[@clerk/react-router] sign-in initiated SSO with legal compliance enabled fails on complete-sign-up when signUp.update({ legalAccepted: true }) is called
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 52/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Tranquilla
- Stack tecnologico
- react, typescript
- Ambito
- api, authentication
Direzione di ricerca
Inizia con il flusso di continuazione della registrazione di @clerk/react-router utilizzato da /sign-up/complete/future e confronta signUp.update(...) con clerk.client.signUp.update(...) nel flusso legacy. Usa la riproduzione live collegata con la conformità legale abilitata e verifica che il flusso futuro invii una richiesta di registrazione specifica per l'ID e si completi correttamente con legalAccepted: true.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Preliminary Checks
- I have reviewed the documentation: https://clerk.com/docs
- I have searched for existing issues: https://github.com/clerk/javascript/issues
- I have not already reached out to Clerk support via email or Discord (if you have, no need to open an issue here)
- This issue is not a question, general help request, or anything other than a bug report directly related to Clerk. Please ask questions in our Discord community: https://clerk.com/discord.
Reproduction
Live repro: https://clerk-react-router-legal-repro.vercel.app/
Repository: https://github.com/pplytas/clerk-react-router-legal-repro
Publishable key
pk_test_ZHJpdmVuLW1vbmtmaXNoLTU3LmNsZXJrLmFjY291bnRzLmRldiQ
Description
Steps to reproduce:
- Enable Google SSO and legal compliance in Clerk for the publishable key above.
- Open the live repro.
- Go to
/sign-in. - Click
Continue with Google (future). - Use a Google account that does not already exist in this Clerk instance.
- After the OAuth callback, Clerk transfers the attempt into sign-up and routes to
/sign-up/complete/future. - Fill in first name and last name, check the legal acceptance checkbox, and submit.
- Observe that the request made by
signUp.update(...)targets the client sign-up collection endpoint without a sign-up ID and fails with405 Method Not Allowed.
The repro now also includes a control flow:
- Repeat the same steps with
Continue with Google (legacy), which routes to/sign-up/complete/legacy. - That page uses
clerk.client.signUp.update(...)instead ofsignUp.update(...), so the repro exposes both the new and legacy update paths side-by-side.
Expected behavior:
The continued sign-up flow should accept legalAccepted: true and proceed normally.
More specifically, signUp.update(...) in the custom sign-up continuation flow should update the current sign-up attempt using an ID-aware sign-up endpoint, not the collection endpoint.
Actual behavior:
On the future flow, the request sent by signUp.update(...) does not include a sign-up ID in the path. It hits the collection endpoint shape instead:
PATCH /v1/client/sign_ups?...&_method=PATCH
instead of an ID-specific endpoint shape:
PATCH /v1/client/sign_ups/{sign_up_id}
The result is:
405 Method Not Allowed
and the browser UI then throws:
Failed to execute 'json' on 'Response': Unexpected end of JSON input
The repro now isolates this to the new sign-up completion path by exposing two flows:
future: usessignUp.update(...)legacy: usesclerk.client.signUp.update(...)
The issue is specifically on the future flow. The legacy flow is included as a control for direct comparison.
Environment
System:
OS: macOS 26.3.1
CPU: (8) arm64 Apple M3
Memory: 5.64 GB / 24.00 GB
Shell: 5.9 - /bin/zsh
Binaries:
Node: 24.14.1 - /opt/homebrew/bin/node
npm: 11.11.0 - /opt/homebrew/bin/npm
pnpm: 10.25.0 - /opt/homebrew/bin/pnpm
Watchman: 2026.03.30.00 - /opt/homebrew/bin/watchman
Browsers:
Chrome: 147.0.7727.56
Firefox: 149.0
Safari: 26.3.1
npmPackages:
@clerk/react-router: ^3.1.2 => 3.1.2
@react-router/dev: 7.14.0 => 7.14.0
@react-router/node: 7.14.0 => 7.14.0
@react-router/serve: 7.14.0 => 7.14.0
react: ^19.2.4 => 19.2.5
react-dom: ^19.2.4 => 19.2.5
react-router: 7.14.0 => 7.14.0
- Lingua principale
- TypeScript
- Stelle
- 1.8k
- Fork
- 472
- Merge medio
- 2g 8h
- PR unite (30g)
- 184
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di clerk/javascript
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
clerk/javascript#9611 · 1 commento ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
clerk/javascript#9573 ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 64/100
clerk/javascript#9775 · 1 commento ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
clerk/javascript#9770 · 3 commenti ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 68/100
clerk/javascript#9667 · 1 commento ·
Tutte le issue di clerk/javascript
Issue simili
-
Type/Bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
OpenNSW/nsw-srilanka#497 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
0xMiden/bridge-portal#132 ·
-
react-doctor severity:warning tech-debt
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
digidem/comapeo-cloud-app#403 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100