
mauricio-antunes/orgs-1852-add-all-members-from-a-given-role
Sep 24, 2026
Merged

mauricioabreu merged 2 commits into
mainfrom
mauricio-antunes/orgs-1852-add-all-members-from-a-given-role

Conversation

@mauricioabreu

@mauricioabreu mauricioabreu commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Description

Allowlisting everyone with a role, every admin for example, meant picking members one at a time on the SSO allow list page.

The "Add members" card now has two tabs. Email takes a single address and adds that member. Role lists the organization's roles with their member counts; picking one adds everyone with that role who is not on the list yet, through the bulk route from clerk/clerk_go#22265 in batches of 100. Members whose email address is not served by one of the organization's connections are skipped by the backend, and the page reports how many were added and how many skipped.

For custom flows, organization.ssoBypassAllowlist gains addUsers({ userIds }), returning the added entries and the users that could not be added with the reason.

Resolves ORGS-1852.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@vercel

vercel Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
clerk-js-sandbox Ready Ready Preview Sep 24, 2026 4:19pm UTC
swingset Ready Ready Preview Sep 24, 2026 4:19pm UTC

Request Review

@coderabbitai

coderabbitai Bot commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Team

Run ID: f9c57e73-3232-4970-9c6c-007372ca648c

📥 Commits

Reviewing files that changed from the base of the PR and between c96413b and dd7726e.

⛔ Files ignored due to path filters (1)
  • packages/ui/src/icons/user-plus.svg is excluded by !**/*.svg
📒 Files selected for processing (3)
  • packages/ui/src/components/OrganizationProfile/MemberListTable.tsx
  • packages/ui/src/components/OrganizationProfile/SSOBypassAllowlistPage.tsx
  • packages/ui/src/components/OrganizationProfile/__tests__/SSOBypassAllowlist.test.tsx
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go (manual)
  • clerk/dashboard (manual)
  • clerk/accounts (manual)
  • clerk/backoffice (manual)
  • clerk/clerk (manual)
  • clerk/clerk-docs (manual)
  • clerk/cloudflare-workers (manual)
  • clerk/cli (auto-detected)
  • clerk/clerk-ios (auto-detected)
  • clerk/clerk-android (auto-detected)

Included review availability: 4 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 8 reviews per hour.


📝 Walkthrough

Walkthrough

The SSO bypass allowlist now supports additions by email or organization role. A bulk API accepts user IDs in batches of up to 100 and returns created entries and per-user errors. The organization profile collects role members, filters existing allowlist entries, and displays added and skipped results. Localization types and locale resources define the updated form and result messages. Appearance handles, password-manager attributes, bundle limits, role-label formatting, and release notes were also updated.

Priority: ➖ Normal

Estimated code review effort: 4 (Complex) | ~60 minutes

Merge Risk: 🔵 Low · up to dd772

Adding members by email or role works as intended. If a later batch fails during a large role-based addition, the page shows an error instead of reporting the members already added. The table still refreshes to show them. Arabic and Traditional Chinese users will not see translated text for the new controls and messages. These issues are limited and can be merged with owner awareness or a quick follow-up.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: adding all members of a selected role to the SSO allow list.
Description check ✅ Passed The description accurately explains role-based bulk additions, batching, skipped members, the custom API, tests, and the related objective.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 49 files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

@changeset-bot

changeset-bot Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 4ea108e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 23 packages
Name Type
@clerk/localizations Minor
@clerk/clerk-js Minor
@clerk/shared Minor
@clerk/ui Minor
@clerk/react Patch
@clerk/chrome-extension Patch
@clerk/electron Patch
@clerk/expo Patch
@clerk/astro Patch
@clerk/backend Patch
@clerk/expo-passkeys Patch
@clerk/express Patch
@clerk/fastify Patch
@clerk/hono Patch
@clerk/mosaic Patch
@clerk/msw Patch
@clerk/nextjs Patch
@clerk/nuxt Patch
@clerk/react-router Patch
@clerk/swingset Patch
@clerk/tanstack-react-start Patch
@clerk/testing Patch
@clerk/vue Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-new Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9826

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9826

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9826

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9826

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9826

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9826

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9826

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9826

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9826

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9826

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9826

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9826

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9826

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9826

@clerk/mosaic

npm i https://pkg.pr.new/@clerk/mosaic@9826

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9826

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9826

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9826

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9826

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9826

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9826

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9826

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9826

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9826

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9826

commit: 4ea108e

@mauricioabreu
mauricioabreu force-pushed the mauricio-antunes/orgs-1852-add-all-members-from-a-given-role branch from 5899c02 to 8fd775a Compare September 18, 2026 19:10
@mauricioabreu mauricioabreu self-assigned this Sep 18, 2026
@mauricioabreu
mauricioabreu force-pushed the mauricio-antunes/orgs-1852-add-all-members-from-a-given-role branch from bdf0d0d to e63703b Compare September 21, 2026 19:57
@mauricioabreu
mauricioabreu marked this pull request as ready for review September 21, 2026 20:08
@mauricioabreu
mauricioabreu force-pushed the mauricio-antunes/orgs-1852-add-all-members-from-a-given-role branch from e63703b to 75c94d0 Compare September 21, 2026 20:11

@dstaley dstaley left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

approved, let's just remove the deprecated localization keys since this feature wasn't ever enabled from the backend

… email or by role

The Add members card offers an Email tab for a single address and a Role tab that adds everyone with that role through the new bulk route, in batches of 100. When nothing could be added the card keeps the form open and says why, below the field; when some were added it moves to a success step that reports the skipped ones in a warning. Role member counts load through useFetch and only once the Role tab is open, and RoleSelect gains a formatLabel hook so the count survives a localized role name. The email lookup pages through search results until it finds an exact match. The allowlist hook refetches even when a batch fails so committed additions show up. On the Security tab the allow list count sits inline with its menu. The member picker's localization keys from 4.18.0 are removed; the feature was never enabled for anyone. The bulk code pushes two bundles past their bundlewatch budgets; pnpm bundlewatch:fix raised them. Inputs flagged ignorePasswordManager now also opt out of Bitwarden, LastPass and Dashlane.
@mauricioabreu
mauricioabreu force-pushed the mauricio-antunes/orgs-1852-add-all-members-from-a-given-role branch from 9d01315 to 4ea108e Compare September 24, 2026 16:16
@mauricioabreu
mauricioabreu merged commit d46b544 into main Sep 24, 2026
51 checks passed
@mauricioabreu
mauricioabreu deleted the mauricio-antunes/orgs-1852-add-all-members-from-a-given-role branch September 24, 2026 16:28

This branch was successfully deployed

2 active deployments
Preview – swingset — 4ea108ee Deployed Sep 24, 2026 by vercel[bot]
Preview – clerk-js-sandbox — 4ea108ee Deployed Sep 24, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants