import { Badge, cn, Tabs, TabsContent, TabsList, TabsTrigger } from 'ui' import { Admonition } from 'ui-patterns/admonition' import { Results } from '../../SQLEditor/UtilityPanel/Results' import { RLSTableCard } from './RLSTableCard' import { ParseQueryResults } from './RLSTester.types' import { deriveRLSTestState } from './RLSTesterResults.utils' import { useTestQueryRLS } from './useTestQueryRLS' import type { Policy } from '@/components/interfaces/Database/Policies/PolicyTableRow/PolicyTableRow.utils' import { type QueryResponseError } from '@/data/sql/execute-sql-mutation' interface RLSTesterResultsProps { results: Object[] autoLimit: boolean parseQueryResults: ParseQueryResults executeSqlError: Error | QueryResponseError | null | undefined handleSelectEditPolicy: (policy: Policy) => void } export const RLSTesterResults = ({ results, autoLimit, parseQueryResults, executeSqlError, handleSelectEditPolicy, }: RLSTesterResultsProps) => { const { limit } = useTestQueryRLS() const { isServiceRole, tableWithRLSEnabledButNoPolicies, tableWithRLSEnabledWithPolicyFalse, tableWithRLSEnabledWithPoliciesDontApply, noAccessToData, } = deriveRLSTestState(parseQueryResults) const { operation, role } = parseQueryResults const rlsBlockInsert = executeSqlError && operation === 'INSERT' const noAccess = noAccessToData || rlsBlockInsert return (

Summary

{noAccess ? ( No access ) : ( {results.length > 0 ? 'Can access' : 'Has access'} )}
Policies applied Data preview {!!parseQueryResults && (

Ran as

{!parseQueryResults.role ? ( postgres ) : parseQueryResults.user ? (

{parseQueryResults.user.email}

) : parseQueryResults.role === 'anon' ? (

an Anonymous user

) : null}
{parseQueryResults.role === 'anon' && (

Not logged in user

)} {!!parseQueryResults.user && ( ID: {parseQueryResults.user.id} )}
)} {!isServiceRole && (!!tableWithRLSEnabledButNoPolicies ? (

This user{' '} {operation === 'SELECT' ? 'has no access to any rows' : `is unable to ${operation?.toLowerCase()} any rows`}{' '} from this query

The table{' '} {tableWithRLSEnabledButNoPolicies.schema}. {tableWithRLSEnabledButNoPolicies.table} {' '} has RLS enabled but no policies set up for the{' '} {parseQueryResults.role}{' '} role.

) : tableWithRLSEnabledWithPolicyFalse ? (

This user has no access to any rows from this query

The table{' '} {tableWithRLSEnabledWithPolicyFalse.schema}. {tableWithRLSEnabledWithPolicyFalse.table} {' '} has a policy that evaluates to false for the{' '} {parseQueryResults.role}{' '} role.

) : rlsBlockInsert && parseQueryResults.user && tableWithRLSEnabledWithPoliciesDontApply ? (

This user is unable to {operation?.toLowerCase()} any rows from this query

The table{' '} {tableWithRLSEnabledWithPoliciesDontApply.schema}. {tableWithRLSEnabledWithPoliciesDontApply.table} {' '} has a policy for the{' '} {parseQueryResults.role}{' '} role, but its condition wasn't satisfied for this specific request.

) : null)} {isServiceRole && (

The postgres role has access to all rows for this query

The postgres role has admin privileges and bypasses all RLS policies.

)}

Table access

{!isServiceRole && (
{parseQueryResults?.tables.map((x) => { const { schema, table, tablePolicies, isRLSEnabled } = x return ( ) })}
)}
{results.length > 0 && (

{results.length} row{results.length > 1 ? 's' : ''} {autoLimit && results.length >= limit && ` (Limited to only ${limit} rows)`}

)}
) }