Six comments and doc lines put the number of RLS policies at 58. It is
21 — counted from pg_policy while building the data catalogue. The
figure appears in load-bearing prose ("all 58 policies call
is_hr_user()", "all 58 policies stay unchanged"), where being wrong by a
factor of three invites someone to go looking for the missing thirty-
seven.
The two occurrences inside supabase/migrations/ stay as they are. That
file already ran against the database; its comments record what was
believed at the time, and editing them would make the file differ from
what was applied for no gain.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
33 lines
1.3 KiB
TypeScript
33 lines
1.3 KiB
TypeScript
import "server-only";
|
|
import { auth } from "@/auth";
|
|
|
|
// Der einzige Ort, an dem die Kennung der angemeldeten Person herkommt.
|
|
//
|
|
// Dass der Wechsel von GoTrue auf Auth.js eine Änderung an dieser Datei war
|
|
// und nicht an fünfzig Aufrufstellen, lag genau an dieser Bündelung: alles
|
|
// andere ruft `currentUserId()` auf und reicht den Wert an withUser() weiter.
|
|
//
|
|
// Der Wert ist app_users.id — nicht die `oid` von Entra. Die Zuordnung
|
|
// zwischen beiden macht app_upsert_user() bei der Anmeldung, und sie
|
|
// übernimmt für eine bereits bekannte Adresse die vorhandene profiles.id.
|
|
// Deshalb passt die Kennung weiterhin auf das, was app_current_user_id() in
|
|
// der Datenbank erwartet, und die 21 RLS-Policies merken vom Wechsel nichts.
|
|
|
|
export async function currentUserId(): Promise<string | null> {
|
|
const session = await auth();
|
|
return session?.user?.id ?? null;
|
|
}
|
|
|
|
/**
|
|
* Wie currentUserId(), bricht aber ab, statt null zu liefern.
|
|
*
|
|
* Für Stellen, die ohne angemeldete Person keinen Sinn ergeben. Die
|
|
* Absicherung hängt trotzdem nicht daran: ohne Kontext geben die
|
|
* RLS-Policies nichts zurück, unabhängig davon, was der Anwendungscode tut.
|
|
*/
|
|
export async function requireUserId(): Promise<string> {
|
|
const id = await currentUserId();
|
|
if (!id) throw new Error("Nicht angemeldet.");
|
|
return id;
|
|
}
|