Files
supabase/apps/studio/lib/ai/tools/index.test.ts
ec574f3a51 fix(studio): pass Authorization header to assistant list_policies tool (#50756)
<!-- ccr-slack-attribution -->
_Requested by **Saxon Fletcher** · [Slack
thread](https://supabase.slack.com/archives/C051L8U2EJF/p1789995309253479?thread_ts=1789995309.253479&cid=C051L8U2EJF)_

Resolves AI-1246

## Problem

**Before:** The Assistant's `list_policies` tool fails in about 70% of
traces. It only "succeeds" when the org has AI opt-in disabled, because
then it returns the privacy stub and never makes a request. When opt-in
is enabled, it runs the pg-meta query server-side with no
`Authorization` header, so the request is unauthenticated and fails. The
Assistant then falls back to `execute_sql`.

**After:** `list_policies` sends the caller's `Authorization` header,
the same way `execute_sql` in `studio-tools.ts` already does, so it
returns the project's RLS policies.

## Solution

`getTools` already receives `authorization` but didn't pass it to
`getSchemaTools`. This PR passes it through. `list_policies` builds `{
Authorization }` from it, and `getDatabasePolicies` gets an optional
`headersInit` argument that it forwards to `executeSql`, the same
pattern `getDatabaseFunctions` uses. Existing client-side callers of
`getDatabasePolicies` don't change.

Files: `lib/ai/tools/index.ts`, `lib/ai/tools/schema-tools.ts`,
`data/database-policies/database-policies-query.ts`, plus tests in
`lib/ai/tools/schema-tools.test.ts` (new) and
`lib/ai/tools/index.test.ts`.

## Review instructions

1. Read `schema-tools.ts` and compare it with the `authHeaders` handling
in `studio-tools.ts` (`execute_sql`).
2. On the preview, use an org with AI opt-in set to at least "schema"
and ask the Assistant to list the RLS policies on `public`.
`list_policies` should return the policies without falling back to
`execute_sql`.

Local gates (all passed):
- `pnpm typecheck` in `apps/studio` (next typegen + `tsc --noEmit`)
- `npx eslint` on touched files: 0 errors. The 2 warnings are on lines
this PR doesn't change.
- `npx vitest run lib/ai/tools/schema-tools.test.ts
lib/ai/tools/index.test.ts lib/ai/tool-filter.test.ts`: 24/24 passed. I
also ran the new header test against the old `schema-tools.ts` and it
failed, as expected.
- `SORT_IMPORTS=false npx prettier --config prettier.config.mjs --check`
on touched files

Follow-up, not in this PR: `getRlsKnowledge` in `fallback-tools.ts`
(self-hosted path) also calls `getDatabasePolicies` without headers,
even though a `headers` object is already in scope there.

## AI disclosure

Claude Code (agent) wrote this PR from the Slack request. @SaxonF (Saxon
Fletcher) is the accountable human owner. A human needs to review it
before merge.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill (N/A, no docs changes)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_0171Mk7SiKYLDDoAQvbDYfeK

---
_Generated by [Claude
Code](https://claude.ai/code/session_0171Mk7SiKYLDDoAQvbDYfeK)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-23 14:38:40 +08:00

