{"_id":"@dalkommatt/supabase-safesession","_rev":"2-929e3462ff2233f9af59e043ab82dc30","name":"@dalkommatt/supabase-safesession","dist-tags":{"latest":"0.2.5"},"versions":{"0.2.0":{"name":"@dalkommatt/supabase-safesession","version":"0.2.0","keywords":["Supabase","Auth","Next.js","Server Components"],"author":{"name":"Zanzofily"},"license":"MIT","_id":"@dalkommatt/supabase-safesession@0.2.0","maintainers":[{"name":"dalkommatt","email":"mr.matthewc.king@gmail.com"}],"homepage":"https://github.com/dalkommatt/supabase-safesession#readme","bugs":{"url":"https://github.com/dalkommatt/supabase-safesession/issues"},"dist":{"shasum":"8889662017a21396208cfaf634d1875882ee38d0","tarball":"https://registry.npmjs.org/@dalkommatt/supabase-safesession/-/supabase-safesession-0.2.0.tgz","fileCount":8,"integrity":"sha512-HL0cq5WVOa/xtMDPAviuHlvFv71qGJjI/Cq52DMmvJT3EQjbm/IajJ3hqjGvZKTnqJanUeF/6Qr3BpMuT85BGw==","signatures":[{"sig":"MEQCIH7HFf2Stl7LHlbG5Ez8xNXy2QyDktCDqUu6gCytR+gSAiBCkLKbxeNh17fYrA/QbEv+4v7ZBiDpgyv/qbMWxfmrIw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":30867},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"9d8d270e5008916575c75a5314b11284547dadaf","scripts":{"lint":"tsc --noEmit","build":"tsup --config tsup.config.ts","prepublish":"npm run build"},"_npmUser":{"name":"dalkommatt","email":"mr.matthewc.king@gmail.com"},"repository":{"url":"git+https://github.com/dalkommatt/supabase-safesession.git","type":"git"},"_npmVersion":"9.6.2","description":"A secure tool designed for server-side user session management in applications using Supabase.","directories":{},"_nodeVersion":"20.15.1","dependencies":{"server-only":"^0.0.1","jsonwebtoken":"^9.0.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","typescript":"^5.6.2","@types/cookie":"^0.6.0","@types/jsonwebtoken":"^9.0.7"},"peerDependencies":{"next":"canary","@supabase/ssr":"^0.5.1","@supabase/supabase-js":"^2"},"_npmOperationalInternal":{"tmp":"tmp/supabase-safesession_0.2.0_1728315289103_0.48872591726551073","host":"s3://npm-registry-packages"}},"0.2.1":{"name":"@dalkommatt/supabase-safesession","version":"0.2.1","keywords":["Supabase","Auth","Next.js","Server Components"],"author":{"name":"Zanzofily"},"license":"MIT","_id":"@dalkommatt/supabase-safesession@0.2.1","maintainers":[{"name":"dalkommatt","email":"mr.matthewc.king@gmail.com"}],"homepage":"https://github.com/dalkommatt/supabase-safesession#readme","bugs":{"url":"https://github.com/dalkommatt/supabase-safesession/issues"},"dist":{"shasum":"4dbce272cf4d4356e74a46b31333d13f905099b4","tarball":"https://registry.npmjs.org/@dalkommatt/supabase-safesession/-/supabase-safesession-0.2.1.tgz","fileCount":8,"integrity":"sha512-E/+DtyEPVh2C/X+9CqpoUW6ZSvRc/psCOCdoU5FLrr7poz2V/tyCtjDxWInCl0FeN+H8NDLdMBxvCMw20PHehg==","signatures":[{"sig":"MEUCIQDflcTpTBadXLeIw3bFiF5QIfKXrzS5Nkj97SI4XyIfgAIgMbizItbLdW4QmTZMGPaf8wENez1IAs3H82NOkJy5uuk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":30867},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"889b0a11385549e7b5f644b81b95a9547f857e27","scripts":{"lint":"tsc --noEmit","build":"tsup --config tsup.config.ts","prepublish":"npm run build"},"_npmUser":{"name":"dalkommatt","email":"mr.matthewc.king@gmail.com"},"repository":{"url":"git+https://github.com/dalkommatt/supabase-safesession.git","type":"git"},"_npmVersion":"9.6.2","description":"A secure tool designed for server-side user session management in applications using Supabase.","directories":{},"_nodeVersion":"20.15.1","dependencies":{"server-only":"^0.0.1","jsonwebtoken":"^9.0.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","typescript":"^5.6.2","@types/cookie":"^0.6.0","@types/jsonwebtoken":"^9.0.7"},"peerDependencies":{"next":"canary","@supabase/ssr":"^0.5.1","@supabase/supabase-js":"^2"},"_npmOperationalInternal":{"tmp":"tmp/supabase-safesession_0.2.1_1728316225590_0.24515197759708962","host":"s3://npm-registry-packages"}},"0.2.5":{"name":"@dalkommatt/supabase-safesession","version":"0.2.5","main":"dist/index.js","types":"dist/index.d.ts","publishConfig":{"access":"public"},"scripts":{"build":"tsup --config tsup.config.ts","lint":"tsc --noEmit","prepublish":"npm run build"},"repository":{"type":"git","url":"git+https://github.com/dalkommatt/supabase-safesession.git"},"keywords":["Supabase","Auth","Next.js","Server Components"],"author":{"name":"Zanzofily"},"license":"MIT","bugs":{"url":"https://github.com/dalkommatt/supabase-safesession/issues"},"homepage":"https://github.com/dalkommatt/supabase-safesession#readme","dependencies":{"jsonwebtoken":"^9.0.2","server-only":"^0.0.1"},"devDependencies":{"@types/cookie":"^0.6.0","@types/jsonwebtoken":"^9.0.7","tsup":"^8.3.0","typescript":"^5.6.2"},"peerDependencies":{"@supabase/ssr":"^0.5.1","@supabase/supabase-js":"^2","next":"canary"},"gitHead":"cf034de3fe11f108462d399ad5f80b38cfcbc4b0","description":"A secure tool designed for server-side user session management in applications using Supabase.","_id":"@dalkommatt/supabase-safesession@0.2.5","_nodeVersion":"20.15.1","_npmVersion":"9.6.2","dist":{"integrity":"sha512-bXBs4CJ99Nu3NdTcNa9vIE8cr+lrBEfdSB0PwtJIBmZvF9Rs8yevHwCRk85Xve7jWF/F1J+fSCwJfYlvgixBmA==","shasum":"32cae47665bd93359b6bd3c9d31759b612f5e3b1","tarball":"https://registry.npmjs.org/@dalkommatt/supabase-safesession/-/supabase-safesession-0.2.5.tgz","fileCount":8,"unpackedSize":30867,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC/gKSu88tGlDf11KCnqNxsUvXgLmdNrG8oK+z9Q0s3qAIhAI53Y6D1ldwwHDvLNv5eFGO4illlIGKWs8+pehKTEU/p"}]},"_npmUser":{"name":"dalkommatt","email":"mr.matthewc.king@gmail.com"},"directories":{},"maintainers":[{"name":"dalkommatt","email":"mr.matthewc.king@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/supabase-safesession_0.2.5_1728318354509_0.20490611725373453"},"_hasShrinkwrap":false}},"time":{"created":"2024-10-07T15:34:49.023Z","modified":"2024-10-07T16:25:54.933Z","0.2.0":"2024-10-07T15:34:49.317Z","0.2.1":"2024-10-07T15:50:25.795Z","0.2.5":"2024-10-07T16:25:54.739Z"},"bugs":{"url":"https://github.com/dalkommatt/supabase-safesession/issues"},"author":{"name":"Zanzofily"},"license":"MIT","homepage":"https://github.com/dalkommatt/supabase-safesession#readme","keywords":["Supabase","Auth","Next.js","Server Components"],"repository":{"type":"git","url":"git+https://github.com/dalkommatt/supabase-safesession.git"},"description":"A secure tool designed for server-side user session management in applications using Supabase.","maintainers":[{"name":"dalkommatt","email":"mr.matthewc.king@gmail.com"}],"readme":"# supabase-safesession\r\n\r\nA secure tool designed for server-side user session management in applications using Supabase.\r\n\r\n## Glossary\r\n\r\n### Background\r\n\r\nThe default Supabase auth client lacks optimal compatibility with server components, leading to potential security risks and performance issues.\r\n\r\n### Database Overload\r\n\r\nUsing Supabase's `auth.getUser()` method in server components triggers a unique backend request each time, potentially resulting in a large number of database queries. This can significantly slow down your system. Below is a screenshot from a Supabase dashboard showing the frequency of queries for a single user with minimal server components:\r\n\r\n![Supabase frequent queries tab](docs/supabase-queries.png)\r\n\r\n### Security Concerns\r\n\r\nThe typical approach of using `getUser` once in middleware and then relying on `getSession` is problematic. The `getUser` method validates a JWT based solely on its format and expiry, not its authenticity, accepting any correctly formatted JWT as valid.\r\n\r\n## Alternative Approach\r\n\r\n`supabase-safesession` utilizes `jsonwebtoken` to securely verify sessions without unnecessary database queries, focusing primarily on user ID to manage user-related data efficiently. It also handles expired tokens, leveraging Supabase to refresh tokens and update cookies accordingly.\r\n\r\n## Quick Start\r\n\r\n### Configuration\r\n\r\n1. Retrieve your JWT secret from the Supabase project settings (API tab) and add it to your `.env` file.\r\n\r\n### Setup\r\n\r\n2. Install the package:\r\n\r\n```bash\r\nnpm i supabase-safesession\r\n```\r\n\r\n3. Create a Supabase server client and initialize `AuthManager`:\r\n\r\n```typescript\r\nimport { createServerClient, type CookieOptions } from \"@supabase/ssr\";\r\nimport { cookies } from \"next/headers\";\r\nimport { AuthManager } from \"supabase-safesession\";\r\n\r\nexport function createSupabaseServerClient() {\r\n  const cookieStore = cookies();\r\n\r\n  return createServerClient(\r\n    process.env.NEXT_PUBLIC_SUPABASE_URL!,\r\n    process.env.NEXT_PUBLIC_SUPABASE_ANON_KEY!,\r\n    {\r\n      cookies: {\r\n        get(name: string) {\r\n          return cookieStore.get(name)?.value;\r\n        },\r\n        set(name: string, value: string, options: CookieOptions) {\r\n          try {\r\n            cookieStore.set({ name, value, ...options });\r\n          } catch (error) {\r\n            console.error(\"Error setting cookie in server component:\", error);\r\n          }\r\n        },\r\n        remove(name: string, options: CookieOptions) {\r\n          try {\r\n            cookieStore.delete({ name, ...options });\r\n          } catch (error) {\r\n            console.error(\"Error removing cookie in server component:\", error);\r\n          }\r\n        },\r\n      },\r\n    }\r\n  );\r\n}\r\n// Export the initialized Supabase client and AuthManager\r\nexport const supabaseServerClient = () => createSupabaseServerClient();\r\nexport const supabaseServerAuth = () =>\r\n  new AuthManager(supabaseServerClient(), process.env.SUPABASE_JWT_SECRET!);\r\n```\r\n\r\n4. use `AuthManager` inside your server components:\r\n\r\n```typescript\r\nexport default async function ExampleComponent() {\r\n  const {\r\n    data: session,\r\n    status,\r\n    error,\r\n  } = await supabaseServerAuth.getSafeSession();\r\n\r\n  // Implement component logic using the session data\r\n  return <div>User session status: {status}</div>;\r\n}\r\n```\r\n","readmeFilename":"README.md"}