fix(dev2): carry app triggers and storage policies across a Supabase move - #111
Merged
Merged
Conversation
…move supabase-pull dumped DDL for app schemas only. pg_dump files a trigger or policy under its table's schema, so every trigger ON auth.users (on_auth_user_created -> public.handle_new_user()) and every policy on storage.objects was silently dropped on all 22 stacks moved 2026-09-25: signups got no profile and browser uploads were denied by RLS. The pull now exports both, excluding triggers whose function belongs to supabase_auth_admin / supabase_storage_admin (the stack ships those), schema-qualified and as drop-if-exists + create. The load applies them after the data, so on_auth_user_created cannot fire during the auth.users COPY, and warns when a dump predates the export. Round-tripped in a throwaway postgres:17: export, drop, reload twice, and the restored trigger fires on insert. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ThreatCrush Security Scan25 finding(s) HIGH/CRITICAL: 4 | MEDIUM: 12 | LOW: 9
Snippets are redacted; ThreatCrush never prints matched credential material. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
supabase-pull dumped DDL for app schemas only, and pg_dump files a trigger or policy under its table's schema. So every trigger on
auth.usersand everystorage.objectspolicy was silently lost on all 22 stacks moved on 2026-09-25: signups got no profile and browser uploads were denied (ugig.net#569, ugig.net#570).auth.*/storage.*tables (skipping those whose function is owned bysupabase_auth_admin/supabase_storage_admin) and all policies on those schemas. They are schema-qualified, written as drop-if-exists + create, and counted in MANIFEST.on_auth_user_createdcannot double-insert during theauth.usersCOPY. It warns when a dump predates this export.Tested: queries run against the live ugig stack, and a full round-trip in a throwaway postgres:17 (export, drop, reload twice, restored trigger fires on insert). The already-moved stacks are being repaired by per-repo migrations.
🤖 Generated with Claude Code