113 lines
4.3 KiB
TypeScript

import { beforeEach, describe, expect, it, vi } from 'vitest'
import { getTools } from './index'
import { getMcpTools } from './mcp-tools'
import { getSchemaTools } from './schema-tools'
vi.mock('common', () => ({ IS_PLATFORM: true }))
vi.mock('./mcp-tools', () => ({ getMcpTools: vi.fn() }))
vi.mock('./studio-tools', () => ({ getStudioTools: vi.fn(() => ({ studio_tool: {} })) }))
vi.mock('./schema-tools', () => ({ getSchemaTools: vi.fn(() => ({ schema_tool: {} })) }))
vi.mock('./incident-tools', () => ({ getIncidentTools: vi.fn(() => ({ incident_tool: {} })) }))
vi.mock('./fallback-tools', () => ({ getFallbackTools: vi.fn(() => ({ fallback_tool: {} })) }))
// Identity filter so assertions can check the raw merged tool set
vi.mock('../tool-filter', () => ({ filterToolsByOptInLevel: vi.fn((tools) => tools) }))
const BASE_PARAMS = {
projectRef: 'abcdefghijklmnopqrst',
connectionString: 'postgresql://localhost',
authorization: 'Bearer token',
aiOptInLevel: 'schema_and_log_and_data' as const,
accessToken: 'access-token',
baseUrl: 'https://supabase.com/dashboard',
signal: new AbortController().signal,
}
describe('ai/tools getTools', () => {
beforeEach(async () => {
vi.mocked(getMcpTools).mockResolvedValue({ list_tables: {} } as any)
// Reset to platform each test; the self-hosted test overrides to false.
// Done here (not afterEach) so the spy can't leak across tests via order.
const common = await import('common')
vi.spyOn(common, 'IS_PLATFORM', 'get').mockReturnValue(true)
})
it('includes studio, MCP, schema and incident tools on platform', async () => {
const tools = await getTools(BASE_PARAMS)
expect(getMcpTools).toHaveBeenCalledWith({
accessToken: BASE_PARAMS.accessToken,
projectRef: BASE_PARAMS.projectRef,
aiOptInLevel: BASE_PARAMS.aiOptInLevel,
signal: BASE_PARAMS.signal,
})
expect(tools).toHaveProperty('studio_tool')
expect(tools).toHaveProperty('list_tables')
expect(tools).toHaveProperty('schema_tool')
expect(tools).toHaveProperty('incident_tool')
})
it('passes authorization through to schema tools', async () => {
await getTools(BASE_PARAMS)
expect(getSchemaTools).toHaveBeenCalledWith({
projectRef: BASE_PARAMS.projectRef,
connectionString: BASE_PARAMS.connectionString,
authorization: BASE_PARAMS.authorization,
})
})
it('degrades gracefully to the remaining tools when remote MCP fetch fails', async () => {
const consoleSpy = vi.spyOn(console, 'error').mockImplementation(() => {})
vi.mocked(getMcpTools).mockRejectedValueOnce(new Error('remote MCP unreachable'))
const tools = await getTools(BASE_PARAMS)
// The assistant still works with the non-MCP tools instead of throwing
expect(tools).toHaveProperty('studio_tool')
expect(tools).toHaveProperty('schema_tool')
expect(tools).toHaveProperty('incident_tool')
expect(tools).not.toHaveProperty('list_tables')
expect(consoleSpy).toHaveBeenCalled()
consoleSpy.mockRestore()
})
it('does not fetch MCP tools when no access token is provided', async () => {
const tools = await getTools({ ...BASE_PARAMS, accessToken: undefined })
expect(getMcpTools).not.toHaveBeenCalled()
expect(tools).toHaveProperty('studio_tool')
expect(tools).not.toHaveProperty('list_tables')
})
it('uses fallback tools and skips MCP when self-hosted', async () => {
const common = await import('common')
vi.spyOn(common, 'IS_PLATFORM', 'get').mockReturnValue(false)
const tools = await getTools(BASE_PARAMS)
expect(getMcpTools).not.toHaveBeenCalled()
expect(tools).toHaveProperty('studio_tool')
expect(tools).toHaveProperty('fallback_tool')
expect(tools).not.toHaveProperty('list_tables')
})
it('excludes notebook tools when isExplorerEnabled is not set', async () => {
const tools = await getTools(BASE_PARAMS)
expect(tools).not.toHaveProperty('list_notebooks')
expect(tools).not.toHaveProperty('get_notebook')
expect(tools).not.toHaveProperty('run_notebook')
})
it('includes notebook tools only when isExplorerEnabled is true', async () => {
const tools = await getTools({ ...BASE_PARAMS, isExplorerEnabled: true })
expect(tools).toHaveProperty('list_notebooks')
expect(tools).toHaveProperty('get_notebook')
expect(tools).toHaveProperty('run_notebook')
})
})