mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 17:35:10 +03:00
## What Adds a warning in Project Settings > API when the `authenticator` role's `pgrst.db_schemas` setting overrides the Dashboard's "Exposed schemas" configuration, plus an inline "Reset override" button to fix it in one click. ## Why `ALTER ROLE authenticator SET pgrst.db_schemas = ...` silently overrides what PostgREST actually exposes, regardless of what's selected in the Dashboard. Users hit a confusing PGRST106 error with no indication that a role-level override is the cause. ## How - New query (`authenticatorRoleConfigQueryOptions`) reads `pg_roles.rolconfig` for the `authenticator` role and parses out any `pgrst.db_schemas` value. Configured to always refetch on mount and window focus, since the fix is often applied outside the Dashboard (SQL editor, another client) with no cache-invalidation event for the app to react to. - `PostgrestConfig.tsx` compares that value against the currently selected schemas and shows an `Admonition` warning naming the actual overriding schemas, with a link to the PGRST106 troubleshooting guide, when they differ. - The warning includes a "Reset override" button that runs `alter role authenticator reset pgrst.db_schemas` after a confirmation step (showing the exact SQL that will run, with a copy button), then refetches so the warning clears immediately without a page reload. ## Testing 1. In the SQL Editor of a test project, run: ```sql alter role authenticator set pgrst.db_schemas = 'public'; ``` 2. Go to Project Settings > API, and select a schema other than (or in addition to) `public` in "Exposed schemas" (e.g. add `api`). 3. The new warning should appear, naming `public` as the schema actually in effect, with a link to the PGRST106 troubleshooting guide. 4. Click "Reset override" in the warning, confirm in the modal, and check that the warning clears immediately without a page reload. 5. Alternatively, clear the override manually from the SQL editor: ```sql alter role authenticator reset pgrst.db_schemas; ``` then navigate away from the API settings page and back (or refocus the browser tab) — the warning should clear without a hard refresh. Fixes [FE-4472](https://linear.app/supabase/issue/FE-4472/warn-when-authenticator-role-overrides-exposed-schemas) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * The API settings page now warns when the authenticator role’s exposed schemas differ from the saved Dashboard configuration. * You can reset the override to restore the saved schema configuration. The reset requires permission and provides success or error feedback. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
84 lines
4.2 KiB
TypeScript
84 lines
4.2 KiB
TypeScript
import { sqlKeys } from '@/data/sql/keys'
|
|
|
|
export const databaseKeys = {
|
|
schemas: (projectRef: string | undefined) => ['projects', projectRef, 'schemas'] as const,
|
|
keywords: (projectRef: string | undefined) => ['projects', projectRef, 'keywords'] as const,
|
|
migrations: (projectRef: string | undefined) => ['projects', projectRef, 'migrations'] as const,
|
|
tableColumns: (
|
|
projectRef: string | undefined,
|
|
schema: string | undefined,
|
|
table: string | undefined
|
|
) => ['projects', projectRef, 'table-columns', schema, table] as const,
|
|
tableColumnsPrefix: (projectRef: string | undefined) =>
|
|
['projects', projectRef, 'table-columns'] as const,
|
|
databaseFunctions: (projectRef: string | undefined, schema?: string) =>
|
|
['projects', projectRef, 'database-functions', schema].filter(Boolean),
|
|
entityDefinition: (projectRef: string | undefined, id?: number) =>
|
|
['projects', projectRef, 'entity-definition', id] as const,
|
|
entityDefinitions: (projectRef: string | undefined, schemas: string[]) =>
|
|
['projects', projectRef, 'entity-definitions', schemas] as const,
|
|
tableDefinition: (projectRef: string | undefined, id?: number) =>
|
|
['projects', projectRef, 'table-definition', id] as const,
|
|
viewDefinition: (projectRef: string | undefined, id?: number, includeCreateStatement?: boolean) =>
|
|
['projects', projectRef, 'view-definition', id, includeCreateStatement ?? false] as const,
|
|
backups: (projectRef: string | undefined) =>
|
|
['projects', projectRef, 'database', 'backups'] as const,
|
|
poolingConfiguration: (projectRef: string | undefined) =>
|
|
['projects', projectRef, 'database', 'pooling-configuration'] as const,
|
|
indexesFromQuery: (projectRef: string | undefined, query: string) =>
|
|
['projects', projectRef, 'indexes', { query }] as const,
|
|
indexAdvisorFromQuery: (
|
|
projectRef: string | undefined,
|
|
query: string,
|
|
connectionString?: string
|
|
) => {
|
|
// Use only the host (no credentials) as a safe cache discriminator
|
|
let connectionFingerprint: string | undefined
|
|
if (connectionString) {
|
|
try {
|
|
connectionFingerprint = new URL(connectionString).host
|
|
} catch {
|
|
connectionFingerprint = undefined
|
|
}
|
|
}
|
|
return ['projects', projectRef, 'index-advisor', { query, connectionFingerprint }] as const
|
|
},
|
|
tableConstraints: (projectRef: string | undefined, id?: number) =>
|
|
['projects', projectRef, 'table-constraints', id] as const,
|
|
foreignKeyConstraintsPrefix: (projectRef: string | undefined, schema?: string) =>
|
|
schema === undefined
|
|
? (['projects', projectRef, 'foreign-key-constraints'] as const)
|
|
: (['projects', projectRef, 'foreign-key-constraints', schema] as const),
|
|
foreignKeyConstraints: (projectRef: string | undefined, schema?: string, options = {}) =>
|
|
['projects', projectRef, 'foreign-key-constraints', schema, options] as const,
|
|
databaseSize: (projectRef: string | undefined) =>
|
|
['projects', projectRef, 'database-size'] as const,
|
|
maxConnections: (projectRef: string | undefined) =>
|
|
['projects', projectRef, 'max-connections'] as const,
|
|
pgbouncerStatus: (projectRef: string | undefined) =>
|
|
['projects', projectRef, 'pgbouncer', 'status'] as const,
|
|
pgbouncerConfig: (projectRef: string | undefined) =>
|
|
['projects', projectRef, 'pgbouncer', 'config'] as const,
|
|
checkPrimaryKeysExists: (
|
|
projectRef: string | undefined,
|
|
tables: { name: string; schema: string }[]
|
|
) => ['projects', projectRef, 'check-primary-keys', tables] as const,
|
|
tableIndexAdvisor: (
|
|
projectRef: string | undefined,
|
|
schema: string | undefined,
|
|
table: string | undefined
|
|
) => ['projects', projectRef, 'table-index-advisor', schema, table] as const,
|
|
supamonitorEnabled: (projectRef: string | undefined) =>
|
|
['projects', projectRef, 'supamonitor-enabled'] as const,
|
|
databaseActivity: (projectRef: string | undefined) =>
|
|
['projects', projectRef, 'database-activity'] as const,
|
|
authenticatorRoleConfig: (projectRef: string | undefined) =>
|
|
['projects', projectRef, 'authenticator-role-config'] as const,
|
|
}
|
|
|
|
export const getLiveTupleEstimateKey = (
|
|
projectRef: string | undefined,
|
|
table: string,
|
|
schema = 'public'
|
|
) => sqlKeys.query(projectRef, ['live-tuple-estimate', schema, table])
|