[splinter] Proposal: two INFO lints for grant/policy mismatch (privilege_without_policy, policy_without_privilege) #50949
Unanswered
larik15
asked this question in
Feature Requests
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
With the Data API change (discussion #45329, applied to all projects on 2026-10-30), grants become explicit. Two mismatches between grants and RLS policies then become worth surfacing:
privilege_without_policy — RLS is enabled, anon/authenticated hold a table privilege (SELECT/INSERT/UPDATE/DELETE, or TRUNCATE which RLS doesn't cover), but no permissive policy allows that command for that role. RLS still blocks the rows, so nothing leaks today; the grant is just wider than the policies need. Proposed level: INFO (same reasoning as 0008).
policy_without_privilege — a permissive policy exists for a role/command, but the role has no table (or column) privilege. The policy is dead code and requests fail with 42501 before it is evaluated. Expected to become common after Oct 30. Proposed level: INFO.
How this differs from 0026/0027: those flag relations a role can read (introspection exposure). These compare the grant set against the policy set per role and command, in both directions.
Data: a static replay of migrations across 580 unique public Lovable+Supabase repos (write-up: https://github.com/larik15/supabase-grants/blob/main/STUDY.md). Between 17% and 78% of them rely on the legacy default grants, so on older projects lint 1 would fire on many RLS tables. That's why I'd keep it INFO, one row per table+role, and possibly limit it to write privileges.
Questions before I write code:
Implementation notes: has_table_privilege / has_any_column_privilege (covers PUBLIC and role membership), polroles containing the role or {public}, polcmd '*' expansion, relkind 'r', the same schema exclusion list as 0013, pg_depend deptype 'e' exclusion, pgrst.db_schemas scope. Happy to follow the /new-lint skill.
All reactions