mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 17:35:10 +03:00
## What Adds a warning in Project Settings > API when the `authenticator` role's `pgrst.db_schemas` setting overrides the Dashboard's "Exposed schemas" configuration, plus an inline "Reset override" button to fix it in one click. ## Why `ALTER ROLE authenticator SET pgrst.db_schemas = ...` silently overrides what PostgREST actually exposes, regardless of what's selected in the Dashboard. Users hit a confusing PGRST106 error with no indication that a role-level override is the cause. ## How - New query (`authenticatorRoleConfigQueryOptions`) reads `pg_roles.rolconfig` for the `authenticator` role and parses out any `pgrst.db_schemas` value. Configured to always refetch on mount and window focus, since the fix is often applied outside the Dashboard (SQL editor, another client) with no cache-invalidation event for the app to react to. - `PostgrestConfig.tsx` compares that value against the currently selected schemas and shows an `Admonition` warning naming the actual overriding schemas, with a link to the PGRST106 troubleshooting guide, when they differ. - The warning includes a "Reset override" button that runs `alter role authenticator reset pgrst.db_schemas` after a confirmation step (showing the exact SQL that will run, with a copy button), then refetches so the warning clears immediately without a page reload. ## Testing 1. In the SQL Editor of a test project, run: ```sql alter role authenticator set pgrst.db_schemas = 'public'; ``` 2. Go to Project Settings > API, and select a schema other than (or in addition to) `public` in "Exposed schemas" (e.g. add `api`). 3. The new warning should appear, naming `public` as the schema actually in effect, with a link to the PGRST106 troubleshooting guide. 4. Click "Reset override" in the warning, confirm in the modal, and check that the warning clears immediately without a page reload. 5. Alternatively, clear the override manually from the SQL editor: ```sql alter role authenticator reset pgrst.db_schemas; ``` then navigate away from the API settings page and back (or refocus the browser tab) — the warning should clear without a hard refresh. Fixes [FE-4472](https://linear.app/supabase/issue/FE-4472/warn-when-authenticator-role-overrides-exposed-schemas) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * The API settings page now warns when the authenticator role’s exposed schemas differ from the saved Dashboard configuration. * You can reset the override to restore the saved schema configuration. The reset requires permission and provides success or error feedback. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
58 lines
2.1 KiB
TypeScript
58 lines
2.1 KiB
TypeScript
import { safeSql } from '@supabase/pg-meta'
|
|
import { queryOptions } from '@tanstack/react-query'
|
|
|
|
import { getAuthenticatorDbSchemasOverride } from './authenticator-role-config-query.utils'
|
|
import { databaseKeys } from './keys'
|
|
import { executeSql } from '@/data/sql/execute-sql-mutation'
|
|
import type { ResponseError } from '@/types'
|
|
|
|
export type AuthenticatorRoleConfigVariables = {
|
|
projectRef?: string
|
|
connectionString?: string | null
|
|
}
|
|
|
|
const getAuthenticatorRoleConfigSql = safeSql`
|
|
select rolconfig from pg_roles where rolname = 'authenticator'
|
|
`
|
|
|
|
export async function getAuthenticatorRoleConfig(
|
|
{ projectRef, connectionString }: AuthenticatorRoleConfigVariables,
|
|
signal?: AbortSignal
|
|
) {
|
|
if (!projectRef) throw new Error('projectRef is required')
|
|
|
|
const { result } = await executeSql(
|
|
{
|
|
projectRef,
|
|
connectionString,
|
|
sql: getAuthenticatorRoleConfigSql,
|
|
queryKey: ['authenticator-role-config'],
|
|
},
|
|
signal
|
|
)
|
|
|
|
const rolconfig = (result[0] as { rolconfig: string[] | null } | undefined)?.rolconfig ?? null
|
|
|
|
return getAuthenticatorDbSchemasOverride(rolconfig)
|
|
}
|
|
|
|
export type AuthenticatorRoleConfigData = Awaited<ReturnType<typeof getAuthenticatorRoleConfig>>
|
|
export type AuthenticatorRoleConfigError = ResponseError
|
|
|
|
export const authenticatorRoleConfigQueryOptions = ({
|
|
projectRef,
|
|
connectionString,
|
|
}: AuthenticatorRoleConfigVariables) =>
|
|
queryOptions({
|
|
// eslint-disable-next-line @tanstack/query/exhaustive-deps -- connection string doesn't change the result of the query
|
|
queryKey: databaseKeys.authenticatorRoleConfig(projectRef),
|
|
queryFn: ({ signal }) => getAuthenticatorRoleConfig({ projectRef, connectionString }, signal),
|
|
// The fix for this override is usually applied outside the Dashboard (SQL editor, another
|
|
// client), so there's no cache-invalidation event to react to. Always refetch on mount and
|
|
// window focus so navigating back to this page (or back to this browser tab) picks up a fix
|
|
// immediately, instead of silently serving a stale cached result.
|
|
refetchOnMount: 'always',
|
|
refetchOnWindowFocus: 'always',
|
|
enabled: typeof projectRef !== 'undefined',
|
|
})
|