| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
|
@supabase/auth-js
npm i https://pkg.pr.new/@supabase/auth-js@2511
npm i https://pkg.pr.new/@supabase/functions-js@2511
npm i https://pkg.pr.new/@supabase/postgrest-js@2511
npm i https://pkg.pr.new/@supabase/realtime-js@2511
npm i https://pkg.pr.new/@supabase/storage-js@2511
npm i https://pkg.pr.new/@supabase/supabase-js@2511 commit: 7500549 |
Sorry, something went wrong.
Sorry, something went wrong.
…ader logic Future-proof the sb_ key family per auth-team guidance (stojan): createClient() now validates the key format at construction and throws for a key that starts with sb_ but is not a recognized subtype (sb_publishable_ / sb_secret_), signalling that the SDK must be upgraded to support the new type. Legacy JWT keys (no sb_ prefix) and the two recognized subtypes are unaffected, so no key that works today starts failing — this is not a breaking change. Also addresses review feedback on fetch.ts: - rename the fetchWithAuth option isFunctionsClient -> omitApiKeyAsBearer so the generic util no longer knows about a "functions client" - compute the key-as-Bearer decision once at construction instead of per request - drop the accessToken === supabaseKey equality proxy; split a raw _getSessionToken() (null when no session) from the coalescing _getAccessToken(), and feed the raw getter to the fetch wrappers so Authorization fallback lives in one place - collapse the triplicated rationale comment to a single canonical location Realtime keeps using _getAccessToken(); PostgREST/Storage behavior is unchanged.
There was a problem hiding this comment.
LGTM 💚
Sorry, something went wrong.
This PR updates `@supabase/supabase-js` to v2.110.5. **Source**: supabase-js-stable-release --- ## Release Notes ## v2.110.5 ## 2.110.5 (2026-07-14) ### 🩹 Fixes - **supabase:** avoid edge runtime warning ([#2522](supabase/supabase-js#2522)) ### ❤️ Thank You - Vaibhav @7ttp ## v2.110.4 ## 2.110.4 (2026-07-14) ### 🩹 Fixes - **functions:** stop sending API key in Authorization header for function calls ([#2511](supabase/supabase-js#2511)) - **realtime:** encode broadcast header fields as UTF-8 ([#2516](supabase/supabase-js#2516)) ### ❤️ Thank You - Katerina Skroumpelou @mandarini - Pedro Henrique This PR was created automatically. Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
This PR updates @supabase/*-js libraries to version 2.110.5. **Source**: supabase-js-stable-release **Changes**: - Updated @supabase/supabase-js to 2.110.5 - Updated @supabase/auth-js to 2.110.5 - Updated @supabase/realtime-js to 2.110.5 - Updated @supabase/postgest-js to 2.110.5 - Refreshed pnpm-lock.yaml --- ## Release Notes ## v2.110.5 ## 2.110.5 (2026-07-14) ### 🩹 Fixes - **supabase:** avoid edge runtime warning ([#2522](supabase/supabase-js#2522)) ### ❤️ Thank You - Vaibhav @7ttp ## v2.110.4 ## 2.110.4 (2026-07-14) ### 🩹 Fixes - **functions:** stop sending API key in Authorization header for function calls ([#2511](supabase/supabase-js#2511)) - **realtime:** encode broadcast header fields as UTF-8 ([#2516](supabase/supabase-js#2516)) ### ❤️ Thank You - Katerina Skroumpelou @mandarini - Pedro Henrique ## v2.110.3 ## 2.110.3 (2026-07-13) ### 🩹 Fixes - **auth:** preserve pkce verifier ([#2513](supabase/supabase-js#2513)) - **postgrest:** pin tstyche target off floating latest ([#2509](supabase/supabase-js#2509)) ### ❤️ Thank You - Katerina Skroumpelou @mandarini - Vaibhav @7ttp ## v2.110.2 ## 2.110.2 (2026-07-09) ### 🩹 Fixes - **auth:** clear local session on signout failures ([#2504](supabase/supabase-js#2504)) ### ❤️ Thank You - Luc Peng This PR was created automatically. Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
This PR updates @supabase/*-js libraries to version 2.110.6. **Source**: supabase-js-stable-release **Changes**: - Updated @supabase/supabase-js to 2.110.6 - Updated @supabase/auth-js to 2.110.6 - Updated @supabase/realtime-js to 2.110.6 - Updated @supabase/postgest-js to 2.110.6 - Refreshed pnpm-lock.yaml --- ## Release Notes ## v2.110.6 ## 2.110.6 (2026-07-15) ### 🩹 Fixes - **postgrest:** type hinted self-referencing embeds as arrays ([#2520](supabase/supabase-js#2520)) - **realtime:** forward opts to send() in track() ([#2490](supabase/supabase-js#2490)) - **supabase:** warn instead of throw for unrecognized sb_ API key subtypes ([#2526](supabase/supabase-js#2526)) ### ❤️ Thank You - Franco Kaddour @FrancoKaddour - Katerina Skroumpelou @mandarini ## v2.110.5 ## 2.110.5 (2026-07-14) ### 🩹 Fixes - **supabase:** avoid edge runtime warning ([#2522](supabase/supabase-js#2522)) ### ❤️ Thank You - Vaibhav @7ttp ## v2.110.4 ## 2.110.4 (2026-07-14) ### 🩹 Fixes - **functions:** stop sending API key in Authorization header for function calls ([#2511](supabase/supabase-js#2511)) - **realtime:** encode broadcast header fields as UTF-8 ([#2516](supabase/supabase-js#2516)) ### ❤️ Thank You - Katerina Skroumpelou @mandarini - Pedro Henrique ## v2.110.3 ## 2.110.3 (2026-07-13) ### 🩹 Fixes - **auth:** preserve pkce verifier ([#2513](supabase/supabase-js#2513)) - **postgrest:** pin tstyche target off floating latest ([#2509](supabase/supabase-js#2509)) ### ❤️ Thank You - Katerina Skroumpelou @mandarini - Vaibhav @7ttp ## v2.110.2 ## 2.110.2 (2026-07-09) ### 🩹 Fixes - **auth:** clear local session on signout failures ([#2504](supabase/supabase-js#2504)) ### ❤️ Thank You - Luc Peng This PR was created automatically. Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
| Back | FazBrowse Home | New Git URL |
Description
Edge Function calls (supabase.functions.invoke()) no longer put the project API key in the Authorization header when there is no user session. The key is sent only in the apikey header, and Authorization is reserved for a real user (or custom) session token, matching the Server SDK pattern.
What changed?
Why was this change needed?
New-format API keys (sb_publishable_... / sb_secret_...) are not JWTs, so sending them as Authorization: Bearer <key> caused the gateway to reject the request with "invalid token format." A platform apikey-compatibility patch (now GA) lets verify_jwt=true functions be called with only the apikey header, so the SDK no longer needs to duplicate the key into Authorization. This aligns Functions with the Server SDK convention: Authorization is for user/custom tokens only.
Closes SDK-1050.
Screenshots/Examples
Unauthenticated function call with a new-format key:
Before:
After:
Authenticated call (unchanged):
Breaking changes
The change is scoped to Edge Functions only, and legacy JWT keys keep their existing behavior (still sent in Authorization for backward compatibility), so this is not a breaking change in practice. The only impacted case is code that reads the API key out of the Authorization header inside an Edge Function; those should read the apikey header instead, or migrate to @supabase/server.
Checklist
Additional notes
Scope is intentionally limited to new-format keys so there is zero regression risk for self-hosted or legacy-key users on older gateways. Moving to an unconditional drop for all key types later is a one-line change (removing the key-format guard in fetch.ts), best done on v3 or once apikey-compatibility is universal.