mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 17:35:10 +03:00
## What kind of change does this PR introduce? Mechanical cleanup on top of the Button default-variant change (#50160). ## What is the current behavior? Many callsites still pass `variant="default"` even though that is now the component default. ## What is the new behavior? Removes redundant static `variant="default"` from legacy `Button` and `ButtonTooltip` callsites. Keeps explicit defaults where they document the API: - `button-default.tsx` and `button-sizes.tsx` demos - `DocsButton`, which pins neutral styling at the wrapper boundary ## To test Studio: - [Auth → Rate Limits](https://studio-staging-2s957kwc4-supabase.vercel.app/dashboard/project/_/auth/rate-limits): dirty the form so Cancel appears; Cancel stays neutral, Save stays green - [Project Settings → API Keys](https://studio-staging-2s957kwc4-supabase.vercel.app/dashboard/project/_/settings/api-keys): `DocsButton` in the header actions stays neutral Design system: - [Design system → Button](https://design-system-git-dnywh-dc924ac1-supabase.vercel.app/design-system/docs/components/button): `button-default` / `button-sizes` still show explicit default styling; Primary (green) is restricted to the Primary section (and `asChild`) WWW: - [www → Brand assets](https://zone-www-dot-com-git-dnywh-dc924ac1-supabase.vercel.app/brand-assets): Download logo kit / Download button kit stay neutral
206 lines
7.9 KiB
TypeScript
206 lines
7.9 KiB
TypeScript
import { zodResolver } from '@hookform/resolvers/zod'
|
|
import { PermissionAction } from '@supabase/shared-types/out/constants'
|
|
import { useParams } from 'common'
|
|
import Link from 'next/link'
|
|
import { useEffect } from 'react'
|
|
import { useForm } from 'react-hook-form'
|
|
import { toast } from 'sonner'
|
|
import { Button, Card, CardContent, CardFooter, Form, FormControl, FormField, Switch } from 'ui'
|
|
import { Admonition } from 'ui-patterns/Admonition'
|
|
import { FormItemLayout } from 'ui-patterns/form/FormItemLayout/FormItemLayout'
|
|
import { GenericSkeletonLoader } from 'ui-patterns/ShimmeringLoader'
|
|
import { z } from 'zod'
|
|
|
|
import { ScaffoldContainer, ScaffoldSection } from '@/components/layouts/Scaffold'
|
|
import { AlertError } from '@/components/ui/AlertError'
|
|
import { NoPermission } from '@/components/ui/NoPermission'
|
|
import { UpgradeToPro } from '@/components/ui/UpgradeToPro'
|
|
import { useOrganizationMembersQuery } from '@/data/organizations/organization-members-query'
|
|
import { useOrganizationMfaToggleMutation } from '@/data/organizations/organization-mfa-mutation'
|
|
import { useOrganizationMfaQuery } from '@/data/organizations/organization-mfa-query'
|
|
import { useCheckEntitlements } from '@/hooks/misc/useCheckEntitlements'
|
|
import { useAsyncCheckPermissions } from '@/hooks/misc/useCheckPermissions'
|
|
import { useProfile } from '@/lib/profile'
|
|
import { useTrack } from '@/lib/telemetry/track'
|
|
|
|
const schema = z.object({
|
|
enforceMfa: z.boolean(),
|
|
})
|
|
|
|
export const SecuritySettings = () => {
|
|
const { slug } = useParams()
|
|
const { profile } = useProfile()
|
|
const {
|
|
data: members,
|
|
error: membersError,
|
|
isPending: isLoadingMembers,
|
|
isError: isMembersError,
|
|
isSuccess: isSuccessMembers,
|
|
} = useOrganizationMembersQuery({ slug })
|
|
|
|
const { can: canReadMfaConfig, isLoading: isLoadingPermissions } = useAsyncCheckPermissions(
|
|
PermissionAction.READ,
|
|
'organizations'
|
|
)
|
|
const { can: canUpdateMfaConfig } = useAsyncCheckPermissions(
|
|
PermissionAction.UPDATE,
|
|
'organizations'
|
|
)
|
|
const track = useTrack()
|
|
|
|
const { hasAccess: hasAccessToEnforceMfa, isLoading: isLoadingEntitlement } =
|
|
useCheckEntitlements('security.enforce_mfa')
|
|
|
|
const {
|
|
data: mfaConfig,
|
|
error: mfaError,
|
|
isPending: isLoadingMfa,
|
|
isError: isErrorMfa,
|
|
isSuccess: isSuccessMfa,
|
|
} = useOrganizationMfaQuery({ slug }, { enabled: hasAccessToEnforceMfa && canReadMfaConfig })
|
|
|
|
const { mutate: toggleMfa, isPending: isUpdatingMfa } = useOrganizationMfaToggleMutation({
|
|
onError: (error) => {
|
|
