megachangelog
Feature1.33.0

@clerk/ui@1.33.0

Added self-serve Directory Sync (SCIM) capabilities and SSO fallback sign-in flow for enterprise users who cannot reach their identity provider. Fixed OAuth sign-ups from openSignIn with withSignUp: true incorrectly landing on sign-in page with an error.

Minor Changes

  • Introduce self-serve Directory Sync (SCIM) capabilities and related functionality. (#9590) by @kalafut

  • Add the SSO fallback sign-in flow to <SignIn />, for enterprise users the instance has allowlisted to sign in with an email code when they cannot reach their identity provider. (#9685) by @mauricioabreu

    For such a user the sign-in no longer redirects straight to the identity provider. It shows the SSO action — or the connection picker, when several connections serve the address — alongside a "Can't use SSO?" link leading to the standard email code step, which carries a notice that the organization requires single sign-on and that the attempt is recorded. Users without a fallback, and instances without the feature, are unaffected.

    Custom flows can read the same factor from the new ssoFallbackFirstFactors property on the sign-in resource. The flow adds the signIn.enterpriseSSO and signIn.ssoFallback localization keys and the ssoFallback card action element id.

Patch Changes

  • Fixed OAuth sign-ups from openSignIn({ withSignUp: true }) landing on the sign-in page with an "External Account was not found" error instead of creating the account. (#9758) by @wobsoriano

  • Updated dependencies [b5a3abe, ddf9afc, f21352f, 2502266, 607d561, 39782e3]:

    • @clerk/localizations@4.17.0
    • @clerk/shared@4.32.0
authssosigninenterpriseoauth

Source: original entry ↗