Skip to content

Show only the sign-in providers switched on in Supabase - #45

Merged
JFrusher merged 1 commit into
mainfrom
claude/elegant-carson-5o5558
Oct 3, 2026
Merged

JFrusher merged 1 commit into
mainfrom
claude/elegant-carson-5o5558

Conversation

@JFrusher

@JFrusher JFrusher commented Oct 3, 2026

Copy link
Copy Markdown
Owner

Why

Apple isn't enabled in the hosted Supabase project yet, but its button still showed. Pressing a disabled provider sends the browser to Supabase's /authorize, which answers with a bare JSON page ({"code":400,"error_code":"validation_failed","msg":"Unsupported provider: provider is not enabled"}) on Supabase's domain. The app never sees that, so it can't explain it. Seen live for Google before it was enabled (auth log: provider is not enabled on /authorize).

What

  • suite/lib/accounts/providers.ts: enabledProviders() reads Auth's public settings (GET /auth/v1/settings with the anon key, the endpoint Supabase's docs use to check a provider is on) and returns the known providers whose external.<id> is true. It throws if the settings can't be read.
  • Login page: offers only those buttons. With none, there are no buttons and no "or" divider, just the email code. If the settings can't be read, no buttons show (with a console.warn) and the email code still works.
  • The invite hint mentions Apple's Share My Email only when the Apple button is shown.
  • docs/SELF-HOSTING.md: describes the new behaviour instead of the old error.

No CSP change needed: connect-src already allows the Supabase origin.

Checks

  • New unit tests for enabledProviders (request shape, filtering, none, unreadable) and for the login page (one provider, none, unreadable, invite hint without Apple).
  • Suite unit tests (1,946) and tsc --noEmit pass locally.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Ns6xSyytpwWuhH7vCJ8Dam


Generated by Claude Code

A provider not yet enabled (Apple, here) still had a button, and pressing
it left the person on Supabase's bare JSON 'provider is not enabled' page,
which the app never sees. The login page now reads Auth's public settings
(external.<provider>) and shows only what is on; with none, no buttons and
no 'or' divider. Settings that cannot be read offer none — the email code
still works. The invite hint mentions Apple's Share My Email only when the
Apple button is there.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Ns6xSyytpwWuhH7vCJ8Dam
@vercel

vercel Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
knotwork-suite Ready Ready Preview Oct 3, 2026 2:48pm UTC

@JFrusher
JFrusher merged commit 4704ba1 into main Oct 3, 2026
9 of 10 checks passed
@JFrusher
JFrusher deleted the claude/elegant-carson-5o5558 branch October 3, 2026 15:19

This branch was successfully deployed

1 active deployment
Preview — 769e1581 Deployed Oct 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants