AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Dashboard Misclassifies System Roles And Enables Delete For Postgres

The Database → Roles page places postgres and supabase_privileged_role under 'Other database roles' and shows an enabled Delete action for postgres, risking accidental deletion of a critical superuser role.

highConfidence 92%React

Origin Analysis

RolesList.tsx filters roles using only SUPABASE_ROLES, ignoring SYSTEM_ROLES, so system roles appear under 'Other database roles'. RoleRow.tsx determines delete eligibility solely with SUPABASE_ROLES, leaving system roles unprotected.
1. Open a hosted Supabase project. 2. Navigate to Database → Roles. 3. Observe postgres and supabase_privileged_role under 'Other database roles'. 4. Open the three-dot actions menu for postgres and see the enabled Delete item.

Fixing Code Block

Edge Case Audit

The change only affects the dashboard UI; backend deletion safeguards may still be required. Ensure all protected role lists (SUPABASE_ROLES + SYSTEM_ROLES) are kept in sync with server-side validation. If the grouping change is deployed before the UI Delete disable, users may still see Delete under 'Protected roles'; coordinate both changes. Rollback: revert the diff; no database migration is needed.

Ecosystem Topology