fix(auth): namespace edge functions, restore miniapp sign-in

The Supabase edge-function volume on the host is shared with pwap-web, which
deploys into it by rsyncing its whole tree. Both projects defined a function
called telegram-auth, so on 2026-06-28 pwap-web's login-widget handler replaced
this project's initData handler. Sign-in and every wallet screen behind it have
returned 401 ever since; nothing failed loudly because the name still resolved.

Rename this project's two colliding functions to a tgm- namespace so the two
deploys can no longer reach the same directory, and point the client at the new
name. process-withdraw is renamed too: it is currently unreferenced here, but it
moves platform funds, so leaving it shadowed by another project's version is not
something to keep.

Also deploy functions from CI. They were last pushed by hand in April, so seven
of them had drifted behind the repo and one had never shipped at all. The new
step writes through the host's ownership gate, which refuses any name this
project does not own — the drift and the collision both stop here.

Ownership is recorded in /opt/supabase-self-hosted/functions-registry.json.
This commit is contained in:
2026-07-29 20:21:37 -07:00
parent 06eb6ae5e7
commit 54f565621c
6 changed files with 49 additions and 5 deletions
+41
View File
@@ -63,3 +63,44 @@ jobs:
username: ${{ secrets.VPS2_USER }}
key: ${{ secrets.VPS2_SSH_KEY }}
script: bash /opt/cleanup-miniapp.sh
# Edge functions live in a Supabase volume shared with other projects, so they
# are written through the ownership gate on the host rather than copied in
# directly. The gate refuses any name this project does not own, which is what
# stops a repeat of the 2026-06-28 incident where another project's deploy
# silently replaced telegram-auth and broke sign-in for a month.
deploy-functions:
name: Deploy edge functions
needs: deploy
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Package functions
run: tar czf functions.tgz -C supabase functions
- name: Copy to staging on VPS
uses: appleboy/scp-action@v1.0.0
with:
host: ${{ secrets.VPS2_HOST }}
username: ${{ secrets.VPS2_USER }}
key: ${{ secrets.VPS2_SSH_KEY }}
source: 'functions.tgz'
target: '/opt/miniapp-deploy-staging'
- name: Deploy through ownership gate
uses: appleboy/ssh-action@v1.0.0
with:
host: ${{ secrets.VPS2_HOST }}
username: ${{ secrets.VPS2_USER }}
key: ${{ secrets.VPS2_SSH_KEY }}
script: |
set -e
BASE=/opt/miniapp-deploy-staging
trap 'rm -rf "$BASE"' EXIT
rm -rf "$BASE/functions"
tar xzf "$BASE/functions.tgz" -C "$BASE"
supabase-deploy-functions \
--project pezkuwi-telegram-miniapp \
--src "$BASE/functions" \
--restart
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "pezkuwi-telegram-miniapp",
"version": "1.0.242",
"version": "1.0.243",
"type": "module",
"description": "Pezkuwichain Telegram Mini App - Forum, Announcements, Rewards",
"author": "Pezkuwichain Team",
+4 -1
View File
@@ -11,7 +11,10 @@ export async function signInWithTelegram(initData: string) {
throw new Error('No Telegram initData provided');
}
const { data, error } = await supabase.functions.invoke('telegram-auth', {
// Namespaced: the shared Supabase instance also hosts pwap-web, whose own
// login-widget handler owns the bare 'telegram-auth' name. See
// /opt/supabase-self-hosted/functions-registry.json on the host.
const { data, error } = await supabase.functions.invoke('tgm-telegram-auth', {
body: { initData },
});
+3 -3
View File
@@ -1,5 +1,5 @@
{
"version": "1.0.242",
"buildTime": "2026-07-21T14:51:23.002Z",
"buildNumber": 1784645483003
"version": "1.0.243",
"buildTime": "2026-07-30T03:21:37.873Z",
"buildNumber": 1785381697873
}