44 lines
2.0 KiB
SQL
44 lines
2.0 KiB
SQL
-- ============================================================================
|
|
-- CORRECTIF : Policies RLS du bucket "fiches-horaires"
|
|
-- Date : 2026-03-01
|
|
--
|
|
-- Problème : L'application utilise la clé anon et une authentification custom. Les
|
|
-- policies de storage.objects qui exigent auth.uid() bloquent l'INSERT
|
|
-- et provoquent l'erreur "new row violates row-level security policy".
|
|
--
|
|
-- Solution : Recréer des policies pour permettre l'INSERT/UPDATE/DELETE/SELECT
|
|
-- sur le bucket 'fiches-horaires' en se basant sur bucket_id seulement.
|
|
--
|
|
-- ⚠️ À EXÉCUTER dans l'éditeur SQL Supabase :
|
|
-- https://app.supabase.com → votre projet → SQL Editor
|
|
-- ============================================================================
|
|
|
|
-- Supprimer d'abord les policies existantes (si elles existent)
|
|
DROP POLICY IF EXISTS "fiches-horaires - lecture publique" ON storage.objects;
|
|
DROP POLICY IF EXISTS "fiches-horaires - upload" ON storage.objects;
|
|
DROP POLICY IF EXISTS "fiches-horaires - update" ON storage.objects;
|
|
DROP POLICY IF EXISTS "fiches-horaires - delete" ON storage.objects;
|
|
|
|
-- Créer des policies permissives basées sur le bucket_id
|
|
CREATE POLICY "fiches-horaires - lecture publique"
|
|
ON storage.objects FOR SELECT
|
|
USING (bucket_id = 'fiches-horaires');
|
|
|
|
CREATE POLICY "fiches-horaires - upload"
|
|
ON storage.objects FOR INSERT
|
|
WITH CHECK (bucket_id = 'fiches-horaires');
|
|
|
|
CREATE POLICY "fiches-horaires - update"
|
|
ON storage.objects FOR UPDATE
|
|
USING (bucket_id = 'fiches-horaires');
|
|
|
|
CREATE POLICY "fiches-horaires - delete"
|
|
ON storage.objects FOR DELETE
|
|
USING (bucket_id = 'fiches-horaires');
|
|
|
|
-- Note : Si vous souhaitez restreindre les uploads aux utilisateurs authentifiés,
|
|
-- remplacez la clause WITH CHECK (bucket_id = 'fiches-horaires') par
|
|
-- WITH CHECK (bucket_id = 'fiches-horaires' AND auth.uid() IS NOT NULL)
|
|
-- et assurez-vous que vos utilisateurs sont bien authentifiés côté front.
|
|
|