The role Supabase plays
Supabase commonly controls authentication, Postgres data, storage, edge functions, and row-level security. Its surrounding reliability depends on policies, JWT identity, generated queries, migrations, and client/service-key boundaries, so the visible error may originate outside the file the AI last changed.
Specific failure patterns to inspect
For Login Not Working, common causes include cookie settings, callback URL mismatch, session persistence, authorization and row policies. Generated implementations also tend to omit defensive error handling, version checks, idempotency, or a safe difference between public configuration and private credentials.
A safer diagnostic sequence
Preserve the current branch and exact error. Then try one clean test account; record the redirect chain; compare preview and production domains. Follow one test request across the interface, server or provider, and durable data rather than making several speculative code changes.
Repair boundaries
The repair should change the narrowest contract that is actually broken. Broader refactoring is justified only when duplicated ownership or an unsafe architecture would otherwise let the failure return.
What to avoid
Do not disable authorization globally or share a real customer password. Do not upgrade the entire Supabase stack during a contained incident unless version incompatibility is the proven cause.
What a complete handoff includes
The handoff identifies the root cause, affected code or settings, safe test case, deployment note, and any remaining follow-up. The repaired behavior should be protected by a repeatable check.