Files
supabase/apps
Claude 2e8f0f91a1 feat(ui-library): bundle the mcp-server-compute block before pushing
The `node` Compute runtime installs nothing server-side: `supabase compute
push` uploads the source directory exactly as it stands. The block handled
that by telling the user to `npm install` and ship `node_modules` in the
upload, which is a vendored dependency tree in the archive and an install
step to remember on every machine that pushes.

Bundle instead. `npm run build` runs `build.mjs`, which esbuilds `main.ts`
into `dist/index.mjs` as one ESM bundle with its dependencies inlined, and
`[compute.mcp-server] source = "supabase/compute/mcp-server/dist"` points the
push at that directory. The uploaded archive is two files and needs no
`node_modules`.

`index.mjs` is deliberate, not incidental: it is the entrypoint name the
`node` runtime looks for, so the bundle satisfies the contract directly. The
build also writes a `dist/package.json` so a push with no `runtime` recorded
still classifies as `node` rather than falling back to the `deno` default;
pinning `runtime` in config.toml stays the documented path.

`deploy` runs the build and the push together and forwards `--project-ref`.
Docs frame it as the two commands in sequence locally, and the same pair in
CI as the setup to aim for. `dist/` is git-ignored.

Left unminified on purpose: a public instance has 50 seconds to accept
connections and parsing this bundle is a few milliseconds of that, so the
trade buys nothing, while readable frames in `supabase compute logs` are what
makes a failed request diagnosable.

Verified by building and booting the output with no `node_modules` present:
default export carries a `fetch` function, RFC 9728 metadata answers `200`
with the `/compute/v1/mcp-server` resource URL, an unauthenticated `POST /`
answers `401` with the `resource_metadata` challenge, and
`MCP_AUTHORIZATION_SERVER` still overrides `authorization_servers`. Bundle is
1.76 MB and cold start (import to listening) is ~135 ms. `tsc --noEmit` clean.

The `public/r` artifacts are regenerated by hand and have not been checked
against a real `pnpm build:registry`.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LbcCtAHAHnTCXNJGFfEcQF
2026-09-16 08:54:05 +00:00
..