fix(supabase): enable row level security and fail closed on malformed filters - #38
Conversation
🦋 Changeset detectedLatest commit: 63ec40e The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Warning Review limit reachedNext included review available in 18 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (6)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
commit: |
|
Security review: nothing to raise. Read the install script and its test. Row level security is now enabled on new tables, and the revoke step runs conditionally when Supabase roles exist. The filter validation closes the |
537a6ce to
c8f739c
Compare
c8f739c to
e8feaae
Compare
e8feaae to
ad15865
Compare
ad15865 to
63ec40e
Compare
|
Deployment failed for project vecstore-sdk with the following error: Learn More: https://vercel.com/pungrumpy?upgradeToPro=build-rate-limit |
Background
The Supabase adapter targets Edge Functions and the browser. The install script and the docs said row level security "still applies", but
vecstore_create_indexnever enabled it. On Supabase, tables inpublicusually get grants foranonandauthenticated. A freshly created vecstore table therefore let any holder of the public anon key read, overwrite, or delete every namespace, through the RPCs or directly through/rest/v1.Postgres also grants
EXECUTEon new functions toPUBLIC, so the anon key could call the DDL functionsvecstore_create_indexandvecstore_drop_index.vecstore_filter_sqlbuilt SQL by concatenation. A range leaf with novaluecompiled toNULL, andarray_to_stringdropped thatNULLfrom anand. Soand(eq("tenant", "a"), lt("price", undefined))deleted every row withtenant = a.Stacked on #35.
Summary
vecstore_create_indexenables row level security on the table it creates.anonandauthenticatedsee and change nothing until a policy exists. The service role bypasses row level security as before.vecstore_create_indexandvecstore_drop_indexfrompublic,anon, andauthenticated, and grants them toservice_role. A role check skips this on a plain Postgres, where those roles do not exist.vecstore_filter_sqlraises22023when a range leaf has no numericvalue, and when anand,or, ornotchild compiles to nothing. The adapter reports22023asinvalid_argument.Existing tables are unchanged. Users need to re-run
sql/supabase.sql, and the changeset says so.Verification
bun run testinpackages/vecstore-sdkshows 398 pass, 0 fail.anonreads no rows without a policy and reads them with one.anongets42501onvecstore_create_indexonce the Supabase roles exist.22023and deletes nothing.bun x tsc --noEmitexits 0.bun run checkexits 0.Checklist
vecstore-sdk(runbun run changesetin the project root)