Harden production auth for hackathon demo.

Configure Supabase redirect URLs, disable email confirmation on the remote
project, create profile and avatar rows on signup, and route new users to
/protected when a session is returned immediately.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
2026-05-23 18:13:52 -06:00
parent 34c9dfa68b
commit f20c053db3
4 changed files with 46 additions and 7 deletions

View File

@@ -0,0 +1,28 @@
create or replace function public.handle_new_user()
returns trigger
language plpgsql
security definer
set search_path = public
as $$
begin
insert into public.profiles (id, display_name)
values (
new.id,
coalesce(new.raw_user_meta_data ->> 'display_name', split_part(new.email, '@', 1))
)
on conflict (id) do nothing;
insert into public.avatar_state (user_id)
values (new.id)
on conflict (user_id) do nothing;
return new;
end;
$$;
drop trigger if exists on_auth_user_created on auth.users;
create trigger on_auth_user_created
after insert on auth.users
for each row
execute function public.handle_new_user();