Merge branch 'master' of github.com:supabase/supabase

This commit is contained in:
Terry Sutton committed 2022-08-16 11:58:44 -02:30
commit 4fb86fae18
45 files changed
+1374 -1118

No files matched your search

@@ -1,7 +1,7 @@
---
id: auth-api-createuser
id: auth-admin-createuser
title: 'createUser()'
slug: /auth-api-createuser
slug: /auth-admin-createuser
custom_edit_url: https://github.com/supabase/supabase/edit/master/spec/supabase_js_v2_legacy.yml
---
@@ -12,7 +12,7 @@ Creates a new user.
This function should only be called on a server. Never expose your `service_role` key in the browser.
```js
const { data: user, error } = await supabase.auth.api.createUser({
const { data, error } = await supabase.auth.admin.createUser({
email: 'user@email.com',
password: 'password',
user_metadata: { name: 'Yoda' },
@@ -257,7 +257,7 @@ this attribute is used instead of UserAttributes data.
### Create a new user.
```js
const { data: user, error } = await supabase.auth.api.createUser({
const { data, error } = await supabase.auth.admin.createUser({
email: 'user@email.com',
password: 'password',
user_metadata: { name: 'Yoda' },
@@ -267,7 +267,7 @@ const { data: user, error } = await supabase.auth.api.createUser({
### Auto-confirm email.
```js
const { data: user, error } = await supabase.auth.api.createUser({
const { data, error } = await supabase.auth.admin.createUser({
email: 'user@email.com',
email_confirm: true,
})
@@ -276,7 +276,7 @@ const { data: user, error } = await supabase.auth.api.createUser({
### Auto-confirm phone.
```js
const { data: user, error } = await supabase.auth.api.createUser({
const { data, error } = await supabase.auth.admin.createUser({
phone: '1234567890',
phone_confirm: true,
})
@@ -1,7 +1,7 @@
---
id: auth-api-deleteuser
id: auth-admin-deleteuser
title: 'deleteUser()'
slug: /auth-api-deleteuser
slug: /auth-admin-deleteuser
custom_edit_url: https://github.com/supabase/supabase/edit/master/spec/supabase_js_v2_legacy.yml
---
@@ -11,7 +11,7 @@ import TabItem from '@theme/TabItem'
Delete a user. Requires a `service_role` key.
```js
const { data: user, error } = await supabase.auth.api.deleteUser(
const { data, error } = await supabase.auth.admin.deleteUser(
'715ed5db-f090-4b8c-a067-640ecee36aa0'
)
```
@@ -54,7 +54,7 @@ This function should only be called on a server. Never expose your `service_role
### Remove a user completely.
```js
const { data: user, error } = await supabase.auth.api.deleteUser(
const { data, error } = await supabase.auth.admin.deleteUser(
'715ed5db-f090-4b8c-a067-640ecee36aa0'
)
```
@@ -1,7 +1,7 @@
---
id: auth-api-generatelink
id: auth-admin-generatelink
title: 'generateLink()'
slug: /auth-api-generatelink
slug: /auth-admin-generatelink
custom_edit_url: https://github.com/supabase/supabase/edit/master/spec/supabase_js_v2_legacy.yml
---
@@ -10,6 +10,16 @@ import TabItem from '@theme/TabItem'
Generates links to be sent via email or other.
```js
const { data, error } = await supabase.auth.admin.generateLink(
'email@example.com'
'signup',
{
'password': 'secret'
}
)
```
## Parameters
<ul className="method-list-group">
@@ -152,11 +162,23 @@ The redirect url which should be appended to the generated link
## Examples
### Generate invite link.
### Generate a signup link.
```js
const { data: user, error } = await supabase.auth.api.generateLink(
'invite',
const { data, error } = await supabase.auth.admin.generateLink(
'email@example.com'
'signup',
{
'password': 'secret'
}
)
```
### Generate an invite link.
```js
const { data, error } = await supabase.auth.admin.generateLink(
'email@example.com'
'invite',
)
```
@@ -1,7 +1,7 @@
---
id: auth-api-getuserbyid
id: auth-admin-getuserbyid
title: 'getUserById()'
slug: /auth-api-getuserbyid
slug: /auth-admin-getuserbyid
custom_edit_url: https://github.com/supabase/supabase/edit/master/spec/supabase_js_v2_legacy.yml
---
@@ -11,7 +11,7 @@ import TabItem from '@theme/TabItem'
Get user by id.
```js
const { user, error } = await supabase.auth.api.getUserById(1)
const { user, error } = await supabase.auth.admin.getUserById(1)
```
## Parameters
@@ -53,5 +53,5 @@ This function should only be called on a server. Never expose your `service_role
### Fetch the user object using the access_token jwt.
```js
const { user, error } = await supabase.auth.api.getUserById(1)
const { user, error } = await supabase.auth.admin.getUserById(1)
```
@@ -1,7 +1,7 @@
---
id: auth-api-inviteuserbyemail
id: auth-admin-inviteuserbyemail
title: 'inviteUserByEmail()'
slug: /auth-api-inviteuserbyemail
slug: /auth-admin-inviteuserbyemail
custom_edit_url: https://github.com/supabase/supabase/edit/master/spec/supabase_js_v2_legacy.yml
---
@@ -111,7 +111,7 @@ A URL or mobile address to send the user to after they are confirmed.
### Basic example.
```js
const { data: user, error } = await supabase.auth.api.inviteUserByEmail(
const { data, error } = await supabase.auth.admin.inviteUserByEmail(
'email@example.com'
)
```
@@ -1,7 +1,7 @@
---
id: auth-api-listusers
id: auth-admin-listusers
title: 'listUsers()'
slug: /auth-api-listusers
slug: /auth-admin-listusers
custom_edit_url: https://github.com/supabase/supabase/edit/master/spec/supabase_js_v2_legacy.yml
---
@@ -13,7 +13,7 @@ Get a list of users.
This function should only be called on a server. Never expose your `service_role` key in the browser.
```js
const { data: user, error } = await supabase.auth.api.listUsers()
const { data: user, error } = await supabase.auth.admin.listUsers()
```
## Notes
@@ -26,5 +26,5 @@ const { data: user, error } = await supabase.auth.api.listUsers()
### Get a full list of users.
```js
const { data: user, error } = await supabase.auth.api.listUsers()
const { data: user, error } = await supabase.auth.admin.listUsers()
```
@@ -1,7 +1,7 @@
---
id: auth-api-updateuserbyid
id: auth-admin-updateuserbyid
title: 'updateUserById()'
slug: /auth-api-updateuserbyid
slug: /auth-admin-updateuserbyid
custom_edit_url: https://github.com/supabase/supabase/edit/master/spec/supabase_js_v2_legacy.yml
---
@@ -11,7 +11,7 @@ import TabItem from '@theme/TabItem'
Updates the user data.
```js
const { data: user, error } = await supabase.auth.api.updateUserById(
const { data: user, error } = await supabase.auth.admin.updateUserById(
'6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',
{ email: 'new@email.com' }
)
@@ -274,7 +274,7 @@ this attribute is used instead of UserAttributes data.
### Updates a user's email.
```js
const { data: user, error } = await supabase.auth.api.updateUserById(
const { data: user, error } = await supabase.auth.admin.updateUserById(
'6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',
{ email: 'new@email.com' }
)
@@ -283,7 +283,7 @@ const { data: user, error } = await supabase.auth.api.updateUserById(
### Updates a user's password.
```js
const { data: user, error } = await supabase.auth.api.updateUserById(
const { data: user, error } = await supabase.auth.admin.updateUserById(
'6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',
{ password: 'new_password' }
)
@@ -292,7 +292,7 @@ const { data: user, error } = await supabase.auth.api.updateUserById(
### Updates a user's metadata.
```js
const { data: user, error } = await supabase.auth.api.updateUserById(
const { data: user, error } = await supabase.auth.admin.updateUserById(
'6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',
{ user_metadata: { hello: 'world' } }
)
@@ -301,7 +301,7 @@ const { data: user, error } = await supabase.auth.api.updateUserById(
### Updates a user's app_metadata.
```js
const { data: user, error } = await supabase.auth.api.updateUserById(
const { data: user, error } = await supabase.auth.admin.updateUserById(
'6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',
{ app_metadata: { plan: 'trial' } }
)
@@ -310,7 +310,7 @@ const { data: user, error } = await supabase.auth.api.updateUserById(
### Confirms a user's email address.
```js
const { data: user, error } = await supabase.auth.api.updateUserById(
const { data: user, error } = await supabase.auth.admin.updateUserById(
'6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',
{ email_confirm: true }
)
@@ -319,7 +319,7 @@ const { data: user, error } = await supabase.auth.api.updateUserById(
### Confirms a user's phone number.
```js
const { data: user, error } = await supabase.auth.api.updateUserById(
const { data: user, error } = await supabase.auth.admin.updateUserById(
'6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',
{ phone_confirm: true }
)
@@ -1,59 +0,0 @@
---
id: auth-api-getuser
title: 'getUser()'
slug: /auth-api-getuser
custom_edit_url: https://github.com/supabase/supabase/edit/master/spec/supabase_js_v2_legacy.yml
---
import Tabs from '@theme/Tabs'
import TabItem from '@theme/TabItem'
Gets the current user details.
This method is called by the GoTrueClient `update` where
the jwt is set to this.currentSession.access_token
and therefore, acts like getting the currently authenticated user
```js
const { user, error } = await supabase.auth.api.getUser('ACCESS_TOKEN_JWT')
```
## Parameters
<ul className="method-list-group">
<li className="method-list-item">
<h4 className="method-list-item-label">
<span className="method-list-item-label-name">
jwt
</span>
<span className="method-list-item-label-badge required">
required
</span>
<span className="method-list-item-validation">
<code>string</code>
</span>
</h4>
<div class="method-list-item-description">
A valid, logged-in JWT. Typically, the access_token for the currentSession
</div>
</li>
</ul>
## Notes
- Fetches the user object from the database instead of local storage.
- Note that user() fetches the user object from local storage which might not be the most updated.
- Requires the user's access_token.
## Examples
### Fetch the user object using the access_token jwt.
```js
const { user, error } = await supabase.auth.api.getUser('ACCESS_TOKEN_JWT')
```
@@ -12,7 +12,7 @@ Returns the session data, refreshing it if necessary.
If no session is detected, the session returned will be null.
```js
const session = supabase.auth.session()
const { data, error } = supabase.auth.getSession()
```
## Examples
@@ -20,5 +20,5 @@ const session = supabase.auth.session()
### Get the session data
```js
const session = supabase.auth.session()
const { data, error } = supabase.auth.getSession()
```
@@ -11,7 +11,7 @@ import TabItem from '@theme/TabItem'
Gets the current user details if there is an existing session.
```js
const user = await supabase.auth.getUser()
const user = supabase.auth.getUser()
```
## Parameters
@@ -42,12 +42,19 @@ Takes in an optional access token jwt. If no jwt is provided, getUser() will att
## Notes
This method gets the user object from memory.
- This method gets the user object using the current session.
- Fetches the user object from the database instead of local storage.
## Examples
### Get the logged in user
### Get the logged in user with the current existing session
```js
const user = await supabase.auth.getUser()
const user = supabase.auth.getUser()
```
### Get the logged in user with a custom access token jwt.
```js
const user = supabase.auth.getUser(jwt)
```
@@ -1,7 +1,7 @@
---
id: auth-api-resetpasswordforemail
id: auth-resetpasswordforemail
title: 'resetPasswordForEmail()'
slug: /auth-api-resetpasswordforemail
slug: /auth-resetpasswordforemail
custom_edit_url: https://github.com/supabase/supabase/edit/master/spec/supabase_js_v2_legacy.yml
---
@@ -11,9 +11,9 @@ import TabItem from '@theme/TabItem'
Sends a reset request to an email address.
```js
const { data, error } = await supabase.auth.api.resetPasswordForEmail(
'user@email.com'
)
const { error, data } = await supabase.auth.resetPasswordForEmail(email, options: {
redirectTo: 'https://example.com/update-password',
})
```
## Parameters
@@ -111,7 +111,7 @@ A URL to send the user to after they are confirmed.
