mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 17:35:10 +03:00
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — a new UI Library block. Stacked on #49573 (already in main) Fixes AI-1064 ## What is the new behavior? Adds `headless-app-tanstack`: customers sign in, authorize an MCP client, and use the product through agent tool calls. It composes the existing Password-Based Auth, OAuth Consent, and MCP Server blocks. - `/agents` provides a copyable connection prompt, lists OAuth authorizations, and lets customers revoke access. - The shared MCP runtime exposes `whoami` plus example task CRUD tools. Tools use the caller's Supabase client, with database grants and RLS enforcing ownership. - A root-level `supabase/` directory supplies local Auth/OAuth configuration, a declarative tasks schema, and Edge Function files, including `.env.example`. - Docs cover local setup, signing keys, migrations, environment configuration, deployment, and extending the tools. `/example/headless-app` previews the sign-in, consent, connect, and connected states. Shared block fixes make a fresh install work: - Explicit public URL resolution fixes OAuth discovery in local Edge Runtime when middleware runtime detection fails. Both external OAuth access tokens and ordinary authenticated app session tokens remain supported; embedded agents do not need an additional consent flow. - Registry targets keep backend files outside `src/`, and generated consumer routes omit source-only TypeScript suppressions. - Signup respects `auth.email.enable_confirmations`; sign-in/signup preserve the return destination. Missing consent IDs retain the existing error state without serializing `null` into the URL. ## How to test Use the UI Library on **staging** and follow the block pages' instructions. 1. Open the **Headless App** block page for TanStack Start. Install it into a fresh app and follow the setup instructions through connecting an MCP client. 2. Sign up, open `/agents`, and use the connection prompt to authorize a client. Call `whoami`, then create, list, update, and delete a task. 3. Confirm the client appears on `/agents`. Revoke access and verify it disappears and token refresh fails. An existing access token can continue working until it expires. 4. Follow the **MCP Server** block page's embedded-agent instructions using an authenticated app session. Confirm tools work without another OAuth consent flow and `whoami` returns `client_id: null`. 5. With a second user, confirm each user can only access their own tasks. Check that signup behaves correctly for the configured email-confirmation setting. 6. Check the Headless App preview states and run the installed app's typecheck and production build. ## Validation performed Fresh local installation and browser/SDK verification passed: 26 live MCP/Data API checks, 10 Deno tests, and 7 connection-page component tests. Also passed UI Library typecheck, targeted lint, registry/Markdown builds, and fresh consumer typecheck/production build. Both OAuth and ordinary app session authentication were exercised. Hosted deployment and consuming the confirmation-email link were not tested. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a TanStack Headless App example with sign-in, OAuth consent, MCP connection, and connected-agent screens. - Added task management tools for listing, creating, updating, and deleting tasks through MCP. - Added connected-agent management, including server URL and prompt copying, refresh, and access revocation. - Added a new Headless App registry block and documentation. - **Bug Fixes** - Preserved intended destinations through sign-up, email confirmation, and protected-route login redirects. - Improved OAuth discovery URL handling across forwarded-host deployments. - **Documentation** - Updated setup, environment, deployment, and Supabase CLI guidance for headless apps and MCP servers. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Saxon Fletcher <SaxonF@users.noreply.github.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: repro <repro@local> Co-authored-by: Raúl Barroso <code@raulb.dev>
117 lines
4.0 KiB
JSON
117 lines
4.0 KiB
JSON
{
|
|
"name": "library",
|
|
"version": "0.1.0",
|
|
"private": true,
|
|
"type": "module",
|
|
"scripts": {
|
|
"preinstall": "npx only-allow pnpm",
|
|
"dev:content": "velite dev",
|
|
"dev:next": "next dev --port 3004",
|
|
"dev": "run-p build:content build:registry build:markdown && run-p --race dev:*",
|
|
"build:content": "velite build --strict",
|
|
"build:registry": "rimraf -G public/r/* && tsx ./scripts/build-registry.mts && shadcn build public/r/registry.json && tsx scripts/clean-registry.ts",
|
|
"build:markdown": "tsx ./scripts/build-markdown.ts",
|
|
"build:llms": "tsx ./scripts/build-llms-txt.ts",
|
|
"build:next": "next build --turbopack",
|
|
"build": "run-p build:content build:registry build:llms build:markdown && pnpm build:next",
|
|
"test:markdown": "tsx --test scripts/library-mdx-to-markdown.test.ts",
|
|
"test:headless-app": "vitest run --config vitest.config.ts",
|
|
"test:headless-tools": "tsx scripts/test-headless-tools.mts",
|
|
"test:middleware": "pnpm run build:markdown && tsx --test middleware.test.ts",
|
|
"start": "next start",
|
|
"lint": "eslint .",
|
|
"lint:mdx": "supa-mdx-lint content --config ../../supa-mdx-lint.config.toml",
|
|
"clean": "rimraf .next .turbo tsconfig.tsbuildinfo .contentlayer .velite",
|
|
"typecheck": "pnpm build:content && tsc --noEmit -p tsconfig.json"
|
|
},
|
|
"dependencies": {
|
|
"@hookform/resolvers": "^3.1.1",
|
|
"@monaco-editor/react": "catalog:",
|
|
"@react-router/fs-routes": "^7.4.0",
|
|
"@supabase-labs/y-supabase": "0.1.0",
|
|
"@supabase/postgrest-js": "catalog:",
|
|
"@supabase/supa-mdx-lint": "0.2.6-alpha",
|
|
"@supabase/vue-blocks": "workspace:*",
|
|
"@tanstack/react-query": "~5.83.0",
|
|
"@xyflow/react": "^12.10.1",
|
|
"api-types": "workspace:*",
|
|
"axios": "^1.12.0",
|
|
"class-variance-authority": "^0.7.1",
|
|
"cmdk": "^1.1.1",
|
|
"common": "workspace:*",
|
|
"common-tags": "^1.8.2",
|
|
"eslint-config-supabase": "workspace:*",
|
|
"framer-motion": "^11.18.2",
|
|
"icons": "workspace:*",
|
|
"jotai": "^2.8.0",
|
|
"lucide-react": "*",
|
|
"monaco-editor": "catalog:",
|
|
"next": "catalog:",
|
|
"next-themes": "catalog:",
|
|
"openai": "^5.9.0",
|
|
"openapi-fetch": "0.12.4",
|
|
"radix-ui": "catalog:",
|
|
"react": "catalog:",
|
|
"react-dom": "catalog:",
|
|
"react-hook-form": "^7.71.2",
|
|
"react-markdown": "^10.1.0",
|
|
"react-wrap-balancer": "^1.1.0",
|
|
"recharts": "catalog:",
|
|
"rehype-autolink-headings": "^7.1.0",
|
|
"rehype-pretty-code": "^0.9.0",
|
|
"rehype-slug": "^6.0.0",
|
|
"remark": "^14.0.3",
|
|
"remark-code-import": "^1.2.0",
|
|
"remark-gfm": "^4.0.0",
|
|
"sonner": "^1.5.0",
|
|
"ui": "workspace:*",
|
|
"ui-patterns": "workspace:*",
|
|
"unist-util-visit": "^5.0.0",
|
|
"vaul": "^1.1.2",
|
|
"velite": "catalog:",
|
|
"y-monaco": "^0.1.6",
|
|
"y-protocols": "^1.0.7",
|
|
"yjs": "^13.6.29",
|
|
"zod": "catalog:"
|
|
},
|
|
"devDependencies": {
|
|
"@babel/core": "*",
|
|
"@react-router/dev": "^7.9.0",
|
|
"@shikijs/compat": "^1.1.7",
|
|
"@supabase/ssr": "catalog:",
|
|
"@supabase/supabase-js": "catalog:",
|
|
"@tanstack/react-router": "catalog:",
|
|
"@tanstack/react-start": "catalog:",
|
|
"@types/common-tags": "^1.8.4",
|
|
"@types/lodash": "^4.17.16",
|
|
"@types/mdast": "^3.0.15",
|
|
"@types/react": "catalog:",
|
|
"@types/react-dom": "catalog:",
|
|
"@typescript/native": "catalog:",
|
|
"config": "workspace:^",
|
|
"gray-matter": "^4.0.3",
|
|
"lodash": "catalog:",
|
|
"mdast-util-from-markdown": "^1.3.1",
|
|
"mdast-util-gfm": "^2.0.2",
|
|
"mdast-util-mdx": "^2.0.1",
|
|
"mdast-util-mdx-jsx": "^2.1.4",
|
|
"mdast-util-to-markdown": "^1.5.0",
|
|
"mdast-util-toc": "^6.1.1",
|
|
"micromark-extension-gfm": "^2.0.3",
|
|
"micromark-extension-mdxjs": "^1.0.1",
|
|
"npm-run-all": "^4.1.5",
|
|
"postcss": "catalog:",
|
|
"react-dropzone": "^14.3.8",
|
|
"react-router": "^7.13.2",
|
|
"rimraf": "^4.1.3",
|
|
"shadcn": "^3.0.0",
|
|
"shiki": "^1.1.7",
|
|
"tailwindcss": "catalog:",
|
|
"tsconfig": "workspace:*",
|
|
"tsx": "catalog:",
|
|
"typescript": "catalog:",
|
|
"vite": "catalog:",
|
|
"vitest": "catalog:"
|
|
}
|
|
}
|