Replies: 1 comment
|
Hi @thn95, The difference in behavior between local and hosted Supabase comes down to role ownership:
Here are the authoritative, supported patterns to accomplish your requirements in hosted Supabase: Question 1: Is there a supported way on hosted Supabase to grant direct privileges on
|
Uh oh!
There was an error while loading. Please reload this page.
Hi,
I am testing an MFA / owner-authorization flow on a hosted Supabase staging project.
The local Supabase environment passes all tests, but the hosted project fails during a prerequisite migration with:
SQLSTATE 42501: insufficient privilege
The migration needs narrowly scoped access for NOLOGIN application definer roles:
It also conditionally creates a restrictive policy on auth.users.
These permissions are used only by database-side authorization guards for:
The connected postgres role can read the managed Auth objects, but it does not appear to have the grant option / ownership required to grant these privileges or create the policy.
The transaction was rolled back cleanly. I am not trying to disable RLS, broaden grants, change ownership, or bypass Supabase Auth security.
My questions are:
I would prefer to follow a supported hosted-Supabase pattern rather than work around the managed Auth permissions.
Thanks.
All reactions