Sends a reset request to an email address.
When the user clicks the reset link in the email they will be forwarded to:
When the user clicks the reset link in the email they will be forwarded to the site url or the redirect url specified:
`<SITE_URL>#access_token=x&refresh_token=y&expires_in=z&token_type=bearer&type=recovery`
@@ -120,7 +120,7 @@ Your app must detect `type=recovery` in the fragment and display a password rese
You should then use the access_token in the url and new password to update the user as follows:
```js
const { error, data } = await supabase.auth.api.updateUser(access_token, {
const { error, data } = await supabase.auth.updateUser({
password: new_password,
})
```
@@ -130,7 +130,7 @@ const { error, data } = await supabase.auth.api.updateUser(access_token, {
### Reset password
```js
const { data, error } = await supabase.auth.api.resetPasswordForEmail(
'user@email.com'
)
const { error, data } = await supabase.auth.resetPasswordForEmail(email, options: {
redirectTo: 'https://example.com/update-password',
})
```
@@ -11,16 +11,7 @@ import TabItem from '@theme/TabItem'
Sets the session data from refresh_token and returns current session or an error if the refresh_token is invalid.
```js
function apiFunction(req, res) {
// Assuming the access token was sent as a header "X-Supabase-Auth"
const { access_token } = req.get('X-Supabase-Auth')
// You can now use it within a Supabase Client
const supabase = createClient("https://xyzcompany.supabase.co", "public-anon-key")
const { user, error } = supabase.auth.setAuth(access_token)
// This client will now send requests as this user
const { data } = await supabase.from('your_table').select()
const { data, error } = supabase.auth.setSession(refresh_token)
}
```
@@ -54,57 +45,9 @@ The refresh token returned by gotrue.
### Basic example.
This is most useful on server-side functions where you cannot log the user in, but have access to the user's access token.
Sets the session data from refresh_token and returns current session or an error if the refresh_token is invalid.
```js
function apiFunction(req, res) {
// Assuming the access token was sent as a header "X-Supabase-Auth"
const { access_token } = req.get('X-Supabase-Auth')
// You can now use it within a Supabase Client
const supabase = createClient("https://xyzcompany.supabase.co", "public-anon-key")
const { user, error } = supabase.auth.setAuth(access_token)
// This client will now send requests as this user
const { data } = await supabase.from('your_table').select()
}
```
### With Express.
```js
/**
* Make a request from the client to your server function
*/
async function makeApiRequest() {
const token = newClient.session()?.access_token
await fetch('https://example.com/withAuth', {
method: 'GET',
withCredentials: true,
credentials: 'include',
headers: {
'Content-Type': 'application/json',
Authorization: bearer, // Your own auth
'X-Supabase-Auth': token, // Set the Supabase user
},
})
}
/**
* Use the Auth token in your server-side function.
*/
async function apiFunction(req, res) {
const { access_token } = req.get('X-Supabase-Auth')
// You can now use it within a Supabase Client
const supabase = createClient(
'https://xyzcompany.supabase.co',
'public-anon-key'
)
const { user, error } = supabase.auth.setAuth(access_token)
// This client will now send requests as this user
const { data } = await supabase.from('your_table').select()
const { data, error } = supabase.auth.setSession(refresh_token)
}
```
@@ -10,13 +10,6 @@ import TabItem from '@theme/TabItem'
Log in an existing user via a third-party provider.
```js
const { user, session, error } = await supabase.auth.signIn({
email: 'example@email.com',
password: 'example-password',
})
```
## Parameters
<ul className="method-list-group">
@@ -155,71 +148,32 @@ A space-separated list of scopes granted to the OAuth application.
## Notes
- A user can sign up either via email or OAuth.
- If you provide `email` without a `password`, the user will be sent a magic link.
- The magic link's destination URL is determined by the SITE_URL config variable. To change this, you can go to Authentication -> Settings on [app.supabase.com](https://app.supabase.com)
- Specifying a `provider` will open the browser to the relevant login page.
- This method is used for signing in using a third-party provider.
- Supabase supports many different [third-party providers](https://supabase.com/docs/guides/auth#providers).
## Examples
### Sign in with email.
### Sign in using a third-party provider.
```js
const { user, session, error } = await supabase.auth.signIn({
email: 'example@email.com',
password: 'example-password',
})
```
### Sign in with magic link.
If no password is provided, the user will be sent a "magic link" to their email address, which they can click to open your application with a valid session. By default, a given user can only request a Magic Link once every 60 seconds.
```js
const { user, session, error } = await supabase.auth.signIn({
email: 'example@email.com',
})
```
### Sign in using third-party providers.
Supabase supports many different [third-party providers](https://supabase.com/docs/guides/auth#providers).
```js
const { user, session, error } = await supabase.auth.signIn({
// provider can be 'github', 'google', 'gitlab', and more
const { data, error } = await supabase.auth.signInWithOAuth({
provider: 'github',
})
```
### Sign in with Phone.
### Sign in using a third-party provider with redirect.
Supabase supports Phone Auth.
```js
const { user, session, error } = await supabase.auth.signIn({
phone: '+13334445555',
password: 'some-password',
})
```
### Sign in with redirect.
Note that the `redirectTo` param is only relevant for OAuth logins, where the login flow is managed by
the Auth server. If you are using email/phone logins you should set up your own redirects (within the email/sms template).
Sometimes you want to control where the user is redirected to after they are logged in. Supabase supports this for
The `redirectTo` param will only applied on the callback made from the third-party provider. It does not redirect the user immediately after invoking this method.
In order for the `redirectTo` param to be allowed, one needs to include it in an allowlist. Supabase supports this for
any URL path on your website (the URL must either be on the same domain as your Site URL [see Auth>Settings in dashboard], or must match one of the Additional Redirect URLs [also in Auth>Settings]).
```js
const { user, session, error } = await supabase.auth.signIn(
{
provider: 'github',
},
{
redirectTo: 'https://example.com/welcome',
const { user, session, error } = await supabase.auth.signInWithOAuth({
provider: 'github'
options: {
redirectTo: 'https://example.com/welcome'
}
)
}
```
### Sign in with scopes.
@@ -228,33 +182,11 @@ If you need additional data from an OAuth provider, you can include a space-sepa
You may also need to specify the scopes in the provider's OAuth app settings, depending on the provider.
```js
const { user, session, error } = await supabase.auth.signIn(
{
provider: 'github',
},
{
scopes: 'repo gist notifications',
const { data, error } = await supabase.auth.signInWithOAuth({
provider: 'github'
options: {
scopes: 'repo gist notifications'
}
)
const oAuthToken = session.provider_token // use to access provider API
```
### Sign in using a refresh token (e.g. in React Native).
If you are completing a sign up or login in a React Native app you can pass the refresh token obtained from the provider to obtain a session.
```js
// An example using Expo's `AuthSession`
const redirectUri = AuthSession.makeRedirectUri({ useProxy: false })
const provider = 'google'
AuthSession.startAsync({
authUrl: `https://MYSUPABASEAPP.supabase.co/auth/v1/authorize?provider=${provider}&redirect_to=${redirectUri}`,
returnUrl: redirectUri,
}).then(async (response: any) => {
if (!response) return
const { user, session, error } = await supabase.auth.signIn({
refreshToken: response.params?.refresh_token,
})
})
const oAuthToken = data.session.provider_token // use to access provider API
```
@@ -11,9 +11,8 @@ import TabItem from '@theme/TabItem'
Passwordless method for logging in an existing user.
```js
const { user, session, error } = await supabase.auth.signIn({
const { data, error } = await supabase.auth.signInWithOtp({
email: 'example@email.com',
password: 'example-password',
})
```
@@ -175,106 +174,30 @@ If set to false, this method will not create a new user. Defaults to true.
## Notes
- A user can sign up either via email or OAuth.
- If you provide `email` without a `password`, the user will be sent a magic link.
- This method is used for passwordless sign-ins where an otp is sent to the user's email or phone number.
- Requires either an email or phone number.
- If you're using an email, you can configure whether you want the user to receive a magiclink or an otp.
- If you're using phone, you can configure whether you want the user to receive a magiclink or an otp.
- The magic link's destination URL is determined by the SITE_URL config variable. To change this, you can go to Authentication -> Settings on [app.supabase.com](https://app.supabase.com)
- Specifying a `provider` will open the browser to the relevant login page.
## Examples
### Sign in with email.
```js
const { user, session, error } = await supabase.auth.signIn({
email: 'example@email.com',
password: 'example-password',
})
```
### Sign in with magic link.
If no password is provided, the user will be sent a "magic link" to their email address, which they can click to open your application with a valid session. By default, a given user can only request a Magic Link once every 60 seconds.
The user will be sent an otp to their email. By default, a given user can only request an otp once every 60 seconds.
```js
const { user, session, error } = await supabase.auth.signIn({
const { data, error } = await supabase.auth.signInWithOtp({
email: 'example@email.com',
})
```
### Sign in using third-party providers.
### Sign in with sms otp.
Supabase supports many different [third-party providers](https://supabase.com/docs/guides/auth#providers).
The user will be sent an otp to their phone number. By default, a given user can only request an otp once every 60 seconds.
```js
const { user, session, error } = await supabase.auth.signIn({
// provider can be 'github', 'google', 'gitlab', and more
provider: 'github',
})
```
### Sign in with Phone.
Supabase supports Phone Auth.
```js
const { user, session, error } = await supabase.auth.signIn({
const { data, error } = await supabase.auth.signInWithPassword({
phone: '+13334445555',
password: 'some-password',
})
```
### Sign in with redirect.
Note that the `redirectTo` param is only relevant for OAuth logins, where the login flow is managed by
the Auth server. If you are using email/phone logins you should set up your own redirects (within the email/sms template).
Sometimes you want to control where the user is redirected to after they are logged in. Supabase supports this for
any URL path on your website (the URL must either be on the same domain as your Site URL [see Auth>Settings in dashboard], or must match one of the Additional Redirect URLs [also in Auth>Settings]).
```js
const { user, session, error } = await supabase.auth.signIn(
{
provider: 'github',
},
{
redirectTo: 'https://example.com/welcome',
}
)
```
### Sign in with scopes.
If you need additional data from an OAuth provider, you can include a space-separated list of scopes in your request to get back an OAuth provider token.
You may also need to specify the scopes in the provider's OAuth app settings, depending on the provider.
```js
const { user, session, error } = await supabase.auth.signIn(
{
provider: 'github',
},
{
scopes: 'repo gist notifications',
}
)
const oAuthToken = session.provider_token // use to access provider API
```
### Sign in using a refresh token (e.g. in React Native).
If you are completing a sign up or login in a React Native app you can pass the refresh token obtained from the provider to obtain a session.
```js
// An example using Expo's `AuthSession`
const redirectUri = AuthSession.makeRedirectUri({ useProxy: false })
const provider = 'google'
AuthSession.startAsync({
authUrl: `https://MYSUPABASEAPP.supabase.co/auth/v1/authorize?provider=${provider}&redirect_to=${redirectUri}`,
returnUrl: redirectUri,
}).then(async (response: any) => {
if (!response) return
const { user, session, error } = await supabase.auth.signIn({
refreshToken: response.params?.refresh_token,
})
})
```
@@ -10,13 +10,6 @@ import TabItem from '@theme/TabItem'
Log in an existing user, or login via a third-party provider.
```js
const { user, session, error } = await supabase.auth.signIn({
email: 'example@email.com',
password: 'example-password',
})
```
## Parameters
<ul className="method-list-group">
@@ -155,106 +148,4 @@ Verification token received when the user completes the captcha on the site.
## Notes
- A user can sign up either via email or OAuth.
- If you provide `email` without a `password`, the user will be sent a magic link.
- The magic link's destination URL is determined by the SITE_URL config variable. To change this, you can go to Authentication -> Settings on [app.supabase.com](https://app.supabase.com)
- Specifying a `provider` will open the browser to the relevant login page.
## Examples
### Sign in with email.
```js
const { user, session, error } = await supabase.auth.signIn({
email: 'example@email.com',
password: 'example-password',
})
```
### Sign in with magic link.
If no password is provided, the user will be sent a "magic link" to their email address, which they can click to open your application with a valid session. By default, a given user can only request a Magic Link once every 60 seconds.
```js
const { user, session, error } = await supabase.auth.signIn({
email: 'example@email.com',
})
```
### Sign in using third-party providers.
Supabase supports many different [third-party providers](https://supabase.com/docs/guides/auth#providers).
```js
const { user, session, error } = await supabase.auth.signIn({
// provider can be 'github', 'google', 'gitlab', and more
provider: 'github',
})
```
### Sign in with Phone.
Supabase supports Phone Auth.
```js
const { user, session, error } = await supabase.auth.signIn({
phone: '+13334445555',
password: 'some-password',
})
```
### Sign in with redirect.
Note that the `redirectTo` param is only relevant for OAuth logins, where the login flow is managed by
the Auth server. If you are using email/phone logins you should set up your own redirects (within the email/sms template).
Sometimes you want to control where the user is redirected to after they are logged in. Supabase supports this for
any URL path on your website (the URL must either be on the same domain as your Site URL [see Auth>Settings in dashboard], or must match one of the Additional Redirect URLs [also in Auth>Settings]).
```js
const { user, session, error } = await supabase.auth.signIn(
{
provider: 'github',
},
{
redirectTo: 'https://example.com/welcome',
}
)
```
### Sign in with scopes.
If you need additional data from an OAuth provider, you can include a space-separated list of scopes in your request to get back an OAuth provider token.
You may also need to specify the scopes in the provider's OAuth app settings, depending on the provider.
```js
const { user, session, error } = await supabase.auth.signIn(
{
provider: 'github',
},
{
scopes: 'repo gist notifications',
}
)
const oAuthToken = session.provider_token // use to access provider API
```
### Sign in using a refresh token (e.g. in React Native).
If you are completing a sign up or login in a React Native app you can pass the refresh token obtained from the provider to obtain a session.
```js
// An example using Expo's `AuthSession`
const redirectUri = AuthSession.makeRedirectUri({ useProxy: false })
const provider = 'google'
AuthSession.startAsync({
authUrl: `https://MYSUPABASEAPP.supabase.co/auth/v1/authorize?provider=${provider}&redirect_to=${redirectUri}`,
returnUrl: redirectUri,
}).then(async (response: any) => {
if (!response) return
const { user, session, error } = await supabase.auth.signIn({
refreshToken: response.params?.refresh_token,
})
})
```
- Requires either an email and password or a phone number and password.
@@ -11,7 +11,7 @@ import TabItem from '@theme/TabItem'
Creates a new user.
```js
const { user, session, error } = await supabase.auth.signUp({
const { data, error } = await supabase.auth.signUp({
email: 'example@email.com',
password: 'example-password',
})
@@ -209,7 +209,7 @@ The redirect url embedded in the email link
### Sign up.
```js
const { user, session, error } = await supabase.auth.signUp({
const { data, error } = await supabase.auth.signUp({
email: 'example@email.com',
password: 'example-password',
})
@@ -218,37 +218,14 @@ const { user, session, error } = await supabase.auth.signUp({
### Sign up with additional user meta data.
```js
const { user, session, error } = await supabase.auth.signUp(
{
email: 'example@email.com',
password: 'example-password',
},
{
const { data, error } = await supabase.auth.signUp({
email: 'example@email.com',
password: 'example-password',
options: {
data: {
first_name: 'John',
age: 27,
},
}
)
```
### Sign up with third-party providers.
You can sign up with OAuth providers using the [`signIn()`](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers) method.
### Sign up with Phone.
Supabase supports Phone Auth. After a user has verified their number, they can use the [`signIn()`](/docs/reference/javascript/auth-signin#sign-in-using-phone) method.
```js
const { user, session, error } = await supabase.auth.signUp({
phone: '+13334445555',
password: 'some-password',
})
// After receiving an SMS with One Time Password.
let { session, error } = await supabase.auth.verifyOTP({
phone: '+13334445555',
token: '123456',
},
})
```
@@ -1,178 +0,0 @@
---
id: auth-update
title: 'update()'
slug: /auth-update
custom_edit_url: https://github.com/supabase/supabase/edit/master/spec/supabase_js_v2_legacy.yml
---
import Tabs from '@theme/Tabs'
import TabItem from '@theme/TabItem'
Updates user data, if there is a logged in user.
```js
const { user, error } = await supabase.auth.update({ email: 'new@email.com' })
```
## Parameters
<ul className="method-list-group">
<li className="method-list-item">
<h4 className="method-list-item-label">
<span className="method-list-item-label-name">
UserAttributes
</span>
<span className="method-list-item-label-badge required">
required
</span>
<span className="method-list-item-validation">
<code>object</code>
</span>
</h4>
<div class="method-list-item-description">
No description provided.
</div>
<ul className="method-list-group">
<h5 class="method-list-title method-list-title-isChild expanded">Properties</h5>
<li className="method-list-item">
<h4 className="method-list-item-label">
<span className="method-list-item-label-name">
data
</span>
<span className="method-list-item-label-badge false">
optional
</span>
<span className="method-list-item-validation">
<code>object</code>
</span>
</h4>
<div class="method-list-item-description">
A custom data object for user_metadata that a user can modify. Can be any JSON.
</div>
</li>
<li className="method-list-item">
<h4 className="method-list-item-label">
<span className="method-list-item-label-name">
email
</span>
<span className="method-list-item-label-badge false">
optional
</span>
<span className="method-list-item-validation">
<code>string</code>
</span>
</h4>
<div class="method-list-item-description">
The user's email.
</div>
</li>
<li className="method-list-item">
<h4 className="method-list-item-label">
<span className="method-list-item-label-name">
email_change_token
</span>
<span className="method-list-item-label-badge false">
optional
</span>
<span className="method-list-item-validation">
<code>string</code>
</span>
</h4>
<div class="method-list-item-description">
An email change token.
</div>
</li>
<li className="method-list-item">
<h4 className="method-list-item-label">
<span className="method-list-item-label-name">
password
</span>
<span className="method-list-item-label-badge false">
optional
</span>
<span className="method-list-item-validation">
<code>string</code>
</span>
</h4>
<div class="method-list-item-description">
The user's password.
</div>
</li>
<li className="method-list-item">
<h4 className="method-list-item-label">
<span className="method-list-item-label-name">
phone
</span>
<span className="method-list-item-label-badge false">
optional
</span>
<span className="method-list-item-validation">
<code>string</code>
</span>
</h4>
<div class="method-list-item-description">
The user's phone.
</div>
</li>
</ul>
</li>
</ul>
## Notes
User email: Email updates will send an email to both the user's current and new email with a confirmation link by default.
To toggle this behavior off and only send a single confirmation link to the new email, toggle "Double confirm email changes" under "Authentication" -> "Settings" off.
User metadata: It's generally better to store user data in a table inside your public schema (i.e. `public.users`).
Use the `update()` method if you have data which rarely changes or is specific only to the logged in user.
## Examples
### Update email for authenticated user.
Sends a "Confirm Email Change" email to the new email address.
```js
const { user, error } = await supabase.auth.update({ email: 'new@email.com' })
```
### Update password for authenticated user.
```js
const { user, error } = await supabase.auth.update({ password: 'new password' })
```
### Update a user's metadata.
```js
const { user, error } = await supabase.auth.update({
data: { hello: 'world' },
})
```
@@ -11,7 +11,7 @@ import TabItem from '@theme/TabItem'
Updates user data, if there is a logged in user.
```js
const { user, error } = await supabase.auth.updateUser({
const { data, error } = await supabase.auth.updateUser({
email: 'new@email.com',
})
```
@@ -162,7 +162,7 @@ Use the `update()` method if you have data which rarely changes or is specific o
Sends a "Confirm Email Change" email to the new email address.
```js
const { user, error } = await supabase.auth.updateUser({
const { data, error } = await supabase.auth.updateUser({
email: 'new@email.com',
})
```
@@ -170,7 +170,7 @@ const { user, error } = await supabase.auth.updateUser({
### Update password for authenticated user.
```js
const { user, error } = await supabase.auth.updateUser({
const { data, error } = await supabase.auth.updateUser({
password: 'new password',
})
```
@@ -1,7 +0,0 @@
---
id: migration-guide
---
# Migration Guide
Migrating from v1 to v2.
+208 -3
View File
@@ -4,8 +4,213 @@ id: release-notes
# Release Notes
Supabase.js v2 release
Supabase.js v2 release notes.
## 2.0.0
## 2.0.0 Release Candidate
TBD
Install the latest with `npm install @supabase/supabase-js@2.0.0-rc.1`.
### Explicit constructor options
All client specific options within the constructor are keyed to the library: [PR](https://github.com/supabase/supabase-js/pull/458):
```jsx
const supabase = createClient(apiURL, apiKey, {
// subclient specific options
// should map 1 - 1 with the constructor options of the underlying library
// any options here will override the common options later on in the client
db: {
schema: 'public',
},
auth: {
autoRefreshToken: true,
persistSession: true,
detectSessionInUrl: true,
},
// realtime already does this :heart-eyes:
realtime: {
channels,
endpoint,
},
// common across all libraries
global: {
fetch: customFetch,
headers: DEFAULT_HEADERS,
},
})
```
### Typescript support
The libraries now support typescript.
```ts
// v2 - definitions are injected in `createClient()`
import type { Database } from './DatabaseDefinitions'
const supabase = createClient<Database>(SUPABASE_URL, ANON_KEY)
const { data } = await supabase.from('messages').select().match({ id: 1 })
// v1 -- previously definitions were injected in the `from()` method
supabase.from<Definitions['Message']>('messages').select('*')
```
Types can be generated via the CLI:
```bash
supabase start
supabase gen types typescript --local > DatabaseDefinitions.ts
```
### Data operations return minimal
`.insert()` / `.upsert()` / `.update()` / `.delete()` don't return rows by default: [PR](https://github.com/supabase/postgrest-js/pull/276).
Previously, these methods return inserted/updated/deleted rows by default (which caused [some confusion](https://github.com/supabase/supabase/discussions/1548)), and you can opt to not return it by specifying `returning: 'minimal'`. Now the default behavior is to not return rows. To return inserted/updated/deleted rows, add a `.select()` call at the end, e.g.:
```sql
const { data, error } = await supabase
.from('my_table')
.delete()
.eq('id', 1)
.select()
```
### New ordering defaults
`.order()` now defaults to Postgres’s default: [PR](https://github.com/supabase/postgrest-js/pull/283).
Previously `nullsFirst` defaults to `false` , meaning `null`s are ordered last. This is bad for performance if e.g. the column uses an index with `NULLS FIRST` (which is the default direction for indexes).
### Cookies and localstorage namespace
Storage key name in the Auth library has changed to include project reference which means that existing website that had their JWT expiry set to a longer time could find their user’s logged out with this upgrade.
```jsx
const defaultStorageKey = `sb-${
new URL(this.authUrl).hostname.split('.')[0]
}-auth-token`
```
### New Auth Types
Typescript typings have been reworked. `Session` interface now guarantees that it will always have an `access_token`, `refresh_token` and `user`
```jsx
interface Session {
provider_token?: string | null
access_token: string
expires_in?: number
expires_at?: number
refresh_token: string
token_type: string
user: User
}
```
### New Auth methods
We're removing the `signIn()` method in favor of more explicit function signatures:
`signInWithPassword()`, `signInWithPasswordless()`, and `signInWithOtp()`.
```ts
// v2
const { data } = await supabase.auth.signInWithPassword({
email: 'hello@example',
password: 'pass',
})
// v1
const { data } = await supabase.auth.signIn({
email: 'hello@example',
password: 'pass',
})
```
### New Realtime methods
There is a new `channel()` method in the Realtime library, which will be used for our Multiplayer updates.
