Fixed public payment reads

X-Lovable-Edit-ID: edt-76b4dd29-c3c1-4603-a335-f4152d68bf3a
Co-authored-by: renee-png <262607627+renee-png@users.noreply.github.com>
This commit is contained in:
gpt-engineer-app[bot]
2026-04-28 00:53:12 +00:00
co-authored by renee-png
2 changed files with 13 additions and 9 deletions
+4 -9
View File
@@ -176,15 +176,10 @@ export const cancelPaymentRequest = createServerFn({ method: "POST" })
export const getPublicPaymentRequest = createServerFn({ method: "GET" })
.inputValidator((data: { id: string }) => data)
.handler(async ({ data }) => {
// Use anon-key client; RLS policy "pr_select_public_by_id" allows public reads
const { createClient } = await import("@supabase/supabase-js");
const url = process.env.SUPABASE_URL;
const anonKey = process.env.SUPABASE_PUBLISHABLE_KEY;
if (!url || !anonKey) throw new Error("Supabase env not configured");
const sb = createClient(url, anonKey, {
auth: { persistSession: false, autoRefreshToken: false },
});
const { data: row } = await sb
// Use service-role client to bypass RLS; return only a strict whitelist
// of non-sensitive fields for the public pay page.
const { supabaseAdmin } = await import("@/integrations/supabase/client.server");
const { data: row } = await supabaseAdmin
.from("payment_requests")
.select(
"id, recipient_name, description, base_amount_cents, fee_amount_cents, total_amount_cents, currency, status, stripe_checkout_url, paid_at",
@@ -0,0 +1,9 @@
-- Remove overly-permissive public SELECT policy on payment_requests
DROP POLICY IF EXISTS pr_select_public_by_id ON public.payment_requests;
-- Authenticated users can see payment requests they created, or admins see all
CREATE POLICY pr_select_owner_or_admin
ON public.payment_requests
FOR SELECT
TO authenticated
USING (is_admin(auth.uid()) OR created_by = auth.uid());