01

The role Supabase plays

Supabase commonly controls authentication, Postgres data, storage, edge functions, and row-level security. Its surrounding reliability depends on policies, JWT identity, generated queries, migrations, and client/service-key boundaries, so the visible error may originate outside the file the AI last changed.

02

Specific failure patterns to inspect

For Login Not Working, common causes include cookie settings, callback URL mismatch, session persistence, authorization and row policies. Generated implementations also tend to omit defensive error handling, version checks, idempotency, or a safe difference between public configuration and private credentials.

03

A safer diagnostic sequence

Preserve the current branch and exact error. Then try one clean test account; record the redirect chain; compare preview and production domains. Follow one test request across the interface, server or provider, and durable data rather than making several speculative code changes.

04

Repair boundaries

The repair should change the narrowest contract that is actually broken. Broader refactoring is justified only when duplicated ownership or an unsafe architecture would otherwise let the failure return.

05

What to avoid

Do not disable authorization globally or share a real customer password. Do not upgrade the entire Supabase stack during a contained incident unless version incompatibility is the proven cause.

06

What a complete handoff includes

The handoff identifies the root cause, affected code or settings, safe test case, deployment note, and any remaining follow-up. The repaired behavior should be protected by a repeatable check.