diff --git a/apps/docs/content/guides/database/extensions/pg_graphql.mdx b/apps/docs/content/guides/database/extensions/pg_graphql.mdx index e724379d995..389dc09ddd6 100644 --- a/apps/docs/content/guides/database/extensions/pg_graphql.mdx +++ b/apps/docs/content/guides/database/extensions/pg_graphql.mdx @@ -100,7 +100,13 @@ returning the JSON } ``` -Note that `pg_graphql` fully supports schema introspection so you can connect any GraphQL IDE or schema inspection tool to see the full set of fields and arguments available in the API. +Note that `pg_graphql` supports schema introspection, so you can connect any GraphQL IDE or schema inspection tool to see the full set of fields and arguments available in the API. Starting from `pg_graphql` 1.6.0, introspection is **disabled by default** and must be enabled per schema: + +```sql +comment on schema public is e'@graphql({"introspection": true})'; +``` + +See the [upgrade notes](/guides/platform/upgrading#upgrading-to-pg_graphql-160) for details. ## API diff --git a/apps/docs/content/guides/platform/upgrading.mdx b/apps/docs/content/guides/platform/upgrading.mdx index d589dd42477..58a2c79a6e1 100644 --- a/apps/docs/content/guides/platform/upgrading.mdx +++ b/apps/docs/content/guides/platform/upgrading.mdx @@ -172,3 +172,37 @@ Projects planning to upgrade from Postgres 15 to Postgres 17 need to first disab `pgjwt` was enabled by default on every Supabase project up until Postgres 17. If you weren’t explicitly using `pgjwt` in your project, it’s most likely safe to disable. Existing projects on lower versions of Postgres are not impacted, and the extensions will continue to be supported on projects using Postgres 15, until the end of life of Postgres 15 on the Supabase platform. + +### Upgrading to pg_graphql 1.6.0 + +Starting with pg_graphql 1.6.0, GraphQL introspection is disabled by default. After the upgrade, queries to `__schema` and `__type` will return an error unless introspection is explicitly enabled. See the [pg_graphql configuration docs](https://supabase.github.io/pg_graphql/configuration/#introspection) for full details. + +This affects tools that rely on introspection: + +- Studio's GraphQL inspector (GraphiQL) +- External GraphiQL or GraphQL Playground +- Code generators (e.g. `graphql-codegen`) +- Relay compiler +- Any tool that calls `__schema` or `__type` directly + +Regular data queries (e.g. `accountCollection`, `insertIntoAccountCollection`) are not affected. + +To re-enable introspection on a schema, run the following SQL in the SQL editor: + +```sql +comment on schema public is e'@graphql({"introspection": true})'; +``` + +If your schema already has a comment with other directives (e.g. `inflect_names`), combine the keys — setting a new comment overwrites the old one: + +```sql +comment on schema public is e'@graphql({"inflect_names": true, "introspection": true})'; +``` + +To verify introspection is enabled: + +```sql +select graphql.resolve('{ __schema { queryType { name } } }'); +``` + +Existing projects on pg_graphql 1.5.x are not impacted unless they choose to upgrade. diff --git a/apps/studio/components/interfaces/Settings/Infrastructure/InfrastructureInfo.tsx b/apps/studio/components/interfaces/Settings/Infrastructure/InfrastructureInfo.tsx index 7468e0c470b..0df92efc963 100644 --- a/apps/studio/components/interfaces/Settings/Infrastructure/InfrastructureInfo.tsx +++ b/apps/studio/components/interfaces/Settings/Infrastructure/InfrastructureInfo.tsx @@ -16,7 +16,11 @@ import { FormItemLayout } from 'ui-patterns/form/FormItemLayout/FormItemLayout' import { GenericSkeletonLoader } from 'ui-patterns/ShimmeringLoader' import { ProjectUpgradeAlert } from '../General/Infrastructure/ProjectUpgradeAlert' -import { ReadReplicasWarning, ValidationErrorsWarning } from './UpgradeWarnings' +import { + ReadReplicasWarning, + ValidationErrorsWarning, + ValidationWarningsAdmonition, +} from './UpgradeWarnings' import { NoticeBar } from '@/components/interfaces/DiskManagement/ui/NoticeBar' import { ScaffoldContainer, @@ -83,8 +87,6 @@ export const InfrastructureInfo = () => { const isInactive = project?.status === 'INACTIVE' const hasReadReplicas = (databases ?? []).length > 1 - const hasValidationErrors = (data?.validation_errors ?? []).length > 0 - return ( <> @@ -227,9 +229,13 @@ export const InfrastructureInfo = () => { ) ) : null} - {showDatabaseUpgrades && data && !data.eligible && hasValidationErrors ? ( - - ) : null} + {showDatabaseUpgrades && data && !data.eligible && ( + + )} + + {showDatabaseUpgrades && data && ( + + )} )} diff --git a/apps/studio/components/interfaces/Settings/Infrastructure/UpgradeWarnings.tsx b/apps/studio/components/interfaces/Settings/Infrastructure/UpgradeWarnings.tsx index f46f83cfe87..ba02bf5116f 100644 --- a/apps/studio/components/interfaces/Settings/Infrastructure/UpgradeWarnings.tsx +++ b/apps/studio/components/interfaces/Settings/Infrastructure/UpgradeWarnings.tsx @@ -4,7 +4,10 @@ import { Button } from 'ui' import { Admonition } from 'ui-patterns/admonition' import { InlineLink } from '@/components/ui/InlineLink' -import { ProjectUpgradeEligibilityValidationError } from '@/data/config/project-upgrade-eligibility-query' +import { + ProjectUpgradeEligibilityValidationError, + ProjectUpgradeEligibilityWarning, +} from '@/data/config/project-upgrade-eligibility-query' import { DOCS_URL } from '@/lib/constants' export const ReadReplicasWarning = ({ latestPgVersion }: { latestPgVersion: string }) => { @@ -126,6 +129,8 @@ export const ValidationErrorsWarning = ({ }: { validationErrors: ProjectUpgradeEligibilityValidationError[] }) => { + if (validationErrors.length === 0) return null + return (
@@ -142,3 +147,47 @@ export const ValidationErrorsWarning = ({ ) } + +const getWarningTitle = (warning: ProjectUpgradeEligibilityWarning): string => { + switch (warning.type) { + case 'pg_graphql_introspection_change': + return 'GraphQL introspection will be disabled by default after upgrade' + } +} + +const getWarningDescription = (warning: ProjectUpgradeEligibilityWarning): string => { + switch (warning.type) { + case 'pg_graphql_introspection_change': + return 'After upgrading, queries to `__schema` and `__type` will return an error unless introspection is explicitly re-enabled on the schema. Regular data queries are not affected.' + } +} + +const getWarningLink = (warning: ProjectUpgradeEligibilityWarning): string => { + switch (warning.type) { + case 'pg_graphql_introspection_change': + return `${DOCS_URL}/guides/platform/upgrading#upgrading-to-pg_graphql-160` + } +} + +export const ValidationWarningsAdmonition = ({ + warnings, +}: { + warnings: ProjectUpgradeEligibilityWarning[] +}) => { + if (warnings.length === 0) return null + + return warnings.map((warning, idx) => ( + + + + )) +} diff --git a/apps/studio/data/config/project-upgrade-eligibility-query.ts b/apps/studio/data/config/project-upgrade-eligibility-query.ts index 8e62c0441f2..2f922756647 100644 --- a/apps/studio/data/config/project-upgrade-eligibility-query.ts +++ b/apps/studio/data/config/project-upgrade-eligibility-query.ts @@ -14,6 +14,7 @@ export type ProjectUpgradeEligibilityResponse = components['schemas']['ProjectUpgradeEligibilityResponse'] export type ProjectUpgradeEligibilityValidationError = ProjectUpgradeEligibilityResponse['validation_errors'][number] +export type ProjectUpgradeEligibilityWarning = ProjectUpgradeEligibilityResponse['warnings'][number] /** * Fetches upgrade eligibility information for a project. diff --git a/packages/api-types/types/api.d.ts b/packages/api-types/types/api.d.ts index 0ef1b6b20a7..07d186d944d 100644 --- a/packages/api-types/types/api.d.ts +++ b/packages/api-types/types/api.d.ts @@ -3749,6 +3749,10 @@ export interface components { type: 'active_replication_slot' } )[] + warnings: { + /** @enum {string} */ + type: 'pg_graphql_introspection_change' + }[] } ProjectUpgradeInitiateResponse: { tracking_id: string diff --git a/supa-mdx-lint/Rule003Spelling.toml b/supa-mdx-lint/Rule003Spelling.toml index 6d6937c8b11..c57e093dde1 100644 --- a/supa-mdx-lint/Rule003Spelling.toml +++ b/supa-mdx-lint/Rule003Spelling.toml @@ -225,6 +225,7 @@ allow_list = [ "Grafana", "Grafana OnCall", "GraphQL", + "GraphiQL", "Groonga", "HackerOne", "[Hh][Aa][Pp]roxy",