7 solution docs
Supabase Auth solution docs
Postgres-native auth where the database, not the API layer, is the last line of defence.
Pick Supabase Auth and all 7 land in docs/solutions/supabase-auth/, next to the rules and skills that reference them.
Every Supabase Auth doc in the registry
Tags: admin · app-router · auth · cookies · impersonation · incident-response · jwt · migration · multi-tenancy · nextjs · oauth · performance · postgres · proxy · refactor · rls · secrets · security · service-role · sessions · sign-in · supabase
Logged out after an hour: Supabase cookie refresh in the App Router
Access tokens expire hourly and Server Components cannot write cookies, so the refresh has to happen in the proxy and be returned on the same response object.
supabase · nextjs · app-router · cookies
getSession() vs getUser(): the Supabase trust trap
getSession() decodes a cookie the browser controls; getUser() verifies it with the auth server. On the server, only one of them is a security check.
supabase · auth · security · sessions
Admin impersonation on Supabase Auth, bound to one session
Supabase Auth has no "view as user". Build it from a server-side magic link plus an app_metadata marker tied to the new session id, so only that session is flagged and nobody can forge it.
supabase · auth · admin · impersonation
Migrating an app that only ever used the anon key
Tables with RLS off are public. Turn it on table by table behind a feature switch, write the policies, and fix the queries the policies break, in that order.
supabase · rls · migration · security
Show only the OAuth buttons your Supabase project has switched on
Read the public /auth/v1/settings endpoint on the server, cache it, and fail closed, so a sign-in page never shows a Google button that ends on an error page.
supabase · auth · oauth · nextjs
RLS policy patterns for multi-tenant rows
Owner-scoped, org-scoped and role-scoped policies, the with-check clause people forget, and the indexes that stop a policy from turning every read into a scan.
supabase · rls · postgres · multi-tenancy
The blast radius of a leaked Supabase service-role key
The key bypasses every policy for every table. Here is how it leaks, what an attacker gets, how to contain it, and how to make the leak impossible.
supabase · security · service-role · secrets