feat(studio): add notebook permissions to scoped access tokens (#50764)

## Problem

The Management API now has `/v2/projects/{ref}/notebooks`, gated by the
new `project_notebooks_read` / `project_notebooks_write` FGA
permissions. Studio pins `@supabase/shared-types` 0.1.95, which predates
them, so the scoped access token form can't grant them. Tokens created
with every permission selected still get `403 forbidden` on the notebook
endpoints.

## Solution

- Bump `@supabase/shared-types` to 0.1.96 (Studio and shared-data),
which publishes the notebook permissions.
- Add a **Notebooks** entry to the permission catalog (Project category,
next to SQL Snippets).
- Add minimum roles to `FGA_SCOPE_MINIMUM_ROLE`: read is `readonly`,
write is `developer`, matching the OpenFGA model.

The docs permission tables don't change yet. They're built from the
docs' checked-in v2 spec, which doesn't include the notebook endpoints,
so the row appears on the next spec sync.

## Review instructions

1. In the preview, go to **Account → Access Tokens** and create a scoped
token for a project. Check that **Notebooks** is listed under Project,
and set it to Read-write.
2. List notebooks with the new token:
   ```bash
curl -s -H "Authorization: Bearer $TOKEN"
"https://api.supabase.com/v2/projects/$REF/notebooks"
   ```
It should return `200` with `{ "links": ..., "data": [...] }`, not
`403`.
3. Optional: create a token with Notebooks set to None, repeat step 2,
and check it returns `403`.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
  - Added project-level notebook permissions to access tokens.
- Access tokens can now grant read-only or developer-level access for
managing shared project notebooks.
- Project notebook permissions are displayed in the token creation
interface and supporting documentation.


<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Saxon FletcherandClaude Opus 5.5 authored and GitHub committed 2026-09-23 15:18:28 +08:00
1 parent c8521c7ed4
commit cf5f1545bd
5 files changed
+20 -9

No files matched your search

@@ -146,6 +146,8 @@ export const FGA_SCOPE_MINIMUM_ROLE: Record<string, TokenRoleLevel> = {
infra_disk_config_write: 'administrator',
infra_read_replicas_read: 'readonly',
infra_read_replicas_write: 'administrator',
project_notebooks_read: 'readonly',
project_notebooks_write: 'developer',
project_snippets_read: 'readonly',
project_snippets_write: 'readonly',
realtime_config_read: 'readonly',
+1 -1
View File
@@ -78,7 +78,7 @@
"@supabase/mcp-server-supabase": "^0.12.0",
"@supabase/pg-meta": "workspace:*",
"@supabase/realtime-js": "catalog:",
"@supabase/shared-types": "0.1.95",
"@supabase/shared-types": "0.1.96",
"@supabase/supabase-js": "catalog:",
"@tanstack/react-devtools": "^0.10.3",
"@tanstack/react-hotkeys": "^0.10.0",
+1 -1
View File
@@ -15,7 +15,7 @@
"author": "",
"license": "MIT",
"dependencies": {
"@supabase/shared-types": "0.1.95",
"@supabase/shared-types": "0.1.96",
"zod": "catalog:"
}
}
@@ -231,6 +231,15 @@ const RESOURCE_METADATA: Record<string, ResourceMeta> = {
allowsRead: ['Read project SQL snippets'],
allowsWrite: ['Manage project SQL snippets'],
},
'project:notebooks': {
category: 'project',
name: 'Notebooks',
description: 'Notebooks shared with everyone on the project.',
risk: 'low',
riskReason: 'Read-write can create, edit, and delete notebooks shared across the project.',
allowsRead: ['Read project notebooks'],
allowsWrite: ['Manage project notebooks'],
},
// --- Database ---
'project:database': {
+7 -7
View File
@@ -1066,8 +1066,8 @@ importers:
specifier: 'catalog:'
version: 2.116.0
'@supabase/shared-types':
specifier: 0.1.95
version: 0.1.95
specifier: 0.1.96
version: 0.1.96
'@supabase/supabase-js':
specifier: 'catalog:'
version: 2.116.0(@opentelemetry/api@1.9.1)
@@ -2641,8 +2641,8 @@ importers:
packages/shared-data:
dependencies:
'@supabase/shared-types':
specifier: 0.1.95
version: 0.1.95
specifier: 0.1.96
version: 0.1.96
zod:
specifier: 'catalog:'
version: 3.25.76
@@ -8374,8 +8374,8 @@ packages:
resolution: {integrity: sha512-MHAnlXxi2s6yiJsZsQMfs2B3RFxeVfQWxerqYhIMqcCQV/FuY3LIeouPEkXw/ah7wUWMLYwempF9MOCUScyddg==}
engines: {node: '>=22.0.0'}
'@supabase/shared-types@0.1.95':
resolution: {integrity: sha512-Z/L/nHCiQVqj6nRIBerfQJLcEgYUUFTw+pIr/RMCbldibFrsAg8AkZQxVx/Oe9kSlwgKVxiWHj8m89CLtqo6lg==}
'@supabase/shared-types@0.1.96':
resolution: {integrity: sha512-2qB7Cmtu/59VgDpSjFN11hQhmhKK0RXgmGuF8F4fKDFHiTWA5Tu3EhPpcU5/j7jKhEsgUPFLXiZaGxn9hNQk/g==}
'@supabase/sql-to-rest@0.1.6':
resolution: {integrity: sha512-06KgjeINtc6405XQvfnchBE1azEsU8G2NElfadmvVHKmHa5l2bFzjbtFbpaYgpgTzccHlcDmBaCgedVf2Gyl8Q==}
@@ -25180,7 +25180,7 @@ snapshots:
'@supabase/phoenix': 0.4.5
tslib: 2.8.1
'@supabase/shared-types@0.1.95': {}
'@supabase/shared-types@0.1.96': {}
'@supabase/sql-to-rest@0.1.6(encoding@0.1.13)(supports-color@8.1.1)':
dependencies: