Files
supabase/apps/studio/lib
Gildas Garcia 1e26457bac Scoped PAT: refactor the scope permission map to be computed from Open API specs (#48182)
Fifth stacked PR for scoped PAT extracted from the prototype #47783 to
ease reviewing.
Previous stacked PR is #47999
Next stacked PR is #48359

This PR refactor how we get the map of which scopes enable which
endpoint or mcp tool. Previously it was an hardcoded file. We now
compute it from the OpenAPI specs of our API. This ensure the map stays
up to date when the API changes.

However, we don't have an always up-to-date equivalent for mcp tools so
we duplicated code from platform that map the OAuth scopes they check
with the FGA permissions.

## Notes

The react-hook-form usage is not great. A follow up PR will fix it

## How to test

- On
https://studio-staging-git-scopedpat-scope-permissions-api-supabase.vercel.app/dashboard/account/tokens
- Create a new token with a few permissions (their risk marker should be
displayed: (_High risk_, _Medium risk_ or _Low risk_)
- You should see the available endpoints and mcp tools in the review
step

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added dynamic permission mapping for scoped access tokens, covering
Management API endpoints and MCP tools.
* Added a permissions endpoint with hosted-platform support and caching.
* Updated scoped token creation and review screens to show capabilities
based on granted permissions.
  * Added permission-aware risk indicators and tool visibility.

* **Bug Fixes**
* Improved authorization checks so endpoints and tools require all
necessary scopes.

* **Tests**
  * Added coverage for endpoint, scope, and MCP tool mapping behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-30 15:42:33 +02:00
..
2026-07-16 14:06:40 +01:00
2026-02-11 09:50:11 +01:00
2026-02-11 09:50:11 +01:00