Files
supabase/apps/studio/lib/role-impersonation.ts
9eab4f8fbf build(studio): Vite/TanStack-Start build pipeline behind flag (stack 1/6, from #46424) (#47107)
**Stack 1/6** of the TanStack Start migration (#46424), split into
reviewable, independently-mergeable PRs.

> [!IMPORTANT]
> **Next stays the default and only active framework after this PR.**
This wires up the Vite/TanStack-Start build pipeline behind the
`STUDIO_FRAMEWORK` flag, but there are no TanStack routes yet — so the
TanStack build isn't functional or tested until later PRs in the stack.
Nothing about the Next build, dev, or deploy changes behaviourally here.

## What's in this PR
- **Dispatch:** `dev`/`build`/`start` now go through
`scripts/dispatch.js`, which runs the Next variant unless
`STUDIO_FRAMEWORK=tanstack`. The original commands are preserved as
`dev:next`/`build:next`/`start:next`.
- **Build pipeline:** `vite.config.ts`, `serve.js`, `smoke-server.mjs`,
vite/tanstack deps, `turbo.jsonc`.
- **`tsconfig.json`:** `jsx: react-jsx`, `moduleResolution: Bundler`,
`target: ES2022`. Because `include` is `**/*.ts(x)`, this re-typechecks
the whole app, so the companion adaptations below land with it.
- **Shared adaptations (companions to the tsconfig change):**
`BufferSource` casts, `packages/ui` unused-`React` import removals, etc.
- **Routing/middleware plumbing:** `next.config.ts` +
`redirects.shared.ts` (redirect rules now shared with `vercel.ts`),
`proxy.ts`/`start.ts` middleware + `hosted-api-allowlist.ts`.

## Verification
Run locally off `master`: frozen install ✓, `studio` typecheck ✓, **Next
build ✓** (compiles + generates all routes), lint ratchet ✓ ("some rules
improved"), prettier ✓.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a hosted API endpoint allowlist to return 404 for non-supported
`/api/*` routes.
* Introduced a TanStack route-migration checklist and expanded TanStack
Start routing support.
* **Improvements**
* Enhanced deployment refresh/detection by tightening cookie handling
for “latest deployment” updates.
* Centralized redirect/maintenance-mode rules for consistent platform vs
self-hosted behavior.
* Improved production serving with a dedicated static + proxy server and
a post-build smoke test.
* **Dependencies**
* Updated TanStack-related packages and React Table/query tooling
versions.
* **Documentation / Chores**
* Updated formatting and tooling config; added shared build environment
parsing utilities.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-06-24 17:55:22 +08:00

167 lines
4.2 KiB
TypeScript

import { getImpersonationSQL, type SafeSqlFragment } from '@supabase/pg-meta'
import { uuidv4 } from './helpers'
import type { User } from '@/data/auth/users-infinite-query'
import { RoleImpersonationState as ValtioRoleImpersonationState } from '@/state/role-impersonation-state'
type PostgrestImpersonationRole =
| {
type: 'postgrest'
role: 'anon'
}
| {
type: 'postgrest'
role: 'service_role'
}
| {
type: 'postgrest'
role: 'authenticated'
userType: 'native'
user?: User
aal?: 'aal1' | 'aal2'
}
| {
type: 'postgrest'
role: 'authenticated'
userType: 'external'
externalAuth?: {
sub: string
additionalClaims?: Record<string, any>
}
aal?: 'aal1' | 'aal2'
}
export type PostgrestRole = PostgrestImpersonationRole['role']
type CustomImpersonationRole = {
type: 'custom'
role: string
}
export type ImpersonationRole = PostgrestImpersonationRole | CustomImpersonationRole
export function getExp1HourFromNow() {
return Math.floor((Date.now() + 60 * 60 * 1000) / 1000)
}
export function getPostgrestClaims(projectRef: string, role: PostgrestImpersonationRole) {
const exp = getExp1HourFromNow()
const nowTimestamp = Math.floor(Date.now() / 1000)
if (role.role === 'authenticated') {
// Supabase native auth case
if (role.userType === 'native' && role.user) {
const user = role.user
return {
aal: role.aal ?? 'aal1',
amr: [{ method: 'password', timestamp: nowTimestamp }],
app_metadata: user.raw_app_meta_data,
aud: 'authenticated',
email: user.email,
exp,
iat: nowTimestamp,
iss: `https://${projectRef}.supabase.co/auth/v1`,
phone: user.phone,
role: user.role ?? role.role,
session_id: uuidv4(),
sub: user.id,
user_metadata: user.raw_user_meta_data,
is_anonymous: user.is_anonymous,
}
}
// External auth case
if (role.userType === 'external' && role.externalAuth) {
return {
aal: role.aal ?? 'aal1',
aud: 'authenticated',
exp,
iat: nowTimestamp,
role: 'authenticated',
session_id: uuidv4(),
sub: role.externalAuth.sub,
...role.externalAuth.additionalClaims,
}
}
}
return {
iss: 'supabase',
ref: projectRef,
role: role.role,
iat: nowTimestamp,
exp,
}
}
export type RoleImpersonationState = Pick<ValtioRoleImpersonationState, 'role' | 'claims'>
export function wrapWithRoleImpersonation(
sql: SafeSqlFragment,
state?: RoleImpersonationState
): SafeSqlFragment {
const { role, claims } = state ?? { role: undefined, claims: undefined }
if (role === undefined) return sql
const unexpiredClaims =
claims !== undefined ? { ...claims, exp: getExp1HourFromNow() } : undefined
const impersonationSql = getImpersonationSQL({ role: role, unexpiredClaims, sql })
return impersonationSql
}
function encodeText(data: string) {
return new TextEncoder().encode(data)
}
function encodeBase64Url(data: ArrayBuffer | Uint8Array | string): string {
return btoa(
String.fromCharCode(...new Uint8Array(typeof data === 'string' ? encodeText(data) : data))
)
.replace(/\+/g, '-')
.replace(/\//g, '_')
.replace(/=+$/, '')
}
function genKey(rawKey: string) {
return window.crypto.subtle.importKey(
'raw',
encodeText(rawKey) as BufferSource,
{ name: 'HMAC', hash: 'SHA-256' },
false,
['sign', 'verify']
)
}
async function createToken(jwtPayload: object, key: string) {
const headerAndPayload =
encodeBase64Url(encodeText(JSON.stringify({ alg: 'HS256', typ: 'JWT' }))) +
'.' +
encodeBase64Url(encodeText(JSON.stringify(jwtPayload)))
const signature = encodeBase64Url(
new Uint8Array(
await window.crypto.subtle.sign(
{ name: 'HMAC' },
await genKey(key),
encodeText(headerAndPayload) as BufferSource
)
)
)
return `${headerAndPayload}.${signature}`
}
export function getRoleImpersonationJWT(
projectRef: string,
jwtSecret: string,
role: PostgrestImpersonationRole
): Promise<string> {
const claims = {
...getPostgrestClaims(projectRef, role),
exp: getExp1HourFromNow(),
}
return createToken(claims, jwtSecret)
}