mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 01:45:10 +03:00
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix. Complete App configurations produce the same auth options as before. ## What is the current behavior? Without the docs GitHub App private key, two things fail for a contributor: - `pnpm run embeddings` aborts before doing any work. The lint warnings source throws, and every source shares one `Promise.all` in [`fetchAllSources()`](https://github.com/supabase/supabase/blob/master/apps/docs/scripts/search/sources/index.ts). - `pnpm --filter docs build` exits 1 in prebuild, so the `npm run build` pre-flight CONTRIBUTING.md asks for cannot run either: ``` Error: DOCS_GITHUB_APP_PRIVATE_KEY environment variable is required at octokit (apps/docs/lib/octokit.ts:21:13) at fetchAiSkills (apps/docs/scripts/federated-content/fetch-federated-content.ts:258:36) ``` Both read public content, so this is a rate-limit guard rather than access control: App auth landed in #43015 because unauthenticated calls (60 req/hr per IP) went flaky on shared runners. ## What is the new behavior? `apps/docs/lib/octokit.auth.ts` adds one rung below the App: a token from `GH_TOKEN`, then `GITHUB_TOKEN` (the precedence [`gh help environment`](https://cli.github.com/manual/gh_help_environment) documents), so `export GH_TOKEN=$(gh auth token)` is enough to build locally. Still authenticated, so #43015's fix holds, and still an authenticated Octokit client, so #44274 holds. A partially configured App is now an error naming the missing vars, rather than falling through to a token. Used by the lint warnings loader and `lib/octokit.ts`. The two token vars are declared in `apps/docs/turbo.jsonc` for `turbo/no-undeclared-env-vars`. ## Additional context With only `GH_TOKEN` set, `turbo run build --filter=docs --force` passes 4/4 and search-index source loading completes. `pnpm test` passes (20 files, 164 tests), and `tsc --noEmit` plus `pnpm run lint` match `origin/master`. For a complete App config the auth options are identical to before. Happy to post the fuller verification as a comment. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added flexible GitHub authentication for documentation services, supporting GitHub App credentials or personal access tokens. - GitHub App authentication is preferred when fully configured, with token-based fallback when unavailable. - Added support for both `GH_TOKEN` and `GITHUB_TOKEN`, with clear precedence rules. - **Bug Fixes** - Improved configuration validation with clear errors for missing or incomplete authentication settings. - Standardized authentication across GitHub content and lint-warning retrieval. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
82 lines
2.8 KiB
JSON
82 lines
2.8 KiB
JSON
{
|
|
"$schema": "./../../node_modules/turbo/schema.json",
|
|
"extends": ["//"],
|
|
"tasks": {
|
|
"codegen:examples": {
|
|
"inputs": ["../../examples/**"],
|
|
"outputs": ["examples/**"],
|
|
},
|
|
"codegen:references": {
|
|
"inputs": ["spec/**"],
|
|
"outputs": ["features/docs/generated/**"],
|
|
},
|
|
// Generates the guide/reference .md files and manifest.json under public/markdown/.
|
|
// Declaring outputs lets Turbo restore these artifacts on a cache hit; without it a
|
|
// cached run would skip the script and leave the generated markdown missing for `next build`.
|
|
"build:markdown": {
|
|
"outputs": ["public/markdown/**", "public/markdown/manifest.json"],
|
|
},
|
|
"test": {
|
|
// Lets the smoke tests target a preview deploy or localhost instead of production.
|
|
"env": ["DOCS_SMOKE_URL"],
|
|
},
|
|
"build": {
|
|
"dependsOn": ["^build", "codegen:examples", "codegen:references", "build:markdown"],
|
|
"env": [
|
|
"ANALYZE",
|
|
"NEXT_PUBLIC_SUPABASE_URL",
|
|
"NEXT_PUBLIC_SUPABASE_ANON_KEY",
|
|
"NEXT_PUBLIC_MISC_URL",
|
|
"NEXT_PUBLIC_MISC_ANON_KEY",
|
|
"NEXT_PUBLIC_MARKETPLACE_API_URL",
|
|
"NEXT_PUBLIC_MARKETPLACE_PUBLISHABLE_KEY",
|
|
"NODE_ENV",
|
|
"NEXT_PUBLIC_API_URL",
|
|
"NEXT_PUBLIC_BASE_PATH",
|
|
"NEXT_PUBLIC_SITE_URL",
|
|
"NEXT_PUBLIC_DEV_AUTH_PAGE",
|
|
"NEXT_PUBLIC_IS_PLATFORM",
|
|
"NEXT_PUBLIC_SENTRY_DSN",
|
|
"NEXT_PUBLIC_VERCEL_ENV",
|
|
"NEXT_PUBLIC_VERCEL_GIT_COMMIT_SHA",
|
|
"VERCEL",
|
|
"VERCEL_ENV",
|
|
"VERCEL_GIT_COMMIT_SHA",
|
|
"VERCEL_URL",
|
|
// These envs are used in the packages
|
|
"NEXT_PUBLIC_STORAGE_KEY",
|
|
"NEXT_PUBLIC_AUTH_DEBUG_KEY",
|
|
"NEXT_PUBLIC_AUTH_PERSISTED_KEY",
|
|
"NEXT_PUBLIC_AUTH_NAVIGATOR_LOCK_KEY",
|
|
"NEXT_PUBLIC_AUTH_DETECT_SESSION_IN_URL",
|
|
"NEXT_PUBLIC_GOOGLE_TAG_MANAGER_ID",
|
|
"NEXT_PUBLIC_GOTRUE_URL",
|
|
"NEXT_PUBLIC_SUPABASE_ANON_KEY",
|
|
"NEXT_PUBLIC_MCP_URL",
|
|
// These envs are technically passthrough env vars because they're only used on the server side of Nextjs
|
|
"ASSET_CDN_S3_ENDPOINT",
|
|
"AWS_ACCESS_KEY_ID",
|
|
"AWS_SECRET_ACCESS_KEY",
|
|
"CI",
|
|
"DOCS_GITHUB_APP_ID",
|
|
"DOCS_GITHUB_APP_INSTALLATION_ID",
|
|
"DOCS_GITHUB_APP_PRIVATE_KEY",
|
|
"DOCS_REVALIDATION_KEYS",
|
|
"DOCS_REVALIDATION_OVERRIDE_KEYS",
|
|
"ENABLED_FEATURES_OVERRIDE_DISABLE_ALL",
|
|
"GH_TOKEN",
|
|
"GITHUB_ACTIONS",
|
|
"GITHUB_TOKEN",
|
|
"FORCE_ASSET_CDN",
|
|
"LOGFLARE_INGESTION_API_KEY",
|
|
"LOGFLARE_SOURCE_TOKEN",
|
|
"OPENAI_API_KEY",
|
|
"SITE_NAME",
|
|
"SUPABASE_SECRET_KEY",
|
|
],
|
|
"inputs": ["$TURBO_DEFAULT$"],
|
|
"outputs": [".next/**", "!.next/cache/**"],
|
|
},
|
|
},
|
|
}
|