Files
supabase/apps/studio/components/interfaces/ProjectCreation/ProjectCreation.schema.ts
T
0760733a40 Project create security section updates (#42021)
<img width="1196" height="427" alt="image"
src="https://github.com/user-attachments/assets/6784b5e9-99c8-4fc9-b9f5-49672ba6e768"
/>

This reworks the security section within our project creation form to
expose two options.

1/ Enable or disable Data API which is essentially the same as we had
previously, just reframed
2/ Enable auto RLS which creates an event trigger that enables RLS on
all tables created via public schema. This is the same as what we do via
the RLS banner in authentication pages.

Note that this also removes the option to disable Data API on public
schema and move to dedicated schema. The user can still do this post
project creation . Assumption is this is rarely changed on project
creation and adds complexity.

To test:
1. Create a new project
2. Enable Data API and enable RLS setting
3. After project creation, go to triggers -> event tab -> notice enable
rls trigger
4. Create project and disable Data API
5. After project creation , go to settings/api and make sure data api is
disabled

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added an optional automatic Row-Level Security (RLS) event trigger
option in project creation (toggleable via experiment).

* **Improvements**
* Security panel simplified to checkbox-based controls for Data API and
RLS.
* Project creation form now includes the enableRlsEventTrigger flag and
applies related setup when enabled.
* Telemetry records RLS experiment exposure, variant, and whether the
RLS trigger was enabled.
  * Free-project messaging updated to consider user limits.

<sub>✏️ Tip: You can customize this high-level summary in your review
settings.</sub>
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Charis Lam <26616127+charislam@users.noreply.github.com>
Co-authored-by: Sean Oliver <882952+seanoliver@users.noreply.github.com>
2026-02-02 15:49:35 +10:00

50 lines
1.7 KiB
TypeScript

import { DEFAULT_MINIMUM_PASSWORD_STRENGTH } from 'lib/constants'
import { z } from 'zod'
export const FormSchema = z
.object({
organization: z.string({
required_error: 'Please select an organization',
}),
projectName: z
.string()
.trim()
.min(1, 'Please enter a project name.') // Required field check
.min(3, 'Project name must be at least 3 characters long.') // Minimum length check
.max(64, 'Project name must be no longer than 64 characters.'), // Maximum length check
postgresVersion: z.string({
required_error: 'Please enter a Postgres version.',
}),
dbRegion: z.string({
required_error: 'Please select a region.',
}),
cloudProvider: z.string({
required_error: 'Please select a cloud provider.',
}),
dbPass: z
.string({ required_error: 'Please enter a database password.' })
.min(1, 'Password is required.'),
dbPassStrength: z
.union([z.literal(0), z.literal(1), z.literal(2), z.literal(3), z.literal(4)])
.default(0),
dbPassStrengthMessage: z.string().default(''),
dbPassStrengthWarning: z.string().default(''),
instanceSize: z.string().optional(),
dataApi: z.boolean(),
enableRlsEventTrigger: z.boolean(),
postgresVersionSelection: z.string(),
useOrioleDb: z.boolean(),
})
.superRefine(({ dbPassStrength, dbPassStrengthWarning }, ctx) => {
if (dbPassStrength < DEFAULT_MINIMUM_PASSWORD_STRENGTH) {
ctx.addIssue({
code: z.ZodIssueCode.custom,
path: ['dbPass'],
message: dbPassStrengthWarning || 'Password not secure enough',
})
}
})
export type CreateProjectForm = z.infer<typeof FormSchema>