From 54f565621c61da88d02d2efaecd6ebcd6ea62727 Mon Sep 17 00:00:00 2001 From: Satoshi Qazi Muhammed Date: Wed, 29 Jul 2026 20:21:37 -0700 Subject: [PATCH] fix(auth): namespace edge functions, restore miniapp sign-in MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The Supabase edge-function volume on the host is shared with pwap-web, which deploys into it by rsyncing its whole tree. Both projects defined a function called telegram-auth, so on 2026-06-28 pwap-web's login-widget handler replaced this project's initData handler. Sign-in and every wallet screen behind it have returned 401 ever since; nothing failed loudly because the name still resolved. Rename this project's two colliding functions to a tgm- namespace so the two deploys can no longer reach the same directory, and point the client at the new name. process-withdraw is renamed too: it is currently unreferenced here, but it moves platform funds, so leaving it shadowed by another project's version is not something to keep. Also deploy functions from CI. They were last pushed by hand in April, so seven of them had drifted behind the repo and one had never shipped at all. The new step writes through the host's ownership gate, which refuses any name this project does not own — the drift and the collision both stop here. Ownership is recorded in /opt/supabase-self-hosted/functions-registry.json. --- .github/workflows/deploy.yml | 41 +++++++++++++++++++ package.json | 2 +- src/lib/supabase.ts | 5 ++- src/version.json | 6 +-- .../index.ts | 0 .../index.ts | 0 6 files changed, 49 insertions(+), 5 deletions(-) rename supabase/functions/{process-withdraw => tgm-process-withdraw}/index.ts (100%) rename supabase/functions/{telegram-auth => tgm-telegram-auth}/index.ts (100%) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index a563e46..2740ea9 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -63,3 +63,44 @@ jobs: username: ${{ secrets.VPS2_USER }} key: ${{ secrets.VPS2_SSH_KEY }} script: bash /opt/cleanup-miniapp.sh + + # Edge functions live in a Supabase volume shared with other projects, so they + # are written through the ownership gate on the host rather than copied in + # directly. The gate refuses any name this project does not own, which is what + # stops a repeat of the 2026-06-28 incident where another project's deploy + # silently replaced telegram-auth and broke sign-in for a month. + deploy-functions: + name: Deploy edge functions + needs: deploy + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + + - name: Package functions + run: tar czf functions.tgz -C supabase functions + + - name: Copy to staging on VPS + uses: appleboy/scp-action@v1.0.0 + with: + host: ${{ secrets.VPS2_HOST }} + username: ${{ secrets.VPS2_USER }} + key: ${{ secrets.VPS2_SSH_KEY }} + source: 'functions.tgz' + target: '/opt/miniapp-deploy-staging' + + - name: Deploy through ownership gate + uses: appleboy/ssh-action@v1.0.0 + with: + host: ${{ secrets.VPS2_HOST }} + username: ${{ secrets.VPS2_USER }} + key: ${{ secrets.VPS2_SSH_KEY }} + script: | + set -e + BASE=/opt/miniapp-deploy-staging + trap 'rm -rf "$BASE"' EXIT + rm -rf "$BASE/functions" + tar xzf "$BASE/functions.tgz" -C "$BASE" + supabase-deploy-functions \ + --project pezkuwi-telegram-miniapp \ + --src "$BASE/functions" \ + --restart diff --git a/package.json b/package.json index 73458c5..6fd93af 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "pezkuwi-telegram-miniapp", - "version": "1.0.242", + "version": "1.0.243", "type": "module", "description": "Pezkuwichain Telegram Mini App - Forum, Announcements, Rewards", "author": "Pezkuwichain Team", diff --git a/src/lib/supabase.ts b/src/lib/supabase.ts index ab4e436..72091c8 100644 --- a/src/lib/supabase.ts +++ b/src/lib/supabase.ts @@ -11,7 +11,10 @@ export async function signInWithTelegram(initData: string) { throw new Error('No Telegram initData provided'); } - const { data, error } = await supabase.functions.invoke('telegram-auth', { + // Namespaced: the shared Supabase instance also hosts pwap-web, whose own + // login-widget handler owns the bare 'telegram-auth' name. See + // /opt/supabase-self-hosted/functions-registry.json on the host. + const { data, error } = await supabase.functions.invoke('tgm-telegram-auth', { body: { initData }, }); diff --git a/src/version.json b/src/version.json index 89e672c..7d8739d 100644 --- a/src/version.json +++ b/src/version.json @@ -1,5 +1,5 @@ { - "version": "1.0.242", - "buildTime": "2026-07-21T14:51:23.002Z", - "buildNumber": 1784645483003 + "version": "1.0.243", + "buildTime": "2026-07-30T03:21:37.873Z", + "buildNumber": 1785381697873 } diff --git a/supabase/functions/process-withdraw/index.ts b/supabase/functions/tgm-process-withdraw/index.ts similarity index 100% rename from supabase/functions/process-withdraw/index.ts rename to supabase/functions/tgm-process-withdraw/index.ts diff --git a/supabase/functions/telegram-auth/index.ts b/supabase/functions/tgm-telegram-auth/index.ts similarity index 100% rename from supabase/functions/telegram-auth/index.ts rename to supabase/functions/tgm-telegram-auth/index.ts