Commit Graph
13 Commits
Author SHA1 Message Date
Ali Waseem d8563cfc6a fix(studio): require full authentication for the support form (#49318)
The support form was exempted from the highest AAL check (since the
original MFA rollout in #16813) so that users stuck on the MFA challenge
could still file a ticket. The platform API now rejects AAL1 sessions
with `403 Insufficient AAL: MFA required`, so for those users the form
is simply broken — it renders an error toast and the submit would fail
too.

This requires AAL2 on `/support/new`, so an AAL1 session gets redirected
to the MFA challenge and returns to the form afterwards, and removes the
links to the support form from the MFA screen. A dedicated flow for
users who can't get past MFA to reach us is being worked on separately
and should be out soon!

Fixes FE-4218

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added an “Email support” action for multi-factor authentication
issues, with a prefilled subject line.
- Provided clearer guidance when authentication factors cannot be
retrieved.

- **Bug Fixes**
- Improved authentication error handling based on the session’s
assurance level.
- Reduced confusing permission and error messages for lower-assurance
sessions.
- Updated support page access to use standard authentication behavior
for a more consistent sign-in experience.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 08:27:37 -06:00
Charis 0abfbdd3d7 fix(studio): preserve session and redirect to MFA when AAL elevation is needed (#47145)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix.

## What is the current behavior?

`withAuth` calls `signOut()` and redirects to `/sign-in` whenever the
current AAL is below the required level. For IdP-initiated SSO logins —
where the user lands directly on `/dashboard` rather than passing
through `/sign-in-mfa` — this destroys the valid AAL1 session that was
just established. Subsequent mgmt-api requests then return 401
Unauthorized, and the user is dumped on `/sign-in` with no way to
recover except restarting the SSO flow (which loops them back to the
same state).

The platform already returns an actionable `403 Insufficient AAL: MFA
required` on the first mgmt-api request, but the dashboard does not
capture it.

## What is the new behavior?

`withAuth` now distinguishes between "not logged in" and "needs AAL
elevation":

- **Logged in but AAL1** → `router.push('/sign-in-mfa?returnTo=…')`,
session preserved. The existing `/sign-in-mfa` page picks up the
session, renders the MFA form, and bounces the user to `returnTo` after
a successful challenge.
- **Not logged in** → unchanged: `signOut()` then redirect to
`/sign-in?returnTo=…`.
- `/sign-in-mfa` is also added to the "already there, do nothing" guard
so the user isn't re-redirected mid-challenge.

This relies on the gotrue client's local AAL state via
`useAuthenticatorAssuranceLevelQuery`, which fires before any mgmt-api
request, so no fetcher-level error parsing is needed.

## Additional context

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved multi-factor authentication (MFA) elevation flow to preserve
user sessions instead of forcing sign-out and requiring users to restart
sign-in.
  * Fixed unnecessary redirects when users are already on sign-in pages.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-29 13:28:46 -04:00
Charis 180ce515f6 style: require @ imports and sort imports for studio/hooks (#44444)
* **Chores**
* Updated internal module import paths across hook files to use
standardized path aliases for improved code consistency and
maintainability.
2026-04-01 11:48:02 -04:00
Danny WhiteandJoshen Lim 22ff9b2d81 chore(studio): session expired dialog (#43122)
## What kind of change does this PR introduce?

UI improvement

## What is the current behavior?

The session expired dialog is quite hard to parse when, for most people,
the ask is simple.

## What is the new behavior?

Improved session expired dialog:

- Refactored to use AlertDialog
- Clarified copywriting
- Uses the new AlertCollapsible to hide all the complicated debugging
steps under a toggle
	- This component is documented in the design-system

| Before | After |
| --- | --- |
| <img width="1024" height="563"
alt="Supabase-B1728A05-DDD2-4A50-AED4-D62EAA2E7D7C"
src="https://github.com/user-attachments/assets/771f85d8-21ea-42b5-99f5-b9b05f5617dd"
/> | <img width="1024" height="563" alt="Storage Supabase"
src="https://github.com/user-attachments/assets/b2fcab68-fb29-4cb9-bd42-aecc57b9fa32"
/> |
| <img width="1024" height="563"
alt="Supabase-B1728A05-DDD2-4A50-AED4-D62EAA2E7D7C"
src="https://github.com/user-attachments/assets/771f85d8-21ea-42b5-99f5-b9b05f5617dd"
/> | <img width="1024" height="563" alt="Storage Supabase"
src="https://github.com/user-attachments/assets/babd3711-5fdf-43b9-be06-d96268a191fd"
/> |

## To test

In apps/studio/hooks/misc/withAuth.tsx:

```diff
- const [isSessionTimeoutModalOpen, setIsSessionTimeoutModalOpen] = useState(false)
+ const [isSessionTimeoutModalOpen, setIsSessionTimeoutModalOpen] = useState(true) // Mocked as true for UI testing
```

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-02-25 16:27:48 +08:00
Ivan Vasilov 0d5be306ef chore: Bump React Query to v5 (#40174)
* Bump the deps, refactor deprecated code.

