mirror of
https://github.com/supabase/supabase.git
synced 2026-10-09 03:15:06 +03:00
## Context Back to working on the [RLS Tester](https://github.com/orgs/supabase/discussions/45233), slowly adding support for mutation queries. First part here will be to add support for testing `INSERT` based queries (Note that there's no changes to the sandbox stuff in this PR) ## Changes involved - If testing an `INSERT` query, we show a big warning first that the query will be ran on the actual DB - Note that we skip the warning if the sandbox is used <img width="534" height="231" alt="image" src="https://github.com/user-attachments/assets/ef75a0c9-61e4-49b0-9d78-458e8e5f7f4f" /> - If the testing as an anon user + RLS enabled <img width="601" height="386" alt="image" src="https://github.com/user-attachments/assets/b21f048d-bac1-4ddd-b84b-c231ae9f9e3e" /> - If testing as an auth-ed user + RLS enabled, but the INSERT violates RLS (conditions don't meet) <img width="604" height="489" alt="image" src="https://github.com/user-attachments/assets/41c40486-48d5-4eee-b7cd-8f993edc47be" /> - Else if testing as an auth-ed user + RLS enabled and INSERT matches RLS <img width="612" height="402" alt="image" src="https://github.com/user-attachments/assets/41854b40-b351-408b-8d23-cc5e0fa40813" /> - Minor cosmetic layout change here - Use layout horizontal - Also added the user ID below the dropdown with click to copy action for convenience <img width="615" height="528" alt="image" src="https://github.com/user-attachments/assets/b9c04395-5435-474a-b3c5-640143faa782" /> - Added inline guard againsts some conditions - Should not be able to run UPDATE or DELETE queries <img width="622" height="319" alt="image" src="https://github.com/user-attachments/assets/351af7c6-8f1e-47ae-8651-3b9b0b512490" /> - Should not be able to run multiple queries <img width="612" height="317" alt="image" src="https://github.com/user-attachments/assets/603d9a1f-1d1f-40f2-806d-93aea6b6cf8e" /> ## To test - [ ] Verify that the RLS Tester works as expected for an insert query - Against actual DB - Against sandbox (only available on staging) - [ ] Verify that inline guards are all working as expected - Let me know if there's any edge cases I might have missed! <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * RLS Tester results are now operation-aware (SELECT vs mutations), with clearer “no rows/all rows” and policy evaluation explanations. * Added copy-to-clipboard for the impersonated user ID. * Query parsing now surfaces richer context, including WHERE clause details and statement count, and SELECT-only previews. * **Bug Fixes** * Improved handling of blocked mutation queries and RLS-related error messaging. * Updated RLS Tester navigation to the correct policies page. * Refined sandbox-assisted execution flow and empty/error states. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
116 lines
4.0 KiB
TypeScript
116 lines
4.0 KiB
TypeScript
import { LOCAL_STORAGE_KEYS, useFlag } from 'common'
|
|
import { useMemo } from 'react'
|
|
|
|
export type FeaturePreview = {
|
|
key: string
|
|
name: string
|
|
discussionsUrl?: string
|
|
isNew: boolean
|
|
/** If feature flag is only relevant for the hosted platform */
|
|
isPlatformOnly: boolean
|
|
/** If feature flag should be enabled by default for users, if not yet toggled before */
|
|
isDefaultOptIn: boolean
|
|
/** Visibility in the feature preview modal (For feature flagging a feature preview) */
|
|
enabled: boolean
|
|
/**
|
|
* Where to send the user after enabling, to try the feature out. Omit if the
|
|
* feature has no single destination (e.g. a global layout change).
|
|
*/
|
|
getRoute?: (ref?: string) => string
|
|
}
|
|
|
|
export const useFeaturePreviews = (): FeaturePreview[] => {
|
|
const platformWebhooksEnabled = useFlag('platformWebhooks')
|
|
const jitDbAccessEnabled = useFlag('jitDbAccess')
|
|
const isMarketplaceEnabled = useFlag('marketplaceIntegrations')
|
|
|
|
const unifiedLogsDefaultOptIn = useFlag('unifiedLogsDefaultOptIn')
|
|
|
|
return useMemo(
|
|
() =>
|
|
[
|
|
{
|
|
key: LOCAL_STORAGE_KEYS.UI_PREVIEW_RLS_TESTER,
|
|
name: 'RLS Tester',
|
|
discussionsUrl: 'https://github.com/orgs/supabase/discussions/45233',
|
|
enabled: true,
|
|
isNew: true,
|
|
isPlatformOnly: false,
|
|
isDefaultOptIn: false,
|
|
getRoute: (ref?: string) => `/project/${ref}/database/policies`,
|
|
},
|
|
{
|
|
key: LOCAL_STORAGE_KEYS.UI_PREVIEW_UNIFIED_LOGS,
|
|
name: 'Updated Logs interface',
|
|
discussionsUrl: 'https://github.com/orgs/supabase/discussions/37234',
|
|
enabled: true,
|
|
isNew: true,
|
|
isPlatformOnly: true,
|
|
isDefaultOptIn: unifiedLogsDefaultOptIn,
|
|
getRoute: (ref?: string) => `/project/${ref}/logs`,
|
|
},
|
|
{
|
|
key: LOCAL_STORAGE_KEYS.UI_PREVIEW_ADVISOR_RULES,
|
|
name: 'Disable Advisor rules',
|
|
discussionsUrl: undefined,
|
|
enabled: true,
|
|
isNew: false,
|
|
isPlatformOnly: true,
|
|
isDefaultOptIn: false,
|
|
getRoute: (ref?: string) => `/project/${ref}/advisors/rules/security`,
|
|
},
|
|
|
|
{
|
|
key: LOCAL_STORAGE_KEYS.UI_PREVIEW_PG_DELTA_DIFF,
|
|
name: 'PG Delta Diff',
|
|
discussionsUrl: undefined,
|
|
isNew: false,
|
|
isPlatformOnly: true,
|
|
isDefaultOptIn: true,
|
|
enabled: true,
|
|
},
|
|
{
|
|
key: LOCAL_STORAGE_KEYS.UI_PREVIEW_PLATFORM_WEBHOOKS,
|
|
name: 'Platform webhooks',
|
|
discussionsUrl: undefined,
|
|
isNew: true,
|
|
isPlatformOnly: true,
|
|
isDefaultOptIn: false,
|
|
enabled: platformWebhooksEnabled,
|
|
getRoute: (ref?: string) => `/project/${ref}/settings/webhooks`,
|
|
},
|
|
{
|
|
key: LOCAL_STORAGE_KEYS.UI_PREVIEW_JIT_DB_ACCESS,
|
|
name: 'Temporary access',
|
|
discussionsUrl: undefined,
|
|
isNew: true,
|
|
isPlatformOnly: true,
|
|
isDefaultOptIn: false,
|
|
enabled: jitDbAccessEnabled,
|
|
getRoute: (ref?: string) => `/project/${ref}/database/settings`,
|
|
},
|
|
{
|
|
key: LOCAL_STORAGE_KEYS.UI_PREVIEW_CLS,
|
|
name: 'Column-level privileges',
|
|
discussionsUrl: 'https://github.com/orgs/supabase/discussions/20295',
|
|
enabled: true,
|
|
isNew: false,
|
|
isPlatformOnly: false,
|
|
isDefaultOptIn: false,
|
|
getRoute: (ref?: string) => `/project/${ref}/database/column-privileges`,
|
|
},
|
|
{
|
|
key: LOCAL_STORAGE_KEYS.UI_PREVIEW_MARKETPLACE,
|
|
name: 'Integrations layout',
|
|
discussionsUrl: undefined,
|
|
enabled: isMarketplaceEnabled,
|
|
isNew: true,
|
|
isPlatformOnly: true,
|
|
isDefaultOptIn: false,
|
|
getRoute: (ref?: string) => `/project/${ref}/integrations`,
|
|
},
|
|
].sort((a, b) => Number(b.isNew) - Number(a.isNew)),
|
|
[unifiedLogsDefaultOptIn, platformWebhooksEnabled, jitDbAccessEnabled, isMarketplaceEnabled]
|
|
)
|
|
}
|