Skip to content

fix(db): clear Supabase advisor warnings - #496

Merged
charlesrhoward merged 1 commit into
mainfrom
fix/supabase-advisor-warnings
Oct 11, 2026
Merged

charlesrhoward merged 1 commit into
mainfrom
fix/supabase-advisor-warnings

Conversation

@charlesrhoward

Copy link
Copy Markdown
Contributor

Move get_user_org_ids/is_org_admin RLS helpers into a non-exposed private
schema (any caller could query another user's orgs via /rest/v1/rpc), revoke
EXECUTE on the handle_new_user trigger function, wrap auth.role() in the
sdk_projects service-role policy, and index sdk_projects foreign keys.

Already applied to prod as migration 20261011015625.

Move get_user_org_ids/is_org_admin RLS helpers into a non-exposed private
schema (any caller could query another user's orgs via /rest/v1/rpc), revoke
EXECUTE on the handle_new_user trigger function, wrap auth.role() in the
sdk_projects service-role policy, and index sdk_projects foreign keys.

Already applied to prod as migration 20261011015625.
@vercel

vercel Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
memories Ignored Ignored Preview Oct 11, 2026 1:56am UTC

Request Review

@mogplex

mogplex Bot commented Oct 11, 2026

Copy link
Copy Markdown
Contributor

Mogplex PR Review

Status: No material issues found

PR #496 is approve-ready. The migration correctly fixes Supabase advisor warnings by moving RLS helper functions to a private schema, tightening permissions, fixing auth.role() evaluation in the service-role policy, and adding FK indexes. All changes are idempotent and align with the stated security and performance fixes.

  • supabase/migrations/20261011015625_fix_advisor_warnings_definer_rpc_and_sdk_projects.sql — Moves get_user_org_ids and is_org_admin from public to private schema to prevent RPC exposure while preserving RLS behavior (policies reference functions by OID). Grants execute to authenticated and service_role, revokes from public/anon.
  • supabase/migrations/20261011015625_fix_advisor_warnings_definer_rpc_and_sdk_projects.sql — Revokes all execute on public.handle_new_user() from public/anon/authenticated (trigger-only; execute not checked on triggers).
  • supabase/migrations/20261011015625_fix_advisor_warnings_definer_rpc_and_sdk_projects.sql — Wraps auth.role() in (SELECT auth.role()) for the sdk_projects service-role policy and recreates it safely.
  • supabase/migrations/20261011015625_fix_advisor_warnings_definer_rpc_and_sdk_projects.sql — Adds indexes on sdk_projects.owner_user_id, owner_org_id, and created_by_user_id to cover FK lookups.

View check run

@charlesrhoward
charlesrhoward merged commit a683843 into main Oct 11, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant