mirror of
https://github.com/supabase/supabase.git
synced 2026-10-10 03:45:06 +03:00
## What kind of change does this PR introduce? Feature / abuse-prevention update. Resolves DEPR-198. ## What is the current behaviour? Free projects using Supabase's built-in email service can edit raw Auth email template subjects and HTML in Studio. That is the risky cohort this project is trying to constrain. ## What is the new behaviour? ### Template editing restrictions For free projects using Supabase's built-in email service, Studio keeps Auth email templates viewable and previewable but disables subject/body editing and saving. Editing is unlocked by setting up Custom SMTP, configuring a send-email hook, or upgrading to a paid plan. **Grandfathering:** projects created before `2026-06-01T00:00:00Z` (the platform enforcement cutoff) are exempt; their editing UI stays unlocked. This mirrors `FREE_TIER_TEMPLATE_BLOCK_CUTOFF_DATE` in the platform PR exactly. | After | | --- | | <img width="1024" height="759" alt="Emails Authentication Fizz Test Supabase-173BB09B-0FB9-4133-8202-9E310DDB347A" src="https://github.com/user-attachments/assets/c966212d-ed0c-443b-8197-440cc2937ef6" /> | | <img width="1024" height="759" alt="Emails Authentication Fizz Test Supabase-CD5845EB-0E45-4779-8989-44E775B2411A" src="https://github.com/user-attachments/assets/055a64d6-b5e8-4d37-a261-6e280f04536a" /> | ### Warning dialogs on transitions that reset templates Two flows now surface a warning before the user commits to a state change that resets their custom email templates to defaults: 1. **Disabling custom SMTP** (SMTP settings page): a confirmation dialog warns that templates will be reset to defaults and the email rate limit reduced to 2 per hour. On confirm, Studio resets all 13 templates via the existing per-template reset endpoint (`Promise.allSettled`). The "won't be able to edit" sentence is shown only for post-cutoff projects; grandfathered projects skip it. The corresponding server-side enforcement is in the Platform PR: https://github.com/supabase/platform/pull/33129 2. **Downgrading to the Free plan** (billing settings): an admonition in the existing downgrade confirmation modal warns that custom templates will be reset to defaults and won't be editable without custom SMTP. The admonition is shown only when the org has at least one post-cutoff project; orgs whose projects are all grandfathered skip it. | Custom SMTP | Downgrading | | --- | --- | | <img width="862" height="586" alt="66764" src="https://github.com/user-attachments/assets/6470c8a6-2f79-40a5-ad3b-bfe5b0ba9c54" /> | <img width="1268" height="1552" alt="CleanShot 2026-05-22 at 17 28 37@2x-FEB1901E-38E6-42DF-8C27-0A036D8A1B94" src="https://github.com/user-attachments/assets/e8caa9e6-c3ed-4787-b771-af77a43eb854" /> | ### Informational admonition when enabling SMTP When a user enables custom SMTP for the first time, a sandwiched admonition above the save footer informs them that the email rate limit will be increased to 30 per hour and can be adjusted. _This is just a minor cosmetic change, unrelated to the email template disabling. Sorry._ | Before | After | | --- | --- | | <img width="1024" height="759" alt="Emails Authentication Chisel Toolshed Supabase-54317D18-803C-4A58-8211-2359355D083B" src="https://github.com/user-attachments/assets/29eff649-02dc-40f3-a379-0b4d484a76c7" /> | <img width="1024" height="759" alt="Emails Authentication Chisel Toolshed Supabase-9E12399E-E9FB-4F9A-B029-A08008EA4B50" src="https://github.com/user-attachments/assets/e542ed86-4da6-407e-8293-0f4c0f071e18" /> | ## How to test All existing projects pre-date the enforcement cutoff (`2026-06-01T00:00:00Z`) and are grandfathered, so the restriction UI won't appear by default. To force the restricted state locally, back-date the cutoff in one file: In `apps/studio/components/interfaces/Auth/EmailTemplates/EmailTemplates.utils.ts`, temporarily change: ```ts export const FREE_TIER_TEMPLATE_BLOCK_CUTOFF_DATE = '2026-06-01T00:00:00Z' ``` to: ```ts export const FREE_TIER_TEMPLATE_BLOCK_CUTOFF_DATE = '2025-01-01T00:00:00Z' ``` Revert before committing. With the cutoff back-dated, use a free-plan project and: - **Template restriction + admonition:** navigate to Authentication > Emails with no custom SMTP configured. Subject/body fields should be read-only and the "Set up SMTP" admonition should appear, with its dropdown offering upgrade and send-email hook options. - **SMTP disable warning:** enable custom SMTP on a project, then disable it via Authentication > SMTP Settings. The confirmation dialog should warn that templates will reset to defaults and that editing will be restricted after disabling. - **Downgrade warning:** in billing settings, initiate a downgrade to the Free plan. The downgrade modal should include an admonition warning about template reset and restricted editing (only if the org has at least one post-cutoff project). ## Additional context The default Auth email template copy was also improved across docs, examples, and UI library snippets (separate prior commits). The per-template reset button (`ResetTemplateDialog`) was migrated to the async `AlertDialogAction` pattern introduced in #45960; the dialog stays open and shows a loading state while the reset is in-flight, closes on success, and stays open on error. Closes PRODSEC-183 --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com> Co-authored-by: Stephen Morgan <stephen@doublethink.co.nz>
282 lines
10 KiB
Plaintext
282 lines
10 KiB
Plaintext
---
|
|
title: 'Build a User Management App with Next.js'
|
|
description: 'Learn how to use Supabase in your Next.js App.'
|
|
---
|
|
|
|
<$Partial path="uiLibCta.mdx" />
|
|
<$Partial path="quickstart_intro.mdx" />
|
|
|
|

|
|
|
|
<Admonition type="note">
|
|
|
|
If you get stuck while working through this guide, you can find the [full example on GitHub](https://github.com/supabase/supabase/tree/master/examples/user-management/nextjs-user-management).
|
|
|
|
</Admonition>
|
|
|
|
<$Partial path="project_setup.mdx" variables={{ "framework": "nextjs", "tab": "frameworks" }} />
|
|
|
|
## Building the app
|
|
|
|
Start building the Next.js app from scratch.
|
|
|
|
### Initialize a Next.js app
|
|
|
|
Use [`create-next-app`](https://nextjs.org/docs/getting-started) to initialize an app called `supabase-nextjs`:
|
|
|
|
```bash
|
|
npx create-next-app@latest --ts --use-npm supabase-nextjs
|
|
cd supabase-nextjs
|
|
```
|
|
|
|
Install [supabase-js](https://github.com/supabase/supabase-js):
|
|
|
|
```bash
|
|
npm install @supabase/supabase-js
|
|
```
|
|
|
|
Save the environment variables in a `.env.local` file at the root of the project, and paste the API URL and the key that you copied [earlier](#get-api-details).
|
|
|
|
The application exposes these variables in the browser, and that's fine as Supabase enables [Row Level Security](/docs/guides/database/postgres/row-level-security) by default on all tables.
|
|
|
|
```bash .env.local
|
|
NEXT_PUBLIC_SUPABASE_URL=YOUR_SUPABASE_URL
|
|
NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY=YOUR_SUPABASE_PUBLISHABLE_KEY
|
|
```
|
|
|
|
### App styling (optional)
|
|
|
|
An optional step is to update the CSS file `app/globals.css` to make the app look better.
|
|
You can find the full contents of this file [in the example repository](https://raw.githubusercontent.com/supabase/supabase/master/examples/user-management/nextjs-user-management/app/globals.css).
|
|
|
|
### Supabase Server-Side Auth package
|
|
|
|
Next.js is a versatile framework offering pre-rendering at build time (SSG), server-side rendering at request time (SSR), API routes, and proxy edge-functions.
|
|
|
|
To better integrate with the framework, we've created the `@supabase/ssr` package for Server-Side Auth. It has all the functionalities to quickly configure your Supabase project to use cookies for storing user sessions. Read the [Next.js Server-Side Auth guide](/docs/guides/auth/server-side/creating-a-client?queryGroups=package-manager&package-manager=npm&queryGroups=framework&framework=nextjs) for more information.
|
|
|
|
Install the package for Next.js.
|
|
|
|
```bash
|
|
npm install @supabase/ssr
|
|
```
|
|
|
|
### Supabase utilities
|
|
|
|
There are two different types of clients in Supabase:
|
|
|
|
1. **Client Component client** - To access Supabase from Client Components, which run in the browser.
|
|
2. **Server Component client** - To access Supabase from Server Components, Server Actions, and Route Handlers, which run only on the server.
|
|
|
|
We recommend creating the following utilities files for creating clients, and organize them within `lib/supabase` at the root of the project.
|
|
|
|
Create a `client.ts` and a `server.ts` with the following code for client-side Supabase and server-side Supabase, respectively.
|
|
|
|
<$CodeTabs>
|
|
|
|
<$CodeSample
|
|
path="/user-management/nextjs-user-management/lib/supabase/client.ts"
|
|
lines={[[1, -1]]}
|
|
meta="name=lib/supabase/client.ts"
|
|
/>
|
|
|
|
<$CodeSample
|
|
path="/user-management/nextjs-user-management/lib/supabase/server.ts"
|
|
lines={[[1, -1]]}
|
|
meta="name=lib/supabase/server.ts"
|
|
/>
|
|
|
|
</$CodeTabs>
|
|
|
|
### Next.js proxy
|
|
|
|
Since Server Components can't write cookies, you need [Proxy](https://nextjs.org/docs/app/getting-started/proxy) to refresh expired Auth tokens and store them.
|
|
|
|
You accomplish this by:
|
|
|
|
- Refreshing the Auth token with the call to `supabase.auth.getClaims`.
|
|
- Passing the refreshed Auth token to Server Components through `request.cookies.set`, so they don't attempt to refresh the same token themselves.
|
|
- Passing the refreshed Auth token to the browser, so it replaces the old token. This is done with `response.cookies.set`.
|
|
|
|
You could also add a matcher, so that the Proxy only runs on routes that access Supabase. For more information, read [the Next.js matcher documentation](https://nextjs.org/docs/app/api-reference/file-conventions/proxy#matcher).
|
|
|
|
<Admonition type="danger">
|
|
|
|
Be careful when protecting pages. The server gets the user session from the cookies, which anyone can spoof.
|
|
|
|
</Admonition>
|
|
|
|
<$Partial path="auth_methods.mdx" />
|
|
|
|
Create a `proxy.ts` file at the project root and another one within the `lib/supabase` folder. The `lib/supabase` file contains the logic for updating the session. The `proxy.ts` file uses this, which is a Next.js convention.
|
|
|
|
<$CodeTabs>
|
|
|
|
<$CodeSample
|
|
path="/user-management/nextjs-user-management/proxy.ts"
|
|
lines={[[1, -1]]}
|
|
meta="name=proxy.ts"
|
|
/>
|
|
|
|
<$CodeSample
|
|
path="/user-management/nextjs-user-management/lib/supabase/proxy.ts"
|
|
lines={[[1, -1]]}
|
|
meta="name=lib/supabase/proxy.ts"
|
|
/>
|
|
|
|
</$CodeTabs>
|
|
|
|
### Set up a login page
|
|
|
|
#### Login and signup form
|
|
|
|
To add login/signup page for your application, create a new folder named `login`, containing a `page.tsx` file with the following code for a login/signup form:
|
|
|
|
<$CodeTabs>
|
|
|
|
<$CodeSample
|
|
path="/user-management/nextjs-user-management/app/login/page.tsx"
|
|
lines={[[1, -1]]}
|
|
meta="name=app/login/page.tsx"
|
|
/>
|
|
|
|
</$CodeTabs>
|
|
|
|
Create the login/signup actions to hook up the form to the function which does the following:
|
|
|
|
- Retrieve the user's information.
|
|
- Send that information to Supabase as a signup request, which in turns sends a confirmation email. It uses [Magic Links](/docs/guides/auth/auth-email-passwordless#with-magic-link), so users can sign in with their email without using passwords.
|
|
- Handle any error that arises.
|
|
|
|
Create the `action.ts` file in the `app/login` folder, which contains the login and signup functions and the `error/page.tsx` file, which displays an error message if the login or signup fails.
|
|
|
|
<$CodeTabs>
|
|
|
|
<$CodeSample
|
|
path="/user-management/nextjs-user-management/app/login/actions.ts"
|
|
lines={[[1, -1]]}
|
|
meta="name=app/login/actions.ts"
|
|
/>
|
|
|
|
<$CodeSample
|
|
path="/user-management/nextjs-user-management/app/error/page.tsx"
|
|
lines={[[1, -1]]}
|
|
meta="name=app/error/page.tsx"
|
|
/>
|
|
|
|
</$CodeTabs>
|
|
|
|
<Admonition type="caution">
|
|
|
|
The `cookies` method is called before any calls to Supabase, which takes fetch calls out of Next.js's caching. This is important for authenticated data fetches, to ensure that users get access only to their own data.
|
|
|
|
Read the Next.js docs to learn more about [opting out of data caching](https://nextjs.org/docs/app/building-your-application/data-fetching/fetching-caching-and-revalidating#opting-out-of-data-caching).
|
|
|
|
</Admonition>
|
|
|
|
#### Email template
|
|
|
|
Before proceeding, change the email template to support a server-side authentication flow that sends a token hash:
|
|
|
|
- Go to the [Auth templates](/dashboard/project/_/auth/templates) page in your dashboard.
|
|
- Select the **Confirm signup** template.
|
|
- Change `{{ .ConfirmationURL }}` to `{{ .SiteURL }}/auth/confirm?token_hash={{ .TokenHash }}&type=email`.
|
|
|
|
<Admonition type="tip" title="Did you know?">
|
|
|
|
You can customize other emails sent out to new users, including the email's looks, content, and query parameters from [the **Authentication > Email**](/dashboard/project/_/auth/templates) section of the Dashboard.
|
|
|
|
</Admonition>
|
|
|
|
#### Confirmation endpoint
|
|
|
|
As you are working in a server-side rendering (SSR) environment, you need to create a server endpoint responsible for exchanging the `token_hash` for a session.
|
|
|
|
The code performs the following steps:
|
|
|
|
- Retrieves the code sent back from the Supabase Auth server using the `token_hash` query parameter.
|
|
- Exchanges this code for a session, which you store in your chosen storage mechanism (in this case, cookies).
|
|
- Finally, redirects the user to the `account` page.
|
|
|
|
<$CodeSample
|
|
path="/user-management/nextjs-user-management/app/auth/confirm/route.ts"
|
|
lines={[[1, -1]]}
|
|
meta="name=app/auth/confirm/route.ts"
|
|
/>
|
|
|
|
### Account page
|
|
|
|
After a user signs in, they need a way to edit their profile details and manage their accounts.
|
|
|
|
Create a new component for that called `AccountForm` within the `app/account` folder.
|
|
|
|
<$CodeSample
|
|
path="/user-management/nextjs-user-management/app/account/account-form.tsx"
|
|
lines={[[1, 4], [7, 78], [88, 89], [99, -1]]}
|
|
meta="name=app/account/account-form.tsx"
|
|
/>
|
|
|
|
Create an account page for the `AccountForm` component you just created
|
|
|
|
<$CodeSample
|
|
path="/user-management/nextjs-user-management/app/account/page.tsx"
|
|
lines={[[1, -1]]}
|
|
meta="name=app/account/page.tsx"
|
|
/>
|
|
|
|
### Sign out
|
|
|
|
Create a route handler to handle the sign out from the server side, making sure to check if the user is logged in first.
|
|
|
|
<$CodeSample
|
|
path="/user-management/nextjs-user-management/app/auth/signout/route.ts"
|
|
lines={[[1, -1]]}
|
|
meta="name=app/auth/signout/route.ts"
|
|
/>
|
|
|
|
## Profile photos
|
|
|
|
Next, add a way for users to upload a profile photo. Supabase configures every project with [Storage](/docs/guides/storage) for managing large files like photos and videos.
|
|
|
|
### Create an upload widget
|
|
|
|
Start by creating a new component:
|
|
|
|
<$CodeSample
|
|
path="/user-management/nextjs-user-management/app/account/avatar.tsx"
|
|
lines={[[1, -1]]}
|
|
meta="name=app/account/avatar.tsx"
|
|
/>
|
|
|
|
### Update the account form
|
|
|
|
With the Avatar component created, update `app/account/account-form.tsx` to include it:
|
|
|
|
<$CodeSample
|
|
path="/user-management/nextjs-user-management/app/account/account-form.tsx"
|
|
lines={[[1, -1]]}
|
|
meta="name=app/account/account-form.tsx"
|
|
/>
|
|
|
|
### Launch
|
|
|
|
With all the pages, route handlers, and components in place, run the following in a terminal window:
|
|
|
|
```bash
|
|
npm run dev
|
|
```
|
|
|
|
And then open the browser to [localhost:3000/login](http://localhost:3000/login) and you should see the completed app.
|
|
|
|
When you enter your email and password, you will receive an email with the title **Confirm your email**. Congrats 🎉!!!
|
|
|
|
At this stage you have a fully functional application!
|
|
|
|
## See also
|
|
|
|
- See the complete [example on GitHub](https://github.com/supabase/supabase/tree/master/examples/user-management/nextjs-user-management) and deploy it to Vercel
|
|
- [Build a Twitter Clone with the Next.js App Router and Supabase - free egghead course](https://egghead.io/courses/build-a-twitter-clone-with-the-next-js-app-router-and-supabase-19bebadb)
|
|
- Explore the [pre-built Auth components](/ui/docs/nextjs/password-based-auth)
|
|
- Explore the [Supabase Cache Helpers](https://github.com/psteinroe/supabase-cache-helpers)
|
|
- See the [Next.js Subscription Payments Starter](https://github.com/vercel/nextjs-subscription-payments) template on GitHub
|