diff --git a/apps/docs/content/guides/auth/auth-helpers/nextjs.mdx b/apps/docs/content/guides/auth/auth-helpers/nextjs.mdx index 2b478b4251d..9094f5609a4 100644 --- a/apps/docs/content/guides/auth/auth-helpers/nextjs.mdx +++ b/apps/docs/content/guides/auth/auth-helpers/nextjs.mdx @@ -73,7 +73,7 @@ export async function middleware(req) { const supabase = createMiddlewareClient({ req, res }) // Refresh session if expired - required for Server Components - await supabase.auth.getSession() + await supabase.auth.getUser() return res } diff --git a/apps/docs/spec/supabase_js_v2.yml b/apps/docs/spec/supabase_js_v2.yml index 1594bbf2544..66ba85c94bc 100644 --- a/apps/docs/spec/supabase_js_v2.yml +++ b/apps/docs/spec/supabase_js_v2.yml @@ -825,7 +825,7 @@ functions: notes: | - This method fetches the user object from the database instead of local session. - This method is useful for checking if the user is authorized because it validates the user's access token JWT on the server. - - Should be used only when you require the most current user data. For faster results, `getSession().session.user` is recommended. + - Should always be used when checking for user authorization on the server. On the client, you can instead use `getSession().session.user` for faster results. `getSession` is insecure on the server. examples: - id: get-the-logged-in-user-with-the-current-existing-session name: Get the logged in user with the current existing session