Skip to content

feat: Add standard client headers - #1130

Merged
grdsdev merged 2 commits into
mainfrom
guilherme/clibs-120-supabase-flutter-send-standard-client-headers-on-all
May 5, 2025
Merged

grdsdev merged 2 commits into
mainfrom
guilherme/clibs-120-supabase-flutter-send-standard-client-headers-on-all

Conversation

@grdsdev

@grdsdev grdsdev commented Mar 12, 2025

Copy link
Copy Markdown
Contributor

What kind of change does this PR introduce?

Bug fix, feature, docs update, ...

What is the current behavior?

Please link any relevant issues here.

What is the new behavior?

Feel free to include screenshots if it includes visual changes.

Additional context

Add any other context or screenshots.

@linear

linear Bot commented Mar 12, 2025

Copy link
Copy Markdown

@coveralls

coveralls commented Mar 12, 2025 •

Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 14836594270

Details

  • 8 of 8 (100.0%) changed or added relevant lines in 1 file are covered.
  • 2 unchanged lines in 1 file lost coverage.
  • Overall coverage increased (+0.03%) to 75.4%

Files with Coverage Reduction New Missed Lines %
packages/supabase/lib/src/supabase_client.dart 2 67.74%
Totals Coverage Status
Change from base Build 14836498956: 0.03%
Covered Lines: 2878
Relevant Lines: 3817

💛 - Coveralls

@grdsdev grdsdev changed the title feat: add standard client headers feat: Add standard client headers Mar 12, 2025
class Constants {
static const Map<String, String> defaultHeaders = {
static String get platform {
return Platform.operatingSystem;

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I know this is still draft, but still want to mention that this won't work on web.
You will either need a conditional import, or probably better use a constant to guard web with a definition like the kIsWeb in flutter:

const bool kIsWeb = bool.fromEnvironment('dart.library.js_util');

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, @Vinzent03

Do we have any test for asserting that it doesn't break in Web? Didn't see any fail on CI.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sadly not yet, but hopefully #1140 solves this

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Vinzent03 I added the guard as you suggested, we could send data in case of web, if that is easy to do, not a requirement since our reports also fetches from the user-agent, and user-agent in web is better defined then mobile.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, I think using the user-agent is the better and correct way for web.

@grdsdev
grdsdev force-pushed the guilherme/clibs-120-supabase-flutter-send-standard-client-headers-on-all branch from 3e7b4aa to 070966e Compare May 2, 2025 09:20
@grdsdev
grdsdev marked this pull request as ready for review May 2, 2025 09:25
@grdsdev
grdsdev force-pushed the guilherme/clibs-120-supabase-flutter-send-standard-client-headers-on-all branch from 070966e to b0af382 Compare May 5, 2025 12:36
@grdsdev
grdsdev requested review from Vinzent03 and dshukertjr May 5, 2025 12:42
@grdsdev
grdsdev merged commit f33c9fe into main May 5, 2025
@grdsdev
grdsdev deleted the guilherme/clibs-120-supabase-flutter-send-standard-client-headers-on-all branch May 5, 2025 19:54
spydon added a commit that referenced this pull request Jul 17, 2026
…cognized sb_ key subtype (#1615)

## Summary

Parity with supabase-js and supabase-swift
([#1130](supabase/supabase-swift#1130)) for the
new Supabase API key format (`sb_publishable_…` / `sb_secret_…`). These
keys are not JWTs and must never be sent as an `Authorization: Bearer`
token.

- **Functions never sends a new-format key as Bearer.** The
`Authorization: Bearer` header for Functions (and REST/Storage) is
injected per request by the shared `AuthHttpClient`. When no user
session exists it previously fell back to the API key, so a
`sb_publishable_`/`sb_secret_` key was sent as `Bearer …`, which the
Edge Functions runtime rejects. The Functions client now uses a
dedicated `AuthHttpClient` that omits the Bearer header for a new-format
key when there is no session. A genuine session JWT is still sent
normally.
- **Warn on unrecognized `sb_` subtypes.** `SupabaseClient` now warns
once per unrecognized `sb_`-prefixed key subtype at construction. It
never throws (the server, not the SDK, decides key validity) and never
logs the key value.

Scope matches the reference implementations: this affects Functions
only. Legacy JWT keys, REST, Storage, Auth, and Realtime are unchanged.

## Implementation notes

Unlike supabase-swift/js, supabase-flutter injects the Bearer token
through a **shared** `AuthHttpClient` used by REST, Functions, and
Storage, and `FunctionsClient.setAuth` is never wired up from
`SupabaseClient`. To keep the fix scoped to Functions, a separate
`AuthHttpClient` instance (`omitNewApiKeyAsBearer: true`) is created for
the Functions client instead of changing auth-state handling.

## Changes

- `packages/supabase/lib/src/api_key.dart` (new): `isNewApiKey`
classification and `warnOnUnrecognizedApiKey` warn-once helper.
- `packages/supabase/lib/src/auth_http_client.dart`:
`omitNewApiKeyAsBearer` flag suppressing the Bearer header for
new-format keys with no session.
- `packages/supabase/lib/src/supabase_client.dart`: dedicated Functions
`AuthHttpClient`; warn at construction.
- `packages/supabase/test/api_key_test.dart` (new): classification,
warn-once/no-key-leak, and all Bearer-suppression cases.

## Test plan

- [x] `dart analyze` — clean
- [x] `dart test` (supabase package) — all 91 tests pass, including the
8 new ones
- [x] `dart format` run
Vinzent03 pushed a commit that referenced this pull request Jul 28, 2026
…cognized sb_ key subtype (#1615)

## Summary

Parity with supabase-js and supabase-swift
([#1130](supabase/supabase-swift#1130)) for the
new Supabase API key format (`sb_publishable_…` / `sb_secret_…`). These
keys are not JWTs and must never be sent as an `Authorization: Bearer`
token.

- **Functions never sends a new-format key as Bearer.** The
`Authorization: Bearer` header for Functions (and REST/Storage) is
injected per request by the shared `AuthHttpClient`. When no user
session exists it previously fell back to the API key, so a
`sb_publishable_`/`sb_secret_` key was sent as `Bearer …`, which the
Edge Functions runtime rejects. The Functions client now uses a
dedicated `AuthHttpClient` that omits the Bearer header for a new-format
key when there is no session. A genuine session JWT is still sent
normally.
- **Warn on unrecognized `sb_` subtypes.** `SupabaseClient` now warns
once per unrecognized `sb_`-prefixed key subtype at construction. It
never throws (the server, not the SDK, decides key validity) and never
logs the key value.

Scope matches the reference implementations: this affects Functions
only. Legacy JWT keys, REST, Storage, Auth, and Realtime are unchanged.

## Implementation notes

Unlike supabase-swift/js, supabase-flutter injects the Bearer token
through a **shared** `AuthHttpClient` used by REST, Functions, and
Storage, and `FunctionsClient.setAuth` is never wired up from
`SupabaseClient`. To keep the fix scoped to Functions, a separate
`AuthHttpClient` instance (`omitNewApiKeyAsBearer: true`) is created for
the Functions client instead of changing auth-state handling.

## Changes

- `packages/supabase/lib/src/api_key.dart` (new): `isNewApiKey`
classification and `warnOnUnrecognizedApiKey` warn-once helper.
- `packages/supabase/lib/src/auth_http_client.dart`:
`omitNewApiKeyAsBearer` flag suppressing the Bearer header for
new-format keys with no session.
- `packages/supabase/lib/src/supabase_client.dart`: dedicated Functions
`AuthHttpClient`; warn at construction.
- `packages/supabase/test/api_key_test.dart` (new): classification,
warn-once/no-key-leak, and all Bearer-suppression cases.

## Test plan

- [x] `dart analyze` — clean
- [x] `dart test` (supabase package) — all 91 tests pass, including the
8 new ones
- [x] `dart format` run
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants