Live demo mode
A second deployment with NEXT_PUBLIC_DEMO_MODE=true becomes a public demo of your app. Setup guide: apps/web/supabase/demo/README.md, or the Live demo docs page.
apps/web/supabase/demo/demo.sqladds a sample team (Acme Inc) with members, pending invitations and notifications, and a shared login.- Database guards keep the shared login usable: its email, password, two-step sign-in and deletion, and the team's deletion and ownership, can only be changed by the database owner.
- An hourly
pg_cronreset puts everything back. It stays off until you switch it on, so applying the file to another database cannot wipe it.uninstall.sqlremoves it all. - In the app: a demo banner, a one-click "Sign in as the demo user" card, locked settings for the shared login, a note on password reset that emails are off, and sign-out that ends only the current session.
- Tests:
pnpm --filter web supabase:demo:test(rolled back after the run),demo.rls.test.sqlfor attacks through the API roles, andapps/e2e/tests/demo/demo.spec.ts.
New settings
MAILER_PROVIDER=logsends no email and logs only the recipient's domain and the subject.NEXT_PUBLIC_AUTH_OAUTH_PROVIDERSchooses the OAuth buttons (comma-separated). It defaults togoogle;nonehides them.NEXT_PUBLIC_KIT_DEMO_URL, when set, adds a live demo link under the hero and the final call to action on the kit's sales page.
Sign-in pages
Sign-in, sign-up, password reset, two-step verification and update password were redesigned: a split layout with a brand panel on desktop and a single column on phones, visible labels tied to their inputs, autocomplete hints, a labelled show-password button, 44-pixel touch targets and "Sign up with Google" on the sign-up page. The sign-in logic is unchanged, except that a wrong two-step code no longer causes an unhandled error.
The sample billing plans now list example limits instead of "Feature 1, Feature 2".