CARVIEW |
Select Language
HTTP/2 200
date: Sun, 27 Jul 2025 10:13:26 GMT
content-type: text/html; charset=utf-8
vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With,Accept-Encoding, Accept, X-Requested-With
etag: W/"3a20bd224830ceaa4de01f3b3932a4b6"
cache-control: max-age=0, private, must-revalidate
strict-transport-security: max-age=31536000; includeSubdomains; preload
x-frame-options: deny
x-content-type-options: nosniff
x-xss-protection: 0
referrer-policy: no-referrer-when-downgrade
content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net/ productionresultssa1.blob.core.windows.net/ productionresultssa2.blob.core.windows.net/ productionresultssa3.blob.core.windows.net/ productionresultssa4.blob.core.windows.net/ productionresultssa5.blob.core.windows.net/ productionresultssa6.blob.core.windows.net/ productionresultssa7.blob.core.windows.net/ productionresultssa8.blob.core.windows.net/ productionresultssa9.blob.core.windows.net/ productionresultssa10.blob.core.windows.net/ productionresultssa11.blob.core.windows.net/ productionresultssa12.blob.core.windows.net/ productionresultssa13.blob.core.windows.net/ productionresultssa14.blob.core.windows.net/ productionresultssa15.blob.core.windows.net/ productionresultssa16.blob.core.windows.net/ productionresultssa17.blob.core.windows.net/ productionresultssa18.blob.core.windows.net/ productionresultssa19.blob.core.windows.net/ github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com/ user-images.githubusercontent.com/ private-user-images.githubusercontent.com opengraph.githubassets.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com; manifest-src 'self'; media-src github.com user-images.githubusercontent.com/ secured-user-images.githubusercontent.com/ private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
server: github.com
content-encoding: gzip
accept-ranges: bytes
set-cookie: _gh_sess=Q4Z8R4WVFXJ5Fd8tTDuG63ksZdo6fg1vqbCI40aLEu%2B6ay7Vkp%2FsTSxBMkDx2sDYXwArj6nyoEvk3FUpkz%2Bka6AHgHHl8mxND12CkvViByE3WhmuoORe36FpGb7tyb196Qhc9EqdYUldJpwYxrmH%2FIZDK55lmJt84wYDL6PJDjIu5r5%2FmlBSbgEwRYpJoAN1GaXwUM5TwlbJIQwdTtzEBPFb4uNIDSnKcHVEfrBZ9xC2%2BsBOERkTXZ4enxkh1cNaij2RpJn4DNSklDTKqtnEHQ%3D%3D--CGSDkyxV6fzJt58F--yU%2BDuizMgT3WMZGEoh67Vg%3D%3D; Path=/; HttpOnly; Secure; SameSite=Lax
set-cookie: _octo=GH1.1.1307773208.1753611206; Path=/; Domain=github.com; Expires=Mon, 27 Jul 2026 10:13:26 GMT; Secure; SameSite=Lax
set-cookie: logged_in=no; Path=/; Domain=github.com; Expires=Mon, 27 Jul 2026 10:13:26 GMT; HttpOnly; Secure; SameSite=Lax
x-github-request-id: BBA8:1C79A4:D23056:115C1B1:6885FBC6
Tags · supabase/auth · GitHub
Toggle rc2.178.0-rc.3's commit message
Toggle rc2.178.0-rc.2's commit message
Toggle rc2.178.0-rc.1's commit message
Toggle v2.177.0's commit message
Toggle rc2.177.0-rc.14's commit message
Toggle rc2.177.0-rc.13's commit message
Toggle rc2.177.0-rc.12's commit message
Toggle rc2.177.0-rc.11's commit message
Toggle rc2.177.0-rc.10's commit message
Skip to content
Navigation Menu
{{ message }}
-
Notifications
You must be signed in to change notification settings - Fork 489
Tags: supabase/auth
Tags
rc2.178.0-rc.3
feat: add sign in with ethereum (#2069) Adds Sign in with Ethereum. Configure it by: ``` GOTRUE_EXTERNAL_WEB3_ETHEREUM_ENABLED="carview.php?tsp=true" GOTRUE_EXTERNAL_WEB3_ETHEREUM_MAXIMUM_VALIDITY_DURATION="10m" ``` SIWS & SIWE are based off of EIP-4361, which is referenced here: https://eips.ethereum.org/EIPS/eip-4361, so they are close in implementation with slight differences between address/signature verification format & algorithm. For Ethereum, specifically the signature verification part, It requires recovering the public address from the signature, and then testing the signature against it, with the algorithm Ethereum uses, this is tedious to implement without using the https://github.com/ethereum/go-ethereum package, as the verification has some error correction that it does, would be hard to test/maintain without the dependency, let me know what you think.
