Skip to content

Add the OAuth consent page at /oauth/consent #225

Description

@HMarzban

Problem

The Supabase OAuth server redirects a person to a consent page before it issues a token. That page does not exist.

Supabase redirects to site_url + authorization_url_path, which is /oauth/consent, and then validates the request origin.

The redirect path is in this repository at packages/supabase/config.toml:357-363, which sets authorization_url_path = "/oauth/consent".

What to do

Add the consent page at apps/webapp/src/pages/oauth/consent.tsx.

It must live in the webapp. Only the webapp holds the browser Supabase session, and the redirect target is the webapp origin.

The page reads the pending authorization request, shows the client and the scopes it asks for, and offers approve and deny.

Acceptance

  • An authorize request renders the page, and it names the requesting client.
  • Approve returns to the client with a code, and the client exchanges it for a token.
  • Deny returns to the client with an error, and no token is issued.
  • A signed-out visitor is sent to sign in first, and returns to the same consent request afterwards.
  • The page labels the requesting client as unverified, unless the probe on Enable the Supabase OAuth server and confirm the connector can discover it #223 shows the host is using a client identity document rather than open registration.
  • The client name renders as escaped text, capped in length, inside a bounded block that is clearly not part of the docs.plus interface. Never as markup, and never folded into a sentence the page writes.
  • The registered redirect origin appears beside the name, because the origin is the fact a person can actually judge.

Notes

The client name is attacker-chosen when dynamic client registration is open. A consent page that
renders it as trusted markup, or folds it into its own sentence, invites a person to approve
something they misread. Treat the name as untrusted content.

Do not advertise instant revocation anywhere on this page. A granted access token lives 3600
seconds, and a verified token is cached for 60 seconds at apps/hocuspocus.server/src/lib/auth.ts:52.
Publish the access-token lifetime instead, so the wording matches the behaviour.

Follow the design system. This page is a public utility route, like /privacy and /terms.

Blocked by #223. Nothing renders until the OAuth server is on.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions