From 08fc3ec28738d9930754270aa8d1fa8bde371dad Mon Sep 17 00:00:00 2001 From: Naren <41925131+narendraio@users.noreply.github.com> Date: Wed, 23 Sep 2026 14:35:00 +0530 Subject: [PATCH] fix(self-hosted): grant supabase_functions_admin USAGE on extensions schema (#46526) --- docker/volumes/db/webhooks.sql | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/docker/volumes/db/webhooks.sql b/docker/volumes/db/webhooks.sql index 5837b86188e..fe273decb89 100644 --- a/docker/volumes/db/webhooks.sql +++ b/docker/volumes/db/webhooks.sql @@ -122,6 +122,10 @@ BEGIN; ALTER table "supabase_functions".hooks OWNER TO supabase_functions_admin; ALTER function "supabase_functions".http_request() OWNER TO supabase_functions_admin; GRANT supabase_functions_admin TO postgres; + -- http_request() is SECURITY DEFINER and runs as supabase_functions_admin. Serializing + -- NEW/OLD can touch objects in the extensions schema (PostGIS geometry reads + -- extensions.spatial_ref_sys), so the role needs USAGE on it. + GRANT USAGE ON SCHEMA extensions TO supabase_functions_admin; -- Remove unused supabase_pg_net_admin role DO $$