Repository navigation
Conversation
🦋 Changeset detectedLatest commit: 9c6673f The changes in this PR will be included in the next version bump. This PR includes changesets to release 0 packagesWhen changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (1)
🔗 Linked repositories identifiedCodeRabbit considers these linked repositories for cross-repo context during reviews:
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 3 remain after this review. 📝 WalkthroughWalkthroughAdds the Priority: ➖ Normal Estimated code review effort: 5 (Critical) | ~120 minutes Merge Risk: 🔵 Low · up to The verification tool can lose run evidence or encounter cleanup, duplicate-runner, and proxy-check failures in specific conditions. These are bounded workflow risks; merge is possible with owner awareness and follow-up. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Comment |
160b44a to
729ecd1
Compare
729ecd1 to
2d05137
Compare
2d05137 to
43ca8cc
Compare
43ca8cc to
e31b477
Compare
caefb95 to
8647439
Compare
b0d1508 to
249bffc
Compare
9b925c9 to
e0f90bd
Compare
…ring Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…roker, secrets, and evidence Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…on per worktree Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Description
Adds
verify-clerk-expo, a skill and a CLI that an agent or a developer uses to prove a@clerk/expochange on an iOS simulator or an Android emulator. It builds theexpo-nativefixture, launches it with the inputs from #10052, runs tests against a Clerk application that it creates and deletes, and keeps a video and screenshots of each run. The device is on the machine that runs the CLI.It sits on #10052. #10090, on top of this, runs the same tests in CI. #10131, on top of #10090, lets a machine that cannot run a device borrow one on a CI runner.
The seven commits are in dependency order, and each adds one part.
package-lock.jsoncontrol-clerk-expocommand, and the ignore and lint settings that keep its files out of the rest of the repo's way. Most of the lines are the generated lockfile.expo-nativefixture, install it on the simulator or emulator, and launch it.specs/fixtures.tsin commit 5, and most of commit 6 are the same files, byte for byte, in clerk/clerk-ios#629 and clerk/clerk-android#1046.src/core/MANIFESTlists them with their hashes, and a unit test fails when one drifts. Review them once, in whichever of the three pull requests you read first.The unit tests for all of the code arrive together in commit 6, so the commits before it do not pass a test run by themselves.
The skill is in
.claude/skills/verify-clerk-expo/, and.cursor/skills/verify-clerk-expois a symlink to it. The CLI isbin/control-clerk-expo.packages/expo/AGENTS.mdhas the short instructions and the rootAGENTS.mdpoints to them.To review, read
SKILL.md, thensrc/host.tsandsrc/fixture.ts, thenspecs/golden/. Most of the 17,753 added lines are the lockfile and files shared with the verification skills of clerk-ios (clerk/clerk-ios#629) and clerk-android (clerk/clerk-android#1046):src/core/,src/platform/ios/,src/platform/android/,specs/fixtures.ts,testing/, and every test file buttest/host.test.tsandtest/freshness.test.ts.src/core/MANIFESTlists the hashes of the core files, and a unit test anddoctorfail when one differs..prettierignoreleaves the shared files alone.To try it on a Mac with Xcode, Node 24.8 or newer, and the team's Clerk Platform API key:
doctoronly reads, and prints a fix for each thing the machine lacks.runbuilds the fixture as a Debug dev client, creates the application, takes a simulator that the CLI cloned for itself, starts Metro andtsdown --watchinpackages/expo, and runs the tests. A later JS edit reaches the app on the nextrunwith no native build.downreleases the device and deletes the application with every user in it. The evidence stays in.verify/runs/<run-id>/.The 22 tests are in
specs/golden/, in seven groups.native-auth-viewAuthView, its React Native logo, and a sign-in through ituser-button-and-profileUserButton, the profile it opens, the home's sign-out, and an inlineUserProfileViewwithonHostBackand a custom pagecustom-flow-sign-inuseSignIncustom-flow-sign-upuseSignUptoken-cache-persistencenative-js-syncuseAuth,useUser, anduseSessionnative-modulesuseSignInWithGoogleopening the native Google sign-in and reporting a cancel, anduseBiometricCredentialsgiving the native module's answerEvery test starts at the fixture's home and taps to the screen it needs, as a user would.
