From 6eb40f17a7fb8a61ab4d12a1f7c1158381457cfd Mon Sep 17 00:00:00 2001 From: Katerina Skroumpelou Date: Wed, 17 Jun 2026 18:53:27 +0300 Subject: [PATCH] docs: purge safeGetSession + getUser from auth example code (#47042) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sweeps the example code that creating-a-client.mdx and other auth docs pull via $CodeSample, so the rendered pages match the "use getClaims()" guidance. Also adds Database type stubs and parameterizes SupabaseClient across SvelteKit and Hono examples. Fixes #40985 ## Summary by CodeRabbit ## Release Notes * **Documentation** * Updated OAuth server getting-started guide to use a claims-based consent/auth gate and preserve the authorization identifier on redirect. * Added the `auth_methods` partial across framework sections in the server-side “creating a client” guide. * **Refactor** * Updated authentication examples for Hono, Next.js, and SvelteKit to rely on JWT claims for logged-in checks and protected routes. * Streamlined example auth state and UI rendering to use claims-derived information. * **Type Updates** * Improved TypeScript typing for Supabase clients and app auth data across examples, including generated database type stubs. --------- Co-authored-by: Chris Chinchilla --- .../auth/oauth-server/getting-started.mdx | 9 +++-- .../auth/server-side/creating-a-client.mdx | 10 +++++ examples/auth/hono-full/src/database.types.ts | 4 ++ examples/auth/hono-full/src/index.tsx | 6 +-- .../src/middleware/auth.middleware.ts | 4 +- examples/auth/hono/src/database.types.ts | 4 ++ .../hono/src/middleware/auth.middleware.ts | 4 +- .../auth/nextjs-full/app/private/page.tsx | 7 ++-- .../nextjs-full/components/AuthButton.tsx | 9 ++--- examples/auth/sveltekit-full/src/app.d.ts | 10 ++--- .../auth/sveltekit-full/src/database.types.ts | 4 ++ .../auth/sveltekit-full/src/hooks.server.ts | 40 +++++-------------- .../src/routes/+layout.server.ts | 6 +-- .../sveltekit-full/src/routes/+layout.svelte | 6 +-- .../auth/sveltekit-full/src/routes/+layout.ts | 19 ++++----- .../src/routes/private/+page.svelte | 6 +-- examples/auth/sveltekit/src/app.d.ts | 10 +---- examples/auth/sveltekit/src/database.types.ts | 4 ++ examples/auth/sveltekit/src/hooks.server.ts | 27 +------------ .../sveltekit/src/routes/+layout.server.ts | 6 +-- examples/auth/sveltekit/src/routes/+layout.ts | 15 +++---- .../sveltekit-user-management/src/app.d.ts | 5 ++- .../src/database.types.ts | 4 ++ 23 files changed, 97 insertions(+), 122 deletions(-) create mode 100644 examples/auth/hono-full/src/database.types.ts create mode 100644 examples/auth/hono/src/database.types.ts create mode 100644 examples/auth/sveltekit-full/src/database.types.ts create mode 100644 examples/auth/sveltekit/src/database.types.ts create mode 100644 examples/user-management/sveltekit-user-management/src/database.types.ts diff --git a/apps/docs/content/guides/auth/oauth-server/getting-started.mdx b/apps/docs/content/guides/auth/oauth-server/getting-started.mdx index 1d40792deaf..a7f70ebcf6c 100644 --- a/apps/docs/content/guides/auth/oauth-server/getting-started.mdx +++ b/apps/docs/content/guides/auth/oauth-server/getting-started.mdx @@ -189,6 +189,8 @@ Here's how to build a minimal authorization page at your configured path (e.g., > +<$Partial path="auth_methods.mdx" /> + ```tsx // app/oauth/consent/page.tsx import { createServerClient } from '@supabase/ssr' @@ -221,11 +223,10 @@ export default async function ConsentPage({ ) // Check if user is authenticated - const { - data: { user }, - } = await supabase.auth.getUser() + const { data } = await supabase.auth.getClaims() + const claims = data?.claims - if (!user) { + if (!claims) { // Redirect to login, preserving authorization_id redirect(`/login?redirect=/oauth/consent?authorization_id=${authorizationId}`) } diff --git a/apps/docs/content/guides/auth/server-side/creating-a-client.mdx b/apps/docs/content/guides/auth/server-side/creating-a-client.mdx index 30a6f5d2802..92ce3e4f2d2 100644 --- a/apps/docs/content/guides/auth/server-side/creating-a-client.mdx +++ b/apps/docs/content/guides/auth/server-side/creating-a-client.mdx @@ -172,6 +172,8 @@ You need setup code to configure a Supabase client to use cookies. Once you have Use the browser client in code that runs on the browser, and the server client in code that runs on the server. +<$Partial path="auth_methods.mdx" /> + + +<$Partial path="auth_methods.mdx" /> +
