Repository navigation
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Contributor
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Comment |
🦋 Changeset detectedLatest commit: ea5fc27 The changes in this PR will be included in the next version bump. This PR includes changesets to release 0 packagesWhen changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
mikepitre
force-pushed
the
mike/expo-verify-borrowed-device
branch
from
October 8, 2026 00:47
8df30c1 to
3f84067
Compare
mikepitre
force-pushed
the
mike/expo-verify-borrowed-device
branch
from
October 8, 2026 00:50
3f84067 to
a8d3a72
Compare
mikepitre
force-pushed
the
mike/expo-verify-borrowed-device
branch
from
October 8, 2026 04:37
a8d3a72 to
888ca43
Compare
mikepitre
force-pushed
the
mike/expo-verify-borrowed-device
branch
from
October 8, 2026 12:03
888ca43 to
82c1950
Compare
mikepitre
force-pushed
the
mike/expo-verify-borrowed-device
branch
from
October 8, 2026 14:19
82c1950 to
e30aa43
Compare
mikepitre
force-pushed
the
mike/expo-verify-borrowed-device
branch
from
October 8, 2026 16:49
6a7fa08 to
dfba920
Compare
mikepitre
force-pushed
the
mike/expo-verify-borrowed-device
branch
from
October 8, 2026 20:40
dfba920 to
c11bb10
Compare
mikepitre
force-pushed
the
mike/expo-verify-borrowed-device
branch
from
October 8, 2026 20:46
c11bb10 to
4d2e482
Compare
mikepitre
added this pull request to stack #10100
October 8, 2026 22:12
| } | ||
|
|
||
| function bearer(req: IncomingMessage): string | null { | ||
| return /^Bearer\s+(.+)$/i.exec((req.headers.authorization ?? '').trim())?.[1] ?? null; |
mikepitre
force-pushed
the
mike/expo-verify-borrowed-device
branch
from
October 9, 2026 01:04
4d2e482 to
e3b38b3
Compare
@clerk/astro
@clerk/backend
@clerk/chrome-extension
@clerk/clerk-js
@clerk/electron
@clerk/electron-passkeys
@clerk/eslint-plugin
@clerk/expo
@clerk/expo-biometrics
@clerk/expo-google-signin
@clerk/expo-passkeys
@clerk/express
@clerk/fastify
@clerk/hono
@clerk/localizations
@clerk/mosaic
@clerk/nextjs
@clerk/nuxt
@clerk/react
@clerk/react-router
@clerk/shared
@clerk/tanstack-react-start
@clerk/testing
@clerk/ui
@clerk/upgrade
@clerk/vue
commit: |
1 of 9 tasks
`attach` posted the video and screenshots of a run as a pull request comment. It now writes them into the description with `gh pr edit --attach`, in one block between two HTML comments that name the platform. A later `attach` replaces the block, so the description holds the latest run. Everything outside the block is passed back as it was read. `attach` reads the description again just before it writes. If the description changed, it rebuilds on the new text once, and fails if it changed again. It refuses a description whose markers are doubled, halved, or out of order. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
mikepitre
force-pushed
the
mike/expo-verify-borrowed-device
branch
from
October 9, 2026 04:58
e3b38b3 to
ea5fc27
Compare
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
The end-to-end tests in #10087 run on a simulator or an emulator on the machine that runs their CLI, so they need a Mac for iOS and hardware virtualization for Android. An agent in a cloud sandbox often has neither. This PR adds a second backend to that CLI. On a machine that cannot run the device,
upstarts a session on a GitHub Actions runner, and the CLI drives the device there through a tunnel, with the same verbs, tests, and evidence. No session has been started from the commits in this PR.The tests and the CLI are the package
integration/expo-native/, and theverify-clerk-exposkill is the instructions that point an agent at it. The stack is #10052, then #10087, then #10090, then this one, then #10163, which adds the upload workflow. Nothing in the first three needs it.Five commits, in dependency order.
attachwrite a run's video and screenshots into the pull request description, in one block per platform that a laterattachreplaces. In #10087 it posts a comment.src/fixture.ts,src/platform/android/emulator.ts, andsrc/core/in commit 2 hold every edit to code that #10087 and #10090 added.Commit 1 has its own unit tests. The unit tests for commits 2 and 3 arrive in commit 4.
Everything under
integration/expo-native/src/core/andintegration/expo-native/specs/support/, and most of the unit tests, are the same files, byte for byte, in clerk/clerk-ios#661 and clerk/clerk-android#1069.src/core/MANIFESTlists every shared file with its hash, and a unit test fails when one drifts. Review them once.What changes:
--backend remoteondoctor,up, andrunforces the remote backend. With no flag the CLI picks the local backend where the machine can run the device and the remote one anywhere else, and its first line says which and why. A worktree keeps the backend it started with untildown.verify-remote.ymlruns one session for either platform. It builds the pushed commit, never the working tree, as a Release app with the JS embedded, so the device needs no Metro. It boots the device, records the video, and ends ondown, after 15 idle minutes, or at 60 minutes.--runner <label>onuporrunnames the runner for a new session. The defaults aremacos-26for iOS andubuntu-24.04for Android.doctorchecks that GitHub has HEAD and that this machine reaches GitHub, the tunnel host, and Clerk. It starts nothing without--live.doctor --livestarts one short session and stops it.run.jsongainsremote, with the provider, the runner label, and the commit the session built. It isnullfor a local run.downends the runner job.down --stalealso ends a session that a crashed run of the same checkout left running.ghcannot attach files,attachhands the video and screenshots to the session's runner through the tunnel, and the runner keeps them as the artifactverify-evidence.references/remote.md.Expo Native Runner Testsjob inci.ymlnow also runs whenverify-remote.ymlchanges, because a unit test reads that file.In the package,
test/remote-host.test.tsis this repository's own. It also holds the unit tests of the two build products and the fixture build from #10087 and #10090.To try it, on any machine with Node 24.8 or newer, the team's Clerk Platform API key, and push access to this repository:
On a machine that cannot run the device, leave out
--backend remote. On a free runner labeluptakes tens of minutes, nearly all of it the build.Someone with write access starts a session, by
workflow_dispatchonly. The workflow has nopull_requestorpushtrigger and uses no repository or environment secret. Its onepermissionsblock iscontents: read, so no job can write to the repository. The step that reads the request uses the job's own read-only token to check the requested commit. A session starts only for the commit the run was dispatched on, or for a later commit of that branch.Every route on the tunnel answers 403 without a bearer token that the CLI made. The token stays under
integration/expo-native/.verify/remote/on the machine that started the session. The workflow gets only its SHA-256. The tunnel is a Cloudflare quick tunnel, so Cloudflare can read the traffic, which includes sign-in tickets for test users. The Clerk application is a throwaway one thatdowndeletes, and the runner never gets a secret key.A session costs nothing on the default labels, which are free for a public repository and slow.
--runner blacksmith-6vcpu-macos-26for iOS or--runner blacksmith-8vcpu-ubuntu-2204for Android is faster and billed by the minute.A run on a machine's own device takes the same path as before this PR. Apart from
attach, the new code runs only when the CLI picks the remote backend, and the workflow in #10090 does not use it. Outside the package and the skill directory, this PR addsverify-remote.yml, an empty changeset, one path inci.yml, one line in.prettierignore, and an edit to the skill's row in.claude/skills/README.md.Checklist
pnpm testruns as expected.pnpm buildruns as expected.Type of change
🤖 Generated with Claude Code