Files
supabase/apps/studio/components/interfaces/Account/AccessTokens/AccessToken.constants.ts
Wen Bo Xie 2681a21f5c docs: add Personal Access Tokens guide with generated permission tables (#49732)
Add a guide that compares classic and scoped personal access tokens,
explains how account roles constrain token permissions, and walks
through creating and testing a project-scoped token. Include generated
tables mapping permissions to Management API endpoints and MCP tools,
and link the guide from docs navigation and Studio token sheets.

Move the scoped-token permission catalog from Studio into shared-data.
Studio and docs generation now share permission names, categories,
descriptions, risk metadata, modes, scopes, and display order.

Generate the tables from the shared catalog, OpenAPI
x-fga-permissions, and the downloaded MCP permission map. Exclude
Workers permissions until the feature is live.

Run regeneration through the docs Makefile, verify checked-in output in
CI, and refresh it in the weekly Management API workflow. Add Dashboard
and Docs ownership plus contributor guidance so permission changes stay
synchronized.
2026-09-01 12:30:56 +00:00

68 lines
2.0 KiB
TypeScript

import { permissions } from '@supabase/shared-types'
import { components } from 'api-types'
import {
getAction,
getResource,
PERMISSION_CATALOG,
type FgaAction,
} from 'shared-data/scoped-access-token-permissions'
export type ScopedAccessTokenPermission =
components['schemas']['CreateScopedAccessTokenBody']['permissions'][number]
export const CUSTOM_EXPIRY_VALUE = 'custom'
/** Shared tail for every "this token can no longer be used" message. */
export const TOKEN_DENIED_REMEDIATION =
'Requests with this token will be denied. Delete this token and create a new one with the resources and permissions you need.'
/** Warning shown on both entry points that create a classic (account-wide) token. */
export const CLASSIC_TOKEN_WARNING = {
title: 'Access tokens can be used to control your whole account',
description: 'Be careful when sharing your tokens',
} as const
export const EXPIRES_AT_OPTIONS = {
hour: { value: 'hour', label: '1 hour' },
day: { value: 'day', label: '1 day' },
week: { value: 'week', label: '7 days' },
month: { value: 'month', label: '30 days' },
custom: { value: CUSTOM_EXPIRY_VALUE, label: 'Custom' },
} as const
const FGA = permissions.FgaPermissions
const buildPermissionList = () => {
const list: Array<{
scope: string
resource: string
action: FgaAction
id: string
}> = []
for (const [scope, scopePerms] of Object.entries(FGA)) {
for (const [key, perm] of Object.entries(scopePerms)) {
list.push({
scope: scope.toLowerCase(),
resource: getResource(key),
action: getAction(key),
id: perm.id,
})
}
}
return list
}
export const PERMISSION_LIST = buildPermissionList()
/**
* Resources shown in token permission summaries (e.g. the post-creation banner).
* Titles come from the shared permission catalog so they match the creation form
* and the generated docs tables.
*/
export const ACCESS_TOKEN_RESOURCES = PERMISSION_CATALOG.map((entry) => ({
resource: entry.key,
title: entry.name,
}))