From 239825e9a3dfb05dcdc8cc1e9c4aa2b5202543c7 Mon Sep 17 00:00:00 2001
From: Danny White <3104761+dnywh@users.noreply.github.com>
Date: Tue, 26 May 2026 18:46:24 +1000
Subject: [PATCH] fix(studio): clarify RLS disable destructiveness (#46357)
## What kind of change does this PR introduce?
UI fix
## What is the current behavior?
RLS disable dialog is just plain prose.
## What is the new behavior?
RLS disable dialog better communicates the high-risk action.
| Before | After |
| --- | --- |
|
|
|
## Summary by CodeRabbit
* **Refactor**
* Improved RLS toggle dialog component logic.
* **Tests**
* Enhanced RLS policies test assertions for better accuracy.
[](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/46357?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)
---
.../interfaces/Database/RLSToggleDialog.tsx | 27 +++++++++++--------
e2e/studio/features/rls-policies.spec.ts | 13 ++++++---
2 files changed, 26 insertions(+), 14 deletions(-)
diff --git a/apps/studio/components/interfaces/Database/RLSToggleDialog.tsx b/apps/studio/components/interfaces/Database/RLSToggleDialog.tsx
index 9ad0b7e6ca1..25888e4ce34 100644
--- a/apps/studio/components/interfaces/Database/RLSToggleDialog.tsx
+++ b/apps/studio/components/interfaces/Database/RLSToggleDialog.tsx
@@ -28,20 +28,25 @@ export function RLSToggleDialog({
onOpenChange,
onConfirm,
}: RLSToggleDialogProps) {
- const title = isEnabled ? 'Disable Row Level Security' : 'Enable Row Level Security'
- const description = isEnabled
- ? 'This table will become publicly readable and writable. Anyone can view, add, update, or delete data in this table, and existing RLS policies will no longer apply.'
- : 'RLS restricts table access until policies allow a request. Existing queries may stop returning rows until policies are added.'
- const confirmLabel = isEnabled ? 'Disable RLS' : 'Enable RLS'
- const confirmVariant = isEnabled ? 'danger' : 'primary'
-
return (
- {title}
+
+ {isEnabled ? 'Disable Row Level Security' : 'Enable Row Level Security'}
+
- {description}{' '}
+ {isEnabled ? (
+ <>
+ This table will become publicly readable and writable.{' '}
+
+ Anyone can view, add, update, or delete data in this table
+
+ , and existing RLS policies will no longer apply.
+ >
+ ) : (
+ 'RLS restricts table access until policies allow a request. Existing queries may stop returning rows until policies are added.'
+ )}{' '}
Learn more
@@ -51,11 +56,11 @@ export function RLSToggleDialog({
Cancel
onConfirm()}
>
- {confirmLabel}
+ {isEnabled ? 'Disable RLS' : 'Enable RLS'}
diff --git a/e2e/studio/features/rls-policies.spec.ts b/e2e/studio/features/rls-policies.spec.ts
index c7dfb6b3f7d..7b96a968f58 100644
--- a/e2e/studio/features/rls-policies.spec.ts
+++ b/e2e/studio/features/rls-policies.spec.ts
@@ -160,10 +160,17 @@ test.describe('RLS Policies', () => {
'RLS disable confirmation modal should appear'
).toBeVisible({ timeout: 50000 })
await expect(
- page.getByText(
- 'This table will become publicly readable and writable. Anyone can view, add, update, or delete data in this table, and existing RLS policies will no longer apply.'
- ),
+ page.getByRole('alertdialog'),
'RLS disable confirmation should explain the access risk'
+ ).toContainText(
+ 'This table will become publicly readable and writable. Anyone can view, add, update, or delete data in this table, and existing RLS policies will no longer apply.'
+ )
+ await expect(
+ page
+ .getByRole('alertdialog')
+ .locator('span.font-medium.text-foreground')
+ .filter({ hasText: 'Anyone can view, add, update, or delete data in this table' }),
+ 'Key risk phrase should be visually emphasized'
).toBeVisible()
await expect(
page.getByRole('alertdialog').getByRole('link', { name: 'Learn more' })