```ts
supabaseClient
.channel('any_string_you_want')
.on('presence', { event: 'track' }, (payload) => {
console.log(payload)
})
.subscribe()
supabaseClient
.channel('any_string_you_want')
.on(
'postgres_changes',
{
event: 'INSERT',
schema: 'public',
table: 'movies',
},
(payload) => {
console.log(payload)
}
)
.subscribe()
```
We will deprecate the `.from().on().subscribe()` method previosuly used for listening to postgres changes.
### Deprecated setAuth()
Deprecated and removed `setAuth()` . To set a custom `access_token` jwt instead, pass the custom header into the `createClient()` method provided: ([PR](https://github.com/supabase/gotrue-js/pull/340))
### All changes
- `supabase-js`
- `shouldThrowOnError` has been removed until all the client libraries support this option ([PR](https://github.com/supabase/supabase-js/pull/490)).
- `postgrest-js`
- TypeScript typings have been reworked [PR](https://github.com/supabase/postgrest-js/pull/279)
- Use `undefined` instead of `null` for function params, types, etc. (https://github.com/supabase/postgrest-js/pull/278)
- Some features are now obsolete: (https://github.com/supabase/postgrest-js/pull/275)
- filter shorthands (e.g. `cs` vs. `contains`)
- `body` in response (vs. `data`)
- `upsert`ing through the `.insert()` method
- `auth` method on `PostgrestClient`
- client-level `throwOnError`
- `gotrue-js`
- `supabase-js` client allows passing a `storageKey` param which will allow the user to set the key used in local storage for storing the session. By default, this will be namespace-d with the supabase project ref. ([PR](https://github.com/supabase/supabase-js/pull/460))
- `signIn` method is now split into `signInWithPassword` , `signInWithPasswordless` , `signInWithOAuth` ([PR](https://github.com/supabase/gotrue-js/pull/304))
- Deprecated and removed `session()` , `user()` in favour of using `getSession()` instead. `getSession()` will always return a valid session if a user is already logged in, meaning no more random logouts. ([PR](https://github.com/supabase/gotrue-js/pull/299))
- Deprecated and removed setting for `multitab` support because `getSession()` and gotrue’s reuse interval setting takes care of session management across multiple tabs ([PR](https://github.com/supabase/gotrue-js/pull/366))
- No more throwing of random errors, gotrue-js v2 always returns a custom error type: ([PR](https://github.com/supabase/gotrue-js/pull/341))
- `AuthSessionMissingError`
- Indicates that a session is expected but missing
- `AuthNoCookieError`
- Indicates that a cookie is expected but missing
- `AuthInvalidCredentialsError`
- Indicates that the incorrect credentials were passed
- Renamed the `api` namespace to `admin` , the `admin` namespace will only contain methods that should only be used in a trusted server-side environment with the service role key
- Moved `resetPasswordForEmail` , `getUser` and `updateUser` to the `GoTrueClient` which means they will be accessible from the `supabase.auth` namespace in `supabase-js` instead of having to do `supabase.auth.api` to access them
- Removed `sendMobileOTP` , `sendMagicLinkEmail` in favor of `signInWithOtp`
- Removed `signInWithEmail`, `signInWithPhone` in favor of `signInWithPassword`
- Removed `signUpWithEmail` , `signUpWithPhone` in favor of `signUp`
- `storage-js`
- Return types are more strict. Functions types used to indicate that the data returned could be null even if there was no error. We now make use of union types which only mark the data as null if there is an error and vice versa. ([PR](https://github.com/supabase/storage-js/pull/60))
- The `upload` and `update` function returns the path of the object uploaded as the `path` parameter. Previously the returned value had the bucket name prepended to the path which made it harder to pass the value on to other storage-js methods since all methods take the bucket name and path separately. We also chose to call the returned value `path` instead of `Key` ([PR](https://github.com/supabase/storage-js/pull/75))
- `getPublicURL` only returns the public URL inside the data object. This keeps it consistent with our other methods of returning only within the data object. No error is returned since this method cannot does not throw an error ([PR](https://github.com/supabase/storage-js/pull/93))
- signed urls are returned as `signedUrl` instead of `signedURL` in both `createSignedUrl` and `createSignedUrls` ([PR](https://github.com/supabase/storage-js/pull/94))
- Encodes URLs returned by `createSignedUrl`, `createSignedUrls` and `getPublicUrl` ([PR](https://github.com/supabase/storage-js/pull/86))
- `createsignedUrl` used to return a url directly and and within the data object. This was inconsistent. Now we always return values only inside the data object across all methods. ([PR](https://www.notion.so/LW5-supabase-js-v2-7b0bfcdf571d4f20b9b7a9308883f24b))
- `createBucket` returns a data object instead of the name of the bucket directly. ([PR](https://github.com/supabase/storage-js/pull/89))
- Fixed types for metadata ([PR](https://github.com/supabase/storage-js/pull/90))
- Better error types make it easier to track down what went wrong quicker.
- `SupabaseStorageClient` is no longer exported. Use `StorageClient` instead. ([PR](https://github.com/supabase/storage-js/pull/92)).
- `realtime-js`
- `RealtimeSubscription` class no longer exists and replaced by `RealtimeChannel`.
- `RealtimeClient`'s `disconnect` method now returns type of `void` . It used to return type of `Promise<{ error: Error | null; data: boolean }`.
- Removed `removeAllSubscriptions` and `removeSubscription` methods from `SupabaseClient` class.
- Removed `SupabaseRealtimeClient` class.
- Removed `SupabaseQueryBuilder` class.
- Removed `SupabaseEventTypes` type.
- Thinking about renaming this to something like `RealtimePostgresChangeEvents` and moving it to `realtime-js` v2.
- Removed `.from(’table’).on(’INSERT’, () ⇒ {}).subscribe()` in favor of new Realtime client API.
- `functions-js`
- supabase-js v1 only threw an error if the fetch call itself threw an error (network errors, etc) and not if the function returned HTTP errors like 400s or 500s. We have changed this behaviour to return an error if your function throws an error.
- We have introduced new error types to distinguish between different kinds of errors. A `FunctionsHttpError` error is returned if your function throws an error, `FunctionsRelayError` if the Supabase Relay has an error processing your function and `FunctionsFetchError` if there is a network error in calling your function.
- The correct content-type headers are automatically attached when sending the request if you don’t pass in a `Content-Type` header and pass in an argument to your function. We automatically attach the content type for `Blob`, `ArrayBuffer`, `File`, `FormData` ,`String` . If it doesn’t match any of these we assume the payload is `json` , we serialise the payload as JSON and attach the content type as `application/json`.
- `responseType` does not need to be explicitly passed in. We parse the response based on the `Content-Type` response header sent by the function. We support parsing the responses as `text`, `json`, `blob`, `form-data` and are parsed as `text` by default.
+2 -2
View File
@@ -32,13 +32,13 @@ const frameworks = [
{
name: 'Expo',
logo: ExpoLogo,
href: 'https://github.com/supabase/supabase/tree/master/examples/todo-list/expo-todo-list',
href: 'https://github.com/supabase/examples/tree/main/supabase-js-v1/todo-list/expo-todo-list',
},
{ name: 'Flutter', logo: DartLogo, href: '/guides/with-flutter' },
{
name: 'JavaScript',
logo: JavascriptLogo,
href: 'https://github.com/supabase/supabase/tree/master/examples/auth/javascript-auth',
href: 'https://github.com/supabase/examples/tree/main/supabase-js-v1/auth/javascript-auth',
},
{
name: 'Next.js',
+11 -11
View File
@@ -4,7 +4,7 @@ title: Examples and Resources
description: 'Examples you can use to get started with Supabase'
---
We have a [set of examples](https://github.com/supabase/supabase/tree/master/examples) in our [main repository](https://github.com/supabase/supabase) to help you get started.
We have a [set of examples](https://github.com/supabase/examples) in our [main repository](https://github.com/supabase/supabase) to help you get started.
## Featured
@@ -53,23 +53,23 @@ By [Fireship](https://www.youtube.com/watch?v=WiwfiVdfRIc).
Build a basic Todo List with Supabase and your favorite frontend framework:
- [Expo Todo List.](https://github.com/supabase/supabase/tree/master/examples/todo-list/expo-todo-list)
- [Next.js Todo List.](https://github.com/supabase/supabase/tree/master/examples/todo-list/nextjs-todo-list)
- [React Todo List.](https://github.com/supabase/supabase/tree/master/examples/todo-list/react-todo-list)
- [Svelte Todo List.](https://github.com/supabase/supabase/tree/master/examples/todo-list/sveltejs-todo-list)
- [Vue 3 Todo List (Typescript).](https://github.com/supabase/supabase/tree/master/examples/todo-list/vue3-ts-todo-list)
- [Angular Todo List.](https://github.com/supabase/supabase/tree/master/examples/todo-list/angular-todo-list)
- [Expo Todo List.](https://github.com/supabase/examples/tree/main/supabase-js-v1/todo-list/expo-todo-list)
- [Next.js Todo List.](https://github.com/supabase/examples/tree/main/supabase-js-v1/todo-list/nextjs-todo-list)
- [React Todo List.](https://github.com/supabase/examples/tree/main/supabase-js-v1/todo-list/react-todo-list)
- [Svelte Todo List.](https://github.com/supabase/examples/tree/main/supabase-js-v1/todo-list/sveltejs-todo-list)
- [Vue 3 Todo List (Typescript).](https://github.com/supabase/examples/tree/main/supabase-js-v1/todo-list/vue3-ts-todo-list)
- [Angular Todo List.](https://github.com/supabase/examples/tree/main/supabase-js-v1/todo-list/angular-todo-list)
- [Nuxt 3 Todo List.](https://github.com/nuxt-community/supabase-module/tree/main/demo)
### Auth examples
- [Supabase Auth with vanilla JavaScript.](https://github.com/supabase/supabase/tree/master/examples/auth/javascript-auth). Use Supabase without any frontend frameworks.
- [Supabase Auth with Next.js SSR.](https://github.com/supabase/supabase/tree/master/examples/nextjs-with-supabase-auth) Uses cookies to persist auth between the server and the client.
- [Supabase Auth with vanilla JavaScript.](https://github.com/supabase/examples/tree/main/supabase-js-v1/auth/javascript-auth). Use Supabase without any frontend frameworks.
- [Supabase Auth with Next.js SSR.](https://github.com/supabase/examples/tree/main/supabase-js-v1/nextjs-with-supabase-auth) Uses cookies to persist auth between the server and the client.
- [Supabase Auth with RedwoodJS.](https://redwood-playground-auth.netlify.app/supabase) Try out Supabase authentication in the [RedwoodJS](https://redwoodjs.com) Authentication Playground complete with OAuth support and code samples.
### Collaborative
- [Next.js Slack Clone.](https://github.com/supabase/supabase/tree/master/examples/slack-clone/nextjs-slack-clone)
- [Next.js Slack Clone.](https://github.com/supabase/examples/tree/main/supabase-js-v1/slack-clone/nextjs-slack-clone)
## Community
@@ -115,7 +115,7 @@ Build a basic Todo List with Supabase and your favorite frontend framework:
- Supabase + Svelte Trello clone. [GitHub](https://github.com/joshnuss/supabase-kanban)
- Supabase + Expo Starter. [GitHub](https://github.com/codingki/react-native-expo-template/tree/master/template-typescript-bottom-tabs-supabase-auth-flow)
- Supabase + Nest.js. [GitHub](https://github.com/hiro1107/nestjs-supabase-auth)
- Supabase + Cloudflare Workers. [GitHub](https://github.com/supabase/supabase/tree/master/examples/with-cloudflare-workers)
- Supabase + Cloudflare Workers. [GitHub](https://github.com/supabase/examples/tree/main/supabase-js-v1/with-cloudflare-workers)
- Supabase + Cloudflare Workers + Webpack. [GitHub](https://github.com/signalnerve/supabase-workers-proxy)
- Realtime chat app with Supabase + React. [GitHub](https://github.com/shwosner/realtime-chat-supabase-react)
- Repository.surf: GitHub insights dashboard. [GitHub](https://github.com/supabase/repository.surf)
+4 -4
View File
@@ -10,12 +10,12 @@ const examples = [
{
name: 'With supabase-js',
description: 'Use the Supabase client inside your Edge Function.',
href: 'https://github.com/supabase/supabase/tree/master/examples/edge-functions',
href: 'https://github.com/supabase/examples/tree/main/supabase-js-v1/edge-functions',
},
{
name: 'With CORS headers',
description: 'Send CORS headers for invoking from the browser.',
href: 'https://github.com/supabase/supabase/tree/master/examples/edge-functions/supabase/functions/browser-with-cors/index.ts',
href: 'https://github.com/supabase/examples/tree/main/supabase-js-v1/edge-functions/supabase/functions/browser-with-cors',
},
{
name: 'React Native with Stripe',
@@ -88,7 +88,7 @@ The command outputs a URL to the Supabase Dashboard which you can open to find v
By default Edge Functions require a valid JWT to be send in the authorization header. This header is automatically set when invoking your function via a Supabase client library.
If you want to use Edge Functions to handle webhooks (e.g. [Stripe payment webhooks](https://github.com/supabase/supabase/tree/master/examples/edge-functions/supabase/functions/stripe-webhooks), or [chat bot webhooks](https://github.com/supabase/supabase/tree/master/examples/edge-functions/supabase/functions/telegram-bot) etc.), you need to pass the `--no-verify-jwt` flag when deploying your function.
If you want to use Edge Functions to handle webhooks (e.g. [Stripe payment webhooks](https://github.com/supabase/examples/tree/main/supabase-js-v1/edge-functions/supabase/functions/stripe-webhooks), or [chat bot webhooks](https://github.com/supabase/examples/tree/main/supabase-js-v1/edge-functions/supabase/functions/telegram-bot) etc.), you need to pass the `--no-verify-jwt` flag when deploying your function.
:::
@@ -235,7 +235,7 @@ supabase secrets list
## Examples
You can find a list of useful [Edge Function Examples](https://github.com/supabase/supabase/tree/master/examples/edge-functions) in our GitHub repository.
You can find a list of useful [Edge Function Examples](https://github.com/supabase/examples/tree/main/supabase-js-v1/edge-functions) in our GitHub repository.
<div class="container" style={{ padding: 0 }}>
<div class="row is-multiline">
+1 -1
View File
@@ -31,7 +31,7 @@ keep all public files in a "public" bucket, and other files that require logged-
## Getting started
This is a quick guide that shows the basic functionality of Supabase Storage. Find a full
[example application in GitHub](https://github.com/supabase/supabase/tree/master/examples/user-management/nextjs-ts-user-management),
[example application in GitHub](https://github.com/supabase/examples/tree/main/supabase-js-v1/user-management/nextjs-ts-user-management),
which you can deploy yourself.
**Note before begin** : File, Folder, and Bucket names **must follow** [AWS Safe Characters naming guideline](https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-keys.html) and avoid use of any other characters
+1 -1
View File
@@ -423,7 +423,7 @@ import { View } from 'react-native'
import { Session } from '@supabase/supabase-js'
export default function App() {
const [session, setSession] = useState<Session|null>(null);
const [session, setSession] = (useState < Session) | (null > null)
useEffect(() => {
setSession(supabase.auth.session())
+51 -10
View File
@@ -214,7 +214,7 @@ export default function Auth() {
const handleLogin = async (email) => {
try {
setLoading(true)
const { error } = await supabase.auth.signIn({ email })
const { error } = await supabase.auth.signInWithOtp({ email })
if (error) throw error
alert('Check your email for the login link!')
} catch (error) {
@@ -278,10 +278,27 @@ export default function Account({ session }) {
getProfile()
}, [session])
async function getCurrentUser() {
const {
data: { session },
error,
} = await supabase.auth.getSession()
if (error) {
throw error
}
if (!session?.user) {
throw new Error('User not logged in')
}
return session.user
}
async function getProfile() {
try {
setLoading(true)
const user = supabase.auth.user()
const user = await getCurrentUser()
let { data, error, status } = await supabase
.from('profiles')
@@ -308,7 +325,7 @@ export default function Account({ session }) {
async function updateProfile({ username, website, avatar_url }) {
try {
setLoading(true)
const user = supabase.auth.user()
const user = await getCurrentUser()
const updates = {
id: user.id,
@@ -318,9 +335,7 @@ export default function Account({ session }) {
updated_at: new Date(),
}
let { error } = await supabase.from('profiles').upsert(updates, {
returning: 'minimal', // Don't return the value after inserting
})
let { error } = await supabase.from('profiles').upsert(updates)
if (error) {
throw error
@@ -391,14 +406,40 @@ import Auth from '../components/Auth'
import Account from '../components/Account'
export default function Home() {
const [isLoading, setIsLoading] = useState(true)
const [session, setSession] = useState(null)
useEffect(() => {
setSession(supabase.auth.session())
let mounted = true
supabase.auth.onAuthStateChange((_event, session) => {
setSession(session)
})
async function getInitialSession() {
const {
data: { session },
} = await supabase.auth.getSession()
// only update the react state if the component is still mounted
if (mounted) {
if (session) {
setSession(session)
}
setIsLoading(false)
}
}
getInitialSession()
const { subscription } = supabase.auth.onAuthStateChange(
(_event, session) => {
setSession(session)
}
)
return () => {
mounted = false
subscription?.unsubscribe()
}
}, [])
return (
+10 -12
View File
@@ -26,7 +26,6 @@ const sidebars = {
'initializing',
'typescript-support',
'release-notes',
'migration-guide',
],
collapsed: false,
},
@@ -41,11 +40,11 @@ const sidebars = {
'generated/auth-signout',
'generated/auth-getsession',
'generated/auth-getuser',
'generated/auth-update',
'generated/auth-updateuser',
'generated/auth-setsession',
'generated/auth-onauthstatechange',
'generated/auth-api-getuser',
'generated/auth-api-resetpasswordforemail',
'generated/auth-getuser',
'generated/auth-resetpasswordforemail',
],
collapsed: true,
},
@@ -53,14 +52,13 @@ const sidebars = {
type: 'category',
label: 'Auth (Server Only)',
items: [
'generated/auth-api-listusers',
'generated/auth-api-createuser',
'generated/auth-api-deleteuser',
'generated/auth-api-generatelink',
'generated/auth-api-inviteuserbyemail',
// 'generated/auth-api-sendmobileotp',
'generated/auth-api-getuserbyid',
'generated/auth-api-updateuserbyid',
'generated/auth-admin-listusers',
'generated/auth-admin-createuser',
'generated/auth-admin-deleteuser',
'generated/auth-admin-generatelink',
'generated/auth-admin-inviteuserbyemail',
'generated/auth-admin-getuserbyid',
'generated/auth-admin-updateuserbyid',
],
collapsed: true,
},
@@ -78,9 +78,9 @@ Launch your database in South Africa.
### Community
One of the community, [@ftonato](https://github.com/ftonato), has built an amazing [example](https://github.com/supabase/supabase/tree/master/examples/with-stencil) that shows how to use Supabase with [Stencil](https://stenciljs.com/) (a Web Component compiler built by they [Ionic](https://ionicframework.com/) team.)
One of the community, [@ftonato](https://github.com/ftonato), has built an amazing [example](https://github.com/supabase/examples/tree/main/supabase-js-v1/with-stencil) that shows how to use Supabase with [Stencil](https://stenciljs.com/) (a Web Component compiler built by they [Ionic](https://ionicframework.com/) team.)
[Check it out!](https://github.com/supabase/supabase/tree/master/examples/with-stencil)
[Check it out!](https://github.com/supabase/examples/tree/main/supabase-js-v1/with-stencil)
![Supabase with Stencil](/images/blog/feb/supabase-stencil.png)
@@ -95,7 +95,7 @@ Thanks to a comunity contribution ([@\_mateomorris](https://twitter.com/_mateomo
- Ionic Integration by [Simon Grimm](https://www.youtube.com/user/saimon1924) [[Video](https://www.youtube.com/watch?v=pl9XfIWutKE)]
- Flutter Integration by [Aditya Thakur](https://www.youtube.com/channel/UChCAJNpMwoEUYCsE_eSyU4w) by [[Video](https://www.youtube.com/watch?v=fqfHEZvQPlY)]
- Svelte Integration by [Khaerunnisa Isnaeni](https://www.youtube.com/channel/UCqNDj6eQeTLHuEwgEHWOGjw) [[Video](https://www.youtube.com/watch?v=odPYzJJyEJI)]
- An [example app](https://github.com/supabase/supabase/tree/master/examples/nextjs-ts-user-management) for adding User Profiles to your Next.js app
- An [example app](https://github.com/supabase/examples/tree/main/supabase-js-v1/user-management) for adding User Profiles to your Next.js app
![Supabase Stars march 2021](/images/blog/march-2021/supabase-stars-march-2021.png)
@@ -95,12 +95,12 @@ type AccountHolder {
It’s all anyone seems to be [talking about](https://twitter.com/jkup/status/1456360115205033989). We genuinely love what [Remix](https://remix.run/) are doing, so it’s only right that we show off how Remix and Supabase work well together.
Check out the new [Remix Auth example](https://github.com/supabase/supabase/tree/master/examples/remix-auth), and let us know what you think.
Check out the new [Remix Auth example](https://github.com/supabase/examples/tree/main/supabase-js-v1/auth/remix-auth), and let us know what you think.
### Expo Todo List
Our React Native example has been correctly updated to be an Expo example.
[Check it out here](https://github.com/supabase/supabase/tree/master/examples/todo-list/expo-todo-list).
[Check it out here](https://github.com/supabase/examples/tree/main/supabase-js-v1/todo-list/expo-todo-list).
## Video: API requests with Database Webhooks
@@ -98,7 +98,7 @@ Our observability pipeline has been built [using Logflare](https://supabase.com/
![new —> deploy —> invoke —> logs](/images/blog/launch-week-4/thursday-functions/functions-new-deploy-invoke-logs.gif)
new —> deploy —> invoke —> logs
To round off the end-to-end experience, `supabase-js` now works in Deno, making it easy to interact with the rest of your Supabase project from within your Edge Functions. Your project's URLs, API keys, and database connection strings are made available as environment variables within your Function to make this even easier. And if you want to interact with third-party APIs which require a secret key, such as Stripe, you can easily and securely make these available to your Function as environment variables via the Supabase CLI. To get an idea for what is possible, check out our examples page [here](https://github.com/supabase/supabase/tree/master/examples/edge-functions).
To round off the end-to-end experience, `supabase-js` now works in Deno, making it easy to interact with the rest of your Supabase project from within your Edge Functions. Your project's URLs, API keys, and database connection strings are made available as environment variables within your Function to make this even easier. And if you want to interact with third-party APIs which require a secret key, such as Stripe, you can easily and securely make these available to your Function as environment variables via the Supabase CLI. To get an idea for what is possible, check out our examples page [here](https://github.com/supabase/examples/tree/main/supabase-js-v1/edge-functions).
## Quickstart
@@ -132,7 +132,7 @@ Here's a collection of resources that will help you get started building with Su
- [Edge Functions Guide](https://supabase.com/docs/guides/functions)
- [Edge Functions Quickstart video](https://youtu.be/rzglqRdZUQE)
- [Supabase CLI local development guide](https://supabase.com/docs/guides/local-development)
- [Edge Functions examples](https://github.com/supabase/supabase/tree/master/examples/edge-functions)
- [Edge Functions examples](https://github.com/supabase/examples/tree/main/supabase-js-v1/edge-functions)
### Additional Info
@@ -99,6 +99,6 @@ If you're inspired to build, check out some of the latest resources:
- [Edge Functions Guide](https://supabase.com/docs/guides/functions)
- [Edge Functions Quickstart video](https://youtu.be/rzglqRdZUQE)
- [Supabase CLI local development guide](https://supabase.com/docs/guides/local-development)
- [Edge Functions examples](https://github.com/supabase/supabase/tree/master/examples/edge-functions)
- [Edge Functions examples](https://github.com/supabase/examples/tree/main/supabase-js-v1/edge-functions)
[^1]: Updated on June 14 2022 for search optimization: Removed links as account does not exist anymore on GitHub
@@ -20,9 +20,9 @@ Wildcard redirects are especially useful for Jamstack platforms with preview dep
## Supabase Edge functions with Webhooks
Now you can deploy functions with optional JWT verification. This makes it easier to trigger Edge Functions with webhooks. Use the -no-verify-jwt flag when deploying your functions via the CLI to enable this mode. You can test this out with our [Edge Functions Telegram Bot example](https://github.com/supabase/supabase/tree/master/examples/edge-functions/supabase/functions/telegram-bot).
Now you can deploy functions with optional JWT verification. This makes it easier to trigger Edge Functions with webhooks. Use the -no-verify-jwt flag when deploying your functions via the CLI to enable this mode. You can test this out with our [Edge Functions Telegram Bot example](https://github.com/supabase/examples/tree/main/supabase-js-v1/edge-functions/supabase/functions/telegram-bot).
[![graphql](/images/blog/2022-may/stripe-webhook.jpg)](https://github.com/supabase/supabase/tree/master/examples/edge-functions/supabase/functions/telegram-bot)
[![graphql](/images/blog/2022-may/stripe-webhook.jpg)](https://github.com/supabase/examples/tree/main/supabase-js-v1/edge-functions/supabase/functions/telegram-bot)
## Metrics for everybody
@@ -39,7 +39,7 @@ The Policy editor now includes a “Target roles” field. We now have a strong
## State of DB 2022
Basedash conducted a survey that takes the pulse of the current databases that teams, individuals, startups, enterprises and hobbyists are using.
Supabase was listed in two categories, including the first place in satisfaction for hosting providers (84% of users would use us again 🙏). [Full results](https://stateofdb.com/).
[![secret scanning](/images/blog/2022-may/databasesurvey.jpg)](https://stateofdb.com/)
@@ -67,7 +67,7 @@ There is an opportunity to work inside the growth team at Supabase. It's still a
### Deepnote
Deepnote is a data notebook that’s built for collaboration — Jupyter compatible, works magically in the cloud, and sharing is as easy as sending a link.
You can connect your Supabase Postgres Database to your Deepnote notebooks to quickly analyze data and share your findings with others. [Check out the guide](https://docs.deepnote.com/integrations/supabase).
[![supabrew](/images/blog/2022-may/graph.jpg)](https://docs.deepnote.com/integrations/supabase)
@@ -21,8 +21,8 @@ const BuiltExamples = () => {
</Button>
</Link>
<Link
href="https://github.com/supabase/supabase/tree/master/examples"
as="https://github.com/supabase/supabase/tree/master/examples"
href="https://github.com/supabase/examples"
as="https://github.com/supabase/examples"
passHref
>
<Button as="a" type="default" icon={<IconGitHub />} size="small">
@@ -42,8 +42,8 @@ function GithubExamples() {
</Button>
</Link>
<Link
href="https://github.com/supabase/supabase/tree/master/examples"
as="https://github.com/supabase/supabase/tree/master/examples"
href="https://github.com/supabase/examples"
as="https://github.com/supabase/examples"
>
<Button size="small" as="a" type="default" icon={<IconGitHub size={12} />}>
Official GitHub library
+1 -1
View File
@@ -23,7 +23,7 @@ export const createUserExample: ExampleProps = {
const supabase = createClient(supabaseUrl, supabaseKey)
// Create a new user
const { user, error } = await supabase.auth.signUp({
const { user, error } = await supabase.auth.signUpWithPassword({
email: 'example@email.com',
password: 'example-password',
})
+8 -8
View File
@@ -21,7 +21,7 @@
"author_url": "https://github.com/supabase",
"author_img": "https://avatars.githubusercontent.com/u/54469796",
"repo_name": "nextjs-slack-clone",
"repo_url": "https://github.com/supabase/supabase/tree/master/examples/slack-clone/nextjs-slack-clone",
"repo_url": "https://github.com/supabase/examples/tree/main/supabase-js-v1/slack-clone/nextjs-slack-clone",
"vercel_deploy_url": "",
"demo_url": ""
},
@@ -86,7 +86,7 @@
"author_url": "https://github.com/supabase",
"author_img": "https://avatars.githubusercontent.com/u/54469796",
"repo_name": "javascript-auth",
"repo_url": "https://github.com/supabase/supabase/tree/master/examples/auth/javascript-auth",
"repo_url": "https://github.com/supabase/examples/tree/main/supabase-js-v1/auth/javascript-auth",
"vercel_deploy_url": "",
"demo_url": "https://auth-vanilla-js.vercel.app/"
},
@@ -99,7 +99,7 @@
"author_url": "https://github.com/supabase",
"author_img": "https://avatars.githubusercontent.com/u/54469796",
"repo_name": "expo-todo-list",
"repo_url": "https://github.com/supabase/supabase/tree/master/examples/todo-list/expo-todo-list",
"repo_url": "https://github.com/supabase/examples/tree/main/supabase-js-v1/todo-list/react-native-ts-todo-list",
"vercel_deploy_url": "",
"demo_url": ""
},
@@ -112,7 +112,7 @@
"author_url": "https://github.com/supabase",
"author_img": "https://avatars.githubusercontent.com/u/54469796",
"repo_name": "nextjs-todo-list",
"repo_url": "https://github.com/supabase/supabase/tree/master/examples/todo-list/nextjs-todo-list",
"repo_url": "https://github.com/supabase/examples/tree/main/supabase-js-v1/todo-list/nextjs-todo-list",
"vercel_deploy_url": "",
"demo_url": "https://supabase-nextjs-todo-list.vercel.app/"
},
@@ -125,7 +125,7 @@
"author_url": "https://github.com/supabase",
"author_img": "https://avatars.githubusercontent.com/u/54469796",
"repo_name": "react-todo-list",
"repo_url": "https://github.com/supabase/supabase/tree/master/examples/todo-list/react-todo-list",
"repo_url": "https://github.com/supabase/examples/tree/main/supabase-js-v1/todo-list/react-todo-list",
"vercel_deploy_url": "",
"demo_url": ""
},
@@ -138,7 +138,7 @@
"author_url": "https://github.com/supabase",
"author_img": "https://avatars.githubusercontent.com/u/54469796",
"repo_name": "sveltejs-todo-list",
"repo_url": "https://github.com/supabase/supabase/tree/master/examples/todo-list/sveltejs-todo-list",
"repo_url": "https://github.com/supabase/examples/tree/main/supabase-js-v1/todo-list/sveltejs-todo-list",
"vercel_deploy_url": "",
"demo_url": ""
},
@@ -151,7 +151,7 @@
"author_url": "https://github.com/supabase",
"author_img": "https://avatars.githubusercontent.com/u/54469796",
"repo_name": "vue3-ts-todo-list",
"repo_url": "https://github.com/supabase/supabase/tree/master/examples/todo-list/vue3-ts-todo-list",
"repo_url": "https://github.com/supabase/examples/tree/main/supabase-js-v1/todo-list/vue3-ts-todo-list",
"vercel_deploy_url": "",
"demo_url": ""
},
@@ -164,7 +164,7 @@
"author_url": "https://github.com/geromegrignon",
"author_img": "https://avatars.githubusercontent.com/u/32737308",
"repo_name": "angular-todo-list",
"repo_url": "https://github.com/supabase/supabase/tree/master/examples/todo-list/angular-todo-list",
"repo_url": "https://github.com/supabase/examples/tree/main/supabase-js-v1/todo-list/angular-todo-list",
"vercel_deploy_url": "",
"demo_url": ""
}
+2 -2
View File
@@ -23,7 +23,7 @@
{
"imgUrl": "images/slack-clone.jpg",
"title": "Chat app with Next.js",
"url": "https://github.com/supabase/supabase/tree/master/examples/slack-clone/nextjs-slack-clone",
"url": "https://github.com/supabase/examples/tree/main/supabase-js-v1/slack-clone/nextjs-slack-clone",
"description": "Build a full-stack Slack clone using Next.js and Supabase.",
"icons": [
{
@@ -40,7 +40,7 @@
{
"imgUrl": "images/to-do-app.jpg",
"title": "Todo list with Vue.js",
"url": "https://github.com/supabase/supabase/tree/master/examples/todo-list/vue3-ts-todo-list",
"url": "https://github.com/supabase/examples/tree/main/supabase-js-v1/todo-list/vue3-ts-todo-list",
"description": "Build a simple todo list with Vue and Supabase.",
"icons": [
{
+1 -1
View File
@@ -11,7 +11,7 @@ const supabaseKey = 'public-anon-key'
const supabase = createClient(supabaseUrl, supabaseKey)
// Create a new user
const { user, error } = await supabase.auth.signUp({
const { user, error } = await supabase.auth.signUpWithPassword({
email: 'example@email.com',
password: 'example-password',
})
@@ -5,7 +5,7 @@ export default [
description: '',
code: `
// Sign up with email
const { user, error } = await supabase.auth.signUp({
const { user, error } = await supabase.auth.signUpWithPassword({
email: 'example@email.com',
password: 'example-password',
})
+51
View File
@@ -1413,6 +1413,57 @@ module.exports = withMDX({
source: '/docs/guides/local-development',
destination: '/docs/guides/cli/local-development',
},
// V2 redirects
// {
// permanent: true,
// source: '/docs/reference/javascript/auth-update',
// destination: '/docs/reference/javascript/auth-updateuser',
// },
// {
// permanent: true,
// source: '/docs/reference/javascript/auth-api-getuser',
// destination: '/docs/reference/javascript/auth-getuser',
// },
// {
// permanent: true,
// source: '/docs/reference/javascript/auth-api-resetpasswordforemail',
// destination: '/docs/reference/javascript/auth-resetpasswordforemail',
// },
// {
// permanent: true,
// source: '/docs/reference/javascript/auth-api-listusers',
// destination: '/docs/reference/javascript/auth-admin-listusers',
// },
// {
// permanent: true,
// source: '/docs/reference/javascript/auth-api-createuser',
// destination: '/docs/reference/javascript/auth-admin-createuser',
// },
// {
// permanent: true,
// source: '/docs/reference/javascript/auth-api-deleteuser',
// destination: '/docs/reference/javascript/auth-admin-deleteuser',
// },
// {
// permanent: true,
// source: '/docs/reference/javascript/auth-api-generatelink',
// destination: '/docs/reference/javascript/auth-admin-generatelink',
// },
// {
// permanent: true,
// source: '/docs/reference/javascript/auth-api-inviteuserbyemail',
// destination: '/docs/reference/javascript/auth-admin-inviteuserbyemail',
// },
// {
// permanent: true,
// source: '/docs/reference/javascript/auth-api-getuserbyid',
// destination: '/docs/reference/javascript/auth-admin-getuserbyid',
// },
// {
// permanent: true,
// source: '/docs/reference/javascript/auth-api-updateuserbyid',
// destination: '/docs/reference/javascript/auth-admin-updateuserbyid',
// },
]
},
})
+1 -1
View File
@@ -155,7 +155,7 @@ function StoragePage() {
author_img={'https://avatars.githubusercontent.com/u/54469796'}
repo_name={'nextjs-ts-user-management'}
repo_url={
'https://github.com/supabase/supabase/tree/master/examples/user-management/nextjs-ts-user-management'
'https://github.com/supabase/examples/tree/main/supabase-js-v1/user-management/nextjs-ts-user-management'
}
vercel_deploy_url={
'https://vercel.com/new/git/external?repository-url=https%3A%2F%2Fgithub.com%2Fsupabase%2Fsupabase%2Ftree%2Fmaster%2Fexamples%2Fuser-mangement%2Fnextjs-ts-user-management&project-name=supabase-user-management&repository-name=supabase-user-management&demo-title=Supabase%20User%20Management&demo-description=An%20example%20web%20app%20using%20Supabase%20and%20Next.js&demo-url=https%3A%2F%2Fsupabase-nextjs-ts-user-management.vercel.app&demo-image=https%3A%2F%2Fi.imgur.com%2FZ3HkQqe.png&integration-ids=oac_jUduyjQgOyzev1fjrW83NYOv&external-id=nextjs-user-management'
+775 -18
View File
File diff suppressed because it is too large. Load diff
+109 -356
View File
@@ -33,7 +33,7 @@ pages:
isSpotlight: true
js: |
```js
const { user, session, error } = await supabase.auth.signUp({
const { data, error } = await supabase.auth.signUp({
email: 'example@email.com',
password: 'example-password',
})
@@ -42,282 +42,106 @@ pages:
isSpotlight: true
js: |
```js
const { user, session, error } = await supabase.auth.signUp(
const { data, error } = await supabase.auth.signUp(
{
email: 'example@email.com',
password: 'example-password',
},
{
data: {
first_name: 'John',
age: 27,
options: {
data: {
first_name: 'John',
age: 27,
}
}
}
)
```
- name: Sign up with third-party providers.
hideCodeBlock: true
auth.signInWithPassword():
title: 'signInWithPassword()'
$ref: '@supabase/gotrue-js.GoTrueClient.signInWithPassword'
notes: |
- Requires either an email and password or a phone number and password.
example:
- name: Sign in with Email.
description: |
You can sign up with OAuth providers using the [`signIn()`](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers) method.