<$CodeTabs> <$CodeSample path="/auth/nextjs/proxy.ts" meta="name=proxy.ts" language="typescript" /> @@ -291,6 +297,8 @@ Set up server-side hooks in `src/hooks.server.ts`. The hooks: - Check user authentication. - Guard protected pages. +<$Partial path="auth_methods.mdx" /> + <$CodeSample path="/auth/sveltekit/src/hooks.server.ts" meta="name=src/hooks.server.ts" @@ -843,6 +851,8 @@ language="typescript" You can now use this middleware in your Hono application to create a server Supabase client that can be used to make authenticated requests. +<$Partial path="auth_methods.mdx" /> + <$CodeSample path="/auth/hono/src/index.tsx" meta="name=src/index.tsx" diff --git a/examples/auth/hono-full/src/database.types.ts b/examples/auth/hono-full/src/database.types.ts new file mode 100644 index 00000000000..06410b30b2d --- /dev/null +++ b/examples/auth/hono-full/src/database.types.ts @@ -0,0 +1,4 @@ +// Replace this file by running: +// npx supabase gen types typescript --local > src/database.types.ts +// or pass --project-id for a remote project. +export type Database = Record diff --git a/examples/auth/hono-full/src/index.tsx b/examples/auth/hono-full/src/index.tsx index 8560a3bcabf..a458903fcb3 100644 --- a/examples/auth/hono-full/src/index.tsx +++ b/examples/auth/hono-full/src/index.tsx @@ -6,11 +6,11 @@ app.use('*', supabaseMiddleware()) const routes = app.get('/api/user', async (c) => { const supabase = getSupabase(c) - const { data, error } = await supabase.auth.getUser() + const { data, error } = await supabase.auth.getClaims() if (error) console.log('error', error) - if (!data?.user) { + if (!data?.claims) { return c.json({ message: 'You are not logged in.', }) @@ -18,7 +18,7 @@ const routes = app.get('/api/user', async (c) => { return c.json({ message: 'You are logged in!', - userId: data.user, + userId: data.claims.sub, }) }) diff --git a/examples/auth/hono-full/src/middleware/auth.middleware.ts b/examples/auth/hono-full/src/middleware/auth.middleware.ts index 89daae8a19f..a9b578e7429 100644 --- a/examples/auth/hono-full/src/middleware/auth.middleware.ts +++ b/examples/auth/hono-full/src/middleware/auth.middleware.ts @@ -4,9 +4,11 @@ import type { Context, MiddlewareHandler } from 'hono' import { env } from 'hono/adapter' import { setCookie } from 'hono/cookie' +import type { Database } from '../database.types' + declare module 'hono' { interface ContextVariableMap { - supabase: SupabaseClient + supabase: SupabaseClient } } diff --git a/examples/auth/hono/src/database.types.ts b/examples/auth/hono/src/database.types.ts new file mode 100644 index 00000000000..06410b30b2d --- /dev/null +++ b/examples/auth/hono/src/database.types.ts @@ -0,0 +1,4 @@ +// Replace this file by running: +// npx supabase gen types typescript --local > src/database.types.ts +// or pass --project-id for a remote project. +export type Database = Record diff --git a/examples/auth/hono/src/middleware/auth.middleware.ts b/examples/auth/hono/src/middleware/auth.middleware.ts index b8896494b25..f0a01eb0a20 100644 --- a/examples/auth/hono/src/middleware/auth.middleware.ts +++ b/examples/auth/hono/src/middleware/auth.middleware.ts @@ -4,9 +4,11 @@ import type { Context, MiddlewareHandler } from 'hono' import { env } from 'hono/adapter' import { setCookie } from 'hono/cookie' +import type { Database } from '../database.types' + declare module 'hono' { interface ContextVariableMap { - supabase: SupabaseClient + supabase: SupabaseClient } } diff --git a/examples/auth/nextjs-full/app/private/page.tsx b/examples/auth/nextjs-full/app/private/page.tsx index f025b2dfc6f..b0585f19439 100644 --- a/examples/auth/nextjs-full/app/private/page.tsx +++ b/examples/auth/nextjs-full/app/private/page.tsx @@ -8,11 +8,10 @@ import { redirect } from 'next/navigation' export default async function ProtectedPage() { const supabase = await createClient() - const { - data: { user }, - } = await supabase.auth.getUser() + const { data } = await supabase.auth.getClaims() + const claims = data?.claims - if (!user) { + if (!claims) { return redirect('/login') } diff --git a/examples/auth/nextjs-full/components/AuthButton.tsx b/examples/auth/nextjs-full/components/AuthButton.tsx index c07ea4da058..97b296f4b63 100644 --- a/examples/auth/nextjs-full/components/AuthButton.tsx +++ b/examples/auth/nextjs-full/components/AuthButton.tsx @@ -5,9 +5,8 @@ import { redirect } from 'next/navigation' export default async function AuthButton() { const supabase = await createClient() - const { - data: { user }, - } = await supabase.auth.getUser() + const { data } = await supabase.auth.getClaims() + const claims = data?.claims const signOut = async () => { 'use server' @@ -17,9 +16,9 @@ export default async function AuthButton() { return redirect('/login') } - return user ? ( + return claims ? (
- Hey, {user.email}! + Hey, {claims.email}!