AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Storage Policy Bucket Misattribution For Multi-Bucket And Negated Conditions

The Studio storage policy parser incorrectly attributes bucket-scoped policies, causing multi-bucket policies to appear under only one bucket and negated policies to appear under excluded buckets. This can mislead audit and lead to deletion of policies that still protect other buckets.

highConfidence 87%ReactAffected Vmaster

Origin Analysis

`extractBucketNameFromDefinition` in `apps/studio/components/interfaces/Storage/Storage.utils.ts` splits policy definition on ' AND ', selects the first segment containing `bucket_id`, and returns the first quoted string. It does not handle `IN` lists, `ANY (ARRAY[...])`, `<>`/`!=` negation, or multiple buckets, so it always returns one bucket and ignores operator semantics.
1. Create two buckets `avatars` and `logos`. 2. Run SQL: `create policy "Multi bucket read" on storage.objects for select to authenticated using (bucket_id in ('avatars','logos'));` 3. Open Storage > Policies; policy only shows under `avatars`, not `logos`. 4. Run `create policy "Not avatars" on storage.objects for select using (bucket_id <> 'avatars');` and observe it appears under `avatars`; deleting `avatars` deletes it.

Fixing Code Block

Edge Case Audit

Changing the function signature will break current call sites unless updated. Ensure all three consumers (Policies page, useBucketPolicyCount, DeleteBucketModal) are migrated simultaneously. On rollback, re-deploy previous parser but the bug persists. Test with multi-bucket, negated, and ANY array policies. Be cautious with policies created by older Studio versions or manually crafted SQL that may not match regex (e.g. complex expressions with OR); consider fallback to full definition scan if regex misses.

Ecosystem Topology