| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051 |
- import { ident, safeSql, type SafeSqlFragment } from '@supabase/pg-meta/src/pg-format'
- import { Hook } from './hooks.constants'
- export const extractMethod = (
- uri: string,
- secret?: string
- ):
- | { type: 'postgres'; schema: string; functionName: string }
- | { type: 'https'; url: string; secret: string } => {
- if (uri.startsWith('https')) {
- return { type: 'https', url: uri, secret: secret || '' }
- } else {
- const [_proto, _x, _db, schema, functionName] = (uri || '').split('/')
- return {
- type: 'postgres',
- schema: schema || '',
- functionName: functionName || '',
- }
- }
- }
- export const isValidHook = (h: Hook) => {
- return (
- (h.method.type === 'postgres' &&
- h.method.schema.length > 0 &&
- h.method.functionName.length > 0) ||
- (h.method.type === 'https' && h.method.url.startsWith('https') && h.method.secret.length > 0)
- )
- }
- /**
- *
- * @param schema the schema that the function belongs to
- * @param functionName the function name associated with the hook
- * @returns an array of SQL statements to restore the original permissions to the function
- */
- export const getRevokePermissionStatements = (
- schema: string,
- functionName: string
- ): Array<SafeSqlFragment> => {
- return [
- safeSql`-- Revoke access to function from briven_auth_admin
- revoke execute on function ${ident(schema)}.${ident(functionName)} from briven_auth_admin;`,
- safeSql`-- Revoke access to schema from briven_auth_admin
- revoke usage on schema ${ident(schema)} from briven_auth_admin;`,
- safeSql`-- Restore function permissions to authenticated, anon and public
- grant execute on function ${ident(schema)}.${ident(functionName)} to authenticated, anon, public;`,
- ]
- }
|