Harden production auth for hackathon demo.
Configure Supabase redirect URLs, disable email confirmation on the remote project, create profile and avatar rows on signup, and route new users to /protected when a session is returned immediately. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -30,8 +30,14 @@ file_size_limit = "50MiB"
|
||||
|
||||
[auth]
|
||||
enabled = true
|
||||
site_url = "http://127.0.0.1:3000"
|
||||
additional_redirect_urls = ["http://127.0.0.1:3000/**", "http://localhost:3000/**"]
|
||||
site_url = "https://cursor-hackathon-flame.vercel.app"
|
||||
additional_redirect_urls = [
|
||||
"http://127.0.0.1:3000/**",
|
||||
"http://localhost:3000/**",
|
||||
"https://cursor-hackathon-flame.vercel.app/**",
|
||||
"https://cursor-hackathon-*-harkamal-randhawas-projects.vercel.app/**",
|
||||
"https://cursor-hackathon-*-recentrunner-harkamal-randhawas-projects.vercel.app/**",
|
||||
]
|
||||
jwt_expiry = 3600
|
||||
enable_refresh_token_rotation = true
|
||||
refresh_token_reuse_interval = 10
|
||||
|
||||
@@ -0,0 +1,28 @@
|
||||
create or replace function public.handle_new_user()
|
||||
returns trigger
|
||||
language plpgsql
|
||||
security definer
|
||||
set search_path = public
|
||||
as $$
|
||||
begin
|
||||
insert into public.profiles (id, display_name)
|
||||
values (
|
||||
new.id,
|
||||
coalesce(new.raw_user_meta_data ->> 'display_name', split_part(new.email, '@', 1))
|
||||
)
|
||||
on conflict (id) do nothing;
|
||||
|
||||
insert into public.avatar_state (user_id)
|
||||
values (new.id)
|
||||
on conflict (user_id) do nothing;
|
||||
|
||||
return new;
|
||||
end;
|
||||
$$;
|
||||
|
||||
drop trigger if exists on_auth_user_created on auth.users;
|
||||
|
||||
create trigger on_auth_user_created
|
||||
after insert on auth.users
|
||||
for each row
|
||||
execute function public.handle_new_user();
|
||||
Reference in New Issue
Block a user