Skip to content

chore(auth): route callback diagnostics to Vercel logs, drop auth_debug cookie - #842

Merged
tran-christian merged 1 commit into
mainfrom
claude/debug-pending-cookies-FNAlV
Apr 22, 2026
Merged

tran-christian merged 1 commit into
mainfrom
claude/debug-pending-cookies-FNAlV

Conversation

@tran-christian

Copy link
Copy Markdown
Contributor

Summary

Follow-up cleanup for the OAuth session-cookie saga. Now that #841 has proven the pipeline end-to-end, the browser-side auth_debug cookie from #840 is no longer earning its keep. Replacing it with server-side error logs that land in Vercel's runtime log viewer: zero client footprint, no leaked deployment details to analytics/session-replay scripts, and full context when things actually go wrong.

What changed

next.config.js

removeConsole in prod now uses { exclude: ['error'] } instead of stripping everything.

// before
removeConsole: process.env.NODE_ENV === 'production' && process.env.DEBUG_AUTH !== '1'

// after
removeConsole:
  process.env.NODE_ENV === 'production' && process.env.DEBUG_AUTH !== '1'
    ? { exclude: ['error'] }
    : false

console.log/warn/info/debug are still stripped. console.error survives — so real errors from anywhere in the app reach Vercel's runtime logs. DEBUG_AUTH=1 continues to disable stripping entirely for local pnpm build && pnpm start auth-flow repro.

app/auth/callback/route.ts

  • Shared diag object captures the same fields the auth_debug cookie carried (forwardedHost, pendingCookieCount, pendingCookieNames, requestCookieNames, publishableKeyPrefix, origin) plus SDK-side signals (hasSession, hasUser).
  • Every abnormal branch logs [auth/callback] reason=<branch> with diag via console.error:
    • exchange_failed — adds SDK message + status
    • no_session
    • no_pending_cookies
  • no_code is not logged — crawler/direct-URL hits, would be noise.
  • auth_debug cookie + debugPayload construction removed from the success path.
  • DEBUG_AUTH-gated console.log block removed — its content was a subset of diag and only fires now when something is actually wrong, which is when you'd want it anyway.
  • oauth_error removed from failureRedirect's reason union — it was never passed (the GoTrue error path uses a different redirect).

What you'll see in Vercel's log viewer on a future failing sign-in

[auth/callback] reason=no_pending_cookies {
  hasSession: true,
  hasUser: true,
  pendingCookieCount: 0,
  pendingCookieNames: [],
  requestCookieNames: [ 'sb-ilwqylsdqacxmfkisclx-auth-token-code-verifier' ],
  publishableKeyPrefix: 'sb_publishable_aBcDeF',
  forwardedHost: 'www.omshub.org',
  origin: 'https://some-internal-vercel-lb.vercel.app'
}

Successful sign-ins log nothing. Clean and silent.

Non-goals

Test plan

  • CI green
  • Preview sign-in on Google still works (expect no ?error=, welcome toast, session cookies on Domain=<preview-host>)
  • Preview DevTools → Cookies: no auth_debug cookie present anymore
  • Force a failure (e.g., navigate to /auth/callback?code=bogus on the preview) → URL gets ?reason=exchange_failed&message=…, Vercel log viewer shows one [auth/callback] reason=exchange_failed {…} error line

Rollback

Revert this commit. No schema, env, or API changes.

Related

…ug cookie

With the root cause fixed in #841, the browser-side auth_debug cookie
from #840 has served its purpose — it was one-off scaffolding to prove
the pipeline carries cookies end-to-end. Replacing it with server-side
error logs in Vercel's runtime log viewer: zero client footprint, no
leaked deployment details to analytics/replay scripts, full context
when things actually go wrong.

next.config.js: removeConsole in prod now uses { exclude: ['error'] }
so console.error survives compilation. console.log/warn/info/debug are
still stripped. DEBUG_AUTH=1 continues to disable stripping entirely
for local `pnpm build && pnpm start` repro.

app/auth/callback/route.ts:
- Shared `diag` object captures the same fields the auth_debug cookie
  carried (forwardedHost, pendingCookieCount, pendingCookieNames,
  requestCookieNames, publishableKeyPrefix, origin, hasSession,
  hasUser) plus SDK-side signals.
- Every abnormal branch logs `[auth/callback] reason=<branch>` with
  `diag` to console.error. exchange_failed also includes the SDK
  message + status. no_code is not logged (crawler noise).
- auth_debug cookie + debugPayload construction removed.
- DEBUG_AUTH-gated console.log block removed — its content is a subset
  of `diag` and only fires now when something is actually wrong.
- Unused `oauth_error` option removed from failureRedirect's union.
@vercel

vercel Bot commented Apr 22, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
website Ready Ready Preview, Comment Apr 22, 2026 3:35am

@tran-christian
tran-christian marked this pull request as draft April 22, 2026 03:34
@supabase

supabase Bot commented Apr 22, 2026

Copy link
Copy Markdown

This pull request has been ignored for the connected project ilwqylsdqacxmfkisclx because there are no changes detected in supabase directory. You can change this behaviour in Project Integrations Settings ↗︎.


Preview Branches by Supabase.
Learn more about Supabase Branching ↗︎.

@tran-christian
tran-christian marked this pull request as ready for review April 22, 2026 03:36
@tran-christian
tran-christian merged commit 4cade5f into main Apr 22, 2026
17 checks passed
@tran-christian
tran-christian deleted the claude/debug-pending-cookies-FNAlV branch April 22, 2026 03:36

This branch was successfully deployed

1 active deployment
Preview — bbc66ee4 Deployed Apr 22, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant