mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 09:55:06 +03:00
## What kind of change does this PR introduce? Docs update. Aligns documentation and style guides with the **Sign in / Sign out / Sign up** platform standard. Closes DOCS-1328. Related to [#49874](https://github.com/supabase/supabase/pull/49874). ## What is the current behavior? Docs style guides prefer _login_ / _log in_. Guide prose uses mixed login and sign in wording. ## What is the new behavior? - [WORD_LIST.md](apps/docs/WORD_LIST.md) and [copywriting.mdx](apps/design-system/content/docs/copywriting.mdx) document the sign in standard - Design-system auth examples updated - Guide prose and API reference spec descriptions updated ### Terminology **Standard:** Use _sign in_, _sign out_, and _sign up_ as verbs. Use _sign-in_, _sign-out_, and _sign-up_ as nouns and adjectives. Match Studio UI labels (**Sign in**, **Sign out**, **Sign up**). **Preserved intentionally:** | Category | Keep as-is | Example | | -------- | ---------- | ------- | | Feature name | social login | `/social-login`, `features.mdx` heading, OAuth provider section | | URL slugs | `login` in paths | `/phone-login`, `/login-flows`, `choosing-login-flow` | | CLI | `supabase login` / `supabase logout` | Reference ids `supabase-login` / `supabase-logout`; executable commands unchanged | | SDK methods | `logout()` | Kotlin/Swift method names in API reference titles and examples | | Third-party UI | Provider product labels | Facebook Login, Kakao Login, portal **Login** buttons | | Postgres | Database terminology | login privileges, login credentials, login via role | | Audit/logging | Log prose | "Generates the following **log** in the Postgres Logs" | | Code and routes | Paths and filenames | `app/login/`, `Login.tsx`, `demos/android-login` | | External URLs | Third-party login pages | `dash.cloudflare.com/login`, `console.neon.tech/login`, `vercel.com/login` | | API identifiers | Event and field names | Audit actions `login`/`logout`, `should_logout_user` | ## To test - Run `pnpm lint:mdx` in `apps/docs` - Spot-check `features.mdx`, `social-login.mdx`, and a provider guide (e.g. Facebook, Kakao) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Standardized authentication terminology across guides, reference material, CLI documentation, and copywriting guidance using “sign in,” “sign out,” and “sign up.” * Updated authentication instructions, headings, link text, examples, and SSO guidance for clearer, more consistent wording. * Corrected related grammar, spelling, hyphenation, and documentation links while preserving established product names and implementation commands. * **Style** * Refined code examples with consistent import ordering and spacing. * **Examples** * Updated authentication button and menu labels to “Sign in” and “Sign out.” <!-- end of auto-generated comment: release notes by coderabbit.ai -->
85 lines
3.7 KiB
Plaintext
85 lines
3.7 KiB
Plaintext
---
|
||
id: 'auth-audit-logs'
|
||
title: 'Auth Audit Logs'
|
||
description: 'Monitor and track authentication events with audit logging.'
|
||
subtitle: 'Monitor and track authentication events with audit logging.'
|
||
---
|
||
|
||
Auth audit logs provide comprehensive tracking of authentication events in your Supabase project. Audit logs are automatically captured for all authentication events and help you monitor user authentication activities, detect suspicious behavior, and maintain compliance with security requirements.
|
||
|
||
## What gets logged
|
||
|
||
Supabase auth audit logs automatically capture all authentication events including:
|
||
|
||
- User sign-ups and sign-ins
|
||
- Password changes and resets
|
||
- Email verification events
|
||
- Token refresh and sign-out events
|
||
|
||
## Storage options
|
||
|
||
Audit logs are stored in:
|
||
|
||
- **External log storage** - Cost-efficient storage accessible through the dashboard
|
||
- **Postgres database** (optional) - Stored in the `auth.audit_log_entries` table, searchable via SQL, but uses additional database storage
|
||
|
||
You can enable or disable Postgres database storage to optimize your costs.
|
||
|
||
### Configuring audit log storage
|
||
|
||
1. Navigate to your project’s dashboard
|
||
2. Go to **Authentication**
|
||
3. Find the **Audit Logs** under the **Configuration** section
|
||
4. Toggle "Write audit logs to the database" on to enable or off to disable database storage
|
||
|
||
## Log format
|
||
|
||
Audit logs contain detailed information about each authentication event:
|
||
|
||
```json
|
||
{
|
||
"timestamp": "2025-08-01T10:30:00Z",
|
||
"user_id": "uuid",
|
||
"action": "user_signedup",
|
||
"ip_address": "192.168.1.1",
|
||
"user_agent": "Mozilla/5.0...",
|
||
"metadata": {
|
||
"provider": "email"
|
||
}
|
||
}
|
||
```
|
||
|
||
### Log actions reference
|
||
|
||
| Action | Description |
|
||
| ------------------------------- | --------------------------------------- |
|
||
| `login` | User sign-in attempt |
|
||
| `logout` | User sign-out |
|
||
| `invite_accepted` | Team invitation accepted |
|
||
| `user_signedup` | New user registration |
|
||
| `user_invited` | User invitation sent |
|
||
| `user_deleted` | User account deleted |
|
||
| `user_modified` | User profile updated |
|
||
| `user_recovery_requested` | Password reset request |
|
||
| `user_reauthenticate_requested` | User reauthentication required |
|
||
| `user_confirmation_requested` | Email/phone confirmation requested |
|
||
| `user_repeated_signup` | Duplicate signup attempt |
|
||
| `user_updated_password` | Password change completed |
|
||
| `token_revoked` | Refresh token revoked |
|
||
| `token_refreshed` | Refresh token used to obtain new tokens |
|
||
| `generate_recovery_codes` | MFA recovery codes generated |
|
||
| `factor_in_progress` | MFA factor enrollment started |
|
||
| `factor_unenrolled` | MFA factor removed |
|
||
| `challenge_created` | MFA challenge initiated |
|
||
| `verification_attempted` | MFA verification attempt |
|
||
| `factor_deleted` | MFA factor deleted |
|
||
| `recovery_codes_deleted` | MFA recovery codes deleted |
|
||
| `factor_updated` | MFA factor settings updated |
|
||
| `mfa_code_login` | Sign in with MFA code |
|
||
| `identity_unlinked` | An identity unlinked from account |
|
||
|
||
## Limitations
|
||
|
||
- There may be a short delay before logs appear
|
||
- Query capabilities are limited to the dashboard interface
|