mirror of
https://github.com/supabase/supabase.git
synced 2026-10-09 19:35:06 +03:00
## Context Back to working on the [RLS Tester](https://github.com/orgs/supabase/discussions/45233), slowly adding support for mutation queries. First part here will be to add support for testing `INSERT` based queries (Note that there's no changes to the sandbox stuff in this PR) ## Changes involved - If testing an `INSERT` query, we show a big warning first that the query will be ran on the actual DB - Note that we skip the warning if the sandbox is used <img width="534" height="231" alt="image" src="https://github.com/user-attachments/assets/ef75a0c9-61e4-49b0-9d78-458e8e5f7f4f" /> - If the testing as an anon user + RLS enabled <img width="601" height="386" alt="image" src="https://github.com/user-attachments/assets/b21f048d-bac1-4ddd-b84b-c231ae9f9e3e" /> - If testing as an auth-ed user + RLS enabled, but the INSERT violates RLS (conditions don't meet) <img width="604" height="489" alt="image" src="https://github.com/user-attachments/assets/41c40486-48d5-4eee-b7cd-8f993edc47be" /> - Else if testing as an auth-ed user + RLS enabled and INSERT matches RLS <img width="612" height="402" alt="image" src="https://github.com/user-attachments/assets/41854b40-b351-408b-8d23-cc5e0fa40813" /> - Minor cosmetic layout change here - Use layout horizontal - Also added the user ID below the dropdown with click to copy action for convenience <img width="615" height="528" alt="image" src="https://github.com/user-attachments/assets/b9c04395-5435-474a-b3c5-640143faa782" /> - Added inline guard againsts some conditions - Should not be able to run UPDATE or DELETE queries <img width="622" height="319" alt="image" src="https://github.com/user-attachments/assets/351af7c6-8f1e-47ae-8651-3b9b0b512490" /> - Should not be able to run multiple queries <img width="612" height="317" alt="image" src="https://github.com/user-attachments/assets/603d9a1f-1d1f-40f2-806d-93aea6b6cf8e" /> ## To test - [ ] Verify that the RLS Tester works as expected for an insert query - Against actual DB - Against sandbox (only available on staging) - [ ] Verify that inline guards are all working as expected - Let me know if there's any edge cases I might have missed! <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * RLS Tester results are now operation-aware (SELECT vs mutations), with clearer “no rows/all rows” and policy evaluation explanations. * Added copy-to-clipboard for the impersonated user ID. * Query parsing now surfaces richer context, including WHERE clause details and statement count, and SELECT-only previews. * **Bug Fixes** * Improved handling of blocked mutation queries and RLS-related error messaging. * Updated RLS Tester navigation to the correct policies page. * Refined sandbox-assisted execution flow and empty/error states. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
106 lines
3.4 KiB
TypeScript
106 lines
3.4 KiB
TypeScript
import { Box, Loader2, LogOut, RefreshCw } from 'lucide-react'
|
|
import { Badge, Button } from 'ui'
|
|
import { Admonition } from 'ui-patterns/admonition'
|
|
|
|
import { ButtonTooltip } from '@/components/ui/ButtonTooltip'
|
|
import { usePostgresSandbox } from '@/state/postgres-sandbox/sandbox'
|
|
|
|
export const SandboxManagement = () => {
|
|
const { status, error, isSyncing, startSandbox, destroySandbox, syncSandbox } =
|
|
usePostgresSandbox()
|
|
|
|
if (status === 'idle') {
|
|
return (
|
|
<Admonition
|
|
type="default"
|
|
layout="horizontal"
|
|
className="min-h-min border-none [&>div>div>div>div>p]:!mb-0 [&>div>div]:gap-x-2"
|
|
actions={[
|
|
<Button key="sandbox" variant="default" onClick={() => startSandbox()}>
|
|
Set up sandbox
|
|
</Button>,
|
|
]}
|
|
>
|
|
<div className="flex items-center gap-x-2">
|
|
<p className="text-foreground !m-0">Run queries in a sandbox</p>
|
|
<Badge variant="success">Recommended</Badge>
|
|
</div>
|
|
<p className="text-foreground-light !m-0">
|
|
Ensure that queries do not affect your actual database
|
|
</p>
|
|
</Admonition>
|
|
)
|
|
}
|
|
|
|
if (status === 'loading') {
|
|
return (
|
|
<Admonition
|
|
showIcon={false}
|
|
type="default"
|
|
className="min-h-min border-none py-2 [&>div>div]:flex [&>div>div]:items-center [&>div>div]:justify-between"
|
|
>
|
|
<div className="flex items-center gap-x-3">
|
|
<div className="bg w-6 h-6 rounded border border-border flex items-center justify-center">
|
|
<Loader2 size={14} className="animate-spin" />
|
|
</div>
|
|
<p className="text-xs !mb-0 font-mono uppercase tracking-tight">Setting up sandbox</p>
|
|
</div>
|
|
</Admonition>
|
|
)
|
|
}
|
|
|
|
if (status === 'error') {
|
|
return (
|
|
<Admonition
|
|
type="warning"
|
|
layout="horizontal"
|
|
title="Unable to set up sandbox"
|
|
description={error ?? 'Please try again'}
|
|
className="min-h-min border-none"
|
|
actions={[
|
|
<Button key="set-up" variant="default" onClick={() => startSandbox()}>
|
|
Retry set up
|
|
</Button>,
|
|
]}
|
|
/>
|
|
)
|
|
}
|
|
|
|
return (
|
|
<Admonition
|
|
showIcon={false}
|
|
type="default"
|
|
layout="horizontal"
|
|
className="min-h-min border-none py-2 [&>div>div>div>div>p]:!mb-0 [&>div>div]:gap-x-2"
|
|
actions={[
|
|
<ButtonTooltip
|
|
key="destroy"
|
|
variant="default"
|
|
icon={<LogOut />}
|
|
className="w-7"
|
|
disabled={isSyncing}
|
|
tooltip={{ content: { side: 'bottom', text: 'Exit sandbox' } }}
|
|
onClick={() => destroySandbox()}
|
|
/>,
|
|
<ButtonTooltip
|
|
key="refresh"
|
|
variant="default"
|
|
icon={<RefreshCw />}
|
|
className="w-7"
|
|
loading={isSyncing}
|
|
tooltip={{ content: { side: 'bottom', text: 'Refresh schema' } }}
|
|
onClick={() => syncSandbox()}
|
|
/>,
|
|
]}
|
|
>
|
|
<div className="flex items-center gap-x-3">
|
|
<div className="bg-brand-300 w-6 h-6 rounded border border-brand-500 flex items-center justify-center">
|
|
<Box size={14} className="text-brand" />
|
|
</div>
|
|
<p className="text-xs text-foreground font-mono uppercase tracking-tight">Sandbox active</p>
|
|
<p className="text-xs text-foreground-lighter ">Your database is never modified</p>
|
|
</div>
|
|
</Admonition>
|
|
)
|
|
}
|