From e69e5327b0d06128b5eed8d8eca8f16d2c00c23e Mon Sep 17 00:00:00 2001 From: "joel@joellee.org" Date: Fri, 21 Jul 2023 10:12:12 +0200 Subject: [PATCH 1/4] fix: update recognized auth methods --- apps/docs/pages/guides/auth/auth-mfa.mdx | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/apps/docs/pages/guides/auth/auth-mfa.mdx b/apps/docs/pages/guides/auth/auth-mfa.mdx index 0591e3af52b..ef8c4d2976b 100644 --- a/apps/docs/pages/guides/auth/auth-mfa.mdx +++ b/apps/docs/pages/guides/auth/auth-mfa.mdx @@ -689,13 +689,18 @@ json_query_path(auth.jwt(), '$.amr[0]') Once you have extracted the most recent entry in the array, you can compare the `method` and `timestamp` to enforce stricter rules. -Currently recognized methods are: +Currently recognized authentication methods are: +- `oauth` - any OAuth based sign in (social login). - `password` - any password based sign in. - `otp` - any one-time password based sign in (email code, SMS code, magic link). -- `oauth` - any OAuth based sign in (social login). - `totp` - a TOTP additional factor. +- `sso/saml` - any Single Sign On (SAML) method. +- `invite` - any sign in via an invitation. +- `magiclink` - any sign in via magic link. Excludes logins resulting from invocation of `signUp`. +- `email/signup` - any login resulting from an email signup. +- `email_change` - any login resulting from a change in email. This list will expand in the future. From 7240d22c60f8de3b319a9a80f6c682e4f90f13c6 Mon Sep 17 00:00:00 2001 From: "joel@joellee.org" Date: Fri, 21 Jul 2023 10:16:59 +0200 Subject: [PATCH 2/4] docs: update mfa docs --- apps/docs/pages/guides/auth/auth-mfa.mdx | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/apps/docs/pages/guides/auth/auth-mfa.mdx b/apps/docs/pages/guides/auth/auth-mfa.mdx index ef8c4d2976b..8a6b73aceb4 100644 --- a/apps/docs/pages/guides/auth/auth-mfa.mdx +++ b/apps/docs/pages/guides/auth/auth-mfa.mdx @@ -687,7 +687,7 @@ json_query_path(auth.jwt(), '$.amr[0]') authentication method in the JWT. Once you have extracted the most recent entry in the array, you can compare the -`method` and `timestamp` to enforce stricter rules. +`method` and `timestamp` to enforce stricter rules. For instance, you can mandate that access will be only be granted on a table to users who have recently signed in with a password. Currently recognized authentication methods are: @@ -702,7 +702,7 @@ Currently recognized authentication methods are: - `email/signup` - any login resulting from an email signup. - `email_change` - any login resulting from a change in email. -This list will expand in the future. +More authentication methods will be added over time as we increase the number of authentication methods supported by Supabase. export const Page = ({ children }) => From e2954a66563ed793c37f09566fe981c1312e6271 Mon Sep 17 00:00:00 2001 From: "joel@joellee.org" Date: Fri, 21 Jul 2023 10:27:29 +0200 Subject: [PATCH 3/4] docs: split pkce methods --- apps/docs/pages/guides/auth/auth-mfa.mdx | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/apps/docs/pages/guides/auth/auth-mfa.mdx b/apps/docs/pages/guides/auth/auth-mfa.mdx index 8a6b73aceb4..e5d1e92c6ab 100644 --- a/apps/docs/pages/guides/auth/auth-mfa.mdx +++ b/apps/docs/pages/guides/auth/auth-mfa.mdx @@ -697,10 +697,12 @@ Currently recognized authentication methods are: link). - `totp` - a TOTP additional factor. - `sso/saml` - any Single Sign On (SAML) method. -- `invite` - any sign in via an invitation. + +The following additional claims are available only when using PKCE flow: +- `invite` - any sign in via an invitation. Only available with PKCE. - `magiclink` - any sign in via magic link. Excludes logins resulting from invocation of `signUp`. -- `email/signup` - any login resulting from an email signup. -- `email_change` - any login resulting from a change in email. +- `email/signup` - any login resulting from an email signup. Only available with PKCE. +- `email_change` - any login resulting from a change in email. Only available with PKCE More authentication methods will be added over time as we increase the number of authentication methods supported by Supabase. From d9537937e360e8f585d850eb7ab21d8c52ac255a Mon Sep 17 00:00:00 2001 From: "joel@joellee.org" Date: Fri, 21 Jul 2023 10:28:59 +0200 Subject: [PATCH 4/4] docs: refactor phrasing --- apps/docs/pages/guides/auth/auth-mfa.mdx | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/apps/docs/pages/guides/auth/auth-mfa.mdx b/apps/docs/pages/guides/auth/auth-mfa.mdx index e5d1e92c6ab..3365952bd57 100644 --- a/apps/docs/pages/guides/auth/auth-mfa.mdx +++ b/apps/docs/pages/guides/auth/auth-mfa.mdx @@ -698,11 +698,11 @@ Currently recognized authentication methods are: - `totp` - a TOTP additional factor. - `sso/saml` - any Single Sign On (SAML) method. -The following additional claims are available only when using PKCE flow: -- `invite` - any sign in via an invitation. Only available with PKCE. +The following additional claims are available when using PKCE flow: +- `invite` - any sign in via an invitation. - `magiclink` - any sign in via magic link. Excludes logins resulting from invocation of `signUp`. -- `email/signup` - any login resulting from an email signup. Only available with PKCE. -- `email_change` - any login resulting from a change in email. Only available with PKCE +- `email/signup` - any login resulting from an email signup. +- `email_change` - any login resulting from a change in email. More authentication methods will be added over time as we increase the number of authentication methods supported by Supabase.