Repository navigation
feat(mosaic): wire up user profile passkeys - #9983
Conversation
🦋 Changeset detectedLatest commit: af42c2b The changes in this PR will be included in the next version bump. This PR includes changesets to release 0 packagesWhen changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository YAML (base), Organization UI (inherited) Review profile: ASSERTIVE Plan: Team Run ID: 📒 Files selected for processing (1)
🔗 Linked repositories identifiedCodeRabbit considers these linked repositories for cross-repo context during reviews:
Included review availability: This review used your included allowance. 7 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 10 reviews per hour. 📝 WalkthroughWalkthroughMosaic adds passkey creation, verification, renaming, and removal flows, with checks for account ownership and passkey eligibility. The user-profile security panel now accepts passkey content through a slot. The changes add passkey localization, a live passkeys page, and FAPI test handlers and fixtures. New tests cover passkey flows, validation, account changes, and security-panel composition. Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~60 minutes Merge Risk: 🔵 Low · up to The fake API can accept more passkeys than the backend limit, reducing confidence in quota-related tests. This is a bounded test-fidelity risk, so the change is mergeable with owner awareness. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Comment |
58c24d4 to
6dd278a
Compare
c6994fe to
1db43a1
Compare
1db43a1 to
92d3b75
Compare
35f9699 to
b095076
Compare
b095076 to
7856ef9
Compare
Description
Wire the Mosaic passkeys section to Clerk so users can create a passkey with their authenticator, rename it, and remove it through the confirmation dialog. Show pending states, prevent duplicate actions, preserve rename drafts after failures, and restore focus after removal. Use the configured locale for passkey errors and dates.
Keep eligibility, SDK calls, and error translation in the separate model file. Reset dialogs and feedback when the user or session changes, and recheck the current account and policy before mutations. Compose the security panel with a resolved passkeys slot following the Password pattern, so hidden content cannot leave an empty Authentication heading. Respect enterprise restrictions and hide Add on satellite applications.
Add a Swingset live page at
/live/passkeys. The stateful fake FAPI models passkey eligibility, quota, pending ownership, verified response metadata, and the backend name limit.Session reverification UI remains deferred with explicit feature-test TODOs. Requests that require reverification surface the API error.
Checklist
pnpm testruns as expected.pnpm buildruns as expected.Type of change