From 73e6f97c65dc8270874d8915313e09350fedeec0 Mon Sep 17 00:00:00 2001 From: Stojan Dimitrovski Date: Thu, 5 Jun 2025 11:24:19 +0200 Subject: [PATCH] docs: add web3 cli instructions (#36188) --- apps/docs/content/guides/auth/auth-web3.mdx | 28 +++++++++++++++++++-- 1 file changed, 26 insertions(+), 2 deletions(-) diff --git a/apps/docs/content/guides/auth/auth-web3.mdx b/apps/docs/content/guides/auth/auth-web3.mdx index 4cdd718943b..3eb05326a42 100644 --- a/apps/docs/content/guides/auth/auth-web3.mdx +++ b/apps/docs/content/guides/auth/auth-web3.mdx @@ -21,21 +21,45 @@ The Web3 wallet application uses the information contained in the message to pro Not all Web3 wallet applications show a dedicated confirmation dialog for these sign in messages. In that case the Web3 wallet shows a traditional message signature confirmation dialog. +## Enable the Web3 provider + +In the dashboard navigate to your project's [Authentication Providers](/dashboard/project/_/auth/providers) section and enable the Web3 Wallet provider. + +In the CLI add the following config to your `supabase/config.toml` file: + +```toml +[auth.web3.solana] +enabled = true +``` + ### Potential for abuse User accounts that sign in with their Web3 wallet will not have an email address or phone number associated with them. This can open your project to abuse as creating a Web3 wallet account is free and easy to automate and difficult to correlate with a real person's identity. -Control your project's exposure by configuring: +Control your project's exposure by configuring in the dashboard: - [Rate Limits for Web3](/dashboard/project/_/auth/rate-limits) - [Enable CAPTCHA protection](/docs/guides/auth/auth-captcha) +Or in the CLI: + +```toml +[auth.rate_limit] +# Number of Web3 logins that can be made in a 5 minute interval per IP address. +web3 = 30 + +[auth.captcha] +enabled = true +provider = "hcaptcha" # or other supported providers +secret = "0x0000000000000000000000000000000000000000" +``` + Many wallet applications will warn the user if the message sent for signing is not coming from the page they are currently visiting. To further prevent your Supabase project from receiving signed messages destined for other applications, you must register your application's URL using the [Redirect URL settings](/docs/guides/auth/redirect-urls). For example if the user is signing in to the page `https://example.com/sign-in` you should add the following configurations in the Redirect URL settings: - `https://example.com/sign-in/` (last slash is important) -- Alternatively set up a glob pattern such ash `https://example.com/**` +- Alternatively set up a glob pattern such as `https://example.com/**` ## Sign in with Ethereum