From 3fcc5538b7842a97ff1fadb360bdde243ceb2e98 Mon Sep 17 00:00:00 2001 From: Nico Kempe <50241630+nicokempe@users.noreply.github.com> Date: Wed, 7 May 2025 01:27:36 +0200 Subject: [PATCH] docs(auth-js): add nonce usage note to reauthenticate() docs (#35206) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit docs(auth-js): include reminder to pass OTP as nonce in updateUser() Add one‑liner on using the received OTP as the `nonce` in updateUser() --- apps/docs/spec/supabase_js_v2.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/apps/docs/spec/supabase_js_v2.yml b/apps/docs/spec/supabase_js_v2.yml index 73c07127349..80a47bbc8a3 100644 --- a/apps/docs/spec/supabase_js_v2.yml +++ b/apps/docs/spec/supabase_js_v2.yml @@ -1593,6 +1593,7 @@ functions: - If you require your user to reauthenticate before updating their password, you need to enable the **Secure password change** option in your [project's email provider settings](/dashboard/project/_/auth/providers). - A user is only require to reauthenticate before updating their password if **Secure password change** is enabled and the user **hasn't recently signed in**. A user is deemed recently signed in if the session was created in the last 24 hours. - This method will send a nonce to the user's email. If the user doesn't have a confirmed email address, the method will send the nonce to the user's confirmed phone number instead. + - After receiving the OTP, include it as the `nonce` in your `updateUser()` call to finalize the password change. examples: - id: send-reauthentication-nonce name: Send reauthentication nonce