chore(auth): route callback diagnostics to Vercel logs, drop auth_debug cookie - #842
Merged
Merged
Conversation
…ug cookie With the root cause fixed in #841, the browser-side auth_debug cookie from #840 has served its purpose — it was one-off scaffolding to prove the pipeline carries cookies end-to-end. Replacing it with server-side error logs in Vercel's runtime log viewer: zero client footprint, no leaked deployment details to analytics/replay scripts, full context when things actually go wrong. next.config.js: removeConsole in prod now uses { exclude: ['error'] } so console.error survives compilation. console.log/warn/info/debug are still stripped. DEBUG_AUTH=1 continues to disable stripping entirely for local `pnpm build && pnpm start` repro. app/auth/callback/route.ts: - Shared `diag` object captures the same fields the auth_debug cookie carried (forwardedHost, pendingCookieCount, pendingCookieNames, requestCookieNames, publishableKeyPrefix, origin, hasSession, hasUser) plus SDK-side signals. - Every abnormal branch logs `[auth/callback] reason=<branch>` with `diag` to console.error. exchange_failed also includes the SDK message + status. no_code is not logged (crawler noise). - auth_debug cookie + debugPayload construction removed. - DEBUG_AUTH-gated console.log block removed — its content is a subset of `diag` and only fires now when something is actually wrong. - Unused `oauth_error` option removed from failureRedirect's union.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
tran-christian
marked this pull request as draft
April 22, 2026 03:34
|
This pull request has been ignored for the connected project Preview Branches by Supabase. |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Follow-up cleanup for the OAuth session-cookie saga. Now that #841 has proven the pipeline end-to-end, the browser-side
auth_debugcookie from #840 is no longer earning its keep. Replacing it with server-side error logs that land in Vercel's runtime log viewer: zero client footprint, no leaked deployment details to analytics/session-replay scripts, and full context when things actually go wrong.What changed
next.config.jsremoveConsolein prod now uses{ exclude: ['error'] }instead of stripping everything.console.log/warn/info/debugare still stripped.console.errorsurvives — so real errors from anywhere in the app reach Vercel's runtime logs.DEBUG_AUTH=1continues to disable stripping entirely for localpnpm build && pnpm startauth-flow repro.app/auth/callback/route.tsdiagobject captures the same fields theauth_debugcookie carried (forwardedHost,pendingCookieCount,pendingCookieNames,requestCookieNames,publishableKeyPrefix,origin) plus SDK-side signals (hasSession,hasUser).[auth/callback] reason=<branch>withdiagviaconsole.error:exchange_failed— adds SDKmessage+statusno_sessionno_pending_cookiesno_codeis not logged — crawler/direct-URL hits, would be noise.auth_debugcookie +debugPayloadconstruction removed from the success path.DEBUG_AUTH-gatedconsole.logblock removed — its content was a subset ofdiagand only fires now when something is actually wrong, which is when you'd want it anyway.oauth_errorremoved fromfailureRedirect's reason union — it was never passed (the GoTrue error path uses a different redirect).What you'll see in Vercel's log viewer on a future failing sign-in
Successful sign-ins log nothing. Clean and silent.
Non-goals
Domain=omshub.org(from fix(auth): scope session cookies to registrable domain + diagnostic reasons #840), still redirected viax-forwarded-host(from fix(auth): restore canonical Supabase SSR pattern with x-forwarded-host #835).AuthErrorNotification,page.tsx, or thereason=URL params — those stay useful and visible to the end user.Test plan
?error=, welcome toast, session cookies onDomain=<preview-host>)auth_debugcookie present anymore/auth/callback?code=boguson the preview) → URL gets?reason=exchange_failed&message=…, Vercel log viewer shows one[auth/callback] reason=exchange_failed {…}error lineRollback
Revert this commit. No schema, env, or API changes.
Related
@supabase/ssrupgrade, the actual root-cause fix