diff --git a/.changeset/electron-allowed-origins-dev-server.md b/.changeset/electron-allowed-origins-dev-server.md new file mode 100644 index 00000000000..d88d1ac39c2 --- /dev/null +++ b/.changeset/electron-allowed-origins-dev-server.md @@ -0,0 +1,5 @@ +--- +'@clerk/backend': patch +--- + +Update the `allowedOrigins` JSDoc on `clerkClient.instances.update()` and the `Instance` resource to note that Electron apps using `@clerk/electron` also need the renderer's dev server origin, for example `http://localhost:5173`, during development. diff --git a/packages/backend/src/api/endpoints/InstanceApi.ts b/packages/backend/src/api/endpoints/InstanceApi.ts index cabb90f5c09..c7eb452179f 100644 --- a/packages/backend/src/api/endpoints/InstanceApi.ts +++ b/packages/backend/src/api/endpoints/InstanceApi.ts @@ -20,7 +20,7 @@ export type UpdateParams = { clerkJsVersion?: string | null | undefined; /** The development origin for the instance. */ developmentOrigin?: string | null | undefined; - /** For browser-like stacks such as browser extensions, Electron, or Capacitor.js, the instance allowed origins need to be updated with the request origin value. For Chrome extensions popup, background, or service worker pages the origin is `chrome-extension://extension_uiid`. For Electron apps using `@clerk/electron`, the origin is the custom renderer scheme registered with `createClerkBridge()`, for example `my-app://renderer`. For Capacitor.js, the origin is `capacitor://localhost`. */ + /** For browser-like stacks such as browser extensions, Electron, or Capacitor.js, the instance allowed origins need to be updated with the request origin value. For Chrome extensions popup, background, or service worker pages the origin is `chrome-extension://extension_uiid`. For Electron apps using `@clerk/electron`, the origins are the custom renderer scheme registered with `createClerkBridge()`, for example `my-app://renderer`, and, during development, the renderer's dev server origin, for example `http://localhost:5173`. For Capacitor.js, the origin is `capacitor://localhost`. */ allowedOrigins?: Array | undefined; /** Whether the instance should use URL-based session syncing in development mode (i.e., without third-party cookies). */ urlBasedSessionSyncing?: boolean | null | undefined; diff --git a/packages/backend/src/api/resources/Instance.ts b/packages/backend/src/api/resources/Instance.ts index 15092579b5f..64b54751dc4 100644 --- a/packages/backend/src/api/resources/Instance.ts +++ b/packages/backend/src/api/resources/Instance.ts @@ -7,7 +7,7 @@ export class Instance { readonly id: string, /** The type of instance environment, either `'production'` or `'development'`. */ readonly environmentType: string, - /** For browser-like stacks such as browser extensions, Electron, or Capacitor.js, the instance allowed origins need to be updated with the request origin value. For Chrome extensions popup, background, or service worker pages the origin is `chrome-extension://extension_uiid`. For Electron apps using `@clerk/electron`, the origin is the custom renderer scheme registered with `createClerkBridge()`, for example `my-app://renderer`. For Capacitor.js, the origin is `capacitor://localhost`. */ + /** For browser-like stacks such as browser extensions, Electron, or Capacitor.js, the instance allowed origins need to be updated with the request origin value. For Chrome extensions popup, background, or service worker pages the origin is `chrome-extension://extension_uiid`. For Electron apps using `@clerk/electron`, the origins are the custom renderer scheme registered with `createClerkBridge()`, for example `my-app://renderer`, and, during development, the renderer's dev server origin, for example `http://localhost:5173`. For Capacitor.js, the origin is `capacitor://localhost`. */ readonly allowedOrigins: Array | null, ) {}