mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
Merge pull request #10838 from supabase/km/add-mfa-reference-docs
fix: add mfa reference docs
This commit is contained in:
10 files changed
+8238
-6879
No files matched your search
@@ -10,3 +10,6 @@ NEXT_PUBLIC_STUDIO_URL="https://localhost:8082"
|
||||
NEXT_PUBLIC_LAUNCHWEEKSITE_URL="https://localhost:3008"
|
||||
NEXT_PUBLIC_REFERENCE_DOCS_URL="https://localhost:3010"
|
||||
|
||||
NEXT_PUBLIC_SITE_ORIGIN=http://localhost:3000
|
||||
NEXT_PUBLIC_SUPABASE_URL=https://obuldanrptloktxcffvn.supabase.co
|
||||
NEXT_PUBLIC_SUPABASE_ANON_KEY=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJzdXBhYmFzZSIsInJlZiI6Im9idWxkYW5ycHRsb2t0eGNmZnZuIiwicm9sZSI6ImFub24iLCJpYXQiOjE2Njk3MjcwMTIsImV4cCI6MTk4NTMwMzAxMn0.SZLqryz_-stF8dgzeVXmzZWPOqdOrBwqJROlFES8v3I
|
||||
@@ -1116,18 +1116,18 @@
|
||||
"PostgrestConfigResponse": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"max_rows": { "type": "integer" },
|
||||
"db_schema": { "type": "string" },
|
||||
"max_rows": { "type": "number" },
|
||||
"db_extra_search_path": { "type": "string" }
|
||||
},
|
||||
"required": ["db_schema", "max_rows", "db_extra_search_path"]
|
||||
"required": ["max_rows", "db_schema", "db_extra_search_path"]
|
||||
},
|
||||
"UpdatePostgrestConfigBody": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"max_rows": { "type": "integer", "minimum": 0, "maximum": 1000000 },
|
||||
"db_extra_search_path": { "type": "string" },
|
||||
"db_schema": { "type": "string" },
|
||||
"max_rows": { "type": "number", "maximum": 1000000 }
|
||||
"db_schema": { "type": "string" }
|
||||
}
|
||||
},
|
||||
"UpdateCustomHostnameResponse": {
|
||||
|
||||
@@ -387,6 +387,13 @@
|
||||
"title": "Auth",
|
||||
"libs": ["js", "js_v1", "dart", "dart_v0"],
|
||||
"items": [
|
||||
{
|
||||
"id": "auth-api",
|
||||
"title": "Overview",
|
||||
"slug": "auth-api",
|
||||
"libs": ["js"],
|
||||
"type": "function"
|
||||
},
|
||||
{
|
||||
"id": "sign-up",
|
||||
"title": "Create a new user",
|
||||
@@ -547,7 +554,6 @@
|
||||
"type": "function",
|
||||
"libs": ["js"]
|
||||
},
|
||||
|
||||
{
|
||||
"id": "on-auth-state-change",
|
||||
"title": "Listen to auth events",
|
||||
@@ -564,86 +570,154 @@
|
||||
"type": "function",
|
||||
"libs": ["js", "js_v1", "dart", "dart_v0"]
|
||||
},
|
||||
{
|
||||
"id": "mfa-enroll",
|
||||
"title": "Enroll a factor",
|
||||
"slug": "auth-mfa-enroll",
|
||||
"product": "auth",
|
||||
"type": "function",
|
||||
"libs": ["js"]
|
||||
},
|
||||
{
|
||||
"id": "mfa-challenge",
|
||||
"title": "Create a challenge",
|
||||
"slug": "auth-mfa-challenge",
|
||||
"product": "auth",
|
||||
"type": "function",
|
||||
"libs": ["js"]
|
||||
},
|
||||
{
|
||||
"id": "mfa-verify",
|
||||
"title": "Verify a challenge",
|
||||
"slug": "auth-mfa-verify",
|
||||
"product": "auth",
|
||||
"type": "function",
|
||||
"libs": ["js"]
|
||||
},
|
||||
{
|
||||
"id": "mfa-challenge-and-verify",
|
||||
"title": "Create and verify a challenge",
|
||||
"slug": "auth-mfa-challengeandverify",
|
||||
"product": "auth",
|
||||
"type": "function",
|
||||
"libs": ["js"]
|
||||
},
|
||||
{
|
||||
"id": "mfa-unenroll",
|
||||
"title": "Unenroll a factor",
|
||||
"slug": "auth-mfa-unenroll",
|
||||
"product": "auth",
|
||||
"type": "function",
|
||||
"libs": ["js"]
|
||||
},
|
||||
{
|
||||
"id": "mfa-get-authenticator-assurance-level",
|
||||
"title": "Get Authenticator Assurance Level",
|
||||
"slug": "auth-mfa-getauthenticatorassurancelevel",
|
||||
"product": "auth",
|
||||
