From 772c4ac11996bc5673d8e3e28b5d5a34bbe58a16 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Thor=20=E9=9B=B7=E7=A5=9E=20Schaeff?= <5748289+thorwebdev@users.noreply.github.com> Date: Mon, 20 Nov 2023 15:06:01 +0800 Subject: [PATCH] docs: update scopes docs. (#19090) * docs: update scopes docs. * docs: backlink to oauth app creation docs. --- .../platform/oauth-apps/build-a-supabase-integration.mdx | 2 +- apps/docs/pages/guides/platform/oauth-apps/oauth-scopes.mdx | 2 ++ .../supabase/functions/connect-supabase/index.ts | 3 --- 3 files changed, 3 insertions(+), 4 deletions(-) diff --git a/apps/docs/pages/guides/platform/oauth-apps/build-a-supabase-integration.mdx b/apps/docs/pages/guides/platform/oauth-apps/build-a-supabase-integration.mdx index f98840a4034..56a5fcd5a74 100644 --- a/apps/docs/pages/guides/platform/oauth-apps/build-a-supabase-integration.mdx +++ b/apps/docs/pages/guides/platform/oauth-apps/build-a-supabase-integration.mdx @@ -32,10 +32,10 @@ Within your app's UI, redirect the user to [`https://api.supabase.com/v1/oauth/a - `client_id`: Your client id from the app creation above. - `redirect_uri`: The URL where Supabase will redirect the user to after providing consent. -- `scope`: Currently only `all` is supported. More fine-grained access control coming soon. - `response_type`: Set this to `code`. - `state`: Information about the state of your app. Note that `redirect_uri` and `state` together cannot exceed 4kB in size. - (Recommended) PKCE: We strongly recommend using the PKCE flow for increased security. Generate a random value before taking the user to the authorize endpoint. This value is called code verifier. Hash it with SHA256 and include it as the `code_challenge` parameter, while setting `code_challenge_method` to `S256`. In the next step, you would need to provide the code verifier to get the first access and refresh token. +- [deprecated] `scope`: Scopes are configured when you create your OAuth app. Read the [docs](/docs/guides/platform/oauth-apps/oauth-scopes) for more details. ```ts router.get('/connect-supabase/login', async (ctx) => { diff --git a/apps/docs/pages/guides/platform/oauth-apps/oauth-scopes.mdx b/apps/docs/pages/guides/platform/oauth-apps/oauth-scopes.mdx index 484e3cfde59..3bde7d623d7 100644 --- a/apps/docs/pages/guides/platform/oauth-apps/oauth-scopes.mdx +++ b/apps/docs/pages/guides/platform/oauth-apps/oauth-scopes.mdx @@ -15,6 +15,8 @@ Scopes are only available for OAuth apps. Check out [**our guide**](/docs/guides Scopes restrict access to the specific [Supabase Management API endpoints](/docs/reference/api/introduction) for OAuth tokens. All scopes can be specified as read and/or write. +Scopes are set when you [create an OAuth app](/docs/guides/platform/oauth-apps/build-a-supabase-integration#create-an-oauth-app) in the Supabase Dashboard. + ## Available Scopes | Name | Type | Description | diff --git a/examples/edge-functions/supabase/functions/connect-supabase/index.ts b/examples/edge-functions/supabase/functions/connect-supabase/index.ts index b01bc39d771..41b5ce316eb 100644 --- a/examples/edge-functions/supabase/functions/connect-supabase/index.ts +++ b/examples/edge-functions/supabase/functions/connect-supabase/index.ts @@ -9,9 +9,6 @@ const config = { authorizationEndpointUri: 'https://api.supabase.com/v1/oauth/authorize', tokenUri: 'https://api.supabase.com/v1/oauth/token', redirectUri: 'http://localhost:54321/functions/v1/connect-supabase/oauth2/callback', - defaults: { - scope: 'all', - }, } const oauth2Client = new OAuth2Client(config)