mirror of
https://github.com/supabase/supabase.git
synced 2026-10-09 03:15:06 +03:00
**Stack 1/6** of the TanStack Start migration (#46424), split into reviewable, independently-mergeable PRs. > [!IMPORTANT] > **Next stays the default and only active framework after this PR.** This wires up the Vite/TanStack-Start build pipeline behind the `STUDIO_FRAMEWORK` flag, but there are no TanStack routes yet — so the TanStack build isn't functional or tested until later PRs in the stack. Nothing about the Next build, dev, or deploy changes behaviourally here. ## What's in this PR - **Dispatch:** `dev`/`build`/`start` now go through `scripts/dispatch.js`, which runs the Next variant unless `STUDIO_FRAMEWORK=tanstack`. The original commands are preserved as `dev:next`/`build:next`/`start:next`. - **Build pipeline:** `vite.config.ts`, `serve.js`, `smoke-server.mjs`, vite/tanstack deps, `turbo.jsonc`. - **`tsconfig.json`:** `jsx: react-jsx`, `moduleResolution: Bundler`, `target: ES2022`. Because `include` is `**/*.ts(x)`, this re-typechecks the whole app, so the companion adaptations below land with it. - **Shared adaptations (companions to the tsconfig change):** `BufferSource` casts, `packages/ui` unused-`React` import removals, etc. - **Routing/middleware plumbing:** `next.config.ts` + `redirects.shared.ts` (redirect rules now shared with `vercel.ts`), `proxy.ts`/`start.ts` middleware + `hosted-api-allowlist.ts`. ## Verification Run locally off `master`: frozen install ✓, `studio` typecheck ✓, **Next build ✓** (compiles + generates all routes), lint ratchet ✓ ("some rules improved"), prettier ✓. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a hosted API endpoint allowlist to return 404 for non-supported `/api/*` routes. * Introduced a TanStack route-migration checklist and expanded TanStack Start routing support. * **Improvements** * Enhanced deployment refresh/detection by tightening cookie handling for “latest deployment” updates. * Centralized redirect/maintenance-mode rules for consistent platform vs self-hosted behavior. * Improved production serving with a dedicated static + proxy server and a post-build smoke test. * **Dependencies** * Updated TanStack-related packages and React Table/query tooling versions. * **Documentation / Chores** * Updated formatting and tooling config; added shared build environment parsing utilities. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
138 lines
4.6 KiB
JSON
138 lines
4.6 KiB
JSON
{
|
|
"$schema": "./../../node_modules/turbo/schema.json",
|
|
"extends": ["//"],
|
|
"tasks": {
|
|
"build": {
|
|
"dependsOn": ["^build"],
|
|
"env": [
|
|
"ANALYZE",
|
|
"CI",
|
|
"NEXT_PUBLIC_SUPPORT_API_URL",
|
|
"NEXT_PUBLIC_CONTENT_API_URL",
|
|
"NEXT_PUBLIC_BASE_PATH",
|
|
"NEXT_PUBLIC_STRIPE_PUBLIC_KEY",
|
|
"NEXT_PUBLIC_SUPPORT_ANON_KEY",
|
|
"NEXT_PUBLIC_ENVIRONMENT",
|
|
"NEXT_PUBLIC_IS_PLATFORM",
|
|
"NEXT_PUBLIC_SITE_URL",
|
|
"NEXT_PUBLIC_API_URL",
|
|
"NEXT_PUBLIC_DOCS_URL",
|
|
"NEXT_PUBLIC_CONFIGCAT_SDK_KEY",
|
|
"NEXT_PUBLIC_CONFIGCAT_PROXY_URL",
|
|
"NEXT_PUBLIC_HCAPTCHA_SITE_KEY",
|
|
"NEXT_PUBLIC_SUPABASE_URL",
|
|
"NEXT_PUBLIC_SUPABASE_ANON_KEY",
|
|
"NEXT_PUBLIC_NODE_ENV",
|
|
"NEXT_PUBLIC_GOTRUE_URL",
|
|
"NEXT_PUBLIC_VERCEL_BRANCH_URL",
|
|
"NEXT_PUBLIC_GOOGLE_MAPS_KEY",
|
|
"NEXT_RUNTIME",
|
|
"NIMBUS_PROD_PROJECTS_URL",
|
|
"NIMBUS_PROD_PROJECTS_URL_WS",
|
|
"NODE_ENV",
|
|
"SUPABASE_URL",
|
|
"VERCEL",
|
|
"VERCEL_ENV",
|
|
"MAINTENANCE_MODE",
|
|
// These envs are used in the packages
|
|
"NEXT_PUBLIC_STORAGE_KEY",
|
|
"NEXT_PUBLIC_AUTH_DEBUG_KEY",
|
|
"NEXT_PUBLIC_AUTH_PERSISTED_KEY",
|
|
"NEXT_PUBLIC_AUTH_NAVIGATOR_LOCK_KEY",
|
|
"NEXT_PUBLIC_AUTH_DETECT_SESSION_IN_URL",
|
|
"NEXT_PUBLIC_GOOGLE_TAG_MANAGER_ID",
|
|
"NEXT_PUBLIC_VERCEL_ENV",
|
|
"NEXT_PUBLIC_USERCENTRICS_RULESET_ID",
|
|
"NEXT_PUBLIC_MCP_URL",
|
|
"NEXT_PUBLIC_IS_NIMBUS",
|
|
"NEXT_PUBLIC_ONGOING_INCIDENT",
|
|
// These envs are technically passthrough env vars because they're only used on the server side of Nextjs
|
|
"PLATFORM_PG_META_URL",
|
|
"STUDIO_PG_META_URL",
|
|
"PG_META_CRYPTO_KEY",
|
|
"PGRST_DB_SCHEMAS",
|
|
"PGRST_DB_MAX_ROWS",
|
|
"PGRST_DB_EXTRA_SEARCH_PATH",
|
|
"POSTGRES_PASSWORD",
|
|
"POSTGRES_HOST",
|
|
"POSTGRES_USER_READ_WRITE",
|
|
"POSTGRES_USER_READ_ONLY",
|
|
"POSTGRES_DB",
|
|
"POSTGRES_PORT",
|
|
"READ_ONLY_URL",
|
|
"READ_ONLY_API_KEY",
|
|
"SUPABASE_SERVICE_KEY",
|
|
"SUPABASE_ANON_KEY",
|
|
"SUPABASE_PUBLISHABLE_KEY",
|
|
"SUPABASE_SECRET_KEY",
|
|
"SUPABASE_PUBLIC_URL",
|
|
"DEFAULT_PROJECT_NAME",
|
|
"DEFAULT_ORGANIZATION_NAME",
|
|
"OPENAI_API_KEY",
|
|
"BRAINTRUST_API_KEY",
|
|
"BRAINTRUST_PROJECT_ID",
|
|
"AUTH_JWT_SECRET",
|
|
"LOGFLARE_API_KEY",
|
|
"LOGFLARE_PUBLIC_ACCESS_TOKEN",
|
|
"LOGFLARE_PRIVATE_ACCESS_TOKEN",
|
|
"LOGFLARE_URL",
|
|
"SENTRY_ORG",
|
|
"SENTRY_PROJECT",
|
|
"SENTRY_AUTH_TOKEN",
|
|
"NEXT_PUBLIC_SENTRY_DSN",
|
|
"AWS_BEDROCK_PROFILE",
|
|
"AWS_BEDROCK_ROLE_ARN",
|
|
"AWS_ACCESS_KEY_ID",
|
|
"AWS_SECRET_ACCESS_KEY",
|
|
"FORCE_ASSET_CDN",
|
|
"ASSET_CDN_S3_ENDPOINT",
|
|
"SITE_NAME",
|
|
"VERCEL_URL",
|
|
"IS_BRAINTRUST_PUSH",
|
|
"GITHUB_HEAD_REF",
|
|
"GITHUB_REF_NAME",
|
|
"GITHUB_PR_NUMBER",
|
|
"IS_THROTTLED",
|
|
"AI_PRO_MODEL",
|
|
"AI_NORMAL_MODEL",
|
|
"SUPPORT_SUPABASE_SECRET_KEY",
|
|
"STATUSPAGE_API_KEY",
|
|
"STATUSPAGE_PAGE_ID",
|
|
"INCIDENT_IO_API_KEY",
|
|
"LIVE_SUPABASE_SECRET_KEY",
|
|
// Selects the build mode for the studio's `build`/`start` scripts
|
|
// (e.g. e2e sets `MODE=test`). Listed so turbo invalidates the
|
|
// cache when it changes — without this, switching between test and
|
|
// production builds reuses a stale cached output.
|
|
"MODE",
|
|
// Read by scripts/serve.js (the Node host for `pnpm start`).
|
|
// Declared here so the studio-package turbo env lint rule passes
|
|
// even though turbo doesn't directly drive `start`.
|
|
"PORT",
|
|
// Gates the TanStack vs Next path in api/server.js, vercel.ts,
|
|
// and scripts/dispatch.js (the dev/build/start dispatcher).
|
|
"STUDIO_FRAMEWORK",
|
|
// Vite's built-in `import.meta.env.SSR` flag (used in ConnectStepsSection
|
|
// to gate Vite-only `import.meta.glob`). Not a real process env var
|
|
// but turbo's `no-undeclared-env-vars` lint flags any `env.SSR` access.
|
|
"SSR",
|
|
],
|
|
"passThroughEnv": [
|
|
"CURRENT_CLI_VERSION",
|
|
"VERCEL_GIT_COMMIT_REF",
|
|
"VERCEL_GIT_COMMIT_SHA",
|
|
"SNIPPETS_MANAGEMENT_FOLDER",
|
|
"EDGE_FUNCTIONS_MANAGEMENT_FOLDER",
|
|
"S3_PROTOCOL_ACCESS_KEY_ID",
|
|
"S3_PROTOCOL_ACCESS_KEY_SECRET",
|
|
],
|
|
"outputs": [
|
|
".next/**",
|
|
"!.next/cache/**",
|
|
"!.next/dev/**/*",
|
|
"dist/**",
|
|
],
|
|
},
|
|
},
|
|
}
|