megachangelog
Feature4.32.0

@clerk/shared@4.32.0

This release introduces self-serve Directory Sync (SCIM) capabilities and adds SSO fallback sign-in flow to the SignIn component, allowing enterprise users to sign in with email code when their identity provider is unreachable. JSDoc documentation links were also updated to match new URL anchors.

Minor Changes

  • Introduce self-serve Directory Sync (SCIM) capabilities and related functionality. (#9590) by @kalafut

  • Add the SSO fallback sign-in flow to <SignIn />, for enterprise users the instance has allowlisted to sign in with an email code when they cannot reach their identity provider. (#9685) by @mauricioabreu

    For such a user the sign-in no longer redirects straight to the identity provider. It shows the SSO action — or the connection picker, when several connections serve the address — alongside a "Can't use SSO?" link leading to the standard email code step, which carries a notice that the organization requires single sign-on and that the attempt is recorded. Users without a fallback, and instances without the feature, are unaffected.

    Custom flows can read the same factor from the new ssoFallbackFirstFactors property on the sign-in resource. The flow adds the signIn.enterpriseSSO and signIn.ssoFallback localization keys and the ssoFallback card action element id.

Patch Changes

  • Update docs deep links in JSDoc comments to match clerk.com's new heading anchors (#get-token is now #gettoken, #o-auth-strategy is now #oauthstrategy, and so on). (#9520) by @manovotny
authssoscimenterprisesignin

Source: original entry ↗