fix: protect public Auth flows from automated abuse (#1904)
* fix: add Turnstile to public auth flows * test: isolate Turnstile auth tests
This commit is contained in:
@@ -18,6 +18,11 @@ NEXT_PUBLIC_SELF_HOSTED=true
|
||||
# Optional dedicated HMAC secret; otherwise SUPABASE_SERVICE_ROLE_KEY is used.
|
||||
# SESSION_TIMEOUT_SECRET=
|
||||
|
||||
# Optional Cloudflare Turnstile site key for Supabase Auth bot protection.
|
||||
# The matching secret is configured in GoTrue/Supabase Auth, never here.
|
||||
# Enable provider-side enforcement only after this public key is deployed.
|
||||
# NEXT_PUBLIC_TURNSTILE_SITE_KEY=
|
||||
|
||||
# Set to true when public signup is turned off in your GoTrue/Supabase auth
|
||||
# config (GOTRUE_DISABLE_SIGNUP / "Allow new users to sign up" off). GoTrue
|
||||
# offers no clean server-side read of that setting, so this flag mirrors it.
|
||||
|
||||
Reference in New Issue
Block a user