mirror of
https://github.com/supabase/supabase.git
synced 2026-10-08 02:45:07 +03:00
Mirror Edge Functions' Secrets pattern, adapted for the future Workers Secrets
API's fine-grained model.
Project pool (real API):
- New sidebar item "Secrets" under Workers, next to the main list.
- New page /project/[ref]/workers/secrets backed by useSecretsQuery /
useSecretsCreateMutation / useSecretsDeleteMutation — the same v1 project
secrets endpoint Edge Functions already reads. Filters out SUPABASE_*.
Per-worker overrides (prototype):
- New state/worker-secret-overrides.ts valtio store keyed by
${projectRef}:${workerName}. Two axes: `overrides` (name → value) and
`denied` (project secret names hidden from this worker).
- Worker Settings gains a "Secrets" section with a resolved table:
From project / Override / This worker / Denied — with per-row actions
(override value, deny/allow, revert to project, delete worker-only).
- Admonition on the section makes it clear the fine-grained control is
prototype state until the real Workers Secrets API ships.
Reusable AddSecretDialog handles both the project add flow and per-worker
add/override with a SCREAMING_SNAKE zod schema, SUPABASE_ reserved-prefix
guard, and dup detection.
Note: TanStack route mirror for the new page is deferred — routeTree.gen.ts
is a Vite-plugin generated file and can't be hand-edited. Next pages router
serves the page today; whoever runs pnpm dev:studio next can regenerate the
tree and add the route wrapper.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb