Skip to content

feat(oauth): passkey enrollment after a legacy provider sign-in - #156

Merged
Bccorb merged 2 commits into
mainfrom
feat/oauth-cutover
Oct 6, 2026
Merged

Bccorb merged 2 commits into
mainfrom
feat/oauth-cutover

Conversation

@Bccorb

@Bccorb Bccorb commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Part of fells-code/seamless-auth-api#337 (epic fells-code/seamless-auth-api#334). Client side of fells-code/seamless-auth-api#346.

Changes

  • @seamless-auth/types goes from ^0.20.0 to ^0.25.0 in client, react and react-native. Nothing else needed changing for the jump.
  • getOAuthErrorCode recognises oauth_provider_retired and oauth_invalid_id_token. The exhaustive Record<OAuthErrorCode, …> maps would not compile without them.
  • The bundled OAuthCallback sends the user to /register-passkey when the sign-in response carries nextStep: 'enroll_passkey'. The API only sends it for providers with promptPasskeyEnrollment set, and only when the user has no passkey. The in-app returnTo goes along in router state.
  • The passkey screen continues to that destination after registering or skipping, instead of always /. Only an in-app path is followed: //host, /\host, absolute URLs and non-strings fall back to /.
  • The callback shows a specific message for each of the two new codes.

Checks

From a clean npm ci: lint, typecheck, format:check, npm test -- --runInBand (37 suites, 434 tests), build and check-npm-build all pass.

verify / verify will fail for a reason outside this PR. The conformance run builds seamless-templates' react-vite template against React main, and that template still imports AuthRoutes from the package root, which #153 moved to @seamless-auth/react/routes. The template can only switch once a React release with /routes is published.

Base automatically changed from fix/ci-react-router-dev-dependency to main October 6, 2026 01:20
Bccorb added 2 commits October 5, 2026 21:36
Route nextStep: 'enroll_passkey' from the OAuth callback into passkey
enrollment, carrying returnTo through it, and recognise the
oauth_provider_retired and oauth_invalid_id_token codes.

Part of fells-code/seamless-auth-api#337.
@Bccorb
Bccorb force-pushed the feat/oauth-cutover branch from 604a361 to 8bb6371 Compare October 6, 2026 01:36
@Bccorb
Bccorb merged commit 0dfe622 into main Oct 6, 2026
2 of 3 checks passed
@Bccorb
Bccorb deleted the feat/oauth-cutover branch October 6, 2026 01:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant