AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Turnstile Secret Input Reverts To Previous Value When Editing, Preventing Updates

In Supabase Studio's Bot and Abuse Protection settings, editing the Turnstile secret field resets it to the last saved value, making it impossible to change or delete the secret. The issue affects the latest dashboard version.

highConfidence 72%React

Origin Analysis

The secret input is bound directly to the fetched configuration value. When the component re-renders after a state change (e.g., form submission, query cache update, or blur), the input's `value` or `defaultValue` is re-initialized from the server response, overwriting the user's edits. Deleting the field also fails because the fallback to the cached secret is applied on every render.
1. Open Supabase Studio and go to Authentication → Bot and Abuse Protection. 2. Enable Turnstile and save a secret. 3. Click on the secret field, select all text, and delete it. 4. Type a new secret or leave empty. 5. The field immediately or on blur reverts to the previous secret. 6. Attempting to save results in the old secret being stored.

Fixing Code Block

Edge Case Audit

The fix introduces local state that may diverge from the global store if the parent component updates `initialSecret` while the user is editing. The current guard ignores prop changes after user interaction, which could lead to stale display if the secret is updated elsewhere (e.g., another tab). To mitigate, call `handleSave` before external updates or implement a more robust state sync with `usePrevious` comparison. Rollback: revert this component to the original code if unexpected side effects occur (e.g., saved values not reflected after external changes). Ensure the input is not part of an uncontrolled form that relies on `defaultValue`; all form submissions should use the local state value.

Ecosystem Topology