diff --git a/apps/docs/pages/guides/auth/quickstarts/react.mdx b/apps/docs/pages/guides/auth/quickstarts/react.mdx index 3dfdc081c80..8a852e454fd 100644 --- a/apps/docs/pages/guides/auth/quickstarts/react.mdx +++ b/apps/docs/pages/guides/auth/quickstarts/react.mdx @@ -58,7 +58,7 @@ export const meta = { ```bash Terminal - cd my-app && npm install @supabase/supabase-js @supabase/auth-ui-react + cd my-app && npm install @supabase/supabase-js @supabase/auth-ui-react @supabase/auth-ui-shared ``` diff --git a/apps/docs/pages/guides/auth/social-login/auth-google.mdx b/apps/docs/pages/guides/auth/social-login/auth-google.mdx index a4d2728207b..b066163eefb 100644 --- a/apps/docs/pages/guides/auth/social-login/auth-google.mdx +++ b/apps/docs/pages/guides/auth/social-login/auth-google.mdx @@ -289,6 +289,34 @@ async function handleSignInWithGoogle(response) { Use of nonce is recommended, though optional. Make sure each nonce is generated randomly and available both in the `data-nonce` attribute as well as in the `handleSignInWithGoogle` callback function; otherwise the ID token will not be accepted. +### Important Note on Nonce Validation + +Supabase Auth expects the nonce in Google's ID token to be hashed (specifically with SHA-256 and represented as a hexadecimal string). + +To succeed with nonce validation, you will need to provide a hashed version of the nonce to Google and the non-hashed version to the `signInWithIdToken` method. + +The following code snippet provides an example of how to create both versions in a web application: + +```js +// Adapted from https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/digest#converting_a_digest_to_a_hex_string + +import crypto from 'crypto' + +// ... + +const nonce = crypto.randomBytes(16).toString('base64') // Generate a random nonce +const encoder = new TextEncoder() +const encodedNonce = encoder.encode(nonce) // Encode the nonce +const hash = await crypto.subtle.digest('SHA-256', encodedNonce) // Hash it with SHA-256 +const bytes = new Uint8Array(hash) +const hashedNonce = Array.from(bytes) + .map((b) => b.toString(16).padStart(2, '0')) // Convert the hash to a hexadecimal string + .join('') + +// Use 'hashedNonce' when making the authentication request to Google +// Use 'nonce' when invoking the supabase.auth.signInWithIdToken() method +``` + ### Configuration [#configuration-personalized-sign-in-button] 1. Obtain OAuth credentials for your Google Cloud project in the [Credentials](https://console.developers.google.com/apis/credentials) page of the console. When creating a new credential, choose _Web application_. As you're using the Google sign in button, you should configure the _Authorized JavaScript origins_ and _Authorized redirect URIs_ to the website where the buttons appear. You should not use your Supabase project domain name. For this use case, the client secret provided is not needed and can be ignored. diff --git a/apps/docs/pages/guides/cli/getting-started.mdx b/apps/docs/pages/guides/cli/getting-started.mdx index dd01d4ffcf7..91d69bfe7f9 100644 --- a/apps/docs/pages/guides/cli/getting-started.mdx +++ b/apps/docs/pages/guides/cli/getting-started.mdx @@ -161,7 +161,7 @@ The CLI provides a number of commands to help you develop your project locally a - [Project](/docs/reference/cli/supabase-projects) and [Organization](/docs/reference/cli/supabase-orgs) management - [Database management](/docs/reference/cli/supabase-db) - [Database migrations](/docs/reference/cli/supabase-migration) and [Database Branching](/docs/reference/cli/supabase-branches) -- [Database debugigng tools](/docs/reference/cli/supabase-inspect-db-calls) +- [Database debugging tools](/docs/reference/cli/supabase-inspect-db-calls) - [Edge Function management](/docs/reference/cli/supabase-functions) - [Auth management](/docs/reference/cli/supabase-functions) - [Types Generators](/docs/reference/cli/supabase-gen) diff --git a/apps/docs/pages/guides/database/testing.mdx b/apps/docs/pages/guides/database/testing.mdx index 1ff2d912d66..7db3ed93dd6 100644 --- a/apps/docs/pages/guides/database/testing.mdx +++ b/apps/docs/pages/guides/database/testing.mdx @@ -63,8 +63,9 @@ Files=1, Tests=1, 1 wallclock secs ( 0.01 usr 0.00 sys + 0.04 cusr 0.02 csys Result: PASS ``` -## More resource +## More resources +- [Testing RLS policies](/docs/guides/auth/row-level-security#testing-policies) - [pgTAP extension](/docs/guides/database/extensions/pgtap) - Official [pgTAP documentation](https://pgtap.org/) diff --git a/apps/docs/pages/guides/getting-started/tutorials/with-nextjs.mdx b/apps/docs/pages/guides/getting-started/tutorials/with-nextjs.mdx index 4bf3351ce31..a771e0f5571 100644 --- a/apps/docs/pages/guides/getting-started/tutorials/with-nextjs.mdx +++ b/apps/docs/pages/guides/getting-started/tutorials/with-nextjs.mdx @@ -333,7 +333,7 @@ export async function GET(req: NextRequest) { ### Sign out -Let's create an route handler to handle the signout from the server side. +Let's create a route handler to handle the signout from the server side. `staging` -> `prod`). - As your database to grows, we strongly recommend moving to [Point-in-Time Recovery](/docs/guides/platform/backups#point-in-time-recovery). This is safer and has less impact on your database performance during maintenance windows. diff --git a/apps/docs/pages/guides/platform/migrating-and-upgrading-projects.mdx b/apps/docs/pages/guides/platform/migrating-and-upgrading-projects.mdx index 6472e628044..f425d5d260d 100644 --- a/apps/docs/pages/guides/platform/migrating-and-upgrading-projects.mdx +++ b/apps/docs/pages/guides/platform/migrating-and-upgrading-projects.mdx @@ -42,7 +42,7 @@ Migrating projects can be achieved using the Supabase CLI. This is particularly ```bash supabase db dump --db-url "$OLD_DB_URL" -f roles.sql --role-only supabase db dump --db-url "$OLD_DB_URL" -f schema.sql -supabase db dump --db-url "$OLD_DB_URL" -f data.sql --data-only +supabase db dump --db-url "$OLD_DB_URL" -f data.sql --use-copy --data-only ``` ### Restore to your new project diff --git a/apps/docs/pages/guides/self-hosting/analytics/config.mdx b/apps/docs/pages/guides/self-hosting/analytics/config.mdx index 8267f6a913e..97dc3bf3a97 100644 --- a/apps/docs/pages/guides/self-hosting/analytics/config.mdx +++ b/apps/docs/pages/guides/self-hosting/analytics/config.mdx @@ -1,18 +1,19 @@ import Layout from '~/layouts/DefaultGuideLayout' import { getAnalyticsConfigV0 } from '~/lib/mdx/getConfig' import Param from '~/components/Params' - -export const spec = getAnalyticsConfigV0() +import { serialize } from 'next-mdx-remote/serialize' +import components from '~/components' +import { MDXRemote } from 'next-mdx-remote' export const meta = { title: 'Analytics Self-hosting Config', description: 'How to configure and deploy Supabase Analytics.', } -
{spec.info.description}
+
-{spec.info.tags.map(tag => { +{props.spec.info.tags.map(tag => { return ( <>

{tag.title}

@@ -20,7 +21,7 @@ export const meta = {
Parameters