{"_id":"@benjamin.dobell/supabase-auth-helpers-nextjs","_rev":"2-f977e420160385b65b7029ea4bdf65af","name":"@benjamin.dobell/supabase-auth-helpers-nextjs","dist-tags":{"latest":"0.3.2"},"versions":{"0.3.0":{"name":"@benjamin.dobell/supabase-auth-helpers-nextjs","version":"0.3.0","description":"A collection of framework specific Auth utilities for working with Supabase.","main":"dist/index.js","types":"dist/index.d.ts","publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/benjamin-dobell/supabase-auth-helpers.git"},"keywords":["Supabase","Auth","Nextjs"],"author":{"name":"Supabase Community"},"license":"MIT","bugs":{"url":"https://github.com/supabase-community/auth-helpers/issues"},"homepage":"https://github.com/supabase-community/auth-helpers/tree/main/packages/nextjs#readme","devDependencies":{"@supabase/supabase-js":"^1.35.3","config":"0.1.0","next":"^12.1.5","react":"^18.0.0","react-dom":"^18.0.0","rimraf":"^3.0.2","tsconfig":"0.1.0","tslib":"^2.3.1","tsup":"^5.12.5"},"dependencies":{"@supabase/auth-helpers-shared":"0.1.3"},"scripts":{"build":"tsup","clean":"rimraf dist","clean:all":"rimraf dist node_modules"},"_id":"@benjamin.dobell/supabase-auth-helpers-nextjs@0.3.0","_integrity":"sha512-X83Gtp8APhXu6DdXU/O2zSx7swd3y27gJU261DiVP+tEVR2c9cuBAmgQwmEcvEZpQ5mgh5ME3OSYWf7AiBKpxw==","_resolved":"/private/var/folders/5f/g7blsrpd1r53y7yfsl4z2z1w0000gn/T/49444120c8d145af9ef113d78fe1662e/benjamin.dobell-supabase-auth-helpers-nextjs-0.3.0.tgz","_from":"file:benjamin.dobell-supabase-auth-helpers-nextjs-0.3.0.tgz","_nodeVersion":"18.3.0","_npmVersion":"8.11.0","dist":{"integrity":"sha512-X83Gtp8APhXu6DdXU/O2zSx7swd3y27gJU261DiVP+tEVR2c9cuBAmgQwmEcvEZpQ5mgh5ME3OSYWf7AiBKpxw==","shasum":"a361a28b2cdc149a566acc106b1cdd9a5fb0bb98","tarball":"https://registry.npmjs.org/@benjamin.dobell/supabase-auth-helpers-nextjs/-/supabase-auth-helpers-nextjs-0.3.0.tgz","fileCount":30,"unpackedSize":119817,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQClTYgOuPay1jVIbMQh14ksz3mGCDlx+X4Wx3AMqdKeUwIgHoDH2luMqsL4fyCpLJZ1+XK5qFSeU3AESfvP10FLpG8="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi4oTQACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmresA/7BskN9roPz9qD9EJmY3ck8Wocv2a9FeivP0Vh5QGCcjxkhhk9\r\nqsKnzjXC1D67HvW+i6lj4JOttJrzXoaj47+t0axwWJDoJikVcKnQwBfH/AcN\r\nCbGTvwX+dkquZXItQmKKidaDIE7TCwEnRTi59XqqGunSEcRHydmEy+gdRAJV\r\nxKMpQFo9pLCHSvsnspLvRfqLbTCrBlAwylyBpmll6QdcvzVeamNyr10SryWx\r\nP7s/9ZSYPKGCNQSMDb6If2s3WKXemz3dtV4IaAHfY1awBjE+NSGG/j+tL64E\r\nMiSVFVpDdO3neWYvIfUWCpT/UcCw4glXbOVrJ6+KkquaiZzMbEn32GkCZL2L\r\n1Y8MSwA/1IhwoseHxka2x73yTzD8wKIlUlP6GM9i3Q4j8PC3WwYAZ1DE1GKA\r\nXiM/3FstK6ZAj/8IDldyt1uMhLLeyGV8HXnpzEI1CUsJodJadFc8CnPp6ygb\r\nTxYKhSQQnXjaBYdRKvk1TqCnTygZ9WPrv+AAjYt7b/3V9OET0i5cuInUAxAY\r\n+PEMi1DmMSGsSZt2s52EXXyab2ZBC+icXI5QD/lHBjlNe3yeSn0kF2XATvi8\r\np98JMDuRfcWTcAxcck2AP+3my4okLlhz7KWGLzhHdfbOkntCl6DT5VhKH9vt\r\nE1LLoSxA1XFsabfqLbUH1zZXGge6wGuGhFo=\r\n=h5Jd\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"benjamin.dobell","email":"contact@glassechidna.com.au"},"directories":{},"maintainers":[{"name":"benjamin.dobell","email":"contact@glassechidna.com.au"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/supabase-auth-helpers-nextjs_0.3.0_1659012303174_0.6188521025253937"},"_hasShrinkwrap":false},"0.3.1":{"name":"@benjamin.dobell/supabase-auth-helpers-nextjs","version":"0.3.1","description":"A collection of framework specific Auth utilities for working with