Update programmatically generated policies to use authenticated role (#41812)

* Update programmatically generated policies to use authenticated role

* Fix test

* Fix unit tests
This commit is contained in:
Joshen Lim authored and GitHub committed 2026-01-15 10:27:07 +07:00
1 parent 202a3f96ad
commit 17715744b2
3 files changed
+8 -7

No files matched your search

@@ -156,7 +156,7 @@ describe('Policies.utils - Policy Generation', () => {
expect(policy).toHaveProperty('schema', 'public')
expect(policy).toHaveProperty('action', 'PERMISSIVE')
expect(policy).toHaveProperty('roles')
expect(policy.roles).toContain('public')
expect(policy.roles).toContain('authenticated')
}
})
@@ -214,7 +214,7 @@ describe('Policies.utils - Policy Generation', () => {
expect(selectPolicy?.sql).toContain('CREATE POLICY')
expect(selectPolicy?.sql).toContain('public.posts')
expect(selectPolicy?.sql).toContain('AS PERMISSIVE FOR SELECT')
expect(selectPolicy?.sql).toContain('TO public')
expect(selectPolicy?.sql).toContain('TO authenticated')
expect(selectPolicy?.sql).toContain('USING')
expect(selectPolicy?.sql).toContain('auth.uid()')
})
@@ -316,7 +316,7 @@ const buildPoliciesForPath = (
return (['SELECT', 'INSERT', 'UPDATE', 'DELETE'] as const).map((command) => {
const name = `Enable ${command.toLowerCase()} access for users based on ${ident(targetCol)}`
const base = `CREATE POLICY "${name}" ON ${ident(table.schema)}.${ident(table.name)} AS PERMISSIVE FOR ${command} TO public`
const base = `CREATE POLICY "${name}" ON ${ident(table.schema)}.${ident(table.name)} AS PERMISSIVE FOR ${command} TO authenticated`
const sql =
command === 'INSERT'
@@ -338,7 +338,7 @@ const buildPoliciesForPath = (
definition,
check,
action: 'PERMISSIVE' as const,
roles: ['public'],
roles: ['authenticated'],
}
})
}
@@ -319,9 +319,10 @@ export const ApiAccessToggle = ({
<p className="text-sm text-foreground flex items-center gap-1.5">
Data API Access
<InfoTooltip side="top" className="max-w-80">
This controls which operations the <code className="text-xs">anon</code> and{' '}
<code className="text-xs">authenticated</code> roles can perform on this table via
the Data API. Unselected privileges are revoked from these roles.
This controls which operations the <code className="text-code-inline">anon</code>{' '}
and <code className="text-code-inline whitespace-nowrap">authenticated</code> roles
can perform on this table via the Data API. Unselected privileges are revoked from
these roles.
</InfoTooltip>
</p>
<p className="text-sm text-foreground-lighter">