diff --git a/apps/studio/components/interfaces/Auth/RLSTester/RLSTableCard.tsx b/apps/studio/components/interfaces/Auth/RLSTester/RLSTableCard.tsx index 18670c8ebb7..25ca8b5942b 100644 --- a/apps/studio/components/interfaces/Auth/RLSTester/RLSTableCard.tsx +++ b/apps/studio/components/interfaces/Auth/RLSTester/RLSTableCard.tsx @@ -8,9 +8,9 @@ import { CollapsibleTrigger_Shadcn_, WarningIcon, } from 'ui' -import { Admonition } from 'ui-patterns' import { ButtonTooltip } from '@/components/ui/ButtonTooltip' +import { useRoleImpersonationStateSnapshot } from '@/state/role-impersonation-state' interface RLSTableCardProps { table: { schema: string; name: string; isRLSEnabled: boolean } @@ -53,9 +53,10 @@ export const RLSTableCard = ({ <> {!!trueOnlyPolicy ? (
- A policy exists for the {role} role on this
- table that evaluates to true, so all data is
- accessible to the role.
+ The policy "{trueOnlyPolicy.name}" for the{' '}
+ {role} role on this table that evaluates to{' '}
+ true, so all data from this query is
+ accessible to this user.
@@ -65,31 +66,33 @@ export const RLSTableCard = ({
)} -- Evaluated policies -
-{policy.name}
-
- Show rows where:{' '}
- {policy.definition}
-
+ {policies.length} {policies.length > 1 ? 'policies' : 'policy'} applied +
+{policy.name}
+
+ Show rows where:{' '}
+ {policy.definition}
+
- Table access summary + Summary
- {!isServiceRole && hasRLSEnabledButNoPolicies && ( -Ran as
+ {!parseQueryResults.role ? ( +postgres
+ ) : parseQueryResults.user ? (
+ {parseQueryResults.user.email}
+ ) : parseQueryResults.externalAuth ? ( ++ {parseQueryResults.externalAuth} +
+ ) : ( +{parseQueryResults.role}
+ )}
+ Not logged in user
+ )} + {!!parseQueryResults.user && ( +ID: {parseQueryResults.user.id}
+ )}
+
Query returns no rows for the{' '}
{parseQueryResults.role} role
- One of the tables has RLS enabled, but no policies set up for this role
+ The table{' '}
+
+ {tableWithRLSEnabledButNoPolicies.schema}.
+ {tableWithRLSEnabledButNoPolicies.table}
+ {' '}
+ has RLS enabled but no policies set up for this role.
+ Query returns all rows for the{' '}
+ postgres role
+
+ The role has admin privileges and bypasses all RLS policies. +
+- Table access -
*/} ++ Policies applied +