The proxy in front of every page, RSC, prefetch and /api request makes
several sequential network calls (getUser, session state, the
resolve_active_company RPC, MFA factor lookups) and nothing measured them,
while the route wrapper has logged authMs/companyMs/handlerMs per API call
for months. This is the first PR of the responsiveness plan (customer
report: "it takes time before all fields load when clicking around"): the
baseline every later change is measured against.
- lib/supabase/proxy-timing.ts: pure helpers (request classification from
the app-router headers, route template that collapses ids and tokens,
Server-Timing formatting, a timed() accumulator).
- lib/supabase/middleware.ts: updateSession wraps updateSessionInner, times
each phase, sets Server-Timing on page/RSC/prefetch responses and
X-Proxy-Timing on /api responses (withRouteContext owns Server-Timing
there), and emits one "proxy completed" log line per request.
- scripts/perf/log-percentiles.ts: p50/p90/p99 per group over
`vercel logs --json` output, for both "op completed" and
"proxy completed"; scripts/perf/README.md documents the protocol and
targets.
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>