import { Badge, cn, Tabs, TabsContent, TabsList, TabsTrigger } from 'ui' import { Admonition } from 'ui-patterns/admonition' import { Results } from '../../SQLEditor/UtilityPanel/Results' import { RLSTableCard } from './RLSTableCard' import { ParseQueryResults } from './RLSTester.types' import { deriveRLSTestState } from './RLSTesterResults.utils' import { useTestQueryRLS } from './useTestQueryRLS' import type { Policy } from '@/components/interfaces/Database/Policies/PolicyTableRow/PolicyTableRow.utils' import { type QueryResponseError } from '@/data/sql/execute-sql-mutation' interface RLSTesterResultsProps { results: Object[] autoLimit: boolean parseQueryResults: ParseQueryResults executeSqlError: Error | QueryResponseError | null | undefined handleSelectEditPolicy: (policy: Policy) => void } export const RLSTesterResults = ({ results, autoLimit, parseQueryResults, executeSqlError, handleSelectEditPolicy, }: RLSTesterResultsProps) => { const { limit } = useTestQueryRLS() const { isServiceRole, tableWithRLSEnabledButNoPolicies, tableWithRLSEnabledWithPolicyFalse, tableWithRLSEnabledWithPoliciesDontApply, noAccessToData, } = deriveRLSTestState(parseQueryResults) const { operation, role } = parseQueryResults const rlsBlockInsert = executeSqlError && operation === 'INSERT' const noAccess = noAccessToData || rlsBlockInsert return (
Summary
{noAccess ? (Ran as
{!parseQueryResults.role ? (postgres
) : parseQueryResults.user ? (
{parseQueryResults.user.email}
) : parseQueryResults.role === 'anon' ? (an Anonymous user
) : null}Not logged in user
)} {!!parseQueryResults.user && (ID: {parseQueryResults.user.id}
)}
This user{' '} {operation === 'SELECT' ? 'has no access to any rows' : `is unable to ${operation?.toLowerCase()} any rows`}{' '} from this query
The table{' '}
{tableWithRLSEnabledButNoPolicies.schema}.
{tableWithRLSEnabledButNoPolicies.table}
{' '}
has RLS enabled but no policies set up for the{' '}
{parseQueryResults.role}{' '}
role.
This user has no access to any rows from this query
The table{' '}
{tableWithRLSEnabledWithPolicyFalse.schema}.
{tableWithRLSEnabledWithPolicyFalse.table}
{' '}
has a policy that evaluates to
false for the{' '}
{parseQueryResults.role}{' '}
role.
This user is unable to {operation?.toLowerCase()} any rows from this query
The table{' '}
{tableWithRLSEnabledWithPoliciesDontApply.schema}.
{tableWithRLSEnabledWithPoliciesDontApply.table}
{' '}
has a policy for the{' '}
{parseQueryResults.role}{' '}
role, but its condition wasn't satisfied for this specific request.
The postgres role has access to all rows
for this query
The postgres role has admin privileges and
bypasses all RLS policies.
Table access
{!isServiceRole && ({results.length} row{results.length > 1 ? 's' : ''} {autoLimit && results.length >= limit && ` (Limited to only ${limit} rows)`}
)}