docs: Add section about dynamically generated redirect url (#29612)

This commit is contained in:
Kamil Ogórek authored and GitHub committed 2024-10-01 11:24:37 +02:00
1 parent f58afe2e76
commit d5107e4ea2
1 file changed
+11
@@ -65,6 +65,12 @@ Exchange the authorization code for an access and refresh token by calling [`POS
- `redirect_uri`: This must be exactly the same URL used in the first step.
- (Recommended) `code_verifier`: If you used the PKCE flow in the first step, include the code verifier as `code_verifier`.
<Admonition type="note">
If your application need to support dynamically generated Redirect URLs, check out [Handling Dynamic Redirect URLs](#handling-dynamic-redirect-urls) section below.
</Admonition>
As per OAuth2 spec, provide the client id and client secret as basic auth header:
- `client_id`: The unique client ID identifying your OAuth App.
@@ -151,6 +157,11 @@ When creating a new project, you can either ask the user to provide a database p
You can configure the user's [custom SMTP settings](https://supabase.com/docs/guides/auth/auth-smtp) using the [`/config/auth` endpoint](https://api.supabase.com/api/v1#/projects%20config/updateV1AuthConfig).
### Handling Dynamic Redirect URLs
To handle multiple, dynamically generated redirect URLs within the same OAuth app, you can leverage the `state` query parameter. When starting the OAuth process, include the desired, encoded redirect URL in the `state` parameter.
Once authorization is complete, we will sends the `state` value back to your app. You can then verify its integrity and extract the correct redirect URL, decoding it and redirecting the user to the correct URL.
## Current limitations
Only some features are available until we roll out fine-grained access control. If you need full database access, you will need to prompt the user for their database password.