Conversation
Replace manual jsonwebtoken signing and createClient with @supabase/server core primitives: verifyCredentials + createContextClient for the user-scoped insert example, and createAdminClient for the admin example. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JGxYWHGbdiQ1BwXWY92dJ4
|
|
Hi @mrprkr, thanks for your interest in contributing! This project requires that pull request authors are vouched, and you are not in the list of vouched users. This PR will be closed automatically. See https://github.com/triggerdotdev/trigger.dev/blob/main/CONTRIBUTING.md for more details. |
| // An invalid or expired token won't succeed on retry, so abort the run | ||
| if (authError) { | ||
| throw new AbortTaskRunError(`Invalid access token: ${authError.message}`); |
There was a problem hiding this comment.
🔴 Temporary JWKS failures permanently abort inserts
When the JWKS endpoint temporarily fails, verifyCredentials returns an error that AbortTaskRunError treats as an invalid token. The insert never retries after the endpoint recovers.
Learn more
verifyCredentials returns errors for both bad tokens and server-side failures. In particular, fetching the remote JWKS can fail and returns an authentication error with HTTP status 500. AbortTaskRunError ends the Trigger.dev run without retries, so transient verification failures permanently prevent a valid user's insert.
Example: A valid user token arrives while the Supabase JWKS endpoint is unavailable for 30 seconds. Verification returns a 500 fetch error. The task aborts, and the insert never runs even after the endpoint recovers.
Recommended fix: Branch on authError.status or its error code. Abort only for permanent credential failures; throw a regular error for retryable JWKS failures. Consider distinguishing expired tokens from other permanent errors when deciding whether retries are useful.
Was this helpful? React with 👍 or 👎 to provide feedback.
| <Note> | ||
| Supabase access tokens are short-lived (1 hour by default). If a run is delayed or retried after | ||
| the token has expired, verification will fail. For long-running or delayed work, use the admin | ||
| client shown in the next example and pass the user ID in the payload instead. | ||
| </Note> |
There was a problem hiding this comment.
🔍 Authentication link retains legacy setup
The Supabase authentication guide linked immediately below the new example still teaches HS256 signing and legacy keys. Readers following that link get setup instructions that conflict with this example's prerequisites.
Was this helpful? React with 👍 or 👎 to provide feedback.
| ### Prerequisites | ||
|
|
||
| - A [Supabase account](https://supabase.com/dashboard/) and a project set up | ||
| - Your project uses the new [API keys](https://supabase.com/docs/guides/api/api-keys) (`sb_publishable_...` / `sb_secret_...`) and [JWT signing keys](https://supabase.com/docs/guides/auth/signing-keys). `@supabase/server` does not accept legacy `anon` / `service_role` keys or HS256-signed JWTs. |
There was a problem hiding this comment.
🔍 HS256 prerequisite overstates package limitations
@supabase/server 1.9.0 supports HS256 verification against a matching inline JWK. The default remote JWKS setup cannot verify legacy-secret tokens, but the blanket claim rules out a supported configuration.
Was this helpful? React with 👍 or 👎 to provide feedback.
| // Create an admin Supabase client using SUPABASE_URL and SUPABASE_SECRET_KEY | ||
| // 'Database' supplies the type definitions to supabase-js | ||
| const supabase = createAdminClient<Database>(); |
There was a problem hiding this comment.
🟥 Unverified user IDs allow subscription changes
When a caller supplies another user's ID, createAdminClient updates that user's subscription without checking the caller's identity. Its secret key bypasses RLS, so a triggerable task can change any user's plan.
Was this helpful? React with 👍 or 👎 to provide feedback.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Replace manual jsonwebtoken signing and createClient with @supabase/server core primitives: verifyCredentials + createContextClient for the user-scoped insert example, and createAdminClient for the admin example.
✅ Checklist
Testing
Testing
Typechecked both task snippets in strict mode against
@supabase/server@1.9.0,@supabase/supabase-jsand@trigger.dev/sdk. Not yet run against a live Supabase project.Changelog
Updated the Supabase database operations guide to use
@supabase/server:verifyCredentialsand queries with a user-scopedcreateContextClient(RLS applies), replacing manualjsonwebtokensigning with the legacy JWT secret.createAdminClientwithSUPABASE_SECRET_KEYinstead of the service role key.