Files
Saxon Fletcher 9718eea593 refine role impersonation popover (#49467)
**Old**
<img width="979" height="839" alt="image"
src="https://github.com/user-attachments/assets/7239604f-a37f-483c-84eb-dbafabdeb73c"
/>

**New**
<img width="1185" height="645" alt="image"
src="https://github.com/user-attachments/assets/e699d75f-fd04-47dc-a8da-97f880e39796"
/>


## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Studio UI refinement. This is PR 2 of 2 and depends on #49466.

## What is the current behavior?

The Run SQL query as a role submenu uses the full role-impersonation
card layout, making the nested popover substantially larger than the
surrounding query controls.

## What is the new behavior?

- Adds a compact role-impersonation presentation used only by the query
submenu.
- Uses horizontal FormItemLayout rows and base ToggleGroup, InputGroup,
Input, and Button components.
- Keeps role choices stacked while using tiny controls for user source,
user lookup, external-user fields, and MFA level.
- Keeps authenticated-user controls visible but disabled for Postgres
and Anonymous roles.
- Preserves project-user search, external-user claims, impersonation,
and stop-impersonating behavior.
- Leaves existing role selectors in GraphQL, Table Editor, Realtime, and
other surfaces unchanged.

## Verification

- Focused compact role-selector test
- Studio, UI, and UI Patterns typechecks
- Existing focused Toggle and MultiSelector tests
- Studio ESLint
- Local visual and interaction verification against the supplied
prototype



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary by CodeRabbit

* **New Features**
* Redesigned role impersonation with role-specific summaries and native
role icons.
* Added native and external user impersonation, including user-source
switching and MFA controls.
* Added user search, external user ID entry, and clearer active-user
controls with accessible labels.

* **Bug Fixes**
* Improved role switching, impersonation clearing, pending selections,
and error recovery.

* **Tests**
* Expanded coverage for role selection, user impersonation, MFA updates,
state transitions, and error handling.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-08-26 16:28:02 +08:00

