Skip to content

feat(mosaic): wire up user profile passkeys - #9983

Merged
austincalvelage merged 16 commits into
mainfrom
austin/pass-keys-wire-up
Oct 7, 2026
Merged

austincalvelage merged 16 commits into
mainfrom
austin/pass-keys-wire-up

Conversation

@austincalvelage

@austincalvelage austincalvelage commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Description

Wire the Mosaic passkeys section to Clerk so users can create a passkey with their authenticator, rename it, and remove it through the confirmation dialog. Show pending states, prevent duplicate actions, preserve rename drafts after failures, and restore focus after removal. Use the configured locale for passkey errors and dates.

Keep eligibility, SDK calls, and error translation in the separate model file. Reset dialogs and feedback when the user or session changes, and recheck the current account and policy before mutations. Compose the security panel with a resolved passkeys slot following the Password pattern, so hidden content cannot leave an empty Authentication heading. Respect enterprise restrictions and hide Add on satellite applications.

Add a Swingset live page at /live/passkeys. The stateful fake FAPI models passkey eligibility, quota, pending ownership, verified response metadata, and the backend name limit.

Session reverification UI remains deferred with explicit feature-test TODOs. Requests that require reverification surface the API error.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-bot Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: af42c2b

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercel Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
clerk-js-sandbox Ready Ready Preview Oct 7, 2026 8:23pm UTC
swingset Ready Ready Preview Oct 7, 2026 8:23pm UTC

Request Review

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Team

Run ID: b402a260-9bb0-4a69-8cc7-e8f58a9da64c

📥 Commits

Reviewing files that changed from the base of the PR and between d7731c2 and 0ca1edf.

📒 Files selected for processing (1)
  • packages/mosaic/src/features/user-profile/__tests__/user-profile-passkeys-section.feature.test.tsx
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

Included review availability: This review used your included allowance. 7 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 10 reviews per hour.


📝 Walkthrough

Walkthrough

Mosaic adds passkey creation, verification, renaming, and removal flows, with checks for account ownership and passkey eligibility. The user-profile security panel now accepts passkey content through a slot. The changes add passkey localization, a live passkeys page, and FAPI test handlers and fixtures. New tests cover passkey flows, validation, account changes, and security-panel composition.

Priority: ➖ Normal

Estimated code review effort: 4 (Complex) | ~60 minutes

Merge Risk: 🔵 Low · up to 0ca1e

The fake API can accept more passkeys than the backend limit, reducing confidence in quota-related tests. This is a bounded test-fidelity risk, so the change is mergeable with owner awareness.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 3.77% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 53 functions across 36 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description check ✅ Passed The description clearly explains the Mosaic passkeys integration, related behavior, tests, and live page changes.
Title check ✅ Passed The title clearly and concisely identifies the main change: wiring user profile passkeys into Mosaic.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@austincalvelage
austincalvelage force-pushed the austin/enterprise-accounts-wire-up branch 4 times, most recently from 58c24d4 to 6dd278a Compare October 1, 2026 18:13
@austincalvelage
austincalvelage force-pushed the austin/pass-keys-wire-up branch from c6994fe to 1db43a1 Compare October 1, 2026 18:40
@austincalvelage
austincalvelage force-pushed the austin/pass-keys-wire-up branch from 1db43a1 to 92d3b75 Compare October 2, 2026 15:48
@austincalvelage
austincalvelage changed the base branch from austin/enterprise-accounts-wire-up to main October 2, 2026 15:49

This branch was successfully deployed

2 active deployments
Preview – swingset — af42c2b1 Deployed Oct 7, 2026 by vercel[bot]
Preview – clerk-js-sandbox — af42c2b1 Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants