fix(auth): route server-side Supabase calls via internal URL to avoid edge rate-limit

Server-side Supabase calls (middleware getUser/refresh, server components,
admin client) all egress through the Docker gateway as a single NATed IP and
traverse Caddy's per-IP /auth/* rate limiter (8 events/s). A handful of active
users saturate that shared bucket, 429ing getUser()/token refresh; the
middleware then treats the session as invalid and bounces to /login, while a
manual refresh lands under budget and works again.

Add SUPABASE_INTERNAL_URL (e.g. http://kong-prod:8000) used only by the
server-side clients (middleware, lib/supabase/server.ts, admin getSupabaseAdmin
/getSupabaseAnon), falling back to the public URL when unset. Browser clients
keep the public URL so real per-user-IP edge rate limiting still applies.

Also bake the arg in the Dockerfile/build and make the web-prod network alias
durable via WEB_ALIAS (dev sets web-dev) so the dev container can't reclaim the
web-prod alias on redeploy.
This commit is contained in:
Gerhard Scheikl
2026-06-02 12:45:10 +02:00
parent 9f8477f16f
commit fa457de8ec
5 changed files with 29 additions and 6 deletions
+6 -1
View File
@@ -4,7 +4,8 @@
# supplied via env vars resolved from the project-dir ".env" file
# (in prod and dev that is a symlink -> .env.production). The defaults below are
# the PRODUCTION values, so prod works with no extra vars; the dev worktree's
# .env.production sets WEB_PROJECT / WEB_IMAGE / WEB_CONTAINER / WEB_NETWORK.
# .env.production sets WEB_PROJECT / WEB_IMAGE / WEB_CONTAINER / WEB_NETWORK /
# WEB_ALIAS (and SUPABASE_INTERNAL_URL for the internal API hostname).
name: ${WEB_PROJECT:-web}
services:
web:
@@ -15,6 +16,7 @@ services:
NEXT_PUBLIC_SUPABASE_URL: ${NEXT_PUBLIC_SUPABASE_URL}
NEXT_PUBLIC_SUPABASE_ANON_KEY: ${NEXT_PUBLIC_SUPABASE_ANON_KEY}
NEXT_PUBLIC_APP_URL: ${NEXT_PUBLIC_APP_URL}
SUPABASE_INTERNAL_URL: ${SUPABASE_INTERNAL_URL:-}
image: ${WEB_IMAGE:-web:1.0.0}
container_name: ${WEB_CONTAINER:-web}
restart: unless-stopped
@@ -29,6 +31,9 @@ services:
networks:
default:
aliases:
# PROD defaults to web-prod; dev's .env.production sets WEB_ALIAS=web-dev
# so the dev container does NOT also claim the web-prod alias (which
# would make Caddy round-robin prod traffic onto the dev build).
- ${WEB_ALIAS:-web-prod}
healthcheck:
test: ["CMD", "wget", "-qO-", "http://127.0.0.1:3000/"]