Files
supabase/apps
Pamela Chia 3338be76f0 fix(studio): emit sign_in on totp challenge (#49755)
The dashboard's `sign_in` event never fires when a user completes a TOTP
challenge: `SignInForm` only tracks when no MFA challenge is needed, and
the /sign-in-mfa page only tracks on mount when the assurance level is
already satisfied (OAuth/SSO returns). Sign-ins that go through the
actual MFA form were invisible to analytics, and the login audit event
was missing on the same path.

**Changed:**
- **MFA-challenged sign-ins now tracked**: `SignInMfaForm` fires
`sign_in` (reading the same `method` query param the page mount site
reads) plus the login audit event on successful TOTP verification, in
the sign-in context only. The forgot-password flow stays untracked: it
is a reset, not a sign-in.
- **Password+MFA sign-ins report `method: email`**: `SignInForm` now
passes `?method=email` when routing to /sign-in-mfa instead of falling
through to `unknown`.
- **Partner TOTP sign-ins carry their provider**: `SignInPartner` now
passes `?method=<partner>` when routing to /sign-in-mfa, matching the
raw-provider-name convention the other entry points use.
- **Join caveat documented**: the `SignInEvent` doc comment now notes
the event is captured server-side and races the identify call, so it is
not a valid funnel join key across the auth boundary.

## Linear
- fixes GROWTH-1156


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added sign-in method details to MFA redirects for email and partner
authentication, improving sign-in flow tracking.
* Added telemetry and login auditing for successful MFA sign-ins while
keeping forgot-password flows untracked.
* **Documentation**
* Clarified sign-in event tracking coverage, including OAuth providers,
server-side capture, anonymous identifiers, and the sign-in page.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-01 13:26:08 +00:00
..
2026-08-31 14:55:04 +00:00