migrate/supabase: emit the users module + JWT only when auth.users is in the export; gap dangling auth references (conformance M3) - #315
Merged
Conversation
… in the export; gap on dangling auth references (M3) The translator called authmap::build_auth unconditionally and pushed the users module as modules[0], so an export with a single `todos` table came back with a User entity, register/login and auth.model=jwt — "migrated 2 entities" for one source table, an auth surface the source never had. The users module is now emitted only when the export really carries auth.users: its dumped DDL, a foreign key referencing it (a `--schema public` dump keeps the reference), or its exported rows. The auth MODEL is gated separately — a source that restricts rows by the authenticated user (auth.uid(), membership) keeps jwt auth so its guards survive, with a blocking gap naming the missing identity surface; dropping the model there would have silently unguarded every restricted table. With no auth anywhere, the design has no auth block, no auth dependency and unguarded CRUD (as open as the source, stated as an advisory), and storage/realtime blocks that need an identity are gap-reported instead of emitted. Output is byte-identical for any export that carries auth.users. The migrate fixtures now declare auth.users, matching the export layout the docs prescribe.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Docs↔codegen conformance sweep.
19-migrate-supabase.md:72frames the users module as derived fromauth.users, butauthmap::build_authran unconditionally — a table-only export got a fullusersmodule,register/login, andAuthModel::Jwt("migrated 2 entities" for one source table): an unrequested auth surface, violating never-guess.Fix:
export_has_auth_usersgates the users module on theauth.userstable, or any fk withref_table == auth.users, ordata/auth.users.csv— the fk/csv signals matter because asupabase db dump --schema public(very common) drops theauth.usersDDL but keeps the references; a table-only gate would have silently stripped auth from those exports. Separately,auth_needed(tenancy or any non-NoRls table, but noauth.users) keepsauth.model: jwtwithout an identity surface and raises a blocking gap — the only shape that neither drops auth nor widens access (dropping it would abort on a no-endpoint module or silently unguard restricted tables).Verified: (a) table-only export → no auth block, 1 entity, deps [db]; (b) normal export with auth.users → entire generated app tree byte-identical (diff -r); (c) RLS referencing auth.uid() with no auth.users → blocking gap, endpoints stay guarded. Fixtures updated to declare
auth.usersper the documented export layout;19-migrate-supabase.mddocuments the auth-less and dangling-reference behaviours.Test:
the_users_module_follows_auth_users_and_a_dangling_auth_reference_is_a_blocking_gap. Fullcargo test -p jerrycangreen. No version bump.