[auth 2] Reconcile dynamic GoTrue redirects and Auth runtime rollout - #48
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related roadmap issue: ankhorage/studio#190
Scope
This is the owning-package Infra release boundary for
[auth 2]. Studio consumption and admin diagnostics must follow only after this package is merged and released.What changed
<gateway-origin>/auth/v1/callback;API_EXTERNAL_URL,SITE_URL, and callback route;OAUTH_NATIVE_REDIRECT_URLS;deployment/auth;appandsupabasenamespaces canonical when lifecycle contributions are registered;Security
OAuth client secrets remain in trusted runtime secret resolution. Generated status output and lifecycle commands expose callback URLs and readiness only; they do not print client secrets, authorization codes, tokens, or service-role credentials.
Validation
CI is green on
ac051c9d4aa82cc67e076e5acb373c4f63e68973:Release boundary
Do not bridge this change into Studio with an unreleased workspace dependency. After this PR is merged and
@ankhorage/infrais released, the Studio phase can update its dependency and surface the exact callback/rollout diagnostics.