Repository navigation
Proxy: stop paying a Supabase round trip on every request - #172
Merged
Merged
Conversation
Vercel flagged 75% of the Hobby Fluid provisioned memory allowance. Every page is client-rendered, so the proxy is nearly the only server work, and it awaited supabase.auth.getUser() (a network call to Auth) on every matched request, public or not, including every MCP call and static files like the manifest and fonts. - Public paths other than '/' and '/auth' return before any Supabase client is made. The MCP connector and OAuth routes do their own auth. - getUser() becomes getClaims(), which verifies the JWT locally against the cached JWKS when the project uses asymmetric signing keys. - The matcher skips anything with a file extension; isPublicPath already waved those through. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_011hdAG7Aq4BQEH7NVpMAiQP
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Vercel emailed that the Hobby team is at 75% of the Fluid provisioned memory allowance (360 GB-hrs). Every page is client-rendered, so
proxy.tsis close to the only server work, and it was awaitingsupabase.auth.getUser()(a network call to Supabase Auth) on every matched request. That covered public pages, every MCP call, and static files like the manifest and fonts. Provisioned memory gets billed for all the time spent waiting on that call./and/authnow return before any Supabase client gets created. The MCP connector and the OAuth routes do their own auth.getUser()is nowgetClaims(). It still verifies the JWT signature and refreshes tokens that are about to expire. When the project uses asymmetric signing keys it does the check locally against the cached JWKS, with no Auth round trip.isPublicPathalready let those through, so matching them just cost a function call each.Private routes behave the same as before: no session means a redirect to
/auth, theno-storeheader is still set, and signed-in visits to/or/authstill go to/dashboard.Checks:
npm run typecheckandnpm run lintpass. I also tested the new matcher regex against the main paths (/dashboard,/api/mcp,/opengraph-imagematch;/robots.txt,/manifest.webmanifest, fonts and_next/staticdon't).🤖 Generated with Claude Code
https://claude.ai/code/session_011hdAG7Aq4BQEH7NVpMAiQP
Generated by Claude Code