Files
supabase/apps/studio/data/database/authenticator-role-config-query.ts
Monica Khoury 123c768de1 Warn when authenticator role overrides exposed schemas (FE-4472) (#50982)
## What

Adds a warning in Project Settings > API when the `authenticator` role's
`pgrst.db_schemas` setting overrides the Dashboard's "Exposed schemas"
configuration, plus an inline "Reset override" button to fix it in one
click.

## Why

`ALTER ROLE authenticator SET pgrst.db_schemas = ...` silently overrides
what PostgREST actually exposes, regardless of what's selected in the
Dashboard. Users hit a confusing PGRST106 error with no indication that
a role-level override is the cause.

## How

- New query (`authenticatorRoleConfigQueryOptions`) reads
`pg_roles.rolconfig`
for the `authenticator` role and parses out any `pgrst.db_schemas`
value.
Configured to always refetch on mount and window focus, since the fix is
often applied outside the Dashboard (SQL editor, another client) with no
  cache-invalidation event for the app to react to.
- `PostgrestConfig.tsx` compares that value against the currently
selected
  schemas and shows an `Admonition` warning naming the actual overriding
  schemas, with a link to the PGRST106 troubleshooting guide, when they
  differ.
- The warning includes a "Reset override" button that runs
  `alter role authenticator reset pgrst.db_schemas` after a confirmation
  step (showing the exact SQL that will run, with a copy button), then
  refetches so the warning clears immediately without a page reload.

## Testing

1. In the SQL Editor of a test project, run:
   ```sql
   alter role authenticator set pgrst.db_schemas = 'public';
   ```
2. Go to Project Settings > API, and select a schema other than (or in
   addition to) `public` in "Exposed schemas" (e.g. add `api`).
3. The new warning should appear, naming `public` as the schema actually
   in effect, with a link to the PGRST106 troubleshooting guide.
4. Click "Reset override" in the warning, confirm in the modal, and
check
   that the warning clears immediately without a page reload.
5. Alternatively, clear the override manually from the SQL editor:
   ```sql
   alter role authenticator reset pgrst.db_schemas;
   ```
then navigate away from the API settings page and back (or refocus the
   browser tab) — the warning should clear without a hard refresh.

Fixes
[FE-4472](https://linear.app/supabase/issue/FE-4472/warn-when-authenticator-role-overrides-exposed-schemas)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* The API settings page now warns when the authenticator role’s exposed
schemas differ from the saved Dashboard configuration.
* You can reset the override to restore the saved schema configuration.
The reset requires permission and provides success or error feedback.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-01 16:02:00 +03:00

58 lines
2.1 KiB
TypeScript

import { safeSql } from '@supabase/pg-meta'
import { queryOptions } from '@tanstack/react-query'
import { getAuthenticatorDbSchemasOverride } from './authenticator-role-config-query.utils'
import { databaseKeys } from './keys'
import { executeSql } from '@/data/sql/execute-sql-mutation'
import type { ResponseError } from '@/types'
export type AuthenticatorRoleConfigVariables = {
projectRef?: string
connectionString?: string | null
}
const getAuthenticatorRoleConfigSql = safeSql`
select rolconfig from pg_roles where rolname = 'authenticator'
`
export async function getAuthenticatorRoleConfig(
{ projectRef, connectionString }: AuthenticatorRoleConfigVariables,
signal?: AbortSignal
) {
if (!projectRef) throw new Error('projectRef is required')
const { result } = await executeSql(
{
projectRef,
connectionString,
sql: getAuthenticatorRoleConfigSql,
queryKey: ['authenticator-role-config'],
},
signal
)
const rolconfig = (result[0] as { rolconfig: string[] | null } | undefined)?.rolconfig ?? null
return getAuthenticatorDbSchemasOverride(rolconfig)
}
export type AuthenticatorRoleConfigData = Awaited<ReturnType<typeof getAuthenticatorRoleConfig>>
export type AuthenticatorRoleConfigError = ResponseError
export const authenticatorRoleConfigQueryOptions = ({
projectRef,
connectionString,
}: AuthenticatorRoleConfigVariables) =>
queryOptions({
// eslint-disable-next-line @tanstack/query/exhaustive-deps -- connection string doesn't change the result of the query
queryKey: databaseKeys.authenticatorRoleConfig(projectRef),
queryFn: ({ signal }) => getAuthenticatorRoleConfig({ projectRef, connectionString }, signal),
// The fix for this override is usually applied outside the Dashboard (SQL editor, another
// client), so there's no cache-invalidation event to react to. Always refetch on mount and
// window focus so navigating back to this page (or back to this browser tab) picks up a fix
// immediately, instead of silently serving a stale cached result.
refetchOnMount: 'always',
refetchOnWindowFocus: 'always',
enabled: typeof projectRef !== 'undefined',
})