mirror of
https://github.com/supabase/supabase.git
synced 2026-10-09 11:25:06 +03:00
The Next pages-router build guards platform-only API routes via middleware (proxy.ts, Next 16's renamed middleware convention). TanStack Start has no middleware runtime, so that guard didn't run on the TanStack build at all. Add an equivalent global request middleware on a TanStack start instance (start.ts). On Vercel, /api/* and /_serverFn/* are rewritten to the api/server.js function which runs createStartHandler, so requestMiddleware executes server-side for every API request even though pages are a static SPA shell. Extract the shared HOSTED_SUPPORTED_API_URLS allowlist into lib/hosted-api-allowlist.ts so the Next and TanStack guards can't drift while both frameworks run in parallel.
38 lines
1.2 KiB
TypeScript
38 lines
1.2 KiB
TypeScript
// [Joshen] Allowlist of API endpoints supported in hosted (platform) mode.
|
|
// Every other /api/* route must 404 in platform mode. Shared by the Next
|
|
// middleware (proxy.ts) and the TanStack request middleware (start.ts) so
|
|
// the list can't drift between the two frameworks while both run in parallel.
|
|
export const HOSTED_SUPPORTED_API_URLS = [
|
|
'/ai/sql/generate-v4',
|
|
'/ai/sql/policy',
|
|
'/ai/feedback/rate',
|
|
'/ai/code/complete',
|
|
'/ai/sql/cron-v2',
|
|
'/ai/sql/title-v2',
|
|
'/ai/sql/filter-v1',
|
|
'/ai/onboarding/design',
|
|
'/ai/feedback/classify',
|
|
'/ai/docs',
|
|
'/ai/sql/parse-client-code',
|
|
'/get-ip-address',
|
|
'/get-utc-time',
|
|
'/get-deployment-commit',
|
|
'/check-cname',
|
|
'/edge-functions/test',
|
|
'/edge-functions/body',
|
|
'/generate-attachment-url',
|
|
'/incident-status',
|
|
'/incident-banner',
|
|
'/status-override',
|
|
'/api/integrations/stripe-sync',
|
|
'/content/graphql',
|
|
'/parse-query',
|
|
]
|
|
|
|
// `pathname` must be basePath-relative — Next's `nextUrl.pathname` already is,
|
|
// and the TanStack guard strips BASE_PATH before calling. Entries are path
|
|
// suffixes, so `endsWith` stays correct regardless.
|
|
export function isHostedSupportedApiPath(pathname: string): boolean {
|
|
return HOSTED_SUPPORTED_API_URLS.some((url) => pathname.endsWith(url))
|
|
}
|