Files
claude[bot]andClaude ffd5a93f37 feat(www): add hidden Legal Hub subprocessor list page (draft) (#48100)
<!-- ccr-slack-attribution -->
_Requested by **Nicole Kramer** · [Slack
thread](https://supabase.slack.com/archives/C0161K73J1J/p1783431374242039?thread_ts=1783431374.242039&cid=C0161K73J1J)_

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature (`apps/www`).

## What is the current behavior?

No public page for Supabase's subprocessor list, and no way for
customers to be notified when it changes.

## What is the new behavior?

A new hidden page at `/legal/customer-resources/subprocessor-list` shows
the current dated subprocessor PDF and lets anyone subscribe with their
name and email to receive an email whenever the list is updated. The
page is `noindex` and not linked from any nav, so it's shareable by
direct URL only for now. Mirrors Wiz's sub-processor-list page.

**How:**

- **Page**
`apps/www/pages/legal/customer-resources/subprocessor-list.tsx` —
pages-router, mirrors the existing Legal Hub pages (`DefaultLayout`,
`NextSeo`, `PageHeader` + breadcrumb, `SectionContainer` prose). Embeds
the PDF (inline preview + download link) and renders the subscribe form.
Marked `NextSeo` noindex/nofollow and intentionally left unlinked.
- A single `CURRENT_PDF` constant (filename + display date) is the only
thing to change when Legal hands over a new dated PDF.
- **Form** `apps/www/components/SubprocessorUpdatesForm.tsx` — mirrors
`SecurityNewsletterForm` (First name, Last name, Email; `ui`
primitives). Carries the framing copy verbatim, with **Subscribe to
updates** bold and Privacy Policy linked to
https://supabase.com/privacy.
- **API route**
`apps/www/app/api-v2/submit-form-subprocessor-updates/route.tsx` — exact
mirror of `submit-form-security-newsletter`; subscribes the user to the
Customer.io "Subprocessor Alerts" subscription (topic 4) via
`cio_subscription_preferences.topics.topic_4: true`.
- **PDF** `apps/www/public/legal/subprocessor-list/June-1-2026.pdf`.

**Updating the list in future:** Drop the new dated PDF into
`apps/www/public/legal/subprocessor-list/` and update the `CURRENT_PDF`
constant. Nothing else changes.

## Additional context

**Notes / to confirm:**

- Customer.io topic id `4` → `topic_4` (per Prashant); not independently
verified against Customer.io.
- Draft: page is intentionally unlinked and noindex until Legal signs
off.

---
_Generated by [Claude
Code](https://claude.ai/code/session_01D9WS2QWQ8Y3o7PqDZabS3F)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-22 11:19:14 +01:00

63 lines
2.0 KiB
TypeScript

import * as Sentry from '@sentry/nextjs'
import { CustomerioTrackClient } from '~/lib/customerio'
const corsHeaders = {
'Access-Control-Allow-Origin': '*',
'Access-Control-Allow-Headers': 'authorization, x-client-info, apikey, content-type',
}
const isValidEmail = (email: string): boolean => {
const emailPattern = /^[\w-\.+]+@([\w-]+\.)+[\w-]{2,8}$/
return emailPattern.test(email)
}
export async function POST(req: Request) {
const body = await req.json()
const { firstName, lastName, email } = body
if (!firstName || !lastName || !email) {
return new Response(JSON.stringify({ message: 'All fields are required' }), {
headers: { ...corsHeaders, 'Content-Type': 'application/json' },
status: 422,
})
}
if (!isValidEmail(email)) {
return new Response(JSON.stringify({ message: 'Invalid email address' }), {
headers: { ...corsHeaders, 'Content-Type': 'application/json' },
status: 422,
})
}
try {
const customerioSiteId = process.env.CUSTOMERIO_SITE_ID
const customerioApiKey = process.env.CUSTOMERIO_API_KEY
if (!customerioSiteId || !customerioApiKey) {
throw new Error('Customer.io credentials not configured')
}
const cio = new CustomerioTrackClient(customerioSiteId, customerioApiKey)
await cio.createOrUpdateProfile(email, {
firstName,
lastName,
// Subprocessor Alerts subscription topic. Per Prashant: subscription topic id 4.
// (The security newsletter route uses topic_2 for its own topic.)
'cio_subscription_preferences.topics.topic_4': true,
})
return new Response(JSON.stringify({ message: 'Subscription successful' }), {
headers: { ...corsHeaders, 'Content-Type': 'application/json' },
status: 200,
})
} catch (error: any) {
Sentry.captureException(error)
return new Response(JSON.stringify({ error: error.message }), {
headers: { ...corsHeaders, 'Content-Type': 'application/json' },
status: 500,
})
}
}