feat(auth): add OAuth 2.1 authorization consent management API calls #1793
Add this suggestion to a batch that can be applied as a single commit. This suggestion is invalid because no changes were made to the code. Suggestions cannot be applied while the pull request is closed. Suggestions cannot be applied while viewing a subset of changes. Only one suggestion per line can be applied in a batch. Add this suggestion to a batch that can be applied as a single commit. Applying suggestions on deleted lines is not supported. You must change the existing code in this line in order to create a valid suggestion. Outdated suggestions cannot be applied. This suggestion has been applied or marked resolved. Suggestions cannot be applied from pending reviews. Suggestions cannot be applied on multi-line comments. Suggestions cannot be applied while the pull request is queued to merge. Suggestion cannot be applied right now. Please check back later.
Summary
Adds user-facing OAuth authorization methods to
@supabase/auth-jsfor building consent pages when Supabase Auth acts as an OAuth 2.1 authorization server.Implements the consent flow where users approve/deny OAuth client authorization requests.
New API
Namespace:
auth.oauth.*Three new methods for managing OAuth authorization consent:
Use Case
Enables developers to build custom OAuth consent pages for their Supabase projects when acting as an OAuth 2.1 authorization server. Example flow:
authorization_idin URLgetAuthorizationDetails(authorizationId)to fetch client and scope infoapproveAuthorization()ordenyAuthorization()What's NOT Included
Third-party OAuth client integration (calling
/oauth/authorizeand/oauth/tokenfrom external apps) is intentionally not included in this PR.Rationale:
Third-party integration will be addressed through comprehensive documentation showing how to use standard OAuth client libraries with Supabase Auth endpoints.
Breaking Changes
None. This is a purely additive change with zero breaking changes to existing APIs