fix(auth): treat blank session cookies as absent#1130
Conversation
Blank or whitespace-only current and legacy Supabase session cookies were treated as presented credentials, which blocked legacy fallback during migration and forced 401 on anonymous public APIs. Require a non-blank value before counting a cookie as present, and cover the edge cases in auth-tri-state tests. Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
|
This pull request has been ignored for the connected project Preview Branches by Supabase. |
|
Warning Review limit reached
Next review available in: 58 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
Summary
sb-<ref>-auth-tokencookies (including empty chunks) as absent so a still-valid legacysb-access-tokencan authenticate during migration.sb-access-tokencookies as absent so anonymous public APIs are not forced to 401.tests/auth-tri-state.test.tswith blank-presence coverage and a synthetic project-ref fixture for cookie-name resolution.Verification
npm exec vitest run tests/auth-tri-state.test.ts— 16 passednpm run verify:pr-local— running after PR openRisk and rollout
invalid→absent(or fall through to legacy when blank current + valid legacy). Non-empty invalid modern sessions still do not fall back to legacy.Clinical Governance Preflight
Notes