From 0cb07c30f727e17f247eb241e45bb68fbb545747 Mon Sep 17 00:00:00 2001 From: Miranda Limonczenko Date: Thu, 24 Sep 2026 17:29:25 -0700 Subject: [PATCH] docs: fix the local development anchor and the propagation claim Two claims on the custom claims and RBAC guide that leave a reader with a wrong outcome. The "local development" link pointed at /docs/guides/auth/auth-hooks#local-development, and no heading by that name exists. The section is "Developing", so the one link that carries the local `config.toml` setting dropped the reader at the top of the page. Renaming the heading restores the anchor rather than repointing the link, because the Slack Clone example's own `config.toml` comment expects the same anchor in two places. Nothing links to `#developing`. The conclusion said the setup "automatically propagates to Supabase Auth", which reads as though a role change reaches open sessions. It reaches the next token the hook issues. Say when a change lands and how to make it land now. --- .../api/custom-claims-and-role-based-access-control-rbac.mdx | 4 +++- apps/docs/content/guides/auth/auth-hooks.mdx | 2 +- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/apps/docs/content/guides/api/custom-claims-and-role-based-access-control-rbac.mdx b/apps/docs/content/guides/api/custom-claims-and-role-based-access-control-rbac.mdx index 98b4cf6f57d..7e14fad3c77 100644 --- a/apps/docs/content/guides/api/custom-claims-and-role-based-access-control-rbac.mdx +++ b/apps/docs/content/guides/api/custom-claims-and-role-based-access-control-rbac.mdx @@ -199,7 +199,9 @@ For server-side logic, you can use a JWT package for your language, such as [`ex ## Conclusion -You now have a robust system in place to manage user roles and permissions within your database that automatically propagates to Supabase Auth. +You now have a system for managing user roles and permissions in your database, and the Auth Hook copies a user's role into every access token it issues. + +A role change reaches a user the next time their access token is issued, not immediately. Sessions that are already open keep the role they were issued with until the client refreshes them. To apply a role change right away, refresh the session with [`refreshSession()`](/docs/reference/javascript/auth-refreshsession) or have the user sign in again. See [Sessions](/docs/guides/auth/sessions) for how long an access token lasts. ## More resources diff --git a/apps/docs/content/guides/auth/auth-hooks.mdx b/apps/docs/content/guides/auth/auth-hooks.mdx index 327d87456d1..39b8816fd7d 100644 --- a/apps/docs/content/guides/auth/auth-hooks.mdx +++ b/apps/docs/content/guides/auth/auth-hooks.mdx @@ -134,7 +134,7 @@ Deno.serve(async (req) => { ## Using Hooks -### Developing +### Local development Let us develop a Hook locally and then deploy it to the cloud. As a recap, here’s a list of available Hooks