Commit Graph
3 Commits
Author SHA1 Message Date
Gildas GarciaandAli Waseem d276f75c89 Recovery codes: allow users to use recovery codes to access their account (#50569)
## What kind of change does this PR introduce?

Allow users to sign in using a recovery code after being redirected to
the MFA verification page.

## Additional context

<img width="435" height="373" alt="image"
src="https://github.com/user-attachments/assets/968fd15e-3081-4aa2-b645-4e0d2ec2637c"
/>

<img width="494" height="404" alt="image"
src="https://github.com/user-attachments/assets/fd7cee49-dca7-4f1a-873a-293e21c68faa"
/>

## How to test

- Enable MFA on your account if needed
- Generate recovery codes if needed (make sure you actually saved the
recovery codes somewhere)
- Sign out
- Sign in and when redirected to the MFA verification page, click the
_Authenticate using a recovery code_ link
- Enter one recovery code

Check that:
- you're signed in
- when on [your account security
page](https://studio-staging-git-gildasgarcia-auth-1624-dashb-177251-supabase.vercel.app/dashboard/account/security),
you have one less code available

Then:
- Disable the `enableAuthRecoveryCodes` config cat flag
- Sign out
- Sign in and wait on the MFA verification page

Check that:
- the _Authenticate using a recovery code_ link is not displayed
- Accessing [the recovery code sign in
page](https://studio-staging-git-gildasgarcia-auth-1624-dashb-177251-supabase.vercel.app/dashboard/sign-in-recovery-code)
redirects you to the MFA page

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added recovery-code authentication as an alternative MFA sign-in
method.
* Added a dedicated recovery-code sign-in page with validation,
visibility controls, cancellation, and sign-out options.
* Added a link from the MFA sign-in screen when recovery codes are
available.
* Added loading and error states while checking recovery-code
availability.

* **Bug Fixes**
* Prevented valid recovery-code sign-ins from being redirected back to
the MFA prompt.
* Limited recovery-code settings to accounts with exactly one enrolled
authenticator.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-09-21 09:23:02 +02:00
Alaister YoungandAlaister Young b9c8857394 fix(studio): TanStack route parity fixes from Next comparison audit (#48028)
Audited every TanStack route (~300 files) against its Next.js
pages-router counterpart — layout wrapping, root providers, API routes,
and deploy config — and fixed the divergences found. Same bug class as
#48024, plus a few setup-level gaps.

**Fixed (user-visible):**
- `routes/__root.tsx` was missing `TimezoneProvider` + the
`TimestampInfoProvider` bridge, so the stored timezone preference was
silently ignored app-wide (timestamps always rendered in browser-local
time)
- `routes/_auth.tsx` wrapped all 10 auth pages in `AuthenticationLayout`
(status banners + extra full-screen scroll container); in Next only
`/sign-in` has it via getLayout. The parent is now a passthrough and
sign-in wraps at the leaf
- `routes/project/$ref/integrations.tsx` hardcoded
`ProjectIntegrationsLayout`; the Next pages use
`ProjectIntegrationsLayoutDispatch`, which switches to the Marketplace
layout when that flag is enabled
- `GlobalShortcuts` wasn't mounted, so the shortcuts-reference sheet
(`?`) and its command-menu entry were unreachable
- `routes/join.tsx` added a full-screen wrapper the Next page doesn't
have (double `min-h-screen` around `InterstitialLayout`)

**Fixed (behavior/config):**
- ConfigCat flags lost the `plan` custom attribute, so plan-targeted
flags could evaluate differently
- `vercel.ts`: `api/server.js` had no `maxDuration` (Next sets up to
300s per route — stripe-sync, AI streaming); added the
`/.well-known/vercel/flags` rewrite + JSON content-type (Flags Explorer
endpoint previously fell through to the HTML shell); added
`img`/`favicon` cache-control headers
- `routes/api/v1/.../functions/$slug/body.ts` (bespoke reimplementation)
dropped `apiWrapper`'s global catch — errors now get Sentry capture +
the same 500 `{ error }` body
- Reverted migration drift in `__root.tsx`: tooltip `delayDuration` 0 →
Radix default (matching Next), `og:image` back to `supabase-og.png`
- lodash → lodash-es for the whole SSR module graph (#48029, merged into
this branch): the lodash CJS build's named-export interop yields
non-functions under the Vite SSR module runner, which 500'd every page
once `GlobalShortcuts` (or anything calling lodash during SSR render)
mounted. An `options.ssr`-gated `resolveId` plugin in `vite.config.ts`
serves `lodash-es` (same version, real ESM) to app source, workspace
packages, and deps alike; client bundles untouched. Note: dev servers
need a restart after pulling this (config change)

Also corrected two stale route comments claiming the CLI/Stripe login
pages inline `APIAuthorizationLayout` (they inline
`InterstitialLayout`).

