diff --git a/apps/docs/content/guides/self-hosting/docker.mdx b/apps/docs/content/guides/self-hosting/docker.mdx index a196650d77b..6e9b5bacf22 100644 --- a/apps/docs/content/guides/self-hosting/docker.mdx +++ b/apps/docs/content/guides/self-hosting/docker.mdx @@ -446,7 +446,7 @@ See the [Configure Phone Login & MFA](/docs/guides/self-hosting/self-hosted-phon Configuring the Supabase AI Assistant is optional. By adding **your own** `OPENAI_API_KEY` to `.env` you can enable AI services, which help with writing SQL queries, statements, and policies. -#### Setting database's `log_min_messages` +#### Setting log_min_messages in Postgres By default, the database's `log_min_messages` configuration is set to `fatal` in [docker-compose.yml](https://github.com/supabase/supabase/blob/df8729a82b1847e2989c14ede27965612761d503/docker/docker-compose.yml#L466) to prevent redundant logs generated by Realtime. You can configure `log_min_messages` using any of the Postgres [Severity Levels](https://www.postgresql.org/docs/current/runtime-config-logging.html#RUNTIME-CONFIG-SEVERITY-LEVELS). diff --git a/apps/docs/content/guides/self-hosting/self-hosted-auth-keys.mdx b/apps/docs/content/guides/self-hosting/self-hosted-auth-keys.mdx index 1cbdd4d4199..21e7c60e03f 100644 --- a/apps/docs/content/guides/self-hosting/self-hosted-auth-keys.mdx +++ b/apps/docs/content/guides/self-hosting/self-hosted-auth-keys.mdx @@ -131,7 +131,7 @@ When `JWT_KEYS` is set, Auth will start signing new user session JWTs with the n -## Rotating `sb_` API keys +## Rotating the new API keys If your new API keys are compromised or you want to rotate them periodically, you can regenerate `sb_publishable` and `sb_secret` without touching the asymmetric key pair: @@ -175,9 +175,9 @@ Regenerating asymmetric keys invalidates all ES256 user sessions. Plan a mainten Below are a few notes on the details of the new authentication architecture. -### What `supabase-js` sends +### What client SDK sends -Every request includes two headers: +Every request via `supabase-js` includes two headers: - `apikey` - the API key (`sb_` or legacy JWT) - `Authorization` - when unauthenticated, the client SDK copies the API key here (`Bearer sb_publishable_xxx` or `Bearer eyJ...`). When authenticated, this contains the user session JWT minted by Auth. diff --git a/apps/docs/content/guides/self-hosting/self-hosted-functions.mdx b/apps/docs/content/guides/self-hosting/self-hosted-functions.mdx index 02eaefaa097..06db096061c 100644 --- a/apps/docs/content/guides/self-hosting/self-hosted-functions.mdx +++ b/apps/docs/content/guides/self-hosting/self-hosted-functions.mdx @@ -24,7 +24,7 @@ This returns `"Hello from Edge Functions!"`. ## Create a new function -### Step 1: Create a new directory with an `index.ts` file in `volumes/functions/`: +### Step 1: Add a new function directory and the function code ``` mkdir -p volumes/functions/my-function && @@ -44,13 +44,13 @@ Deno.serve(async (req: Request) => { }) ``` -### Step 2: Restart the functions service to pick up the new function: +### Step 2: Restart the functions service to pick up the new function ```bash docker compose restart functions --no-deps ``` -### Step 3: Invoke your function: +### Step 3: Invoke your function ```bash curl -X POST http://:8000/functions/v1/my-function \ diff --git a/apps/docs/content/guides/self-hosting/self-hosted-oauth.mdx b/apps/docs/content/guides/self-hosting/self-hosted-oauth.mdx index 4297d06127c..eb457106ea4 100644 --- a/apps/docs/content/guides/self-hosting/self-hosted-oauth.mdx +++ b/apps/docs/content/guides/self-hosting/self-hosted-oauth.mdx @@ -56,7 +56,7 @@ The default `.env.example` and `docker-compose.yml` include commented-out placeh 2. Set the **authorized redirect URL**, e.g., `https:///auth/v1/callback` 3. Copy the **client ID** and **client secret** into your `.env` file. -### Step 2: Configure variables in the `.env` file +### Step 2: Configure environment variables Uncomment the lines for your provider in `.env` and add your client ID and secret, e.g., for Google: @@ -66,7 +66,9 @@ GOOGLE_CLIENT_ID=your-client-id GOOGLE_SECRET=your-client-secret ``` -### Step 3: Enable the matching lines in `docker-compose.yml` +{/* supa-mdx-lint-disable-next-line Rule001HeadingCase */} + +### Step 3: Enable the matching lines in Docker Compose configuration Uncomment the corresponding `GOTRUE_EXTERNAL_` lines in the `auth` service's `environment`: @@ -400,12 +402,12 @@ For detailed client-side integration, see [Social Login](/docs/guides/auth/socia ## Troubleshooting -### "Provider not enabled" or provider shows `false` in `/auth/v1/settings` +### "Provider not enabled" or provider seen as false in settings - Check that `GOTRUE_EXTERNAL_*_ENABLED` is set to `true` in `docker-compose.yml` - Verify the `.env` variable is not empty, e.g., check with `docker compose exec auth env | grep GOOGLE` -### Variables added to `.env` but provider still not working +### Variables added to the environment but provider still not working Configuration variables from `.env` are **not** automatically available inside the container unless there's a matching passthrough definition in `docker-compose.yml`. Check, e.g., for: @@ -415,7 +417,7 @@ GOTRUE_EXTERNAL_GOOGLE_ENABLED: ${GOOGLE_ENABLED} Run `docker compose exec auth env | grep GOTRUE_EXTERNAL` to verify the variables are reaching the container. -### `SITE_URL` or redirect URL errors after login +### Site URL or redirect URL errors after login After a successful OAuth login, the Auth service redirects to `SITE_URL` or a URL from `ADDITIONAL_REDIRECT_URLS`. Ensure: diff --git a/apps/docs/content/guides/self-hosting/self-hosted-phone-mfa.mdx b/apps/docs/content/guides/self-hosting/self-hosted-phone-mfa.mdx index 30d427e471f..69c214fdec6 100644 --- a/apps/docs/content/guides/self-hosting/self-hosted-phone-mfa.mdx +++ b/apps/docs/content/guides/self-hosting/self-hosted-phone-mfa.mdx @@ -23,7 +23,7 @@ The default `.env.example` and `docker-compose.yml` include commented-out SMS pr To enable SMS delivery: -### Step 1: Uncomment and configure the settings in `.env` +### Step 1: Uncomment and configure the environment variables ``` SMS_PROVIDER=twilio @@ -38,7 +38,9 @@ SMS_TWILIO_AUTH_TOKEN=your-auth-token SMS_TWILIO_MESSAGE_SERVICE_SID=your-message-service-sid ``` -### Step 2: Uncomment the matching lines in `docker-compose.yml` +{/* supa-mdx-lint-disable-next-line Rule001HeadingCase */} + +### Step 2: Uncomment the matching lines in Docker Compose configuration Uncomment the `GOTRUE_SMS_*` lines in the `auth` service's `environment` block: @@ -200,7 +202,7 @@ Common causes: - Provider credentials are wrong - Phone number format is wrong (use E.164 format: `+1234567890`) -### Variables are configured in `.env` but not working +### Variables added to the environment but not working Configuration variables from `.env` are **not** automatically available inside the container unless there's a matching passthrough definition in `docker-compose.yml`. Check, e.g., for: diff --git a/apps/docs/content/guides/self-hosting/self-hosted-proxy-https.mdx b/apps/docs/content/guides/self-hosting/self-hosted-proxy-https.mdx index cb040b48ab4..048e7b4e40d 100644 --- a/apps/docs/content/guides/self-hosting/self-hosted-proxy-https.mdx +++ b/apps/docs/content/guides/self-hosting/self-hosted-proxy-https.mdx @@ -147,7 +147,7 @@ kong: KONG_SSL_CERT_KEY: /home/kong/server.key ``` -### Step 3: Update configuration variables in `.env` +### Step 3: Update configuration variables Edit your `.env` file to use HTTPS with the Kong HTTPS port: