mirror of
https://github.com/supabase/supabase.git
synced 2026-10-09 03:15:06 +03:00
**Stack 1/6** of the TanStack Start migration (#46424), split into reviewable, independently-mergeable PRs. > [!IMPORTANT] > **Next stays the default and only active framework after this PR.** This wires up the Vite/TanStack-Start build pipeline behind the `STUDIO_FRAMEWORK` flag, but there are no TanStack routes yet — so the TanStack build isn't functional or tested until later PRs in the stack. Nothing about the Next build, dev, or deploy changes behaviourally here. ## What's in this PR - **Dispatch:** `dev`/`build`/`start` now go through `scripts/dispatch.js`, which runs the Next variant unless `STUDIO_FRAMEWORK=tanstack`. The original commands are preserved as `dev:next`/`build:next`/`start:next`. - **Build pipeline:** `vite.config.ts`, `serve.js`, `smoke-server.mjs`, vite/tanstack deps, `turbo.jsonc`. - **`tsconfig.json`:** `jsx: react-jsx`, `moduleResolution: Bundler`, `target: ES2022`. Because `include` is `**/*.ts(x)`, this re-typechecks the whole app, so the companion adaptations below land with it. - **Shared adaptations (companions to the tsconfig change):** `BufferSource` casts, `packages/ui` unused-`React` import removals, etc. - **Routing/middleware plumbing:** `next.config.ts` + `redirects.shared.ts` (redirect rules now shared with `vercel.ts`), `proxy.ts`/`start.ts` middleware + `hosted-api-allowlist.ts`. ## Verification Run locally off `master`: frozen install ✓, `studio` typecheck ✓, **Next build ✓** (compiles + generates all routes), lint ratchet ✓ ("some rules improved"), prettier ✓. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a hosted API endpoint allowlist to return 404 for non-supported `/api/*` routes. * Introduced a TanStack route-migration checklist and expanded TanStack Start routing support. * **Improvements** * Enhanced deployment refresh/detection by tightening cookie handling for “latest deployment” updates. * Centralized redirect/maintenance-mode rules for consistent platform vs self-hosted behavior. * Improved production serving with a dedicated static + proxy server and a post-build smoke test. * **Dependencies** * Updated TanStack-related packages and React Table/query tooling versions. * **Documentation / Chores** * Updated formatting and tooling config; added shared build environment parsing utilities. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
167 lines
4.2 KiB
TypeScript
167 lines
4.2 KiB
TypeScript
import { getImpersonationSQL, type SafeSqlFragment } from '@supabase/pg-meta'
|
|
|
|
import { uuidv4 } from './helpers'
|
|
import type { User } from '@/data/auth/users-infinite-query'
|
|
import { RoleImpersonationState as ValtioRoleImpersonationState } from '@/state/role-impersonation-state'
|
|
|
|
type PostgrestImpersonationRole =
|
|
| {
|
|
type: 'postgrest'
|
|
role: 'anon'
|
|
}
|
|
| {
|
|
type: 'postgrest'
|
|
role: 'service_role'
|
|
}
|
|
| {
|
|
type: 'postgrest'
|
|
role: 'authenticated'
|
|
userType: 'native'
|
|
user?: User
|
|
aal?: 'aal1' | 'aal2'
|
|
}
|
|
| {
|
|
type: 'postgrest'
|
|
role: 'authenticated'
|
|
userType: 'external'
|
|
externalAuth?: {
|
|
sub: string
|
|
additionalClaims?: Record<string, any>
|
|
}
|
|
aal?: 'aal1' | 'aal2'
|
|
}
|
|
|
|
export type PostgrestRole = PostgrestImpersonationRole['role']
|
|
|
|
type CustomImpersonationRole = {
|
|
type: 'custom'
|
|
role: string
|
|
}
|
|
|
|
export type ImpersonationRole = PostgrestImpersonationRole | CustomImpersonationRole
|
|
|
|
export function getExp1HourFromNow() {
|
|
return Math.floor((Date.now() + 60 * 60 * 1000) / 1000)
|
|
}
|
|
|
|
export function getPostgrestClaims(projectRef: string, role: PostgrestImpersonationRole) {
|
|
const exp = getExp1HourFromNow()
|
|
const nowTimestamp = Math.floor(Date.now() / 1000)
|
|
|
|
if (role.role === 'authenticated') {
|
|
// Supabase native auth case
|
|
if (role.userType === 'native' && role.user) {
|
|
const user = role.user
|
|
return {
|
|
aal: role.aal ?? 'aal1',
|
|
amr: [{ method: 'password', timestamp: nowTimestamp }],
|
|
app_metadata: user.raw_app_meta_data,
|
|
aud: 'authenticated',
|
|
email: user.email,
|
|
exp,
|
|
iat: nowTimestamp,
|
|
iss: `https://${projectRef}.supabase.co/auth/v1`,
|
|
phone: user.phone,
|
|
role: user.role ?? role.role,
|
|
session_id: uuidv4(),
|
|
sub: user.id,
|
|
user_metadata: user.raw_user_meta_data,
|
|
is_anonymous: user.is_anonymous,
|
|
}
|
|
}
|
|
|
|
// External auth case
|
|
if (role.userType === 'external' && role.externalAuth) {
|
|
return {
|
|
aal: role.aal ?? 'aal1',
|
|
aud: 'authenticated',
|
|
exp,
|
|
iat: nowTimestamp,
|
|
role: 'authenticated',
|
|
session_id: uuidv4(),
|
|
sub: role.externalAuth.sub,
|
|
...role.externalAuth.additionalClaims,
|
|
}
|
|
}
|
|
}
|
|
|
|
return {
|
|
iss: 'supabase',
|
|
ref: projectRef,
|
|
role: role.role,
|
|
iat: nowTimestamp,
|
|
exp,
|
|
}
|
|
}
|
|
|
|
export type RoleImpersonationState = Pick<ValtioRoleImpersonationState, 'role' | 'claims'>
|
|
|
|
export function wrapWithRoleImpersonation(
|
|
sql: SafeSqlFragment,
|
|
state?: RoleImpersonationState
|
|
): SafeSqlFragment {
|
|
const { role, claims } = state ?? { role: undefined, claims: undefined }
|
|
|
|
if (role === undefined) return sql
|
|
|
|
const unexpiredClaims =
|
|
claims !== undefined ? { ...claims, exp: getExp1HourFromNow() } : undefined
|
|
const impersonationSql = getImpersonationSQL({ role: role, unexpiredClaims, sql })
|
|
return impersonationSql
|
|
}
|
|
|
|
function encodeText(data: string) {
|
|
return new TextEncoder().encode(data)
|
|
}
|
|
|
|
function encodeBase64Url(data: ArrayBuffer | Uint8Array | string): string {
|
|
return btoa(
|
|
String.fromCharCode(...new Uint8Array(typeof data === 'string' ? encodeText(data) : data))
|
|
)
|
|
.replace(/\+/g, '-')
|
|
.replace(/\//g, '_')
|
|
.replace(/=+$/, '')
|
|
}
|
|
|
|
function genKey(rawKey: string) {
|
|
return window.crypto.subtle.importKey(
|
|
'raw',
|
|
encodeText(rawKey) as BufferSource,
|
|
{ name: 'HMAC', hash: 'SHA-256' },
|
|
false,
|
|
['sign', 'verify']
|
|
)
|
|
}
|
|
|
|
async function createToken(jwtPayload: object, key: string) {
|
|
const headerAndPayload =
|
|
encodeBase64Url(encodeText(JSON.stringify({ alg: 'HS256', typ: 'JWT' }))) +
|
|
'.' +
|
|
encodeBase64Url(encodeText(JSON.stringify(jwtPayload)))
|
|
|
|
const signature = encodeBase64Url(
|
|
new Uint8Array(
|
|
await window.crypto.subtle.sign(
|
|
{ name: 'HMAC' },
|
|
await genKey(key),
|
|
encodeText(headerAndPayload) as BufferSource
|
|
)
|
|
)
|
|
)
|
|
|
|
return `${headerAndPayload}.${signature}`
|
|
}
|
|
|
|
export function getRoleImpersonationJWT(
|
|
projectRef: string,
|
|
jwtSecret: string,
|
|
role: PostgrestImpersonationRole
|
|
): Promise<string> {
|
|
const claims = {
|
|
...getPostgrestClaims(projectRef, role),
|
|
exp: getExp1HourFromNow(),
|
|
}
|
|
|
|
return createToken(claims, jwtSecret)
|
|
}
|