Problem
The Supabase OAuth server redirects a person to a consent page before it issues a token. That page does not exist.
Supabase redirects to site_url + authorization_url_path, which is /oauth/consent, and then validates the request origin.
The redirect path is in this repository at packages/supabase/config.toml:357-363, which sets authorization_url_path = "/oauth/consent".
What to do
Add the consent page at apps/webapp/src/pages/oauth/consent.tsx.
It must live in the webapp. Only the webapp holds the browser Supabase session, and the redirect target is the webapp origin.
The page reads the pending authorization request, shows the client and the scopes it asks for, and offers approve and deny.
Acceptance
Notes
The client name is attacker-chosen when dynamic client registration is open. A consent page that
renders it as trusted markup, or folds it into its own sentence, invites a person to approve
something they misread. Treat the name as untrusted content.
Do not advertise instant revocation anywhere on this page. A granted access token lives 3600
seconds, and a verified token is cached for 60 seconds at apps/hocuspocus.server/src/lib/auth.ts:52.
Publish the access-token lifetime instead, so the wording matches the behaviour.
Follow the design system. This page is a public utility route, like /privacy and /terms.
Blocked by #223. Nothing renders until the OAuth server is on.
Problem
The Supabase OAuth server redirects a person to a consent page before it issues a token. That page does not exist.
Supabase redirects to
site_url + authorization_url_path, which is/oauth/consent, and then validates the request origin.The redirect path is in this repository at
packages/supabase/config.toml:357-363, which setsauthorization_url_path = "/oauth/consent".What to do
Add the consent page at
apps/webapp/src/pages/oauth/consent.tsx.It must live in the webapp. Only the webapp holds the browser Supabase session, and the redirect target is the webapp origin.
The page reads the pending authorization request, shows the client and the scopes it asks for, and offers approve and deny.
Acceptance
Notes
The client name is attacker-chosen when dynamic client registration is open. A consent page that
renders it as trusted markup, or folds it into its own sentence, invites a person to approve
something they misread. Treat the name as untrusted content.
Do not advertise instant revocation anywhere on this page. A granted access token lives 3600
seconds, and a verified token is cached for 60 seconds at
apps/hocuspocus.server/src/lib/auth.ts:52.Publish the access-token lifetime instead, so the wording matches the behaviour.
Follow the design system. This page is a public utility route, like
/privacyand/terms.Blocked by #223. Nothing renders until the OAuth server is on.