**Not changed (audited, intentionally left):**
- Redirect-only pages briefly flash `DefaultLayout` chrome under
TanStack (normally unreachable — router-level redirects fire first)
- Org pages inherit an inert `AppLayout` div via `routes/_app.tsx`
(visually a no-op; Next org pages don't have it)
- Adapter-level differences: framework 405s instead of Next's
`Allow`-header JSON, `bodyParser.sizeLimit` not enforced on two routes,
narrower favicon non-prod detection (commented as known)
- Known pre-existing dev console error (also on Next master): closing
the shortcuts sheet logs a setState-in-render warning —
`@tanstack/react-hotkeys@0.10.0` calls `setOptions` in the
`useHotkeySequence` render body, notifying `useHotkeyRegistrations`
subscribers mid-render. Worth an upstream report/dep bump as a follow-up

## To test

Verified on the local TanStack dev server via Playwright (all pass):
- Set a timezone in the account dropdown → log timestamps show that
timezone's row in the hover tooltip
- `?` opens the shortcuts sheet; `⌘K` → "Show all keyboard shortcuts"
does too
- `/sign-in` still shows banners/window chrome; `/sign-up`,
`/sign-in-sso`, `/forgot-password`, `/cli/login` render without the
extra wrapper
- `/project/<ref>/integrations` renders (legacy sidebar when marketplace
flag off)
- `/join` renders a single centered interstitial
- `og:image` meta is `supabase-og.png`
- Vercel deploy-button new-project page renders the consolidated #47995
form inside the window chrome
- `vercel.ts` changes are deploy-config only — verify Flags Explorer +
function timeout on a preview deploy

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
  - Added timezone-aware timestamp handling across Studio.
  - Added support for global keyboard shortcuts.
- Updated authentication page layouts for a more consistent sign-in
experience.
  - Refreshed social sharing imagery.

- **Bug Fixes**
- Improved error reporting and responses when loading function source
files fails.
  - Improved handling of integration page layouts.
  - Fixed Vercel routing for feature configuration requests.

- **Performance**
  - Added caching for static images and favicons.
  - Increased server execution time for longer-running requests.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-07-17 16:42:10 +08:00
3d931aceb7 feat(studio): TanStack app shell — root + auth/org routes (stack 3/6, from #46424) (#47112)
**Stack 3/6** of the TanStack Start migration (#46424). Stacked on
**#47110** (S2) → review that first; this PR's diff is the app shell.

> [!NOTE]
> Thin route wrappers that render the existing pages-router page
components through the compat shims (S2). Next is untouched — it builds
`pages/` and ignores `routes/`. The app doesn't function end-to-end on
TanStack until the API + project routes land (S4/S5) and the flag is
flipped.

## What's in this PR
- `routes/__root.tsx` — root layout + a `beforeLoad` that runs the
shared redirect rules; `router.tsx`.
- `routes/_auth/*` — sign-in/up, forgot/reset password, SSO/MFA/partner
sign-in, CLI login, Stripe-projects login.
- `routes/_app/*` — account (me/security/audit/tokens), `org/$slug/*`
(general/billing/team/usage/…), support.
- `routeTree.gen.ts` — **regenerated** by the tanstackStart vite plugin
for exactly the routes in this PR (the migration branch's tree
references all ~300 routes, so it can't be copied verbatim here). It's a
generated artifact; the meaningful review surface is the route files.

## Verification
On top of S1+S2: `studio` typecheck ✓, lint (0 errors) ✓.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Refactor**
* Enhanced internal routing infrastructure to improve application
performance and code organization. These behind-the-scenes updates
ensure a more stable and maintainable foundation for the platform
without affecting existing functionality or user experience.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-06-29 14:08:26 +02:00