42 lines
1.8 KiB
SQL
42 lines
1.8 KiB
SQL
-- ============================================================================
|
|
-- CORRECTIF : Policies RLS du bucket "materiel-roulant"
|
|
-- Date : 2026-03-01
|
|
--
|
|
-- Problème : L'application utilise une authentification custom (RPC authenticate_user
|
|
-- + localStorage). supabase.auth.signIn() n'est jamais appelé, donc
|
|
-- auth.uid() est toujours NULL → la policy WITH CHECK auth.uid() IS NOT NULL
|
|
-- bloque tous les uploads.
|
|
--
|
|
-- Solution : Policies ouvertes sur le bucket (accès par clé anon publique).
|
|
-- Le bucket est déjà créé — ce script corrige uniquement les policies.
|
|
--
|
|
-- ⚠️ À EXÉCUTER dans l'éditeur SQL Supabase :
|
|
-- https://supabase.com/dashboard → votre projet → SQL Editor
|
|
-- ============================================================================
|
|
|
|
-- Supprimer toutes les policies existantes du bucket
|
|
DROP POLICY IF EXISTS "materiel-roulant - lecture publique" ON storage.objects;
|
|
DROP POLICY IF EXISTS "materiel-roulant - upload authentifié" ON storage.objects;
|
|
DROP POLICY IF EXISTS "materiel-roulant - update authentifié" ON storage.objects;
|
|
DROP POLICY IF EXISTS "materiel-roulant - delete authentifié" ON storage.objects;
|
|
|
|
-- Recréer les policies sans condition auth.uid()
|
|
-- (l'app utilise la clé anon, auth.uid() est toujours NULL)
|
|
|
|
CREATE POLICY "materiel-roulant - lecture publique"
|
|
ON storage.objects FOR SELECT
|
|
USING (bucket_id = 'materiel-roulant');
|
|
|
|
CREATE POLICY "materiel-roulant - upload authentifié"
|
|
ON storage.objects FOR INSERT
|
|
WITH CHECK (bucket_id = 'materiel-roulant');
|
|
|
|
CREATE POLICY "materiel-roulant - update authentifié"
|
|
ON storage.objects FOR UPDATE
|
|
USING (bucket_id = 'materiel-roulant');
|
|
|
|
CREATE POLICY "materiel-roulant - delete authentifié"
|
|
ON storage.objects FOR DELETE
|
|
USING (bucket_id = 'materiel-roulant');
|
|
|