Overview
Authentication is where most security incidents start. Use a battle-tested provider and secure defaults.
Sessions
Prefer short-lived access tokens with HTTP-only refresh cookies. Never store secrets in the client bundle.
OAuth
callback
const { data, error } = await supabase.auth
.exchangeCodeForSession(code);
if (error) redirect("/login");Security
- Enforce MFA for admin roles.
- Rate-limit login and magic-link endpoints.
- Rotate and scope API keys; never log them.