mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 09:55:06 +03:00
### Context Resolves [https://github.com/supabase/supabase/issues/28820](<https://github.com/supabase/supabase/issues/28820>) CSV imports via the table editor is currently missing the role impersonation check. Assuming you've got a table that has a column which references `auth.users` + default values to `auth.uid() + not nullable` (e.g `user_id`), if you try to manually add a row while impersonating a user and leaving the `user_id` input field NULL, the newly inserted row will default to the user ID of the impersonated user <img src="https://github.com/user-attachments/assets/f6eb7e24-50e4-42aa-b6e6-64c50e195be7 " alt="image" width="685" data-linear-height="255" /> However, because CSV imports are missing the role impersonation check, importing data with a CSV that has null values for `user_id` column will throw a NOT NULL postgres error. PR here adds the role impersonation check and resolves ^ this particular behaviour ### To test - [X] Create a table that references the `auth.users` table ``` create table public.empty ( id uuid primary key default gen_random_uuid(), user_id uuid not null references auth.users(id) on delete cascade default auth.uid(), note text ); ``` - [ ] Import data via CSV via the table editor using this CSV while impersonating a user [empty_test_import_no_user_id.csv](<https://github.com/user-attachments/files/32053194/empty_test_import_no_user_id.csv>) - [ ] Should pass without any errors, inserted rows should have `user_id` filled as the impersonated user's ID * Can also verify first on staging that doing this will throw a not null error ## Summary by CodeRabbit * **Bug Fixes** * Spreadsheet imports in the table editor now respect the currently selected role-impersonation state, ensuring imported rows are processed with the appropriate permissions. * Manually inserted or pasted rows now use the active role-impersonation settings, providing consistent permission handling across table editing workflows.