From a7b5360374305f7c4a61abf2bd2922be56292b90 Mon Sep 17 00:00:00 2001 From: twoimo Date: Sun, 16 Aug 2026 22:04:06 +0900 Subject: [PATCH] perf: pin Vercel to Seoul and tighten hosted Supabase clients Run production functions in icn1, keep browser auth/realtime sessions bounded, and stop service-role clients from persisting or detecting browser sessions. --- .vercelignore | 6 ++++++ apps/web/integrations/supabase/client.ts | 14 +++++++++++++- apps/web/lib/supabase/server.ts | 4 ++++ apps/web/lib/supabase/service-role.ts | 6 ++++++ apps/web/tests-unit/vercel-ignore-build.test.ts | 2 ++ apps/web/vercel.json | 1 + 6 files changed, 32 insertions(+), 1 deletion(-) diff --git a/.vercelignore b/.vercelignore index 7fb9fc4066..8d5809751f 100644 --- a/.vercelignore +++ b/.vercelignore @@ -24,3 +24,9 @@ test-results/ /backend/ /supabase/ /docs/ +/tmp/ +/artifacts/ +/scripts/ +/DESIGN.md +/SECURITY.md +/AGENTS.md diff --git a/apps/web/integrations/supabase/client.ts b/apps/web/integrations/supabase/client.ts index eceaca21ac..81b573daa6 100644 --- a/apps/web/integrations/supabase/client.ts +++ b/apps/web/integrations/supabase/client.ts @@ -15,7 +15,19 @@ function createSupabaseBrowserClient(): SupabaseClient { ) } - return createBrowserClient(supabaseUrl, supabaseAnonKey) + return createBrowserClient(supabaseUrl, supabaseAnonKey, { + isSingleton: true, + auth: { + persistSession: true, + autoRefreshToken: true, + detectSessionInUrl: true, + }, + realtime: { + params: { + eventsPerSecond: 2, + }, + }, + }) } export function getSupabaseBrowserClient(): SupabaseClient { diff --git a/apps/web/lib/supabase/server.ts b/apps/web/lib/supabase/server.ts index d94545b238..13694a3bc9 100644 --- a/apps/web/lib/supabase/server.ts +++ b/apps/web/lib/supabase/server.ts @@ -39,6 +39,10 @@ export function createClientForCookieStore( } }, }, + auth: { + persistSession: false, + autoRefreshToken: false, + }, }); } diff --git a/apps/web/lib/supabase/service-role.ts b/apps/web/lib/supabase/service-role.ts index 081faa2985..a90adc9f8b 100644 --- a/apps/web/lib/supabase/service-role.ts +++ b/apps/web/lib/supabase/service-role.ts @@ -32,6 +32,12 @@ export function createSupabaseServiceRoleClient(): SupabaseClient { auth: { persistSession: false, autoRefreshToken: false, + detectSessionInUrl: false, + }, + global: { + headers: { + 'X-Client-Info': 'tzudong-service-role', + }, }, }); diff --git a/apps/web/tests-unit/vercel-ignore-build.test.ts b/apps/web/tests-unit/vercel-ignore-build.test.ts index 15e17ac575..688d7efb82 100644 --- a/apps/web/tests-unit/vercel-ignore-build.test.ts +++ b/apps/web/tests-unit/vercel-ignore-build.test.ts @@ -24,6 +24,7 @@ describe("Vercel ignored build branch policy", () => { deploymentEnabled?: Record; }; ignoreCommand?: string; + regions?: string[]; }; expect(config.git?.deploymentEnabled).toEqual({ @@ -31,6 +32,7 @@ describe("Vercel ignored build branch policy", () => { main: true, develop: true, }); + expect(config.regions).toEqual(["icn1"]); expect(config.ignoreCommand).toBe("node scripts/vercel-ignore-build.mjs"); }); diff --git a/apps/web/vercel.json b/apps/web/vercel.json index 7051d30582..a609344ece 100644 --- a/apps/web/vercel.json +++ b/apps/web/vercel.json @@ -1,6 +1,7 @@ { "$schema": "https://openapi.vercel.sh/vercel.json", "framework": "nextjs", + "regions": ["icn1"], "installCommand": "npm ci", "buildCommand": "npm run build", "git": {