fix(auth): reject invalid optional credentials - #1078
Conversation
This pull request has been ignored for the connected project Preview Branches by Supabase. |
Uh oh!
There was an error while loading. Please reload this page.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit:f83bb6772f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Uh oh!
There was an error while loading. Please reload this page.
Summary
absent | valid | invalid.Verification
npm run verify:pr-local— final merged head passed; 360 files, 3,192 tests passed, 1 skipped; build and offline fixtures passednpm run verify:cheap— 21 gates; 360 files passed; 3,191 tests passed, 1 skippednpm exec vitest run tests/auth-tri-state.test.ts tests/account-access-model.test.ts tests/private-access-routes.test.ts— 3 files, 141 tests passed on the final merged headnpm run build— production build, TypeScript, 1,677 static pages, and client-bundle secret scan passednpm run check:rag:fixtures— 36 golden cases / 21 suites passed; no RAG behavior changednpm run check:production-readiness— code guards passed; clean worktree intentionally lacks.env.local, so Supabase/OpenAI configuration checks reported missing variables and no provider call was madeRed proof: before the implementation, the focused invalid-bearer test failed because
getOptionalAuthenticatedUserresolvednullinstead of rejecting.Risk and rollout
Clinical Governance Preflight
Clinical KB Database(sjrfecxgysukkwxsowpy)Notes