Skip to content

docs: use @supabase/server in Supabase database operations guide - #4991

Closed
mrprkr wants to merge 1 commit into
triggerdotdev:mainfrom
stunt-double:claude/compassionate-thompson-72smc5
Closed

mrprkr wants to merge 1 commit into
triggerdotdev:mainfrom
stunt-double:claude/compassionate-thompson-72smc5

Conversation

@mrprkr

@mrprkr mrprkr commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Replace manual jsonwebtoken signing and createClient with @supabase/server core primitives: verifyCredentials + createContextClient for the user-scoped insert example, and createAdminClient for the admin example.

✅ Checklist

  • [ -] I have followed every step in the contributing guide
  • [-] The PR title follows the convention. (docs only)
  • [-] I ran and tested the code works (docs only)

Testing

Testing

Typechecked both task snippets in strict mode against @supabase/server@1.9.0, @supabase/supabase-js and @trigger.dev/sdk. Not yet run against a live Supabase project.


Changelog

Updated the Supabase database operations guide to use @supabase/server:

  • Insert example: verifies the user's access token with verifyCredentials and queries with a user-scoped createContextClient (RLS applies), replacing manual jsonwebtoken signing with the legacy JWT secret.
  • Update example: uses createAdminClient with SUPABASE_SECRET_KEY instead of the service role key.
  • Added installation, environment variable and prerequisite notes (new API keys and JWT signing keys required), plus a note on access token expiry.

Replace manual jsonwebtoken signing and createClient with @supabase/server
core primitives: verifyCredentials + createContextClient for the
user-scoped insert example, and createAdminClient for the admin example.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JGxYWHGbdiQ1BwXWY92dJ4
@changeset-bot

changeset-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: e34510b

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Hi @mrprkr, thanks for your interest in contributing!

This project requires that pull request authors are vouched, and you are not in the list of vouched users.

This PR will be closed automatically. See https://github.com/triggerdotdev/trigger.dev/blob/main/CONTRIBUTING.md for more details.

@github-actions github-actions Bot closed this Oct 1, 2026

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 4 potential issues.

Devin Review

Comment on lines +65 to +67
// An invalid or expired token won't succeed on retry, so abort the run
if (authError) {
throw new AbortTaskRunError(`Invalid access token: ${authError.message}`);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 Temporary JWKS failures permanently abort inserts

When the JWKS endpoint temporarily fails, verifyCredentials returns an error that AbortTaskRunError treats as an invalid token. The insert never retries after the endpoint recovers.

Learn more

verifyCredentials returns errors for both bad tokens and server-side failures. In particular, fetching the remote JWKS can fail and returns an authentication error with HTTP status 500. AbortTaskRunError ends the Trigger.dev run without retries, so transient verification failures permanently prevent a valid user's insert.

Example: A valid user token arrives while the Supabase JWKS endpoint is unavailable for 30 seconds. Verification returns a 500 fetch error. The task aborts, and the insert never runs even after the endpoint recovers.

Recommended fix: Branch on authError.status or its error code. Abort only for permanent credential failures; throw a regular error for retryable JWKS failures. Consider distinguishing expired tokens from other permanent errors when deciding whether retries are useful.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines +94 to +98
<Note>
Supabase access tokens are short-lived (1 hour by default). If a run is delayed or retried after
the token has expired, verification will fail. For long-running or delayed work, use the admin
client shown in the next example and pass the user ID in the payload instead.
</Note>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Authentication link retains legacy setup

The Supabase authentication guide linked immediately below the new example still teaches HS256 signing and legacy keys. Readers following that link get setup instructions that conflict with this example's prerequisites.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

### Prerequisites

- A [Supabase account](https://supabase.com/dashboard/) and a project set up
- Your project uses the new [API keys](https://supabase.com/docs/guides/api/api-keys) (`sb_publishable_...` / `sb_secret_...`) and [JWT signing keys](https://supabase.com/docs/guides/auth/signing-keys). `@supabase/server` does not accept legacy `anon` / `service_role` keys or HS256-signed JWTs.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 HS256 prerequisite overstates package limitations

@supabase/server 1.9.0 supports HS256 verification against a matching inline JWK. The default remote JWKS setup cannot verify legacy-secret tokens, but the blanket claim rules out a supported configuration.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines +167 to +169
// Create an admin Supabase client using SUPABASE_URL and SUPABASE_SECRET_KEY
// 'Database' supplies the type definitions to supabase-js
const supabase = createAdminClient<Database>();

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟥 Unverified user IDs allow subscription changes

When a caller supplies another user's ID, createAdminClient updates that user's subscription without checking the caller's identity. Its secret key bypasses RLS, so a triggerable task can change any user's plan.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: 72e4af7d-cd6a-41e2-88da-478b8b1a66cd

📥 Commits

Reviewing files that changed from the base of the PR and between c3b0a24 and e34510b.

📒 Files selected for processing (1)
  • docs/guides/examples/supabase-database-operations.mdx
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant