Files
Miranda Limonczenko 8140fb58a9 docs: state the local setting, add a verification step, and warn on grants
Three additions from the eval findings in DOCS-1317, all verified on a
local stack.

State the local setting. "Enable the hook" gave a Dashboard click and a
link out, so the one setting a local project needs was never on the
page. Inline the four `config.toml` lines and say that Supabase Auth
reads them at startup, so the stack has to restart. Verified: the
stanza arrives in the Auth container as
GOTRUE_HOOK_CUSTOM_ACCESS_TOKEN_ENABLED and _URI, and
`supabase stop && supabase start` keeps the data.

Say that the hook gates everything. With every table, function, and
policy on the page applied and a user holding an admin row, a token
issued with the hook off carries no role at all. Nothing errors.

Add a verification step. Decode a token and confirm the claim before
writing any policy, with a table reading the three outcomes. All three
verified: `admin` with the hook on and a role row, `null` with the hook
on and no role row, absent with the hook off.

Warn that missing grants break sign-in. Revoking `execute` from
`supabase_auth_admin` answers 500 `Error running hook URI` to every
sign-up and sign-in, including users who have no role.

Also note that `channels` and `messages` belong to the Slack Clone
schema. The policy block is the one fence on the page that fails when a
reader pastes the page top to bottom, because nothing here creates
those tables.
2026-09-24 17:44:58 -07:00
..