Files
supabase/apps/studio/data/content/content-upsert-mutation.ts
Charis 0433eeb5f5 feat(studio): mark sql provenance for safety (#45336)
Mark provenance of SQL via the branded types SafeSqlFragment and
UntrustedSqlFragment. Only SafeSqlFragment should be executed;
UntrustedSqlFragments require some kind of implicit user approval (show
on screen + user has to click something) before they are promoted to
SafeSqlFragment.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Editor and RLS tester show loading states for inferred/generated SQL
and include a dedicated user SQL editor for safer edits.

* **Refactor**
* Platform-wide SQL handling tightened: snippets and AI-generated SQL
are treated as untrusted/display-only until promoted, improving safety
and consistency.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-05-04 13:08:06 -04:00

75 lines
2.3 KiB
TypeScript

import { useMutation, useQueryClient } from '@tanstack/react-query'
import { toast } from 'sonner'
import type { Content } from './content-query'
import { unmapSqlContentField } from './content-remap'
import { contentKeys } from './keys'
import type { Snippet } from './sql-folders-query'
import type { components } from '@/data/api'
import { handleError, put } from '@/data/fetchers'
import type { ResponseError, UseCustomMutationOptions } from '@/types'
export type UpsertContentPayload = Omit<components['schemas']['UpsertContentBody'], 'content'> & {
id: string
content: Partial<Content['content']>
favorite?: boolean
}
export type UpsertContentVariables = {
projectRef: string
payload: UpsertContentPayload
}
export async function upsertContent(
{ projectRef, payload }: UpsertContentVariables,
signal?: AbortSignal
) {
const { data, error } = await put('/platform/projects/{ref}/content', {
params: { path: { ref: projectRef } },
body: unmapSqlContentField(payload),
headers: { Version: '2' },
signal,
})
if (error) handleError(error)
return data as Snippet | null
}
export type UpsertContentData = Awaited<ReturnType<typeof upsertContent>>
export const useContentUpsertMutation = ({
onError,
onSuccess,
invalidateQueriesOnSuccess = true,
...options
}: Omit<
UseCustomMutationOptions<UpsertContentData, ResponseError, UpsertContentVariables>,
'mutationFn'
> & {
invalidateQueriesOnSuccess?: boolean
} = {}) => {
const queryClient = useQueryClient()
return useMutation<UpsertContentData, ResponseError, UpsertContentVariables>({
mutationFn: (args) => upsertContent(args),
async onSuccess(data, variables, context) {
const { projectRef } = variables
if (invalidateQueriesOnSuccess) {
await Promise.all([
queryClient.invalidateQueries({ queryKey: contentKeys.allContentLists(projectRef) }),
queryClient.invalidateQueries({ queryKey: contentKeys.infiniteList(projectRef) }),
])
}
await onSuccess?.(data, variables, context)
},
async onError(data, variables, context) {
if (onError === undefined) {
toast.error(`Failed to insert content: ${data.message}`)
} else {
onError(data, variables, context)
}
},
...options,
})
}