mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 01:15:03 +03:00
feat(studio): add notebook permissions to scoped access tokens (#50764)
## Problem
The Management API now has `/v2/projects/{ref}/notebooks`, gated by the
new `project_notebooks_read` / `project_notebooks_write` FGA
permissions. Studio pins `@supabase/shared-types` 0.1.95, which predates
them, so the scoped access token form can't grant them. Tokens created
with every permission selected still get `403 forbidden` on the notebook
endpoints.
## Solution
- Bump `@supabase/shared-types` to 0.1.96 (Studio and shared-data),
which publishes the notebook permissions.
- Add a **Notebooks** entry to the permission catalog (Project category,
next to SQL Snippets).
- Add minimum roles to `FGA_SCOPE_MINIMUM_ROLE`: read is `readonly`,
write is `developer`, matching the OpenFGA model.
The docs permission tables don't change yet. They're built from the
docs' checked-in v2 spec, which doesn't include the notebook endpoints,
so the row appears on the next spec sync.
## Review instructions
1. In the preview, go to **Account → Access Tokens** and create a scoped
token for a project. Check that **Notebooks** is listed under Project,
and set it to Read-write.
2. List notebooks with the new token:
```bash
curl -s -H "Authorization: Bearer $TOKEN"
"https://api.supabase.com/v2/projects/$REF/notebooks"
```
It should return `200` with `{ "links": ..., "data": [...] }`, not
`403`.
3. Optional: create a token with Notebooks set to None, repeat step 2,
and check it returns `403`.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
- **New Features**
- Added project-level notebook permissions to access tokens.
- Access tokens can now grant read-only or developer-level access for
managing shared project notebooks.
- Project notebook permissions are displayed in the token creation
interface and supporting documentation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
1 parent
c8521c7ed4
commit
cf5f1545bd
5 files changed
+20
-9
No files matched your search
@@ -15,7 +15,7 @@
|
||||
"author": "",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"@supabase/shared-types": "0.1.95",
|
||||
"@supabase/shared-types": "0.1.96",
|
||||
"zod": "catalog:"
|
||||
}
|
||||
}
|
||||
@@ -231,6 +231,15 @@ const RESOURCE_METADATA: Record<string, ResourceMeta> = {
|
||||
allowsRead: ['Read project SQL snippets'],
|
||||
allowsWrite: ['Manage project SQL snippets'],
|
||||
},
|
||||
'project:notebooks': {
|
||||
category: 'project',
|
||||
name: 'Notebooks',
|
||||
description: 'Notebooks shared with everyone on the project.',
|
||||
risk: 'low',
|
||||
riskReason: 'Read-write can create, edit, and delete notebooks shared across the project.',
|
||||
allowsRead: ['Read project notebooks'],
|
||||
allowsWrite: ['Manage project notebooks'],
|
||||
},
|
||||
|
||||
// --- Database ---
|
||||
'project:database': {
|
||||
|
||||
Reference in new issue
Block a user