From 28a6cb64678f33f3a01d80462c3db6bbe536b636 Mon Sep 17 00:00:00 2001 From: QA Runner Date: Fri, 17 Jul 2026 14:31:34 -0700 Subject: [PATCH] ci(e2e): grant service_role table access after loading schema.sql MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The backend queries exclusively as service_role (lib/supabase.ts, service key, 'bypasses RLS'). schema.sql revokes client grants (anon/authenticated) but assumes a hosted Supabase where service_role already has full table access — on a fresh CLI stack loaded via psql it gets none, so the first backend write 500s with 'permission denied for table user_profiles' and every project/chat spec fails. Granting service_role after the schema load reproduces the production grant posture. Verified in CI: POST /projects 500 -> 201, GET /chat 500 -> 200. Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/workflows/e2e.yml | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/.github/workflows/e2e.yml b/.github/workflows/e2e.yml index 5e2c457e..a09a0621 100644 --- a/.github/workflows/e2e.yml +++ b/.github/workflows/e2e.yml @@ -113,6 +113,19 @@ jobs: # schema file already includes the latest shape, so no migrations are # replayed on a fresh CI database. psql "$DB_URL" -v ON_ERROR_STOP=1 -f backend/schema.sql + # schema.sql revokes client grants (anon/authenticated) on purpose, but + # it assumes a HOSTED Supabase project where service_role already holds + # full table access. On a fresh CLI stack loaded via psql, service_role + # gets no grants on the newly-created public tables, so the backend — + # which queries exclusively as service_role (lib/supabase.ts) — 500s with + # "permission denied for table user_profiles" on the first write. Restore + # the production grant posture so the API behaves as it does in prod. + psql "$DB_URL" -v ON_ERROR_STOP=1 <<'SQL' + GRANT USAGE ON SCHEMA public TO service_role; + GRANT ALL ON ALL TABLES IN SCHEMA public TO service_role; + GRANT ALL ON ALL SEQUENCES IN SCHEMA public TO service_role; + GRANT ALL ON ALL FUNCTIONS IN SCHEMA public TO service_role; + SQL - name: Wire env from Supabase run: |