mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 01:45:10 +03:00
<img width="1510" height="860" alt="image" src="https://github.com/user-attachments/assets/36a748b7-bdeb-4685-8bb1-da911711874b" /> Introduces a new OAuth consent block in preparation for offering more MCP focused blocks that require authentication and consent. The general approach for this is to decouple consent block from authentication block but provide guidance on how to use both. The alternative is to add auth as a dependency to consent but apps may already have their own authentication UI / flows. The block is also positioned as a general OAuth Consent vs MCP Consent as it can be put to use for other use cases outside of MCP on projects who want to make use of the OAuth 2.1 Server offering. A couple of changes outside of the block itself were required: - Updated the Auth blocks to allow for a `next` param to redirect users to after signing in - Updated middleware so next param is correctly passed through to sign in ## How to test Requires Docker and a Supabase CLI recent enough to support `[auth.oauth_server]` (verified on 2.109.0 / GoTrue v2.192.0). ### 1. Local Supabase with the OAuth server enabled In your `supabase/config.toml`, edit the existing `[auth.oauth_server]` section — `supabase init` already writes one, and adding a second fails with `table oauth_server already exists`: ```toml [auth.oauth_server] enabled = true authorization_url_path = "/oauth/consent" allow_dynamic_registration = true ``` Set `site_url` to wherever your test app runs (e.g. `http://localhost:3100`), then `supabase start`. Grab the API URL and publishable key from `supabase status`. ### 2. A consumer app with the blocks installed The consent block ships no login route by design, so pair it with an auth block: ```bash npx create-next-app@latest consent-test --ts --tailwind --app --yes ``` ```bash cd consent-test && npx shadcn@latest init -d -y && npx shadcn@latest add https://supabase.com/library/r/password-based-auth-nextjs.json https://supabase.com/library/r/oauth-consent-nextjs.json ``` To test this branch before it deploys, run `pnpm --filter ui-library dev` and use `http://localhost:3004/library/r/...` instead. If you changed anything under `registry/default/blocks/oauth-consent/**`, run `pnpm --filter ui-library build:registry` first — shadcn fetches the generated `public/r/*.json`, not the source. Put `NEXT_PUBLIC_SUPABASE_URL` and `NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY` in `.env.local` and start the app on the port you set as `site_url`. ### 3. Register an OAuth client and start a real authorization request ```bash curl -s -X POST http://127.0.0.1:54321/auth/v1/oauth/clients/register -H "Content-Type: application/json" -d '{"client_name":"Test Client","redirect_uris":["http://localhost:3100/callback"],"grant_types":["authorization_code"],"response_types":["code"],"scope":"openid profile email"}' ``` Then open the authorize URL in a browser (not curl — you need the redirect chain and cookies): ``` http://127.0.0.1:54321/auth/v1/oauth/authorize?client_id=<id>&response_type=code&redirect_uri=http://localhost:3100/callback&scope=openid+profile+email&state=xyz&code_challenge=<challenge>&code_challenge_method=S256 ``` Auth mints the `authorization_id` and redirects to `<site_url>/oauth/consent?authorization_id=…`. An MCP client pointed at your app is an even better driver, since that's the real consumer shape. ### 4. Cases to walk | Case | Expected | | --- | --- | | Signed out, hit the authorize URL | Lands on `/auth/login?next=%2Foauth%2Fconsent%3Fauthorization_id%3D…`; after login, returns to the consent screen | | Consent screen | Shows client name, redirect URI, signed-in email, and requested scopes from `getAuthorizationDetails` | | Allow access | Redirects to `redirect_uri` with `code` and your original `state`; the code exchanges at `/oauth/token` for a real access token | | Deny | Redirects with `error=access_denied` and your `state` | | Re-run the same authorize URL after approving | Skips the screen, straight to callback with a new code | | Visit `/oauth/consent` with no `authorization_id` | "This page needs an authorization_id" | | Stale or bogus `authorization_id` | Error shown, buttons still usable | | Double-click Allow | Exactly one `POST /oauth/authorizations/<id>/consent` | Test the react, react-router, or tanstack variant the same way if you're touching them — the hook is duplicated per framework, so a fix in one doesn't carry. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added an OAuth 2.1 consent experience with client details, requested scopes, redirect URI, and approve/deny actions. * Added OAuth consent examples and registry blocks for Next.js, React, React Router, and TanStack Start. * Added OAuth documentation, navigation, and framework support across the UI library. * **Bug Fixes** * Login flows now safely preserve valid same-origin redirect destinations while rejecting unsafe URLs. * OAuth routes can handle consent flows before authentication and redirect safely to sign-in. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
81 lines
5.0 KiB
TypeScript
81 lines
5.0 KiB
TypeScript
import { type RegistryItem } from 'shadcn/schema'
|
|
|
|
import { clients } from './clients'
|
|
import currentUserAvatar from './default/blocks/current-user-avatar/registry-item.json' with { type: 'json' }
|
|
import dropzone from './default/blocks/dropzone/registry-item.json' with { type: 'json' }
|
|
import infiniteQueryHook from './default/blocks/infinite-query-hook/registry-item.json' with { type: 'json' }
|
|
import oauthConsentNextjs from './default/blocks/oauth-consent-nextjs/registry-item.json' with { type: 'json' }
|
|
import oauthConsentReactRouter from './default/blocks/oauth-consent-react-router/registry-item.json' with { type: 'json' }
|
|
import oauthConsentReact from './default/blocks/oauth-consent-react/registry-item.json' with { type: 'json' }
|
|
import oauthConsentTanstack from './default/blocks/oauth-consent-tanstack/registry-item.json' with { type: 'json' }
|
|
import passwordBasedAuthNextjs from './default/blocks/password-based-auth-nextjs/registry-item.json' with { type: 'json' }
|
|
import passwordBasedAuthReactRouter from './default/blocks/password-based-auth-react-router/registry-item.json' with { type: 'json' }
|
|
import passwordBasedAuthReact from './default/blocks/password-based-auth-react/registry-item.json' with { type: 'json' }
|
|
import passwordBasedAuthTanstack from './default/blocks/password-based-auth-tanstack/registry-item.json' with { type: 'json' }
|
|
import realtimeAvatarStack from './default/blocks/realtime-avatar-stack/registry-item.json' with { type: 'json' }
|
|
import realtimeChat from './default/blocks/realtime-chat/registry-item.json' with { type: 'json' }
|
|
import realtimeCursor from './default/blocks/realtime-cursor/registry-item.json' with { type: 'json' }
|
|
import realtimeFlow from './default/blocks/realtime-flow/registry-item.json' with { type: 'json' }
|
|
import realtimeMonaco from './default/blocks/realtime-monaco/registry-item.json' with { type: 'json' }
|
|
import safeNextPath from './default/blocks/safe-next-path/registry-item.json' with { type: 'json' }
|
|
import socialAuthNextjs from './default/blocks/social-auth-nextjs/registry-item.json' with { type: 'json' }
|
|
import socialAuthReactRouter from './default/blocks/social-auth-react-router/registry-item.json' with { type: 'json' }
|
|
import socialAuthReact from './default/blocks/social-auth-react/registry-item.json' with { type: 'json' }
|
|
import socialAuthTanstack from './default/blocks/social-auth-tanstack/registry-item.json' with { type: 'json' }
|
|
import tanstackDbNextjs from './default/blocks/tanstack-db/registry-item.json' with { type: 'json' }
|
|
import { registryItemAppend } from './utils'
|
|
|
|
const combine = (component: RegistryItem) => {
|
|
return clients.flatMap((client) => {
|
|
return registryItemAppend(
|
|
{
|
|
...component,
|
|
name: `${component.name}-${client.name.replace('supabase-client-', '')}`,
|
|
},
|
|
[client]
|
|
)
|
|
})
|
|
}
|
|
|
|
const withClientAndDocs = (component: RegistryItem, client: RegistryItem) => ({
|
|
...registryItemAppend(component, [client]),
|
|
docs: [component.docs, client.docs].filter(Boolean).join('\n\n'),
|
|
})
|
|
|
|
const nextjsClient = clients.find((client) => client.name === 'supabase-client-nextjs')
|
|
const reactClient = clients.find((client) => client.name === 'supabase-client-react')
|
|
const tanstackClient = clients.find((client) => client.name === 'supabase-client-tanstack')
|
|
const reactRouterClient = clients.find((client) => client.name === 'supabase-client-react-router')
|
|
|
|
export const blocks = [
|
|
safeNextPath as RegistryItem,
|
|
|
|
registryItemAppend(passwordBasedAuthNextjs as RegistryItem, [nextjsClient!]),
|
|
registryItemAppend(passwordBasedAuthReact as RegistryItem, [reactClient!]),
|
|
registryItemAppend(passwordBasedAuthReactRouter as RegistryItem, [reactRouterClient!]),
|
|
registryItemAppend(passwordBasedAuthTanstack as RegistryItem, [tanstackClient!]),
|
|
|
|
registryItemAppend(socialAuthNextjs as RegistryItem, [nextjsClient!]),
|
|
registryItemAppend(socialAuthReact as RegistryItem, [reactClient!]),
|
|
registryItemAppend(socialAuthReactRouter as RegistryItem, [reactRouterClient!]),
|
|
registryItemAppend(socialAuthTanstack as RegistryItem, [tanstackClient!]),
|
|
|
|
...combine(dropzone as RegistryItem),
|
|
...combine(realtimeCursor as RegistryItem),
|
|
...combine(currentUserAvatar as RegistryItem),
|
|
...combine(realtimeAvatarStack as RegistryItem),
|
|
...combine(realtimeChat as RegistryItem),
|
|
...combine(realtimeFlow as RegistryItem),
|
|
...combine(realtimeMonaco as RegistryItem),
|
|
// infinite query hook is intentionally not combined with the clients since it depends on clients having database types.
|
|
infiniteQueryHook as RegistryItem,
|
|
|
|
withClientAndDocs(oauthConsentNextjs as RegistryItem, nextjsClient!),
|
|
withClientAndDocs(oauthConsentReact as RegistryItem, reactClient!),
|
|
withClientAndDocs(oauthConsentReactRouter as RegistryItem, reactRouterClient!),
|
|
withClientAndDocs(oauthConsentTanstack as RegistryItem, tanstackClient!),
|
|
|
|
// tanstack-db is served dynamically via API route, but we register it here for the static build
|
|
registryItemAppend(tanstackDbNextjs as RegistryItem, [nextjsClient!]),
|
|
] as RegistryItem[]
|