# Supabase Auth solution docs

- [Logged out after an hour: Supabase cookie refresh in the App Router](https://agenticboilerplate.com/cookbook/supabase-auth/cookie-refresh-in-the-app-router): Access tokens expire hourly and Server Components cannot write cookies, so the refresh has to happen in the proxy and be returned on the same response object.
- [getSession() vs getUser(): the Supabase trust trap](https://agenticboilerplate.com/cookbook/supabase-auth/getsession-vs-getuser): getSession() decodes a cookie the browser controls; getUser() verifies it with the auth server. On the server, only one of them is a security check.
- [Admin impersonation on Supabase Auth, bound to one session](https://agenticboilerplate.com/cookbook/supabase-auth/impersonation-bound-to-one-session): Supabase Auth has no "view as user". Build it from a server-side magic link plus an app_metadata marker tied to the new session id, so only that session is flagged and nobody can forge it.
- [Migrating an app that only ever used the anon key](https://agenticboilerplate.com/cookbook/supabase-auth/migrating-from-anon-key-only-access): Tables with RLS off are public. Turn it on table by table behind a feature switch, write the policies, and fix the queries the policies break, in that order.
- [Show only the OAuth buttons your Supabase project has switched on](https://agenticboilerplate.com/cookbook/supabase-auth/oauth-buttons-from-auth-settings): Read the public /auth/v1/settings endpoint on the server, cache it, and fail closed, so a sign-in page never shows a Google button that ends on an error page.
- [RLS policy patterns for multi-tenant rows](https://agenticboilerplate.com/cookbook/supabase-auth/rls-patterns-for-multi-tenant-rows): Owner-scoped, org-scoped and role-scoped policies, the with-check clause people forget, and the indexes that stop a policy from turning every read into a scan.
- [The blast radius of a leaked Supabase service-role key](https://agenticboilerplate.com/cookbook/supabase-auth/service-role-key-blast-radius): The key bypasses every policy for every table. Here is how it leaks, what an attacker gets, how to contain it, and how to make the leak impossible.

---

Agentic Boilerplate: A Next.js repo your agent already knows. Free during launch, then $99 once.

- Site map for agents: https://agenticboilerplate.com/llms.txt
- Public API: https://agenticboilerplate.com/openapi.json
- Contact: agenticstudio@gmail.com
