# Password-based Authentication

Password-based authentication block for Next.js

## Installation

Install this block:

```bash
npx shadcn@latest add @supabase/password-based-auth-nextjs
```

## Folder structure

This block includes the [Supabase client](https://supabase.com/library/docs/nextjs/client.md). If you already have one installed, you can skip overwriting it.

- `app/`
  - `auth/`
    - `confirm/`
      - `route.ts`
    - `error/`
      - `page.tsx`
    - `forgot-password/`
      - `page.tsx`
    - `login/`
      - `page.tsx`
    - `sign-up-success/`
      - `page.tsx`
    - `sign-up/`
      - `page.tsx`
    - `update-password/`
      - `page.tsx`
  - `protected/`
    - `page.tsx`
- `components/`
  - `forgot-password-form.tsx`
  - `login-form.tsx`
  - `logout-button.tsx`
  - `sign-up-form.tsx`
  - `update-password-form.tsx`
- `middleware.ts`
- `lib/`
  - `supabase/`
    - `client.ts`
    - `middleware.ts`
    - `server.ts`

Full source: https://supabase.com/library/r/password-based-auth-nextjs.json

## Usage

Once you install the block in your Next.js project, you'll get all the necessary pages and components to set up a password-based authentication flow.

### Getting started

After installing the block, you'll have the following environment variables in your `.env.local` file:

```env
NEXT_PUBLIC_SUPABASE_URL=
NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY=
```

- If you're using supabase.com, you can find these values in the [Connect modal](https://supabase.com/dashboard/project/_?showConnect=true\&connectTab=frameworks\&framework=nextjs) under App Frameworks or in your project's [API settings](https://supabase.com/dashboard/project/_/settings/api).

- If you're using a local instance of Supabase, you can find these values by running `supabase start` or `supabase status` (if you already have it running).

### Adding email templates

1. Add an [email template for sign-up](https://supabase.com/dashboard/project/_/auth/templates) to the Supabase project. Your signup email template should contain at least the following HTML:

   ```html
   <h2>Confirm your email address</h2>

   <p>Follow the link below to confirm this email address and finish signing up.</p>
   <p>
     <a
       href="{{ .SiteURL }}/auth/confirm?token_hash={{ .TokenHash }}&type=email&next={{ .RedirectTo }}"
       >Confirm email address</a
     >
   </p>
   ```

   For detailed instructions on how to configure your email templates, including the use of variables like `{{ .SiteURL }}`,`{{ .TokenHash }}`, and `{{ .RedirectTo }}`, refer to our [Email Templates guide](https://supabase.com/docs/guides/auth/auth-email-templates).

2. Add an [email template for reset password](https://supabase.com/dashboard/project/_/auth/templates) to the Supabase project. Your reset password email template should contain at least the following HTML:

   ```html
   <h2>Reset your password</h2>

   <p>We received a request to reset your password. Follow the link below to choose a new one.</p>
   <p>
     <a
       href="{{ .SiteURL }}/auth/confirm?token_hash={{ .TokenHash }}&type=recovery&next={{ .RedirectTo }}"
       >Reset password</a
     >
   </p>
   ```

### Setting up routes and redirect URLs

1. Set the site URL in the [URL Configuration](https://supabase.com/dashboard/project/_/auth/url-configuration) settings in the Supabase Dashboard.

2. Set up the Next.js route that users will visit to reset or update their password. Go to the [URL Configuration](https://supabase.com/dashboard/project/_/auth/url-configuration) settings and add the `forgot-password` route to the list of Redirect URLs. It should look something like: `http://example.com/auth/forgot-password`.

3. Update the redirect paths in `login-form.tsx` and `update-password-form.tsx` components to point to the logged-in routes in your app. Our examples use `/protected`, but you can set this to whatever fits your app.

Info: You can use this block with the Pages router by moving the routes from the `app` folder into the `pages` folder and renaming them. Example instead of `app/sign-up/page.tsx`, you'd create a `pages/sign-up.tsx` file.

## Further reading

- [Password-based authentication (PKCE flow)](https://supabase.com/docs/guides/auth/passwords?queryGroups=flow\&flow=pkce)
- [Authentication error codes](https://supabase.com/docs/guides/auth/debugging/error-codes)
- [Email templates](https://supabase.com/docs/guides/auth/auth-email-templates)
- [Email templates for local development](https://supabase.com/docs/guides/local-development/customizing-email-templates)
- [Custom SMTP](https://supabase.com/docs/guides/auth/auth-smtp)
