@clerk/ui@1.34.0
This release renames the SSO fallback feature to SSO bypass and adds tools for Organization admins to manage the SSO bypass allowlist from OrganizationProfile. It also includes UI improvements for enterprise connection management, new phone utilities in @clerk/shared, and several fixes for OAuth flows and account reconnection.
Minor Changes
-
Rename the SSO fallback sign-in flow to SSO bypass, matching the name the feature ships under. The sign-in resource's
ssoFallbackFirstFactorsis nowssoBypassFirstFactorsand reads thesso_bypass_first_factorsfield from the API, thesignIn.ssoFallbacklocalization keys are nowsignIn.ssoBypass, and thessoFallbackcard action element id is nowssoBypass. The flow has not been enabled on any instance, so no application is affected by the old names going away. (#9822) by @mauricioabreu -
Add the ability for Organization admins to manage the SSO bypass allowlist from the Security page of
<OrganizationProfile />. (#9809) by @mauricioabreuFor custom flows,
organization.ssoBypassAllowlistexposesgetUsers(),addUser({ userId })andremoveUser(userId).
Patch Changes
-
Add
@clerk/shared/phonewith Clerk's country metadata and phone-number parsing, formatting, and detection helpers. (#9763) by @Ephem -
Fix reconnecting disconnected Google One Tap accounts in UserProfile to use Google OAuth while preserving session reverification. (#9767) by @wobsoriano
-
Each enterprise connection listed on the organization Security page now opens its own page. It lists the connection name and domains, the service provider values to copy into the identity provider, the identity provider configuration behind an Edit form, and the connection settings as a form you save. The header carries one action, either Activate or Continue setup, and deactivating or removing the connection lives in a Danger zone section at the bottom of the page. The row menu is gone; click the row instead. (#9748) by @NicolasLopes7
The setup wizard's domains step now shows a checkbox per verified domain, so an admin picks which domains a connection covers. A domain another connection of the organization already authenticates is disabled and labelled with that connection's name, and an error from creating the connection is shown on the provider step instead of being dropped.
New customization handles ship with it: the
organizationProfileSecuritySsoConnectionRowandorganizationProfileSecuritySsoConnectionPageappearance elements, theconfigureSSOVerifyDomainCardCheckboxelement, theclaimedbadge id, the newFieldIdvalues for the connection settings, and thessoConnectionName,ssoConnectionDomains,ssoConnectionServiceProvider,ssoConnectionIdentityProvider,ssoConnectionSettingsandssoConnectionDangerZoneProfileSectionIdvalues. -
Add
@clerk/mosaic, an experimental standalone package for next generation Clerk components. (#9765) by @EphemIf you try this out, make sure to pin your version as breaking changes can happen in minors.
-
<OAuthConsent />and<OAuthDeviceVerification />no longer show an empty permissions list when an OAuth client requests only theoffline_accessscope. (#9877) by @wobsoriano -
Add
createDynamicParamParserandpopulateParamFromObjectto@clerk/shared/urlfor resolving:propertyplaceholders in URL templates. (#9761) by @Ephem -
Updated dependencies [
804d3db,64c8e3e,07b4c2b,4e36687,9e7485c]:- @clerk/shared@4.34.0
- @clerk/localizations@4.18.0
Source: original entry ↗