Scoped PAT availability and complete database_read server-side enforcement
#51030
Unanswered
marcoxxx72-cmyk
asked this question in
Questions
Replies: 1 comment
Comprehensive Architectural Verification: Scoped PATs and
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Hello Supabase Support,
I am preparing a supervised, metadata-only, read-only security validation. I am not requesting credential creation, project/database access, inspection, SQL execution or any configuration change.
My Access Tokens creation form previously displayed Name and Expires but no project or permission selectors. Your current Personal Access Tokens guide documents scoped tokens with selected project and permission restrictions.
Could you please confirm, preferably with direct documentation links:
database_readas its sole permission and no forced, implicit or inherited token permission/resource scope.POST /v1/projects/{ref}/database/query, when the token hasdatabase_readbut notdatabase_write:read_only=falserejected?read_onlyfield rejected or forced to true?POST /v1/projects/{ref}/database/query/read-onlyand excludes the generic query endpoint and MCPexecute_sql.database_read, and identify whether any operation can create or mutate persistent/session/temporary state; alter configuration, roles, grants, functions, branches, migrations or backups; access secrets/Auth/Storage; or trigger an external action.{}.supabase_read_only_user, what versioned visibility guarantees apply topg_roles,pg_auth_members,pg_database,pg_namespace,pg_class,pg_proc,pg_language,pg_depend,pg_extension, andpg_policy? Specifically, can an empty or missing result from those catalogues be interpreted as absence rather than restricted visibility?Please do not ask for or include any token, project reference, account/organisation identifier, database content, API key, password, connection string, authenticated screenshot or other secret. A fixed capability description and public documentation link are preferred.
Thank you.
All reactions