AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Preview Branch Creation Fails To Preserve Object Privileges In Public Schema And Misses Auth Schema Triggers

Supabase preview branches created via Management API do not retain GRANT/REVOKE state on public schema objects, causing unintended privilege escalation for anon and authenticated roles, and skip creation of triggers on auth.users, breaking post-signup logic.

highConfidence 85%Supabase

Origin Analysis

Branch provisioning recreates database objects as the postgres role without replaying explicit ACLs from the parent, causing default privileges to apply. Additionally, DDL targeting the auth schema (trigger creation) is either skipped or executed without sufficient privileges during branch build, so migrations that create such triggers do not take effect.
1. Create a Supabase project with non-default grants on public functions/tables and a trigger on auth.users. 2. Create a preview branch via POST /v1/branches with with_data:false. 3. Wait for branch to settle (note ACTIVE_HEALTHY may not be terminal). 4. Compare ACLs between parent and branch using pg_proc.proacl and pg_class.relacl queries; observe differences. 5. Compare triggers on auth schema; observe missing trigger.

Fixing Code Block

Edge Case Audit

This is a manual workaround and must be rerun after each branch creation. It assumes only the four built-in roles need management; custom roles must be handled separately. The REVOKE ALL step may affect platform-internal dependencies if Supabase relies on certain default privileges; test thoroughly in a non-production branch first. Column-level privileges and GRANT OPTION are not fully replicated. Recommended rollback: recreate the branch from scratch or restore from a backup taken before applying this fix. If parent permissions change later, the branch will not automatically stay in sync.

Ecosystem Topology