# Deno Edge Functions Dependencies and Configuration in TCG Pocket Collection Tracker

> Learn about Deno Edge Functions dependencies and configuration for the TCG Pocket Collection Tracker. Discover direct URL imports, Supabase JS, Node.js polyfills, and essential environment variables.

- Repository: [Marcel Panse/tcg-pocket-collection-tracker](https://github.com/marcelpanse/tcg-pocket-collection-tracker)
- Tags: architecture
- Published: 2026-03-06

---

**The TCG Pocket Collection Tracker relies on direct URL imports for Deno Edge Functions dependencies—including PostgreSQL client v0.17.0, Supabase JS v2, and Node.js polyfills—while using empty [`deno.json`](https://github.com/marcelpanse/tcg-pocket-collection-tracker/blob/main/deno.json) import maps and five critical environment variables for runtime configuration.**

The repository implements serverless logic via Supabase Edge Functions written for the Deno runtime. Understanding the Deno Edge Functions dependencies and configuration is essential for local development, debugging, or extending the trading and statistics features. This guide breaks down the import structure, the role of [`deno.json`](https://github.com/marcelpanse/tcg-pocket-collection-tracker/blob/main/deno.json), and the required environment variables extracted from the source code.

## Core Dependencies and Runtime Imports

All edge functions share a common pattern of importing external modules directly from URLs rather than using a package manager. This approach is standard for Deno deployments on Supabase Edge Runtime.

### Database and Supabase Clients

The **Stats Tracker**, **Manage-Friend**, and **Get-Trading-Partners** functions connect to PostgreSQL using the `postgres` client:

```typescript
// From supabase/functions/stats-tracker/index.ts (lines 1-4)
import * as postgres from 'https://deno.land/x/postgres@v0.17.0/mod.ts'

```

They also import the Supabase JavaScript client for storage and admin operations:

```typescript
// From supabase/functions/manage-friend/index.ts (lines 1-4)
import { createClient } from 'jsr:@supabase/supabase-js@2'

```

### Node.js Compatibility Polyfills

The **SSO** function requires Node.js-specific APIs for cryptographic operations. It imports polyfills provided by the Deno runtime:

```typescript
// From supabase/functions/sso/index.ts (lines 1-5)
import { Buffer } from 'node:buffer'
import { createHmac } from 'node:crypto'

```

These polyfills enable HMAC-SHA256 signature verification and Base64 encoding without external dependencies.

## The Empty Import Map Pattern in [`deno.json`](https://github.com/marcelpanse/tcg-pocket-collection-tracker/blob/main/deno.json)

Each function directory contains a [`deno.json`](https://github.com/marcelpanse/tcg-pocket-collection-tracker/blob/main/deno.json) file that defines an empty import map:

```json
{
  "imports": {}
}

```

This configuration serves a specific purpose: it instructs the Deno compiler not to rewrite any import URLs. Consequently, the functions use the exact versions specified in the source code (e.g., `postgres@v0.17.0`). No additional aliasing or version pinning is performed by the import map itself.

The [`deno.json`](https://github.com/marcelpanse/tcg-pocket-collection-tracker/blob/main/deno.json) files are located at:
- [`supabase/functions/stats-tracker/deno.json`](https://github.com/marcelpanse/tcg-pocket-collection-tracker/blob/main/supabase/functions/stats-tracker/deno.json)
- [`supabase/functions/manage-friend/deno.json`](https://github.com/marcelpanse/tcg-pocket-collection-tracker/blob/main/supabase/functions/manage-friend/deno.json)
- [`supabase/functions/get-trading-partners/deno.json`](https://github.com/marcelpanse/tcg-pocket-collection-tracker/blob/main/supabase/functions/get-trading-partners/deno.json)
- [`supabase/functions/sso/deno.json`](https://github.com/marcelpanse/tcg-pocket-collection-tracker/blob/main/supabase/functions/sso/deno.json)

## Required Environment Variables and Configuration

All functions rely on environment variables supplied by the Supabase runtime. These are accessed via `Deno.env.get()` and must be configured in the Supabase project's environment variables section.

| Variable | Required By | Purpose |
|----------|-------------|---------|
| `SUPABASE_DB_URL` | Stats Tracker, Manage-Friend, Get-Trading-Partners | PostgreSQL connection string for the connection pool. |
| `SUPABASE_URL` | Stats Tracker, SSO | Base URL of the Supabase project for client initialization. |
| `SUPABASE_SERVICE_ROLE_KEY` | Stats Tracker, Manage-Friend | Privileged key for storage uploads and admin database operations. |
| `SUPABASE_ANON_KEY` | SSO | Public anonymous key for reading account data. |
| `DISCOURSE_CONNECT` | SSO | Secret key for HMAC-SHA256 signature verification in Discourse SSO. |

In [`supabase/functions/stats-tracker/index.ts`](https://github.com/marcelpanse/tcg-pocket-collection-tracker/blob/main/supabase/functions/stats-tracker/index.ts) (lines 5-9), the database URL is retrieved and used to initialize the connection pool:

```typescript
const dbUrl = Deno.env.get('SUPABASE_DB_URL')!
const pool = new postgres.Pool(dbUrl, 3, true)

```

Similarly, [`supabase/functions/sso/index.ts`](https://github.com/marcelpanse/tcg-pocket-collection-tracker/blob/main/supabase/functions/sso/index.ts) (lines 26-38) validates the presence of multiple variables before processing the request.

## Function-Specific Implementation Patterns

While sharing common dependencies, each function implements distinct patterns for database access and cryptographic validation.

### Database Pooling in Stats Tracker

The Stats Tracker function demonstrates efficient PostgreSQL usage by maintaining a persistent pool of three connections:

```typescript
// From supabase/functions/stats-tracker/index.ts
const pool = new postgres.Pool(dbUrl, 3, true)

```

This pattern prevents connection overhead during high-frequency statistics collection operations.

### Cryptographic Validation in SSO

The SSO function combines Node.js polyfills to implement Discourse-compatible single sign-on. It uses `createHmac` from `node:crypto` and `Buffer` from `node:buffer` to validate signatures:

```typescript
import { Buffer } from 'node:buffer'
import { createHmac } from 'node:crypto'

// ... later in the function
const hmac = createHmac('sha256', Deno.env.get('DISCOURSE_CONNECT')!)
hmac.update(payload)
const signature = hmac.digest('hex')

```

This implementation ensures compatibility with Discourse's SSO protocol while running in the Deno Edge Runtime.

## Local Development Setup

To run these functions locally, you must supply the environment variables that Supabase normally injects. Create a `.env` file in your project root:

```bash
SUPABASE_DB_URL=postgres://postgres:postgres@localhost:54322/postgres
SUPABASE_URL=http://localhost:54321
SUPABASE_SERVICE_ROLE_KEY=eyJhbGciOiJIUzI1NiIs...
SUPABASE_ANON_KEY=eyJhbGciOiJIUzI1NiIs...
DISCOURSE_CONNECT=your_discourse_secret

```

Then serve the function using the Supabase CLI:

```bash
supabase functions serve stats-tracker --env-file .env

```

Alternatively, for pure Deno testing without the Supabase CLI:

```bash
deno run --allow-net --allow-env supabase/functions/stats-tracker/index.ts

```

## Summary

- **Direct URL imports** are used exclusively for dependencies, including `postgres@v0.17.0`, `supabase-js@2`, and Node.js polyfills (`node:buffer`, `node:crypto`).
- **Empty [`deno.json`](https://github.com/marcelpanse/tcg-pocket-collection-tracker/blob/main/deno.json) files** in each function directory prevent import rewriting, ensuring version stability based on source code URLs.
- **Five environment variables** control runtime behavior: `SUPABASE_DB_URL`, `SUPABASE_URL`, `SUPABASE_SERVICE_ROLE_KEY`, `SUPABASE_ANON_KEY`, and `DISCOURSE_CONNECT`.
- **Database pooling** (3 connections) is implemented in [`stats-tracker/index.ts`](https://github.com/marcelpanse/tcg-pocket-collection-tracker/blob/main/stats-tracker/index.ts) for efficient PostgreSQL access.
- **Cryptographic validation** in [`sso/index.ts`](https://github.com/marcelpanse/tcg-pocket-collection-tracker/blob/main/sso/index.ts) uses Node.js polyfills to support HMAC-SHA256 signature verification for Discourse SSO.

## Frequently Asked Questions

### What versions of the PostgreSQL client does the project use?

The edge functions import `https://deno.land/x/postgres@v0.17.0/mod.ts` directly via URL. This version is hardcoded in the import statements found in [`supabase/functions/stats-tracker/index.ts`](https://github.com/marcelpanse/tcg-pocket-collection-tracker/blob/main/supabase/functions/stats-tracker/index.ts), [`manage-friend/index.ts`](https://github.com/marcelpanse/tcg-pocket-collection-tracker/blob/main/manage-friend/index.ts), and [`get-trading-partners/index.ts`](https://github.com/marcelpanse/tcg-pocket-collection-tracker/blob/main/get-trading-partners/index.ts).

### Why are the deno.json files empty?

Each function's [`deno.json`](https://github.com/marcelpanse/tcg-pocket-collection-tracker/blob/main/deno.json) contains only `"imports": {}` to explicitly disable import mapping. This ensures Deno uses the exact URLs specified in the source code rather than rewriting them, providing deterministic dependency resolution based on the version tags in the import URLs.

### How does the SSO function handle cryptographic operations?

The SSO function imports Node.js polyfills `node:buffer` and `node:crypto` to perform HMAC-SHA256 signature verification. It uses `createHmac` to generate a signature from the payload and `DISCOURSE_CONNECT` environment variable, then compares it against the incoming request signature to validate Discourse SSO requests.

### What environment variables are required for local development?

Local development requires five variables: `SUPABASE_DB_URL` for PostgreSQL connections, `SUPABASE_URL` and `SUPABASE_SERVICE_ROLE_KEY` for admin client operations, `SUPABASE_ANON_KEY` for public client access, and `DISCOURSE_CONNECT` for SSO signature validation. These can be supplied via a `.env` file when using `supabase functions serve --env-file .env`.