Supabase.","main":"dist/index.js","types":"dist/index.d.ts","publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/benjamin-dobell/supabase-auth-helpers.git"},"keywords":["Supabase","Auth","Nextjs"],"author":{"name":"Supabase Community"},"license":"MIT","bugs":{"url":"https://github.com/supabase-community/auth-helpers/issues"},"homepage":"https://github.com/supabase-community/auth-helpers/tree/main/packages/nextjs#readme","devDependencies":{"@supabase/supabase-js":"^1.35.3","config":"0.1.0","next":"^12.1.5","react":"^18.0.0","react-dom":"^18.0.0","rimraf":"^3.0.2","tsconfig":"0.1.0","tslib":"^2.3.1","tsup":"^5.12.5"},"dependencies":{"@supabase/auth-helpers-shared":"0.1.3"},"scripts":{"build":"tsup","clean":"rimraf dist","clean:all":"rimraf dist node_modules"},"_id":"@benjamin.dobell/supabase-auth-helpers-nextjs@0.3.1","_integrity":"sha512-Xlq0qf9f4KRiTBlC4GTO9IHoy9FaK3clWyjWOHAOyCC7wRnRiq/h5nOKVVoaL66LKvVfe+TNsG9Uuurb53XVDQ==","_resolved":"/private/var/folders/5f/g7blsrpd1r53y7yfsl4z2z1w0000gn/T/d1dbd3d5c3280927c401b6bb43ebf402/benjamin.dobell-supabase-auth-helpers-nextjs-0.3.1.tgz","_from":"file:benjamin.dobell-supabase-auth-helpers-nextjs-0.3.1.tgz","_nodeVersion":"18.3.0","_npmVersion":"8.11.0","dist":{"integrity":"sha512-Xlq0qf9f4KRiTBlC4GTO9IHoy9FaK3clWyjWOHAOyCC7wRnRiq/h5nOKVVoaL66LKvVfe+TNsG9Uuurb53XVDQ==","shasum":"ecd441ac5b1c95fe8f4ca914e62053755d6438f5","tarball":"https://registry.npmjs.org/@benjamin.dobell/supabase-auth-helpers-nextjs/-/supabase-auth-helpers-nextjs-0.3.1.tgz","fileCount":30,"unpackedSize":119779,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCBCXi6hwHF3yCEYj+adFq9E6FpfbbDu2+SVZZDs1FBAAIgLicnEXC5BxD/X5TBsZ8YWx4k1Jk1xfHelSaee2c1wXQ="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi4ovWACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpxEA//R6GNdmGcsNbcWTO3djjIckZzZ6hE5TZ1gOuP04TJgkB7YI7Q\r\n869LCoXQ7Hb1cgZzlRjYJ5SZPgv8P+4FXpKbru9CsErPu8BtlfaGvUAzTxel\r\nlbLoG2YXQwVNLKE+8+ia9rMqRbewOPs9JnXFy+scbvv1Yfnume2CJDrYHF02\r\nUtg5Jeemh5gKbmu/TXH7PvYapzcPQnxdC5iP+qf84ZdtZLpjnLcWeK7qPyHc\r\nebbZAQDKR+SvKxbq5RuMfd7gkbfpGBjsNABSv0NGlHXCMIwC1MPLGHIugaco\r\nab6peRX/wNJbBi1vGVbIrOBTIUxB6cGZSb/SK0DUmkq7T+D+yeQnpac/YvB5\r\nevKWx8tf7JR8+3dCSLi6z3sryzbaPGwMRKSjIQhfmdYBONciozVHgQ18DdeW\r\nKRoon3kfcAmY2OXi6Ct2OD8ZyodvoQCvEJGmK0pyz1S+ghABVqddUxx/vGOM\r\nndHJC/E2KiJ+gmGPuaWjpnoF1mo3eZESVJ+G4b+kBILndO+6vOQMdi/e/x5a\r\nUfqm17rw4aac6G6BZJNKqlQ6V5s3lQ0B4J8yJ3PIBDWbuB81KYOJy7ElxFyh\r\nr/vG+o/Adrr+r6APlSZDsHpRcvcH/Ftu97sI85PDpDf2OogXXjzTO6urhUra\r\n7IUbD69fp2eGa7dX15RJWB9il9kPvVCWiDA=\r\n=dssA\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"benjamin.dobell","email":"contact@glassechidna.com.au"},"directories":{},"maintainers":[{"name":"benjamin.dobell","email":"contact@glassechidna.com.au"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/supabase-auth-helpers-nextjs_0.3.1_1659014102323_0.15959512429075806"},"_hasShrinkwrap":false},"0.3.2":{"name":"@benjamin.dobell/supabase-auth-helpers-nextjs","version":"0.3.2","description":"A collection of framework specific Auth utilities for working with Supabase.","main":"dist/index.js","types":"dist/index.d.ts","publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/benjamin-dobell/supabase-auth-helpers.git"},"keywords":["Supabase","Auth","Nextjs"],"author":{"name":"Supabase Community"},"license":"MIT","bugs":{"url":"https://github.com/supabase-community/auth-helpers/issues"},"homepage":"https://github.com/supabase-community/auth-helpers/tree/main/packages/nextjs#readme","devDependencies":{"@supabase/supabase-js":"^1.35.3","config":"0.1.0","next":"^12.1.5","react":"^18.0.0","react-dom":"^18.0.0","rimraf":"^3.0.2","tsconfig":"0.1.0","tslib":"^2.3.1","tsup":"^5.12.5"},"dependencies":{"@supabase/auth-helpers-shared":"0.1.3"},"scripts":{"build":"tsup","clean":"rimraf dist","clean:all":"rimraf dist node_modules"},"_id":"@benjamin.dobell/supabase-auth-helpers-nextjs@0.3.2","_integrity":"sha512-rFBxNfYx6WIPNzgTdMz+CzFsH1f9GGJiE/CjIz/yoSf/3Wd3oOsNMk+6jk7NgSaYlwwQpVj9zxY6Vm3nJYVH/Q==","_resolved":"/private/var/folders/5f/g7blsrpd1r53y7yfsl4z2z1w0000gn/T/49323b8c23fb27e85be9cb56c4ca8fc4/benjamin.dobell-supabase-auth-helpers-nextjs-0.3.2.tgz","_from":"file:benjamin.dobell-supabase-auth-helpers-nextjs-0.3.2.tgz","_nodeVersion":"18.3.0","_npmVersion":"8.11.0","dist":{"integrity":"sha512-rFBxNfYx6WIPNzgTdMz+CzFsH1f9GGJiE/CjIz/yoSf/3Wd3oOsNMk+6jk7NgSaYlwwQpVj9zxY6Vm3nJYVH/Q==","shasum":"93a7014f0495aadff88b1e435b011f4e6e9ada69","tarball":"https://registry.npmjs.org/@benjamin.dobell/supabase-auth-helpers-nextjs/-/supabase-auth-helpers-nextjs-0.3.2.tgz","fileCount":30,"unpackedSize":120162,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCdZgVKimuhjVKYCiu8f+AXJb8ONvZ047rBCmKI2+Mi2QIgFHzpTSOx+gDAD4qqkfgcySvbxoMAbDg0eriImpRVoXI="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJi4p52ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoM4g//XxHwQ5iy3MceW1mKXHB5c+kYstc/lTw+XJNaTAOW0KmzXy/U\r\nVb/QmnTAdSDSKNSInctggmN129lYf1xYXcNDxFDRrMs5/Gp5uWZZNC7hkyC7\r\nzNHVKZ2XDtzZ+XP6GkFTYCmBMZGVXMsu5YjRbAH6PuR8tygUiMInBdTWsQ2x\r\nECLt0YHauIo/zMAX9SKUIcTe0zY24PHXrrv+dfgUv27qaPUtFMhaXAUXr06B\r\nNRwyQ5uyTf0e1XkomP2ic4a1nAZOo5o+4JElpH3ADEbJ+3/Hj/psw8kfe2GX\r\nJhDDGs8rG1YB1d+Q1oFcM4kBULJs7V9yzYDQ0EVN2lNreHYcjHFv789++2nC\r\nHM9dkYhy5UQO5ArWoARjPgbwYFUH1Tp3qnTSnyeVzKHmaGEPsBHtHCf/s5Oj\r\nVf6QWvKCyRuMURVttjqGXpK238GAf7tjYt4rljDDrCBgruS4ymljpq4w4c8L\r\nqO6xURV+QsGNS3EpKLIwDJVgFLuXHe8JW7i6F9jaSVKH0jqgn34bWV24RzGu\r\nA40b/HbU8scagv+uQoQ+3hKo5XQsFWvZ/0jiu71TJbBYD/A79w+gvLIjlqyg\r\nvyh/PuatlQDqkdGfQ/OiCRulBQed4/N5F5USUOdGCzaX+nrCUi0c80G2Vv5j\r\nu0UVqQUaI3DA6LhOW0tSCkk/7p1jMJOY7Gw=\r\n=Hh3O\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"benjamin.dobell","email":"contact@glassechidna.com.au"},"directories":{},"maintainers":[{"name":"benjamin.dobell","email":"contact@glassechidna.com.au"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/supabase-auth-helpers-nextjs_0.3.2_1659018870594_0.5543277205612027"},"_hasShrinkwrap":false}},"time":{"created":"2022-07-28T12:45:03.119Z","0.3.0":"2022-07-28T12:45:04.150Z","modified":"2022-07-28T14:34:30.805Z","0.3.1":"2022-07-28T13:15:02.743Z","0.3.2":"2022-07-28T14:34:30.738Z"},"maintainers":[{"name":"benjamin.dobell","email":"contact@glassechidna.com.au"}],"description":"A collection of framework specific Auth utilities for working with Supabase.","homepage":"https://github.com/supabase-community/auth-helpers/tree/main/packages/nextjs#readme","keywords":["Supabase","Auth","Nextjs"],"repository":{"type":"git","url":"git+https://github.com/benjamin-dobell/supabase-auth-helpers.git"},"author":{"name":"Supabase Community"},"bugs":{"url":"https://github.com/supabase-community/auth-helpers/issues"},"license":"MIT","readme":"# @supabase/auth-helpers-nextjs\n\nThis submodule provides convenience helpers for implementing user authentication in Next.js applications.\n\n## Installation\n\nUsing [npm](https://npmjs.org):\n\n```sh\nnpm install @supabase/auth-helpers-nextjs\n\n# Main components and hooks for React based frameworks (optional)\nnpm install @supabase/auth-helpers-react\n```\n\nUsing [yarn](https://yarnpkg.com/):\n```sh\nyarn add @supabase/auth-helpers-nextjs\n\n# Main components and hooks for React based frameworks (optional)\nyarn add @supabase/auth-helpers-react\n```\n\nThis library supports the following tooling versions:\n\n- Node.js: `^10.13.0 || >=12.0.0`\n\n- Next.js: `>=10`\n\n## Getting Started\n\n### Configuration\n\nSet up the fillowing env vars. For local development you can set them in a `.env.local` file. See an example [here](../../examples/nextjs/.env.local.example)).\n\n```bash\n# Find these in your Supabase project settings > API\nNEXT_PUBLIC_SUPABASE_URL=https://your-project.supabase.co\nNEXT_PUBLIC_SUPABASE_ANON_KEY=your-anon-key\n```\n\n### Basic Setup\n\n- Create an `auth` directory under the `/pages/api/` directory.\n\n- Create a `[...supabase].js` file under the newly created `auth` directory.\n\nThe path to your dynamic API route file would be `/pages/api/auth/[...supabase].js`. Populate that file as follows:\n\n```js\nimport { handleAuth } from '@supabase/auth-helpers-nextjs';\n\nexport default handleAuth({ logout: { returnTo: '/' } });\n```\n\nExecuting `handleAuth()` creates the following route handlers under the hood that perform different parts of the authentication flow:\n\n- `/api/auth/callback`: The `UserProvider` forwards the session details here every time `onAuthStateChange` fires on the client side. This is needed to set up the cookies for your application so that SSR works seamlessly.\n\n- `/api/auth/user`: You can fetch user profile information in JSON format.\n\n- `/api/auth/logout`: Your Next.js application logs out the user. You can optionally pass a `returnTo` parameter to return to a custom relative URL after logout, eg `/api/auth/logout?returnTo=/login`. This will overwrite the logout `returnTo` option specified `handleAuth()`\n\nWrap your `pages/_app.js` component with the `UserProvider` component:\n\n```jsx\n// pages/_app.js\nimport React from 'react';\nimport { UserProvider } from '@supabase/auth-helpers-react';\nimport { supabaseClient } from '@supabase/auth-helpers-nextjs';\n\nexport default function App({ Component, pageProps }) {\n  return (\n    <UserProvider supabaseClient={supabaseClient}>\n      <Component {...pageProps} />\n    </UserProvider>\n  );\n}\n```\n\nYou can now determine if a user is authenticated by checking that the `user` object returned by the `useUser()` hook is defined.\n\n## Client-side data fetching with RLS\n\nFor [row level security](https://supabase.com/docs/learn/auth-deep-dive/auth-row-level-security) to work properly when fetching data client-side, you need to make sure to import the `{ supabaseClient }` from `# @supabase/auth-helpers-nextjs` and only run your query once the user is defined client-side in the `useUser()` hook:\n\n```js\nimport { Auth } from '@supabase/ui';\nimport { useUser } from '@supabase/auth-helpers-react';\nimport { supabaseClient } from '@supabase/auth-helpers-nextjs';\nimport { useEffect, useState } from 'react';\n\nconst LoginPage = () => {\n  const { user, error } = useUser();\n  const [data, setData] = useState();\n\n  useEffect(() => {\n    async function loadData() {\n      const { data } = await supabaseClient.from('test').select('*');\n      setData(data);\n    }\n    // Only run query once user is logged in.\n    if (user) loadData();\n  }, [user]);\n\n  if (!user)\n    return (\n      <>\n        {error && <p>{error.message}</p>}\n        <Auth\n          supabaseClient={supabaseClient}\n          providers={['google', 'github']}\n          socialLayout=\"horizontal\"\n          socialButtonSize=\"xlarge\"\n        />\n      </>\n    );\n\n  return (\n    <>\n      <button onClick={() => supabaseClient.auth.signOut()}>Sign out</button>\n      <p>user:</p>\n      <pre>{JSON.stringify(user, null, 2)}</pre>\n      <p>client-side data fetching with RLS</p>\n      <pre>{JSON.stringify(data, null, 2)}</pre>\n    </>\n  );\n};\n\nexport default LoginPage;\n```\n\n### Server-side rendering (SSR) - withPageAuth\n\nIf you wrap your `getServerSideProps` with `withPageAuth` your props object will be augmented with the user object.\n\n```js\n// pages/profile.js\nimport { withPageAuth } from '@supabase/auth-helpers-nextjs';\n\nexport default function Profile({ user }) {\n  return <div>Hello {user.name}</div>;\n}\n\nexport const getServerSideProps = withPageAuth({ redirectTo: '/login' });\n```\n\nIf there is no authenticated user, they will be redirect to your home page, unless you specify the `redirectTo` option.\n\nYou can pass in your own `getServerSideProps` method, the props returned from this will be merged with the\nuser props. You can also access the user session data by calling `getUser` inside of this method, eg:\n\n```js\n// pages/protected-page.js\nimport { withPageAuth, getUser } from '@supabase/auth-helpers-nextjs';\n\nexport default function ProtectedPage({ user, customProp }) {\n  return <div>Protected content</div>;\n}\n\nexport const getServerSideProps = withPageAuth({\n  redirectTo: '/foo',\n  async getServerSideProps(ctx) {\n    // Access the user object\n    const { user, accessToken } = await getUser(ctx);\n    return { props: { email: user?.email } };\n  }\n});\n```\n\n### Server-side data fetching with RLS\n\nFor [row level security](https://supabase.com/docs/learn/auth-deep-dive/auth-row-level-security) to work in a server environment, you need to inject the request context into the supabase client:\n\n```js\nimport {\n  User,\n  withPageAuth,\n  supabaseServerClient\n} from '@supabase/auth-helpers-nextjs';\n\nexport default function ProtectedPage({\n  user,\n  data\n}: {\n  user: User,\n  data: any\n}) {\n  return (\n    <>\n      <div>Protected content for {user.email}</div>\n      <pre>{JSON.stringify(data, null, 2)}</pre>\n      <pre>{JSON.stringify(user, null, 2)}</pre>\n    </>\n  );\n}\n\nexport const getServerSideProps = withPageAuth({\n  redirectTo: '/',\n  async getServerSideProps(ctx) {\n    // Run queries with RLS on the server\n    const { data } = await supabaseServerClient(ctx).from('test').select('*');\n    return { props: { data } };\n  }\n});\n```\n\n### Server-side data fetching to OAuth APIs using `provider_token`\n\nWhen using third-party auth providers, sessions are initiated with an additional `provider_token` field which is persisted as an HTTPOnly cookie upon logging in to enabled usage on the server side. The `provider_token` can be used to make API requests to the OAuth provider's API endpoints on behalf of the logged-in user. In the following example, we fetch the user's full profile from the third-party API during SSR using their id and auth token:\n\n```js\nimport { User, withPageAuth, getUser } from '@supabase/auth-helpers-nextjs';\n\ninterface Profile {\n  /* ... */\n}\n\nexport default function ProtectedPage({\n  user,\n  data\n}: {\n  user: User,\n  profile: Profile\n}) {\n  return <div>Protected content</div>;\n}\n\nexport const getServerSideProps = withPageAuth({\n  redirectTo: '/',\n  async getServerSideProps(ctx) {\n    // Retrieve provider_token from cookies\n    const provider_token = ctx.req.cookies['sb-provider-token'];\n    // Get logged in user's third-party id from metadata\n    const { user } = await getUser(ctx);\n    const userId = user?.user_metadata.provider_id;\n    const profile: Profile = await (\n      await fetch(`https://api.example.com/users/${userId}`, {\n        method: 'GET',\n        headers: {\n          Authorization: `Bearer ${provider_token}`\n        }\n      })\n    ).json();\n    return { props: { profile } };\n  }\n});\n```\n\n## Protecting API routes\n\nWrap an API Route to check that the user has a valid session. If they're not logged in the handler will return a\n401 Unauthorized.\n\n```js\n// pages/api/protected-route.js\nimport {\n  withApiAuth,\n  supabaseServerClient\n} from '@supabase/auth-helpers-nextjs';\n\nexport default withApiAuth(async function ProtectedRoute(req, res) {\n  // Run queries with RLS on the server\n  const { data } = await supabaseServerClient({ req, res })\n    .from('test')\n    .select('*');\n  res.json(data);\n});\n```\n\nIf you visit `/api/protected-route` without a valid session cookie, you will get a 401 response.\n\n## Protecting routes with [Nextjs Middleware](https://nextjs.org/docs/middleware)\n\nAs an alternative to protecting individual pages using `getServerSideProps` with `withPageAuth`, `withMiddlewareAuth` can be used from inside a `_middleware` file to protect an entire directory. In the following example, all requests to `/protected/*` will check whether a user is signed in, if successful the request will be forwarded to the destination route, otherwise the user will be redirected to `/login` (defaults to: `/`) with a 307 Temporary Redirect response status:\n\n```ts\n// pages/protected/_middleware.ts\nimport { withMiddlewareAuth } from '@supabase/auth-helpers-nextjs/middleware';\n\nexport const middleware = withMiddlewareAuth({ redirectTo: '/login' });\n```\n\nIt is also possible to add finer granularity based on the user logged in. I.e. you can specify a promise to determine if a specific user has permission or not.\n\n\n```ts\n// pages/protected/_middleware.ts\nimport { withMiddlewareAuth } from '@supabase/auth-helpers-nextjs/middleware';\n\nexport const middleware = withMiddlewareAuth({ \n  redirectTo: '/login',\n  authGuard: {\n    isPermitted: async (user) => user.email?.endsWith('@example.com') ?? false,\n    redirectTo: '/insufficient-permissions'\n  }\n});\n```\n\n## Migrating from @supabase/supabase-auth-helpers to @supabase/auth-helpers\n\nThis is a step by step guide on migrating away from the `@supabase/supabase-auth-helpers` to the newly released `@supabase/auth-helpers`.\n\n1. Install `@supabase/supabase-js`, `@supabase/auth-helpers-nextjs` and `@supabase/auth-helpers-react` libraries from npm.\n2. Replace all imports of `@supabase/supabase-auth-helpers/nextjs` in your project with `@supabase/auth-helpers-nextjs`.\n3. Replace all imports of `@supabase/supabase-auth-helpers/react` in your project with `@supabase/auth-helpers-react`.\n4. Replace all instances of `withAuthRequired` in any of your NextJS pages with `withPageAuth`.\n5. Replace all instances of `withAuthRequired` in any of your NextJS API endpoints with `withApiAuth`.\n6. Uninstall `@supabase/supabase-auth-helpers`.\n","readmeFilename":"README.md"}