Skip to content

fix(ui): Don't label agent sessions as impersonation in Active devices - #10015

Open
djgould wants to merge 1 commit into
mainfrom
devin/determined-rubin-fa701a
Open

djgould wants to merge 1 commit into
mainfrom
devin/determined-rubin-fa701a

Conversation

@djgould

@djgould djgould commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Description

The Active devices list in <UserProfile /> treated every session with an actor as impersonation, including Agent Task sessions (actor.type === 'agent'). This applies the agent exclusion ImpersonationFab already uses (#7933).

FAPI only lists actor sessions when the current session also has an actor, so this shows up when an agent or an impersonator views the list:

  • Agent viewing: "This device" is no longer red, the user's other devices no longer get "User device", and other agent sessions no longer get "Other impersonator device".
  • Impersonator viewing: agent sessions get "User device" instead of "Other impersonator device".

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@changeset-bot

changeset-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 1b28395

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
Name Type
@clerk/ui Patch
@clerk/chrome-extension Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
clerk-js-sandbox Ready Ready Preview Oct 1, 2026 2:58pm UTC
swingset Ready Ready Preview Oct 1, 2026 2:58pm UTC

Request Review

@github-actions github-actions Bot added the ui label Oct 1, 2026
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
.cursor/rules/typescript.mdc — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Team

Run ID: 093454d2-e1ef-4726-ae49-b09a5e548eec

📥 Commits

Reviewing files that changed from the base of the PR and between 2eae624 and 1b28395.

📒 Files selected for processing (3)
  • .changeset/active-devices-agent-sessions.md
  • packages/ui/src/components/UserProfile/ActiveDevicesSection.tsx
  • packages/ui/src/components/UserProfile/__tests__/SecurityPage.test.tsx
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

Included review availability: This review used your included allowance. 9 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 10 reviews per hour.


📝 Walkthrough

Walkthrough

Active device badge classification now distinguishes agent sessions from impersonation sessions. A SecurityPage test covers agent, impersonator, and null-actor sessions. A patch changeset documents the badge changes in <UserProfile />.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: ⚪ Minimal · up to 1b283

This change stops agent sessions from being labeled as impersonation in the Active devices list. No merge-blocking risk was found.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description check ✅ Passed The description directly explains the Active devices labeling bug and the behavior changes for agent and impersonator sessions.
Title check ✅ Passed The title clearly and concisely identifies the UI bug: agent sessions were incorrectly labeled as impersonation in Active devices.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 1, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@10015

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@10015

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@10015

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@10015

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@10015

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@10015

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@10015

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@10015

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@10015

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@10015

@clerk/express

npm i https://pkg.pr.new/@clerk/express@10015

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@10015

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@10015

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@10015

@clerk/mosaic

npm i https://pkg.pr.new/@clerk/mosaic@10015

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@10015

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@10015

@clerk/react

npm i https://pkg.pr.new/@clerk/react@10015

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@10015

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@10015

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@10015

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@10015

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@10015

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@10015

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@10015

commit: 1b28395

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-10-01T15:00:28.913Z

Summary

Metric Count
Packages analyzed 19
Packages with changes 1
🔴 Breaking changes 1
🟡 Non-breaking changes 0
🟢 Additions 0

Warning
1 breaking change(s) detected - Major version bump required

🤖 This report was reviewed by claude-sonnet-4-6.

🔴 Breaking changes index (1)

Every breaking change, up front. Full diffs are in the package sections below.

Package Subpath Change
@clerk/ui ./themes/experimental createTheme

@clerk/ui

Current version: 1.38.0
Recommended bump: MAJOR → 2.0.0

Subpath ./themes/experimental

🔴 Breaking Changes (1)

Changed: createTheme
// ... 4 unchanged lines elided ...
      theme: InternalTheme;
    }) => Elements);
    theme?: (BaseTheme | BaseTheme[]) | undefined;
-   options?: Options | undefined;
-   variables?: Variables | undefined;
-   captcha?: CaptchaAppearanceOptions | undefined;
+   options?: import("@clerk/ui/internal").Options | undefined;
+   variables?: import("@clerk/ui/internal").Variables | undefined;
+   captcha?: import("@clerk/ui/internal").CaptchaAppearanceOptions | undefined;
    cssLayerName?: string | undefined;
  }

Static analyzer: Breaking change in function createTheme: Return type changed: {__type:"prebuilt_appearance";name?:string;elements?:((params:{theme:import("@clerk/ui").~InternalTheme;})=>import("@clerk/ui").~Elements)|import("@clerk/ui").~Elements;theme?:(import("@clerk/ui").~BaseTheme|import("@clerk/ui").~BaseTheme[])|undefined;options?:import("@clerk/ui").~Options|undefined;variables?:import("@clerk/ui").~Variables|undefined;captcha?:import("@clerk/ui").~CaptchaAppearanceOptions|undefined;cssLayerName?:string|undefined;} → {__type:"prebuilt_appearance";name?:string;elements?:!unknown|((params:{theme:import("@clerk/ui").~InternalTheme;})=>!unknown);theme?:(!unknown|!unknown[])|undefined;options?:import("@clerk/ui/internal").Options|undefined;variables?:import("@clerk/ui/internal").Variables|undefined;captcha?:import("@clerk/ui/internal").CaptchaAppearanceOptions|undefined;cssLayerName?:string|undefined;}

🤖 AI review (confirmed) (72%): The options, variables, and captcha return-type fields now reference @clerk/ui/internal, whose referenceResolutions verdict is unknown (package not found/no exports map verified); per rule 12, an unverifiable specifier cannot be confirmed as publicly resolvable, so consumers may fail to compile if they depend on these named types from the return value.

Migration: If you consume options, variables, or captcha from the createTheme return type by name, update your type imports to use whichever entry point @clerk/ui officially exports for those types, or annotate with ReturnType<typeof createTheme> to avoid explicit type references.


Report generated by Break Check

Last ran on 1b28395.

This branch was successfully deployed

2 active deployments
Preview – swingset — 1b28395a Deployed Oct 1, 2026 by vercel[bot]
Preview – clerk-js-sandbox — 1b28395a Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant