mirror of
https://github.com/supabase/supabase.git
synced 2026-10-10 20:05:06 +03:00
Splits the Edge Function secrets page into two sections so reserved Supabase env vars are always visible, even on new projects without any user secrets created. <img width="1605" height="1006" alt="Screenshot 2026-04-29 at 12 20 43 PM" src="https://github.com/user-attachments/assets/fc74f10e-557d-45bb-b0f0-66a706a9facb" /> **Added:** - `DefaultEdgeFunctionSecrets` component — a read-only reference list (Name + Description) of every `SUPABASE_*`, `SB_*`, and `DENO_*` env var available in every project, sourced from [the docs](https://supabase.com/docs/guides/functions/secrets#default-secrets) - `isInternalEdgeFunctionSecret` helper used to filter the custom secrets table **Changed:** - The custom secrets section now renders first (more actionable), with the educational default secrets section below it - Custom secrets table now filters out anything matching `SUPABASE_*` or any of the hardcoded default names **Removed:** - `isReservedSecret` regex check + its tooltip branches in `EdgeFunctionSecret.tsx` — dead code now that the custom table never receives an internal secret Addresses [FE-3096](https://linear.app/supabase/issue/FE-3096/split-edge-function-secrets-into-internal-and-user-defined-views). ## To test - Open `/project/_/functions/secrets` on a fresh project (no custom secrets) - "Default secrets" section is visible and lists all 9 env vars with descriptions - "Custom secrets" section shows the empty state - Create a custom secret — appears in the Custom section, not the Default section - Edit/delete dropdown still works on custom secrets - Search input only filters the custom secrets table <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a "Default secrets" section showing built-in edge-function secrets with names, descriptions, and a "Deprecated" badge where applicable. * Secret names are clickable to copy to clipboard with a success notification; secret names/values use inline code styling. * UI now separates "Custom secrets" and "Default secrets" with distinct empty states. * **Bug Fixes** * Edit/Delete controls reflect actual permission state (no longer disabled for default/reserved secrets). * **Tests** * Added tests for default-secret detection and visibility rules. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
129 lines
4.1 KiB
TypeScript
129 lines
4.1 KiB
TypeScript
import { PermissionAction } from '@supabase/shared-types/out/constants'
|
|
import { Edit2, MoreVertical, Trash } from 'lucide-react'
|
|
import { toast } from 'sonner'
|
|
import {
|
|
Button,
|
|
copyToClipboard,
|
|
DropdownMenu,
|
|
DropdownMenuContent,
|
|
DropdownMenuItem,
|
|
DropdownMenuSeparator,
|
|
DropdownMenuTrigger,
|
|
TableCell,
|
|
TableRow,
|
|
Tooltip,
|
|
TooltipContent,
|
|
TooltipTrigger,
|
|
} from 'ui'
|
|
import { TimestampInfo } from 'ui-patterns'
|
|
|
|
import { ButtonTooltip } from '@/components/ui/ButtonTooltip'
|
|
import type { ProjectSecret } from '@/data/secrets/secrets-query'
|
|
import { useAsyncCheckPermissions } from '@/hooks/misc/useCheckPermissions'
|
|
|
|
interface EdgeFunctionSecretProps {
|
|
secret: ProjectSecret
|
|
onSelectDelete: () => void
|
|
onSelectEdit: () => void
|
|
}
|
|
|
|
const EdgeFunctionSecret = ({ secret, onSelectEdit, onSelectDelete }: EdgeFunctionSecretProps) => {
|
|
const { can: canUpdateSecrets } = useAsyncCheckPermissions(PermissionAction.SECRETS_WRITE, '*')
|
|
|
|
return (
|
|
<TableRow>
|
|
<TableCell>
|
|
<Tooltip>
|
|
<TooltipTrigger
|
|
onClick={() => {
|
|
copyToClipboard(secret.name)
|
|
toast.success(`Copied ${secret.name}`)
|
|
}}
|
|
>
|
|
<p className="truncate py-1">
|
|
<code className="text-code-inline">{secret.name}</code>
|
|
</p>
|
|
</TooltipTrigger>
|
|
<TooltipContent side="bottom">Click to copy</TooltipContent>
|
|
</Tooltip>
|
|
</TableCell>
|
|
<TableCell>
|
|
<p className="max-w-96 truncate" title={secret.value}>
|
|
<code className="text-code-inline !text-foreground-light">{secret.value}</code>
|
|
</p>
|
|
</TableCell>
|
|
<TableCell>
|
|
{!!secret.updated_at ? (
|
|
<TimestampInfo
|
|
displayAs="utc"
|
|
utcTimestamp={secret.updated_at}
|
|
labelFormat="DD MMM YYYY HH:mm:ss (ZZ)"
|
|
className="!text-sm text-foreground-light whitespace-nowrap"
|
|
/>
|
|
) : (
|
|
'-'
|
|
)}
|
|
</TableCell>
|
|
<TableCell>
|
|
<div className="flex items-center justify-end">
|
|
<DropdownMenu>
|
|
<DropdownMenuTrigger asChild>
|
|
<Button
|
|
aria-label="More options"
|
|
type="default"
|
|
className="px-1"
|
|
icon={<MoreVertical />}
|
|
/>
|
|
</DropdownMenuTrigger>
|
|
<DropdownMenuContent side="bottom" align="end" className="w-52">
|
|
<DropdownMenuItem asChild>
|
|
<ButtonTooltip
|
|
type="text"
|
|
icon={<Edit2 size={14} />}
|
|
className="w-full justify-start group text-inherit"
|
|
disabled={!canUpdateSecrets}
|
|
onClick={() => onSelectEdit()}
|
|
tooltip={{
|
|
content: {
|
|
side: 'bottom',
|
|
text: !canUpdateSecrets
|
|
? 'You need additional permissions to edit edge function secrets'
|
|
: undefined,
|
|
},
|
|
}}
|
|
>
|
|
Edit secret
|
|
</ButtonTooltip>
|
|
</DropdownMenuItem>
|
|
|
|
<DropdownMenuSeparator />
|
|
|
|
<DropdownMenuItem asChild>
|
|
<ButtonTooltip
|
|
type="text"
|
|
icon={<Trash size={14} className="group-[&:not(:disabled)]:text-destructive" />}
|
|
className="w-full justify-start group text-inherit"
|
|
disabled={!canUpdateSecrets}
|
|
onClick={() => onSelectDelete()}
|
|
tooltip={{
|
|
content: {
|
|
side: 'bottom',
|
|
text: !canUpdateSecrets
|
|
? 'You need additional permissions to delete edge function secrets'
|
|
: undefined,
|
|
},
|
|
}}
|
|
>
|
|
Delete secret
|
|
</ButtonTooltip>
|
|
</DropdownMenuItem>
|
|
</DropdownMenuContent>
|
|
</DropdownMenu>
|
|
</div>
|
|
</TableCell>
|
|
</TableRow>
|
|
)
|
|
}
|
|
|
|
export default EdgeFunctionSecret
|