When a session token is refreshed server-side, `@supabase/ssr` writes
the updated JWT via Set-Cookie. If a CDN caches that response and serves
it to another user, that user will be signed in as the wrong person.
Adds documentation covering this in two places:
- creating-a-client.mdx: brief mention with a link to the full
explanation
- advanced-guide.mdx: expands the existing CDN FAQ with an explanation
of the risk and Cache-Control: private, no-store examples for Next.js
and Nuxt
Related: https://github.com/supabase/supabase-js/issues/1682
---------
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* docs: fix broken links in migration guide
Title
fix(docs): update broken next steps links in ssr guides
Description
Fixes#41467
Changes
Updates the "Next steps" section in the following server-side authentication guides:
apps/docs/content/guides/auth/server-side/migrating-to-ssr-from-auth-helpers.mdx
apps/docs/content/guides/auth/server-side/creating-a-client.mdx
Reason
The links in these files were pointing to deprecated "PKCE flow" pages (e.g., email-based-auth-with-pkce-flow-for-ssr) which have been removed from the documentation, resulting in 404 Not Found errors for users attempting to follow the migration or setup steps.
Solution
Remapped the broken links to the currently active, canonical documentation pages:
For migrating-to-ssr-from-auth-helpers.mdx:
Email/Password: .../email-based-auth-with-pkce-flow-for-ssr → /docs/guides/auth/passwords
OAuth: .../oauth-with-pkce-flow-for-ssr → /docs/guides/auth/social-login
SSR Overview: .../guides/auth/server-side → /docs/guides/auth/server-side-rendering
For creating-a-client.mdx:
Email/Password: .../email-based-auth-with-pkce-flow-for-ssr → /docs/guides/auth/passwords
OAuth: .../oauth-with-pkce-flow-for-ssr → /docs/guides/auth/social-login
SSR Overview: .../guides/auth/server-side-rendering → /docs/guides/auth/server-side/advanced-guide (Updated to point to the Advanced Guide to avoid circular linking, or as appropriate for the context).
Verification
Verified that the new target pages exist and cover the relevant SSR/PKCE context needed for these steps.
* fix(www): add redirects for deprecated auth ssr paths
Adds permanent redirects to handle 404 errors for deprecated PKCE flow URLs that were removed in recent updates.
Mappings added:
- /docs/guides/auth/server-side/email-based-auth-with-pkce-flow-for-ssr → /docs/guides/auth/passwords
- /docs/guides/auth/server-side/oauth-with-pkce-flow-for-ssr → /docs/guides/auth/social-login
.
* fix(docs): update broken next steps links in ssr guides
Updates the "Next steps" section in server-side auth guides to point to the correct active documentation.
Replaces broken 404 links to deprecated PKCE flow guides with links to:
- /docs/guides/auth/passwords
- /docs/guides/auth/social-login
- /docs/guides/auth/server-side-rendering
Affected files:
- apps/docs/content/guides/auth/server-side/migrating-to-ssr-from-auth-helpers.mdx
- apps/docs/content/guides/auth/server-side/creating-a-client.mdx
* fix(docs): update broken next steps links in ssr guides
Updates the "Next steps" section in server-side auth guides to point to the correct active documentation.
Replaces broken 404 links to deprecated PKCE flow guides with links to:
- /docs/guides/auth/passwords
- /docs/guides/auth/social-login
- /docs/guides/auth/server-side-rendering
Affected files:
- apps/docs/content/guides/auth/server-side/migrating-to-ssr-from-auth-helpers.mdx
- apps/docs/content/guides/auth/server-side/creating-a-client.mdx
---------
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
PR #41200 introduced template variables ({{ .tab }}, {{ .framework }})
to api_settings_steps.mdx for deep-linking to the Connect dialog.
However, 4 auth docs pages were calling the partial without passing
the required variables prop, causing MDX parsing errors:
- Could not parse expression with acorn: Unexpected token
This resulted in 404 errors on:
- /docs/guides/auth/server-side/creating-a-client
- /docs/guides/auth/quickstarts/nextjs
- /docs/guides/auth/quickstarts/react-native
- /docs/guides/auth/quickstarts/react
Fixes the issue by adding the variables prop to match the pattern
used in other quickstart pages.
* Quickstart next 16 update
* Fix paths and env vars
* docs: refactor nextjs server-side auth to use Proxy instead of middleware
* docs: refactor nextjs server-side auth to match proxy
* docs: refactor nextjs example to match Proxy
* docs: refactor nextjs auth AI prompt to match Proxy
* docs: refactor nextjs sentry telemetry integration to match Proxy
* examples: update nextjs realtime example to match middleware
* docs: refactoring guides to use nextjs proxy
* examples: update nextjs-full example to match Next16 template
* example: update nextjs-user-management to match nextjs 16
* docs: refactoring nextjs user-management tutorial to use typescript only
* docs: refactoring nextjs quickstart, removing step 4
since this step is already included on `with-supabase` template, we can
just remove this redundant step
* docs: auth-helpers nextjs pages, Nextjs16 proxy disclaimer
* stamp: lint
* stamp: revert 'NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY'
* stamp: nextjs examples, revert to use cookie options
* fix(docs): typo
* docs: updating nextjs-auth troubleshoot guide to match proxy
* Update apps/docs/content/guides/getting-started/quickstarts/nextjs.mdx
* Revert auth-helpers changes
* Revert auth-helpers content
* Apply suggestions from code review
* Update apps/docs/content/troubleshooting/how-do-you-troubleshoot-nextjs---supabase-auth-issues-riMCZV.mdx
* Update apps/docs/content/troubleshooting/how-do-you-troubleshoot-nextjs---supabase-auth-issues-riMCZV.mdx
* Update apps/docs/content/troubleshooting/how-do-you-troubleshoot-nextjs---supabase-auth-issues-riMCZV.mdx
* Update apps/docs/content/troubleshooting/how-do-you-troubleshoot-nextjs---supabase-auth-issues-riMCZV.mdx
* Apply suggestions from code review
* Prettier
---------
Co-authored-by: kallebysantos <kalleby_santos@hotmail.com>
* fix: rewrite relative URLs when syncing to GitHub discussion
Relative URLs back to supabse.com won't work in GitHub discussions, so
rewrite them back to absolute URLs starting with https://supabase.com
* fix: replace all supabase urls with relative urls
* chore: add linting for relative urls
* chore: bump linter version
* Prettier
---------
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
* Added <$CodeTabs> to Pages Router tab
There was an inconsistency between the App Router and Pages Router page, which was only a small detail.
* Update apps/docs/content/guides/auth/server-side/nextjs.mdx
---------
Co-authored-by: Charis <26616127+charislam@users.noreply.github.com>
* Update nextjs.mdx
just a little comment.. that save LOTS OF DEBUGGING time.
* fix: tweak wording
---------
Co-authored-by: Charis <26616127+charislam@users.noreply.github.com>