"type": "function",
|
||||
"libs": ["js"]
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"title": "Auth Admin",
|
||||
"libs": ["js", "js_v1"],
|
||||
"items": [
|
||||
{
|
||||
"id": "admin-api",
|
||||
"title": "Auth (server-only)",
|
||||
"title": "Overview",
|
||||
"slug": "admin-api",
|
||||
"libs": ["js", "js_v1"],
|
||||
"type": "function"
|
||||
},
|
||||
{
|
||||
"id": "get-user-by-id",
|
||||
"title": "Retrieve a user",
|
||||
"slug": "auth-admin-getuserbyid",
|
||||
"product": "auth-admin",
|
||||
"type": "function",
|
||||
"items": [
|
||||
{
|
||||
"id": "get-user-by-id",
|
||||
"title": "Retrieve a user",
|
||||
"slug": "auth-admin-getuserbyid",
|
||||
"product": "auth-admin",
|
||||
"type": "function",
|
||||
"libs": ["js"]
|
||||
},
|
||||
{
|
||||
"id": "list-users",
|
||||
"title": "List all users",
|
||||
"slug": "auth-admin-listusers",
|
||||
"product": "auth-admin",
|
||||
"type": "function",
|
||||
"libs": ["js", "js_v1"]
|
||||
},
|
||||
{
|
||||
"id": "create-user",
|
||||
"title": "Create a user",
|
||||
"slug": "auth-admin-createuser",
|
||||
"product": "auth-admin",
|
||||
"type": "function",
|
||||
"libs": ["js", "js_v1"]
|
||||
},
|
||||
{
|
||||
"id": "delete-user",
|
||||
"title": "Delete a user",
|
||||
"slug": "auth-admin-deleteuser",
|
||||
"product": "auth-admin",
|
||||
"type": "function",
|
||||
"libs": ["js", "js_v1"]
|
||||
},
|
||||
{
|
||||
"id": "invite-user-by-email",
|
||||
"title": "Send an email invite link",
|
||||
"slug": "auth-admin-inviteuserbyemail",
|
||||
"product": "auth-admin",
|
||||
"type": "function",
|
||||
"libs": ["js", "js_v1"]
|
||||
},
|
||||
{
|
||||
"id": "reset-password-for-email",
|
||||
"title": "Send a password reset request",
|
||||
"slug": "auth-admin-resetpasswordforemail",
|
||||
"product": "auth-admin",
|
||||
"type": "function",
|
||||
"libs": ["js"]
|
||||
},
|
||||
{
|
||||
"id": "generate-link",
|
||||
"title": "Generate an email link",
|
||||
"slug": "auth-admin-generatelink",
|
||||
"product": "auth-admin",
|
||||
"type": "function",
|
||||
"libs": ["js"]
|
||||
},
|
||||
{
|
||||
"id": "send-mobile-otp",
|
||||
"title": "Send a one-time passcode",
|
||||
"slug": "auth-api-sendmobileotp",
|
||||
"product": "auth-server",
|
||||
"type": "function",
|
||||
"libs": ["js_v1"]
|
||||
},
|
||||
{
|
||||
"id": "update-user-by-id",
|
||||
"title": "Update a user",
|
||||
"slug": "auth-admin-updateuserbyid",
|
||||
"product": "auth-admin",
|
||||
"type": "function",
|
||||
"libs": ["js", "js_v1"]
|
||||
}
|
||||
]
|
||||
"libs": ["js"]
|
||||
},
|
||||
{
|
||||
"id": "list-users",
|
||||
"title": "List all users",
|
||||
"slug": "auth-admin-listusers",
|
||||
"product": "auth-admin",
|
||||
"type": "function",
|
||||
"libs": ["js", "js_v1"]
|
||||
},
|
||||
{
|
||||
"id": "create-user",
|
||||
"title": "Create a user",
|
||||
"slug": "auth-admin-createuser",
|
||||
"product": "auth-admin",
|
||||
"type": "function",
|
||||
"libs": ["js", "js_v1"]
|
||||
},
|
||||
{
|
||||
"id": "delete-user",
|
||||
"title": "Delete a user",
|
||||
"slug": "auth-admin-deleteuser",
|
||||
"product": "auth-admin",
|
||||
"type": "function",
|
||||
"libs": ["js", "js_v1"]
|
||||
},
|
||||
{
|
||||
"id": "invite-user-by-email",
|
||||
"title": "Send an email invite link",
|
||||
"slug": "auth-admin-inviteuserbyemail",
|
||||
"product": "auth-admin",
|
||||
"type": "function",
|
||||
"libs": ["js", "js_v1"]
|
||||
},
|
||||
{
|
||||
"id": "reset-password-for-email",
|
||||
"title": "Send a password reset request",
|
