AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Restored Supabase Project Lacks Postgres Superuser Privileges, Breaking FDW Creation

After restoring or unpausing a Supabase project, the postgres role loses superuser privileges, causing operations like creating foreign data wrappers to fail with permission denied errors. This affects functionality such as adding the ClickHouse Wrapper.

highConfidence 70%Postgresql

Origin Analysis

Supabase's restore process fails to preserve or re-apply the SUPERUSER attribute on the postgres role, leaving the restored project with restricted privileges that block creation of foreign data wrappers and other superuser-only operations.
1. Un-pause or restore a Supabase project. 2. Open the SQL Editor. 3. Execute `CREATE FOREIGN DATA WRAPPER clickhouse_wrapper ...` or attempt to use the ClickHouse Wrapper UI. 4. Observe error: `42501: permission denied to create foreign-data wrapper "clickhouse_wrapper" HINT: Must be superuser to create a foreign-data wrapper.`

Fixing Code Block

Edge Case Audit

Granting SUPERUSER to the postgres role elevates privileges to the maximum level, increasing the risk of accidental data loss, unauthorized access, or destructive operations. If this role is used by application connections, ensure it is trusted. To roll back, execute `ALTER ROLE postgres NOSUPERUSER;`. Long-term fix should address the restore process to correctly preserve role attributes.

Ecosystem Topology