Commit Graph
1 Commits
Author SHA1 Message Date
Marouane SoudaandCharis Lam 0e35cbf4a4 Security definer materialized view (#40800)
Fixes #40799 

Now, the correct error will be shown for materialized views accessible
to `anon` and `authenticated` roles via Data API, instead of the
unrelated "Security Definer view" error.

For convenience, users can immediately fix the issue by running the
correct SQL query to revoke select from `anon` and `authenticated`, just
by clicking on "confirm" on the confirmation modal I just created.



https://github.com/user-attachments/assets/f3ce9353-4ad0-4063-bf33-0b403f5fa87a

Before

<img width="958" height="440" alt="materialized"
src="https://github.com/user-attachments/assets/89047c91-da35-4b9f-b7e3-82e877bcf2c6"
/>

Edit:

Thanks to the review by @saltcod, I now realise that revoking access
from `anon` and `authenticated` users might not be the optimal solution
since it would break many projects relying on the access to materialized
views.

After pondering on the possible solutions, I figured there isn't an easy
one, so I did away with the autofix button, and instead created a dialog
explaining three possible options for the user, with a sample query
under each one for convenience.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added clearer warnings when materialized views are accessible through
the API.
* Added a dialog explaining how to review and revoke API access for
materialized views.
* Added guidance and code examples for restricting access to API roles.
  * Added a link to the Security Advisor for additional information.

* **Improvements**
* Updated materialized view tooltips to accurately describe API
accessibility.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Charis Lam <26616127+charislam@users.noreply.github.com>
2026-09-07 17:56:57 -04:00