From 597c554e7abcf3578eeba3dcd9f0f1643982fc80 Mon Sep 17 00:00:00 2001 From: Simon Ha Date: Tue, 30 Apr 2024 16:34:58 -0400 Subject: [PATCH] [WIP] 20771/fix auth get user for edge functions (#23155) * docs: fix RPC sql example * docs: fix auth.getUser() calls to use auth.getUser(jwt) - add lines to get token before calling auth.getUser() as session is not set after setting authHeader in client * Apply suggestions from code review --------- Co-authored-by: Charis <26616127+charislam@users.noreply.github.com> --- apps/docs/content/guides/functions/auth.mdx | 4 ++-- .../functions/select-from-table-with-auth-rls/index.ts | 6 +++++- .../supabase/functions/upstash-redis-ratelimit/index.ts | 6 +++++- 3 files changed, 12 insertions(+), 4 deletions(-) diff --git a/apps/docs/content/guides/functions/auth.mdx b/apps/docs/content/guides/functions/auth.mdx index 609f18a46de..06f768bc8d2 100644 --- a/apps/docs/content/guides/functions/auth.mdx +++ b/apps/docs/content/guides/functions/auth.mdx @@ -40,11 +40,11 @@ Deno.serve(async (req: Request) => { const supabaseClient = createClient( Deno.env.get('SUPABASE_URL') ?? '', Deno.env.get('SUPABASE_ANON_KEY') ?? '', - { global: { headers: { Authorization: req.headers.get('Authorization')! } } } ) // Get the session or user object - const { data } = await supabaseClient.auth.getUser() + const token = authHeader.replace('Bearer ', '') + const { data } = await supabaseClient.auth.getUser(token) const user = data.user return new Response(JSON.stringify({ user }), { diff --git a/examples/edge-functions/supabase/functions/select-from-table-with-auth-rls/index.ts b/examples/edge-functions/supabase/functions/select-from-table-with-auth-rls/index.ts index 5654c97a95b..93fc185c480 100644 --- a/examples/edge-functions/supabase/functions/select-from-table-with-auth-rls/index.ts +++ b/examples/edge-functions/supabase/functions/select-from-table-with-auth-rls/index.ts @@ -28,10 +28,14 @@ Deno.serve(async (req: Request) => { }, } ) + + // First get the token from the Authorization header + const token = req.headers.get('Authorization').replace('Bearer ', '') + // Now we can get the session or user object const { data: { user }, - } = await supabaseClient.auth.getUser() + } = await supabaseClient.auth.getUser(token) // And we can run queries in the context of our authenticated user const { data, error } = await supabaseClient.from('users').select('*') diff --git a/examples/edge-functions/supabase/functions/upstash-redis-ratelimit/index.ts b/examples/edge-functions/supabase/functions/upstash-redis-ratelimit/index.ts index cd266975080..9ecac3b9ff9 100644 --- a/examples/edge-functions/supabase/functions/upstash-redis-ratelimit/index.ts +++ b/examples/edge-functions/supabase/functions/upstash-redis-ratelimit/index.ts @@ -20,10 +20,14 @@ Deno.serve(async (req) => { }, } ) + + // First get the token from the Authorization header + const token = req.headers.get('Authorization').replace('Bearer ', '') + // Now we can get the session or user object const { data: { user }, - } = await supabaseClient.auth.getUser() + } = await supabaseClient.auth.getUser(token) if (!user) throw new Error('no user') console.log(user.id)