feat(auth): add OAuth 2.1 authorization consent management API calls #1793
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
Adds user-facing OAuth authorization methods to
@supabase/auth-jsfor building consent pages when Supabase Auth acts as an OAuth 2.1 authorization server.Implements the consent flow where users approve/deny OAuth client authorization requests.
New API
Namespace:
auth.oauth.*Three new methods for managing OAuth authorization consent:
Use Case
Enables developers to build custom OAuth consent pages for their Supabase projects when acting as an OAuth 2.1 authorization server. Example flow:
authorization_idin URLgetAuthorizationDetails(authorizationId)to fetch client and scope infoapproveAuthorization()ordenyAuthorization()What's NOT Included
Third-party OAuth client integration (calling
/oauth/authorizeand/oauth/tokenfrom external apps) is intentionally not included in this PR.Rationale:
Third-party integration will be addressed through comprehensive documentation showing how to use standard OAuth client libraries with Supabase Auth endpoints.
Breaking Changes
None. This is a purely additive change with zero breaking changes to existing APIs