rc2.178.0-rc.2
feat: add support for managing SSO providers by resource_id (#2081) Some time ago a `resource_id` was added to the `sso_providers` table to support infrastructure as code use cases down the road. This change adds basic support for utilizing this field to manage SSO providers. Key changes: - Updated API for SSO providers to allow get, put, delete by `resource_id` - Extended `loadSSOProvider` to accept `resource_`-prefixed `idp_id` values - Added optional `resource_id` field to `SSOProvider` model - Implemented `FindSSOProviderByResourceID` in model layer - Renamed `FindAllSAMLProviders` to `FindAllSSOProviders` - Added filtering to the `/admin/sso/providers` via `?resource_id{,_prefix}=` - Included full E2E test coverage for SSO provider api --------- Co-authored-by: Chris Stockton <chris.stockton@supabase.io>
rc2.178.0-rc.1
v2.177.0
chore(master): release 2.177.0 (#2059) 🤖 I have created a release *beep* *boop* --- ## [2.177.0](v2.176.1...v2.177.0) (2025-07-05) ### Features * add option to disable writing to `audit_log_entries` ([#2073](#2073)) ([80758dd](80758dd)) * add snapchat provider ([#2071](#2071)) ([fca8ea4](fca8ea4)) * enhance login analytics ([#2078](#2078)) ([1aed4a2](1aed4a2)) * fallback to jwt secret if alg is `HS256` and the `kid` is not recognized ([#2072](#2072)) ([8fa99bd](8fa99bd)) * ignore `aud` claim from admin jwt (`service_role` never had one) ([#2070](#2070)) ([57eddcb](57eddcb)) ### Bug Fixes * add missing provider info to signedup audit logs ([#2061](#2061)) ([c6e0cbe](c6e0cbe)) * **auditlog:** keep writing to logs even postgres is disabled ([#2076](#2076)) ([b89bc32](b89bc32)) * do not log fatal when http server successfully closes ([#2065](#2065)) ([1f7de6c](1f7de6c)) * invites should send another email when user exists ([#2058](#2058)) ([96469bd](96469bd)) * use `appleid.apple.com` as default issuer ([#2068](#2068)) ([963a781](963a781)) * use `split_words` config option for `AuditLog` ([#2075](#2075)) ([7ecb234](7ecb234)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
rc2.177.0-rc.14
feat: enhance login analytics (#2078) ## Summary Enhance login analytics mainly by adding missing provider information in Supabase Auth. This ensures all authentication flows are properly tracked with structured data.
rc2.177.0-rc.13
feat: enhance login analytics (#2078) ## Summary Enhance login analytics mainly by adding missing provider information in Supabase Auth. This ensures all authentication flows are properly tracked with structured data.
rc2.177.0-rc.12
feat: ignore `aud` claim from admin jwt (`service_role` never had one) ( #2070) There's a problem with new Secret API keys which mint a JWT where the `aud` claim is the requested resource. This is confusing list admin users in returning no users (since there's no such audience). `service_role` never had an `aud` claim in it, so this is the proper place to fix this.
rc2.177.0-rc.11
fix(auditlog): keep writing to logs even postgres is disabled (#2076) move `DisablePostgres` check after payload mutation to ensure auth_event logs have the same data prior to introduce of the `DisablePostgres` config
rc2.177.0-rc.10
feat: fallback to jwt secret if alg is `HS256` and the `kid` is not r… …ecognized (#2072) Some customers may be using JWTs signed with the JWT secret but they may be advertising a `kid` claim for their own purposes. Auth should try to reasonably accept those JWTs.
PreviousNext
You can’t perform that action at this time.