host.launchtakes no screen. Its options still choose who is signed in, the mode ofAuthView, and whether storage is kept from the last launch.specs/native.tsholds the locators of the home's buttons, and a unit test fails when they differ from the fixture's.The tests assert on what a user sees. They look in the prebuilt views first, for example the address on the code screen of
AuthViewor the email underManage account. For the outcome of a flow they read the fixture's home, which showsSigned outandSign in, orSigned in as <email>, the user ID, the session ID, andSign out. Android tests find the prebuilt views by text, because the clerk-android release that@clerk/expopins has no test tags. iOS tests use theclerk.*accessibility identifiers. Tests type only+clerk_testaddresses and the test code424242. Seven tests type a code or a password and carry the tagform-entry, so a runtime that must not type them passes--skip form-entry. Three tests are for iOS only, so Android runs 19.The two
native-modulestests sign no one in. The Google test tapsSign in with Googleand cancels what opens. On iOS it waits for the system prompt that namesaccounts.google.comand dismisses it. On Android it waits until Google's page covers the fixture's button, then tapsSkipwhen the page has one and presses back when it does not, until the fixture is on screen again. On both it expectsGoogle sign-in was cancelled. On Android it asserts on none of Google's text, because what Google Play services shows on an emulator with no Google account differs between images. The test proves that the hook reads the fixture's placeholder client IDs and reaches the native module, and that the module opens Google's sign-in and reports a cancel. It does not prove that a Google account can sign in, or anything about the ID token and the Clerk sign-in that follow. On iOS no Google page loads, because the cancel is at the system prompt.The biometrics test has a settings file beside it,
biometric-availability.settings.json, which turns biometric sign-in on for the instance, andrunapplies it before that file's test. The test expectsbiometric availability: biometric_authentication_unavailableon iOS, where the simulator has no Secure Enclave, andbiometric availability: no_local_credentialon Android, where the emulator has key storage and no stored credential. Both answers come from native code. On the standard settings the hook answersfeature_disabledfrom JS, and the test fails. The test does not prove enrolling, storing, or signing in with a biometric, and neither answer changes when a biometric is enrolled on the device.Four things keep a run steady on a slow device.
host.taptaps again while a screen transition still covers the control, until the control is free or the tap times out. A launch opens the app a second time if the first try fails. Typing waits 40 ms between characters, and a test has 240 seconds.No test is tagged
known-bug. The close-button test of a full-screenAuthViewinnative-auth-view/opensruns with the rest, because #10079 is onmainand in this branch.runleaves out a test with that tag unless--include known-bugis passed.Each worktree gets one Clerk application in a workspace that holds nothing else, with the settings in
src/core/instances/base.json. The CLI creates it with the Platform API key, which comes from the environment, a file, or a 1Password reference kept outside the repository. No file holds the application's secret key. Each command that needs it reads it from the Platform API and keeps it in memory until the command ends. After a run, the CLI searches the run directory for every secret the run used, andattachrefuses to post a run that holds one.The skill also configures e2e's built-in agent, for tests that act on the app or judge a screen with a model. It does so only when the machine has a Vercel AI Gateway key. The model is
anthropic/claude-haiku-5.5, withopenai/gpt-6-luna-fastas a backup that the gateway uses when the first model fails. No committed test uses the agent, and no workflow passes a key.The skill installs
e2e0.18.0,@e2e-dev/mobile0.10.0,@e2e-dev/github0.4.0, andai7.0.128 withnpm cifrom its own lockfile, outside the pnpm workspace. TheVerify Skill Testsjob added toci.ymlruns the skill's 397 unit tests andtscon Linux, with no device and no secret, when a pull request changes the skill or a path its tests read. On a Mac at this head, the 397 tests pass andtscis clean.Nothing in this pull request runs a test on a device in CI. The workflow in #10090 runs the 22 tests on a commit that contains this one.
The last run of that workflow that passed is run 37685636703, started by hand: 22 of 22 tests on iOS and 19 of 19 on Android, where three tests are for iOS only. No test needed its retry. The files it ran on included the borrowed-device code that is now in #10131, the older
native-modulestests, and a fixture without the Google client IDs.A later run on the present
native-modulestests, run 37706627405, failed its Android job on the Google test. The CI emulator showed a Google Play services page that the back button does not cancel. The test now tapsSkipon that page. No runner has run that step yet.A local run on an iOS simulator passed 22 of 22 on an earlier head of #10090 that already had no borrowed-device code. Since that head, only the Google test and its feature file have changed, and the test's iOS steps are the same. Android was not run locally at that head.
The workflow from #10090 passed, started by hand on files identical to its present head, in run 37709561872: 22 of 22 tests on iOS and 19 of 19 on Android, where three tests are for iOS only. The Google test passed on both platforms on its first attempt. One iOS test,
custom-flow-sign-in/complete, passed on its retry: the first attempt typed five of the six digits of the test code.Not proven here:
Skip.Checklist
pnpm testruns as expected.pnpm buildruns as expected.Type of change
🤖 Generated with Claude Code