Skip to content

FE-M0-08 · Sign in on the local stack, then merge pack B

ID FE-M0-08 · Level L0 · Run order row 25

An E2E login signs in and out on the local stack, a signed-out visitor lands on /login, page loads don't call Supabase Auth, and pack B is merged.

  • FE-M0-07 is Done. The local stack is running.
  • You have the E2E admin login's email from BE-M0-25 and <E2E_PASSWORD>.
Terminal window
pnpm --filter web dev

2 · In a second terminal, in ~/opleet-v2/opleet: a signed-out visitor is sent to /login

Section titled “2 · In a second terminal, in ~/opleet-v2/opleet: a signed-out visitor is sent to /login”
Terminal window
curl -s -o /dev/null -D - http://localhost:3000/ | grep -i -E '^HTTP|^location'

3 · In the browser: open http://localhost:3000. Sign in as the E2E admin with a wrong password, then with <E2E_PASSWORD>. Reload the page three times.

Section titled “3 · In the browser: open http://localhost:3000. Sign in as the E2E admin with a wrong password, then with <E2E_PASSWORD>. Reload the page three times.”

4 · In the second terminal: Supabase Auth saw each sign-in, and no request for the page loads

Section titled “4 · In the second terminal: Supabase Auth saw each sign-in, and no request for the page loads”
Terminal window
docker logs --since 10m supabase_auth_opleet 2>&1 | grep -c '"path":"/token"'
docker logs --since 10m supabase_auth_opleet 2>&1 | grep -c '"path":"/user"'
Terminal window
git push -u origin web/auth
gh pr create --title "feat(web): sign-in and sign-out with Supabase" --body "FE pack B (FE-M0-06 to FE-M0-08), timeline row 25."
gh pr checks --watch
gh pr merge --squash --delete-branch
git switch main
git pull
  • Block 2: “HTTP/1.1 307 Temporary Redirect” and “location: /login”.
  • Block 3: the sign-in page in Indonesian (Masuk, Email, Kata sandi), like ~/opleet-v2/packs/fe-pack-b/expected/login-wrong-password.png. The wrong password shows “Email atau kata sandi salah.” and keeps the email. The right one opens “Masuk sebagai” and the email, with a Keluar button.
  • Block 4: 2 or more for /token (one per sign-in attempt), then 0 for /user: the page loads verified the token without asking Auth.
  • Block 5: /login, and opening / sends you to /login again.
  • Block 6: checks and pr-title pass, then “✓ Squashed and merged pull request #…”.
Terminal window
git log --oneline -1

Expect: “feat(web): sign-in and sign-out with Supabase (#…)”.

  • Block 2 prints 500, or the page says to set NEXT_PUBLIC_SUPABASE_URL: apps/web/.env.local is missing; run FE-M0-06 block 5 again and restart the app.
  • The right password also says “Email atau kata sandi salah.”: the E2E login doesn't exist on this stack. Paste the output of BE-M0-25.
  • “Belum bisa masuk. Coba lagi sebentar lagi.”: the app can't reach the stack. Paste pnpm supabase status and the auth.sign_in line from the first terminal.
  • Block 4 counts /user above 0: getClaims() is asking Auth, so tokens aren't signed with the ES256 key. Stop and paste the counts and the output of curl -s http://127.0.0.1:54321/auth/v1/.well-known/jwks.json. Block 4 counting 0 for /token too: paste docker logs --since 10m supabase_auth_opleet | tail -5; the log format may differ.
Terminal window
gh pr close --delete-branch
git switch main
git branch -D web/auth

Before merging. After merging: revert it with a new pull request.

Not run yet.