Add Google SSO
- Migration: profiles.username is now nullable -- Google's OAuth redirect can't collect a username up front the way the email/password signup form does, so a first-time Google sign-in's profile is created with no username. - supabase/config.toml: [auth.external.google] enabled, credentials via env() substitution (SUPABASE_AUTH_EXTERNAL_GOOGLE_CLIENT_ID/_SECRET in .env.local, which the CLI auto-loads). skip_nonce_check is on, which Supabase's own docs call out as required for local sign-in. - LoginScreen: "Continue with Google" alongside the existing email/password form. - CompleteProfileScreen: one-time gate for a signed-in user with no username yet (i.e. first Google sign-in) -- same hard-gate spirit as email verification, nothing else is usable until a username is set. - App.tsx now checks profiles.username after establishing a session and routes to CompleteProfileScreen before AppShell when it's missing. RLS test suite re-run clean (23/23) after the schema change. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017DUU6CnxECCDeqDNYJgr5x
This commit is contained in:
@@ -335,6 +335,24 @@ skip_nonce_check = false
|
||||
# If enabled, it will allow the user to successfully authenticate when the provider does not return an email address.
|
||||
email_optional = false
|
||||
|
||||
# Google SSO (organized-ideas.md §2: username collected up front for manual
|
||||
# signup, email pulled from Google for this path). Client id/secret come
|
||||
# from your own Google Cloud OAuth credentials via env var substitution —
|
||||
# see README/setup notes for how to create them. The CLI auto-loads
|
||||
# .env/.env.local from the repo root, so set these there, never here.
|
||||
[auth.external.google]
|
||||
enabled = true
|
||||
client_id = "env(SUPABASE_AUTH_EXTERNAL_GOOGLE_CLIENT_ID)"
|
||||
secret = "env(SUPABASE_AUTH_EXTERNAL_GOOGLE_SECRET)"
|
||||
redirect_uri = ""
|
||||
url = ""
|
||||
# Required for local sign-in with Google per Supabase's own guidance — the
|
||||
# local GoTrue instance can't satisfy the nonce check the way a deployed
|
||||
# instance with a stable public URL can. Revisit (set false) once this is
|
||||
# ever pointed at a real deployed URL instead of localhost.
|
||||
skip_nonce_check = true
|
||||
email_optional = false
|
||||
|
||||
# Allow Solana wallet holders to sign in to your project via the Sign in with Solana (SIWS, EIP-4361) standard.
|
||||
# You can configure "web3" rate limit in the [auth.rate_limit] section and set up [auth.captcha] if self-hosting.
|
||||
[auth.web3.solana]
|
||||
|
||||
Reference in New Issue
Block a user