mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 18:05:11 +03:00
## What kind of change does this PR introduce? Feature. Resolves DEPR-430. ## What is the current behaviour? The homepage Advisor summary, shared Advisor panel, and top-nav Advisor indicator only surface lints and notifications. Banned IPs are not represented as dismissible Advisor items, so network bans are easy to miss unless a user visits Database Settings directly. The `public bucket allows listing` warning is no longer part of this PR. That warning will move to a follow-up Splinter `WARN` lint so it can flow through the standard lint surfaces instead of a bespoke Studio signal path. ## What is the new behaviour? - adds a new Advisor `signal` source for banned IPs on the platform homepage, in the shared Advisor panel, and in the top-nav Advisor indicator - keeps dismissals client-side only for now, scoped by project and exact IP fingerprint - keeps banned IP signals at `warning` severity because they still indicate suspicious traffic and remain actionable if a user wants to review or remove a ban - leaves `/project/[ref]/advisors/security` as follow-up work because that surface is still lint-native, and banned IPs are management-plane signals rather than Splinter lints | After | | --- | | <img width="1728" height="997" alt="Mallet Toolshed Supabase-65A60B4A-107E-4D79-B9A8-23F754BEAB08" src="https://github.com/user-attachments/assets/c08ecbbb-c302-43bd-81bb-6ba7eb18b7b3" /> | ## Reviewer testing notes 1. Use a throwaway project. 2. Get the database connection string for that project. 3. Attempt to connect with the wrong password 3-4 times until you hit an `ECONNREFUSED`-style error, which should mean your IP has been banned. 4. Refresh Studio and confirm the project overview shows the new `Banned IP address` signal. 5. Open the Advisor Center and confirm: - the top-nav Advisor dot turns warning yellow - the signal detail shows `Entity`, `Issue`, and `Resolve` - `Edit network bans`, `Dismiss`, and `Learn more` are present 6. Open Database Settings > Network bans and confirm your banned IP appears there and can be unbanned. 7. Note that `/project/[ref]/advisors/security` will not show this item. That page is still lint-only, and this banned IP work is a short-term client-side signal rather than a true lint. Longer term, we likely want a more durable event model here so banned IPs can power notifications, webhooks, emails, and other project-level alerts. --------- Co-authored-by: kemal <hello@kemal.earth> Co-authored-by: Charis Lam <26616127+charislam@users.noreply.github.com> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
114 lines
3.8 KiB
TypeScript
114 lines
3.8 KiB
TypeScript
import { QueryClient, QueryClientProvider } from '@tanstack/react-query'
|
|
import { act, renderHook, waitFor } from '@testing-library/react'
|
|
import React from 'react'
|
|
import { afterEach, beforeEach, describe, expect, it } from 'vitest'
|
|
|
|
import { useLocalStorageQuery } from '../useLocalStorage'
|
|
import { customRenderHook } from '@/tests/lib/custom-render'
|
|
|
|
function makeQueryClient() {
|
|
return new QueryClient({ defaultOptions: { queries: { retry: false } } })
|
|
}
|
|
|
|
function makeWrapper(queryClient: QueryClient) {
|
|
return ({ children }: { children: React.ReactNode }) =>
|
|
React.createElement(QueryClientProvider, { client: queryClient }, children)
|
|
}
|
|
|
|
describe('useLocalStorageQuery', () => {
|
|
beforeEach(() => {
|
|
window.localStorage.clear()
|
|
})
|
|
|
|
afterEach(() => {
|
|
window.localStorage.clear()
|
|
})
|
|
|
|
it('returns initialValue when localStorage has no entry for the key', async () => {
|
|
const { result } = customRenderHook(() => useLocalStorageQuery('test-key', 'default'))
|
|
|
|
await waitFor(() => expect(result.current[2].isSuccess).toBe(true))
|
|
expect(result.current[0]).toBe('default')
|
|
})
|
|
|
|
it('returns the stored value from localStorage on mount', async () => {
|
|
window.localStorage.setItem('test-key', JSON.stringify('persisted'))
|
|
|
|
const { result } = customRenderHook(() => useLocalStorageQuery('test-key', 'default'))
|
|
|
|
await waitFor(() => expect(result.current[0]).toBe('persisted'))
|
|
})
|
|
|
|
it('updates the value in state and localStorage when setValue is called', async () => {
|
|
const { result } = customRenderHook(() => useLocalStorageQuery('test-key', 'default'))
|
|
await waitFor(() => expect(result.current[2].isSuccess).toBe(true))
|
|
|
|
act(() => {
|
|
result.current[1]('updated')
|
|
})
|
|
|
|
await waitFor(() => expect(result.current[0]).toBe('updated'))
|
|
expect(window.localStorage.getItem('test-key')).toBe(JSON.stringify('updated'))
|
|
})
|
|
|
|
it('supports a function updater that receives the current value', async () => {
|
|
window.localStorage.setItem('count', JSON.stringify(5))
|
|
|
|
const { result } = customRenderHook(() => useLocalStorageQuery('count', 0))
|
|
await waitFor(() => expect(result.current[0]).toBe(5))
|
|
|
|
act(() => {
|
|
result.current[1]((prev: number) => prev + 1)
|
|
})
|
|
|
|
await waitFor(() => expect(result.current[0]).toBe(6))
|
|
expect(window.localStorage.getItem('count')).toBe(JSON.stringify(6))
|
|
})
|
|
|
|
it('works with object values', async () => {
|
|
const stored = { count: 3, label: 'hello' }
|
|
window.localStorage.setItem('obj-key', JSON.stringify(stored))
|
|
|
|
const { result } = customRenderHook(() =>
|
|
useLocalStorageQuery('obj-key', { count: 0, label: '' })
|
|
)
|
|
|
|
await waitFor(() => expect(result.current[0]).toEqual(stored))
|
|
})
|
|
|
|
it('syncs two hooks sharing the same key via the same QueryClient', async () => {
|
|
const queryClient = makeQueryClient()
|
|
|
|
const { result } = renderHook(
|
|
() => ({
|
|
a: useLocalStorageQuery('shared-key', 'initial'),
|
|
b: useLocalStorageQuery('shared-key', 'initial'),
|
|
}),
|
|
{ wrapper: makeWrapper(queryClient) }
|
|
)
|
|
|
|
await waitFor(() => expect(result.current.a[2].isSuccess).toBe(true))
|
|
|
|
act(() => {
|
|
result.current.a[1]('from-a')
|
|
})
|
|
|
|
await waitFor(() => {
|
|
expect(result.current.a[0]).toBe('from-a')
|
|
expect(result.current.b[0]).toBe('from-a')
|
|
})
|
|
})
|
|
|
|
it('uses the initialValue as fallback when the function updater runs before any stored value', async () => {
|
|
const { result } = customRenderHook(() => useLocalStorageQuery('new-key', 10))
|
|
await waitFor(() => expect(result.current[2].isSuccess).toBe(true))
|
|
|
|
act(() => {
|
|
result.current[1]((prev: number) => prev * 2)
|
|
})
|
|
|
|
await waitFor(() => expect(result.current[0]).toBe(20))
|
|
expect(window.localStorage.getItem('new-key')).toBe(JSON.stringify(20))
|
|
})
|
|
})
|