||||
"slug": "auth-admin-resetpasswordforemail",
|
||||
"product": "auth-admin",
|
||||
"type": "function",
|
||||
"libs": ["js"]
|
||||
},
|
||||
{
|
||||
"id": "generate-link",
|
||||
"title": "Generate an email link",
|
||||
"slug": "auth-admin-generatelink",
|
||||
"product": "auth-admin",
|
||||
"type": "function",
|
||||
"libs": ["js"]
|
||||
},
|
||||
{
|
||||
"id": "send-mobile-otp",
|
||||
"title": "Send a one-time passcode",
|
||||
"slug": "auth-api-sendmobileotp",
|
||||
"product": "auth-server",
|
||||
"type": "function",
|
||||
"libs": ["js_v1"]
|
||||
},
|
||||
{
|
||||
"id": "update-user-by-id",
|
||||
"title": "Update a user",
|
||||
"slug": "auth-admin-updateuserbyid",
|
||||
"product": "auth-admin",
|
||||
"type": "function",
|
||||
"libs": ["js", "js_v1"]
|
||||
},
|
||||
{
|
||||
"id": "mfa-list-factors",
|
||||
"title": "List all factors for a user",
|
||||
"slug": "auth-admin-mfa-listfactors",
|
||||
"product": "auth-admin",
|
||||
"type": "function",
|
||||
"libs": ["js"]
|
||||
},
|
||||
{
|
||||
"id": "mfa-delete-factor",
|
||||
"title": "Delete a factor for a user",
|
||||
"slug": "auth-admin-mfa-deletefactor",
|
||||
"product": "auth-admin",
|
||||
"type": "function",
|
||||
"libs": ["js"]
|
||||
}
|
||||
]
|
||||
},
|
||||
|
||||
+2754
-2362
File diff suppressed because it is too large.
Load diff
+1733
-1645
File diff suppressed because it is too large.
Load diff
File diff suppressed because it is too large.
Load diff
File diff suppressed because it is too large.
Load diff
File diff suppressed because it is too large.
Load diff
+237
-38
@@ -103,6 +103,35 @@ functions:
|
||||
```
|
||||
|
||||
For React Native we recommend using `AsyncStorage` as the storage implementation for Supabase Auth.
|
||||
- id: auth-api
|
||||
title: 'Overview'
|
||||
notes: |
|
||||
- The auth methods can be accessed via the `supabase.auth` namespace.
|
||||
examples:
|
||||
- id: create-auth-client
|
||||
name: Create auth client
|
||||
isSpotlight: true
|
||||
code: |
|
||||
```js
|
||||
import { createClient } from '@supabase/supabase-js'
|
||||
|
||||
const supabase = createClient(supabase_url, anon_key)
|
||||
```
|
||||
- id: create-auth-client-server-side
|
||||
name: Create auth client (server-side)
|
||||
isSpotlight: false
|
||||
code: |
|
||||
```js
|
||||
import { createClient } from '@supabase/supabase-js'
|
||||
|
||||
const supabase = createClient(supabase_url, anon_key, {
|
||||
auth: {
|
||||
autoRefreshToken: false,
|
||||
persistSession: false,
|
||||
detectSessionInUrl: false
|
||||
}
|
||||
})
|
||||
```
|
||||
- id: sign-up
|
||||
title: 'signUp()'
|
||||
$ref: '@supabase/gotrue-js.GoTrueClient.signUp'
|
||||
@@ -118,7 +147,7 @@ functions:
|
||||
- To fetch the currently logged-in user, refer to [`getUser()`](/docs/reference/javascript/auth-getuser).
|
||||
examples:
|
||||
- id: sign-up
|
||||
name: Sign up.
|
||||
name: Sign up
|
||||
isSpotlight: true
|
||||
code: |
|
||||
```js
|
||||
@@ -128,7 +157,7 @@ functions:
|
||||
})
|
||||
```
|
||||
- id: sign-up-with-additional-user-metadata.
|
||||
name: Sign up with additional user metadata.
|
||||
name: Sign up with additional user metadata
|
||||
isSpotlight: false
|
||||
code: |
|
||||
```js
|
||||
@@ -188,7 +217,7 @@ functions:
|
||||
- The magic link's destination URL is determined by the [`SITE_URL`](https://supabase.com/docs/reference/auth/config#site_url). You can modify the `SITE_URL` or add additional redirect urls in [your project](https://app.supabase.com/project/_/auth/settings).
|
||||
examples:
|
||||
- id: sign-in-with-email
|
||||
name: Sign in with email.
|
||||
name: Sign in with email
|
||||
isSpotlight: true
|
||||
description: The user will be sent an email which contains either a magiclink or a OTP or both. By default, a given user can only request a OTP once every 60 seconds.
|
||||
code: |
|
||||
@@ -198,7 +227,7 @@ functions:
|
||||
})
|
||||
```
|
||||
- id: sign-in-with-sms-otp
|
||||
name: Sign in with SMS OTP.
|
||||
name: Sign in with SMS OTP
|
||||
isSpotlight: false
|
||||
description: The user will be sent a SMS which contains a OTP. By default, a given user can only request a OTP once every 60 seconds.
|
||||
code: |
|
||||
@@ -314,7 +343,7 @@ functions:
|
||||
const { data: { user } } = await supabase.auth.getUser()
|
||||
```
|
||||
- id: get-the-logged-in-user-with-a-custom-access-token-jwt
|
||||
name: Get the logged in user with a custom access token jwt.
|
||||
name: Get the logged in user with a custom access token jwt
|
||||
isSpotlight: false
|
||||
code: |
|
||||
```js
|
||||
@@ -367,34 +396,41 @@ functions:
|
||||
isSpotlight: true
|
||||
code: |
|
||||
```js
|
||||
const { data, error } = supabase.auth.setSession(refresh_token)
|
||||
const { data, error } = supabase.auth.setSession({
|
||||
access_token,
|
||||
refresh_token
|
||||
)
|
||||
```
|
||||
- id: refresh-session
|
||||
title: 'refreshSession()'
|
||||
$ref: '@supabase/gotrue-js.GoTrueClient.refreshSession'
|
||||
notes: |
|
||||
- This method will refresh the session whether the current one is expired or not.
|
||||
- Both examples destructure `user` and `session` from `data`. This is not required; so `const { data, error } =` is also valid.
|
||||
examples:
|
||||
- id: refresh-session-using-the-current-session
|
||||
name: Refresh session using the current session
|
||||
isSpotlight: true
|
||||
code: |
|
||||
```js
|
||||
const { data: { user, session }, error } = await supabase.auth.refreshSession()
|
||||
const { data, error } = await supabase.auth.refreshSession()
|
||||
const { session, user } = data
|
||||
```
|
||||
- id: refresh-session-using-a-passed-in-session
|
||||
name: Refresh session using a passed-in session
|
||||
isSpotlight: true
|
||||
name: Refresh session using a refresh token
|
||||
isSpotlight: false
|
||||
code: |
|
||||
```js
|
||||
const { data: { user, session }, error } = await supabase.auth.refreshSession({ refresh_token })
|
||||
const { data, error } = await supabase.auth.refreshSession({ refresh_token })
|
||||
const { session, user } = data
|
||||
```
|
||||
- id: on-auth-state-change
|
||||
title: 'onAuthStateChange()'
|
||||
$ref: '@supabase/gotrue-js.GoTrueClient.onAuthStateChange'
|
||||
notes: |
|
||||
- Types of auth events: `SIGNED_IN`, `SIGNED_OUT`, `TOKEN_REFRESHED`, `USER_UPDATED`, `USER_DELETED`, `PASSWORD_RECOVERY`
|
||||
- Types of auth events: `SIGNED_IN`, `SIGNED_OUT`, `TOKEN_REFRESHED`, `USER_UPDATED`, `PASSWORD_RECOVERY`
|
||||
- Currently, `onAuthStateChange()` does not work across tabs.
|
||||
For instance, in the case of a password reset flow, the original tab which requested for the password reset link will not receive the `SIGNED_IN` and `PASSWORD_RECOVERY` event when the user clicks on the link.
|
||||
|
||||
examples:
|
||||
- id: listen-to-auth-changes
|
||||
name: Listen to auth changes
|
||||
@@ -405,6 +441,19 @@ functions:
|
||||
console.log(event, session)
|
||||
})
|
||||
```
|
||||
- id: listen-to-password-recovery-events
|
||||
name: Listen to password recovery events
|
||||
code: |
|
||||
```js
|
||||
supabase.auth.onAuthStateChange((event, session) => {
|
||||
if (event == 'PASSWORD_RECOVERY') {
|
||||
console.log('PASSWORD_RECOVERY', session)
|
||||
|
||||
// show screen to update user's password
|
||||
showPasswordResetScreen(true)
|
||||
}
|
||||
})
|
||||
```
|
||||
- id: listen-to-sign-in
|
||||
name: Listen to sign in
|
||||
code: |
|
||||
@@ -437,27 +486,136 @@ functions:
|
||||
if (event == 'USER_UPDATED') console.log('USER_UPDATED', session)
|
||||
})
|
||||
```
|
||||
- id: listen-to-user-deleted
|
||||
name: Listen to user deleted
|
||||
- id: mfa-enroll
|
||||
title: 'mfa.enroll()'
|
||||
$ref: '@supabase/gotrue-js.GoTrueMFAApi.enroll'
|
||||
notes: |
|
||||
- Currently, `totp` is the only supported `factorType`. The returned `id` should be used to create a challenge.
|
||||
- To create a challenge, see [`mfa.challenge()`](/docs/reference/javascript/auth-mfa-challenge).
|
||||
- To verify a challenge, see [`mfa.verify()`](/docs/reference/javascript/auth-mfa-verify).
|
||||
- To create and verify a challenge in a single step, see [`mfa.challengeAndVerify()`](/docs/reference/javascript/auth-mfa-challengeandverify).
|
||||
- To generate a QR code for the `totp` secret in nextjs, you can do the following:
|
||||
```html
|
||||
<Image src={data.totp.qr_code} alt={data.totp.uri} layout="fill"></Image>
|
||||
```
|
||||
examples:
|
||||
- id: enroll-totp-factor
|
||||
name: Enroll a time-based, one-time password (TOTP) factor
|
||||
isSpotlight: true
|
||||
code: |
|
||||
```js
|
||||
supabase.auth.onAuthStateChange((event, session) => {
|
||||
if (event == 'USER_DELETED') console.log('USER_DELETED', session)
|
||||
const { data, error } = await supabase.auth.mfa.enroll({
|
||||
factorType: 'totp'
|
||||
})
|
||||
|
||||
// Use the id to create a challenge.
|
||||
// The challenge can be verified by entering the code generated from the authenticator app.
|
||||
// The code will be generated upon scanning the qr_code or entering the secret into the authenticator app.
|
||||
const { id, type, totp: { qr_code, secret, uri } } = data
|
||||
```
|
||||
- id: mfa-challenge
|
||||
title: 'mfa.challenge()'
|
||||
$ref: '@supabase/gotrue-js.GoTrueMFAApi.challenge'
|
||||
notes: |
|
||||
- An [enrolled factor](/docs/reference/javascript/auth-mfa-enroll) is required before creating a challenge.
|
||||
- To verify a challenge, see [`mfa.verify()`](/docs/reference/javascript/auth-mfa-verify).
|
||||
examples:
|
||||
- id: create-mfa-challenge
|
||||
name: Create a challenge for a factor
|
||||
isSpotlight: true
|
||||
code: |
|
||||
```js
|
||||
const { data, error } = await supabase.auth.mfa.challenge({
|
||||
factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225'
|
||||
})
|
||||
```
|
||||
- id: listen-to-password-recovery-events
|
||||
name: Listen to password recovery events
|
||||
- id: mfa-verify
|
||||
title: 'mfa.verify()'
|
||||
$ref: '@supabase/gotrue-js.GoTrueMFAApi.verify'
|
||||
notes: |
|
||||
- To verify a challenge, please [create a challenge](/docs/reference/javascript/auth-mfa-challenge) first.
|
||||
examples:
|
||||
- id: verify-challenge
|
||||
name: Verify a challenge for a factor
|
||||
isSpotlight: true
|
||||
code: |
|
||||
```js
|
||||
supabase.auth.onAuthStateChange((event, session) => {
|
||||
if (event == 'PASSWORD_RECOVERY') console.log('PASSWORD_RECOVERY', session)
|
||||
const { data, error } = await supabase.auth.mfa.verify({
|
||||
factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',
|
||||
challengeId: '4034ae6f-a8ce-4fb5-8ee5-69a5863a7c15',
|
||||
code: '123456'
|
||||
})
|
||||
```
|
||||
- id: mfa-challenge-and-verify
|
||||
title: 'mfa.challengeAndVerify()'
|
||||
$ref: '@supabase/gotrue-js.GoTrueMFAApi.challengeAndVerify'
|
||||
notes: |
|
||||
- An [enrolled factor](/docs/reference/javascript/auth-mfa-enroll) is required before invoking `challengeAndVerify()`.
|
||||
- Executes [`mfa.challenge()`](/docs/reference/javascript/auth-mfa-challenge) and [`mfa.verify()`](/docs/reference/javascript/auth-mfa-verify) in a single step.
|
||||
examples:
|
||||
- id: challenge-and-verify
|
||||
name: Create and verify a challenge for a factor
|
||||
isSpotlight: true
|
||||
code: |
|
||||
```js
|
||||
const { data, error } = await supabase.auth.mfa.challengeAndVerify({
|
||||
factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',
|
||||
challengeId: '4034ae6f-a8ce-4fb5-8ee5-69a5863a7c15',
|
||||
code: '123456'
|
||||
})
|
||||
```
|
||||
- id: mfa-unenroll
|
||||
title: 'mfa.unenroll()'
|
||||
$ref: '@supabase/gotrue-js.GoTrueMFAApi.unenroll'
|
||||
examples:
|
||||
- id: unenroll-a-factor
|
||||
name: Unenroll a factor
|
||||
isSpotlight: true
|
||||
code: |
|
||||
```js
|
||||
const { data, error } = await supabase.auth.mfa.unenroll({
|
||||
factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',
|
||||
})
|
||||
```
|
||||
- id: mfa-get-authenticator-assurance-level
|
||||
title: 'mfa.getAuthenticatorAssuranceLevel()'
|
||||
$ref: '@supabase/gotrue-js.GoTrueMFAApi.getAuthenticatorAssuranceLevel'
|
||||
notes: |
|
||||
- Authenticator Assurance Level (AAL) is the measure of the strength of an authentication mechanism.
|
||||
- In Supabase, having an AAL of `aal1` refers to having the 1st factor of authentication such as an email and password or OAuth sign-in while `aal2` refers to the 2nd factor of authentication such as a time-based, one-time-password (TOTP).
|
||||
- If the user has a verified factor, the `nextLevel` field will return `aal2`, else, it will return `aal1`.
|
||||
examples:
|
||||
- id: get-aal
|
||||
name: Get the AAL details of a session
|
||||
isSpotlight: true
|
||||
code: |
|
||||
```js
|
||||
const { data, error } = await supabase.auth.mfa.getAuthenticatorAssuranceLevel()
|
||||
const { currentLevel, nextLevel, currentAuthenticationMethods } = data
|
||||
```
|
||||
- id: admin-api
|
||||
title: 'Overview'
|
||||
notes: |
|
||||
- Any method under the `supabase.auth.admin` namespace requires a `service_role` key.
|
||||
- These methods are considered admin methods and should be called on a trusted server. Never expose your `service_role` key in the browser.
|
||||
examples:
|
||||
- id: create-auth-admin-client
|
||||
name: Create server-side auth client
|
||||
isSpotlight: true
|
||||
code: |
|
||||
```js
|
||||
import { createClient } from '@supabase/supabase-js'
|
||||
|
||||
const supabase = createClient(supabase_url, service_role_key, {
|
||||
auth: {
|
||||
autoRefreshToken: false,
|
||||
persistSession: false
|
||||
}
|
||||
})
|
||||
|
||||
// Access auth admin api
|
||||
const adminAuthClient = supabase.auth.admin
|
||||
```
|
||||
|
||||
- id: get-user-by-id
|
||||
title: 'getUserById()'
|
||||
@@ -467,7 +625,7 @@ functions:
|
||||
- The `getUserById()` method requires the user's id which maps to the `auth.users.id` column.
|
||||
examples:
|
||||
- id: fetch-the-user-object-using-the-access-token-jwt
|
||||
name: Fetch the user object using the access_token jwt.
|
||||
name: Fetch the user object using the access_token jwt
|
||||
isSpotlight: true
|
||||
code: |
|
||||
```js
|
||||
@@ -477,14 +635,26 @@ functions:
|
||||
- id: list-users
|
||||
title: 'listUsers()'
|
||||
$ref: '@supabase/gotrue-js.GoTrueAdminApi.listUsers'
|
||||
notes: |
|
||||
- Defaults to return 50 users per page.
|
||||
examples:
|
||||
- id: get-a-full-list-of-users
|
||||
name: Get a full list of users.
|
||||
name: Get a full list of users
|
||||
isSpotlight: true
|
||||
code: |
|
||||
```js
|
||||
const { data: { users }, error } = await supabase.auth.admin.listUsers()
|
||||
```
|
||||
- id: get-paginated-list-of-users
|
||||
name: Paginated list of users
|
||||
isSpotlight: false
|
||||
code: |
|
||||
```js
|
||||
const { data: { users }, error } = await supabase.auth.admin.listUsers({
|
||||
page: 1,
|
||||
perPage: 1000
|
||||
})
|
||||
```
|
||||
- id: create-user
|
||||
title: 'createUser()'
|
||||
$ref: '@supabase/gotrue-js.GoTrueAdminApi.createUser'
|
||||
@@ -492,7 +662,7 @@ functions:
|
||||
- To confirm the user's email address or phone number, set `email_confirm` or `phone_confirm` to true. Both arguments default to false.
