Skip to content

fix(dev2): carry app triggers and storage policies across a Supabase move - #111

Merged
ralyodio merged 1 commit into
masterfrom
fix/dev2-kit-auth-storage-objects
Sep 26, 2026
Merged

ralyodio merged 1 commit into
masterfrom
fix/dev2-kit-auth-storage-objects

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

supabase-pull dumped DDL for app schemas only, and pg_dump files a trigger or policy under its table's schema. So every trigger on auth.users and every storage.objects policy was silently lost on all 22 stacks moved on 2026-09-25: signups got no profile and browser uploads were denied (ugig.net#569, ugig.net#570).

  • pull: exports app triggers on auth.*/storage.* tables (skipping those whose function is owned by supabase_auth_admin/supabase_storage_admin) and all policies on those schemas. They are schema-qualified, written as drop-if-exists + create, and counted in MANIFEST.
  • load: applies them after the data, so on_auth_user_created cannot double-insert during the auth.users COPY. It warns when a dump predates this export.

Tested: queries run against the live ugig stack, and a full round-trip in a throwaway postgres:17 (export, drop, reload twice, restored trigger fires on insert). The already-moved stacks are being repaired by per-repo migrations.

🤖 Generated with Claude Code

…move

supabase-pull dumped DDL for app schemas only. pg_dump files a trigger
or policy under its table's schema, so every trigger ON auth.users
(on_auth_user_created -> public.handle_new_user()) and every policy on
storage.objects was silently dropped on all 22 stacks moved 2026-09-25:
signups got no profile and browser uploads were denied by RLS.

The pull now exports both, excluding triggers whose function belongs to
supabase_auth_admin / supabase_storage_admin (the stack ships those),
schema-qualified and as drop-if-exists + create. The load applies them
after the data, so on_auth_user_created cannot fire during the
auth.users COPY, and warns when a dump predates the export.

Round-tripped in a throwaway postgres:17: export, drop, reload twice,
and the restored trigger fires on insert.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

25 finding(s)

HIGH/CRITICAL: 4 | MEDIUM: 12 | LOW: 9

Severity Rule Location
HIGH sh-remote-script-execution root-ubuntu.sh:3236
HIGH sh-remote-script-execution root-ubuntu.sh:3237
HIGH sh-remote-script-execution root-ubuntu.sh:5071
HIGH sh-remote-script-execution root-ubuntu.sh:5075
MEDIUM sql-template-interpolation dev2/dev2-site:805
MEDIUM sql-template-interpolation dev2/dev2-site:882
MEDIUM sh-remote-script-execution root-ubuntu.sh:5248
MEDIUM redos-nested-quantifier src/domain-free.ts:56
MEDIUM redos-nested-quantifier src/emoji.ts:167
MEDIUM redos-nested-quantifier src/icon.ts:166
MEDIUM redos-nested-quantifier src/mail.ts:1042
MEDIUM sql-template-interpolation src/users-dump.ts:487
MEDIUM sql-string-concatenation src/users-dump.ts:507
MEDIUM sql-template-interpolation src/users-dump.ts:540
MEDIUM sql-string-concatenation src/users-dump.ts:574
MEDIUM redos-nested-quantifier src/wcag.ts:556
LOW secret-generic-credential src/credentials.ts:36
LOW secret-generic-credential src/user-export.ts:632
LOW secret-generic-credential src/user-export.ts:638
LOW secret-generic-api-key test/credentials.test.ts:208
LOW secret-generic-credential test/mail.test.ts:141
LOW secret-generic-credential test/shorten.test.ts:36
LOW secret-database-url test/users-dump.test.ts:108
LOW secret-database-url test/users-dump.test.ts:119
LOW secret-database-url test/users-dump.test.ts:120

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit b48a852 into master Sep 26, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant