supabase-postgres.git / summary / log / commit / refs
commit 0271bfe9d773e36c8bece342c72d0eaba064f563
Author: Bobbie Soedirgo <31685197+soedirgo@users.noreply.github.com>
Commit: GitHub <noreply@github.com>
Date: Thu Jun 26 09:16:32 2025 +0000
fix: allow postgres to grant storage privs to other roles (#1666)
* fix: allow postgres to grant storage privs to other roles
Temporary fix until STORAGE-211 is completed
* chore: bump AMI versions
* chore: bump AMI versions
ansible/vars.yml | 6 ++---
...torage_tables_to_postgres_with_grant_option.sql | 6 +++++
nix/tests/expected/storage.out | 28 +++++++++++-----------
3 files changed, 23 insertions(+), 17 deletions(-)
diff --git a/ansible/vars.yml b/ansible/vars.yml
index 446bf6be..7a714735 100644
--- a/ansible/vars.yml
+++ b/ansible/vars.yml
@@ -9,9 +9,9 @@ postgres_major:
# Full version strings for each major version
postgres_release:
- postgresorioledb-17: "17.0.1.097-orioledb"
- postgres17: "17.4.1.47"
- postgres15: "15.8.1.104"
+ postgresorioledb-17: "17.0.1.098-orioledb"
+ postgres17: "17.4.1.048"
+ postgres15: "15.8.1.105"
# Non Postgres Extensions
pgbouncer_release: "1.19.0"
diff --git a/migrations/db/migrations/20250623125453_tmp_grant_storage_tables_to_postgres_with_grant_option.sql b/migrations/db/migrations/20250623125453_tmp_grant_storage_tables_to_postgres_with_grant_option.sql
new file mode 100644
index 00000000..465aee22
--- /dev/null
+++ b/migrations/db/migrations/20250623125453_tmp_grant_storage_tables_to_postgres_with_grant_option.sql
@@ -0,0 +1,6 @@
+-- migrate:up
+-- TODO: remove this migration once STORAGE-211 is completed
+-- DRI: bobbie
+grant all on storage.buckets, storage.objects to postgres with grant option;
+
+-- migrate:down
diff --git a/nix/tests/expected/storage.out b/nix/tests/expected/storage.out
index 353604ec..fc188292 100644
--- a/nix/tests/expected/storage.out
+++ b/nix/tests/expected/storage.out
@@ -81,13 +81,13 @@ order by
storage | buckets | authenticated | TRIGGER | f
storage | buckets | authenticated | TRUNCATE | f
storage | buckets | authenticated | UPDATE | f
- storage | buckets | postgres | DELETE | f
- storage | buckets | postgres | INSERT | f
- storage | buckets | postgres | REFERENCES | f
- storage | buckets | postgres | SELECT | f
- storage | buckets | postgres | TRIGGER | f
- storage | buckets | postgres | TRUNCATE | f
- storage | buckets | postgres | UPDATE | f
+ storage | buckets | postgres | DELETE | t
+ storage | buckets | postgres | INSERT | t
+ storage | buckets | postgres | REFERENCES | t
+ storage | buckets | postgres | SELECT | t
+ storage | buckets | postgres | TRIGGER | t
+ storage | buckets | postgres | TRUNCATE | t
+ storage | buckets | postgres | UPDATE | t
storage | buckets | service_role | DELETE | f
storage | buckets | service_role | INSERT | f
storage | buckets | service_role | REFERENCES | f
@@ -123,13 +123,13 @@ order by
storage | objects | authenticated | TRIGGER | f
storage | objects | authenticated | TRUNCATE | f
storage | objects | authenticated | UPDATE | f
- storage | objects | postgres | DELETE | f
- storage | objects | postgres | INSERT | f
- storage | objects | postgres | REFERENCES | f
- storage | objects | postgres | SELECT | f
- storage | objects | postgres | TRIGGER | f
- storage | objects | postgres | TRUNCATE | f
- storage | objects | postgres | UPDATE | f
+ storage | objects | postgres | DELETE | t
+ storage | objects | postgres | INSERT | t
+ storage | objects | postgres | REFERENCES | t
+ storage | objects | postgres | SELECT | t
+ storage | objects | postgres | TRIGGER | t
+ storage | objects | postgres | TRUNCATE | t
+ storage | objects | postgres | UPDATE | t
storage | objects | service_role | DELETE | f
storage | objects | service_role | INSERT | f
storage | objects | service_role | REFERENCES | f
[parent: 58024c1f1ccc]