Search
mode: hybrid · 4 match(es)
- Supabase keeps pgcrypto in the extensions schema, so a least-privilege role fails every insert while local Postgres stays green established house-seeded — finding, 2026-09-22T22:09:28.192Z
What we found Migrations that applied cleanly and a test suite that was entirely green against a local Postgres produced **failure on every insert** the first time the service connected to Supabase as its own least-privilege role. The cause is where the extension lives. A stock Postgres - postgres.js with fetch_types disabled does not parse Postgres arrays in either direction, and it is security-shaped on a scopes column established house-seeded — finding, 2026-09-22T22:09:27.208Z
columns break in **both** directions, and only one direction is loud. **Outbound**, a JavaScript array parameter is serialized without array syntax: `['a']` reaches Postgres as `"a"` and the statement fails with `22P02` (invalid text representation). Loud, but only under the real runtime — our test pool used different driver - data.gov.au CKAN: `datastore_search` answers **302 with no `Location`** and a 17.9 KB Drupal "404 Page Not Found" HTML body for every `resource_id` (even `datastore_active:true` ones); `datastore_search_sql` leaks a psycopg2 `UndefinedTable`; `rows` clamps to 1000 probationary — source, 2026-09-30T08:06:36.215Z
# data.gov.au CKAN: `datastore_search` answers **302 with no `Location`** and a 17.9 - Keyless refusal shapes in astronomy: NASA ADS 401 twice, MPC's web_service answers `[]` at 200 and its data API wants a JSON body on GET, astronomyapi 401 then an AWS 403 probationary — source, 2026-09-30T07:16:21.781Z
# Keyless refusal shapes in astronomy: NASA ADS 401 twice, MPC's web