mirror of
https://github.com/supabase/server.git
synced 2026-09-14 15:28:52 +08:00
09a67506db
* test: add E2E tests for all four adapters against a local Supabase stack Adds an e2e vitest project (SDK-1143) covering what the mocked unit tests cannot: real GoTrue-issued JWTs verified against the live JWKS endpoint, real Supabase client operations via supabaseAdmin, resolveEnv() reading process.env, and imports from dist/ so packaging regressions fail here. One scenario set (auth + data access + isolation) runs over real HTTP against minimal Hono, H3, Elysia, and NestJS apps. Elysia runs behind a node:http server (srvx) so CI needs no Bun. A separate E2E workflow starts the local stack with the Supabase CLI, builds, and runs the suite. * test: grant explicit table privileges in the e2e notes migration Newer Supabase stacks make new tables private by default — the API roles (anon/authenticated/service_role) no longer receive DML grants on table creation. CI installs the latest CLI, so all supabaseAdmin queries failed with "permission denied for table notes" while JWT scenarios passed. Reproduced locally on CLI 2.109.1; explicit grants fix it on both old and new stacks. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test: align NestJS missing-body handling and cover it in the scenarios The NestJS app silently inserted an empty note when the body was missing, while the other three adapters returned 400 — and no scenario exercised those 400 branches. NestJS now throws BadRequestException like the rest, and a shared missing-body scenario keeps all four aligned. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test: cover forged JWTs, the RLS-scoped client, and optional-auth rejection Closes the three gaps from PR review: the garbage-token scenario failed at header decode without ever reaching signature verification, ctx.supabase (the RLS-scoped client) was never exercised, and nothing pinned that a present-but-invalid token on an optional route is rejected rather than downgraded to anonymous. - Mint a well-formed JWT with the live JWKS kid but a wrong signing key in global setup; every adapter must 401 it — proving signature verification end-to-end, not just structure checks. - Add GET /my-notes reading through ctx.supabase with no WHERE clause, backed by a user_id = auth.uid() select policy — proving the caller's token reaches PostgREST and Postgres RLS scopes the rows. - Assert GET /me-optional with an invalid token → 401. 10 → 14 scenarios per adapter (56 tests). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test: add core-wrapper app, admin-bypass proof, and sign-in readability Addresses PR review comments: - New fifth app on the core withSupabase(config, handler) fetch wrapper — the exact programming model Supabase Edge Functions deploy — running the full scenario set behind node:http. A real Deno runtime e2e via `supabase functions serve` is tracked in SDK-1280. - New GET /all-notes route (admin client, no filter) + scenario: user2's request sees user1's rows through supabaseAdmin, directly proving the admin client is not scoped to the caller's identity. - Replace the `;({ data, error } = ...)` destructuring-reassignment in the sign-in helper with a plain result variable. 15 scenarios × 5 apps (75 tests). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
70 lines
2.0 KiB
TypeScript
70 lines
2.0 KiB
TypeScript
import type { SupabaseClient } from '@supabase/supabase-js'
|
|
|
|
/** Row shape of the e2e `notes` table (see e2e/supabase/migrations). */
|
|
export interface NoteRow {
|
|
id: string
|
|
user_id: string
|
|
body: string
|
|
}
|
|
|
|
const COLUMNS = 'id, user_id, body'
|
|
|
|
/** Inserts a note via the admin client, scoped to the calling user's id. */
|
|
export async function insertNote(
|
|
supabaseAdmin: SupabaseClient,
|
|
userId: string,
|
|
body: string,
|
|
): Promise<NoteRow> {
|
|
const { data, error } = await supabaseAdmin
|
|
.from('notes')
|
|
.insert({ user_id: userId, body })
|
|
.select(COLUMNS)
|
|
.single()
|
|
if (error) throw new Error(`insert note failed: ${error.message}`)
|
|
return data as NoteRow
|
|
}
|
|
|
|
/**
|
|
* Lists ALL notes through the admin client — every user's rows. Proves the
|
|
* admin client is not scoped to the caller's identity and bypasses RLS.
|
|
*/
|
|
export async function listAllNotes(
|
|
supabaseAdmin: SupabaseClient,
|
|
): Promise<NoteRow[]> {
|
|
const { data, error } = await supabaseAdmin
|
|
.from('notes')
|
|
.select(COLUMNS)
|
|
.order('created_at', { ascending: true })
|
|
if (error) throw new Error(`list all notes failed: ${error.message}`)
|
|
return data as unknown as NoteRow[]
|
|
}
|
|
|
|
/**
|
|
* Lists notes through the user-scoped client — no WHERE clause. The caller's
|
|
* JWT travels to PostgREST and the RLS policy alone scopes the rows.
|
|
*/
|
|
export async function listOwnNotes(
|
|
supabase: SupabaseClient,
|
|
): Promise<NoteRow[]> {
|
|
const { data, error } = await supabase
|
|
.from('notes')
|
|
.select(COLUMNS)
|
|
.order('created_at', { ascending: true })
|
|
if (error) throw new Error(`list own notes failed: ${error.message}`)
|
|
return data as unknown as NoteRow[]
|
|
}
|
|
|
|
/** Lists only the calling user's notes. */
|
|
export async function listNotes(
|
|
supabaseAdmin: SupabaseClient,
|
|
userId: string,
|
|
): Promise<NoteRow[]> {
|
|
const { data, error } = await supabaseAdmin
|
|
.from('notes')
|
|
.select(COLUMNS)
|
|
.eq('user_id', userId)
|
|
.order('created_at', { ascending: true })
|
|
if (error) throw new Error(`list notes failed: ${error.message}`)
|
|
return data as unknown as NoteRow[]
|
|
}
|