From 3f54ef7aed9af5cdb63312942cd176aec4597ad4 Mon Sep 17 00:00:00 2001 From: KrishP147 Date: Wed, 23 Sep 2026 22:57:34 -0400 Subject: [PATCH 1/3] cors: allow nutrisync-frontend vercel preview origins Co-Authored-By: Claude Opus 5.5 (1M context) --- supabase/functions/_shared/cors.ts | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/supabase/functions/_shared/cors.ts b/supabase/functions/_shared/cors.ts index 0efcef2..3c7709b 100644 --- a/supabase/functions/_shared/cors.ts +++ b/supabase/functions/_shared/cors.ts @@ -8,8 +8,15 @@ export const ALLOWED_ORIGINS = [ "http://localhost:3000", ]; +// Vercel production + preview deployments of the frontend project. +export const VERCEL_PREVIEW_ORIGIN = /^https:\/\/nutrisync-frontend(-[a-z0-9-]+)?\.vercel\.app$/; + +function isAllowedOrigin(origin: string): boolean { + return ALLOWED_ORIGINS.includes(origin) || VERCEL_PREVIEW_ORIGIN.test(origin); +} + export function corsHeaders(origin: string | null): Record { - const allowOrigin = origin && ALLOWED_ORIGINS.includes(origin) ? origin : ALLOWED_ORIGINS[0]; + const allowOrigin = origin && isAllowedOrigin(origin) ? origin : ALLOWED_ORIGINS[0]; return { "Access-Control-Allow-Origin": allowOrigin, "Access-Control-Allow-Headers": "authorization, x-client-info, apikey, content-type", From 8d2853a1106b1e1721f79987e92df3a88a25e390 Mon Sep 17 00:00:00 2001 From: KrishP147 Date: Wed, 23 Sep 2026 22:57:52 -0400 Subject: [PATCH 2/3] ci: deno typecheck for supabase edge functions Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/ci.yml | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 7ca208e..5944026 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -75,6 +75,22 @@ jobs: sarif_file: 'trivy-results.sarif' continue-on-error: true + supabase-functions-check: + name: Supabase Functions Typecheck + runs-on: ubuntu-latest + + steps: + - name: Checkout code + uses: actions/checkout@v4 + + - name: Setup Deno + uses: denoland/setup-deno@v2 + with: + deno-version: v2.x + + - name: Typecheck Edge Functions + run: deno check supabase/functions/*/index.ts + deploy-frontend: name: Deploy Frontend to Vercel needs: [frontend-tests] From 5444d3c6a924d0cb006d100fe700d4423f32137e Mon Sep 17 00:00:00 2001 From: KrishP147 Date: Wed, 23 Sep 2026 22:58:22 -0400 Subject: [PATCH 3/3] docs: edge functions README, vercel preview CORS note Co-Authored-By: Claude Opus 5.5 (1M context) --- docs/07-deployment.md | 2 ++ supabase/functions/README.md | 38 ++++++++++++++++++++++++++++++++++++ 2 files changed, 40 insertions(+) create mode 100644 supabase/functions/README.md diff --git a/docs/07-deployment.md b/docs/07-deployment.md index 9012e29..30b2aba 100644 --- a/docs/07-deployment.md +++ b/docs/07-deployment.md @@ -191,6 +191,8 @@ Check build logs in Vercel dashboard. Common issues: - Confirm the calling origin is in the `ALLOWED_ORIGINS` list in `supabase/functions/_shared/cors.ts` +- Vercel preview origins (`https://nutrisync-frontend-*.vercel.app`) are + allowed via the `VERCEL_PREVIEW_ORIGIN` regex in the same file - Redeploy the function after changing it ### Database connection errors diff --git a/supabase/functions/README.md b/supabase/functions/README.md new file mode 100644 index 0000000..b147f58 --- /dev/null +++ b/supabase/functions/README.md @@ -0,0 +1,38 @@ +# Supabase Edge Functions + +Deno functions backing the NutriSync frontend. Full deploy walkthrough: +[docs/07-deployment.md](../../docs/07-deployment.md). + +## Layout + +- `/index.ts` - one directory per function; `index.ts` is the entrypoint. +- `_shared/` - helpers imported by functions, never deployed on their own: + `cors.ts` (origin allow-list + JSON responses), `gemini.ts`, + `analyzeFoodImage.ts`, `json.ts`, `supabaseAdmin.ts`. + +## Secrets + +| Secret | Used by | Notes | +| --- | --- | --- | +| `GOOGLE_API_KEY` | Gemini-backed functions (chat, recommendations, image analysis, ...) | Required | +| `USDA_API_KEY` | `search-food`, `food-details` | Optional; falls back to USDA `DEMO_KEY` (heavily rate-limited) | + +`SUPABASE_URL` / `SUPABASE_SERVICE_ROLE_KEY` are injected by Supabase. + +```bash +supabase secrets set GOOGLE_API_KEY= USDA_API_KEY= +``` + +## Local dev and deploy + +```bash +supabase functions serve # run all functions locally +supabase functions deploy # deploy all +supabase functions deploy # deploy one +``` + +## CI + +The `supabase-functions-check` job in `.github/workflows/ci.yml` runs +`deno check supabase/functions/*/index.ts` on pushes and PRs. Marking the job +required is a manual branch-protection setting (repo Settings > Branches).