-
Notifications
You must be signed in to change notification settings - Fork 73
docs: add database.sql and sync-rules.yaml to react-supabase-todolist demo #921
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from 2 commits
8279e5f
df12eb4
efdc7b2
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,66 @@ | ||
| -- Create the lists table | ||
| CREATE TABLE IF NOT EXISTS public.lists ( | ||
| id uuid NOT NULL DEFAULT gen_random_uuid() PRIMARY KEY, | ||
| created_at timestamp with time zone NOT NULL DEFAULT now(), | ||
| name text NOT NULL, | ||
| owner_id uuid NOT NULL REFERENCES auth.users (id) ON DELETE CASCADE | ||
| ); | ||
|
|
||
| -- Create the todos table | ||
| CREATE TABLE IF NOT EXISTS public.todos ( | ||
| id uuid NOT NULL DEFAULT gen_random_uuid() PRIMARY KEY, | ||
| created_at timestamp with time zone NOT NULL DEFAULT now(), | ||
| completed_at timestamp with time zone, | ||
| description text NOT NULL, | ||
| completed boolean NOT NULL DEFAULT false, | ||
| list_id uuid NOT NULL REFERENCES public.lists (id) ON DELETE CASCADE, | ||
| created_by uuid REFERENCES auth.users (id), | ||
| completed_by uuid REFERENCES auth.users (id) | ||
| ); | ||
|
|
||
| -- Enable Row Level Security | ||
| ALTER TABLE public.lists ENABLE ROW LEVEL SECURITY; | ||
| ALTER TABLE public.todos ENABLE ROW LEVEL SECURITY; | ||
|
|
||
| -- RLS policies for lists: users can only access their own lists | ||
| CREATE POLICY "Users can view their own lists" ON public.lists | ||
| FOR SELECT USING (auth.uid() = owner_id); | ||
|
|
||
| CREATE POLICY "Users can insert their own lists" ON public.lists | ||
| FOR INSERT WITH CHECK (auth.uid() = owner_id); | ||
|
|
||
| CREATE POLICY "Users can update their own lists" ON public.lists | ||
| FOR UPDATE USING (auth.uid() = owner_id); | ||
|
|
||
| CREATE POLICY "Users can delete their own lists" ON public.lists | ||
| FOR DELETE USING (auth.uid() = owner_id); | ||
|
|
||
| -- RLS policies for todos: users can only access todos in their own lists | ||
| CREATE POLICY "Users can view todos in their lists" ON public.todos | ||
| FOR SELECT USING ( | ||
| list_id IN (SELECT id FROM public.lists WHERE owner_id = auth.uid()) | ||
| ); | ||
|
|
||
| CREATE POLICY "Users can insert todos in their lists" ON public.todos | ||
| FOR INSERT WITH CHECK ( | ||
| list_id IN (SELECT id FROM public.lists WHERE owner_id = auth.uid()) | ||
| ); | ||
|
|
||
| CREATE POLICY "Users can update todos in their lists" ON public.todos | ||
| FOR UPDATE USING ( | ||
| list_id IN (SELECT id FROM public.lists WHERE owner_id = auth.uid()) | ||
| ); | ||
|
|
||
| CREATE POLICY "Users can delete todos in their lists" ON public.todos | ||
| FOR DELETE USING ( | ||
| list_id IN (SELECT id FROM public.lists WHERE owner_id = auth.uid()) | ||
| ); | ||
|
|
||
| -- Create PowerSync role for replication access | ||
| CREATE ROLE powersync_role REPLICATION LOGIN; | ||
| GRANT SELECT ON public.lists TO powersync_role; | ||
| GRANT SELECT ON public.todos TO powersync_role; | ||
|
|
||
| -- Create PowerSync publication | ||
| -- Note: FOR ALL TABLES is simplest for dev. In production, specify tables explicitly. | ||
| CREATE PUBLICATION powersync FOR TABLE public.lists, public.todos; | ||
|
simolus3 marked this conversation as resolved.
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,7 @@ | ||
| sync_streams: | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. This is not a valid configuration file, it should be something like this: config:
edition: 3
streams:
user_data:
auto_subscribe: true
queries:
# Separate stream per todo list, scoped to the authenticated user
- SELECT * FROM lists WHERE owner_id = auth.user_id()
- SELECT todos.* FROM todos INNER JOIN lists ON todos.list_id = lists.id WHERE lists.owner_id = auth.user_id()
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Updated to use the new format with config: edition: 3 and streams syntax, scoped to the authenticated user. Any changes? |
||
| - name: user_lists | ||
| # Separate stream per todo list, scoped to the authenticated user | ||
| parameters: select id as list_id from lists where owner_id = request.user_id() | ||
| data: | ||
| - select * from lists where id = bucket.list_id | ||
| - select * from todos where list_id = bucket.list_id | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I guess we should also add a note to set a password then?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Added a comment with instructions to set a password for the role.