Conversation
🦋 Changeset detectedLatest commit: 997b6d9 The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueComment |
c640b20 to
2b03817
Compare
ce8ac2f to
92c610f
Compare
2b03817 to
b90dc86
Compare
|
Recorded on a physical iPhone Air (iOS 27) with the full stack (#9955 → #9962) in an Expo SDK 57 app:
A system notification near the top of the screen is blurred between about 0:04 and 0:26. biometrics-device-redacted.mp4 |
b90dc86 to
a5deef3
Compare
92c610f to
22d69b5
Compare
22d69b5 to
31d5f90
Compare
a5deef3 to
f6afce5
Compare
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
getAvailability() and signIn() report biometric_authentication_unavailable before reading local records when @clerk/expo-biometrics reports no secure key storage, and enroll() maps its secure_key_storage_unavailable rejection to biometric_authentication_unavailable before contacting Clerk. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
31d5f90 to
9ab9910
Compare
f6afce5 to
997b6d9
Compare
Description
useBiometricCredentials()(and the deprecateduseTrustedDevices()wrapper) now run enrollment, listing, revocation and sign-in in JS. clerk-js talks to FAPI through the experimental trusted device resources from #9953, and@clerk/expo-biometrics(#9959) handles only keys, signing and on-device records. Before this change, these calls went through theClerkExponative module in@clerk/expo-native-components.@clerk/expo-biometricsis an optional peer dependency. It is loaded with a guardedrequire. When it is missing, or the development build doesn't include its native module, the hook's methods throw an error that explains how to install it and rebuild. Web keeps the existing unsupported stub.BiometricCredentials.swift:nativeSettings.id, then identifier hint, newest first.createKey→ prepare → sign → attempt →saveRecord({ removeOtherRecordsForApp: true }). If prepare, sign or attempt fails, the key is deleted. If saving the record fails, the server credential is revoked and the key is deleted.signIn.create→ signtrustedDeviceChallenge.clientData→attemptFirstFactor. The local record is forgotten onform_resource_not_found/trusted_device_not_registeredfortrusted_device_id, and onkey_invalidated/key_not_found.identifierHintSha256withhashIdentifierHint(). A small compatibility shim falls back to the normalized rawidentifierHintuntil the Android PR adds those members.codeis the API error code, as the native bridge did, with the originalClerkAPIResponseErrorascause. Device errors are mapped to the existingBiometricCredentialErrorCodevalues.reverify()stays on the@clerk/expo-native-componentspath unchanged. FAPI only liststrusted_devicereverification factors from API version 2026-08-20. Its error now names@clerk/expo-native-componentswhen that package is missing.ClerkExpomodule spec types. The Swift/Kotlin implementations will be removed in a follow-up.Stack: #9955 ← #9957 ← #9954 ← #9956 ← #9958 ← #9953 ← #9959 ← this PR. This PR will be rebased onto the
@clerk/expo-biometricsAndroid PR once it's open.Checklist
pnpm testruns as expected.pnpm buildruns as expected.Type of change
🤖 Generated with Claude Code