fix: protect public Auth flows from automated abuse (#1904)

* fix: add Turnstile to public auth flows

* test: isolate Turnstile auth tests
This commit is contained in:
Mattsson
2026-08-25 19:14:06 +02:00
committed by GitHub
parent 743bc82f93
commit 328ccda10d
15 changed files with 619 additions and 10 deletions
+5
View File
@@ -18,6 +18,11 @@ NEXT_PUBLIC_SELF_HOSTED=true
# Optional dedicated HMAC secret; otherwise SUPABASE_SERVICE_ROLE_KEY is used.
# SESSION_TIMEOUT_SECRET=
# Optional Cloudflare Turnstile site key for Supabase Auth bot protection.
# The matching secret is configured in GoTrue/Supabase Auth, never here.
# Enable provider-side enforcement only after this public key is deployed.
# NEXT_PUBLIC_TURNSTILE_SITE_KEY=
# Set to true when public signup is turned off in your GoTrue/Supabase auth
# config (GOTRUE_DISABLE_SIGNUP / "Allow new users to sign up" off). GoTrue
# offers no clean server-side read of that setting, so this flag mirrors it.