AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Storage Policy Editor Silently Fails To Save Cleared USING/WITH CHECK Expressions

Clearing a Storage policy's USING or WITH CHECK expression in the Studio dashboard shows a success toast but does not persist the change because the payload omits undefined fields, leaving the old expression active and potentially causing security misconfigurations.

highConfidence 90%React

Origin Analysis

In createPayloadForUpdatePolicy, when a field is cleared its value becomes undefined; during JSON serialization, undefined keys are dropped, so the API never receives the update. The UI validation allows clearing, but no conversion to null is performed.
1. Go to Storage → Policies, create an UPDATE policy with both USING and WITH CHECK expressions. 2. Edit the policy, clear the WITH CHECK expression, click Review. 3. Notice the preview shows invalid SQL like `ALTER POLICY ... WITH CHECK ();`. 4. Click Save; a success toast appears. 5. Reopen the policy or query pg_policies to see the expression is still present.

Fixing Code Block

Edge Case Audit

This fix assumes the backend API accepts null to drop the expression. If the backend expects an empty string or a different sentinel, clearing may still fail. Additionally, the review modal may still preview invalid SQL (e.g., `WITH CHECK ()`), so a separate fix in the preview generator is required. If the API cannot handle null, rollback by reverting this change and instead preventing clearing in the UI.

Ecosystem Topology