Wen Bo Xie 56ef87a8df feat(studio): role-aware access feedback for scoped access tokens
Scoped PATs are enforced server-side as the intersection of the token's
granted scopes and the owner's live role, re-checked on every request. The
UI previously said nothing about this: any member could select any
permission scope for any resource, get no warning at creation, and the
token view kept rendering stored scopes as fact after the owner's access
changed. This adds advisory (never blocking) feedback across the whole
scoped-token flow so users learn at selection time -- not at their first
403 -- what a token can actually do.

Core (AccessToken.roles.ts, all pure and unit-tested):

- FGA_SCOPE_MINIMUM_ROLE: all 83 permission scopes transcribed from the
  OpenFGA model's role unions, mapped to the lowest base role that holds
  them. A drift-guard test pins the key set to the scope ids published in
  @supabase/shared-types, so upstream additions fail CI here with
  re-transcription instructions.
- estimateRoleLevel: derives the user's base role per org (or per project
  for project-invited members) from the ungated /platform/profile/
  permissions rows via four discriminating ABAC probes, verified against
  the platform's default_permissions seeds. Works for every member type
  with no permission-gated endpoint.
- computeTokenRoleContext + applySelectionToRoleContext: role resolution
  (expensive, memoized) is split from selection evaluation (cheap, re-run
  per permission toggle). Results carry per-resource failing roles,
  including per-project detail for members invited to projects rather
  than the org.

Creation form:

- Orgs where the user only has project-level access are disabled in
  org-scope mode, with an inline explanation.
- Permission rows and the review summary show a red "Exceeds your role"
  pill whose tooltip names the exact resources where requests would be
  denied, the required role, and the user's actual role there (spelling
  out per-project roles for project-invited members).
- The review admonition breaks exceeded permissions down per resource,
  organizations first; the risk badge is computed on the role-capped
  effective scope set.
- The immutability warning moved from a persistent admonition to
  micro-copy at the point of commitment; the permissions step links the
  access-control docs.

Token view sheet:

- Lost access is distinguished from deletion (deleting a project/org
  erases the token's FGA bindings; removal does not): bindings that
  vanished render a "resources no longer exist" state, while bindings the
  user can no longer reach show an anonymous count with a "No longer
  accessible" badge and a "removed from" admonition.
- Accessible resources list name plus ref/slug; capabilities carry the
  same exceeds-role pills; risk reflects what the owner's current role
  allows. Header now has separate Access control and API docs buttons
  (DocsButton gained a label prop).

All signals recompute from live org/project/permission queries, so the
view tracks membership changes without stored state, and everything
degrades to "no warnings" while data loads or on self-hosted.
2026-08-05 18:34:11 +07:00
2025-06-17 11:08:46 +02:00
2026-06-30 14:03:40 +02:00
2024-01-10 13:34:41 +01:00
2021-07-25 12:45:26 +08:00

Supabase

Supabase is the Postgres development platform. We're building the features of Firebase using enterprise-grade open source tools.

  • Hosted Postgres Database. Docs
  • Authentication and Authorization. Docs
  • Auto-generated APIs.
  • Functions.
    • Database Functions. Docs
    • Edge Functions Docs
  • File Storage. Docs
  • AI + Vector/Embeddings Toolkit. Docs
  • Dashboard

Supabase Dashboard

Watch "releases" of this repo to get notified of major updates.

Watch this repo

Documentation

For full documentation, visit supabase.com/docs

To see how to Contribute, visit Getting Started

Community & Support

  • Community Forum. Best for: help with building, discussion about database best practices.
  • GitHub Issues. Best for: bugs and errors you encounter using Supabase.
  • Email Support. Best for: problems with your database or infrastructure.
  • Discord. Best for: sharing your applications and hanging out with the community.

How it works

Supabase is a combination of open source tools. We’re building the features of Firebase using enterprise-grade, open source products. If the tools and communities exist, with an MIT, Apache 2, or equivalent open license, we will use and support that tool. If the tool doesn't exist, we build and open source it ourselves. Supabase is not a 1-to-1 mapping of Firebase. Our aim is to give developers a Firebase-like developer experience using open source tools.

Architecture

Supabase is a hosted platform. You can sign up and start using Supabase without installing anything. You can also self-host and develop locally.

Architecture

  • Postgres is an object-relational database system with over 30 years of active development that has earned it a strong reputation for reliability, feature robustness, and performance.
  • Realtime is an Elixir server that allows you to listen to PostgreSQL inserts, updates, and deletes using websockets. Realtime polls Postgres' built-in replication functionality for database changes, converts changes to JSON, then broadcasts the JSON over websockets to authorized clients.
  • PostgREST is a web server that turns your PostgreSQL database directly into a RESTful API.
  • GoTrue is a JWT-based authentication API that simplifies user sign-ups, logins, and session management in your applications.
  • Storage a RESTful API for managing files in S3, with Postgres handling permissions.
  • pg_graphql a PostgreSQL extension that exposes a GraphQL API.
  • postgres-meta is a RESTful API for managing your Postgres, allowing you to fetch tables, add roles, and run queries, etc.
  • Kong is a cloud-native API gateway.

Client libraries

Our approach for client libraries is modular. Each sub-library is a standalone implementation for a single external system. This is one of the ways we support existing tools.

Language Client Feature-Clients (bundled in Supabase client)
Supabase PostgREST GoTrue Realtime Storage Functions
⚡️ Official ⚡️
JavaScript (TypeScript) supabase-js postgrest-js auth-js realtime-js storage-js functions-js
Flutter supabase-flutter postgrest-dart gotrue-dart realtime-dart storage-dart functions-dart
Swift supabase-swift postgrest-swift auth-swift realtime-swift storage-swift functions-swift
Python supabase-py postgrest-py gotrue-py realtime-py storage-py functions-py
💚 Community 💚
C# supabase-csharp postgrest-csharp gotrue-csharp realtime-csharp storage-csharp functions-csharp
Go - postgrest-go gotrue-go - storage-go functions-go
Java - - gotrue-java - storage-java -
Kotlin supabase-kt postgrest-kt auth-kt realtime-kt storage-kt functions-kt
Ruby supabase-rb postgrest-rb - - - -
Rust - postgrest-rs - - - -
Godot Engine (GDScript) supabase-gdscript - - - - -

Badges

Made with Supabase

[![Made with Supabase](https://supabase.com/badge-made-with-supabase.svg)](https://supabase.com)
<a href="https://supabase.com">
  <img
    width="168"
    height="30"
    src="https://supabase.com/badge-made-with-supabase.svg"
    alt="Made with Supabase"
  />
</a>

Made with Supabase (dark)

[![Made with Supabase](https://supabase.com/badge-made-with-supabase-dark.svg)](https://supabase.com)
<a href="https://supabase.com">
  <img
    width="168"
    height="30"
    src="https://supabase.com/badge-made-with-supabase-dark.svg"
    alt="Made with Supabase"
  />
</a>

Translations

Languages
TypeScript 59.3%
MDX 21.5%
JavaScript 17.9%
CSS 0.6%
Shell 0.4%
Other 0.2%