mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 17:35:10 +03:00
<!-- ccr-slack-attribution --> _Requested by **Saxon Fletcher** · [Slack thread](https://supabase.slack.com/archives/C051L8U2EJF/p1789995309253479?thread_ts=1789995309.253479&cid=C051L8U2EJF)_ Resolves AI-1246 ## Problem **Before:** The Assistant's `list_policies` tool fails in about 70% of traces. It only "succeeds" when the org has AI opt-in disabled, because then it returns the privacy stub and never makes a request. When opt-in is enabled, it runs the pg-meta query server-side with no `Authorization` header, so the request is unauthenticated and fails. The Assistant then falls back to `execute_sql`. **After:** `list_policies` sends the caller's `Authorization` header, the same way `execute_sql` in `studio-tools.ts` already does, so it returns the project's RLS policies. ## Solution `getTools` already receives `authorization` but didn't pass it to `getSchemaTools`. This PR passes it through. `list_policies` builds `{ Authorization }` from it, and `getDatabasePolicies` gets an optional `headersInit` argument that it forwards to `executeSql`, the same pattern `getDatabaseFunctions` uses. Existing client-side callers of `getDatabasePolicies` don't change. Files: `lib/ai/tools/index.ts`, `lib/ai/tools/schema-tools.ts`, `data/database-policies/database-policies-query.ts`, plus tests in `lib/ai/tools/schema-tools.test.ts` (new) and `lib/ai/tools/index.test.ts`. ## Review instructions 1. Read `schema-tools.ts` and compare it with the `authHeaders` handling in `studio-tools.ts` (`execute_sql`). 2. On the preview, use an org with AI opt-in set to at least "schema" and ask the Assistant to list the RLS policies on `public`. `list_policies` should return the policies without falling back to `execute_sql`. Local gates (all passed): - `pnpm typecheck` in `apps/studio` (next typegen + `tsc --noEmit`) - `npx eslint` on touched files: 0 errors. The 2 warnings are on lines this PR doesn't change. - `npx vitest run lib/ai/tools/schema-tools.test.ts lib/ai/tools/index.test.ts lib/ai/tool-filter.test.ts`: 24/24 passed. I also ran the new header test against the old `schema-tools.ts` and it failed, as expected. - `SORT_IMPORTS=false npx prettier --config prettier.config.mjs --check` on touched files Follow-up, not in this PR: `getRlsKnowledge` in `fallback-tools.ts` (self-hosted path) also calls `getDatabasePolicies` without headers, even though a `headers` object is already in scope there. ## AI disclosure Claude Code (agent) wrote this PR from the Slack request. @SaxonF (Saxon Fletcher) is the accountable human owner. A human needs to review it before merge. ## Checklist - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [ ] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill (N/A, no docs changes) 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_0171Mk7SiKYLDDoAQvbDYfeK --- _Generated by [Claude Code](https://claude.ai/code/session_0171Mk7SiKYLDDoAQvbDYfeK)_ --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
63 lines
2.1 KiB
TypeScript
63 lines
2.1 KiB
TypeScript
import pgMeta, { type PGPolicy } from '@supabase/pg-meta'
|
|
import { useQuery } from '@tanstack/react-query'
|
|
|
|
import { executeSql } from '../sql/execute-sql-mutation'
|
|
import { databasePoliciesKeys } from './keys'
|
|
import type { Policy } from '@/components/interfaces/Database/Policies/PolicyTableRow/PolicyTableRow.utils'
|
|
import { useSelectedProjectQuery } from '@/hooks/misc/useSelectedProject'
|
|
import { PROJECT_STATUS } from '@/lib/constants'
|
|
import type { ResponseError, UseCustomQueryOptions } from '@/types'
|
|
|
|
type DatabasePoliciesVariables = {
|
|
projectRef?: string
|
|
connectionString?: string | null
|
|
schemas?: string[]
|
|
}
|
|
|
|
export async function getDatabasePolicies(
|
|
{ projectRef, connectionString, schemas }: DatabasePoliciesVariables,
|
|
signal?: AbortSignal,
|
|
headersInit?: HeadersInit
|
|
) {
|
|
if (!projectRef) throw new Error('projectRef is required')
|
|
|
|
const { sql } = pgMeta.policies.list({ includedSchemas: schemas })
|
|
const { result } = await executeSql(
|
|
{
|
|
projectRef,
|
|
connectionString,
|
|
sql,
|
|
queryKey: ['policies', schemas],
|
|
},
|
|
signal,
|
|
headersInit
|
|
)
|
|
|
|
return result as PGPolicy[]
|
|
}
|
|
|
|
export type DatabasePoliciesData = Awaited<ReturnType<typeof getDatabasePolicies>>
|
|
export type DatabasePoliciesError = ResponseError
|
|
|
|
function markSavedPolicySafe(policy: DatabasePoliciesData[number]): Policy {
|
|
return policy as Policy
|
|
}
|
|
|
|
export const useDatabasePoliciesQuery = <TData = Policy[]>(
|
|
{ projectRef, connectionString, schemas }: DatabasePoliciesVariables,
|
|
{ enabled = true, ...options }: UseCustomQueryOptions<Policy[], DatabasePoliciesError, TData> = {}
|
|
) => {
|
|
const { data: project } = useSelectedProjectQuery()
|
|
const isActive = project?.status === PROJECT_STATUS.ACTIVE_HEALTHY
|
|
|
|
return useQuery<Policy[], DatabasePoliciesError, TData>({
|
|
queryKey: databasePoliciesKeys.list(projectRef, schemas),
|
|
queryFn: ({ signal }) =>
|
|
getDatabasePolicies({ projectRef, connectionString, schemas }, signal).then((data) =>
|
|
data.map(markSavedPolicySafe)
|
|
),
|
|
enabled: enabled && typeof projectRef !== 'undefined' && isActive,
|
|
...options,
|
|
})
|
|
}
|