Skip to content

[PS-2228] Docs: Fliplet.App.Tokens requires a Studio editor or publisher - #304

Merged
Arpanexe merged 1 commit into
masterfrom
fix/PS-2228-tokens-doc-access
Sep 30, 2026
Merged

Arpanexe merged 1 commit into
masterfrom
fix/PS-2228-tokens-doc-access

Conversation

@Arpanexe

@Arpanexe Arpanexe commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Product areas affected

Developer documentation — docs/API/fliplet-tokens.md, published at developers.fliplet.com/API/fliplet-tokens. No code or frontmatter changes.

What does this PR do?

Brings the Fliplet.App.Tokens page in line with the API change in Fliplet/fliplet-api#8690, which restricts GET/POST/DELETE v1/apps/{appId}/tokens to Studio editors and publishers of the app.

  • Access section now states who can call the endpoint: Studio editor or publisher. App and integration tokens, data source logins, viewers and testers get 403; unauthenticated calls get 401.
  • Explains the one way it still works inside a published app: the person is signed in through the Fliplet login component with a Studio account that is an editor or publisher.
  • Notes that direct REST calls should use the master app ID, since roles are checked against the master app.
  • type accepts appToken or integrationToken only; other values return 400.
  • Replaces the curl example that called the tokens endpoint with an app token. It now shows a data source read, matching the section it sits in.
  • Intro no longer suggests calling it from a general app screen.

JIRA ticket

PS-2228

Result

npm run check:docs passes (strict frontmatter validation) and npm run test:unit passes 163/163. Only one file changed, body prose only.

Production scan backing the change (EU, US, CA): three apps reference the library, all in Fliplet's own organisation, and only one calls it from code. No customer app depends on an app token reading its own token list. Details are on the ticket.

Checklist

  • Added automated test coverage as appropriate for this change. (Docs only; existing docs validation and unit tests run and pass.)

Deployment instructions

Merge after Fliplet/fliplet-api#8690 is released to production. Merging earlier would publish a restriction that is not yet enforced.

Author concerns

  • The master app ID guidance is derived from how the role check works and from one production call that used a published app ID. It is worded as guidance rather than a guarantee.
  • The library still returns raw auth_token values to the screen that calls it. Whether it should exist at all is a product question outside this PR.

🤖 Generated with Claude Code

…lisher

The tokens endpoint now checks the app role, so an app token can no longer read the token list. Update the access section, the type values, and replace the curl example that called the endpoint with an app token.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying fliplet-cli with  Cloudflare Pages  Cloudflare Pages

Latest commit: e8ccb54
Status: ✅  Deploy successful!
Preview URL: https://9d330e83.fliplet-cli.pages.dev
Branch Preview URL: https://fix-ps-2228-tokens-doc-acces.fliplet-cli.pages.dev

View logs

@Arpanexe
Arpanexe merged commit 8c88c44 into master Sep 30, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant