mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 01:45:10 +03:00
When a session token is refreshed server-side, `@supabase/ssr` writes the updated JWT via Set-Cookie. If a CDN caches that response and serves it to another user, that user will be signed in as the wrong person. Adds documentation covering this in two places: - creating-a-client.mdx: brief mention with a link to the full explanation - advanced-guide.mdx: expands the existing CDN FAQ with an explanation of the risk and Cache-Control: private, no-store examples for Next.js and Nuxt Related: https://github.com/supabase/supabase-js/issues/1682 --------- Co-authored-by: Chris Chinchilla <chris.ward@supabase.io> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>