From 39e0da5c9ea77bc29f5f60d7cf70df272ca8233b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Maur=C3=ADcio=20Antunes?= Date: Fri, 18 Sep 2026 15:44:03 -0300 Subject: [PATCH 1/2] fix(clerk-js): Stop ssoBypassAllowlist from making Organization circular The allowlist helper kept an enumerable reference back to its organization, so JSON.stringify on an Organization (or a User, through its memberships) threw "Converting circular structure to JSON". --- .changeset/sso-bypass-allowlist-circular-ref.md | 5 +++++ packages/clerk-js/src/core/resources/SSOBypassAllowlist.ts | 6 +++++- .../src/core/resources/__tests__/Organization.test.ts | 7 +++++++ 3 files changed, 17 insertions(+), 1 deletion(-) create mode 100644 .changeset/sso-bypass-allowlist-circular-ref.md diff --git a/.changeset/sso-bypass-allowlist-circular-ref.md b/.changeset/sso-bypass-allowlist-circular-ref.md new file mode 100644 index 00000000000..9afade2f53c --- /dev/null +++ b/.changeset/sso-bypass-allowlist-circular-ref.md @@ -0,0 +1,5 @@ +--- +'@clerk/clerk-js': patch +--- + +Fix `JSON.stringify` throwing a circular structure error on `Organization` objects. The `ssoBypassAllowlist` helper kept an enumerable reference back to its organization. diff --git a/packages/clerk-js/src/core/resources/SSOBypassAllowlist.ts b/packages/clerk-js/src/core/resources/SSOBypassAllowlist.ts index 924f48c39c5..4addb975e7a 100644 --- a/packages/clerk-js/src/core/resources/SSOBypassAllowlist.ts +++ b/packages/clerk-js/src/core/resources/SSOBypassAllowlist.ts @@ -12,7 +12,11 @@ import { DeletedObject } from './DeletedObject'; import { SSOBypassAllowlistUser } from './SSOBypassAllowlistUser'; export class SSOBypassAllowlist implements SSOBypassAllowlistResource { - constructor(private readonly organization: { id: string }) {} + declare private readonly organization: { id: string }; + + constructor(organization: { id: string }) { + Object.defineProperty(this, 'organization', { value: organization, enumerable: false }); + } private get path(): string { return `/organizations/${this.organization.id}/sso_bypass_allowlist_users`; diff --git a/packages/clerk-js/src/core/resources/__tests__/Organization.test.ts b/packages/clerk-js/src/core/resources/__tests__/Organization.test.ts index bc0f0ef7665..674fba28e18 100644 --- a/packages/clerk-js/src/core/resources/__tests__/Organization.test.ts +++ b/packages/clerk-js/src/core/resources/__tests__/Organization.test.ts @@ -484,5 +484,12 @@ describe('Organization', () => { expect(result.id).toBe('user_1'); expect(result.deleted).toBe(true); }); + + it('does not create a cycle when the organization is serialized', () => { + const organization = createOrganization(); + + expect(() => JSON.stringify(organization)).not.toThrow(); + expect(JSON.parse(JSON.stringify(organization)).ssoBypassAllowlist).toEqual({}); + }); }); }); From 6c6401fc248c86409cbeba17d8aa7ad869a8d0f1 Mon Sep 17 00:00:00 2001 From: Mauricio Antunes Date: Fri, 18 Sep 2026 15:53:53 -0300 Subject: [PATCH 2/2] chore: don't need a changeset --- .changeset/sso-bypass-allowlist-circular-ref.md | 3 --- 1 file changed, 3 deletions(-) diff --git a/.changeset/sso-bypass-allowlist-circular-ref.md b/.changeset/sso-bypass-allowlist-circular-ref.md index 9afade2f53c..a845151cc84 100644 --- a/.changeset/sso-bypass-allowlist-circular-ref.md +++ b/.changeset/sso-bypass-allowlist-circular-ref.md @@ -1,5 +1,2 @@ --- -'@clerk/clerk-js': patch --- - -Fix `JSON.stringify` throwing a circular structure error on `Organization` objects. The `ssoBypassAllowlist` helper kept an enumerable reference back to its organization.