Make your first administrator login
Follow these steps in order. You do not need coding experience — mostly clicking in the Supabase website and copying a few keys.
Important: the general public should never get a Sign Up button. Only you create accounts, and only approved volunteers get access.
1. Create a free Supabase project
Supabase stores your private forms and staff logins. Open supabase.com/dashboard, click New project, pick a name (like RecycleBay), set a database password (save it somewhere safe), and wait until the project finishes creating.
2. Copy your project keys into the app
In Supabase, go to Project Settings (gear icon) → API. Copy:
- Project URL
- anon public key
Open the file .env.local in your RecycleBay project and paste:
NEXT_PUBLIC_SUPABASE_URL=https://YOUR-PROJECT-ID.supabase.co NEXT_PUBLIC_SUPABASE_ANON_KEY=paste-anon-key-here ADMIN_LOCAL_CODE=pick-a-secret-code-only-you-know
Save the file, then restart the site (npm run dev).
3. Turn off public sign-ups
In Supabase go to Authentication → Providers → Email.
- Keep Email enabled for login
- Turn OFF “Confirm email” if you want (optional for a school project), or leave it on
- Most importantly: under Authentication → Settings (or Providers), disable Allow new users to sign up so strangers cannot create accounts
RecycleBay also has no Sign up button on the website. Only people you create can log in.
4. Create your first administrator user
Go to Authentication → Users → Add user → Create new user.
- Enter your email (the one you will use to log in)
- Enter a password you will remember
- Check Auto Confirm User
- Click Create user
This is NOT a public account. Only you (or people you create later) get a login.
5. Run the database setup SQL
Go to SQL Editor → New query. Open the file supabase/setup.sql in Cursor, copy everything, paste it into Supabase, and click Run.
Then run this one extra line (change the email to yours):
insert into app_users (email, role, status)
values ('YOUR-EMAIL@example.com', 'admin', 'active')
on conflict (email) do update
set role = 'admin', status = 'active';That tells RecycleBay: “this email is allowed into administrator pages.” (Keep the database role value as admin.)
6. Log in on the website
Open /login, enter the same email and password you created in Supabase, and click Log In.
You should land on the administrator review pages. The public cannot see volunteer forms or approve locations.
7. Approve volunteers later (optional)
When someone submits the volunteer form:
- You review them at /admin/volunteers
- Click “Allow volunteer login” for their email
- In Supabase → Authentication → Users, create a user with that same email and a temporary password, then share the password privately
Until you do both steps, they cannot open administrator pages — even if they somehow guess a password.
