[PS-2228] Docs: Fliplet.App.Tokens requires a Studio editor or publisher - #304
Merged
Merged
Conversation
…lisher The tokens endpoint now checks the app role, so an app token can no longer read the token list. Update the access section, the type values, and replace the curl example that called the endpoint with an app token. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Deploying fliplet-cli with
|
| Latest commit: |
e8ccb54
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://9d330e83.fliplet-cli.pages.dev |
| Branch Preview URL: | https://fix-ps-2228-tokens-doc-acces.fliplet-cli.pages.dev |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Product areas affected
Developer documentation —
docs/API/fliplet-tokens.md, published at developers.fliplet.com/API/fliplet-tokens. No code or frontmatter changes.What does this PR do?
Brings the
Fliplet.App.Tokenspage in line with the API change in Fliplet/fliplet-api#8690, which restrictsGET/POST/DELETE v1/apps/{appId}/tokensto Studio editors and publishers of the app.403; unauthenticated calls get401.typeacceptsappTokenorintegrationTokenonly; other values return400.JIRA ticket
PS-2228
Result
npm run check:docspasses (strict frontmatter validation) andnpm run test:unitpasses 163/163. Only one file changed, body prose only.Production scan backing the change (EU, US, CA): three apps reference the library, all in Fliplet's own organisation, and only one calls it from code. No customer app depends on an app token reading its own token list. Details are on the ticket.
Checklist
Deployment instructions
Merge after Fliplet/fliplet-api#8690 is released to production. Merging earlier would publish a restriction that is not yet enforced.
Author concerns
auth_tokenvalues to the screen that calls it. Whether it should exist at all is a product question outside this PR.🤖 Generated with Claude Code