toast.error(`Failed to update MFA enforcement: ${error.message}`)
|
|
if (mfaConfig !== undefined) form.reset({ enforceMfa: mfaConfig })
|
|
},
|
|
onSuccess: (data) => {
|
|
toast.success('Successfully updated organization MFA settings')
|
|
track('organization_mfa_enforcement_updated', { mfaEnforced: data.enforced })
|
|
},
|
|
})
|
|
|
|
const form = useForm<z.infer<typeof schema>>({
|
|
resolver: zodResolver(schema),
|
|
defaultValues: {
|
|
enforceMfa: false,
|
|
},
|
|
})
|
|
|
|
useEffect(() => {
|
|
if (mfaConfig !== undefined) {
|
|
form.reset({ enforceMfa: mfaConfig })
|
|
}
|
|
}, [mfaConfig, form])
|
|
|
|
const hasMFAEnabled =
|
|
members?.find((member) => member.primary_email == profile?.primary_email)?.mfa_enabled ?? false
|
|
|
|
const requiresPersonalMfa = isSuccessMembers && canUpdateMfaConfig && !hasMFAEnabled
|
|
|
|
const isLoadingMfaEnforcementSettings =
|
|
isLoadingMfa || isLoadingPermissions || isLoadingEntitlement || isLoadingMembers
|
|
const hasMfaConfigError = (isErrorMfa || Boolean(mfaError)) && hasAccessToEnforceMfa
|
|
const canShowMfaEnforcementForm =
|
|
isSuccessMfa && hasAccessToEnforceMfa && isSuccessMembers && !requiresPersonalMfa
|
|
const isMfaEnforcementSwitchDisabled =
|
|
!hasAccessToEnforceMfa || !canUpdateMfaConfig || isUpdatingMfa
|
|
const isSaveMfaEnforcementDisabled =
|
|
isMfaEnforcementSwitchDisabled || isLoadingMfa || !form.formState.isDirty
|
|
|
|
const onSubmit = (values: { enforceMfa: boolean }) => {
|
|
if (!slug || !hasAccessToEnforceMfa) return
|
|
toggleMfa({ slug, setEnforced: values.enforceMfa })
|
|
}
|
|
|
|
return (
|
|
<ScaffoldContainer size="small" className="px-6 xl:px-10">
|
|
<ScaffoldSection isFullWidth>
|
|
{!hasAccessToEnforceMfa && !isLoadingEntitlement ? (
|
|
<UpgradeToPro
|
|
source="organizationMfa"
|
|
primaryText="Organization MFA enforcement is not available on Free Plan"
|
|
secondaryText="Upgrade to Pro or above to enforce MFA requirements for your organization."
|
|
featureProposition="enforce MFA requirements"
|
|
/>
|
|
) : (
|
|
<>
|
|
{isLoadingMfaEnforcementSettings ? (
|
|
<Card>
|
|
<CardContent>
|
|
<GenericSkeletonLoader />
|
|
</CardContent>
|
|
</Card>
|
|
) : !canReadMfaConfig ? (
|
|
<NoPermission resourceText="view organization security settings" />
|
|
) : (
|
|
requiresPersonalMfa && (
|
|
<Admonition
|
|
type="note"
|
|
layout="horizontal"
|
|
title="Enable MFA on your account first"
|
|
description="You need to set up multi-factor authentication (MFA) on your own account before you can enforce it on your organization."
|
|
actions={
|
|
<Button asChild>
|
|
<Link href="/account/security">Set up MFA</Link>
|
|
</Button>
|
|
}
|
|
/>
|
|
)
|
|
)}
|
|
|
|
{isMembersError && (
|
|
<AlertError error={membersError} subject="Failed to retrieve organization members" />
|
|
)}
|
|
|
|
{hasMfaConfigError && (
|
|
<AlertError error={mfaError} subject="Failed to retrieve MFA enforcement status" />
|
|
)}
|
|
|
|
{canShowMfaEnforcementForm && (
|
|
<Form {...form}>
|
|
<form onSubmit={form.handleSubmit(onSubmit)}>
|
|
<Card>
|
|
<CardContent>
|
|
<FormField
|
|
control={form.control}
|
|
name="enforceMfa"
|
|
render={({ field }) => (
|
|
<FormItemLayout
|
|
layout="flex-row-reverse"
|
|
className="justify-between"
|
|
label="Require MFA to access organization"
|
|
description="Team members must have MFA enabled and a valid MFA session to access the organization and any projects."
|
|
>
|
|
<FormControl>
|
|
<Switch
|
|
checked={field.value}
|
|
onCheckedChange={field.onChange}
|
|
disabled={isMfaEnforcementSwitchDisabled}
|
|
/>
|
|
</FormControl>
|
|
</FormItemLayout>
|
|
)}
|
|
/>
|
|
</CardContent>
|
|
<CardFooter className="justify-end space-x-2">
|
|
{form.formState.isDirty && (
|
|
<Button
|
|
disabled={isLoadingMfa || isUpdatingMfa}
|
|
onClick={() =>
|
|
form.reset({ enforceMfa: hasAccessToEnforceMfa ? mfaConfig : false })
|
|
}
|
|
>
|
|
Cancel
|
|
</Button>
|
|
)}
|
|
<Button
|
|
variant="primary"
|
|
type="submit"
|
|
disabled={isSaveMfaEnforcementDisabled}
|
|
loading={isUpdatingMfa}
|
|
>
|
|
Save
|
|
</Button>
|
|
</CardFooter>
|
|
</Card>
|
|
</form>
|
|
</Form>
|
|
)}
|
|
</>
|
|
)}
|
|
</ScaffoldSection>
|
|
</ScaffoldContainer>
|
|
)
|
|
}
|