* Migrate keepPreviousData usage.

* Migrate all uses of InfiniteQuery.

* Fix refetchInterval in queries.

* Migrate all use of isLoading to isPending in mutations.

* Fix accessing location in claim-project.

* Fix a bug in duplicate query keys.

* Migrate all queries to use isPending.

* Revert "Fix accessing location in claim-project."

This reverts commit 2a07df64b5.

* Revert the rss.xml file to master.
2025-12-10 10:10:29 +01:00
Ivan Vasilov a40ccc4b45 chore: Clean onSuccess and onError props on useQuery (#40641)
* Remove all onSuccess and onErrors from useQuery.

* Minor fixes to all refetchInterval.

* Fix smaller type issues.
2025-11-20 14:08:56 +01:00
Charis 297822b0b7 fix(logout): don't use returnTo on sign-in page if user intentionally logs out (#40155)
When user logs out from the user dropdown, they're redirected to the
sign-in page via the withAuth redirect, which means that the returnTo
param is used -- but if the user _intentionally_ logged out, this might
not be the right behavior, i.e., if they want to log in to another
account. Instead, if they chose to log out, we shouldn't use the
returnTo param.

Since the /logout page already implements this behavior, I changed "Log
out" button to just route to the /logout page.
2025-11-04 14:25:08 -05:00
Joshen Lim b4d38fabd0 Chore/barrel files bye part 05 (#40016)
* Clean up barrel files part 4

* nit

* Part 5 of cleaning up barrel files

* Revert changes for types

* Nit
2025-10-31 13:15:31 +08:00
08a7b75f1e chore: add signed out redirect timeout (#35546)
* chore: add signed out redirect timeout

* Add modal

* Nudge language

* Add temp github link

* Use captureException

* Minor refactor

* Revert staging specific testing logic

* Fix the sentry message send

* Change to event

* Add debugging

* Use an actual error

* Adjust logging

* always send errors

* even more debugging

* Remove all beforeSend checks

* Restore beforeSend

* Debug

* Retry original

* Again

* Test always send

* Cleanup

* Test frames again

* Retry third party error function

* Cleanup

* Remove hardcoded debugging

---------

Co-authored-by: Terry Sutton <saltcod@gmail.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2025-07-01 14:26:57 -02:30
df52ea7ee0 feat: Replace all toasts with sonner (#28250)
* Update the design of the sonner toasts. Add the close button by default.

* Migrate studio and www apps to use the SonnerToaster.

* Migrate all toasts from studio.

* Migrate all leftover toasts in studio.

* Add a new toast component with progress. Use it in studio.

* Migrate the design-system app.

* Refactor the consent toast to use sonner.

* Switch docs to use the new sonner toasts.

* Remove toast examples from the design-system app.

* Remove all toast-related components and old code.

* Fix the progress bar in the toast progress component. Also make the bottom components vertically centered.

* Fix the width of the toast progress.

* Use text-foreground-lighter instead of muted for ToastProgress text

* Rename ToastProgress to SonnerProgress.

* Shorten the text in sonner progress.

* Use the correct classes for the close button. Add a const var for the default toast duration. Remove the custom width class from sonner.

* Set the position for all progress toasts to bottom right. Set the duration for all toasts to the default (when reusing a toast id from loading/progress toast, the duration is set to infinity).

* Fix the playwright tests.

* Refactor imports to use ui instead of @ui.

* Change all imports of react-hot-toast with sonner. These components were merged since the last commit to this branch.

* Remove react-hot-toast lib.

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
Co-authored-by: Jonathan Summers-Muir <MildTomato@users.noreply.github.com>
2024-08-31 07:50:51 +08:00
Joshen Lim 6b741bc964 Replace ui setnotification with toast midway (#21867)
Replace ui setnotification with toast
2024-03-08 15:46:52 +08:00
Terry SuttonandAlaister Young d877de2a4c Move setProject out of withAuth so self-hosted still gets project ref #19046 (#19049)
* Move setProject out of withAuth

* Update apps/studio/hooks/misc/useStore.tsx

Co-authored-by: Alaister Young <alaister@users.noreply.github.com>

---------

Co-authored-by: Alaister Young <alaister@users.noreply.github.com>
2023-11-20 14:25:33 +11:00
Ivan Vasilov 436bdb10ae chore: Move the studio app to apps/studio (#18915)
* Move all studio files from /studio to /apps/studio.

* Move studio specific prettier ignores.

* Fix the ui references from studio.

* Fix the css imports.

* Fix all package.json issues.

* Fix the prettier setup for the studio app.

* Add .turbo folder to prettierignore.

* Fix the github workflows.
2023-11-15 12:38:55 +01:00