mirror of
https://github.com/supabase/supabase.git
synced 2026-10-09 19:35:06 +03:00
Mark provenance of SQL via the branded types SafeSqlFragment and UntrustedSqlFragment. Only SafeSqlFragment should be executed; UntrustedSqlFragments require some kind of implicit user approval (show on screen + user has to click something) before they are promoted to SafeSqlFragment. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Editor and RLS tester show loading states for inferred/generated SQL and include a dedicated user SQL editor for safer edits. * **Refactor** * Platform-wide SQL handling tightened: snippets and AI-generated SQL are treated as untrusted/display-only until promoted, improving safety and consistency. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
85 lines
2.8 KiB
TypeScript
85 lines
2.8 KiB
TypeScript
import { DEFAULT_PLATFORM_APPLICATION_NAME } from '@supabase/pg-meta/src/constants'
|
|
import { useQuery } from '@tanstack/react-query'
|
|
|
|
import { databaseTriggerKeys } from './keys'
|
|
import type { PostgresTrigger } from '@/components/interfaces/Database/Triggers/TriggersList/TriggerList.utils'
|
|
import { get, handleError } from '@/data/fetchers'
|
|
import type { ResponseError, UseCustomQueryOptions } from '@/types'
|
|
|
|
function markSavedTriggerSafe(trigger: DatabaseTriggersData[number]): PostgresTrigger {
|
|
return trigger as PostgresTrigger
|
|
}
|
|
|
|
export type DatabaseTriggersVariables = {
|
|
projectRef?: string
|
|
connectionString?: string | null
|
|
}
|
|
|
|
export async function getDatabaseTriggers(
|
|
{ projectRef, connectionString }: DatabaseTriggersVariables,
|
|
signal?: AbortSignal
|
|
) {
|
|
if (!projectRef) throw new Error('projectRef is required')
|
|
|
|
let headers = new Headers()
|
|
if (connectionString) headers.set('x-connection-encrypted', connectionString)
|
|
|
|
const { data, error } = await get('/platform/pg-meta/{ref}/triggers', {
|
|
params: {
|
|
header: {
|
|
'x-connection-encrypted': connectionString!,
|
|
'x-pg-application-name': DEFAULT_PLATFORM_APPLICATION_NAME,
|
|
},
|
|
path: { ref: projectRef },
|
|
query: undefined as any,
|
|
},
|
|
headers,
|
|
signal,
|
|
})
|
|
|
|
if (error) handleError(error)
|
|
return data
|
|
}
|
|
|
|
export type DatabaseTriggersData = Awaited<ReturnType<typeof getDatabaseTriggers>>
|
|
export type DatabaseTriggersError = ResponseError
|
|
|
|
export const useDatabaseHooksQuery = <TData = DatabaseTriggersData>(
|
|
{ projectRef, connectionString }: DatabaseTriggersVariables,
|
|
{
|
|
enabled = true,
|
|
...options
|
|
}: UseCustomQueryOptions<DatabaseTriggersData, DatabaseTriggersError, TData> = {}
|
|
) =>
|
|
useQuery<DatabaseTriggersData, DatabaseTriggersError, TData>({
|
|
queryKey: databaseTriggerKeys.list(projectRef),
|
|
queryFn: ({ signal }) => getDatabaseTriggers({ projectRef, connectionString }, signal),
|
|
select: (data) => {
|
|
return data.filter((trigger) => {
|
|
return (
|
|
trigger.function_schema === 'supabase_functions' &&
|
|
(trigger.schema !== 'net' || trigger.function_args.length === 0)
|
|
)
|
|
}) as any
|
|
},
|
|
enabled: enabled && typeof projectRef !== 'undefined',
|
|
...options,
|
|
})
|
|
|
|
export const useDatabaseTriggersQuery = <TData = PostgresTrigger[]>(
|
|
{ projectRef, connectionString }: DatabaseTriggersVariables,
|
|
{
|
|
enabled = true,
|
|
...options
|
|
}: UseCustomQueryOptions<PostgresTrigger[], DatabaseTriggersError, TData> = {}
|
|
) =>
|
|
useQuery<PostgresTrigger[], DatabaseTriggersError, TData>({
|
|
queryKey: databaseTriggerKeys.list(projectRef),
|
|
queryFn: ({ signal }) =>
|
|
getDatabaseTriggers({ projectRef, connectionString }, signal).then((data) =>
|
|
data.map(markSavedTriggerSafe)
|
|
),
|
|
enabled: enabled && typeof projectRef !== 'undefined',
|
|
...options,
|
|
})
|