- name: Sign up with Phone.
Sign in with email and password. After a user has verified their email, they can use the [`signInWithPassword()`](/docs/reference/javascript/auth-signin#sign-in-using-phone) method.
js: |
```js
const { data, error } = await supabase.auth.signInWithPassword({
email: 'example@email.com',
password: 'example-password',
})
```
- name: Sign in with Phone.
description: |
Supabase supports Phone Auth. After a user has verified their number, they can use the [`signIn()`](/docs/reference/javascript/auth-signin#sign-in-using-phone) method.
js: |
```js
const { user, session, error } = await supabase.auth.signUp({
const { data, error } = await supabase.auth.signInWithPassword({
phone: '+13334445555',
password: 'some-password',
})
// After receiving an SMS with One Time Password.
let { session, error } = await supabase.auth.verifyOTP({
let { data, error } = await supabase.auth.verifyOtp({
phone: '+13334445555',
token: '123456',
})
```
auth.signInWithPassword():
title: 'signInWithPassword()'
$ref: '@supabase/gotrue-js.GoTrueClient.signInWithPassword'
notes: |
- A user can sign up either via email or OAuth.
- If you provide `email` without a `password`, the user will be sent a magic link.
- The magic link's destination URL is determined by the SITE_URL config variable. To change this, you can go to Authentication -> Settings on [app.supabase.com](https://app.supabase.com)
- Specifying a `provider` will open the browser to the relevant login page.
examples:
- name: Sign in with email.
isSpotlight: true
js: |
```js
const { user, session, error } = await supabase.auth.signIn({
email: 'example@email.com',
password: 'example-password',
})
```
- name: Sign in with magic link.
description: If no password is provided, the user will be sent a "magic link" to their email address, which they can click to open your application with a valid session. By default, a given user can only request a Magic Link once every 60 seconds.
js: |
```js
const { user, session, error } = await supabase.auth.signIn({
email: 'example@email.com'
})
```
- name: Sign in using third-party providers.
description: Supabase supports many different [third-party providers](https://supabase.com/docs/guides/auth#providers).
js: |
```js
const { user, session, error } = await supabase.auth.signIn({
// provider can be 'github', 'google', 'gitlab', and more
provider: 'github'
})
```
- name: Sign in with Phone.
description: Supabase supports Phone Auth.
js: |
```js
const { user, session, error } = await supabase.auth.signIn({
phone: '+13334445555',
password: 'some-password',
})
```
- name: Sign in with redirect.
description: |
Note that the `redirectTo` param is only relevant for OAuth logins, where the login flow is managed by
the Auth server. If you are using email/phone logins you should set up your own redirects (within the email/sms template).
Sometimes you want to control where the user is redirected to after they are logged in. Supabase supports this for
any URL path on your website (the URL must either be on the same domain as your Site URL [see Auth>Settings in dashboard], or must match one of the Additional Redirect URLs [also in Auth>Settings]).
js: |
```js
const { user, session, error } = await supabase.auth.signIn({
provider: 'github'
}, {
redirectTo: 'https://example.com/welcome'
})
```
- name: Sign in with scopes.
description: |
If you need additional data from an OAuth provider, you can include a space-separated list of scopes in your request to get back an OAuth provider token.
You may also need to specify the scopes in the provider's OAuth app settings, depending on the provider.
js: |
```js
const { user, session, error } = await supabase.auth.signIn({
provider: 'github'
}, {
scopes: 'repo gist notifications'
})
const oAuthToken = session.provider_token // use to access provider API
```
- name: Sign in using a refresh token (e.g. in React Native).
description: |
If you are completing a sign up or login in a React Native app you can pass the refresh token obtained from the provider to obtain a session.
js: |
```js
// An example using Expo's `AuthSession`
const redirectUri = AuthSession.makeRedirectUri({ useProxy: false });
const provider = 'google';
AuthSession.startAsync({
authUrl: `https://MYSUPABASEAPP.supabase.co/auth/v1/authorize?provider=${provider}&redirect_to=${redirectUri}`,
returnUrl: redirectUri,
}).then(async (response: any) => {
if (!response) return;
const { user, session, error } = await supabase.auth.signIn({
refreshToken: response.params?.refresh_token,
});
});
```
auth.signInWithOtp():
title: 'signInWithOtp()'
$ref: '@supabase/gotrue-js.GoTrueClient.signInWithOtp'
notes: |
- A user can sign up either via email or OAuth.
- If you provide `email` without a `password`, the user will be sent a magic link.
- This method is used for passwordless sign-ins where an otp is sent to the user's email or phone number.
- Requires either an email or phone number.
- If you're using an email, you can configure whether you want the user to receive a magiclink or an otp.
- If you're using phone, you can configure whether you want the user to receive a magiclink or an otp.
- The magic link's destination URL is determined by the SITE_URL config variable. To change this, you can go to Authentication -> Settings on [app.supabase.com](https://app.supabase.com)
- Specifying a `provider` will open the browser to the relevant login page.
examples:
- name: Sign in with email.
isSpotlight: true
description: The user will be sent an otp to their email. By default, a given user can only request an otp once every 60 seconds.
js: |
```js
const { user, session, error } = await supabase.auth.signIn({
const { data, error } = await supabase.auth.signInWithOtp({
email: 'example@email.com',
password: 'example-password',
})
```
- name: Sign in with magic link.
description: If no password is provided, the user will be sent a "magic link" to their email address, which they can click to open your application with a valid session. By default, a given user can only request a Magic Link once every 60 seconds.
- name: Sign in with sms otp.
isSpotlight: true
description: The user will be sent an otp to their phone number. By default, a given user can only request an otp once every 60 seconds.
js: |
```js
const { user, session, error } = await supabase.auth.signIn({
email: 'example@email.com'
})
```
- name: Sign in using third-party providers.
description: Supabase supports many different [third-party providers](https://supabase.com/docs/guides/auth#providers).
js: |
```js
const { user, session, error } = await supabase.auth.signIn({
// provider can be 'github', 'google', 'gitlab', and more
provider: 'github'
})
```
- name: Sign in with Phone.
description: Supabase supports Phone Auth.
js: |
```js
const { user, session, error } = await supabase.auth.signIn({
const { data, error } = await supabase.auth.signInWithPassword({
phone: '+13334445555',
password: 'some-password',
})
```
- name: Sign in with redirect.
description: |
Note that the `redirectTo` param is only relevant for OAuth logins, where the login flow is managed by
the Auth server. If you are using email/phone logins you should set up your own redirects (within the email/sms template).
Sometimes you want to control where the user is redirected to after they are logged in. Supabase supports this for
any URL path on your website (the URL must either be on the same domain as your Site URL [see Auth>Settings in dashboard], or must match one of the Additional Redirect URLs [also in Auth>Settings]).
js: |
```js
const { user, session, error } = await supabase.auth.signIn({
provider: 'github'
}, {
redirectTo: 'https://example.com/welcome'
})
```
- name: Sign in with scopes.
description: |
If you need additional data from an OAuth provider, you can include a space-separated list of scopes in your request to get back an OAuth provider token.
You may also need to specify the scopes in the provider's OAuth app settings, depending on the provider.
js: |
```js
const { user, session, error } = await supabase.auth.signIn({
provider: 'github'
}, {
scopes: 'repo gist notifications'
})
const oAuthToken = session.provider_token // use to access provider API
```
- name: Sign in using a refresh token (e.g. in React Native).
description: |
If you are completing a sign up or login in a React Native app you can pass the refresh token obtained from the provider to obtain a session.
js: |
```js
// An example using Expo's `AuthSession`
const redirectUri = AuthSession.makeRedirectUri({ useProxy: false });
const provider = 'google';
AuthSession.startAsync({
authUrl: `https://MYSUPABASEAPP.supabase.co/auth/v1/authorize?provider=${provider}&redirect_to=${redirectUri}`,
returnUrl: redirectUri,
}).then(async (response: any) => {
if (!response) return;
const { user, session, error } = await supabase.auth.signIn({
refreshToken: response.params?.refresh_token,
});
});
```
auth.signInWithOAuth():
title: 'signInWithOAuth()'
$ref: '@supabase/gotrue-js.GoTrueClient.signInWithOAuth'
notes: |
- A user can sign up either via email or OAuth.
- If you provide `email` without a `password`, the user will be sent a magic link.
- The magic link's destination URL is determined by the SITE_URL config variable. To change this, you can go to Authentication -> Settings on [app.supabase.com](https://app.supabase.com)
- Specifying a `provider` will open the browser to the relevant login page.
- This method is used for signing in using a third-party provider.
- Supabase supports many different [third-party providers](https://supabase.com/docs/guides/auth#providers).
examples:
- name: Sign in with email.
isSpotlight: true
- name: Sign in using a third-party provider.
js: |
```js
const { user, session, error } = await supabase.auth.signIn({
email: 'example@email.com',
password: 'example-password',
})
```
- name: Sign in with magic link.
description: If no password is provided, the user will be sent a "magic link" to their email address, which they can click to open your application with a valid session. By default, a given user can only request a Magic Link once every 60 seconds.
js: |
```js
const { user, session, error } = await supabase.auth.signIn({
email: 'example@email.com'
})
```
- name: Sign in using third-party providers.
description: Supabase supports many different [third-party providers](https://supabase.com/docs/guides/auth#providers).
js: |
```js
const { user, session, error } = await supabase.auth.signIn({
// provider can be 'github', 'google', 'gitlab', and more
const { data, error } = await supabase.auth.signInWithOAuth({
provider: 'github'
})
```
- name: Sign in with Phone.
description: Supabase supports Phone Auth.
js: |
```js
const { user, session, error } = await supabase.auth.signIn({
phone: '+13334445555',
password: 'some-password',
})
```
- name: Sign in with redirect.
- name: Sign in using a third-party provider with redirect.
description: |
Note that the `redirectTo` param is only relevant for OAuth logins, where the login flow is managed by
the Auth server. If you are using email/phone logins you should set up your own redirects (within the email/sms template).
Sometimes you want to control where the user is redirected to after they are logged in. Supabase supports this for
The `redirectTo` param will only applied on the callback made from the third-party provider. It does not redirect the user immediately after invoking this method.
In order for the `redirectTo` param to be allowed, one needs to include it in an allowlist. Supabase supports this for
any URL path on your website (the URL must either be on the same domain as your Site URL [see Auth>Settings in dashboard], or must match one of the Additional Redirect URLs [also in Auth>Settings]).
js: |
```js
const { user, session, error } = await supabase.auth.signIn({
const { user, session, error } = await supabase.auth.signInWithOAuth({
provider: 'github'
}, {
redirectTo: 'https://example.com/welcome'
})
options: {
redirectTo: 'https://example.com/welcome'
}
}
```
- name: Sign in with scopes.
description: |
@@ -325,33 +149,14 @@ pages:
You may also need to specify the scopes in the provider's OAuth app settings, depending on the provider.
js: |
```js
const { user, session, error } = await supabase.auth.signIn({
const { data, error } = await supabase.auth.signInWithOAuth({
provider: 'github'
}, {
scopes: 'repo gist notifications'
options: {
scopes: 'repo gist notifications'
}
})
const oAuthToken = session.provider_token // use to access provider API
const oAuthToken = data.session.provider_token // use to access provider API
```
- name: Sign in using a refresh token (e.g. in React Native).
description: |
If you are completing a sign up or login in a React Native app you can pass the refresh token obtained from the provider to obtain a session.
js: |
```js
// An example using Expo's `AuthSession`
const redirectUri = AuthSession.makeRedirectUri({ useProxy: false });
const provider = 'google';
AuthSession.startAsync({
authUrl: `https://MYSUPABASEAPP.supabase.co/auth/v1/authorize?provider=${provider}&redirect_to=${redirectUri}`,
returnUrl: redirectUri,
}).then(async (response: any) => {
if (!response) return;
const { user, session, error } = await supabase.auth.signIn({
refreshToken: response.params?.refresh_token,
});
});
```
auth.signOut():
title: 'signOut()'
$ref: '@supabase/gotrue-js.GoTrueClient.signOut'
@@ -362,7 +167,6 @@ pages:
```js
const { error } = await supabase.auth.signOut()
```
auth.getSession():
title: 'getSession()'
$ref: '@supabase/gotrue-js.GoTrueClient.getSession'
@@ -371,22 +175,27 @@ pages:
isSpotlight: true
js: |
```js
const session = supabase.auth.session()
const { data, error } = supabase.auth.getSession()
```
auth.getUser():
title: 'getUser()'
$ref: '@supabase/gotrue-js.GoTrueClient.getUser'
notes: |
This method gets the user object from memory.
- This method gets the user object using the current session.
- Fetches the user object from the database instead of local storage.
examples:
- name: Get the logged in user
- name: Get the logged in user with the current existing session
isSpotlight: true
js: |
```js
const user = await supabase.auth.getUser()
const user = supabase.auth.getUser()
```
- name: Get the logged in user with a custom access token jwt.
isSpotlight: true
js: |
```js
const user = supabase.auth.getUser(jwt)
```
auth.updateUser():
title: 'updateUser()'
$ref: '@supabase/gotrue-js.GoTrueClient.updateUser'
@@ -403,13 +212,13 @@ pages:
isSpotlight: true
js: |
```js
const { user, error } = await supabase.auth.updateUser({email: 'new@email.com'})
const { data, error } = await supabase.auth.updateUser({email: 'new@email.com'})
```
- name: Update password for authenticated user.
isSpotlight: true
js: |
```js
const { user, error } = await supabase.auth.updateUser({password: 'new password'})
const { data, error } = await supabase.auth.updateUser({password: 'new password'})
```
- name: Update a user's metadata.
isSpotlight: true
@@ -419,66 +228,18 @@ pages:
data: { hello: 'world' }
})
```
auth.setSession():
title: 'setSession()'
$ref: '@supabase/gotrue-js.GoTrueClient.setSession'
examples:
- name: Basic example.
description: This is most useful on server-side functions where you cannot log the user in, but have access to the user's access token.
description: Sets the session data from refresh_token and returns current session or an error if the refresh_token is invalid.
isSpotlight: true
js: |
```js
function apiFunction(req, res) {
// Assuming the access token was sent as a header "X-Supabase-Auth"
const { access_token } = req.get('X-Supabase-Auth')
// You can now use it within a Supabase Client
const supabase = createClient("https://xyzcompany.supabase.co", "public-anon-key")
const { user, error } = supabase.auth.setAuth(access_token)
// This client will now send requests as this user
const { data } = await supabase.from('your_table').select()
const { data, error } = supabase.auth.setSession(refresh_token)
}
```
- name: With Express.
isSpotlight: true
js: |
```js
/**
* Make a request from the client to your server function
*/
async function makeApiRequest() {
const token = newClient.session()?.access_token
await fetch('https://example.com/withAuth', {
method: 'GET',
withCredentials: true,
credentials: 'include',
headers: {
'Content-Type': 'application/json',
'Authorization': bearer, // Your own auth
'X-Supabase-Auth': token, // Set the Supabase user
}
})
}
/**
* Use the Auth token in your server-side function.
*/
async function apiFunction(req, res) {
const { access_token } = req.get('X-Supabase-Auth')
// You can now use it within a Supabase Client
const supabase = createClient("https://xyzcompany.supabase.co", "public-anon-key")
const { user, error } = supabase.auth.setAuth(access_token)
// This client will now send requests as this user
const { data } = await supabase.from('your_table').select()
}
```
auth.onAuthStateChange():
title: 'onAuthStateChange()'
$ref: '@supabase/gotrue-js.GoTrueClient.onAuthStateChange'
@@ -533,7 +294,7 @@ pages:
if (event == 'PASSWORD_RECOVERY') console.log('PASSWORD_RECOVERY', session)
})
```
auth.api.getUserById():
auth.admin.getUserById():
title: 'getUserById()'
$ref: '@supabase/gotrue-js.GoTrueAdminApi.getUserById'
notes: |
@@ -545,10 +306,10 @@ pages:
isSpotlight: true
js: |
```js
const { user, error } = await supabase.auth.api.getUserById(1)
const { user, error } = await supabase.auth.admin.getUserById(1)
```
auth.api.listUsers():
auth.admin.listUsers():
title: 'listUsers()'
$ref: '@supabase/gotrue-js.GoTrueAdminApi.listUsers'
notes: |
@@ -559,10 +320,9 @@ pages:
isSpotlight: true
js: |
```js
const { data: user, error } = await supabase.auth.api.listUsers()
const { data: user, error } = await supabase.auth.admin.listUsers()
```
auth.api.createUser():
auth.admin.createUser():
title: 'createUser()'
$ref: '@supabase/gotrue-js.GoTrueAdminApi.createUser'
notes: |
@@ -574,7 +334,7 @@ pages:
isSpotlight: true
js: |
```js
const { data: user, error } = await supabase.auth.api.createUser({
const { data, error } = await supabase.auth.admin.createUser({
email: 'user@email.com',
password: 'password',
user_metadata: { name: 'Yoda' }
@@ -584,7 +344,7 @@ pages:
isSpotlight: true
js: |
```js
const { data: user, error } = await supabase.auth.api.createUser({
const { data, error } = await supabase.auth.admin.createUser({
email: 'user@email.com',
email_confirm: true
})
@@ -593,13 +353,12 @@ pages:
isSpotlight: true
js: |
```js
const { data: user, error } = await supabase.auth.api.createUser({
const { data, error } = await supabase.auth.admin.createUser({
phone: '1234567890',
phone_confirm: true
})
```
auth.api.deleteUser():
auth.admin.deleteUser():
title: 'deleteUser()'
$ref: '@supabase/gotrue-js.GoTrueAdminApi.deleteUser'
notes: |
@@ -610,12 +369,12 @@ pages:
isSpotlight: true
js: |
```js
const { data: user, error } = await supabase.auth.api.deleteUser(
const { data, error } = await supabase.auth.admin.deleteUser(
'715ed5db-f090-4b8c-a067-640ecee36aa0'
)
```
auth.api.inviteUserByEmail():
auth.admin.inviteUserByEmail():
title: 'inviteUserByEmail()'
$ref: '@supabase/gotrue-js.GoTrueAdminApi.inviteUserByEmail'
notes: |
@@ -626,34 +385,16 @@ pages:
isSpotlight: false
js: |
```js
const { data: user, error } = await supabase.auth
.api
.inviteUserByEmail('email@example.com')
const { data, error } = await supabase.auth.admin.inviteUserByEmail('email@example.com')
```
# auth.api.sendMobileOTP():
# title: 'sendMobileOTP()'
# $ref: '@supabase/gotrue-js.GoTrueAdminApi.sendMobileOTP'
# notes: |
# - Requires a `service_role` key.
# - This function should only be called on a server. Never expose your `service_role` key in the browser.
# examples:
# - name: Basic example.
# isSpotlight: false
# js: |
# ```js
# const { data: user, error } = await supabase.auth
# .api
# .sendMobileOTP('12345879')
# ```
auth.api.resetPasswordForEmail():
auth.resetPasswordForEmail():
title: 'resetPasswordForEmail()'
$ref: '@supabase/gotrue-js.GoTrueClient.resetPasswordForEmail'
notes: |
Sends a reset request to an email address.
When the user clicks the reset link in the email they will be forwarded to:
When the user clicks the reset link in the email they will be forwarded to the site url or the redirect url specified:
`<SITE_URL>#access_token=x&refresh_token=y&expires_in=z&token_type=bearer&type=recovery`
@@ -662,36 +403,48 @@ pages:
You should then use the access_token in the url and new password to update the user as follows:
```js
const { error, data } = await supabase.auth.api
.updateUser(access_token, { password : new_password })
const { error, data } = await supabase.auth.updateUser({ password : new_password })
```
examples:
- name: Reset password
isSpotlight: true
js: |
```js
const { data, error } = await supabase.auth.api
.resetPasswordForEmail('user@email.com')
const { error, data } = await supabase.auth.resetPasswordForEmail(email, options: {
redirectTo: 'https://example.com/update-password',
})
```
auth.api.generateLink():
auth.admin.generateLink():
title: 'generateLink()'
$ref: '@supabase/gotrue-js.GoTrueAdminApi.generateLink'
notes: |
- Requires a `service_role` key.
- This function should only be called on a server. Never expose your `service_role` key in the browser.
examples:
- name: Generate invite link.
isSpotlight: false
- name: Generate a signup link.
isSpotlight: true
js: |
```js
const { data: user, error } = await supabase.auth.api.generateLink(
'invite',
const { data, error } = await supabase.auth.admin.generateLink(
'email@example.com'
'signup',
{
'password': 'secret'
}
)
```
- name: Generate an invite link.
isSpotlight: true
js: |
```js
const { data, error } = await supabase.auth.admin.generateLink(
'email@example.com'
'invite',
)
```
auth.api.updateUserById():
auth.admin.updateUserById():
title: 'updateUserById()'
$ref: '@supabase/gotrue-js.GoTrueAdminApi.updateUserById'
notes: |
@@ -702,7 +455,7 @@ pages:
isSpotlight: true
js: |
```js
const { data: user, error } = await supabase.auth.api.updateUserById(
const { data: user, error } = await supabase.auth.admin.updateUserById(
'6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',
{ email: 'new@email.com' }
)
@@ -711,7 +464,7 @@ pages:
isSpotlight: true
js: |
```js
const { data: user, error } = await supabase.auth.api.updateUserById(
const { data: user, error } = await supabase.auth.admin.updateUserById(
'6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',
{ password: 'new_password' }
)
@@ -720,7 +473,7 @@ pages:
isSpotlight: true
js: |
```js
const { data: user, error } = await supabase.auth.api.updateUserById(
const { data: user, error } = await supabase.auth.admin.updateUserById(
'6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',
{ user_metadata: { hello: 'world' } }
)
@@ -729,7 +482,7 @@ pages:
isSpotlight: true
js: |
```js
const { data: user, error } = await supabase.auth.api.updateUserById(
const { data: user, error } = await supabase.auth.admin.updateUserById(
'6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',
{ app_metadata: { plan: 'trial' } }
)
@@ -738,7 +491,7 @@ pages:
isSpotlight: true
js: |
```js
const { data: user, error } = await supabase.auth.api.updateUserById(
const { data: user, error } = await supabase.auth.admin.updateUserById(
'6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',
{ email_confirm: true }
)
@@ -747,7 +500,7 @@ pages:
isSpotlight: true
js: |
```js
const { data: user, error } = await supabase.auth.api.updateUserById(
const { data: user, error } = await supabase.auth.admin.updateUserById(
'6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',
{ phone_confirm: true }
)