186 lines
6.5 KiB
TypeScript

import 'graphiql/setup-workers/webpack'
import './graphiql-styles.css'
import { useMonaco, type GraphiQLPlugin } from '@graphiql/react'
import { createGraphiQLFetcher, Fetcher } from '@graphiql/toolkit'
import { PermissionAction } from '@supabase/shared-types/out/constants'
import { useParams } from 'common'
import { GraphiQL, HISTORY_PLUGIN } from 'graphiql'
import { User as IconUser } from 'lucide-react'
import { useTheme } from 'next-themes'
import { useCallback, useEffect, useMemo, useState } from 'react'
import { toast } from 'sonner'
import { LogoLoader } from 'ui'
import { DEFAULT_INTROSPECTION_SCHEMA } from './constants'
import styles from './graphiql.module.css'
import { IntrospectionDisabledNotice } from './IntrospectionDisabledNotice'
import { IntrospectionEnabledNotice } from './IntrospectionEnabledNotice'
import { usePgGraphqlIntrospectionStatus } from './usePgGraphqlIntrospectionStatus'
import { getTheme } from '@/components/interfaces/App/MonacoThemeProvider'
import { RoleImpersonationSelector } from '@/components/interfaces/RoleImpersonationSelector'
import { BASE_MONACO_EDITOR_OPTIONS } from '@/components/ui/CodeEditor/CodeEditor.utils'
import { useSessionAccessTokenQuery } from '@/data/auth/session-access-token-query'
import { useProjectPostgrestConfigQuery } from '@/data/config/project-postgrest-config-query'
import { useAsyncCheckPermissions } from '@/hooks/misc/useCheckPermissions'
import { useSelectedProjectQuery } from '@/hooks/misc/useSelectedProject'
import { API_URL, IS_PLATFORM } from '@/lib/constants'
import { getRoleImpersonationJWT } from '@/lib/role-impersonation'
import { useGetImpersonatedRoleState } from '@/state/role-impersonation-state'
const ROLE_IMPERSONATION_PLUGIN: GraphiQLPlugin = {
title: 'Role Impersonation',
icon: () => <IconUser />,
content: () => <RoleImpersonationSelector />,
}
/**
* GraphiQL (@graphiql/react) bundles its own Monaco instance, separate from the AMD-loaded one
* the rest of Studio uses — they only share the global `.monaco-*` CSS class names, not JS state.
* So theme/options applied here via @graphiql/react's `useMonaco` touch GraphiQL's editors only
* and never leak onto Studio's editors
*/
const GraphiQLEditorSettings = ({ theme }: { theme: 'dark' | 'light' }) => {
const { monaco } = useMonaco()
useEffect(() => {
if (!monaco) return
monaco.editor.defineTheme('supabase', getTheme(theme))
monaco.editor.setTheme('supabase')
}, [monaco, theme])
useEffect(() => {
if (!monaco) return
const options = {
...BASE_MONACO_EDITOR_OPTIONS,
padding: { top: 16, bottom: 16 },
glyphMargin: true,
}
const applyToEditor = (editor: ReturnType<typeof monaco.editor.getEditors>[number]) =>
editor.updateOptions(options)
monaco.editor.getEditors().forEach(applyToEditor)
const disposable = monaco.editor.onDidCreateEditor(applyToEditor)
return () => disposable.dispose()
}, [monaco])
return null
}
export const GraphiQLTab = () => {
const { ref: projectRef } = useParams()
const { resolvedTheme } = useTheme()
const currentTheme = resolvedTheme?.includes('dark') ? 'dark' : 'light'
const { data: accessToken } = useSessionAccessTokenQuery({ enabled: IS_PLATFORM })
const { data: project } = useSelectedProjectQuery()
const { data: config } = useProjectPostgrestConfigQuery({ projectRef })
const jwtSecret = config?.jwt_secret
const getImpersonatedRoleState = useGetImpersonatedRoleState()
const { can: canReadJWTSecret } = useAsyncCheckPermissions(
PermissionAction.READ,
'field.jwt_secret'
)
const { notice, schemaComment } = usePgGraphqlIntrospectionStatus({
projectRef,
connectionString: project?.connectionString,
schema: DEFAULT_INTROSPECTION_SCHEMA,
})
// Bumped to force GraphiQL to re-mount and re-run introspection after the
// introspection setting changes in either direction.
const [graphiqlKey, setGraphiqlKey] = useState(0)
const plugins = useMemo<GraphiQLPlugin[]>(
() => (canReadJWTSecret ? [HISTORY_PLUGIN, ROLE_IMPERSONATION_PLUGIN] : [HISTORY_PLUGIN]),
[canReadJWTSecret]
)
const fetcher = useMemo(() => {
const fetcherFn = createGraphiQLFetcher({
// [Joshen] Opting to hard code /platform for local to match the routes, so that it's clear what's happening
url: `${API_URL}${IS_PLATFORM ? '' : '/platform'}/projects/${projectRef}/api/graphql`,
fetch,
})
const customFetcher: Fetcher = async (graphqlParams, opts) => {
let userAuthorization: string | undefined
const role = getImpersonatedRoleState().role
if (
projectRef !== undefined &&
jwtSecret !== undefined &&
role !== undefined &&
role.type === 'postgrest'
) {
try {
const token = await getRoleImpersonationJWT(projectRef, jwtSecret, role)
userAuthorization = 'Bearer ' + token
} catch (err: any) {
toast.error(`Failed to get JWT for role: ${err.message}`)
}
}
return fetcherFn(graphqlParams, {
...opts,
headers: {
...opts?.headers,
...(accessToken && {
Authorization: `Bearer ${accessToken}`,
}),
'x-graphql-authorization':
opts?.headers?.['Authorization'] ??
opts?.headers?.['authorization'] ??
userAuthorization ??
accessToken,
},
})
}
return customFetcher
}, [projectRef, getImpersonatedRoleState, jwtSecret, accessToken])
const handleIntrospectionChanged = useCallback(() => {
setGraphiqlKey((k) => k + 1)
}, [])
if (IS_PLATFORM && !accessToken) {
return <LogoLoader />
}
return (
<div className="flex flex-col h-full">
<GraphiQLEditorSettings theme={currentTheme} />
{notice === 'opt-in' && (
<IntrospectionDisabledNotice
schema={DEFAULT_INTROSPECTION_SCHEMA}
currentSchemaComment={schemaComment}
onEnabled={handleIntrospectionChanged}
/>
)}
{notice === 'opt-out' && (
<IntrospectionEnabledNotice
schema={DEFAULT_INTROSPECTION_SCHEMA}
currentSchemaComment={schemaComment}
onDisabled={handleIntrospectionChanged}
/>
)}
<div className="flex-1 min-h-0">
<GraphiQL
key={graphiqlKey}
fetcher={fetcher}
forcedTheme={currentTheme}
editorTheme={{ dark: 'supabase', light: 'supabase' }}
className={styles.root}
plugins={plugins}
/>
</div>
</div>
)
}