fix(auth): secure white-label invite and reset links (#1680)

This commit is contained in:
Mattsson
2026-08-18 23:17:26 +02:00
committed by GitHub
parent 3ec76d39db
commit dfa7097f3a
9 changed files with 362 additions and 9 deletions
+7
View File
@@ -10,6 +10,13 @@ SUPABASE_SERVICE_ROLE_KEY=your-service-role-or-secret-key
# App base URL (local dev)
NEXT_PUBLIC_APP_URL=http://localhost:3000
# Shared hosted white-label deployments only: exact comma-separated hostnames
# that are registered on this deployment. No wildcards. Invite and auth links
# use a listed request/browser host; every other host falls back to
# NEXT_PUBLIC_APP_URL. Also add each listed host's /auth/callback and /invite/*
# URLs to the Supabase Auth redirect allowlist before deploying it.
# NEXT_PUBLIC_WHITELABEL_DOMAINS=portal.brand-one.example,books.brand-two.example
# Secret for authenticating cron/scheduled requests.
# Any non-empty random string for local dev: openssl rand -hex 16
CRON_SECRET=generate-a-random-secret