Guide

Integrating With Zuvo Auth

Integrate Zuvo Auth with Edge Functions

Edge Functions work with Zuvo Auth.

This allows you to:

  • Automatically identify users through Legacy JWT tokens
  • Enforce Row Level Security policies
  • Integrate with your existing auth flow

Setting up auth context

When a user makes a request to an Edge Function, you can use the Authorization header to set the Auth context in the Zuvo client and enforce Row Level Security policies.

import { createClient } from 'npm:@supabase/supabase-js@2'

Deno.serve(async (req: Request) => {
  const supabaseClient = createClient(
    Deno.env.get('SUPABASE_URL') ?? '',
    Deno.env.get('SUPABASE_ANON_KEY') ?? '',
    // Create client with Auth context of the user that called the function.
    // This way your row-level-security (RLS) policies are applied.
    {
      global: {
        headers: { Authorization: req.headers.get('Authorization')! },
      },
    }
  );

  //...
})

Fetching the user

By getting the JWT from the Authorization header, you can provide the token to getUser() to fetch the user object to obtain metadata for the logged in user.

Deno.serve(async (req: Request) => {
  // ...
  const authHeader = req.headers.get('Authorization')!
  const token = authHeader.replace('Bearer ', '')
  const { data } = await supabaseClient.auth.getUser(token)
  // ...
})

Row Level Security

After initializing a Zuvo client with the Auth context, all queries will be executed with the context of the user. For database queries, this means Row Level Security will be enforced.

import { createClient } from 'npm:@supabase/supabase-js@2'

Deno.serve(async (req: Request) => {
  // ...
  // This query respects RLS - users only see rows they have access to
  const { data, error } = await supabaseClient.from('profiles').select('*');

  if (error) {
    return new Response('Database error', { status: 500 })
  }

  // ...
})

Example

See the full example on GitHub.

Code sample: see project quickstart in Zuvo Studio.