|
||||
examples:
|
||||
- id: create-a-new-user-with-custom-user-metadata
|
||||
name: Create a new user with custom user metadata
|
||||
name: With custom user metadata
|
||||
isSpotlight: true
|
||||
code: |
|
||||
```js
|
||||
@@ -554,12 +724,17 @@ functions:
|
||||
title: 'resetPasswordForEmail()'
|
||||
$ref: '@supabase/gotrue-js.GoTrueClient.resetPasswordForEmail'
|
||||
notes: |
|
||||
Sends a password reset request to an email address.
|
||||
When the user clicks the reset link in the email they are redirected back to your application.
|
||||
Prompt the user for a new password and call `auth.updateUser()`:
|
||||
- The password reset flow consist of 2 broad steps: (i) Allow the user to login via the password reset link; (ii) Update the user's password.
|
||||
- The `resetPasswordForEmail()` only sends a password reset link to the user's email.
|
||||
To update the user's password, see [`updateUser()`](/docs/reference/javascript/auth-updateuser).
|
||||
- A `SIGNED_IN` and `PASSWORD_RECOVERY` event will be emitted when the password recovery link is clicked.
|
||||
You can use [`onAuthStateChange()`](/docs/reference/javascript/auth-onauthstatechange) to listen and invoke a callback function on these events.
|
||||
- When the user clicks the reset link in the email they are redirected back to your application.
|
||||
Prompt the user for a new password and call `updateUser()`:
|
||||
```js
|
||||
const { data, error } = await supabase.auth
|
||||
.updateUser({ password: new_password })
|
||||
const { data, error } = await supabase.auth.updateUser({
|
||||
password: new_password
|
||||
})
|
||||
```
|
||||
examples:
|
||||
- id: reset-password
|
||||
@@ -673,7 +848,7 @@ functions:
|
||||
$ref: '@supabase/gotrue-js.GoTrueAdminApi.updateUserById'
|
||||
examples:
|
||||
- id: updates-a-users-email
|
||||
name: Updates a user's email.
|
||||
name: Updates a user's email
|
||||
isSpotlight: false
|
||||
code: |
|
||||
```js
|
||||
@@ -683,7 +858,7 @@ functions:
|
||||
)
|
||||
```
|
||||
- id: updates-a-users-password
|
||||
name: Updates a user's password.
|
||||
name: Updates a user's password
|
||||
isSpotlight: false
|
||||
code: |
|
||||
```js
|
||||
@@ -693,7 +868,7 @@ functions:
|
||||
)
|
||||
```
|
||||
- id: updates-a-users-metadata
|
||||
name: Updates a user's metadata.
|
||||
name: Updates a user's metadata
|
||||
isSpotlight: true
|
||||
code: |
|
||||
```js
|
||||
@@ -703,7 +878,7 @@ functions:
|
||||
)
|
||||
```
|
||||
- id: updates-a-users-app-metadata
|
||||
name: Updates a user's app_metadata.
|
||||
name: Updates a user's app_metadata
|
||||
isSpotlight: false
|
||||
code: |
|
||||
```js
|
||||
@@ -713,7 +888,7 @@ functions:
|
||||
)
|
||||
```
|
||||
- id: confirms-a-users-email-address
|
||||
name: Confirms a user's email address.
|
||||
name: Confirms a user's email address
|
||||
isSpotlight: false
|
||||
code: |
|
||||
```js
|
||||
@@ -723,7 +898,7 @@ functions:
|
||||
)
|
||||
```
|
||||
- id: confirms-a-users-phone-number
|
||||
name: Confirms a user's phone number.
|
||||
name: Confirms a user's phone number
|
||||
isSpotlight: false
|
||||
code: |
|
||||
```js
|
||||
@@ -732,7 +907,31 @@ functions:
|
||||
{ phone_confirm: true }
|
||||
)
|
||||
```
|
||||
|
||||
- id: mfa-list-factors
|
||||
title: 'mfa.listFactors()'
|
||||
$ref: '@supabase/gotrue-js.GoTrueAdminMFAApi.listFactors'
|
||||
examples:
|
||||
- id: list-factors
|
||||
name: List all factors for a user
|
||||
isSpotlight: true
|
||||
code: |
|
||||
```js
|
||||
const { data, error } = await supabase.auth.admin.mfa.listFactors()
|
||||
```
|
||||
- id: mfa-delete-factor
|
||||
title: 'mfa.deleteFactor()'
|
||||
$ref: '@supabase/gotrue-js.GoTrueAdminMFAApi.deleteFactor'
|
||||
examples:
|
||||
- id: delete-factor
|
||||
name: Delete a factor for a user
|
||||
isSpotlight: true
|
||||
code: |
|
||||
```js
|
||||
const { data, error } = await supabase.auth.admin.mfa.deleteFactor({
|
||||
id: '34e770dd-9ff9-416c-87fa-43b31d7ef225',
|
||||
userId: 'a89baba7-b1b7-440f-b4bb-91026967f66b',
|
||||
})
|
||||
```
|
||||
- id: select
|
||||
title: 'Fetch data: select()'
|
||||
$ref: '@supabase/postgrest-js.PostgrestQueryBuilder.select'
|
||||
@@ -6765,7 +6964,7 @@ functions:
|
||||
- Responses are automatically parsed as `json`, `blob` and `form-data` depending on the `Content-Type` header sent by your function. Responses are parsed as `text` by default.
|
||||
examples:
|
||||
- id: basic-invocation
|
||||
name: Basic invocation.
|
||||
name: Basic invocation
|
||||
description:
|
||||
isSpotlight: true
|
||||
code: |
|
||||
@@ -6775,7 +6974,7 @@ functions:
|
||||
})
|
||||
```
|
||||
- id: error-handling
|
||||
name: Error handling.
|
||||
name: Error handling
|
||||
description: |
|
||||
A `FunctionsHttpError` error is returned if your function throws an error, `FunctionsRelayError` if the Supabase Relay has an error processing your function and `FunctionsFetchError` if there is a network error in calling your function.
|
||||
isSpotlight: true
|
||||
@@ -6799,7 +6998,7 @@ functions:
|
||||
}
|
||||
```
|
||||
- id: passing-custom-headers
|
||||
name: Passing custom headers.
|
||||
name: Passing custom headers
|
||||
description: |
|
||||
You can pass custom headers to your function. Note: supabase-js automatically passes the `Authorization` header with the signed in user's JWT.
|
||||
isSpotlight: true
|
||||
|
||||
@@ -1078,17 +1078,17 @@
|
||||
"schema": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"max_rows": {
|
||||
"type": "integer"
|
||||
},
|
||||
"db_schema": {
|
||||
"type": "string"
|
||||
},
|
||||
"max_rows": {
|
||||
"type": "number"
|
||||
},
|
||||
"db_extra_search_path": {
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": ["db_schema", "max_rows", "db_extra_search_path"]
|
||||
"required": ["max_rows", "db_schema", "db_extra_search_path"]
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1130,15 +1130,16 @@
|
||||
"schema": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"max_rows": {
|
||||
"type": "integer",
|
||||
"minimum": 0,
|
||||
"maximum": 1000000
|
||||
},
|
||||
"db_extra_search_path": {
|
||||
"type": "string"
|
||||
},
|
||||
"db_schema": {
|
||||
"type": "string"
|
||||
},
|
||||
"max_rows": {
|
||||
"type": "number",
|
||||
"maximum": 1000000
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1153,17 +1154,17 @@
|
||||
"schema": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"max_rows": {
|
||||
"type": "integer"
|
||||
},
|
||||
"db_schema": {
|
||||
"type": "string"
|
||||
},
|
||||
"max_rows": {
|
||||
"type": "number"
|
||||
},
|
||||
"db_extra_search_path": {
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": ["db_schema", "max_rows", "db_extra_search_path"]
|
||||
"required": ["max_rows", "db_schema", "db_extra_search_path"]
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -2396,30 +2397,31 @@
|
||||
"PostgrestConfigResponse": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"max_rows": {
|
||||
"type": "integer"
|
||||
},
|
||||
"db_schema": {
|
||||
"type": "string"
|
||||
},
|
||||
"max_rows": {
|
||||
"type": "number"
|
||||
},
|
||||
"db_extra_search_path": {
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": ["db_schema", "max_rows", "db_extra_search_path"]
|
||||
"required": ["max_rows", "db_schema", "db_extra_search_path"]
|
||||
},
|
||||
"UpdatePostgrestConfigBody": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"max_rows": {
|
||||
"type": "integer",
|
||||
"minimum": 0,
|
||||
"maximum": 1000000
|
||||
},
|
||||
"db_extra_search_path": {
|
||||
"type": "string"
|
||||
},
|
||||
"db_schema": {
|
||||
"type": "string"
|
||||
},
|
||||
"max_rows": {
|
||||
"type": "number",
|
||||
"maximum": 1000000
|
||||
}
|
||||
}
|
||||
},
|
||||
|
||||
Reference in new issue
Block a user